
Autor: Nermin Sefić
No technology in the last three decades has moved from laboratory curiosity to first-order geopolitical issue as quickly as artificial intelligence. While the internet and mobile telephony took nearly…
No technology in the last three decades has moved from laboratory curiosity to first-order geopolitical issue as quickly as artificial intelligence. While the internet and mobile telephony took nearly two decades to become the subject of serious regulatory debate, large language models and generative AI reached that point within a few years of the first widely available products. The result is a race between three major regulatory philosophies — European, American, and Chinese — competing not only for technological advantage but for the right to define the global norms under which this technology will develop over the next decade.
This race is not an abstract academic debate. It determines where data centers get built, which companies attract capital, which standards become de facto global simply because of the market size that imposes them, and, perhaps most importantly, how concentrated or distributed power will be over one of the most consequential technologies in human history.
The European Union has chosen a path that critics call excessively cautious and proponents call responsible: a comprehensive, horizontal regulatory framework that attempts to pre-categorize AI risks and prescribe obligations proportional to those risks. The AI Act, finally adopted after protracted negotiations, represents the first extensive attempt by any major jurisdiction to regulate artificial intelligence as a standalone category, rather than through existing sectoral rules like data protection or consumer protection.
The core logic of the European approach is risk-based classification. Systems that present "unacceptable risk" — such as government social scoring of citizens or manipulative techniques that exploit individual vulnerabilities — are simply banned. "High-risk" systems, which include applications in hiring, credit scoring, criminal justice, and critical infrastructure, are subject to strict documentation, transparency, human oversight, and conformity assessment requirements before market placement. Limited-risk systems, such as chatbots, require only transparency toward users that they are interacting with a machine. Everything else falls into the minimal-risk category and remains largely unregulated.
This architecture has an appealing logical consistency, but also practical challenges that became evident in the first months of implementation. Defining the boundary between "high" and "limited" risk has proven extremely difficult in practice — many systems don't fall purely into one category but exist on a spectrum depending on the context of use rather than the technology itself. The same large language understanding model can be used for writing marketing copy (minimal risk) and for assisting hiring decisions (high risk) — regulation must necessarily attach to the application rather than the technology itself, creating an enormous compliance burden for companies developing general-purpose models without a known end use in advance.
The European strategy rests on an assumption that has already proven partially correct in the context of data protection through GDPR: that the size of the single European market gives the EU the power to impose its standards globally, because it's cheaper for companies to align an entire product with the strictest requirements than to build separate versions for different markets. This phenomenon, known as the "Brussels effect," is partially repeating itself with the AI Act — many large technology companies are already adapting their global risk-management practices to European requirements, even for products not sold directly in the European market, simply because a single, globally harmonized system architecture is cheaper to maintain than a fragmented one.
But there are also serious limitations to the Brussels effect in the AI context that didn't exist to the same degree with data protection. Artificial intelligence, unlike personal data processing, is directly tied to military and national-security competitiveness in a way that creates strong incentives for states to develop their own parallel capabilities regardless of European standards. China and the United States simply don't have the same incentive to align with European rules that global technology companies had in the context of data privacy, where the concerns were primarily commercial rather than strategic.
The United States has chosen a fundamentally different philosophy — a fragmented, sectoral, and largely voluntary approach that favors innovation speed over preventive regulation. Instead of one comprehensive federal law like the European AI Act, the American approach consists of a mosaic of executive orders, voluntary commitments that major technology companies have made in agreement with the White House, existing sectoral regulators applying their authority to AI applications within their domains, and an increasingly active network of state laws trying to fill the gap federal government leaves behind.
This fragmentation is not accidental but reflects a deeply rooted American regulatory philosophy that prefers reactive regulation through litigation and sectoral agencies over preventive, horizontal regulation upfront. Proponents of this approach argue it's impossible to predict in advance all the ways technology developing at this pace will be used, and that attempting comprehensive prior regulation inevitably stifles innovation through disproportionate burden on small companies and startups lacking the resources of major players to comply with complex regulatory requirements.
Critics, on the other hand, warn this approach leaves significant gaps in protection — particularly for citizens exposed to automated decisions in areas like employment, housing, or access to financial services, where no clear federal accountability framework exists comparable to European requirements for high-risk systems. This tension between innovation speed and citizen protection remains unresolved, and differences in approach among individual American states — from relatively strict requirements in some states to near-total absence of regulation in others — create their own kind of fragmentation that complicates matters for companies operating nationally.
What the American approach loses in coherence, it partially compensates for in speed and capital flexibility. Without needing lengthy alignment with comprehensive regulatory requirements before launching products, American companies can iterate faster, test markets earlier, and attract risk capital sensitive to regulatory uncertainty. This dynamic partially explains why the largest share of global capital invested in AI startups continues to flow toward American companies, despite increasingly loud warnings about the risks of uncontrolled application.
The Chinese model represents a third, distinct philosophy that combines active state coordination of industrial policy with targeted regulation of specific applications considered particularly sensitive, such as content recommendation algorithms and publicly available generative models. Unlike the European attempt at comprehensive horizontal regulation or the American fragmented, largely reactive approach, Chinese strategy explicitly links AI regulation to broader goals of national technological sovereignty and social stability.
Chinese regulators have introduced specific registration requirements for algorithms that influence public opinion or social mobilization, mandatory safety assessment for generative AI systems before public launch, and clear guidelines on content such systems must not generate. This approach, while restrictive regarding political and social content, is simultaneously highly supportive of commercial and industrial AI development, with massive state investment in research, data center infrastructure, and workforce education.
This seemingly contradictory combination — strict content control alongside aggressive support for technological development — reflects the fundamental logic of Chinese industrial policy that treats artificial intelligence as a strategic resource comparable to energy or military infrastructure, where state coordination is not an obstacle but a prerequisite for achieving global competitiveness. Restrictions on access to advanced semiconductor chips imposed by the United States have further reinforced this pattern, pushing China toward even more intensive state investment in domestic chip manufacturing capacity and alternative model architecture approaches requiring less computational power.
The practical consequence of these three parallel, mutually incompatible regulatory philosophies is that multinational companies wanting to operate globally must build compliance systems that simultaneously satisfy European documentation and risk-assessment requirements, the American network of sectoral and state regulations, and Chinese requirements for algorithm registration and content control. This fragmentation creates significant operational burden, particularly for smaller companies lacking the resources of large technology conglomerates to maintain separate legal teams per jurisdiction.
One of the most contentious issues arising from this fragmentation is the question of cross-border data flow for model training. European data protection requirements, Chinese restrictions on exporting certain data categories, and relatively liberal American policy create a situation where companies must make difficult decisions about where they train their models, what data they have access to in individual jurisdictions, and how to ensure a model trained in one jurisdiction meets the requirements of another when deployed there.
A second area of friction concerns open models — systems whose weights are publicly available for download and modification. European and American regulators have taken partially different positions on whether open models should be subject to the same requirements as closed commercial systems, while the Chinese approach actively encourages open models as a strategy for reducing dependence on Western technology, with several leading Chinese labs having released competitive open models precisely as part of a broader technological independence strategy.
For countries and regions not among the three major regulatory centers, this race creates a complex set of decisions about their own strategy. Most smaller economies lack the capacity or market size to develop their own independent regulatory framework comparable to any of the three major models, effectively forcing them to position themselves relative to one of the existing approaches or attempt to build a hybrid model tailored to their own priorities.
European neighboring countries and countries aspiring to EU membership naturally lean toward aligning with the European regulatory model, partly due to existing institutional ties and partly due to a desire for access to the European market requiring compliance. Countries with close economic and security ties to the United States often follow a more flexible, sectoral approach, while countries within the broader Chinese economic sphere of influence increasingly consider elements of the Chinese state-coordination model, particularly in the context of developing economies where state-led industrial policy has a longer tradition.
This dynamic creates the risk of forming several relatively isolated regulatory blocs that complicate global interoperability of AI systems, similar to what happened with some aspects of the internet in the context of censorship and content control. While full fragmentation remains an unlikely scenario due to economic incentives to maintain global connectivity, the trend toward regional regulatory blocs with significant differences in fundamental philosophy seems increasingly likely.
Alongside regulation of AI applications, all three jurisdictions face a separate but related question: how to regulate the development of increasingly advanced foundation models whose potential capabilities exceed current applications and introduce new categories of risk, from misuse in developing biological or chemical weapons to the broader question of losing human control over increasingly autonomous systems.
This issue creates an unusual situation where leading AI labs, mostly based in the United States, actively call for stricter regulation of their own industry, arguing that the risks of the most advanced systems are serious enough to warrant preventive rather than merely reactive regulation. This call for regulation from below, from the industry itself, represents an unusual pattern in the history of technology regulation, where industrial actors have typically lobbied against, not for, strict regulatory requirements.
Skepticism toward these calls partly stems from suspicion that large, well-capitalized labs advocate for regulation precisely because the regulatory burden disproportionately affects smaller competitors and new market entrants, effectively acting as a barrier to entry that protects existing leading players from future competition. This dynamic, known as "regulatory capture" in reverse, complicates simple narratives about the motives behind calls for stricter regulation.
The financial sector offers a particularly instructive example of how the three regulatory philosophies collide in practice, as banks and insurers have operated for decades under dense sectoral regulation that must now align with new, horizontal AI requirements. A European bank using a machine-learning model for credit-risk assessment must simultaneously satisfy existing banking-regulation transparency requirements for credit decisions, new AI Act requirements for high-risk systems involving individual creditworthiness assessment, and data-protection requirements limiting which variables the model may use.
This overlapping regulation creates significant compliance cost, but also opportunity — banks that manage to build compliance systems meeting the strictest requirements can use those same systems as a competitive advantage when entering markets with less strict requirements, instead of building separate, less robust systems for each market. This dynamic partly explains why some large global financial institutions actively lobby for stricter, not weaker, AI regulation — once they've built expensive compliance infrastructure, that infrastructure becomes a barrier to entry protecting their market position from less capitalized competitors.
American financial institutions, on the other hand, face a considerably more fragmented regulatory landscape, where federal banking regulators, securities regulators, and individual state regulators each have partially overlapping but not identical jurisdiction over AI applications in financial services. This fragmentation, while theoretically creating more room for innovation, in practice often results in legal uncertainty that pushes institutions toward more conservative AI applications than they might otherwise choose, simply to avoid the risk of subsequent regulatory dispute with any of the overlapping regulators.
One of the most complex legal questions all three jurisdictions are trying to resolve, each in its own way, is the question of liability when an autonomous or semi-autonomous AI system makes a decision causing harm. Traditional product-liability and negligence legal frameworks were developed for a context where a human decision or clearly defined manufacturing defect is the cause of harm — a context that doesn't map simply onto a scenario where an AI model, trained on millions of examples, makes a decision no individual programmer explicitly programmed or could have anticipated in advance.
The European approach tries to address this through a combination of the AI Act, which imposes documentation and transparency requirements easing subsequent liability investigation, and separate AI liability directive proposals that would ease victims' burden of proving causation between an AI system and harm suffered. This approach recognizes that the traditional standard of proof, requiring a victim to prove exactly how a product was defective, becomes nearly impossible to meet when the "product" is a complex machine-learning model whose internal decision-making even its own creators cannot fully explain.
The American approach, relying mostly on existing negligence and product-liability doctrines developed through case law, leaves much more room for courts to gradually, through individual cases, develop standards applicable to AI harm. This approach offers flexibility to adapt to each case's specific circumstances, but also creates significant legal uncertainty for companies unable to know in advance how a court will interpret their liability before actual harm and litigation occur.
Discussion of AI regulation often neglects the fundamental physical resource all three regulatory models depend on in practice — access to advanced computing chips and the energy needed to train and run the largest models. Regulation that looks great on paper becomes irrelevant if the country adopting it lacks domestic capacity to develop its own advanced models, making it dependent on models developed elsewhere that its regulation cannot directly shape during the training phase.
This dynamic partly explains why American export restrictions on advanced semiconductor chips to China have become as significant an element of global AI policy as formal application regulation — control over foundational infrastructure enables indirect influence extending beyond formal regulatory jurisdiction. Countries lacking domestic chip-manufacturing capacity or access to cheap energy at scale face a structural limitation on their ability to pursue an independent AI strategy, regardless of the quality of their regulatory framework on paper.
The question of how to regulate open models — systems whose weights are publicly released and available for download, modification, and redistribution by anyone — deserves special attention because it doesn't fit simply into traditional regulatory logic aimed at individual product manufacturers retaining control over their product after launch. Once a model's weights are publicly released, the original developer loses practical ability to control how that model is used, by whom, or to prevent removal of safety constraints originally built in.
This reality creates a fundamental tension between two valuable public goods — the transparency and democratization of AI access that open models enable, versus the risk that same open access enables malicious actors to remove safety constraints and apply models for harmful purposes that closed, controlled access could prevent. European regulators generally take a more cautious stance toward the most advanced open models, while Chinese strategy actively encourages open models as a tool of technological independence, and the American approach remains divided within the industry itself, with some leading labs advocating openness and others considering it unjustifiably risky for the most advanced systems.
Looking ahead, several broad scenarios seem plausible for how this regulatory race develops over the next decade. The first scenario, partial convergence, assumes practical pressures of multinational business will gradually push all three models toward partially more similar, interoperable requirements, at least regarding basic technical documentation and testing standards, even if underlying philosophies remain different. This scenario resembles what happened with global accounting standards, where significant national differences remain but basic technical infrastructure becomes increasingly interoperable.
The second scenario, deepening fragmentation, assumes rising geopolitical tensions, particularly between the United States and China, will push all three blocs toward increasingly different, less interoperable systems, with technological "walls" separating not just regulation but foundational infrastructure, data, and talent between blocs. This scenario resembles what has partly already happened with access to certain internet platforms and services between China and the Western world.
The third scenario, which many analysts consider most likely, assumes lasting but manageable fragmentation in which companies and countries develop increasingly sophisticated strategies for navigating three parallel systems, similar to how multinational companies have for decades navigated different tax, labor, and regulatory systems without full global harmonization. This scenario doesn't resolve the underlying fragmentation but makes it a manageable operational cost rather than an existential challenge for global business.
Regardless of which scenario materializes, one thing remains certain — the pace at which AI technology itself develops means the regulatory frameworks of all three major players will require continuous revision and adaptation, making this area one of the most dynamic in global economic and legal policy over coming years.
For organizations facing the task of navigating this fragmented regulatory reality, several practical principles emerge from early compliance adopters' experience so far. First, build a modular, not monolithic, AI risk-governance architecture allowing addition or adaptation of market-specific requirements without needing to redesign the entire compliance system from scratch. Second, invest in model documentation and explainability well before it becomes formally mandatory in a given jurisdiction, as documentation created after the fact, under regulatory-deadline pressure, is systematically lower quality than documentation built as an integral part of the development process from the start.
Third, actively monitor regulatory developments across all three major jurisdictions, not just the one where the organization is formally headquartered, as one jurisdiction's regulatory requirements increasingly spill over into practical business decisions affecting global operations, regardless of where a product is originally intended for sale.
While discussion of AI regulation often reduces to a three-way dynamic among governments, large technology companies, and occasionally military and security agencies, civil society and academia have played a more significant role in shaping the regulatory landscape than usually credited. Digital-rights organizations, academic researchers specializing in algorithmic bias and legal accountability, and journalists investigating the real-world consequences of AI systems on vulnerable groups have contributed to documenting concrete harms that shaped the final text of the European AI Act considerably more than might be assumed from the formal legislative process alone.
This dynamic is particularly pronounced in recognizing specific high-risk applications within the AI Act — categories like automated resume screening in hiring or algorithmic determination of social benefits didn't appear in the legislative text spontaneously, but as a direct response to documented cases of real harm identified by researchers and journalists before regulators had even begun considering that specific application. This dynamic suggests future regulatory development, across all three jurisdictions, is likely to continue reacting to documented cases of real harm as much as, if not more than, abstract theoretical risk discussions.
A concrete insight into how seriously the EU takes its regulatory framework comes from the very structure of penalties prescribed in Article 99 of the AI Act. For the most serious violations — prohibited AI practices like manipulative techniques exploiting vulnerabilities or real-time biometric surveillance in public spaces — the fine can reach €35 million or 7% of a company's global annual turnover, whichever is higher. For comparison, this is nearly double the percentage of the maximum GDPR fine of 4% of turnover, making the AI Act one of the strictest regulatory frameworks in EU history by absolute financial exposure.
A second penalty tier, up to €15 million or 3% of turnover, covers violations related to high-risk systems and transparency, while a third tier, up to €7.5 million or 1% of turnover, covers providing incorrect or misleading information to supervisory authorities. An interesting detail that often escapes attention is that an inverted logic applies for small and medium enterprises and startups — instead of the higher amount (fixed or percentage of turnover, whichever is greater), the lower amount applies, providing real, statutorily mandated protection for smaller players against disproportionately harsh penalties that could threaten their survival.
According to mid-2026 reports, despite prohibited practices being formally enforceable since February 2025, no public fine has yet been issued under the AI Act as of June 2026 — the European Commission has launched initial investigations, but has chosen an approach prioritizing cooperation and guidance before strict enforcement, similar to the pattern it applied during GDPR's early years. Experts warn the EU, just as with GDPR, might select a few high-profile cases to set a precedent — a possible target includes AI systems in the human resources sector or generative AI services insufficiently transparent about their nature.
The race to shape global artificial intelligence norms is unlikely to result in one winning model achieving global dominance, as happened with some earlier technology standards. Instead, the more likely scenario is lasting coexistence of three, or more, parallel regulatory philosophies, with companies and countries having to navigate an increasingly complex web of requirements depending on which markets they want to operate in.
Each of the three major approaches carries clear trade-offs. The European model offers clarity and predictability of the legal framework at the cost of potentially slower innovation and the risk of becoming less relevant if technology develops faster than the regulatory framework can track. The American model offers speed and flexibility at the cost of fragmentation and gaps in citizen protection. The Chinese model offers coherent state coordination toward strategic goals at the cost of limited autonomy for individuals and companies within that system.
For organizations operating globally, the practical conclusion is not to wait for this race to resolve toward one dominant model, but to build a flexible, modular compliance architecture that can adapt to different regulatory requirements per market, with continuous monitoring of how all three models evolve in coming years. Given the pace at which the technology itself is developing, it's likely that the regulatory frameworks of all three major players will change significantly over the next decade, making this race a dynamic, continuous process rather than a one-time competition with a clear endpoint.
#AIGovernance #AIRegulation #EUAIAct #Geopolitics #NerminSefic #GNKASG #GNKDINAMOLtd #Economics #GlobalMarkets #Innovation #Leadership #BusinessStrategy #RiskManagement
Cjelovit tekst i izvor: https://gnk-asg.hr/en/publications/ai-governance-race-us-eu-china/
Autor i urednička odgovornost: Nermin Sefić. Izdavač: GNK ASG d.o.o..
#GNKASG #GNKDINAMOLtd #NerminSefic #BusinessIntelligence #AIgovernance #AIregulation #EUAIAct #UnitedStatesAIpolicy #ChinaAIregulation #NerminSefić