Who investigates and regulates AI?
No single agency. The EU has the only comprehensive AI law — the AI Act, in force since August 1, 2024, enforced by the European Commission's AI Office plus national authorities, with fines up to €35 million or 7% of global turnover. The U.S. has no comprehensive AI statute; the FTC, other agencies and state attorneys general apply existing consumer-protection law.
Why — the first-principles explanation
The confusion is real, and it comes from a genuine split in regulatory philosophy.
The EU regulates the technology itself, by risk tier. The AI Act sorts systems into buckets: some practices are banned outright, some are "high-risk" and carry heavy obligations, general-purpose models get their own rules, and most everyday software is barely touched. Enforcement is two-headed. The European AI Office, a division inside the European Commission, supervises general-purpose AI models — it can investigate possible infringements, request information and measures from model providers, and demand corrective action. National authorities in each member state handle everything else. The penalties are tiered under Article 99: up to €35 million or 7% of worldwide annual turnover for banned practices, €15 million or 3% for breaching provider or deployer obligations, and €7.5 million or 1% for supplying misleading information — whichever is higher, with reductions for SMEs. The rollout is staged: prohibitions and AI literacy from February 2, 2025; general-purpose AI obligations and penalty rules from August 2, 2025; the bulk of the rules from August 2, 2026; high-risk system rules from December 2, 2027.
The U.S. regulates conduct, not technology. There is no comprehensive federal AI statute. Instead, existing law applies wherever AI shows up. The FTC is the most active federal player, using its authority over unfair or deceptive acts or practices — it launched "Operation AI Comply" on September 25, 2024, targeting false and exaggerated claims about AI products. The logic is unglamorous but sturdy: lying about what your AI does is just fraud, and fraud has been illegal for a century. Sector regulators do the same in their lanes — lending, housing, health. State attorneys general enforce state consumer-protection and privacy laws, and states have moved faster than Congress.
So "who investigates AI" depends on the harm, not the technology. Deceptive marketing → FTC. Discriminatory lending → financial regulators. Privacy → data protection authorities and state AGs. A banned AI practice in Europe → the AI Office or a national authority. This patchwork is a live political fight, not a settled system, and the EU itself agreed in May 2026 to simplify rules and extend some deadlines — so treat any specific date as provisional.
An example that makes it click
Think about who regulates a car. There isn't one "car agency." Safety standards come from one body, emissions from another, the ads from a consumer-protection regulator, the loan from a financial one, and the guy who ran a red light answers to the local cops.
The U.S. treats AI exactly like that: no AI agency, just every existing regulator covering AI in its own lane. The EU did the opposite — it wrote a single law about the vehicle itself, sorting it by how dangerous it is, and appointed a central office for the biggest engines.
How to do it
- Identify the harm, not the technology — that determines the regulator.
- Deceptive or exaggerated AI marketing claims in the U.S.: report to the FTC at reportfraud.ftc.gov.
- Discrimination in lending, housing or employment: the relevant sector regulator (e.g. CFPB, HUD, EEOC) — existing civil rights law applies regardless of whether a model made the decision.
- Privacy misuse of your data: your state attorney general, or the state privacy regulator where one exists.
- In the EU: the national market surveillance authority designated by your member state; for general-purpose AI models, the European Commission's AI Office.
- In Switzerland: the Federal Data Protection and Information Commissioner (FDPIC), which gained expanded duties and investigation powers under the revised FADP.
- For legal exposure in your own business, get advice from a qualified attorney — this is a fast-moving area and the deadlines have already shifted once.
Key facts
- The EU AI Act entered into force August 1, 2024. Prohibitions and AI literacy provisions applied from February 2, 2025; general-purpose AI obligations and penalty rules (Articles 99–100) from August 2, 2025; the majority of rules from August 2, 2026; high-risk system rules from December 2, 2027.
- AI Act Article 99 fines: up to €35,000,000 or 7% of total worldwide annual turnover for prohibited practices (Article 5); €15,000,000 or 3% for provider/deployer/transparency obligations; €7,500,000 or 1% for supplying incorrect or misleading information — whichever is higher, reduced for SMEs.
- The European AI Office sits within the European Commission and can evaluate general-purpose AI models, investigate possible infringements, and request information and measures from model providers.
- The United States has no comprehensive federal AI statute; regulation runs through executive orders, existing agency enforcement, and state laws.
- The FTC announced Operation AI Comply on September 25, 2024, targeting false, misleading and unsubstantiated claims about AI products under its authority over unfair or deceptive acts or practices.
- In May 2026 the Council and Parliament agreed to simplify and streamline EU AI rules, including timeline changes — meaning specific compliance dates remain subject to change as of 2026-07.
▶ The 60-second explainer (script)
There's no single AI regulator, and the reason is a real philosophical split. The EU regulates the technology. Its AI Act came into force August 1st, 2024 — the only comprehensive AI law anywhere. It sorts systems by risk: some practices banned outright, some high-risk with heavy duties, general-purpose models with their own rules. Enforcement is two-headed. The European AI Office, inside the Commission, supervises general-purpose models — it can investigate infringements and demand corrective action from providers. National authorities handle the rest. Fines under Article 99 go up to 35 million euros or 7% of worldwide turnover for banned practices, 15 million or 3% for other obligations. The U.S. does the opposite. No comprehensive federal AI law. Instead, existing law applies wherever AI shows up. The FTC is the most active player, using its authority over unfair or deceptive practices. It launched Operation AI Comply in September 2024, going after exaggerated AI claims. The logic is sturdy and boring: lying about what your product does is fraud, and fraud's been illegal for a century. Sector regulators cover lending and housing. State attorneys general cover consumer protection and privacy, and states have moved faster than Congress. So who investigates AI depends on the harm, not the technology. Deceptive ads, the FTC. Biased lending, financial regulators. Privacy, your state AG. One caution: this is a live political fight, not a settled system. The EU itself agreed in May 2026 to simplify its rules and shift some deadlines. Treat every date as provisional.
What authoritative sources say
People also ask
Is there a federal AI agency in the United States?
No. There is no comprehensive federal AI statute and no dedicated AI regulator. Existing agencies apply existing law to AI within their own jurisdictions, and state legislatures have moved faster than Congress.
Does the EU AI Act apply to American companies?
It can. The Act reaches providers placing AI systems on the EU market and, in cases, deployers whose output is used in the EU — regardless of where the company sits. If you serve EU users, get legal advice rather than assuming you're out of scope.
Where do I report an AI product that lied about what it does?
In the U.S., the FTC — that's the core of Operation AI Comply, which targets false, misleading and unsubstantiated AI claims under the FTC's unfair-or-deceptive-practices authority. Report at reportfraud.ftc.gov.
What are the biggest AI Act fines?
Up to €35 million or 7% of worldwide annual turnover — whichever is higher — for engaging in prohibited AI practices under Article 5. Other obligation breaches top out at €15 million or 3%. Small and medium enterprises face the lower of the two figures rather than the higher.
Are the AI Act deadlines final?
No. In May 2026 the Council and Parliament agreed to simplify the rules and extend some deadlines. As of 2026-07, treat published compliance dates as provisional and check the Commission's own timeline page.