Skip to content

Europe · Analysis

Independent · Brussels & Berlin

Technology · Digital regulation

AI governance fragmentation tests European resolve as three powers diverge

The EU's AI Act, US executive action and Chinese state-led rules reflect incompatible philosophies. A UN finance adviser warns the window for common standards is narrowing.

By , Technology Editor

Published

10 min read

The European Union's AI Act became fully applicable on 2 August 2026, marking the end of a two-year transition period that began when the regulation entered force. In Washington, the White House continues to rely on an executive order from October 2023 supplemented by voluntary commitments from leading labs. In Beijing, the Cyberspace Administration enforces algorithm registration and security reviews that have been tightening since 2022. Three major powers, three distinct regulatory philosophies, and no shared enforcement mechanism.

Shouqing Zhu, a senior policy adviser at the United Nations Environment Programme Finance Initiative (UNEP FI), argues in a recent commentary that the differences dominate headlines but obscure a more important convergence. All three centres of AI power, he writes, recognise that the technology has become too powerful, pervasive and interconnected to be treated as ordinary technology. The observation carries weight because it comes from the financial side of the UN system, where regulators are already treating AI as a systemic risk category on par with climate change.

The European model: comprehensive but contested

The EU AI Act is the world's first comprehensive horizontal regulation of artificial intelligence. It classifies systems by risk, unacceptable, high, limited, minimal, and imposes obligations proportionate to that classification. Providers of high-risk systems must implement risk management, data governance, transparency and human oversight requirements. The regulation applies extraterritorially to any system placed on the EU market or affecting EU residents, giving it global reach similar to the General Data Protection Regulation.

Implementation has not been smooth. The European Commission's AI Office, established in February 2024, has struggled to recruit the technical expertise needed to evaluate general-purpose models. The codes of practice for foundation model providers, due nine months after entry into force, were delayed by industry pushback on transparency requirements for training data. As of August 2026, only draft codes have been published. National competent authorities in the 27 member states are at vastly different stages of readiness; Germany and France have dedicated AI regulatory sandboxes, while several smaller states have yet to designate lead authorities.

The Act's prohibitions, on social scoring, real-time biometric identification in public spaces, and manipulative systems, took effect in February 2025. Enforcement actions remain rare. The first significant fine, €15 million against a Dutch predictive policing vendor, was issued in March 2026. Critics argue the regulation front-loads compliance costs on European startups while US and Chinese competitors face no equivalent burden. Proponents counter that the Brussels effect will force global alignment, as it did with data protection.

The American model: voluntary layers over sectoral rules

The United States has no federal AI legislation. The October 2023 executive order on safe, secure and trustworthy AI directed agencies to develop standards, required developers of the most powerful models to notify the government and share safety test results, and launched a talent surge for AI expertise in the civil service. The National Institute of Standards and Technology (NIST) published its AI Risk Management Framework in January 2023, updated in 2024, which remains voluntary but is increasingly referenced in procurement and insurance contracts.

Sectoral regulators have moved independently. The Securities and Exchange Commission has proposed rules on predictive data analytics in finance. The Federal Trade Commission has used existing consumer protection authority against deceptive AI claims. The Department of Commerce's Bureau of Industry and Security has expanded export controls on advanced semiconductors and, in 2024, proposed reporting requirements for frontier model training runs above a compute threshold. None of these measures amount to a comprehensive regime.

Congressional action has stalled. The Senate's bipartisan AI working group released a roadmap in May 2024 calling for $32 billion in annual non-defence AI spending by 2026, but legislation on liability, transparency and election deepfakes has not advanced. The 2024 election cycle consumed political oxygen. With a new administration taking office in January 2025, the executive order's future is uncertain; several Republican lawmakers have called for its repeal, arguing it stifles innovation.

The Chinese model: state oversight embedded in deployment

China's approach predates the current generative AI wave. The 2021 regulation on recommendation algorithms established a registration system for algorithms with public opinion properties. The 2022 rules on deep synthesis required watermarking and provider verification. The interim measures on generative AI services, effective August 2023, extended content security obligations and mandated licensing for public-facing services. By mid-2026, over 1,800 algorithms had been registered and more than 200 generative AI services licensed.

The framework is characterised by pre-deployment state review. Providers must submit security assessments covering training data, model architecture and output controls before launch. The Cyberspace Administration coordinates with the Ministry of Industry and Information Technology and the Ministry of Public Security. Foreign companies seeking to offer AI services in China must establish local entities and store data domestically. The system prioritises political stability and information control; innovation is encouraged within those boundaries.

Chinese officials argue their model offers certainty. Companies know the rules before they invest. European and US executives privately acknowledge the clarity but warn the opacity of the approval process, no published criteria, no appeal mechanism, creates unpredictable market access. The regime also fragments the global research ecosystem: Chinese labs publish less, collaborate less internationally, and train on distinct data corpora.

Where the money meets the models

Zhu's perspective from UNEP FI is deliberate. Financial regulators have moved faster than general-purpose AI authorities. The Basel Committee on Banking Supervision issued a consultation paper in December 2024 on AI-related operational and model risk, proposing capital add-ons for banks using unvalidated foundation models in credit decisions. The European Central Bank's 2025 supervisory priorities included AI governance in significant institutions. The US Federal Reserve has conducted horizontal reviews of AI use in large banks. The People's Bank of China has issued guidelines on algorithmic trading and credit scoring models.

The financial sector's interest is practical. A 2025 OECD survey of 42 jurisdictions found that 78% of financial regulators consider AI a material systemic risk, up from 34% in 2022. The risks are concrete: model homogeneity creating correlated failures, opaque third-party dependencies, data provenance gaps, and the difficulty of auditing systems that evolve post-deployment. Insurance markets are pricing AI liability coverage with broad exclusions for foundation model defects. Central banks are exploring AI for supervision itself, the ECB's Athena project uses natural language processing to analyse millions of supervisory documents, creating a recursive governance challenge.

International forums: principles without enforcement

The OECD AI Principles, adopted in 2019 and updated in 2024, remain the only intergovernmental standard with broad adherence, 47 countries including the US, EU members and China. They are non-binding. The G7 Hiroshima AI Process produced a voluntary code of conduct for advanced AI developers in October 2023; 18 companies have signed. The UN Secretary-General's High-Level Advisory Body on AI delivered its final report in September 2024, recommending a global AI governance framework with a scientific panel, policy dialogue and capacity-building fund. The General Assembly adopted a resolution in December 2024 welcoming the report but establishing no new institution.

The EU has pushed for a Council of Europe convention on AI, human rights and democracy. The Framework Convention opened for signature in September 2024; as of August 2026, 14 countries have ratified, none of them major AI powers. The US participates as an observer but has not signed. China was not invited. The convention's focus on public sector use and human rights impact assessments reflects European priorities, not a global consensus.

The standards battleground

Technical standards are where regulatory philosophy becomes code. The European Committee for Standardisation (CEN) and European Committee for Electrotechnical Standardisation (CENELEC) are developing harmonised standards for the AI Act's high-risk requirements under a mandate from the Commission. The US NIST leads the AI Safety Institute Consortium, with over 200 members, producing evaluation methodologies. China's Standardisation Administration has published over 60 AI standards since 2020, many mandatory for government procurement.

The International Organisation for Standardisation (ISO) and International Electrotechnical Commission (IEC) Joint Technical Committee 1 Subcommittee 42 (AI) is the primary global venue. Its working groups include experts from all three blocs. But standard-setting reflects market power. US companies dominate foundation model development; Chinese companies dominate deployment scale in surveillance and smart city applications; European companies dominate industrial AI and regulatory technology. Each bloc promotes standards that favour its incumbents.

A concrete example: watermarking. The EU AI Act requires providers of generative AI systems to ensure outputs are detectable. The US executive order directed NIST to develop watermarking standards. China's deep synthesis rules mandate watermarking. Three standards processes, three technical approaches. Interoperability is not guaranteed. A European regulator trying to verify compliance on a model trained in the US and deployed via a Chinese cloud provider faces a chain of custody problem no current standard solves.

What convergence would require

Zhu invokes institutional economist Douglass North's observation that institutions evolve when changing conditions create incentives and uncertainties existing rules cannot manage. The historical analogies, industrial labour regulation, international banking standards, climate cooperation, each took decades and crises to mature. The Basel Accords emerged from the 1974 Herstatt Bank failure. The Intergovernmental Panel on Climate Change was established in 1988 after years of scientific consensus-building. The International Labour Organization dates to 1919.

AI governance lacks a Herstatt moment, a systemic failure unambiguously attributable to regulatory gaps that forces political action. The 2024 CrowdStrike outage, while not AI-specific, demonstrated how correlated software dependencies can cascade globally. Financial regulators treated it as a wake-up call. The Financial Stability Board's November 2024 report on AI in financial services warned that concentration in cloud and model providers creates single points of failure. A similar event involving an AI system, a hallucinated trading signal triggering a flash crash, a medical diagnostic error scaling across a health system, could catalyse convergence.

Absent crisis, convergence proceeds through technical cooperation. The EU-US Trade and Technology Council's AI working group has mapped risk classifications and identified 12 areas of alignment. The G7 AI Safety Institutes network, launched in May 2024, conducts joint evaluations. China participates in ISO/IEC standardisation but not in the Western safety institute network. A UN-backed scientific panel, as recommended by the advisory body, could provide a shared evidence base. The UNEP FI's own work on AI in sustainable finance taxonomy alignment shows sector-specific convergence is possible even when general frameworks diverge.

The fragmentation Zhu describes is not abstract. It is written into the compliance calendars of every multinational company deploying AI, into the supervisory work programmes of every central bank, into the procurement rules of every government. The convergence he argues for, rooted in shared recognition of systemic power, exists at the level of rhetoric. At the level of enforcement, three regimes operate in parallel, occasionally referencing each other's standards, rarely recognising each other's decisions. The window for voluntary alignment narrows with each model release, each deployment decision, each quarter in which the technical substrate of the global economy becomes more dependent on systems no single regulator can fully oversee.

Sources

  1. South China Morning Post

    scmp.com · 2026-08-03

People mentioned

  • Shouqing Zhu

    Senior policy adviser, United Nations Environment Programme Finance Initiative

Organisations

United Nations Environment Programme Finance Initiative · European Commission · OECD

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.