Pacific Design/ artificial intelligence

Policy & Regulation · entry 03/05

The patchwork

Outside Brussels: America's sectoral sprawl and state experiments, Britain's regulator-led bet, China's control-first regime, and the summit circuit trying to stitch them together.

The United States: everything except one law

No comprehensive federal AI statute — instead, layers. Executive orders that swing with administrations (2023's sweeping order, rescinded and replaced in 2025 with an innovation-first posture). Agencies applying existing law: the FTC on deceptive AI claims, financial and health regulators inside their sectors. NIST's AI Risk Management Framework as the voluntary-but-everywhere vocabulary of corporate practice. And the states filling the vacuum — Colorado's algorithmic-discrimination law (enjoined, then repealed outright in 2026 in favor of a thinner disclosure regime: the patchwork's first big retreat), Texas's governance act, Illinois biometric statutes, California's transparency requirements — producing the compliance patchwork federal preemption fights are made of. The result is real obligations without one rulebook: American AI law is a terrain, not a text.

The United Kingdom and the middle path

Britain chose principles over statute: five cross-sector principles (safety, transparency, fairness, accountability, contestability) handed to existing regulators to apply within their domains, plus an outsized bet on technical capacity — the AI Safety (later Security) Institute made the UK a hub for frontier model evaluation without a licensing regime. The wager: expertise and agility beat early codification. The risk: principles without enforcement teeth depend on regulators' appetite, and appetite varies.

China: capability racing, content controlled

China regulates earlier and harder than the West on content and recommendation — algorithm registry filings, deep-synthesis rules, generative-AI measures requiring alignment with core values, and mandatory labeling of synthetic media — while pouring state resources into capability. The regime's distinctive feature: rules bind consumer-facing deployment tightly while leaving research and industrial use freer. Whatever one thinks of the values enforced, the enforcement machinery is real, and its labeling mandates are quietly shaping global platform behavior.

The stitching: summits and institutes

International coordination runs on softer stuff: the G7's Hiroshima code of conduct, the Bletchley–Seoul–Paris–New Delhi summit series — its themes tracking a drift from "safety" toward "impact" — producing declarations and voluntary frontier-safety commitments, a growing network of national AI safety institutes sharing evaluation methods, and standards bodies doing the unglamorous harmonization. None of it binds; all of it shapes — labs cite the commitments, institutes compare notes, and the vocabulary converges even where the laws don't.

Failure mode

Designing compliance for one jurisdiction and calling it done. A product with global users owes the EU's tiers, several US states' notices, China's labels if it serves there, and sector rules everywhere — obligations that overlap without aligning. Teams that map requirements product-by-market once, then track deltas, stay sane; teams that hear "we're US-based, so just US rules" learn about extraterritoriality from a regulator's letter. The patchwork is the terrain. Budget for the terrain.