Regulators, AI offices, and safety institutes

Lesson 3 of 5 in Who’s Who in AI Governance: Actors, Roles, and Responsibilities.

No country invented an “AI police” from scratch. Each jurisdiction answered the same design question — who should enforce AI rules? — differently, and the answer tells you how that jurisdiction thinks about AI. The core split is horizontal vs. sectoral: one dedicated regulator for AI as such, or the existing regulators (banking, medicines, aviation, consumer protection) each policing AI inside their patch. Nobody chose purely one; everyone mixes.

EU

Horizontal law, layered enforcement. The EU AI Office (inside the European Commission) supervises general-purpose AI models directly and coordinates the regime; each member state designates national competent authorities and market surveillance authorities to enforce the AI Act on the ground; notified bodies handle third-party conformity assessment; the European Artificial Intelligence Board coordinates the member states. Existing sectoral regulators (medical devices, machinery, financial supervision) keep their lanes — the AI Act plugs into them rather than replacing them.

US

No horizontal AI statute — existing powers plus state law. The FTC pursues unfair and deceptive AI practices (its Rite Aid facial-recognition order banned the company’s use of the tech for five years); the EEOC applies employment-discrimination law to hiring algorithms; sectoral regulators (FDA, CFPB, banking supervisors) cover their domains; state attorneys general enforce the new state AI laws (Colorado, Texas). NIST is deliberately non-regulatory — it writes frameworks and standards, not fines. The result: enforcement exists, but you assemble it from a dozen agencies rather than reading one statute.

UK

Empower existing regulators. The 2023 white paper chose principles (safety, transparency, fairness, accountability, contestability) applied by existing regulators — the ICO, FCA, CMA, MHRA and others — rather than a new AI act. The Digital Regulation Cooperation Forum coordinates them. The bet: sector regulators know their contexts better than any new horizontal body could. The cost: gaps between the patches, and no single duty-holder register.

China

A powerful central internet regulator moving rule by rule. The Cyberspace Administration of China (CAC) has issued targeted, binding instruments in quick succession: Algorithm Recommendation Provisions (2022), Deep Synthesis Provisions (2023), Interim Measures for Generative AI (2023), and AI content-labeling measures (2025) — each with registration and filing duties that give the state a live inventory of deployed algorithms. Vertical, fast, and enforcement-ready, with information control as a central objective alongside safety.

Alongside the regulators, a newer species appeared after 2023: the AI safety institute. These are not enforcement agencies. Born from the Bletchley summit wave, they are technical bodies that evaluate frontier models, do safety research, and feed standards — the state building its own capacity to test what companies claim. The UK’s AI Security Institute (renamed from AI Safety Institute in 2025) was first; the US created its counterpart inside NIST; Japan, Singapore, Korea, Canada and the EU (via the AI Office) followed, and they coordinate through an international network of AI safety institutes launched at the Seoul summit in 2024.

Why they matter to you: safety institutes are where pre-deployment testing of frontier models actually happens under government auspices — several frontier labs grant them early model access under voluntary agreements. They are the closest thing AI has to the state test-pilot corps aviation built a century ago.

Key terms: AI Office, national competent authority, safety institute, horizontal regulation, sectoral regulation

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.