Regulatory Cooperation and Conflicts
In February 2025, the heads of state gathered in Paris for an AI summit that was supposed to project unity. Instead it staged the split. Standing before an audience of ministers and executives, U.S. Vice President JD Vance delivered what amounted to a warning shot at his hosts: excessive regulation, he argued, would strangle a transformative technology in its cradle, and the United States would not be lectured into copying Europe's caution. When the summit issued its closing declaration on "inclusive and sustainable" AI, the United States and the United Kingdom declined to sign it. The European organizers had wanted a photograph of the democratic world moving in step. What the cameras captured instead was a room in which the two largest Western economies could not agree on what AI governance was even for.
That disagreement is the subject of this chapter. Three of the world's largest AI markets — the European Union, the United States, and China — have each built a distinct machine for governing artificial intelligence, and the three machines are not merely tuned differently. They are built to different blueprints, from different materials, for different purposes. The comforting story of the last decade was that one of these models would eventually win, the way Europe's data-privacy rules quietly became the planet's default. The harder story, the one the evidence increasingly supports, is that the world is dividing into incompatible regulatory blocs — and that the division is hardening from a phase into a structure.
Three Rulebooks for One Technology
Start with what each system actually requires, because the values reveal themselves in the requirements.
The European Union has built a rights- and risk-based model. The AI Act, which entered into force in August 2024 and phases in over several years, sorts AI systems by the danger they pose to people. A handful of uses are simply banned: government social scoring, most real-time facial recognition in public spaces, systems that manipulate behavior through subliminal techniques. A larger category — AI used in hiring, credit scoring, medical devices, education, law enforcement, critical infrastructure — is labeled "high-risk" and saddled with obligations that begin to bite in August 2026: documented risk management, high-quality training data, human oversight, logging, transparency, and conformity assessments before a system reaches the market. General-purpose models like the ones behind today's chatbots picked up their own transparency and safety duties in August 2025. The penalties are deliberately frightening: up to €35 million or 7% of global annual revenue for deploying a banned system — a fraction of turnover, not of European turnover, which for a large firm means a fine measured in billions. The Act's animating idea is that AI systems touching people's lives must be explainable, contestable, and accountable, and that the burden of proving safety falls on the builder before deployment, not on the victim after harm.
The United States favors the mirror image: innovation-first, permissionless by default. There is still no comprehensive federal AI statute. Governance is a patchwork — sectoral regulators applying existing law (the FDA to medical AI, the FTC to deceptive practices), a scatter of state laws, and executive action that swings with each administration. The Trump administration's 2025 AI Action Plan, titled "Winning the Race," made the philosophy explicit: strip away regulatory friction, accelerate deployment, treat AI dominance as a national-security imperative, and resist rules that might hand an advantage to Beijing. The wager is that markets, product-liability law, and after-the-fact enforcement can handle harms as they surface, and that the greater risk is not moving fast enough. Where the EU asks "prove it's safe before you ship," the U.S. asks "ship it, and we'll deal with problems if they arise."
China prioritizes state control and data sovereignty above both rights and market dynamism. Its rules are, in some respects, the most prescriptive of the three: providers of generative AI must file their algorithms with regulators, pass security assessments, and — critically — ensure outputs "adhere to core socialist values," meaning models must be trained and filtered to avoid content the state deems politically dangerous. Data localization requirements keep Chinese users' data inside the country. Amendments folding AI more explicitly into China's cybersecurity framework tightened these obligations further from 2026. Privacy protections exist on paper, but they are subordinate, by design, to state security and social stability. The system is engineered less to protect the individual from the state than to protect the state's authority over the technology.
| Dimension | European Union | United States | China |
|---|---|---|---|
| Core philosophy | Rights- and risk-based | Innovation-first, market-led | State control, data sovereignty |
| Legal instrument | Binding, cross-border statute (AI Act) | Sectoral rules + executive orders | Algorithm filings, security reviews, cybersecurity law |
| Before deployment | Conformity assessment for high-risk systems | Minimal | Government security review and filing |
| Enforcement teeth | Fines up to 7% of global revenue | Existing liability, sectoral penalties | Licensing, takedowns, state oversight |
| Transparency | Mandatory for high-risk systems | Voluntary / sectoral | Required to the state; opaque to the public |
| Value protected first | The individual | The market | The state |
Why These Are Incompatible, Not Just Different
It is tempting to treat this as three dialects of a common language — variations that a good compliance lawyer could harmonize. They cannot, because the requirements do not merely differ in stringency. At specific points, satisfying one means violating another.
Consider transparency. The EU requires that a person subject to a high-risk decision be able to understand, in meaningful terms, how the system reached it, and that regulators can inspect the model's documentation. China requires that certain model details — particularly the content-filtering apparatus and the logic of political moderation — remain opaque, and treats disclosure of some system internals as a security matter. A single explainability interface cannot be simultaneously open to a European auditor and closed for Chinese state-security reasons.
Consider data. The EU's regime assumes data can flow across the bloc under a common governance standard and be transferred abroad only under adequacy conditions. China's regime requires that Chinese data physically stay in China and pass state review before export. A model trained on a globally pooled dataset in the European style is, by construction, not a model that keeps Chinese user data localized.
Consider the moment of control. The U.S. model permits broad deployment and reserves intervention for after harm occurs. The EU model inserts a mandatory gate before deployment. A product strategy built around rapid, iterative public release — the default of American AI labs — is not a strategy compatible with pre-market conformity assessment for high-risk uses.
This is why serving all three markets is not a matter of translating one compliance package into three languages. It requires, in practice, separate system designs: different data pipelines, different content-moderation stacks, different disclosure surfaces, different release cadences. A firm can build for one blueprint cleanly, for two with pain, and for all three only by maintaining what are effectively three products wearing the same brand.
The Squeeze on Everyone but the Giants
That last point is where the abstract collides with the balance sheet, and it explains one of the most consequential dynamics in AI governance: fragmentation is a subsidy to incumbents.
A trillion-dollar company can afford three products. It can staff a Brussels compliance office, a Washington government-affairs team, and a Beijing licensing operation; it can absorb the cost of maintaining parallel data pipelines and separate release processes as a rounding error against its revenue. A twelve-person startup cannot. Faced with the choice of building for one jurisdiction or none, it builds for one — almost always the United States, where the barrier to entry is lowest — and forgoes global reach. The mechanism is not that regulation is bad for small firms in principle; it is that divergent regulation converts market access into a fixed cost, and fixed costs are precisely what large firms can spread across enormous revenue and small firms cannot. Every additional incompatible regime raises the minimum size a company must reach before it can operate globally. The result is an AI ecosystem in which the ability to be present in all major markets becomes a privilege of scale — which is to say, the regulatory landscape quietly does the work of consolidation that antitrust law is supposed to prevent.
The Stacks Go Global
The three models are not sitting still inside their home markets. Each is being exported, and the competition between them has become structural enough that analysts describe it as a contest of "AI stacks" — rival bundles of infrastructure, technical standards, and governance assumptions, each seeking to become the default for the parts of the world that do not build their own.
The American stack travels on the back of platforms. When a government or a business in Lagos, Jakarta, or São Paulo builds on U.S. cloud infrastructure and U.S. foundation models, it inherits American technical norms and American governance assumptions — light-touch, market-mediated — not because anyone signed a treaty but because that is what the tools embody. The audience is, effectively, everyone with a credit card and an internet connection.
The European stack travels on the back of law. The EU wields the size of its single market to make its rules the price of entry: comply with our standards or lose access to 450 million wealthy consumers. This is the "Brussels Effect," and its target audience is any firm that wants European customers — which is most large firms on earth.
The Chinese stack travels on the back of infrastructure deals and state partnerships. Through the digital component of its Belt and Road investments, China exports surveillance systems, smart-city platforms, and the governance model that accompanies them, normalizing state control of AI as a legitimate — even attractive — choice for governments that value stability over dissent. The audience is deliberately chosen: developing states and authoritarian-leaning governments for whom a turnkey system of technological control is a feature, not a bug.
The contest, then, is not only about whose models are more capable. It is about whose rules become the water that everyone else swims in. And unlike technical standards — voltages, protocols, file formats — that can be reconciled through committee negotiation, these stacks encode political values that cannot be split down the middle.
The Brussels Effect and Its Limits
Europe's whole strategy rests on the bet that its market is too valuable to refuse, and that companies forced to comply for Europe will find it cheaper to adopt European standards everywhere. That bet paid off spectacularly with GDPR, which became a de facto global privacy baseline. The question is whether the AI Act will follow — and here the honest answer is: partially, and less cleanly.
The GDPR precedent is instructive precisely because its record is mixed. Yes, it exported a floor for data handling. But its most visible legacy is the cookie-consent banner — a ritual of clicking "Accept" that changed the interface far more than it changed the underlying data economy. Compliance often meant consent theater rather than substantive restraint. Enforcement was slow and uneven, and while headline fines eventually landed (Meta was fined €1.2 billion in 2023 over data transfers), for years the gap between the letter of the law and the substance of corporate behavior stayed wide. The lesson is not that the Brussels Effect is a myth; it is that a determined industry can frequently satisfy the letter of a rule while hollowing out its spirit.
AI Act compliance is structurally harder to fake in some ways and easier to evade in others. Harder, because privacy compliance can largely be bolted on through policy and access controls, whereas the AI Act reaches into training data, model architecture, and monitoring — changes that touch the product itself. Easier, because that same depth creates more places to hide: a firm can produce a mountain of conformity documentation, tick the human-oversight box with a rubber-stamp reviewer, and label a system as lower-risk to dodge the heavy obligations. Where GDPR's central act was a checkbox, the AI Act's central act is a judgment about risk — and judgment is precisely what a motivated company can shade. There is a credible path in which developers meet the Act's requirements on paper while the riskiest categories of development quietly migrate to jurisdictions that don't ask.
Is the Race to the Bottom Real?
The deepest fear is not compliance cost but competitive erosion of standards themselves — a race to the bottom in which jurisdictions bid down their own rules to attract AI capital, and the global equilibrium settles at minimal governance rather than rising toward a shared high standard.
Is this a credible prediction or a rhetorical scare? The honest position is that the incentive structure is real, and there is early evidence, but the outcome is not foreordained. On the evidence side: the U.S. AI Action Plan explicitly conditioned federal support on states adopting less restrictive AI rules — a deliberate mechanism to reward deregulation. Inside the EU, member states and industry groups anxious about competitiveness have pushed for softer enforcement and delayed timelines. And the sheer scale of Chinese state subsidy to domestic AI firms pressures competitors elsewhere to argue that their own governments are handicapping them with rules.
But the counter-pressure is equally real, and it is the Brussels Effect. A genuine race to the bottom requires that companies actually abandon the strict market — and Europe is too rich to abandon. As long as that holds, the strict standard sets a floor that propagates outward, and the equilibrium tilts toward a mixed landscape rather than a uniform bottom. The condition under which the race to the bottom truly wins is specific: it requires that the strict market become either small enough to skip or lax enough in enforcement that compliance is optional. The distinguishing evidence to watch for is therefore not rhetoric but enforcement — whether Brussels imposes the first billion-euro AI Act fines, or whether the Act becomes another well-drafted law that regulators flinch from using.
The Coordination That Exists — and the Seven Countries
Against fragmentation, the international system has mounted a response, and it is worth being precise about what it has and has not achieved. In 2025 the UN General Assembly established two new bodies: a Global Dialogue on AI Governance, giving all 193 member states a formal venue, and an Independent International Scientific Panel on AI, modeled loosely on the climate system's IPCC to supply a shared evidence base. The G7's Hiroshima AI Process, launched in 2023, produced international guiding principles and a voluntary code of conduct for advanced AI among the wealthy democracies.
Both have delivered the same thing and hit the same wall. They can generate shared principles — safety, transparency, human oversight, accountability — because principles are cheap and non-binding. They cannot generate binding rules, because binding rules require ceding sovereignty, and no major power will accept constraints it fears a rival will evade. The UN bodies can recommend; they cannot enforce. The G7 process can align democracies on values; it cannot bridge the gulf to the authoritarian model, which is the gulf that actually matters.
One statistic captures the depth of the problem better than any communiqué. By one widely cited count, only seven countries — all of them wealthy, developed nations — participate in every major global AI governance initiative. The rest of the world participates in some, or none. Whatever these forums are building, they are building it among a small club at the top of the income distribution and calling it universal. It is not universal. It is a rich-country conversation with a global letterhead.
The View from Everyone Else
For the countries outside that club — most of the world — three incompatible governance models do not present an interesting menu. They present a forced choice with no neutral option. A developing nation deciding how to build its digital future must, in practice, align: adopt EU-style rules to keep access to European markets and aid, plug into the American platform stack and its permissionless norms, or take Chinese infrastructure and the state-control model bundled with it. Each choice is also a geopolitical alignment, and each forecloses the others. A country that builds on Chinese smart-city systems is not then going to certify those systems under the EU AI Act.
What this costs is regulatory autonomy. A nation that adopts EU rules it had no hand in writing has effectively outsourced its AI policy to Brussels; one that takes the Chinese stack has imported a governance philosophy designed for a one-party state into a different political system. The frameworks were built by and for major powers, and the smaller country's role is to conform to one of them, not to shape any of them. Giving these countries genuine voice — rather than a choice of masters — would require governance architecture that does not yet exist: standard-setting bodies where votes are not proportional to market size, capacity-building so poorer states can participate as authors rather than adopters, and interoperability frameworks that let a country meet several standards without rebuilding its systems three times. None of this is on the near-term agenda.
What We Don't Know
Intellectual honesty requires naming the largest hole in this picture: we do not actually know how much of China's AI governance is enforced versus declared. The Chinese framework is prescriptive on paper — algorithm filings, security reviews, ideological alignment — but the gap between the text of a Chinese regulation and its selective, opaque, politically directed enforcement is wide and deliberately unobservable from outside. How rigorously are filings scrutinized? How consistently are the rules applied to state-favored national champions versus smaller players? We are largely guessing. Any confident claim about the "Chinese model" in practice, including some in this chapter, rests on stated policy more than on verified enforcement — and readers should hold those claims accordingly.
The Realistic Best Case
If global harmonization is off the table, what is the ceiling? The honest best case is not a single world rulebook. It is managed coexistence: a world of three durable blocs that agree to prevent their differences from escalating into open conflict. In practice, that means mutual-recognition agreements, so that a safety assessment done in one jurisdiction counts for something in another; technical interoperability standards, so that a company can meet multiple regimes without three full rebuilds; shared incident-reporting channels, so that a dangerous model failure discovered in one bloc is flagged to the others; and diplomatic mechanisms to resolve jurisdictional disputes before they become trade wars. Modest as it sounds, none of this machinery yet exists at scale, and building it before the divides calcify is the practical work in front of the field.
Which brings us to the two questions that have no neutral answer. Which philosophy is the better framework for governing AI across borders? The case for the European model is that AI's harms fall on individuals, and only a rights-based regime treats those individuals as something other than externalities. The case for the American model is that governing a technology this immature by locking in today's rules risks freezing mistakes into law and forfeiting the very capability that gives a society leverage over how AI develops. The case for the Chinese model — made rarely in the West but attractive to many governments — is that AI is too powerful to leave to markets or courts, and only the state can move fast and firmly enough to control it. Each is coherent. Each protects something real. None can be reconciled with the others, which is the whole problem.
And should Europe enforce the AI Act rigorously even at the cost of competitiveness? The trade-off is genuine, not rhetorical: aggressive enforcement may push some AI development to friendlier shores and widen the capability gap with the United States and China. But the argument for enforcing anyway is that a rule nobody enforces is worse than no rule at all — it teaches firms that the strict market is bluffing, which is exactly the condition under which the race to the bottom stops being a fear and becomes the mechanism. The Brussels Effect only works if Brussels is willing to bite. An AI Act that flinches would forfeit the one lever that makes Europe's whole strategy coherent, and prove the skeptics right at the moment it mattered most.
Summary
-
Three incompatible rulebooks, not three flavors of one. The EU governs AI to protect individual rights (risk tiers, pre-market checks, fines up to 7% of global revenue); the U.S. governs to protect market dynamism (permissionless deployment, sectoral cleanup after harm); China governs to protect the state (algorithm filings, data localization, ideological alignment). The values are visible in the requirements.
-
The conflicts are specific, not vague. EU-mandated transparency collides with Chinese-mandated opacity; EU data governance collides with Chinese data localization; U.S. rapid release collides with EU pre-market gates. Serving all three markets requires genuinely separate system designs — which is why fragmentation quietly consolidates the industry around the few firms large enough to maintain three products.
-
Each model is being exported — the U.S. through platforms, the EU through market-access law (the Brussels Effect), China through infrastructure deals — turning regulatory divergence into a global contest of "AI stacks" that encode irreconcilable political values.
-
The Brussels Effect is a partial defense. GDPR became a global baseline but also produced consent theater; AI Act compliance is deeper and harder to fake, but its risk-classification judgments give motivated firms room to meet the letter while evading the substance. Its power depends entirely on whether Europe actually enforces.
-
The race to the bottom is a credible risk, not a certainty. The incentive structure is real and early evidence exists (U.S. federal-funding pressure toward deregulation, softening of EU enforcement); the countervailing force is Europe's market size. Watch enforcement, not rhetoric, to tell which way it breaks.
-
Coordination produces principles, not rules. The UN's new bodies and the G7 Hiroshima Process can align values but cannot bind sovereigns. That only seven wealthy countries take part in every major initiative reveals how far "global" governance is from universal.
-
Fragmentation now looks structural, not transitional. For most of the world it means a forced choice among blocs and a loss of regulatory autonomy. The realistic best case is not convergence but managed coexistence — mutual recognition, interoperability, incident-sharing — and that machinery still has to be built before the divides harden past repair.
Sources
- Eight ways AI will shape geopolitics in 2026 | Atlantic Council
- What drives the divide in transatlantic AI strategy? | Atlantic Council
- Three Rulebooks, One Race: AI Regulation in the U.S., EU, and China | ACM
- AI Regulations in 2025: US, EU, UK, Japan, China & More | Anecdotes
- The UN's new AI governance bodies explained | World Economic Forum
- Fragmentation in AI Governance Is the New Normal | World Politics Review
- Diverging paths to AI governance: Hiroshima AI Process | World Economic Forum
- How 2026 Could Decide the Future of Artificial Intelligence | CFR
- AI Act implementation timeline | EU Artificial Intelligence Act
Last updated: 2026-08-15
V2 (in progress) Previous: V1