Who investigates and regulates AI?

Updated 2026-07-15880 searches/moRanked #380 of 519· AI explained
Short answer

No single agency. The EU has the only comprehensive AI law — the AI Act, in force since August 1, 2024, enforced by the European Commission's AI Office plus national authorities, with fines up to €35 million or 7% of global turnover. The U.S. has no comprehensive AI statute; the FTC, other agencies and state attorneys general apply existing consumer-protection law.

Why — the first-principles explanation

The confusion is real, and it comes from a genuine split in regulatory philosophy.

The EU regulates the technology itself, by risk tier. The AI Act sorts systems into buckets: some practices are banned outright, some are "high-risk" and carry heavy obligations, general-purpose models get their own rules, and most everyday software is barely touched. Enforcement is two-headed. The European AI Office, a division inside the European Commission, supervises general-purpose AI models — it can investigate possible infringements, request information and measures from model providers, and demand corrective action. National authorities in each member state handle everything else. The penalties are tiered under Article 99: up to €35 million or 7% of worldwide annual turnover for banned practices, €15 million or 3% for breaching provider or deployer obligations, and €7.5 million or 1% for supplying misleading information — whichever is higher, with reductions for SMEs. The rollout is staged: prohibitions and AI literacy from February 2, 2025; general-purpose AI obligations and penalty rules from August 2, 2025; the bulk of the rules from August 2, 2026; high-risk system rules from December 2, 2027.

The U.S. regulates conduct, not technology. There is no comprehensive federal AI statute. Instead, existing law applies wherever AI shows up. The FTC is the most active federal player, using its authority over unfair or deceptive acts or practices — it launched "Operation AI Comply" on September 25, 2024, targeting false and exaggerated claims about AI products. The logic is unglamorous but sturdy: lying about what your AI does is just fraud, and fraud has been illegal for a century. Sector regulators do the same in their lanes — lending, housing, health. State attorneys general enforce state consumer-protection and privacy laws, and states have moved faster than Congress.

So "who investigates AI" depends on the harm, not the technology. Deceptive marketing → FTC. Discriminatory lending → financial regulators. Privacy → data protection authorities and state AGs. A banned AI practice in Europe → the AI Office or a national authority. This patchwork is a live political fight, not a settled system, and the EU itself agreed in May 2026 to simplify rules and extend some deadlines — so treat any specific date as provisional.

An example that makes it click

Think about who regulates a car. There isn't one "car agency." Safety standards come from one body, emissions from another, the ads from a consumer-protection regulator, the loan from a financial one, and the guy who ran a red light answers to the local cops.

The U.S. treats AI exactly like that: no AI agency, just every existing regulator covering AI in its own lane. The EU did the opposite — it wrote a single law about the vehicle itself, sorting it by how dangerous it is, and appointed a central office for the biggest engines.

How to do it

  1. Identify the harm, not the technology — that determines the regulator.
  2. Deceptive or exaggerated AI marketing claims in the U.S.: report to the FTC at reportfraud.ftc.gov.
  3. Discrimination in lending, housing or employment: the relevant sector regulator (e.g. CFPB, HUD, EEOC) — existing civil rights law applies regardless of whether a model made the decision.
  4. Privacy misuse of your data: your state attorney general, or the state privacy regulator where one exists.
  5. In the EU: the national market surveillance authority designated by your member state; for general-purpose AI models, the European Commission's AI Office.
  6. In Switzerland: the Federal Data Protection and Information Commissioner (FDPIC), which gained expanded duties and investigation powers under the revised FADP.
  7. For legal exposure in your own business, get advice from a qualified attorney — this is a fast-moving area and the deadlines have already shifted once.

Key facts

Infographic: Who investigates and regulates AI — short answer and key facts
Visual summary — Who investigates and regulates AI?
▶ The 60-second explainer (script)

There's no single AI regulator, and the reason is a real philosophical split. The EU regulates the technology. Its AI Act came into force August 1st, 2024 — the only comprehensive AI law anywhere. It sorts systems by risk: some practices banned outright, some high-risk with heavy duties, general-purpose models with their own rules. Enforcement is two-headed. The European AI Office, inside the Commission, supervises general-purpose models — it can investigate infringements and demand corrective action from providers. National authorities handle the rest. Fines under Article 99 go up to 35 million euros or 7% of worldwide turnover for banned practices, 15 million or 3% for other obligations. The U.S. does the opposite. No comprehensive federal AI law. Instead, existing law applies wherever AI shows up. The FTC is the most active player, using its authority over unfair or deceptive practices. It launched Operation AI Comply in September 2024, going after exaggerated AI claims. The logic is sturdy and boring: lying about what your product does is fraud, and fraud's been illegal for a century. Sector regulators cover lending and housing. State attorneys general cover consumer protection and privacy, and states have moved faster than Congress. So who investigates AI depends on the harm, not the technology. Deceptive ads, the FTC. Biased lending, financial regulators. Privacy, your state AG. One caution: this is a live political fight, not a settled system. The EU itself agreed in May 2026 to simplify its rules and shift some deadlines. Treat every date as provisional.

What authoritative sources say

European Commission — AI Act Service Desk: Timeline for the Implementation of the EU AI Actofficial — EU AI Act entered into force August 1, 2024; prohibitions and AI literacy from February 2, 2025; general-purpose AI obligations and national authority designation from August 2, 2025; majority of rules from August 2, 2026; high-risk rules from December 2, 2027. source ↗
European Commission — The European AI Officeofficial — The European AI Office is established within the European Commission, evaluates general-purpose AI models, investigates possible infringements, and can request information and measures from model providers. source ↗
EU Artificial Intelligence Act — Article 99: Penaltiesorg — AI Act Article 99 sets fines of up to €35,000,000 or 7% of total worldwide annual turnover for prohibited practices; €15,000,000 or 3% for provider/deployer obligations; €7,500,000 or 1% for supplying misleading information, whichever is higher. source ↗
Council of the EU — Artificial intelligence: Council and Parliament agree to simplify and streamline rulesofficial — The Council and Parliament agreed in May 2026 to simplify and streamline AI rules, including changes to deadlines. source ↗

People also ask

Is there a federal AI agency in the United States?

No. There is no comprehensive federal AI statute and no dedicated AI regulator. Existing agencies apply existing law to AI within their own jurisdictions, and state legislatures have moved faster than Congress.

Does the EU AI Act apply to American companies?

It can. The Act reaches providers placing AI systems on the EU market and, in cases, deployers whose output is used in the EU — regardless of where the company sits. If you serve EU users, get legal advice rather than assuming you're out of scope.

Where do I report an AI product that lied about what it does?

In the U.S., the FTC — that's the core of Operation AI Comply, which targets false, misleading and unsubstantiated AI claims under the FTC's unfair-or-deceptive-practices authority. Report at reportfraud.ftc.gov.

What are the biggest AI Act fines?

Up to €35 million or 7% of worldwide annual turnover — whichever is higher — for engaging in prohibited AI practices under Article 5. Other obligation breaches top out at €15 million or 3%. Small and medium enterprises face the lower of the two figures rather than the higher.

Are the AI Act deadlines final?

No. In May 2026 the Council and Parliament agreed to simplify the rules and extend some deadlines. As of 2026-07, treat published compliance dates as provisional and check the Commission's own timeline page.

Related questions