Commentary. Artificial intelligence regulation has entered the phase in which governments must prove that rules can protect people without suffocating useful innovation. The central question is no longer whether AI needs oversight. It is whether oversight will be clear, enforceable and adaptable enough to matter.

The European Union, the United States and China are now pursuing notably different models. The EU has built a binding, risk-based framework; the US has leaned more heavily on voluntary commitments and executive action; China is combining regulation with close state control. A recent comparison by Euronews captures the broad divide.

Our view is straightforward: democratic governments should favor enforceable rules, but resist the temptation to regulate every hypothetical danger with a new layer of bureaucracy. The right goal is not maximal regulation. It is credible accountability.

The case for firm rules

Voluntary promises can be useful when companies are acting in good faith and risks are limited. They are a weak foundation, however, when the incentives point in the opposite direction. Companies competing to release larger and more capable systems may not be reliable judges of the social costs created by those systems. Nor should affected citizens have to negotiate privately with technology firms over basic protections.

Binding obligations can establish a common floor for safety, transparency and redress. The EU’s AI Act uses a tiered approach, with requirements increasing according to the perceived risk of an application. The framework bans some practices and imposes additional obligations on systems used in sensitive contexts. Legal analysis from Simmons & Simmons says the Act’s transparency obligations became enforceable in August 2026, with limited transition arrangements for some systems.

That approach has a virtue often missing from the AI debate: it gives the public a standard against which institutions can be judged. A rule that requires disclosure, testing or human oversight is imperfect, but it is more meaningful than a promise that expires when market pressure rises.

The costs are real

The counterargument deserves more than a dismissive response. Compliance can be expensive, especially for smaller companies that lack large legal and technical teams. Poorly drafted rules can also freeze assumptions about a rapidly changing technology. If regulation makes experimentation prohibitively costly, innovation may concentrate further in the biggest firms—the very outcome many policymakers say they want to avoid.

Industry pressure has already contributed to efforts to simplify parts of the European rulebook. The Simmons & Simmons review describes a 2026 AI Omnibus that streamlines some requirements, expands testing opportunities and seeks greater consistency with other EU legislation. That adjustment is not necessarily evidence of regulatory failure. It may show that durable rules must be revised when their practical effects become clearer.

The United States offers a different warning. According to the Center for Democracy & Technology, federal lawmakers had not passed comprehensive AI legislation in the 2026 session, while states continued to pursue measures covering automated decisions, public-sector use, chatbots and AI companions. State experimentation can reveal what works. But a patchwork of obligations can also leave people with different protections depending on where they live and force responsible companies to navigate conflicting requirements.

What enforcement should mean

Regulation should begin with the harms that are easiest to identify and hardest to excuse: discrimination in employment, housing and finance; deceptive or undisclosed synthetic media; unsafe deployment in high-stakes services; and the collection or exploitation of sensitive personal information. These areas do not require governments to predict the future of AI. They require governments to apply familiar principles to new tools.

Enforcement should also be proportionate. Regulators need technical expertise, independent auditing capacity and enough resources to investigate violations. Companies should have clear duties, but they should not be held liable for impossible guarantees about every output from a general-purpose system. Accountability works best when responsibility follows control: deployers should answer for how they use a system, while developers should answer for the risks they can reasonably detect and mitigate.

China’s tightly controlled model may produce faster state action, but democratic societies should not copy its concentration of authority. Nor should the United States mistake light-touch governance for neutrality. Inaction is itself a policy choice, one that often shifts risk onto workers, consumers and communities with the least bargaining power.

AI policy will not be judged by the elegance of its slogans. It will be judged by whether a person harmed by an automated decision can understand what happened, challenge it and obtain a remedy. That is the standard democratic governments should pursue—and the standard against which every new promise should be measured.

Sources