US vs EU AI Regulation in 2026: Why the Divergence Matters for Your Stack
Last reviewed: 8 July 2026
On 2 June 2026, President Trump signed Executive Order 14409, titled "Restoring American Leadership in Artificial Intelligence Through Regulatory Restraint." The order revoked the residual oversight provisions of EO 14110 (the Biden AI order that had already been partially rescinded on 20 January 2025), disbanded the AI Safety Institute's mandatory red-teaming programme, and shifted federal AI policy to a voluntary pre-release review model administered by NIST.
Sixty days later, on 2 August 2026, the EU AI Act's GPAI obligations become enforceable, carrying administrative fines of up to 3% of global annual turnover.
This is the widest transatlantic regulatory divergence on any technology issue since the 1998 Safe Harbor negotiations. It is not a temporary asymmetry that will close through negotiation — the underlying political drivers on both sides make convergence unlikely before 2028 at the earliest. For European organisations that depend on US-provided AI services, the divergence changes the risk calculus in specific, measurable ways.
This article analyses the divergence at three levels: what each regime now actually requires, how the difference propagates through a European SaaS buyer's stack, and where the practical compliance load has shifted.
The US Position After Executive Order 14409
EO 14409 does three concrete things. First, it revokes Section 4.2 of the residual EO 14110, which had required foundation model developers to notify the Department of Commerce when training runs exceeded 10^26 FLOPs and to share safety evaluation results. Second, it disbands the AI Safety Institute's mandatory red-teaming pilot, converting it into an opt-in advisory service. Third, it directs federal agencies to "identify and rescind" AI-related regulatory guidance that "impedes American AI leadership," with a 180-day reporting deadline.
The order does not touch sector-specific AI regulation — the FDA's Software as a Medical Device framework, the CFPB's fair-lending model risk guidance, the EEOC's guidance on AI in hiring, and state-level laws (Colorado AI Act, California AB 2013, New York City Local Law 144) all remain in force. The federal preemption question that AI industry lobbyists have pushed for is not addressed by the order, though a bill along those lines is expected in the autumn 2026 legislative window.
The net effect is a federal posture that former FTC Chair Lina Khan characterised as "the regulatory equivalent of removing the seatbelt requirement." US foundation model developers no longer have mandatory federal obligations relating to model evaluations, training-data disclosure, or systemic risk assessment. They may voluntarily continue existing practices — and most have publicly committed to doing so — but voluntary commitments are not enforceable by federal authorities.
For European buyers, the significant point is that US regulatory activity no longer produces the evidence base that European compliance depends on. Documentation that European deployers would previously have sourced from US federal filings must now be sourced directly from the vendors or from EU-side documentation prepared for AI Act compliance.
The EU Position After the Digital Omnibus
The Council's Digital Omnibus package, agreed on 29 June 2026, revised several AI Act timelines but reaffirmed the core enforcement architecture. GPAI obligations under Articles 53 and 55 take effect on 2 August 2026 as originally scheduled. High-risk AI system obligations under Article 6 and Annex III were deferred to 2 December 2026. Product-safety-integrated AI obligations under Annex I move to 2 August 2027.
The Omnibus also introduced two substantive changes. It clarified that "training compute" for Article 51 systemic-risk classification includes fine-tuning compute above 10^24 FLOPs, closing a loophole that would have exempted fine-tuned variants of frontier models. And it granted the AI Office authority to issue provisional enforcement orders — including temporary market suspension — without waiting for national court proceedings, subject to a 30-day AI Board review.
The EU regime that will be in force from August 2026 is therefore not only unchanged in substance but slightly strengthened in enforcement teeth. Combined with the 24 April 2026 EDPB guidelines on the interaction between GDPR Article 22 automated-decision-making rules and AI Act deployer obligations, the European stack now has a coherent, layered, and enforceable AI governance regime with clear jurisdictional reach into US-headquartered providers whenever those providers place models on the EU market.
Article 2(1)(c) is the extraterritorial hook: the AI Act applies to providers established in a third country that place AI systems on the Union market or whose output is used in the Union. API access from EU IP addresses is placement. This is a wider extraterritorial reach than GDPR's Article 3 and closer to the extraterritorial scope US privacy advocates opposed when GDPR was drafted.
How the Divergence Propagates Through Your Stack
The practical consequence of the divergence is that documentation and evidence burdens shift downstream. This propagation happens in four steps.
**Step 1 — Upstream evidence gap.** US model providers no longer produce federally mandated documentation. Voluntary documentation continues (OpenAI system cards, Anthropic model cards, Google model cards) but is not standardised or externally verifiable in the way that AI Safety Institute evaluations were.
**Step 2 — Bilateral documentation demand.** European deployers requiring Article 53 evidence must request it directly from providers. The GPAI Code of Practice provides a template, but only for signatories. For non-signatories, the request is bilateral and the response quality varies. AI Office guidance of 12 June 2026 explicitly permits deployers to rely on Code of Practice signatory documentation as sufficient, but requires "equivalent evidence" for non-signatory models.
**Step 3 — SaaS vendor pass-through.** Layer 2 SaaS vendors that embed US-provided models are the pinch point. They must either (a) obtain documentation from upstream providers and pass it through to European customers, or (b) accept downstream provider classification under Article 25 and produce equivalent documentation themselves. Most vendors are choosing option (a) for signatory models and quietly de-emphasising features that depend on non-signatory models.
**Step 4 — European buyer inherits the residual risk.** Where the pass-through breaks — because upstream documentation is thin, the vendor's contractual warranties are weak, or a model swap happens without notification — the deployer carries the risk. Article 99 fines apply to deployers as well as providers, and the AI Office has been clear that "we relied on our vendor" is not a defence when the underlying non-compliance was reasonably discoverable.
The overall effect is that the compliance load which US regulation would previously have absorbed at the source now sits on European buyers. Empirically this shows up as a 30–50% increase in AI-related vendor questionnaire volume reported by European CIOs surveyed by the CIONET-Deloitte AI Governance Pulse of June 2026.
Where This Changes Procurement Decisions
The divergence changes procurement in four measurable ways, all of which favour signatory and European providers at the margin.
**Signatory bias.** GPAI Code of Practice signatory status now carries evidentiary weight that non-signatory status does not. This creates a structural preference for signatory models (OpenAI, Anthropic, Google, Mistral, Microsoft, IBM, Cohere, Aleph Alpha) over non-signatory alternatives (Meta Llama, xAI Grok for chapters beyond safety, DeepSeek, Qwen). The preference is not absolute — non-signatory models remain lawful to deploy — but it shifts the burden of proof.
**Jurisdictional weighting in vendor scoring.** European organisations that previously treated jurisdiction as a nice-to-have differentiator are now treating it as a risk-adjusted cost input. A US-jurisdictioned model requires more documentation collection, more contractual scrutiny, and carries higher residual regulatory risk than an EU-jurisdictioned equivalent. In vendor scoring rubrics, this appears as a 5–15 percentage point handicap.
**Contractual restructuring.** MSA templates are being rewritten. The 2026 standard clauses include (a) AI Act compliance warranties covering embedded models, (b) 30-day notification of material model changes, (c) indemnification for AI Office fines arising from upstream non-compliance, and (d) audit rights covering AI Act documentation. Vendors resisting these clauses are being systematically deprioritised in renewal cycles.
**Sovereign AI positioning.** Mistral, Aleph Alpha, and Silo AI are actively positioning as sovereign alternatives with full Code of Practice signatory documentation. Their pricing has risen 15–25% since Q1 2026 as demand has outpaced European AI compute capacity. This is a market signal that the divergence is being priced in.
None of these shifts is a wholesale rejection of US AI. It is a re-weighting of risk that reflects the actual regulatory topology in force from August 2026 onward.
Why Convergence Is Unlikely Before 2028
Three structural factors make transatlantic AI regulatory convergence unlikely in the medium term, and each has independent staying power.
**Political mandates.** The Trump administration has an explicit deregulatory mandate that extends through January 2029. The European Commission's von der Leyen II mandate runs through 2029 with a clear commitment to AI Act implementation. Neither side has electoral incentive to reverse course before 2028.
**Institutional lock-in.** The EU AI Office reached full operational headcount (approximately 200 staff) in Q2 2026 and has committed enforcement resources aligned to a multi-year work programme. On the US side, the disbanding of the AI Safety Institute has dispersed the institutional expertise that would be required to rebuild federal oversight quickly. Institutional reconstruction is slow.
**Underlying regulatory philosophy.** The EU AI Act reflects a risk-based, ex ante regulatory philosophy consistent with GDPR, DSA, and DORA. EO 14409 reflects an ex post, market-driven philosophy consistent with the broader US regulatory posture. These are not surface disagreements — they are foundational differences in how the two jurisdictions conceptualise the appropriate relationship between the state and emerging technology markets.
For European buyers, the operational implication is that the compliance investments required for August 2026 are not transitional. They are the new baseline for the remainder of the decade. Building AI governance capacity that assumes eventual EU-US alignment is a mispricing of risk. The prudent working assumption is durable divergence, with the compliance centre of gravity firmly in Brussels.
Key Takeaways for Technical Leaders
- •EO 14409 (2 June 2026) removed mandatory US federal AI oversight and shifted to a voluntary model
- •The EU AI Act begins GPAI enforcement on 2 August 2026 with fines up to 3% of global turnover
- •Documentation and evidence burdens shift downstream to European SaaS buyers when US regulation retreats
- •GPAI Code of Practice signatory status now functions as a structural preference in European procurement
- •AI-related vendor questionnaire volume has increased 30–50% for European CIOs since the divergence became clear
- •Convergence is unlikely before 2028 due to political mandates, institutional lock-in, and philosophical differences
Applied Reading
See how these concepts apply in practice:
- AuditGDPR Considerations in SaaS Selection
- AuditSlack Sovereignty Analysis: A Complete Assessment
- AuditAWS and European Digital Sovereignty
- ComparisonEuropean Alternatives to AWS for Startups
- ComparisonOpenAI vs Anthropic: AI Model Sovereignty and Enterprise Risk
- MigrationBuilding an EU-First Tech Stack
- MigrationMigrating from OpenAI to Mistral: An EU-First AI Transition Guide
Audit your technology stack
This guide covers one topic. Your Technology Stack Audit scores your entire technology stack as one system, ranks what to fix first, and maps how your tools depend on each other. One-off €99.
Audit my technology stack — €99