Scope and Enforcement Power Index
Comparison of legal bindingness and penalty severity in AI regulations among global actors.
Regulatory Approach Models
- Risk-Based (EU, Canada): Focuses on the risk created by the specific use case, not the technology itself.
- Sectoral/Distributed (US): Emphasizes existing agencies issuing guidelines in their respective fields rather than a single umbrella law.
- State & Content Control (China): Focuses on the ideological integrity of generated synthetic content and mandatory algorithm registration.
- Principle-Based (OECD, UNESCO): Non-legally binding ethical frameworks acting as a compass for national laws.
Critical Historical Milestones
A
Algorithmic Accountability Act (Draft)
United StatesDeep Analysis: This bill, which grants massive powers to the Federal Trade Commission (FTC) at the national level in the US, mandates companies to conduct an "Impact Assessment" for the decision-making algorithms they use. Particularly in areas directly affecting human lives such as recruitment, lending, housing, and education, it aims to transparently report whether the algorithm discriminates based on race, gender, or age.
In contrast to the general US reluctance towards regulation, this bill is the most concrete legal step focusing on how "black box" systems victimize consumers. If the bill becomes law, tech companies will be forced to explain to the FTC how their algorithms are trained.
Key Takeaways
- Focus: Consumer rights and Algorithmic Bias.
- Enforcement Power: Direct investigation and penalization authority to the FTC.
- Status: Draft stage in Congress (Has not become federal law, but inspired state laws).
Artificial Intelligence Act (EU AI Act)
European UnionDeep Analysis: The world's first comprehensive and legally binding horizontal artificial intelligence law. Adopted in June 2024 and entered into force in August 2024 (phased transition). The law categorizes AI into four tiers based on the "Risk it Creates" (Risk-Based Approach) rather than the technology itself: Unacceptable Risk, High Risk, Limited Risk, and Minimal Risk.
The law's greatest innovation is the "Brussels Effect"; meaning, if a US or Chinese company wants to sell a product in the European market, they must comply with these rules. While social scoring, subliminal manipulation, and unauthorized biometric categorization are strictly banned, transparency, copyright compliance, and systemic risk reporting obligations have been introduced for General Purpose AI (GPAI) and Large Language Models (LLMs).
Key Takeaways
- Penalty Architecture: Massive fines up to 7% of global turnover (or 35 Million Euros) in case of violation.
- Banned Systems: Predictive policing and social scoring are completely prohibited.
- GPAI Models: "Systemic risk" auditing for models like GPT-4.
Artificial Intelligence and Data Act (AIDA - Bill C-27)
CanadaDeep Analysis: AIDA, part of Canada's Bill C-27 draft law, relies on the logic of "Agile Regulation," diverging from the European model. Instead of detailing AI systems extensively, the law frames only "High-Impact" systems and leaves fine details to future regulations.
AIDA's most striking feature is the establishment of a brand new executive authority called the "AI and Data Commissioner." While aiming to provide guidance initially so as not to stifle innovation, the law differentiates itself by bringing malicious and harmful uses of AI directly under heavy criminal law (imprisonment).
Key Takeaways
- High-Impact AI: Focus on systems affecting human life.
- New Authority: AI Commissioner with broad auditing powers.
- Criminal Law: Personal prison sentences for knowingly dangerous data/model usage.
B
Bill No. 2338/2023 (Artificial Intelligence Law)
BrazilDeep Analysis: This draft, the boldest step by the Global South in technology regulation, blends the risk-based approach of the EU AI Act with Brazil's own case law. It contains very strong provisions, especially regarding the labor market, racial discrimination, and the right to appeal algorithmic decisions (Human in the Loop).
The most notable aspect of the Brazilian draft is its clear stance on copyrights. It proposes establishing new mechanisms for AI companies to pay royalties to content creators for copyrighted works used in Data Mining and AI training. It is one of the rare draft laws that directly adapts the Strict Liability principle to artificial intelligence.
Key Takeaways
- Legal Model: Strict liability principle (If there is damage, the company pays).
- Copyrights: Obligation for AI companies to pay authors.
- Human Agency: The right to demand a human review against any algorithmic decision.
Bletchley Declaration
Global (UK Led)Deep Analysis: Signed by 28 countries, including the US, China, EU, and Turkey, as a result of the summit held in November 2023 at Bletchley Park (UK), where Enigma codes were broken during WWII. Although not a legally binding law text, it is a global diplomatic turning point.
The declaration specifically focuses on the existential risks (bioterrorism, cyber warfare, nuclear information proliferation) posed by "Frontier AI" models. By getting geopolitical rivals like China and the US to sign the same text, it is the first global agreement officially recording that AI safety is a supra-political and transnational crisis.
Key Takeaways
- Nature: A non-binding but highly diplomatic declaration of goodwill.
- Focus: Existential risks arising from AGI (Artificial General Intelligence) rather than everyday AI risks (copyright/bias).
- Significance: One of the rare texts jointly signed by the US and China regarding technology.
Blueprint for an AI Bill of Rights
United StatesDeep Analysis: Published by the White House Office of Science and Technology Policy (OSTP), this document does not hold the status of law but forms the philosophical foundation of the American government's view on AI. It is built around five core principles: Safe and Effective Systems, Algorithmic Discrimination Protections, Data Privacy, Notice and Explanation, and Human Alternatives, Consideration, and Fallback.
The strongest legal doctrine in the document is the emphasis on the "Opt-Out" right and the citizen's right to demand to speak with a human instead of interacting with a bot (Human Fallback). It is used as a direct reference point in the American judiciary and the regulations of federal agencies.
Key Takeaways
- Fundamental Right: The right of people not to be victimized by machines.
- Human Alternative: The ability to reject AI in critical decisions and demand a human authority.
- Privacy: The principle that citizen data should be closed/protected by default.
C
Council of Europe Framework Convention on AI
Council of EuropeDeep Analysis: It is the "world's first legally binding international treaty" drafted on artificial intelligence. While the EU's AI Act is merely a market-oriented economic regulation, this convention by the Council of Europe is written directly from the perspective of Human Rights, Democracy, and the Rule of Law.
Opened for signature in September 2024, the convention obliges signatory states to enact national laws that prevent AI from violating the judicial system, democratic processes (election manipulations), and human rights. The biggest point of contention is that national security and defense industry applications are left directly outside the scope of the convention.
Key Takeaways
- Scope: Alignment with the European Convention on Human Rights (ECHR) rather than market dynamics.
- Bindingness: Legally binding in terms of international law for signatory countries.
- Non-Parties: Open not only to Europe but also to the participation of observer countries like the US and Israel.
E
Executive Order 14110 on Safe, Secure, and Trustworthy AI
United StatesDeep Analysis: Signed by US President Joe Biden in October 2023, this Executive Order (EO) commanded all American state agencies (Defense, Energy, Commerce, Health) to establish AI standards in an attempt to bypass Congress's sluggishness. It is the clearest indication that the US has adopted a sectoral and distributed AI management approach instead of a centralized law.
The most striking legal mechanism of the EO is its use of the Defense Production Act to compel tech companies training powerful AI models (OpenAI, Google) to share the results of national security risk tests (Red-Teaming) with the American government before releasing them to the market.
Key Takeaways
- Method: Distributed regulation. Each federal agency audits its own sector.
- Red-Teaming: Testing models to ensure they cannot be used in cyber and biological weapons production.
- National Security: Utilizing defense industry powers over commercial software companies.
G
Generative AI Services Management Interim Measures
People's Republic of ChinaDeep Analysis: Entering into force in August 2023, this regulation is one of the first legal texts in the world specifically regulating "Generative AI" technology. Enforced by the Cyberspace Administration of China (CAC), this law is built on "Content Control and Ideological Integrity," completely diverging from the West's risk-based approach.
Article 4 stipulates that generative AI must "adhere to core Socialist values" and not generate content aimed at subverting state power or disrupting national unity. Furthermore, it mandates AI providers to file their algorithms in the state's database and undergo security assessments. While granting flexibility for research purposes, it establishes a strict state censorship/surveillance infrastructure for public uses.
Key Takeaways
- Ideological Filtering: Obligation for LLM outputs to comply with state political doctrines.
- Filing Obligation: Registering algorithms in the state's central Algorithm Registry.
- Training Data: Proving to the state that the data used is "legitimate" and respects intellectual property.
I
Internet Info. Service Algorithmic Recommendation Provisions
People's Republic of ChinaDeep Analysis: A highly specific law (2021/2022) regulating not just AI models, but the "Recommendation Algorithms" forming the foundation of platforms like TikTok (Douyin) and Taobao. It is the state's direct intervention against algorithmic designs that exploit consumer attention and create addiction.
The law imposes an obligation on companies to offer users the right to "completely turn off the algorithmic recommendation system." It also explicitly bans algorithms from being programmed in a way that exploits platform workers (couriers, drivers) or endangers their physical health. Using algorithms for excessive pricing or anti-competitive (monopolistic) actions is subject to administrative sanctions.
Key Takeaways
- Right to Turn Off: Users can demand a chronological feed instead of an algorithm.
- Workers' Rights: Banning algorithms from imposing superhuman speeds on couriers.
- Anti-Monopoly: Preventing algorithms from being used to wipe competitors out of the market.
O
OECD Principles on Artificial Intelligence
Global (OECD)Deep Analysis: Adopted in May 2019 and updated in 2024, these principles represent the first intergovernmental international standard in the field of artificial intelligence. It has been adopted by over 40 countries, including the US, EU, and Turkey. Although lacking legal bindingness (Hard Law), it forms the primary blueprint (Soft Law) for national AI strategies worldwide.
It is built on five core principles: Inclusive growth/sustainable development, Human-centered values/fairness, Transparency/Explainability, Robustness/Security, and Accountability. Noting that even the AI definition in the EU's AI Act text is directly derived from the technical definition formulated by the OECD (2023 update) illustrates the influential power of these principles in international law.
Key Takeaways
- Impact: Created a common terminology and "AI Definition" for global laws.
- Focus: Introducing the concept of "Trustworthy AI" into international literature.
- Accountability: The principle of holding an actor accountable throughout the entire lifecycle of systems.
P
Pro-innovation Regulation of Technologies (White Paper)
United KingdomDeep Analysis: The primary strategy document demonstrating that the UK has broken away from the EU post-Brexit and drawn a different digital roadmap. The UK rejects the EU's rigid and centralized "AI Act" model, adopting a "Context-specific" and "Pro-innovation" approach instead of establishing a brand new AI regulator.
According to this approach, the existing health authority (MHRA) will regulate AI used in healthcare, and the financial authority (FCA) will regulate AI used in finance based on their own principles. Instead of imposing heavy bans, the state establishes 5 core principles (Safety, Transparency, Fairness, Accountability, Contestability) and constructs a "light-touch" legal framework encouraging companies to innovate in Sandboxes.
Key Takeaways
- Approach: Anti-centralist. Opposes establishing a centralized AI institution.
- Competitive Advantage: A strategy to attract tech companies fleeing the EU's strict laws to London.
- Flexibility: Relies heavily on regulatory agency Guidance rather than enacting Acts.
U
UNESCO Recommendation on the Ethics of AI
Global (United Nations)Deep Analysis: Adopted by UNESCO's 193 member states in 2021, it is the most widely participated global standard created on AI ethics. It is a normative tool deeply analyzing not only technological development but also AI's impacts on cultural diversity, the environment, education, and gender equality.
The recommendation advises states to establish "Ethical Impact Assessment" methodologies. At its core lies the philosophy that "Technological development cannot proceed at the expense of human rights and nature." Although it holds no legal bindingness, it directly provides a legal blueprint for draft laws in countries like those in Africa and Latin America that have not yet enacted their local laws.
Key Takeaways
- Inclusivity: Approaches technology focusing on the Global South and culture, not just West-centric.
- Gender: Dedicates a special section to eliminating the biases of AI algorithms against women and minorities.
- Environment: Defines AI's climate change and carbon emission costs as an ethical issue.