# The U.S. and the EU regulate AI differently

> Source: <https://www.fastcompany.com/91594112/the-u-s-and-the-eu-regulate-ai-differently>
> Published: 2026-08-25 12:00:00+00:00

Spanning [113 articles](https://www.whitecase.com/insight-alert/long-awaited-eu-ai-act-becomes-law-after-publication-eus-official-journal) and roughly 50,000 words, the EU [AI](https://www.fastcompany.com/section/artificial-intelligence) Act is the first of its kind globally to provide comprehensive legislation on AI. Meanwhile, the U.S. has not yet passed any federal laws on the matter, relying instead on [executive orders](https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/), guidance from [agencies](https://www.nist.gov/itl/ai-risk-management-framework) like the National Institute of Standards and Technology and the [Federal Trade Commission](https://www.ftc.gov/ai), and a growing collection of [state-level bills](https://ai-law-center.orrick.com/us-ai-law-tracker-see-all-states/). In fact, in 2024, U.S. states passed [131 AI-related laws](https://hai.stanford.edu/assets/files/hai_ai-index-report-2025_chapter6_final.pdf), more than double the 49 that were enacted in 2023.

At first glance, the U.S. appears more active, but when you measure the weight of its AI laws, the picture reverses. For instance, a California [deepfake bill](https://www.gov.ca.gov/2024/09/17/governor-newsom-signs-bills-to-combat-deepfake-election-content/) and an EU article on [high-risk AI](https://artificialintelligenceact.eu/article/6/) systems are not equivalent instruments. A single EU article can carry more legal force than a dozen state statutes combined, because U.S. state laws might be narrowly focused, and later repealed by a federal law. EU law, on the other hand, has supremacy over national laws of the member states. A single article might have consequences for entire industries.

Comparing what each system prohibits outright is also instructive. [Article 5](https://www.modulos.ai/blog/eu-ai-act-prohibited-practices/) of the EU AI Act bans eight categories of AI practices, including social scoring, real-time facial recognition in public spaces for law enforcement, emotion recognition in workplaces and schools, and pure profiling-based criminal prediction.

These technology uses are clearly unacceptable, so category-wide bans make sense. However, four of these eight categories have use exceptions. For example, in emergency cases, law enforcement agencies are allowed to use facial recognition to find kidnapping victims.

In comparison, the U.S. federal government has not banned any AI technology categories. Instead, during the previous presidency, federal agencies and then courts focused on a specific [AI](https://archives.hud.gov/news/2024/pr24-098.cfm) [use](https://www.navigatehousing.com/fair-housing-guidance-withdrawal-what-huds-2026-notice-means-for-housing-providers/), such as tenant screening and advertising housing opportunities, rather than banning the underlying tools.

There is no AI without content access. So, in a broad sense, copyright laws are also part of AI regulation.

The U.S. relies on the four-factor [Fair Use doctrine](https://www.copyright.gov/fair-use/), which allows limited use of copyrighted material without permission. The EU, on the other hand, relies on a closed list of exceptions under the [2019 DSM Directive](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019L0790).

The EU AI Act’s [Article 4](https://artificialintelligenceact.eu/article/4/) permits commercial AI training on data only where rights holders haven’t actively blocked it. In practice, that means developers must audit their training data against a moving list of opt-outs. This problem does not exist on the other side of the Atlantic.

Economists increasingly measure relevant regulation by what it adds to the price of building a product. For high-risk AI models, like the systems used in [hiring](https://www.fastcompany.com/section/hiring), credit scoring, or healthcare, EU AI Act compliance is estimated to increase in sectors with stringent validation requirements.

In the U.S., the annual compliance burden is estimated to be between [$50,000 and $150,000](https://www.kiteworks.com/cmmc-compliance/level-1-documentation-requirements/). These costs are mostly related to data architecture for AI training and deployment and driven by state privacy laws like the [California Consumer Privacy Act](https://oag.ca.gov/privacy/ccpa). In other states without such comprehensive laws, the burden will still likely be driven by data handling regulation rather than AI laws directly.

By that measure, in the EU, AI is roughly two to three times more expensive to launch in the high-risk tier, as [defined by the EU AI Act](https://ai-act-law.eu/)—AI systems that pose a significant risk of harm to health, safety, or fundamental individual rights.

Small to medium-size enterprises face compliance costs ranging from [€50,000 to €500,000](https://sqmagazine.co.uk/eu-ai-act-compliance-cost-statistics/) depending on use-case complexity, and that’s before the product has even shipped. This partially explains why between 2008 and 2021, close to 30% of the unicorns—privately held companies valued at $1 billion or more—that were founded in Europe [relocated their headquarters](https://www.insme.org/relocation-trends-of-eu-startups-and-scaleups-a-european-investment-bank-study/) outside the European Union, and why today U.S.-based AI companies attract roughly [75% of global AI venture capital](https://renaissanceeurope.org/insights/europes-startup-problem-is-capital-scale-not-just-regulation), compared with just 6% for EU companies.

Recently, Oxylabs became a [unicorn](https://oxylabs.io/blog/oxylabs-receives-investment), receiving a $130 million investment. We have no plans to relocate from Europe. But I understand why some firms do.

[The change in how the EU regulates AI is already underway. While no model is perfect, the EU is feeling greater pressure to reconsider its approach. The EU produces ][22% of global](https://knowledge.insead.edu/economics-finance/europes-historic-second-chance-leading-ais-next-wave) [AI research journal articles](https://knowledge.insead.edu/economics-finance/europes-historic-second-chance-leading-ais-next-wave), compared to 17% by U.S.-based researchers. The problem is that research doesn’t translate into commercial leadership.

EU policymakers are now saying so explicitly. In a [May 2026 address](https://ec.europa.eu/commission/presscorner/detail/en/speech_26_1159) to the Lisbon Council’s Scaling Europe Summit, Commissioner Dombrovskis acknowledged that excessive and overlapping regulatory obligations raise costs, deter investment, and divert resources from innovation.

The Commission [has since tabled](https://ec.europa.eu/commission/presscorner/detail/en/statement_26_410) [10 simplification](https://ec.europa.eu/commission/presscorner/detail/en/statement_26_410) proposals targeting around €15 billion in annual savings for EU companies. It aims to keep the basic framework as is but make operating within the current framework less of a drag on commercial growth.

It’s a start.

*Denas Grybauskas is chief governance and strategy officer at Oxylabs.*
