AI Policy

The AI Regulatory Landscape Split in Two in 2026, and Both Halves Are Still Moving

Illustration representing the AI regulatory landscape split between the EU and United States
The AI regulatory landscape split sharply between the EU and US in 2026

By Stuart Kerr, Technology Correspondent, LiveAIWire

The AI regulatory landscape split decisively in 2026, and the split itself is now the story. The European Union has kept building a single, binding, risk-tiered law that applies across the entire bloc. The United States has moved in the opposite direction: a federal government actively trying to stop states from regulating AI at all, while more than three dozen states pass their own rules anyway. Understanding the AI regulatory landscape in mid-2026 means understanding both halves of that split, because a company operating across borders now has to satisfy an EU law, a shifting patchwork of US state laws, and an increasingly hostile federal posture toward those same state laws, all at once.

None of this is settled, and pretending otherwise is the most common mistake in coverage of the AI regulatory landscape. Deadlines have moved, one state repealed its own flagship AI law and replaced it with something narrower, and a US executive order is actively trying to unwind rules that took months of legislative work to pass. The practical shape of the AI regulatory landscape right now is not a finished rulebook. It is three moving regimes that businesses have to track simultaneously.

The EU AI Act Is No Longer Theoretical

The clearest fixed point in the global AI regulatory landscape is the European Union’s AI Act, which is now in active application rather than early rollout. The prohibitions on the eight practices the Act bans outright, including social scoring and untargeted facial recognition scraping, took effect in February 2025. The governance rules and obligations for general-purpose AI models became applicable in August 2025. The Act’s transparency requirements, covering AI-generated content labelling and chatbot disclosure, arrive in August 2026, the same month the Act becomes fully applicable except for specific carve-outs.

Those carve-outs matter as much as the headline dates. A political agreement reached in May 2026, part of what the Commission calls the AI omnibus simplification package, pushed the rules for high-risk systems in biometrics, critical infrastructure, education, employment, migration and border control to December 2027. High-risk systems embedded in regulated physical products, such as lifts or toys, now have until August 2028. The same agreement added a new prohibition on AI systems that generate non-consensual sexual content, including so-called nudification apps, and gave the European AI Office stronger centralised oversight powers. The AI regulatory landscape in Europe is tightening in some places and easing its timeline in others, in the same document.

The Commission has also been publishing supporting instruments to make the obligations workable in practice rather than purely theoretical. Guidelines on the scope of general-purpose AI obligations, a voluntary Code of Practice for GPAI providers, and a template requiring providers to summarise their training data publicly were all published in mid-2025, ahead of the August 2025 GPAI deadline.

A further Code of Practice covering the labelling of AI-generated content followed in June 2026, giving providers a concrete route to compliance with the transparency rules before they become mandatory. That sequencing, guidance released before enforcement rather than after, is one of the more deliberate features of how the EU has approached the AI regulatory landscape compared with the more reactive US posture.

What EU AI Act Enforcement Actually Looks Like on the Ground

LiveAIWire’s earlier coverage of how AI governance platforms are adapting to EU AI Act enforcement found that fines for serious violations can reach 35 million euros or 7 percent of global annual turnover, a penalty structure that has already turned AI governance software from a nice-to-have into a compliance necessity for any organisation operating in the EU. The same reporting found that shadow AI, tools employees adopt without IT sanction, creates real liability exposure under the Act even when the organisation never formally approved the tool’s use.

Bias documentation is one of the clearest practical obligations to fall out of the AI regulatory landscape so far. LiveAIWire’s coverage of why mitigating AI bias is harder than it looks found that the EU AI Act requires organisations to demonstrate, not merely assert, that bias in high-risk systems has been identified and addressed, a standard that most enterprise AI deployments were not built to meet. The technical difficulty compounds the legal one: different mathematical definitions of fairness are mutually incompatible, so regulators requiring bias mitigation without specifying which definition to use are, in effect, asking every developer to make a philosophical choice before making a technical one.

The United States Has No Federal Law, and the Federal Government Is Fighting the States Instead

The American side of the AI regulatory landscape looks nothing like Europe’s. Congress has not passed a comprehensive federal AI law, and nothing currently on the table suggests one is close. Instead, President Trump signed Executive Order 14365, titled Ensuring a National Policy Framework for Artificial Intelligence, on December 11, 2025. According to White & Case’s analysis of the order, it directs the Attorney General to establish an AI Litigation Task Force to challenge state AI laws in federal court, orders the Commerce Department to identify state laws it considers onerous, and conditions federal funding on states aligning their AI rules with the administration’s minimally burdensome policy.

Because federal preemption ordinarily flows from Congress rather than an executive order, the order’s practical effect on existing state laws remains uncertain, and White & Case’s own guidance to businesses is to keep complying with state AI laws until the courts settle the question. That uncertainty is itself a defining feature of the current AI regulatory landscape: a federal government asserting authority it may not actually have yet, against a set of state laws that remain enforceable until a court says otherwise.

The State Patchwork Keeps Moving Under Its Own Feet

Meanwhile, the state laws the federal order is trying to contain keep changing on their own timeline. Texas’s TRAIGA and California’s SB 53 and AB 2013 all took effect on January 1, 2026, covering intent-based prohibitions on manipulative AI, frontier-model safety disclosures and generative AI training-data summaries respectively. Compyl’s 2026 compliance guide found that Colorado went further than any other state and then reversed course: its original 2024 AI Act was repealed entirely and replaced with a narrower automated-decision law, SB 26-189, that will not take effect until 2027 and focuses on consumer notices and human review rights rather than the broader risk-management obligations the original act imposed.

That repeal-and-replace episode is the clearest illustration of how unstable the state layer of the AI regulatory landscape still is. More than 2,000 AI-related bills have been introduced across US states, and the practical guidance from compliance specialists tracking the space is to treat any summary of state AI law as a floor rather than a ceiling, because the details keep changing quarterly. Illinois and New York City have taken a narrower approach focused specifically on employment decisions, while Texas grants a safe harbor to organisations that can demonstrate substantial alignment with the NIST AI Risk Management Framework, making that framework a de facto backbone for compliance across multiple states at once.

Why the AI Regulatory Landscape Is Also a Geopolitical Story

The AI regulatory landscape does not exist separately from the broader contest over who controls the most capable AI systems. LiveAIWire’s reporting on the AI Cold War between the United States and China found that chip export policy has swung between restriction and access multiple times over the past eighteen months, with the same administration that is trying to minimise domestic AI regulation simultaneously using export controls as a strategic lever against a geopolitical rival. Regulatory posture and industrial strategy are, in practice, the same lever pulled in different directions depending on the audience: light-touch rules at home to preserve competitive speed, and tight technical controls abroad to preserve a capability lead.

That dual posture is not unique to the United States. The EU’s own AI Act sits inside a wider package that includes an AI Continent Action Plan and AI Factories initiative explicitly aimed at building European AI capability and reducing dependence on non-European infrastructure, a version of the same instinct to regulate domestically while competing internationally that shows up in Washington’s approach to chip exports.

The clearest recent example of how far that instinct can extend is LiveAIWire’s coverage of the AI export controls that shut down Anthropic’s most advanced models worldwide in June 2026. A single Commerce Department directive, invoking the same export control law that normally targets semiconductors, removed a piece of commercial AI infrastructure from every user on the planet within hours, before being reversed nineteen days later.

That episode has nothing to do with the EU AI Act or US state consumer-protection laws directly, but it demonstrates the same underlying reality that runs through the entire AI regulatory landscape: the government with authority over the leading AI labs can reshape access to their systems overnight, through export law rather than through the more familiar channels of AI-specific regulation. Businesses building compliance programmes around the visible rulebooks, the EU AI Act, state consumer laws, sector guidance, should treat export control authority as a fourth, less predictable lever that sits alongside them and can override commercial access decisions with no advance notice at all.

What This Means for Anyone Building or Deploying AI

For any organisation operating across the EU and the US, the practical answer to a fragmented AI regulatory landscape is to build a single governance programme that satisfies the strictest applicable requirement in each category rather than maintaining separate compliance tracks per jurisdiction. The NIST AI Risk Management Framework has emerged as the closest thing to a common backbone: Texas grants it explicit legal safe harbor, Colorado’s new consumer-notice duties map onto its structure, and it aligns closely enough with the EU AI Act’s own risk classification approach that documentation built for one regime covers most of what the other requires.

The organisations navigating the AI regulatory landscape most successfully right now share a specific habit: they are not waiting for the federal preemption fight in the US or the EU’s simplification package to resolve before building compliance infrastructure. They are building to the strictest currently enforceable standard in each jurisdiction they operate in, and treating every quarter as an opportunity for the rules to change again, because on the evidence of the past year, they will.

That approach also protects against the specific failure mode this year has demonstrated most clearly: assuming a law’s headline provisions will survive unchanged from announcement to enforcement. Colorado’s own flagship AI act did not survive that gap. Businesses that had already built compliance programmes around its original risk-management requirements had to rebuild around a narrower consumer-notice regime instead, work that could have been avoided by tracking the legislative process rather than the initial statute alone. The same caution applies to the EU’s own timeline and to the outcome of the federal litigation still working its way through US courts.

About the Author

Stuart Kerr is Technology Correspondent at LiveAIWire, covering artificial intelligence, emerging technology, and their impact on business, society, and everyday life. LiveAIWire publishes original AI journalism every weekday at liveaiwire.com.