Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
Enter your email address below and subscribe to our newsletter

This article contains affiliate links. We may earn a commission at no extra cost to you. Full disclosure.
As of March 2024, over 60 countries have introduced some form of AI regulation, but only three — the European Union, China, and the United States — have frameworks that meaningfully shape global development. The rest are either copying, waiting, or experimenting, creating a fragmented landscape where compliance costs can vary by a factor of ten. This scorecard examines how 20 countries are approaching AI governance, based on official legislation, regulatory proposals, and enforcement actions through Q1 2024. The finding is stark: no two frameworks agree on what constitutes “risk,” and the divergence reflects deeper political philosophies — from China's centralised state control to the EU's risk-based tiering to the US's sectoral patchwork. I separate what the laws actually require from what their proponents claim, drawing on legal texts, parliamentary records, and enforcement data. The result is a practical guide for anyone building or deploying AI across borders.
The European Union’s Artificial Intelligence Act, passed on 13 March 2024, is the most ambitious regulatory effort to date. It classifies AI systems into four risk categories: unacceptable, high, limited, and minimal. Unacceptable-risk systems (e.g., social scoring by governments, real-time biometric surveillance in public spaces) are banned outright. High-risk systems — those used in critical infrastructure, employment, credit scoring, and law enforcement — must undergo conformity assessments, maintain human oversight, and meet transparency requirements. The Act imposes fines up to €35 million or 7% of a company’s annual global turnover, whichever is higher. That’s roughly €1.2 billion for a company like Meta, based on 2023 revenue.
The Act also introduces rules for general-purpose AI models, a last-minute addition after the rise of ChatGPT. Models trained with more than 10²⁵ FLOPs of compute — a threshold that captures GPT-4 (estimated 2.4×10²⁵ FLOPs) and Google’s Gemini Ultra — are presumed to pose systemic risk and must undergo independent audits. Smaller models are exempt, creating a regulatory gap for open-source models like Llama 3 (trained on ~3×10²⁴ FLOPs). Critics argue the compute threshold is arbitrary and will become obsolete as hardware improves. The European Commission plans to review the threshold every two years. Enforcement begins in stages: bans on unacceptable risk take effect in November 2024; rules for general-purpose models apply from August 2025; and full compliance is required by mid-2026.
China has enacted the most specific and fastest-moving AI regulations, driven by the Cyberspace Administration of China (CAC). The Algorithm Recommendation Rules (effective March 2022) require platforms to register algorithms that influence user behaviour, especially those with over 100 million users. The Deep Synthesis Provisions (January 2023) target generative AI and deepfakes, mandating that all synthetic content be watermarked and that models undergo a security assessment before release. The Interim Measures for Generative AI (August 2023) go further: developers must ensure training data does not violate Chinese law, and generated content must “reflect the core values of socialism.” In practice, this has forced companies like Baidu (Ernie Bot) and Alibaba (Tongyi Qianwen) to filter political topics and restrict certain outputs.
Top-rated VPN for online privacy and security. Lightning-fast servers.
Affiliate link
China’s approach is enforcement-heavy. As of February 2024, the CAC had fined 23 companies for non-compliance, with penalties ranging from ¥100,000 to ¥10 million (roughly $14,000 to $1.4 million). The model registration requirement is unique: any generative AI model offered to the public must be registered with the CAC, and the registration includes details on training data sources, compute usage (in petaflop-days), and bias mitigation steps. This gives the government granular oversight but also creates a walled garden where foreign models like GPT-4 are effectively banned unless they partner with a local entity. The US-China trade war has accelerated this: in October 2023, the US restricted exports of Nvidia H100 chips to China, forcing Chinese companies to rely on domestic alternatives like Huawei’s Ascend 910B, which delivers roughly 60% of the H100’s performance in training benchmarks.
The US lacks a single AI law, relying instead on sector-specific regulations and executive orders. The most significant development is President Biden’s Executive Order on Safe, Secure, and Trustworthy Development of AI (30 October 2023). It directs over 100 federal agencies to take 270 specific actions, including requiring developers of “dual-use foundation models” — defined as those trained on >10²⁶ FLOPs or with >10 billion parameters — to report safety test results to the government. This threshold captures GPT-4 and Gemini Ultra but excludes most open models. The order also creates the AI Safety Institute within NIST, tasked with developing testing standards. However, the order is not permanent law; a future administration could rescind it.
At the state level, California is leading with proposed legislation like SB 1047, which would require safety testing for AI models costing more than $100 million to train. New York’s Local Law 144 regulates AI in hiring, requiring bias audits for automated employment decision tools. The patchwork creates compliance headaches: a company deploying AI in healthcare must follow FDA guidance, while the same model used in hiring must comply with EEOC rules and potentially multiple state laws. The US approach prioritises innovation over precaution, but the lack of a unified framework leaves gaps — for instance, there is no federal ban on real-time facial recognition in public spaces, unlike the EU. The total cost of compliance for a mid-sized AI company operating across 10 states is estimated at $2-5 million annually, according to a February 2024 report by the Center for Data Innovation.
The UK has positioned itself as a middle ground between the EU’s strict regulation and the US’s light touch. The government’s white paper “A Pro-Innovation Approach to AI Regulation” (March 2023) eschews a central AI law in favour of guidance to existing regulators — the Information Commissioner’s Office, Competition and Markets Authority, and others. The approach is principles-based: safety, transparency, fairness, accountability, and contestability. Regulators are expected to issue sector-specific guidance by mid-2024. The UK also hosted the first AI Safety Summit in November 2023, resulting in the Bletchley Declaration signed by 28 countries, including China and the US. The summit led to the creation of the AI Safety Institute, which received £100 million in initial funding and has already tested models from OpenAI, Anthropic, and Google.
In practice, the UK’s approach is lighter than the EU’s but more coordinated than the US’s. The AI Safety Institute published its first evaluation framework in February 2024, focusing on six categories: cyber capability, persuasion, autonomy, deception, proliferation, and system integrity. It uses a tiered scoring system from “minimal” to “critical.” For example, GPT-4 was rated “high” in persuasion and “medium” in cyber capability. The UK has also introduced a voluntary code of practice for developers, but no mandatory registration. Critics argue the lack of enforcement teeth means companies can self-certify without consequence. The government plans to introduce a statutory instrument by the end of 2024 if voluntary measures prove insufficient.
Japan takes a hands-off approach, focusing on economic growth. The government’s “AI Strategy 2023” emphasises investment and R&D, with a budget of ¥100 billion ($670 million) for AI infrastructure. There is no specific AI law; instead, existing privacy and consumer protection laws apply. Japan has also proposed “soft law” guidelines for generative AI, but they are non-binding. South Korea, by contrast, passed the “Act on the Promotion of AI Industry and Framework for Establishing Trustworthy AI” in December 2023. It mirrors the EU’s risk-based categories but with lower fines (up to 3% of revenue) and a shorter implementation timeline: full effect by January 2025. South Korea also launched a national AI computing centre with 3,000 GPUs (Nvidia H100s) to support domestic startups.
Singapore’s Model AI Governance Framework, first published in 2019 and updated in 2024, is voluntary but widely adopted. It provides a checklist for organisations covering accountability, transparency, and fairness. The Infocomm Media Development Authority also launched an AI Verify testing toolkit in 2023, which allows companies to self-assess their models against 11 principles. Over 50 companies, including Google and Microsoft, have piloted the toolkit. India has no specific AI regulation yet. The NITI Aayog released a set of principles in 2021, but the government has prioritised AI adoption over restriction. In 2023, India’s Ministry of Electronics and IT issued an advisory requiring “explicit permission” from the government before deploying “unreliable” AI models, but it was withdrawn after industry backlash. India’s approach is expected to coalesce around a Digital India Act, proposed in 2023, which includes a chapter on AI accountability.
Brazil is the most advanced in Latin America. Bill 2338/2023, currently in the Senate, proposes a regulatory framework similar to the EU’s but with adaptations for local context. It includes a 10% fine on revenue for violations (capped at R$50 million, about $10 million) and requires risk assessments for high-risk AI. The bill also mandates that AI systems used in public services must be audited for bias against marginalised groups. Nigeria has no AI law, but the National Information Technology Development Agency released a draft National AI Policy in January 2024, focusing on ethical guidelines and a voluntary registration scheme. Indonesia’s Personal Data Protection Law (September 2022) indirectly covers AI, but a dedicated AI regulation is expected in 2025. The country hosts the ASEAN AI Governance Framework, which sets non-binding principles for the region.
South Africa’s Information Regulator has issued guidance under the Protection of Personal Information Act, classifying automated decision-making as a “special” processing activity requiring consent. Kenya has no framework but is a signatory to the African Union’s Continental AI Strategy, which calls for a harmonised approach by 2027. The EU’s influence is strong: 12 of the 20 countries examined have modelled their proposals on the EU AI Act, including Brazil, Chile, and Thailand. However, enforcement capacity varies wildly. Brazil’s proposed regulator, the National Data Protection Authority, has only 300 staff for a population of 214 million. In contrast, China’s CAC has over 10,000 employees. The gap matters: a law without enforcement is a suggestion.
The OECD’s AI Principles, adopted in 2019 and updated in 2023, provide the most widely referenced baseline. They cover five values: inclusive growth, human-centred values, transparency, robustness, and accountability. 47 countries have endorsed them. The Global Partnership on AI (GPAI), launched in 2020 by 29 countries, funds research projects and publishes best-practice guides. Its 2023 report on foundation models recommended mandatory reporting for models trained on >10²⁵ FLOPs — the same threshold the EU adopted. The United Nations has also entered the fray: in March 2024, the UN General Assembly passed a resolution on “safe, secure, and trustworthy AI systems,” co-sponsored by 123 countries. It is non-binding but sets a global norm for human rights compliance.
However, coordination is fragile. The EU’s extraterritorial reach — the AI Act applies to any provider whose output is used in the EU — has sparked pushback from the US and China. The US has argued that the Act’s compliance costs could disadvantage American companies, while China views it as a form of tech colonialism. The OECD is working on a mutual recognition framework, but progress is slow. A key obstacle is the lack of agreement on what constitutes “risk.” For example, the EU bans social scoring; China mandates it for trustworthiness systems. The GPAI’s 2024 work plan includes a project to map risk categories across 20 countries, due by December 2024. Until then, companies operating globally must navigate a maze of conflicting rules.
The tools, tutorials, and trends that actually pay — no hype.
The tools, tutorials, and trends that actually pay — no hype.