AI policy moves fast, and the headlines rarely explain how the pieces fit together. One week brings a new state law, the next a lab’s safety announcement, the next an international summit declaration. To understand AI risk news, it helps to have a map: what the main risks are, which tools governments use to manage them, and where the major jurisdictions stand.
This guide provides that map. It is written for general readers, founders and professionals who need a clear overview, not legal advice. Laws and deadlines change, so we date-stamp our analysis and link to official sources where possible. For the latest developments, see our AI Risk & Policy News section.
Last reviewed: September 29, 2026.
The main categories of AI risk
The International AI Safety Report, a scientific review backed by dozens of governments, groups the risks of general-purpose AI into three families. It is a helpful lens for reading any AI news story.
Malicious use
People deliberately using AI to cause harm. Examples include fraud and impersonation scams, non-consensual intimate deepfakes, disinformation campaigns, AI-assisted cyberattacks, and the possibility that advanced models could provide meaningful help to someone attempting to build biological or chemical weapons. Much of the current policy attention on frontier models focuses on these last two areas.
Malfunctions
AI systems failing without anyone intending harm: confident false answers, biased decisions in hiring or lending, unreliable behavior in safety-critical settings, and, at the extreme end, advanced systems acting in ways their operators cannot control. Our guide to AI safety and alignment explains why these failures happen.
Systemic risks
Broader effects of deploying AI across society, such as labor-market disruption, concentration of power among a few companies or countries, privacy erosion, strains on energy and water, and dependence on systems few people understand.
How governments manage AI risk
Governments use a mix of tools, and most countries combine several:
- Comprehensive, risk-based laws that set rules according to how risky an AI use is (the EU’s approach).
- Voluntary frameworks and standards that describe good practice without legal force (for example, NIST’s frameworks in the United States).
- Targeted laws on specific harms, such as deepfakes, election content or frontier model transparency.
- Existing regulators applying consumer protection, privacy, anti-discrimination and product safety law to AI.
- Government AI safety or security institutes that test models and build evaluation science.
- International agreements that coordinate principles, research and testing across borders.
The European Union: the AI Act
The EU AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive AI law. It entered into force on 1 August 2024 and applies in stages. It sorts AI uses into risk tiers:
- Unacceptable risk (prohibited): practices such as social scoring by public authorities, manipulative techniques that cause significant harm, and certain uses of biometric identification. Prohibitions have applied since 2 February 2025.
- High risk: AI used in areas such as employment, education, credit, essential services, law enforcement, migration, critical infrastructure and safety components of regulated products. These systems face requirements for risk management, data quality, documentation, human oversight, accuracy and robustness.
- Transparency obligations: for example, people must be told when they are interacting with a chatbot, and certain AI-generated or manipulated content must be labeled or marked.
- Minimal risk: most other AI uses, with no specific new obligations.
The Act also sets rules for general-purpose AI (GPAI) models, such as the large models behind popular chatbots. These obligations have applied since 2 August 2025, with additional duties for models deemed to pose systemic risk. A voluntary GPAI Code of Practice, published in July 2025, offers providers one way to demonstrate compliance.
Timeline change in 2026. The EU’s Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on 27 July 2026 and deferred most high-risk obligations: to 2 December 2027 for stand-alone high-risk systems listed in Annex III, and to 2 August 2028 for high-risk AI embedded in products covered by Annex I. The amendments also added new prohibitions on AI systems that generate non-consensual intimate imagery or child sexual abuse material. Other parts of the Act continue on their own schedules. Check the European Commission’s AI Act page for the current official position.
The United States: frameworks, agencies and state laws
The US has no comprehensive federal AI law. Instead, policy comes from several directions:
- NIST frameworks. The voluntary AI Risk Management Framework, released in January 2023, is widely used by companies as a governance baseline, alongside a Generative AI Profile published in 2024.
- Executive policy. Federal priorities have shifted between administrations. A broad 2023 executive order on AI safety was revoked in January 2025, and federal policy has since emphasized AI innovation and competitiveness. The US AI Safety Institute at NIST was reorganized in 2025 as the Center for AI Standards and Innovation (CAISI).
- Existing law. Agencies continue to apply consumer protection, civil rights and sector-specific rules to AI products.
- State laws. States have become the most active source of new AI rules. California’s Transparency in Frontier Artificial Intelligence Act (SB 53), signed in September 2025, requires large frontier AI developers to publish safety frameworks and report certain critical safety incidents, and adds whistleblower protections. Colorado passed a broad law on algorithmic discrimination in 2024, though its start date has been pushed back. Many states have passed narrower laws on deepfakes, election content and AI in specific sectors. There is an ongoing federal debate about whether national rules should override state laws.
The United Kingdom
The UK has favored a “pro-innovation” approach that relies on existing sector regulators rather than a single AI law. It created the world’s first government AI safety institute in 2023, renamed the AI Security Institute in February 2025, which evaluates advanced models and publishes research on evaluation methods.
China
China has adopted a series of targeted regulations, including rules on recommendation algorithms, “deep synthesis” (deepfakes), and interim measures for generative AI services that took effect in 2023. Rules requiring labels on AI-generated content took effect in September 2025. Providers of public-facing generative AI services must meet security assessment and registration requirements.
International coordination
- AI summits. The UK’s Bletchley Park summit (November 2023) produced the Bletchley Declaration on frontier AI risks. The Seoul summit (May 2024) produced the Frontier AI Safety Commitments, under which leading companies pledged to publish safety frameworks. France hosted the AI Action Summit in February 2025, and India hosted the AI Impact Summit in February 2026, each broadening the agenda toward adoption and inclusion.
- International AI Safety Report. An independent scientific assessment led by Yoshua Bengio, first published in January 2025, summarizing evidence on the capabilities and risks of general-purpose AI.
- OECD and G7. The OECD AI Principles (adopted in 2019 and updated in 2024) and the G7 Hiroshima AI Process code of conduct for advanced AI developers set shared expectations.
- United Nations. In 2025 the UN General Assembly agreed to create an Independent International Scientific Panel on AI and a Global Dialogue on AI Governance.
- Network of safety institutes. Government AI safety and security bodies from several countries coordinate on testing methods and research.
How company safety frameworks fit in
Much of the day-to-day governance of frontier AI still happens inside companies, through published safety frameworks that define dangerous capability thresholds and the safeguards required before a model is deployed. Laws like California’s SB 53 and the EU’s GPAI rules increasingly require those frameworks to exist and be followed. We explain how they work in our guide to how AI labs approach safety.
How to read AI risk news critically
When a new AI policy story breaks, ask:
- What kind of instrument is it? A binding law, a proposal, an executive action, a voluntary commitment, or a company blog post? They carry very different weight.
- Who does it apply to, and when? Many laws apply only to certain companies, uses or regions, and often phase in over years.
- What does it actually require? Look for concrete obligations such as testing, disclosure, reporting or penalties, rather than broad principles.
- Who enforces it? A rule without an enforcer or penalties works differently from one with both.
- What is the evidence behind the risk claim? Distinguish demonstrated harms, credible expert concerns and speculation.
We apply these questions in every news analysis we publish, such as our coverage of California’s oversight plans and the push for global standards.
What this means for you
For individuals, new rules mean more disclosure about when you are interacting with AI or viewing AI-generated content, and more channels to challenge automated decisions in some jurisdictions. For businesses, the practical steps are similar everywhere: inventory where you use AI, classify risk, document your systems, keep humans in the loop for consequential decisions, and follow a recognized framework. Developers can start with our guide to responsible AI for developers. And when choosing AI tools, our AI tool safety reviews explain what protections to look for.
Frequently asked questions
What is the EU AI Act?
The EU AI Act is the European Union’s comprehensive AI law. It entered into force in August 2024 and applies in phases, banning certain AI practices, setting strict requirements for high-risk uses, imposing transparency duties, and regulating general-purpose AI models.
When do the EU AI Act’s high-risk rules apply?
After the Digital Omnibus amendments that entered into force in July 2026, most high-risk obligations apply from 2 December 2027 for stand-alone Annex III systems and from 2 August 2028 for AI embedded in regulated products. Always check the European Commission’s official guidance for the latest dates.
Does the United States have a federal AI law?
Not a comprehensive one. US AI governance relies on voluntary NIST frameworks, executive policy, existing consumer protection and civil rights law, and a growing number of state laws such as California’s SB 53.
What are frontier AI safety commitments?
At the Seoul AI summit in May 2024, leading AI companies agreed to publish safety frameworks describing how they assess and manage severe risks from their most capable models, including thresholds at which they would not deploy a model without adequate safeguards.
Is AI regulation slowing down innovation?
The evidence is contested. Supporters argue clear rules build trust and adoption, while critics warn of compliance costs, especially for smaller companies. Many recent policy changes, including the EU’s 2026 deadline deferrals, try to balance these concerns.
Sources
Primary sources used for this guide, checked on September 29, 2026. Policies and products change, so always check the latest version at the source.
- International AI Safety Report, independent scientific assessment, first published January 2025
- Regulation (EU) 2024/1689 (the AI Act), EUR-Lex, official text
- AI Act: regulatory framework for AI, European Commission (check here for the current timeline)
- The General-Purpose AI Code of Practice, European Commission
- AI Risk Management Framework, NIST
- Generative AI Profile (NIST AI 600-1), NIST, July 2024 (PDF)
- Center for AI Standards and Innovation (CAISI), NIST
- SB 53: Transparency in Frontier Artificial Intelligence Act, California Legislative Information
- SB24-205: Consumer Protections for Artificial Intelligence, Colorado General Assembly
- UK AI Security Institute, UK government
- The Bletchley Declaration, GOV.UK, November 2023
- Frontier AI Safety Commitments, AI Seoul Summit 2024, GOV.UK
- OECD AI Principles, OECD.AI
- Hiroshima Process International Code of Conduct for Advanced AI Systems, G7, published by the European Commission
Latest AI risk and policy news
- AI Risk News This Week: California Oversight Plans and a Push for Global StandardsAI risk news analysis: California’s move toward independent oversight of advanced AI and OpenAI’s call for shared international safety standards, and what it means.

