How AI Regulation Differs Across Jurisdictions
In this episode, Rikka founder Charlyn Ho breaks down the three major types of machine learning and why understanding them matters for legal professionals:
- Supervised learning: Think textbook-style learning with labeled data. Great for making predictions, like detecting spam or forecasting prices.
- Unsupervised learning: Used for discovering hidden patterns and structures in data, like customer segmentation in marketing or simplifying complex datasets.
- Reinforcement learning: Learning through feedback. This can power everything from self-driving cars to optimizing advertising strategies.
Whether you're advising on product development, assessing AI risk, or evaluating compliance issues, knowing how a model was trained can offer valuable context.
Transcript
The Regulatory Challenge
Regulators face a real balancing act. They need to protect the public from AI's risks, like bias, job loss, or security threats, while still encouraging innovation and staying globally competitive. Every country is solving that balance differently.
United States: A Light-Touch Federal Approach
The federal government has mostly taken a light-touch approach: guidelines and encouragement, not strict rules. That could change as concerns about AI risk grow.
States are moving faster. Colorado's AI Act creates specific requirements for transparency, accountability, and responsible AI use, and it's becoming a model other states are watching.
European Union: Comprehensive and Risk-Based
The EU has gone the opposite direction. The EU AI Act is comprehensive and prescriptive, built around risk management and ethical principles.
It sorts AI applications by risk level. High-risk systems, like those used in healthcare or law enforcement, face the strictest oversight. The higher the risk, the more stringent the rules. The goal: AI development that holds to fairness, accountability, and transparency.
United Kingdom: Pro-Innovation and Sector-Specific
The UK has taken a third path: pro-innovation and context-specific. Unlike the EU, it doesn't define "AI" or "AI system" in one overarching law.
Instead of new legislation that could put, in the UK's own words, "undue burdens" on businesses, the UK empowers existing regulators, in finance, healthcare, transportation, and elsewhere, to write guidance tailored to their own sector. The goal is to protect the public without slowing innovation down.
At a Glance
Jurisdiction
Overall approach
Key mechanism
United States
Light-touch federally, tightening at the state level
Federal guidelines, plus state laws like the Colorado AI Act
European Union
Comprehensive and risk-based
The EU AI Act, with stricter rules for higher-risk systems
United Kingdom
Pro-innovation, sector-specific
Existing regulators write their own tailored guidance
How Privacy Law Fits In
These regulatory approaches are tightly connected to data privacy law. In the EU, the General Data Protection Regulation (GDPR) plays a major role in how AI systems handle personal data. In the US, state privacy laws like the California Consumer Privacy Act (CCPA) are shaping AI regulation too.
What This Means for Legal Teams
AI regulation is moving fast, and it looks different in every jurisdiction:
- The US is shifting from a light-touch federal approach toward more specific state rules, like Colorado's and California's.
- The EU is committed to broad, risk-based regulation.
- The UK is betting on a flexible, sector-by-sector approach that avoids new burdens on business.
Each approach has real strengths and real gaps. Staying current on all three will matter for how you advise clients on compliance, liability, and technology adoption.
If your team is building or deploying AI across more than one of these jurisdictions, Rikka's AI Governance Assessment maps exactly where your exposure sits under each framework.
















