Europe is widely seen as the leader on AI regulation. The EU has spent years building a comprehensive master plan in the form of the EU AI Act, while the US is often described as having no real AI guardrails at all. Yet in practice the opposite is true. US states are regulating AI faster than almost any legislative response to a new technology in history, and are taking an approach that may prove to be more effective than the EU's.

Since 2023, a tsunami of AI regulation has been building in the US. According to a recent SIA compliance report, there are already around 150 enacted AI laws on the books, with thousands more bills in motion. In the first three months of 2026 alone, states introduced more than 1,500 AI-related bills, an average of over 17 bills proposed every single day.

Meanwhile, the UK has no material AI regulation in the works, and the EU AI Act, the centerpiece of Europe's approach since 2021, is still not materially in effect anywhere, and its most recent timeline pushed the majority of its provisions back by another year and a half.

The shape of regulation between the two is also different. The EU AI Act is meant to be the one law to rule them all, a single horizontal framework covering every AI system across multiple sectors. Most US state laws do the opposite, each targeting a specific harm, sometimes within a single industry. For example, California's SB 1120 bars health insurers from letting AI make the final call on denying treatment. This approach of 'vertical' regulations may be better suited to risks that are themselves specific and vertical in nature.

The US is mounting the largest regulatory response to a new technology in history

Two years ago, AI regulation in the US barely existed. In 2023, fewer than 200 AI-related bills were introduced across all state legislatures combined, and most went nowhere.

In 2024 that changed sharply. Over 600 AI-related bills were introduced, and close to 100 were enacted into law. In 2025 the number nearly doubled again to around 1,200 across all 50 states. By March 2026, just three months in, 45 states had already introduced more than 1,500 AI-related bills, surpassing the entire 2024 total before the year was a quarter old. That is a pace of roughly 17 new bills every day.

There are so many laws, in fact, that tracking them is becoming a full-time job. This is why we recently launched The Warden Watch, the tracker AI regulation for hiring and HR, to help with this problem in our industry.

Europe's trajectory over the same period is the mirror image. The EU AI Act has been in development since 2021, five years of work on a single piece of legislation, and its most recent delay pushed the majority of its provisions back by another year and a half, continuing a pattern of missed deadlines. Five years in, the flagship of European AI regulation still does not meaningfully apply to anyone.

No major technology has ever been regulated this fast

The speed and volume coming out of US states is not just large, it is unprecedented against any previous wave of technological change.

Take the Industrial Revolution, for example, where automation reshaped entire industries and created large-scale harms, yet regulation crawled. In Britain, early child-labor laws in 1802 and 1819 had no enforcement and were widely ignored; it took until 1833 for the first factory inspectorate with real powers, and until 1844 for the first genuine health and safety act. The US was slower still, relying on a handful of state laws through the nineteenth century and not enacting federal labor protections until the Fair Labor Standards Act of 1938, roughly a century after Britain's first enforceable factory act.

The internet tells a similar story. The technologies that reshaped how we communicate and shop emerged in the 1990s, yet comprehensive US data protection remains a work in progress, and even the EU's GDPR did not arrive until nearly two decades after the commercial internet took off.

Set against either timeline, AI is different in kind as well as degree. Within a couple of years of AI entering mainstream use, US states have produced hundreds of enacted laws and thousands of proposed bills, addressing harms as they appear. The "Europe regulates, America does not" narrative misses this entirely: US states have not been slow, they have been faster than almost any legislataive response to a major technology shift in history.

The shape of AI regulation needs to fit the shape of AI risk

One of the greatest differences between the US state regulation and the EU is the way they are structured. The approach taken by each is, in my view, based on a fundamentally different premise about the nature of AI risk itself.

Most past technology shifts created horizontal risks, problems that look roughly the same regardless of industry. Data security is the classic example: the risk of your data being stolen is fundamentally similar whether the software serves healthcare, insurance, or HR. A small number of broad rules, applied across sectors, makes sense for that. Standards like SOC2 or ISO 27001 can be introduced with wide adoption to help mitigate this.

AI risk is vertical. The risk of an AI system denying someone a mortgage, misdiagnosing a patient, or screening out a qualified job candidate are not variations on a theme; they are different problems, with different stakeholders, metrics, and remedies, because AI does not just process information, it substitutes for human judgment and human labor. In that sense it has more in common with the automation of the Industrial Revolution than with the internet or cloud computing.

In my view, you cannot regulate a vertical risk with a horizontal law. You can write all the principles you want about fairness and transparency, but until you have defined what they mean specifically for hiring algorithms, or specifically for medical devices, you have written an aspiration, not a regulation.

Narrow, sector-specific laws fit AI better than one law to rule them all

The EU AI Act applies across all sectors, with eight industries, including employment, healthcare, and financial services, singled out as "high risk." But after five years of work, actual standards specifying what compliance means are nowhere in sight, and when standards do arrive, the plan is for one set to serve all of them.

Compare that to US state laws already in effect. For example, California's SB 1120 (the Physicians Make Decisions Act) bars health insurers from letting AI make the final call on denying or delaying treatment. Tennessee's ELVIS Act extends right-of-publicity protections to stop AI from cloning a performer's voice without consent. California's FEHA amendment makes it unlawful to use automated decision systems in discriminatory ways in employment and housing, and allows the presence or absence of bias testing to count as evidence in a claim.

None of these laws try to solve "AI risk" in the abstract. Each one identifies a specific, observable harm in a specific context and writes a rule to address it, and they are narrow by design, which turns out to be exactly what makes them workable and fast to produce.

What is striking is that this pattern emerged with no coordination, because no committee sat down and decided this is how AI would be regulated. State legislators saw concrete problems, such as deepfaked musicians, biased hiring tools, and insurers using AI to deny medical care, and wrote laws to address them. The result, highly specific, sector-anchored regulation arriving at high speed, is almost by accident exactly the right shape for this technology.

The patchwork problem, and what comes next

None of this means the current arrangement in US is complete or ideal. A system of narrow, sector-specific state laws carries real downsides. A company operating across all 50 states can face dozens of overlapping and sometimes inconsistent obligations covering the same activity, and simply tracking which rules apply where is a serious compliance burden.

That is partly why momentum has been building in Washington toward a federal framework. In December 2025 the White House signed an executive order aimed at curbing what it called an onerous patchwork of state AI laws, directing agencies to identify and challenge state rules deemed inconsistent with federal policy and pushing Congress toward a uniform standard. Earlier proposals for a blanket multi-year moratorium on new state laws failed to pass, and the order itself carves out categories such as child safety and state procurement. Whether any of this survives legal challenge, and how far agencies actually go, remains genuinely uncertain.

The critics raise a fair point about fragmentation, but I would frame the conclusion differently. The answer is not that the state-led approach has been a mistake. In my view, the signs so far suggest it has been closer to the right model than the EU's horizontal one. The more useful question is how to preserve what is working: fast, specific, locally responsive regulation tied to real harms, while adding a federal layer that reduces duplication rather than overriding the substance of what states are building.

The US has the opportunity to lead on AI governance

The headline numbers tell one story: the US has around 150 enacted AI laws and thousands more bills in motion, while Europe has essentially one, still mostly not in force. But the more important difference is the approach.

AI risk is vertical, taking a different form in every industry it touches, and the US, almost by accident, is building regulation to match that: narrow, often sector-specific laws, each aimed at a concrete harm and anchored in existing law. Europe bet on a single horizontal framework to cover everything at once, and is five years into discovering that AI may not fit that mold.

It is still early, and the picture could change. The federal government may yet override state action, and Europe may refine the EU AI Act into something that finally bites. But if the state-led approach holds up, and a federal layer eventually complements rather than replaces it, the US has a real chance to lead not just in AI adoption, but in AI governance too, arguably for the first time in its regulatory history.