EU AI Act vs. California SB 1047 vs. China Generative AI Measures
Side-by-side comparison of the world's three highest-profile AI regulations. Scope, obligations, transparency, enforcement, penalties, and timeline.
EU AI Act
European Union
Effective: Aug 2024 β Aug 2027 (phased)
Read full breakdown βCalifornia SB 1047
California, USA
Effective: Never β vetoed
Read full breakdown βChina Generative AI Measures
People's Republic of China
Effective: 15 Aug 2023
Read full breakdown β| Question | EU AI Act | California SB 1047 | China Generative AI Measures |
|---|---|---|---|
| Scope & coverage | |||
| What does it regulate? | All AI systems placed on the EU market or whose output is used in the EU β sorted into 4 risk tiers (unacceptable, high, limited, minimal). | Only 'covered models' β frontier foundation models trained with > 10^26 FLOPs or > $100M training cost, plus their derivatives over similar thresholds. | Public-facing generative AI services offered in mainland China (chatbots, image/video/text generators). |
| Who is the duty-bearer? | Both providers (developers) and deployers (users) of AI systems. Distinct obligations for each. | Developers of covered models only (no obligations on deployers). | Service providers offering generative AI to the public in China. |
| Extraterritorial reach? | Yes β applies to any provider whose system or output is used in the EU, regardless of where the company is based. | Limited β applies to developers doing business in California. | Applies to any service offered to users in mainland China, including via foreign providers. |
| Key obligations | |||
| Pre-deployment risk assessment? | Yes β risk management system (Article 9) for high-risk systems, plus conformity assessment before market. | Yes β written assessment for 'critical harms' (mass casualties, > $500M damages, critical infrastructure). | Yes β CAC security assessment + algorithm filing for services with 'public-opinion attributes'. |
| Documentation requirements? | Technical documentation per Annex IV, risk management records, post-market monitoring plan, data governance records. | Written Safety and Security Protocol covering testing, red-teaming, mitigation. Published with redactions. | Service agreement, algorithm filing, content-moderation records, security-assessment dossier. |
| Transparency to users? | Disclose AI interaction (chatbots), label AI-generated content (deepfakes) and synthetic media (Article 50). | Not directly β focused on developer-side safety, not user-facing transparency. | Label AI-generated images, video, and audio with visible marks plus embedded metadata identifiers. |
| Incident reporting? | Serious incidents reported to national authorities within 15 days (high-risk systems). | Safety incidents causing or likely to cause critical harm reported to CA Attorney General within 72 hours. | Illegal content incidents reported to CAC; ongoing obligations to monitor and take down. |
| Third-party audits? | Yes β notified-body conformity assessment for some high-risk systems (Annex III categories that require it). | Yes β independent third-party audit annually starting 2028. | Not explicitly β but CAC security assessment effectively serves a similar gating function. |
| Specific bans | |||
| Prohibited practices? | Social scoring, manipulative subliminal AI, exploitation of vulnerabilities, untargeted face-scraping, most real-time remote biometric ID in public spaces. | Not a 'bans' regime β operates via affirmative safety duties on covered models. | Generation of content that 'subverts state power', incites secession, or violates other prohibited categories. |
| Enforcement | |||
| Who enforces it? | National market-surveillance authorities + the new EU AI Office (for general-purpose AI). | California Attorney General would have had exclusive enforcement (now moot β vetoed). | Cyberspace Administration of China (CAC) + sectoral regulators (MIIT, MPS, etc.). |
| Maximum penalty? | Up to 7% of worldwide annual turnover OR β¬35M (whichever higher) for prohibited practices. Up to 3% / β¬15M for other violations. | Civil penalties up to 10% of training compute cost for first violation; 30% for subsequent. (Vetoed β not active.) | Warnings, fines (typically modest), service suspension, or revocation of operating permission. |
| Private right of action? | No β but individuals may complain to authorities, and the AI Liability Directive (in negotiation) may add civil routes. | No β exclusively AG enforcement. | No formal private right of action; complaints go through CAC channels. |
| Timeline | |||
| When does it take effect? | Phased: prohibitions Feb 2025 Β· GPAI Aug 2025 Β· high-risk Aug 2026 Β· final phase Aug 2027. | Never β vetoed by Governor Newsom on 29 Sept 2024. | Already in force (15 Aug 2023). |
Key takeaways
Different premises
The EU AI Act regulates based on the system's intended use and risk category. SB 1047 would have regulated based on training compute (a model-size threshold). China's Measures regulate based on whether the service is public-facing in China. Three fundamentally different regulatory hooks.
Only one of the three is binding on most companies right now
The EU AI Act is the most consequential globally β its phased timeline means high-risk obligations kick in 2 August 2026. China's Measures apply only if you operate in China. SB 1047 was vetoed, but its framework is shaping next-generation US proposals.
Compliance burden falls hardest in the EU
For a company building a hiring AI tool that operates in all three jurisdictions, the EU AI Act imposes the most extensive documentation, registration, and post-market monitoring duties. The China Measures focus more on content moderation and user verification. SB 1047 would have hit only the very largest model developers.
Not sure which of these applies to your situation?
Answer 5 quick questions and we'll match you to the AI regulations that apply to your jurisdiction, AI use case, and users.
Start the 60-second wizard βComparison updated 2026-05-17. Hand-curated by Regulations.ai β not legal advice. For specific compliance decisions, consult qualified counsel in the relevant jurisdiction.