Beginner level6 min readTo learn at another level, choose it before you start the course.
After this lesson you canName the four kinds of AI rules, and explain how the EU’s one big law differs from the US mix of laws.
The short answerAI laws mostly use four tools. They ban a few uses, set strict duties for risky uses, ask for labels that show when AI is involved, and give duties to makers of powerful models.
In simple words
- Some AI uses are banned, such as reading workers’ emotions in the EU.
- Risky uses, such as AI in hiring, get strict duties.
- Labels tell people when they meet AI or AI-made content.
- Makers of the biggest models must test them and report problems.
The short answerAI laws regulate by risk: they ban a few practices, attach duties to high-risk uses, require transparency so people can spot AI, and set duties for makers of general-purpose models. The EU does this in one law; the US through many targeted ones.
In simple words
- Bans: a short list of practices, from harmful manipulation to collecting face photos in bulk from the internet or cameras.
- High risk: from December 2027, hiring, education and credit get duties such as human oversight and logs.
- Transparency: chatbots must say they are AI; AI-made content must be marked or labelled.
- Model duties: documentation and training-data summaries, plus testing for the most powerful models.
The short answerThe EU AI Act combines Article 5 bans, high-risk duties for the uses listed in Annex III, Article 50 transparency and Articles 53 to 55 for general-purpose models. The 2026 Digital Omnibus moved Annex III duties to December 2, 2027, and duties for AI in regulated products to August 2, 2028. US law stays sectoral and state-led.
Key points
- Article 5 bans have applied since February 2, 2025; a sexual-deepfake ban follows on December 2, 2026.
- Annex III high-risk duties for providers and deployers start on December 2, 2027.
- Article 50 transparency and the Article 86 right to an explanation have applied since August 2, 2026.
- GPAI duties since August 2, 2025, with a systemic-risk presumption above 10²⁵ operations.
1 EU: one law in layers
- BannedPractices too harmful to allow · 7 rules
- Do not use AI to read emotions at work or school In force
- Do not build AI that manipulates or exploits people In force
- Do not use AI social scores to treat people unfairly In force
- Do not scrape faces from the web to build face recognition In force
- Do not use AI to predict crime from profiling alone In force
- Do not use biometrics to guess race, religion or union ties In force
- Do not offer or use AI that makes sexual deepfakes From Dec 2026
- High riskStrict duties for uses that shape lives · 5 rules
- AI for hiring and managing staff becomes “high-risk” From Dec 2027
- Check HR AI against the high-risk rules before you sell it From Dec 2027
- Treat AI for admissions, grading and exams as high-risk From Dec 2027
- Treat face recognition and emotion AI as high-risk From Dec 2027
- Treat AI credit scoring and insurance pricing as high-risk From Dec 2027
- Labels (transparency)People must know when AI is involved · 4 rules
- Everything elseMost AI, such as spam filters or games: only the duty to support staff’s AI literacy
2 US: rules from many levels
- In force
- Law, starting later
No single US law covers AI. Federal rules target specific harms, and each state adds its own; a company follows every level it falls under.
Words to know
- AI Act
- The European Union’s main AI law. It applies in every EU country.
- High-risk use
- An AI use that can change people’s lives, such as hiring. Strict duties apply.
- Federal rule
- A rule from the US national government. It applies in every US state.
Four kinds of rules
Most AI laws mix four kinds of rules. Bans stop a few harmful uses completely. High-risk rules set strict duties for uses that can change people’s lives.
Labels make AI visible, for example by telling you when you chat with a bot. Model rules give duties to the companies that build the most powerful AI.
The EU: one big law
The European Union has one main law, the AI Act. Its bans have applied since February 2, 2025, such as the ban on AI that reads emotions at work or school.
Its labelling duties started on August 2, 2026. Strict duties for high-risk uses, such as AI in hiring, start on December 2, 2027.
The US: many smaller laws
The United States has no single AI law. A few federal rules cover specific problems, such as AI-made intimate images or AI voices in phone calls.
Most AI rules come from states and cities, such as California, Colorado, New York and New York City. So the rules depend on where you are.
Try it yourself
Open the AI rules for California. Sort five of them into bans, high-risk rules, labels and model rules. For example, the ban on chatbot toys is a ban.
AI rules for CaliforniaCheck yourself
A company in Amsterdam uses AI to sort job applications. What does EU law ask of it?
A shop’s chat window says: “I am an AI assistant.” Which kind of rule asks for this?
A US company has staff in Colorado and California. Where do most of its AI rules come from?
Words to know
- AI Act
- The European Union’s main AI law. It applies in every EU country.
- High-risk use
- An AI use that can change people’s lives, such as hiring. Strict duties apply.
- Federal rule
- A rule from the US national government. It applies in every US state.
Risk decides the rules
The EU AI Act sorts AI by risk. A short list of practices is banned outright. Examples are social scoring, which rates people by their behaviour and leads to unfair treatment, and AI that reads emotions at work or school.
Uses that can change lives, such as hiring, grading or credit scoring, count as high-risk. The law calls the maker the provider and the business using the AI the deployer. From December 2, 2027, deployers must follow the provider’s instructions, have trained people oversee the AI and keep logs.
Transparency and labels
Since August 2, 2026, AI that talks with people must say it is AI, unless that is obvious. AI-generated audio, images, video and text must be marked in a machine-readable way.
Deepfakes must be disclosed as AI-made. AI-written text that informs the public must be disclosed too, unless a person reviewed it and someone holds editorial responsibility.
Duties for model makers
Makers of general-purpose AI models must document them, follow EU copyright law and publish a summary of their training content. These duties have applied since August 2, 2025.
Models trained with more than 10²⁵ operations are presumed to carry systemic risk. Their makers must test them, reduce the risks and report serious incidents to the EU AI Office.
The US patchwork
The US has no comprehensive AI law. Federal rules target specific harms. The TAKE IT DOWN Act covers sexual deepfakes, and the FCC, the US telecoms regulator, treats AI voices in phone calls as robocalls.
States fill the gaps with their own laws. A December 2025 executive order, an order from the President, tells federal agencies to challenge some of them. The state laws still apply until a court or Congress says otherwise.
Try it yourself
Open the AI rules for California. Sort five of them into bans, high-risk rules, labels and model rules. For example, the ban on chatbot toys is a ban.
AI rules for CaliforniaCheck yourself
A bank in Madrid uses AI to score people who ask for a loan. How does the EU AI Act treat this?
A new general-purpose model offered in the EU was trained with more than 10²⁵ operations. What must its maker do because of that?
A December 2025 executive order tells US agencies to challenge some state AI laws. Do those laws still apply?
Prohibitions and their edges
Article 5 bans manipulation causing significant harm, exploitation of vulnerabilities, harmful social scoring, crime prediction from profiling alone, untargeted face scraping, emotion recognition at work or school and sensitive biometric categorisation.
Police use of real-time face recognition in public spaces is also banned, with narrow exceptions. Breaking a ban can cost up to €35 million or 7% of worldwide turnover.
The bans have edges: emotion recognition for medical or safety reasons is allowed, and ordinary performance reviews are usually not social scoring. Regulation (EU) 2026/1744 adds a ban on sexual deepfake tools from December 2, 2026.
High risk: providers and deployers
Annex III lists high-risk areas such as employment, education, credit and insurance, and biometrics. Providers need risk management, data quality, documentation, logging, human oversight and a conformity assessment, a formal check against the Act’s requirements, before they add the CE mark.
Deployers must follow instructions, assign trained human oversight, keep logs for at least six months and inform affected people. The Digital Omnibus moved these duties to December 2, 2027.
Transparency and explanation
Article 50 covers chatbot disclosure, machine-readable marking of generated content, deepfake labels and notices for emotion or biometric systems. Systems already on the market have until December 2, 2026 for marking.
Since August 2, 2026, Article 86 has given people a right to an explanation of decisions based on high-risk AI that seriously affect them. Germany backs it with fines of up to €50,000.
General-purpose models, and the US contrast
GPAI providers must document models, respect text-and-data-mining opt-outs and publish training-content summaries. Above 10²⁵ training operations, a model is presumed to carry systemic risk, with testing and incident reporting.
The US relies on targeted federal rules and state laws such as California’s SB 53, Colorado’s SB 26-189 and Connecticut’s Public Act 26-15. The design matters: one EU regulation sets the same core duties in every EU country, while US duties change with each state a company serves. As of October 2026, federal efforts to override state laws remained contested.
Try it yourself
Open the AI rules for California. Sort five of them into bans, high-risk rules, labels and model rules. For example, the ban on chatbot toys is a ban.
AI rules for CaliforniaCheck yourself
A call centre in Prague wants AI that infers its staff’s frustration from their voices, to coach them on sales calls. How does the AI Act treat this?
From December 2027, a bank in Rotterdam deploys a vendor’s new AI credit-scoring system. Which duty is the bank’s own?
In October 2026, a job applicant in Munich is rejected after screening by high-risk AI and asks why. What applies?
Sources
- AI Act, Article 5: prohibited practices (EU AI Act Service Desk)
- AI Act, Article 50: transparency (EU AI Act Service Desk)
- AI Omnibus enters into force (European Commission)
- AI Act overview (European Commission)
This lesson was generated by AI systems under the editorial rules of Silicon AI News and checked against the sources it lists. The live parts come from our checked stories, trackers, model comparison and rules checker.