
In June 2025, Anton Carniaux, Microsoft's legal director in France, appeared before a committee of the French Sénat and admitted that Microsoft could not guarantee that data held in Microsoft's cloud inside France would remain beyond the reach of U.S. authorities. The exchange, reported widely in the French press, settled a question that years of vendor marketing had bypassed. Data can be stored in one country while remaining subject to another country's jurisdiction. And so what then began as a debate about data sovereignty in France, quickly widened into a broader question about artificial intelligence, given how much data and cloud infrastructure underpins the modern AI economy.
Three distinct approaches have since come to define the global conversation, represented by the European Union, the United States and China. Each begins from a different answer to the same question: how to hold authority over artificial intelligence?
In the case of Europe, AI is treated as a product that must be shown to be safe before it reaches the market. A principle that's thoroughly codified in the EU AI Act. The higher the risk an AI system poses, the more evidence its provider must produce before deployment. Evidence for this includes showing technical documentation, conformity assessments, human oversight and ongoing monitoring. The regulator's intent in this case is to prevent harm before it occurs rather than respond after the fact.
China begins from a different premise. Its concern is less whether an AI system is safe to sell than whether its output is acceptable to the state. Rules governing generative AI, deep synthesis and recommendation algorithms require providers to label AI-generated content and ensure it does not produce material that conflicts with state policy or what Beijing calls its "core socialist values". If Europe regulates the product itself, China regulates what the product is allowed to say.
The United States has traditionally taken the opposite approach. Rather than regulating AI comprehensively before deployment, it has largely allowed innovation to move ahead while intervening when specific risks emerge. Which resulted in a patchwork of executive orders and state laws rather than a single federal doctrine. California's proposed SB 1047, the most ambitious attempt to regulate frontier AI models, was vetoed in 2024, while narrower transparency measures such as training-data transparency requirements were adopted.
None of the three approaches is without its critics. In the case of the European approach, supporters see it as innovation with responsibility, arguing that trust is a competitive advantage rather than a constraint. Critics argue that the approach asks companies to satisfy regulators before they have had the chance to satisfy the market, raising compliance costs at precisely the stage when young firms need speed, experimentation and investment. The debate then is not whether AI should be governed, but how to prevent governance itself from becoming the constraint: how to establish clear boundaries for genuine harms while preserving the freedom to experiment, compete, and build.
China’s model attracts a different criticism. Its ability to align regulation, industrial policy and national strategy has helped create AI champions at remarkable speed. Critics argue, however, that competition is difficult when the state is both regulator and strategic participant. Questions about market access, reciprocity and state support increasingly accompany discussions about AI capability itself.
The American model has generated extraordinary innovation and attracted unparalleled private investment, but it also draws the opposite criticism of Europe's. Waiting for harm to emerge can leave governments and societies trying to solve problems only after the technology has become deeply embedded. So the question is not whether regulation arrives, but whether it arrives too late.
Each of the three models reflects a legitimate concern. And each also creates a blind spot. Europe’s companies already face a pervasive regulatory environment, risk slowing innovation in the pursuit of safety, while rivals in the US and China exploit the value of speed, are able to experiment sooner, deploy faster, and learn from failure before competitors have even cleared the regulatory process. The United States risks discovering harms only after they become widespread. China risks self-isolation by subordinating technological progress to total political control.
The contrast between Europe, the United States and China is therefore about more than regulation. It is about three competing answers to the question of who should shape the future of AI. For companies operating across all three, the challenge is no longer simply building better AI. It is understanding the rules, values, and ambitions that will determine where and how AI can thrive.