LIVE

Technology

Why AI Regulation Is Harder Than It Looks

Governments worldwide are struggling to regulate AI. Classification, enforcement, and geopolitical competition make effective governance elusive.

Why AI Regulation Is Harder Than It Looks

Artificial intelligence has advanced faster than any technology in living memory, and the regulatory frameworks meant to govern it have struggled to keep pace. In 2026, governments around the world are grappling with the same fundamental question: how do you regulate a technology that evolves faster than the legislative process itself? The answer, so far, is imperfectly. The European Union's AI Act, the most comprehensive regulatory framework to date, has been hailed as a landmark—and criticized as a bureaucratic straitjacket that will drive innovation to less regulated jurisdictions. The United States has taken a patchwork approach, with state-level laws creating a compliance minefield. China has moved swiftly with its own algorithm-specific regulations. The result is a fractured global landscape where the same AI system can be legal in one country and prohibited in another.

The Classification Problem

At the heart of every AI regulatory framework is an attempt to classify AI systems by risk. The EU's approach defines categories ranging from minimal risk to unacceptable risk, with obligations scaling accordingly. High-risk systems—those used in hiring, education, healthcare, and law enforcement—face stringent requirements around transparency, data quality, and human oversight. The logic is sound: a chatbot that recommends restaurants should not face the same scrutiny as an algorithm that decides whether someone gets a mortgage. But classification in practice is messy. An AI system used for customer service might, through integration with other systems, effectively influence hiring decisions. A general-purpose language model can be deployed in both low-risk and high-risk contexts, raising the question of who bears responsibility—the developer, the deployer, or both? These ambiguities have fueled endless debate among policymakers and industry lawyers.

The rapid emergence of general-purpose AI models has made the classification problem even harder. When a single foundation model can write code, generate medical advice, and compose marketing copy, applying a fixed risk category to the model itself becomes almost meaningless. Regulators have responded with additional tiers for "general-purpose AI" and "systemic risk" models, but the thresholds—typically based on training compute—are arbitrary and easy to circumvent. A model trained just below the threshold faces minimal scrutiny, creating an incentive to engineer around the rules. Meanwhile, open-source models, which can be downloaded and modified by anyone, pose a fundamentally different regulatory challenge. You cannot audit an entity that does not exist, and you cannot enforce transparency requirements on a community of anonymous developers. The open-source AI movement only complicates this picture further, as does the rapid evolution of AI-powered translation systems that blur jurisdictional lines.

Enforcement and the Compliance Gap

Even the best-written regulation is worthless without enforcement, and enforcement is where AI governance faces its deepest structural problem. Regulating AI requires technical expertise that most government agencies simply do not have. Understanding whether a model was trained on copyrighted data, whether its outputs are biased, or whether it poses systemic risks requires the ability to inspect complex systems—often held as proprietary secrets by the companies being regulated. The EU has begun building a specialized AI Office, but it remains understaffed relative to the scale of the challenge. In the United States, where AI regulation is fragmented across federal agencies and state legislatures, the expertise gap is even wider. Companies have learned that they can shape regulation by participating in advisory processes, embedding their preferences into standards that regulators lack the knowledge to question.

"Regulators are playing chess against an industry that moves at the speed of software, while they move at the speed of government. The gap between rule-making and reality only widens with each passing month."

The geopolitical dimension adds another layer of complexity. AI development is a strategic priority for every major economy, and there is a real tension between regulation and competitiveness. If one jurisdiction imposes stringent rules, companies can relocate to more permissive ones. This dynamic has led to a regulatory race to the bottom in some areas, even as policymakers publicly call for international coordination. The reality is that meaningful AI governance will require global cooperation on a scale that has been achieved in few other domains. Arms control, climate policy, and nuclear nonproliferation offer partial models, but none perfectly fits a technology that is both ubiquitous and dual-use. The path forward likely involves a combination of binding rules, voluntary standards, and technical safeguards built into the systems themselves.

AI regulation in 2026 is not a solved problem—it is barely a defined one. The technology continues to evolve in ways that surprise even its creators, and the regulatory frameworks being built today will need constant revision. What is clear is that leaving governance entirely to the market is not an option the public will accept, and micromanaging every algorithm is not an option the industry can survive. Finding the narrow path between those two failures is the defining policy challenge of the decade, and there is no guarantee that we will find it in time.

Sources & References

  • 1 European Commission AI Act implementation documents Official
  • 2 Reuters technology policy reporting Media
  • 3 OECD AI Policy Observatory comparative analysis Report

Frequently Asked Questions

The Classification Problem
At the heart of every AI regulatory framework is an attempt to classify AI systems by risk. The EU's approach defines categories ranging from minimal risk to unacceptable risk, with obligations scaling accordingly. High-risk systems—those used in hiring, education, healthcare, and law enforcem...
Enforcement and the Compliance Gap
Even the best-written regulation is worthless without enforcement, and enforcement is where AI governance faces its deepest structural problem. Regulating AI requires technical expertise that most government agencies simply do not have. Understanding whether a model was trained on copyrighted data, ...