Three Systems, Three Theories of Power: Germany, the UK, and the US Take Three Incompatible Approaches to Regulating AI
Comparative analysis: Germany’s KI-MIG under the EU AI Act vs. the UK’s regulator-led, legislation-free approach vs. the US federal-state fight over who even gets to regulate AI at all
Executive Summary
The same underlying problem, regulating a fast-moving, borderless technology, has produced three fundamentally different theories of where that regulatory authority should sit. Germany’s answer is that authority sits above the nation-state: its KI-Marktüberwachungs- und Innovationsförderungsgesetz (KI-MIG) is not really a policy choice at all, but the domestic plumbing required to implement the EU’s binding AI Act. It passed the Bundestag on 11 June 2026 (CDU/CSU and SPD in favor; the AfD and the Greens voted against, with reporting differing on whether Die Linke voted no or abstained), cleared the Bundesrat without a mediation committee on 10 July 2026, and is expected to enter force just before the EU’s 2 August 2026 general-applicability deadline. The UK’s answer is the opposite: authority stays inside existing, pre-AI-era regulators, by deliberate choice. Its May 2026 King’s Speech contained no AI Bill at all, despite years of government promises; instead it introduced a “Regulating for Growth Bill” built around AI sandboxes and a statutory duty for regulators to prioritize growth over caution. The US’s answer isn’t an answer at all: authority is actively, unresolvedly contested. A Republican-controlled Senate voted 99–1 in July 2025 to strip a proposed ten-year moratorium on state AI regulation from a must-pass budget bill; five months later, the White House tried to achieve much the same outcome by executive order instead, directing the Department of Justice to sue states directly. That fight is now live in a Colorado courtroom, with AI company xAI and the DOJ jointly suing to block a state consumer-protection law, and enforcement of that law currently suspended by court order.
None of the three approaches is settled. Germany’s own implementation ran roughly a year behind the EU’s original schedule. The UK’s regulator-led model is already drawing criticism that no single body is actually accountable for AI harms. And the US fight is playing out in real time, in an actual courtroom, over an actual state law, on a compressed timeline that keeps slipping. This piece works through all three, and through the meta-question underneath them: when a Brussels regulation, a Westminster non-decision, and a Washington executive order all claim jurisdiction over the same technology, whose theory of authority wins?
1. The EU Baseline
Before comparing national responses, it’s worth being precise about what they’re responding to, since the UK and US have no equivalent starting point to react against.
The EU’s Artificial Intelligence Act (Regulation (EU) 2024/1689) entered into force in August 2024 and is being phased in on a staggered schedule, organized around four risk tiers: unacceptable-risk practices are banned outright; high-risk systems (biometric identification, critical infrastructure, education, employment, access to essential services such as credit scoring and insurance, law enforcement, migration, and the administration of justice) face a full compliance regime; limited-risk systems face transparency duties; and minimal-risk systems face no obligations at all. The rollout: prohibited practices became illegal on 2 February 2025; obligations for general-purpose AI model providers, and a requirement that member states have national competent authorities operational, took effect on 2 August 2025; and 2 August 2026 is the date the Act becomes generally applicable, including Article 50’s transparency duties (AI chatbots must disclose they’re AI, deepfakes and AI-generated content must be labeled).
That timeline has already bent once. By late 2025, implementation across the bloc was visibly behind schedule, and the European Commission negotiated what’s been called the “Omnibus” agreement: high-risk obligations for standalone systems (Annex III) were pushed from 2 August 2026 to 2 December 2027, and for AI embedded in already-regulated products (Annex I, e.g. medical devices) from 2 August 2027 to 2 August 2028. The Commission’s own reasoning was blunt: the regulatory infrastructure needed to make those obligations operable, meaning national authorities, conformity-assessment bodies, and enforcement capacity, hadn’t materialized on schedule. Penalties for non-compliance remain severe regardless of the delay: up to €35m or 7% of global annual turnover, a higher ceiling than the GDPR’s.
That single fact, that even a harmonized, binding, EU-wide statute needed an emergency timeline extension because member states weren’t ready, is the first data point against treating “supranational mandate” as a synonym for “smooth execution.” Germany’s own experience, below, is the second.
2. Core Comparison
Mechanics
| Germany: KI-MIG | UK: Regulator-led / Regulating for Growth Bill | US: Federal-state AI fight | |
|---|---|---|---|
| Instrument | National implementation of the EU AI Act: designates enforcement authorities, sets penalties, creates a regulatory sandbox | No AI-specific statute. Existing regulators (ICO, Ofcom, FCA) stretch pre-AI powers; a new “Regulating for Growth Bill” adds cross-economy AI sandboxes and a pro-growth duty for regulators | No federal AI statute. State laws (e.g. Colorado’s SB24-205) are the only operative rules; the federal executive is trying to override them by litigation rather than legislation |
| Trigger | External and mandatory: EU Regulation 2024/1689 requires every member state to have this in place | Domestic policy choice, repeatedly deferred: an “AI Bill” has been promised since 2023 and never introduced | Domestic and unresolved: no federal law exists because Congress has twice declined to legislate on preemption |
| Core mechanism | Names the Bundesnetzagentur (BNetzA) as central AI market-surveillance authority, single point of contact, and operator of at least one AI regulatory sandbox (“KI-Reallabor”); also touches whistleblower-protection and financial-supervision law | “Regulating for Growth Bill” creates cross-economy sandboxing powers letting ministers temporarily suspend regulations for AI testing, plus a statutory mandate for regulators to “prioritise growth” and reduce “unnecessary risk aversion” | Executive Order 14365 (11 Dec 2025) directs the DOJ to build a litigation task force to challenge state AI laws on constitutional grounds (Commerce Clause, preemption); a March 2026 White House framework asks Congress for statutory preemption instead |
| Legislative status | Passed Bundestag 11 Jun 2026; cleared Bundesrat without mediation committee 10 Jul 2026; awaiting formal signature/publication, expected before 2 Aug 2026 | Announced in the 13 May 2026 King’s Speech; not yet passed | No federal statute exists or is pending; the fight is playing out through an EO, a DOJ task force, and active litigation |
| Live contestation | Coalition (CDU/CSU, SPD) passed it over opposition from the AfD and the Greens, the latter calling the authority structure a “patchwork” | Criticism that no single regulator is actually accountable for AI harms; government has “eschewed” the EU AI Act as a model | DOJ intervened (24 Apr 2026) in xAI’s lawsuit against Colorado’s AI law; court suspended the law’s enforcement (27 Apr 2026) pending Colorado’s 2026 legislative session and a ruling on the merits |
| Deadline pressure | Must be in force before the EU’s 2 Aug 2026 general-applicability date | None; this is exactly the point | Colorado’s law was rescheduled from 1 Feb 2026 to 30 Jun 2026 and is now suspended entirely |
Structural similarities
All three jurisdictions are wrestling with the same practical question, who has to do what by when, and all three are visibly behind whatever their own original schedule was: Germany needed until July 2026 to finish naming its own enforcement authority, more than a year past the EU’s original August 2025 deadline for national authorities to be operational; the UK’s “AI Bill” has slipped for three years running; and the US federal government’s own preferred policy (a moratorium on state regulation) was rejected by its own party’s Senate majority before the executive branch tried a different route to the same end. Delay, in other words, is the one thing all three systems have in common.
Fundamental differences
Where they diverge is in why they’re delayed. Germany’s delay is implementation friction inside an already-settled policy: nobody in the Bundestag debate disputed that AI should be regulated under the EU framework; the fight was over the domestic enforcement architecture’s complexity. The UK’s delay is a policy choice dressed up as a scheduling problem: the government has had a complete regulatory model (the EU AI Act) sitting right next to it as a template for three years and has pointedly declined to adopt anything resembling it, opting instead for a Bill whose actual content runs the opposite direction, toward deregulation and sandboxes rather than compliance obligations. The US’s delay is neither friction nor choice, it’s an active, unresolved fight between three branches and two levels of government, being fought out in real time in a federal courtroom over one specific state’s law, with no resolution in sight.
3. The Institutional Battles
Germany: a patchwork critique from an unexpected direction
The KI-MIG vote itself is the more interesting story than the bill’s substance. The governing coalition (CDU/CSU, SPD) passed it; the opposition against it was the AfD and the Greens together, an unusual pincer from opposite ends of the spectrum (reporting on Die Linke’s exact vote is inconsistent, with some accounts describing opposition and others an abstention). The AfD’s objection is unsurprising given the party’s general hostility to EU-derived regulation. The Greens’ objection is the one worth understanding, because it isn’t a rejection of AI regulation itself: Green spokesperson Franziska Brantner criticized the national implementation as “a patchwork,” warning of an architecture that would produce “slowdown and complication,” and summarized the government’s approach as having “a thousand directions… but no shared mission.” That’s a structural critique, not a substantive one, and it’s well founded: KI-MIG doesn’t just create a single AI regulator. It names the Bundesnetzagentur as the central authority, but also amends the Whistleblower Protection Act and the Financial Services Supervision Act, meaning AI oversight is genuinely split across BNetzA and Germany’s existing financial regulator (BaFin) rather than consolidated in one place. The Bundestag’s own committee seemed to partially concede the point, adding a requirement to evaluate the oversight structure itself at 18 months and again at 3 years after entry into force, and creating a new federal-state (“Bund-Länder”) AI coordination committee, an unusual admission, baked into the law itself, that the enforcement architecture might not work as designed.
The UK: regulation by whichever existing body gets there first
The UK has no AI regulator, no AI statute, and no single body with clear jurisdiction over AI harms. What it has instead is a set of pre-AI-era regulators stretching their existing powers to cover AI cases as they arise. The Information Commissioner’s Office brought new automated-decision-making rules (UK GDPR Articles 22A–22D) into force on 5 February 2026 and closed a consultation on further guidance on 29 May, with final guidance expected later in 2026. Ofcom, acting under the Online Safety Act 2023, a law written before generative AI chatbots existed in their current form, issued its second-ever fine under that Act in November 2025, against Itai Tech Ltd, operator of an AI “nudification”/deepfake site, for failing to implement mandatory age verification; in January 2026 it opened a formal investigation into an AI companion-chatbot service (Novi Ltd) over pornography age-assurance requirements, and separately opened an investigation into X’s Grok chatbot. None of these are AI-specific enforcement powers; they’re general online-safety and data-protection powers being applied to AI products because nothing more specific exists.
The “Regulating for Growth Bill,” announced in the 13 May 2026 King’s Speech, is the government’s actual answer to the AI-governance gap, and it runs in the opposite direction from Germany’s. Rather than creating obligations, it creates cross-economy “sandboxing powers” letting ministers temporarily suspend regulations so businesses can test AI products in real-world conditions, and gives regulators a statutory “growth duty” explicitly aimed at reducing what the government calls “unnecessary risk aversion.” It is, by design, a deregulatory instrument wearing the clothes of an AI governance bill: the first dedicated statutory AI framework the UK has produced since a non-binding 2023 White Paper, and its substance is permission to experiment rather than a requirement to comply.
The US: an executive branch litigating against its own Senate’s judgment
This is the sharpest institutional fight of the three, because it’s genuinely live and genuinely uncertain. On 1 July 2025, during a marathon “vote-a-rama” session on a budget reconciliation bill, the Senate voted 99–1 (only Senator Thom Tillis in favor of keeping it) to strip out a provision, championed by Senate Commerce Chair Ted Cruz, that would have imposed a ten-year moratorium on state AI regulation. The opposition was genuinely bipartisan: 17 Republican governors, 40 state attorneys general, and advocacy groups spanning the Heritage Foundation to the Center for American Progress all opposed the moratorium. The bill, without that provision, passed the Senate 51–50 (Vice President Vance breaking the tie), passed the House 218–214 two days later, and was signed into law on 4 July 2025.
Five months later, on 11 December 2025, President Trump signed Executive Order 14365, “Ensuring a National Policy Framework for Artificial Intelligence,” directing the Attorney General to build a task force to challenge state AI laws the administration considers unconstitutional or excessively burdensome, on Commerce Clause and federal-preemption grounds. The DOJ’s AI Litigation Task Force was formally established on 9 January 2026. In March 2026, the White House additionally released a “National AI Legislative Framework,” again asking Congress for statutory preemption, this time with carve-outs for child safety, AI data-center permitting, and state government use of AI, but the framework itself is non-binding and creates no compliance obligations on its own.
The task force’s first real target is Colorado’s SB24-205, “Consumer Protections for Artificial Intelligence,” a law requiring developers and deployers of high-risk AI systems to exercise reasonable care against algorithmic discrimination in decisions about education, employment, financial services, government, healthcare, housing, insurance, and legal services, complete with impact assessments and public disclosure duties. In early April 2026, xAI (developer of Grok) sued Colorado’s Attorney General, arguing the law violates the First Amendment (training an AI model is protected speech; the law compels editorial redesign), the Commerce Clause (it reaches conduct entirely outside Colorado), Due Process (its key terms are unconstitutionally vague), and Equal Protection (the law’s own carve-out for AI designed to redress historical discrimination is itself, in xAI’s telling, codified discrimination). On 24 April 2026, the DOJ intervened, the first time it has done so in a challenge to a state AI law, exercising exactly the authority Executive Order 14365 had directed it to build five months earlier. Three days later, the court granted a joint motion by xAI and Colorado’s own Attorney General suspending enforcement of the law entirely, pending both the outcome of Colorado’s 2026 legislative session and a ruling on xAI’s request for a preliminary injunction. The law’s effective date, already once pushed from 1 February to 30 June 2026, is now suspended with no ruling on the merits and no new date set.
Strip away the details and the shape of the story is genuinely unusual: an executive branch is actively litigating, through the DOJ and in partnership with a private company, against a state law, in pursuit of an outcome that the president’s own party’s Senate majority had explicitly and overwhelmingly rejected as legislation eighteen months earlier. Congress said no to preemption by statute. The executive is now trying to get to substantially the same place through Article II authority and a courtroom instead.
4. Domestic Impact Assessment
Germany
Social. KI-MIG’s most immediate real-world effect on ordinary users is the Article 50 transparency package landing on 2 August 2026: AI chatbots must clearly disclose that a user is talking to AI (a simple “Powered by AI” footer is explicitly considered insufficient), AI-driven emotion-recognition and biometric-categorization systems must be disclosed, and AI-generated content used in public communication, advertising, or political messaging must be recognizably labeled. That’s a comparatively light, disclosure-first touch on daily life, consistent with the fact that the harder substantive obligations (for high-risk Annex III and Annex I systems) were pushed out to 2027 and 2028 by the EU’s own Omnibus delay.
Economic. Penalty exposure is the same EU-wide ceiling, up to €35m or 7% of global turnover, regardless of whether a company is headquartered in Germany or merely serves German users, which puts real weight behind the disclosure duties even though the harder compliance regime hasn’t landed yet. The Bund-Länder AI Committee and the built-in 18-month and 3-year evaluation clauses signal that the government itself doesn’t expect the current institutional split (BNetzA plus BaFin plus the whistleblower-protection framework) to be the final word on cost and complexity.
Political. A coalition bill opposed by both the AfD and the Greens, for essentially opposite reasons (one hostile to EU regulation as such, the other unconvinced by this specific implementation’s coherence), is a useful reminder that “passed with a government majority” doesn’t mean “passed without a real critique.” The Greens’ argument, that the state should function as a “wise anchor customer” for AI rather than either a bureaucratic gatekeeper or an absent one, is a specific, articulated alternative theory of the state’s role that didn’t win but is now baked into the law’s own self-review clauses.
United Kingdom
Social. Because there’s no comprehensive UK AI statute, the practical protection an ordinary user gets against AI harms depends entirely on which pre-existing regulator happens to have jurisdiction over the specific product in question, data protection (ICO), online safety and age assurance (Ofcom), or financial conduct (FCA). Ofcom’s enforcement actions against a deepfake “nudification” site and an AI companion chatbot show the model can work reactively, but only after harm has already occurred and only where an existing statute happens to reach the conduct.
Economic. The “Regulating for Growth Bill’s” sandboxing powers are explicitly a business-facing measure: reduced regulatory friction for companies wanting to test AI products, with ministers empowered to temporarily suspend applicable rules. That’s a direct economic trade-off against Germany’s approach, lower compliance cost and faster time-to-market for UK-based AI development, against less certainty for users about what protections, if any, apply to a given product before something goes wrong.
Political. The government’s own framing, that AI should be regulated “at the point of use” by existing expert regulators rather than through dedicated legislation, is a deliberate, stated policy position, not an accident of a crowded legislative calendar, even though a dedicated AI Bill has been promised and deferred across three consecutive King’s Speeches. That consistency across delays suggests the deferral itself may be the policy.
United States
Social. For an ordinary AI user, protection today depends entirely on which state they live in, since no federal baseline exists and the one state law furthest along toward comprehensive AI-specific consumer protection, Colorado’s, is currently suspended by court order. A Colorado resident has, at this moment, materially less legal protection against algorithmic discrimination than the law that was supposed to be in force since February 2026 was designed to give them.
Economic. US AI companies face the most genuinely chaotic compliance picture of the three: EU AI Act obligations for any product reaching EU users, a live and shifting patchwork of state laws for domestic operations, and now a federal executive branch that may or may not eventually succeed in nullifying some of those state obligations through litigation whose outcome isn’t yet known. That’s not “less regulation” in any straightforward sense, it’s regulation whose content depends on the outcome of ongoing litigation, which is arguably harder to plan around than either Germany’s or the UK’s more settled (if very different) postures.
Political. The 99–1 Senate vote is the single most telling data point in this entire comparison: an idea (federal preemption of state AI law) was tested in the legislature first, and rejected by the legislature’s own governing-party majority, on genuinely bipartisan grounds, before the executive branch pursued a similar outcome by a different constitutional route. That sequencing, legislative rejection followed by executive workaround, is a specific and unusual shape for an institutional conflict to take.
5. The Compliance Reality
This is the dimension the earlier pieces in this series didn’t need, because immigration and VAT law don’t typically create overlapping, simultaneous obligations for the same multinational company the way AI regulation does.
The EU AI Act’s reach is extraterritorial by design: it applies to any provider placing an AI system on the EU market, or whose AI system’s output is used within the EU, regardless of where that provider is incorporated. A US company with EU users is bound by KI-MIG-enforced obligations whether or not the US ever adopts anything resembling them domestically, the so-called Brussels Effect operating exactly as intended. That means the practical floor for AI governance, for any company operating globally, is already set in Brussels and enforced through bodies like Germany’s Bundesnetzagentur, independent of what Washington or Westminster decide.
The squeeze is sharpest for US-based AI companies specifically, because they face three simultaneous and only partially compatible obligations: EU AI Act compliance for EU-facing operations, whatever state law currently applies domestically (itself unstable, as Colorado’s suspended law demonstrates), and a federal executive branch actively trying to invalidate some of those state obligations in court. A company like xAI is, right now, in the genuinely strange position of not knowing whether its own federal government will succeed in exempting it from a state law it is not currently required to follow anyway, because that law’s enforcement is suspended pending litigation the company itself brought.
UK-based operations sit in a comparatively calmer position precisely because so little is mandatory yet: fewer hard compliance dates, but correspondingly less certainty about which regulator might assert jurisdiction after the fact, and the added twist that the government’s own sandboxing regime invites exactly the kind of real-world experimentation that, if it goes wrong, is what Ofcom’s and the ICO’s reactive enforcement actions exist to catch after the fact.
6. Contextual Institutional Analysis
Stepping back, each jurisdiction has picked a different theory of where regulatory authority over AI belongs, and the three theories are close to mutually exclusive.
Germany’s theory: authority delegated upward. The domestic political fight, real as it was, was never about whether AI should be regulated, that was settled in Brussels in 2024, but about how well Germany’s own implementation vehicle distributes the resulting responsibility. The Greens’ “patchwork” critique is a complaint about execution, not about the underlying delegation of authority to the EU level, which no party in the Bundestag debate contested.
The UK’s theory: authority deliberately left diffuse. Rather than concentrating new authority anywhere, the UK has chosen, repeatedly and across multiple King’s Speeches, not to create a dedicated AI regulator or statute at all, preferring ad hoc jurisdiction by whichever existing regulator’s mandate happens to reach a given AI harm, backstopped by a new bill whose actual thrust is toward less friction for AI development, not more oversight of it.
The US’s theory: authority is contested, not settled. Unlike Germany (settled above the state) or the UK (deliberately left diffuse), the American fight is over who has the authority to decide at all, Congress, the states, or the executive branch, and that fight is being waged through litigation rather than resolved through ordinary lawmaking, precisely because ordinary lawmaking (the 99–1 vote) already produced an answer the executive branch didn’t accept.
What connects all three is that none of them represents a stable equilibrium. Germany’s institutional split between BNetzA and BaFin is already scheduled for review at 18 months. The UK’s non-decision is a decision that keeps needing to be re-made at every King’s Speech. And the US fight has an actual court date, an actual state legislative session, and an actual private company’s lawsuit all still pending, any one of which could reshape the picture before this piece is a year old.
Synthesis: Long-Term Viability
Germany’s approach is the most institutionally secure of the three, precisely because the underlying policy question was resolved at a level (the EU) below which no single member state can unilaterally reverse it. The genuine uncertainty is administrative, whether the BNetzA/BaFin split survives its own built-in 18-month review, not existential.
The UK’s approach is secure in a different, less comfortable sense: it’s secure because almost nothing has actually been decided yet. The “Regulating for Growth Bill” still has to pass, and even once it does, the underlying accountability gap, no single regulator responsible for AI harms as such, persists by design rather than by oversight. That’s a stable state only in the sense that indefinite deferral is, itself, a stable policy.
The US is the only one of the three with a hard, near-term test of viability already on the calendar: Colorado’s 2026 legislative session, whatever it produces, plus a federal court ruling on xAI’s preliminary injunction, will determine within months whether the executive branch’s litigation strategy can actually substitute for the legislative preemption Congress already refused to grant. If the DOJ succeeds in Colorado, expect the task force to move quickly against other states’ AI laws. If it fails, the administration will be left with an executive order and a legislative framework that, eighteen months after the Senate’s 99–1 vote, still hasn’t produced a single federal statute, and the patchwork of state law will remain the only real AI regulation the US has.
Sources: European Commission, Regulation (EU) 2024/1689 (the AI Act); Gibson Dunn, EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes; Deutscher Bundestag, Ja zur Durchführung der Verordnung über künstliche Intelligenz; Bundesregierung, KI-Verordnung beschlossen; DIP Bundestag, vorgang record, KI-MIG, GESTA Q006; Collective Brain, KI-MIG: Deutschlands neue KI-Behörde und was Unternehmen bis August tun müssen; IAPP, King’s Speech signals diffuse UK digital policy agenda, but no AI bill; Bird & Bird, AI in the King’s Speech 2026: Regulating for Growth Bill announced; Osborne Clarke, UK Regulatory Outlook May 2026: Artificial intelligence; The White House, Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence; US Senate Committee on Commerce, Senate Strikes AI Moratorium from Budget Reconciliation Bill in Overwhelming 99-1 Vote; EPIC, Senate Overwhelmingly Votes to Strike AI State Law Moratorium; Norton Rose Fulbright, X.AI sues, DOJ intervenes, enforcement of Colorado’s AI Act suspended; Jenner & Block, DOJ Joins xAI in Lawsuit Challenging Colorado AI Act.