True North AI

Ethical intelligence, grounded in history, dignity, and moral clarity.

Public Education · September 27, 2026

Who Regulates AI? A Simple Guide to a Complicated Landscape

Who Regulates AI? A Simple Guide to a Complicated Landscape

Introduction

If you want to understand how AI is governed in the United States, imagine a map of the London Underground being used to navigate Tokyo. That is roughly the situation today: the systems we most depend on are global, fast-moving, and increasingly powerful, while the rules that govern them are fragmented, slow-moving, and written for technologies that no longer exist.

This is not because regulators are lazy or corrupt (though individual cases exist). It is because AI governance is genuinely hard. It spans multiple levels of government, multiple sectors of the economy, and multiple definitions of what “AI” even means. This article is a map of that complicated landscape - not a legal treatise, but a practical guide for real people who want to know who, exactly, is responsible for keeping these systems in check.

The Three Major Models of AI Governance

Most AI governance around the world falls into one of three models, though many countries blend elements of all three:

Understanding which model a country follows tells you a great deal about what its rules can and cannot do.

The US Approach: Sector-Specific and Voluntary

The United States does not have a comprehensive AI law. Instead, it relies on:

The result is a patchwork that protects consumers unevenly depending on the sector and the state.

The EU AI Act: The World’s First Comprehensive AI Law

The European Union took a different approach: the AI Act, passed in 2024, is the world’s first comprehensive AI regulation. It classifies AI systems into risk tiers:

The Act applies to any company serving EU customers regardless of where it is headquartered - which is why it has become the de facto global standard, a phenomenon known as the “Brussels Effect.”

Global Bodies: Coordination Without Authority

UNESCO, the OECD, the Council of Europe, and the UN have all issued AI principles and recommendations. The G7 launched the Hiroshima Process. The UK hosted the first AI Safety Summit. These efforts matter because they build consensus and vocabulary - but none of them can enforce anything. They are soft power in a hard-power problem.

Key Frameworks: What Each Actually Does

NIST AI Risk Management Framework

The US National Institute of Standards and Technology released its AI Risk Management Framework (RMF) in January 2023. It is voluntary. It organizes AI governance into four functions:

Its strength is specificity; its weakness is that nobody has to follow it.

US Executive Orders

Executive Order 14110 (October 2023) was the most significant US action to date. It required:

Its vulnerability is structural: an executive order binds the executive branch and can be rescinded by the next president, which is exactly what happened in January 2025.

The EU AI Act

The Act entered into force in August 2024 with obligations phasing in through 2026-2027. It bans practices like emotion recognition in workplaces and schools, restricts facial recognition databases, and requires fundamental rights impact assessments for high-risk systems.

Why Regulation Lags Behind Innovation

The Pacing Problem

AI development cycles are measured in months. Legislative cycles are measured in years. By the time a law is passed, the technology it targets has already been replaced by something its drafters never imagined.

The Complexity Problem

AI systems are opaque even to their builders. Asking a legislature to write precise technical requirements for systems that evolve faster than committees can meet is asking for either vagueness (which lacks teeth) or specificity (which is obsolete on arrival).

The Political Problem

AI governance crosses traditional ideological lines in strange ways. It touches free speech, copyright, national security, labor, and civil rights simultaneously. Coalitions that form for one issue dissolve for the next.

The Role of Companies vs. Governments

Voluntary Commitments and Their Limits

The White House secured voluntary commitments from major AI companies in July 2023. Seven companies promised safety testing, watermarks, and vulnerability disclosure. These commitments matter as signals, but they have three structural limits:

Mandatory Standards and Enforcement

The pattern across history - auto safety, aviation, pharmaceuticals, food - is consistent: voluntary standards raised the floor somewhat, but binding rules with enforcement are what actually protected the public. The question for AI is not whether this pattern will repeat, but when and at what cost of waiting.

What “Responsible AI” Means in Policy Terms

In policy documents, “responsible AI” typically bundles:

The term is doing real work, but it is also in danger of becoming what “organic” was before standards defined it: a meaningful word stretched until it loses meaning.

Conclusion: Governance as a Living System

AI governance is not a single law to pass but a system to maintain - closer to environmental regulation or financial oversight than to a one-time product standard. The lesson from every mature governance domain is the same: start early, build capacity, expect iteration, and never mistake the absence of catastrophe for the presence of safety.