EU vs US AI regulation: federal, state and EU AI Act compared
The EU has one binding law applied across 27 Member States; the United States has federal policy that binds agencies, a voluntary NIST framework, and a growing set of state statutes. Colorado is included because it is the closest US analogue to the EU's high-risk approach.
| Category | European Union
Source-linked
| United States
Source-linked
| Colorado (United States)
Source-linked
|
|---|---|---|---|
| Regulatory status |
Binding regulation in force and partially applicable. Prohibited practices and AI-literacy duties apply since 2 February 2025; general-purpose AI model obligations and the governance and penalties chapters since 2 August 2025; most remaining obligations, including Annex III high-risk requirements, are scheduled from 2 August 2026, with high-risk AI embedded in Annex I regulated products from 2 August 2027. A Commission "Digital Omnibus" proposal published in November 2025 would adjust some high-risk application dates; its adoption status must be checked against the official sources linked below. |
Federal: executive-branch policy (Executive Order 14179 of January 2025 and the July 2025 AI Action Plan) plus binding OMB requirements for federal agencies' use and procurement of AI; NIST AI RMF is voluntary. States: a growing number of binding statutes with 2025–2026 effective dates. A reviewer must confirm the status of federal efforts to pre-empt or discourage state AI laws announced in late 2025. |
Adopted state statute; originally effective 1 February 2026, delayed to 30 June 2026 by SB 25B-004 (August 2025). Enforcement is by the Colorado Attorney General. A reviewer must confirm whether the 2026 regular session made further amendments before the effective date. |
| Binding AI legislation | |||
| High-risk AI rules |
19 binding, 0 voluntary
|
No high-risk tiering recorded. |
4 binding, 0 voluntary |
| Generative and general-purpose AI rules |
4 binding, 0 voluntary |
0 binding, 4 voluntary |
No generative-AI-specific obligations recorded. |
| Transparency obligations |
2 binding, 0 voluntary |
1 binding, 0 voluntary |
1 binding, 0 voluntary |
| Impact assessment |
1 binding, 0 voluntary |
0 binding, 1 voluntary |
1 binding, 0 voluntary |
| Data governance and personal data |
1 binding, 0 voluntary |
No data-governance obligations recorded. |
No data-governance obligations recorded. |
| Human oversight |
1 binding, 0 voluntary |
No human-oversight obligations recorded. |
No human-oversight obligations recorded. |
| Public-sector requirements |
Public-authority deployers must register high-risk AI use and assess fundamental-rights impact |
Federal acquisition of AI must follow OMB M-25-22 |
No public-sector-specific requirements recorded. |
| Key effective dates |
|
||
| Official sources |
Cells are generated from published records; a category showing "not recorded" means no source-backed entry exists yet, not that the jurisdiction has no rules. Scroll horizontally on small screens.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.