The EU (9/10 risk), US (5/10), and Australia (6/10) take vastly different approaches to AI regulation. Build for EU standards globally—the Brussels Effect means you'll need them anyway.
The EU started enforcing its AI Act's prohibited practices rules on February 2nd. Social scoring systems, manipulative AI, certain biometric surveillance. All now banned in Europe.
Meanwhile, the US still has no federal AI law. California has CCPA. Virginia has CDPA. Colorado has its own rules. It's a patchwork.
And Australia? We're watching both approaches play out before committing. The Productivity Commission explicitly recommended against rushing into EU-style comprehensive regulation.
5-10 minute read | Best for: CISOs, CTOs, Compliance Officers, AI Implementation teams
I've been tracking these three regulatory models at raxIT, where we build AI governance infrastructure. The divergence is more dramatic than most people realize.
Here's the paradox: The EU's approach (I'd rate it 9/10 regulatory risk) gives you clarity but kills agility. The US (5/10 risk) offers flexibility but delivers chaos. Australia (6/10 and rising) tries to balance both but creates uncertainty.
If you're building AI agents that operate across borders, you can't pick one model. You need architecture that works with all three.
The EU's philosophy is simple: prove your AI is safe before you deploy it.
GDPR set the template. The AI Act follows the same pattern. Broad principles. Extraterritorial reach. Serious penalties.
The fines are real:
That 7% number caught my attention. It's almost double the GDPR penalty.
Columbia Law professor Anu Bradford coined the term "Brussels Effect" to describe what happens next: when the world's largest regulatory market sets strict standards, global companies adopt those standards everywhere. It's cheaper than maintaining separate compliance programs.
A study on GDPR's effects found something the EU probably didn't intend:
The regulation ended up entrenching large players (who can absorb compliance costs) while creating higher barriers to entry for startups.
The AI Act will likely do the same. If you're a startup trying to compete with established players, EU compliance costs become a significant barrier.
But here's the trade-off: the rules are clear. If you can prove your AI decisions are auditable, attributable, and documented, you can operate. The challenge is building that proof into your architecture from day one.
But here's what I didn't expect: less than a year into enforcement, the EU is already proposing to soften its landmark AI law.
On November 19, 2025, the Commission unveiled its Digital Omnibus Package. "Innovation-friendly AI rules" to "reduce compliance costs." Translation: Mario Draghi's competitiveness report spooked them. European competitiveness is lagging, and they're pointing fingers at their own regulations.
The proposed changes are significant:
The AI Office would also become the exclusive regulator for ChatGPT, Gemini, Claude, and Copilot, centralizing enforcement rather than having 27 different member state authorities.
Important caveat: this is just the Commission's proposal. It still needs Parliament and Council approval. The same trilogue process that created the AI Act will now debate weakening it.
But the signal is clear: even the EU is having second thoughts about the compliance burden it created.
America's approach couldn't be more different.
There's no federal AI law. No federal privacy law equivalent to GDPR. Instead, you get HIPAA for healthcare, Sarbanes-Oxley for financial reporting, and a growing maze of state laws.
But here's where it gets interesting: the federal government keeps trying to kill state AI laws and keeps failing.
In July 2025, the Trump administration proposed a 10-year moratorium on state AI law enforcement. The Senate rejected it 99 to 1. Not a typo. 99 to 1. A bipartisan letter from 260 state lawmakers called states "laboratories of democracy" that need flexibility to respond to digital concerns.
Undeterred, Trump issued a new Executive Order on December 11, 2025 trying again via litigation and funding pressure:
Colorado's AI law (effective June 2026) got singled out by name.
The problem? Executive orders can't actually preempt state laws. That requires legislation. And the Senate just told them no.
Meanwhile, states keep legislating. 131 AI laws passed between 2016-2024. Over 700 AI bills were proposed in 2024 alone. California, Colorado, Maryland, Utah, Virginia. They're not waiting for federal permission.
Here's the irony: companies operating across US states face a patchwork that can actually exceed the compliance burden of the EU's single comprehensive framework. California alone has different rules than Virginia, which differs from Colorado.
I've talked to companies that find the US more complex than the EU because at least the EU is consistent.
We explicitly rejected both extremes.
The government floated an EU-style AI Act with "mandatory guardrails." After consultations, we shifted to an incremental approach: strengthen existing laws, watch what happens elsewhere, only add new regulations when gaps become clear.
Here's the key insight from the National AI Plan: it's not one law. It's a bunch of them being updated in parallel:
And a new AI Safety Institute to identify gaps between current law and reality.
Fines now reach AU$50 million. That's not nothing.
The strategy is clear: no standalone AI Act, but the cumulative effect of updating existing frameworks may rival the EU's approach. We're building the plane while flying it.
The EU path is the most demanding upfront. You can't deploy until you've completed risk assessment and documentation. The US looks easier initially but the ex-post enforcement can be harsh. Australia gives you the most runway but you're building for moving targets.
EU: 9/10: Expensive but predictable. GDPR fines reach hundreds of millions. The AI Act threatens 7% of global revenue. You must prove ongoing compliance, not just pass audits.
US: 5/10: No baseline, 50 state variations, lower upfront penalties but harsh ex-post liability. The irony: most US firms end up implementing EU-style measures anyway to operate internationally—the Brussels Effect in action.
Australia: 6/10: Currently lenient, guidance before penalties, but AU$50M fines are now possible. Trajectory clearly toward tightening.
The EU AI Act phases in over two years:
Most autonomous AI agents will likely classify as "high-risk." That gives you about 8 months to get compliant.
Here's something I didn't fully appreciate until I started tracking this: the EU doesn't just regulate Europe. It effectively sets global standards.
How the Brussels Effect shapes global AI regulation
Bradford's research documents the mechanism:
GDPR sparked privacy legislation worldwide. California's CCPA, Brazil's LGPD, dozens of other national laws borrowed GDPR's concepts. The AI Act will likely do the same.
This means: even if you're a US company with no European customers today, you're probably going to need EU-level compliance eventually. Might as well build for it now.
Here's where it gets interesting. Even the EU AI Act, comprehensive as it is, wasn't really designed for autonomous agents.
Traditional identity systems assume stable, human-controlled principals. Agents break that assumption in several ways:
Identity fragmentation: An agent might be provisioned in the US, trained with EU data, and operate in Australia. Which jurisdiction's identity framework applies?
Recursive delegation: An agent authorized to access financial data spawns a specialized sub-agent to analyze it. GDPR requires knowing who processed data and why. For agent chains, this becomes exponentially complex.
Dynamic lifecycles: Agents spawn, operate briefly, and terminate. At scale, you might create and destroy thousands of identities per hour. No current regulation addresses this.
Computer-using agents: The new breed of agents (Claude, Operator) that control browsers and desktop interfaces bypass most existing authorization frameworks entirely. Regulations like GDPR and HIPAA assume systems interact through defined APIs.
These gaps create practical problems:
If you're building AI agents that operate across borders, build for EU standards globally. The Brussels Effect means you'll need them anyway: comprehensive audit trails, risk classification, documentation generation. Architect these into your platform from day one.
For US markets, add state-by-state configuration since California differs from Virginia differs from Colorado. Make compliance modular so you can enable or disable requirements per jurisdiction.
For Australia, engage in consultation processes while you still can. We're still shaping the rules. Assume Privacy Act requirements will move toward GDPR levels.
The smart approach: unified audit infrastructure that satisfies the EU's strict requirements. It'll work everywhere else too.
The regulatory divide isn't closing. If anything, it's widening. The EU is proposing to soften while the US fights its own states.
But the practical answer is the same regardless: build audit infrastructure that proves who your agents are, what they're authorized to do, and what decisions they made. That's what every jurisdiction will eventually require. The EU just got there first.
If you want to track these changes, Oliver Patel's Enterprise AI Governance newsletter is excellent. For the EU specifically, keep an eye on the Digital Omnibus trilogue. If Parliament and Council approve the amendments, timelines shift significantly.
The regulatory landscape described in this article isn't static. The EU proposed softening its AI Act less than a year after enforcement began. The US federal-state battle keeps shifting. Australia's incremental approach means rules emerge piecemeal. Keeping track of what actually applies to your AI systems is a moving target.
That's what we're building at raxIT: we track regulatory changes across jurisdictions so you can focus on building. When the Draghi competitiveness report dropped, we flagged it as an early signal that EU enforcement timelines might shift - months before the Digital Omnibus Package confirmed it.
What we actually do:
It's a work in progress. The regulations are evolving, and so are we. But our intent is simple: you shouldn't have to become a regulatory expert across three continents to deploy AI responsibly.
We're improving on the regulation side of things so you don't have to.
Building AI agents that need to operate globally? to discuss your specific deployment context and governance needs.