In March, the EU handed out its first real fine under the AI Act. 45 million euros, against an American platform, for using generative AI in hiring without the transparency and human oversight the law demands. Two other companies got notices too, one of them European, which already tells you something about the promise that nobody gets a pass just for being local. The head of the EU's AI Office said something that stuck with people in my line of work for weeks afterward — that the law isn't aspirational, it's law, and it'll be enforced no matter the size of the company involved. The reaction from the other side of the Atlantic was immediate. Tech trade groups called it disguised protectionism, and the US Chamber of Commerce asked for the issue to be raised in bilateral trade talks.
I'm opening with this because, on its own, it captures pretty much everything at stake in this debate. On one side, a region that wrote the rules before the technology was fully mature and is now testing them on real companies with real names. On the other, a country that let the market run first and, well into 2026, still doesn't have a federal AI law. It has something else instead — executive orders, FTC lawsuits, a dozen different state laws, and an institutional tug-of-war nobody knows the ending to yet.
The lazy version of this — Europe regulates, America doesn't — doesn't really hold up anymore. And honestly, that's the more interesting part to write about.
## What actually changed in Europe this year
The AI Act took effect in August 2024, but it was always designed to phase in. The harshest bans — social scoring, real-time biometric surveillance, systems that exploit psychological vulnerabilities — have applied since then. High-risk systems, covering hiring, credit, education, critical infrastructure, only moved into full enforcement this year.
Here's the part almost nobody explained properly in the headlines. In July the EU passed the Digital Omnibus, which pushes back part of those high-risk obligations — standalone systems move from August 2026 to December 2027, ones embedded in physical products go out to 2028. A lot of people read that as a retreat. It isn't, not really. The Article 50 transparency rules still stand for August 2026 — labeling deepfakes, disclosing AI-generated content, the general-purpose model requirements, the AI Office's enforcement powers. The architecture didn't change. The calendar for one specific piece did. And, worth noting, while pushing back deadlines the same package tightened another front entirely — it explicitly banned nudifier apps and AI-generated child sexual abuse material. That wasn't caving to industry pressure across the board. It was more surgical than that.
The fine amounts give a real sense of scale. Up to 35 million euros or 7% of global turnover for prohibited practices, whichever is higher. 15 million or 3% for high-risk violations. For context, even before the AI Act reached full enforcement, Clearview AI had already been fined 30.5 million euros under GDPR over facial recognition. Brussels was showing teeth before any of this.
## The US does have rules. It just doesn't have one
Calling the US unregulated is lazy. What's missing is a single federal law like the AI Act. What exists instead is a patchwork — the FTC suing companies over unsubstantiated AI performance claims using a decades-old statute, the EEOC issuing guidance on algorithmic hiring discrimination, New York's Local Law 144 requiring bias audits with daily fines between 500 and 1,500 dollars per violation, and roughly a dozen more states writing their own versions, Colorado leading the pack.
That's created, ironically, almost exactly the problem critics of Europe usually warn about — just in reverse. Instead of one central regime slowing everything down, the US potentially has 50 different ones. For a startup operating nationally, that's arguably worse than complying with a single European law.
The Trump administration tried twice to fix this legislatively and failed both times. A ten-year moratorium on state AI laws got tucked into the "One Big Beautiful Bill Act" and got stripped before the vote — the Senate rejected it 99 to 1, which isn't exactly close. A second attempt through the defense authorization bill also didn't survive. Faced with that, the president signed Executive Order 14365 in December 2025, which can't repeal state laws directly since that requires Congress, but sets up a Justice Department task force to challenge them in court and ties 42 billion dollars in federal broadband funding to states rolling back AI rules deemed excessive. It's already been used to intervene in xAI's lawsuit against Colorado's AI law. And in August the president talked again about signing yet another order to impose "one rule" nationwide. The standoff, basically, is ongoing.
## Where this actually gets heated
This is where the arguments that split comment sections come in, now backed by real numbers instead of vibes.
Defenders of the European model point to the 45 million euro fine as proof the law has teeth. Critics look at the same Digital Omnibus and say — see, even Brussels admitted the original timeline wasn't realistic. And they ask why none of the leading frontier AI companies — OpenAI, Anthropic, Google DeepMind, Meta — are European. There's no clean answer to that. There probably shouldn't be one.
On the US side, the idea that "there are no rules" doesn't survive contact with the FTC's cases or the state laws. But the opposite claim, that the US has a coherent approach, doesn't survive the Senate rejecting its own administration's proposal 99 to 1 either. What's actually happening is an unresolved power struggle between the White House and the states, outcome unknown.
Then there's the geopolitical argument, usually the most flammable one. For the US, slowing AI down means ceding ground to China — that's the logic behind pushing to standardize and loosen rules federally. Europe, without that race to lead the frontier, can afford to think about rights and transparency first. But it pays for that in near-total dependence on American infrastructure — the chips, the clouds, even the models it's regulating mostly come from there.
None of this closes neatly. And that's probably why the topic is still alive two years after the AI Act passed — both sides have real data backing opposite readings, and the story isn't even finished, with a new US executive order expected in the coming weeks and European deadlines that don't land until 2027 and 2028.