Note: Global regulation of artificial intelligence is evolving rapidly. This article offers a high-level overview of the general approaches and trends and does not constitute legal advice. Always check the current status directly with the relevant national supervisory authorities.
While the European Union has opted for a comprehensive, horizontal regulation with a risk-based approach through the EU AI Act, countries outside the EU are choosing widely divergent strategies. Some jurisdictions emphasize innovation and market flexibility, while others focus on national security, content control, or sector-specific risks.
For international organizations, developers, and Dutch companies that export software or integrate foreign AI models, insight into this global diversity is essential. After all, an approach that suffices in one region can lead to legal bottlenecks elsewhere.
Key points by jurisdiction
The international landscape ranges from strict centralized oversight to market-oriented and fragmented frameworks. Below, the main international players and their philosophy are explained.
United States: fragmented and sectoral
In the United States, there is no central, federal AI law covering the entire field. The American approach has historically focused on protecting innovation and avoiding generic barriers for technology companies. Oversight primarily takes place through existing regulators within their specific domains.
For example, the Federal Trade Commission (FTC) closely scrutinizes misleading marketing, privacy violations, and anti-competitive practices around AI systems, while the Financial Industry Regulatory Authority (FINRA) and the FDA oversee the financial sector and medical applications respectively. At the federal level, executive orders and guidelines (such as the NIST AI Risk Management Framework) are used, serving as guidance for government agencies and industry, but often not constituting a direct legal obligation for the entire market.
In addition, the level of individual states plays a major role. Several American states are introducing their own legislation around consumer privacy, automated decision-making in job applications, and tackling deepfakes and disinformation. This leads to a patchwork of rules that companies must take into account per state.
United Kingdom: principle-driven and decentralized
After leaving the EU, the United Kingdom has chosen a 'pro-innovation' approach. Instead of establishing a new regulator or a broad, central AI law, the UK sets out central principles (such as safety, transparency, fairness, and remediability).
Existing sectoral regulators — such as the Financial Conduct Authority (FCA), the Information Commissioner's Office (ICO), and the Competition and Markets Authority (CMA) — are expected to apply these principles within their own fields. The idea behind this is that sectoral experts are better able to assess the specific risks of AI than a single central authority. This model offers flexibility, but does require clear coordination between the individual bodies.
China: content control, registration, and watermarks
China takes a top-down approach focused on social stability, national security, and content control. Instead of one overarching 'AI law', China regulates specific categories of AI through targeted measures.
Key pillars of Chinese oversight include rules for recommendation algorithms, synthetic media, and generative AI services. Providers of publicly accessible generative AI services often have to register their algorithms and training data with the Cyberspace Administration of China (CAC). Strict requirements also apply to ensuring the accuracy of output, mandatory watermarking of generated content, and compliance with national security and values standards.
Canada, Japan, and South Korea: varying emphases
Other major economies are also developing their own vision on artificial intelligence:
- Canada: Working on legislative initiatives (such as the Artificial Intelligence and Data Act, AIDA) aimed at limiting serious risks and biased decision-making in high-impact AI systems.
- Japan: Adopts a predominantly guiding and voluntary approach ('soft law') for the time being. The focus is on stimulating technological development and supporting industry through guidelines, combined with agreements on safety.
- South Korea: Combines investments in its own AI infrastructure with legislative frameworks aimed at ensuring the safety of AI applications, particularly in the public sector and socially critical processes.
Comparison of regulatory models
To clarify the differences in approach at a glance, the table below compares the central characteristics of the main jurisdictions.
| Jurisdiction | Primary Approach | Supervisory Structure | Core Focus |
|---|---|---|---|
| European Union | Horizontal & Risk-based | Central framework, national supervisory authorities | Fundamental rights, safety & transparency |
| United States | Sectoral & State-level | Existing agencies (FTC, FDA, etc.) | Market innovation, consumer protection |
| United Kingdom | Principle-driven & Decentralized | Existing sectoral regulators | Flexibility, sectoral expertise |
| China | Targeted per AI application | Central government body (e.g. CAC) | Content control, security & registration |
| Japan | Guiding ('Soft Law') | Ministerial guidelines | Technology adoption, innovation |
International coordination and standards
Due to the cross-border nature of software and data flows, there is a call for international harmonization. Several multilateral forums are attempting to establish common principles.
For instance, the OECD and the G7 (among others through the Hiroshima AI Process) have established international principles for responsible AI. The United Nations and the Council of Europe are also working on frameworks around human rights and governance. In parallel, international standardization organizations such as ISO/IEC and the IEEE play a crucial role. They develop technical standards for risk management, transparency, and data quality that companies worldwide can use as a tool to meet different national requirements.
Practical implications for Dutch organizations
For a Dutch organization operating exclusively within the EU, European legislation is the primary frame of reference. Think here of the rules enforced by AI supervision in the Netherlands. As soon as an organization exports software to countries outside the EU, or purchases American models and cloud infrastructure, the international differences become immediately tangible.
1. Extraterritorial effect of foreign rules
Just as the EU AI Act imposes obligations on parties outside the EU that offer services on the European market, foreign rules can also apply to Dutch companies. For example, if you offer services to consumers in specific US states, you may have to deal with local legislation around transparency, automated decision-making, or privacy.
2. Data flows and intellectual property
When using international AI models, questions around data location and copyright play a major role. The rules on what may or may not be used as training data vary by country. Uncertainties around AI and copyright in other jurisdictions can affect whether trained models or generated output are protected outside the EU or infringe on third-party rights.
3. Contractual agreements with suppliers
When purchasing AI models from major American technology companies, it is important to record in contracts where the data is processed and which law applies. Supplier terms are often drafted from the American legal system. It is the buyer's responsibility to check whether these terms align with European obligations and their own risk appetite.
4. The risk of divergent standards
Organizations operating globally run the risk of having to do double work. A system that meets the requirements of the British principle-driven model does not automatically have the correct technical documentation for the EU, or the required registrations for the Chinese market. Building a modular AI governance model helps to meet the specific requirements of each market without having to completely redesign the base system each time.
What to keep an eye on
In the coming years, AI regulation worldwide will further crystallize. Many countries are currently determining how to strike a balance between protecting citizens and stimulating their own tech sector. Organizations would do well to follow the following developments:
- State-level legislation in the US: Follow the emergence of specific AI laws in major American states, as these often become the de facto standard for companies active in the US.
- Evolution from soft law to hard law: Keep an eye on whether countries that currently still work with voluntary guidelines (such as Japan or the UK) will eventually opt for binding legislation.
- International technical standards: Follow the publications of ISO/IEC and CEN/CENELEC. Harmonised standards often provide the most practical foundation for complying with multiple regulations.
Would you like advice on setting up AI governance within your organization, or are you looking for support with integrating language models? Explore the options through our LLMnet Consultancy services or consult our technical documentation at LLMnet API.


