We are told AI regulation is here. But for citizens, the truth is less comforting. For example, the US regulation on AI remains fragmented, and the EU’s model still feels too weak, too technical and too distant from the public it claims to protect. Between EU and US AI-regulation systems, is one better than the other?
Two systems
The EU and the US represent two opposing regulatory systems. The European Union’s model follows a protective way that means to regulate first, define risks and impose duties before harm occurs.
The US, in a different case, is favoring innovation-first governance, leaving control over AI to fragmented rules enforced through consumer protection, civil rights, competition and sector-specific laws.
The EU AI Act is the first broad, binding AI framework, while the US still has no federal statute that is dedicated specifically to AI.
In practice, the EU tries to regulate the technology as a system, whereas the US often regulates only the consequences after they occur.
The US regulatory gap
A central weakness in the American approach is the absence of a single legal framework comparable to the EU AI Act. Federal governance exists, but it is fragmented: agencies may act under existing laws, and states have begun filling some of the gaps, especially around elections and transparency. This creates uneven rules across states and sectors, making compliance and accountability harder to enforce consistently. This does not mean the US has no control at all. It does mean the oversight is fragmented rather than comprehensive. For AI systems that are advancing really fast, and can influence speech, employment, health, and elections, the fragmented systems are a real weakness.
The US has signed the Council of Europe’s Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law. That matters because it signals agreement, at least in principle. Agreement on the fact that AI governance should protect democratic institutions and fundamental rights. But still just signing an international framework is not the same as creating a national structure strong enough to carry those principles into practice.
The EU: strong on paper, weak in practice
The EU deserves recognition for leading the way on regulating AI. But the AI Act has some clear gaps. One concern is that it may focus too much on downstream use and not enough on the full supply chain, including dataset construction and training methods of the AI systems. Another critique is that some duties and responsibilities remain unclear, which can weaken accountability.
There is also a deeper problem regarding enforcement. If penalties are not applied, especially to large tech companies with legal and financial resources, the AI Act risks becoming powerless in practice.
A rules-based framework only works when regulators have the capacity, political will to recognise violations and impose sanctions. Without that, large tech companies may treat compliance as a cost of doing business rather than a real constraint to them.
Where the EU can improve
The EU could improve the AI Act in several ways. It should clarify the legal responsibilities of providers, deployers, and users more clearly so that accountability does not disappear in complex AI supply chains.
Another improvement would be stronger enforcement against high-impact actors, particularly large platforms and major AI companies.
The EU should fill the manipulation and election-related gaps by defining harmful influence more precisely. That would make the regime more responsive to the reality of modern AI persuasion and political targeting.
AI regulation is not just about technology, it is also about power. Who controls it, who benefits from it, and who is protected from its harms.
Right now, citizens are being asked to trust systems that are not transparent, companies that remain the majority of the time unaccountable, and laws that are not yet so strong enough to protect individuals as they should be protected.
The EU and the US are not just regulating AI differently; they are different models of understanding democracy, technology innovation, and state responsibility in regulating AI.
The EU has proposed a stronger legal framework, but it still needs more enforcement and better coverage of manipulation risks.
The US, meanwhile, remains more flexible but also less coherent, leaving major gaps in national protection.
For Citizens Take Over Europe, the debate over AI regulation isn’t a technical one, it’s a democratic one. Citizens do not perceive AI as a risk category or a compliance checklist. Instead, they see it as a political advertisement that is targeted at them.
The EU AI Act, for all its ambition, still largely addresses this issue from the top down.
It regulates companies and assigns duties to providers and deployers but lacks strong participatory mechanisms for citizens to shape AI systems.
Want a say in the future of digital infrastructures?
Join our assemblies where citizens reclaim the tech that shapes their lives.
Next one: Budapest – September 3
We’ll be unpacking the risks of facial recognition technology, often sold to us as “safety”, but at what cost to our freedoms?
Sources:
AI legislation in the US: A 2026 overview – SIG
Impact of artificial intelligence on elections