EU and US AI rules move further apart
President Trump revoked EO 14110 on January 20, 2025, ending the federal compute-based reporting trigger and shifting US policy away from mandatory AI oversight. The replacement approach emphasizes removing barriers to development, federal procurement rules, cybersecurity expectations and challenges to state AI laws viewed as burdensome.
Colorado has become the clearest test case for that strategy. Its original AI Act, SB 24-205, was stayed before taking effect after an xAI lawsuit and DOJ intervention, then repealed and replaced by SB 26-189, a narrower automated decision-making law effective January 1, 2027. The rewrite removed mandatory impact assessments and eliminated the NIST and ISO 42001 safe harbor as a codified legal defense.
The EU AI Act remains a binding risk-based regime, with GPAI obligations already applicable since August 2, 2025 and enforcement powers starting August 2, 2026. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on July 27, 2026 and moved the main standalone high-risk deadline to December 2, 2027, with embedded high-risk systems due August 2, 2028. GPAI-specific fines can reach the greater of €15 million or 3% of global annual turnover, while the most serious breaches can reach €35 million or 7% of global annual turnover.