Washington is dismantling its own AI rulebook. Brussels is enforcing one. For a company that sells on both sides of the Atlantic, the divergence is not a reason to wait — it is the reason a European footing has become the deciding move.
For most of the last decade, the assumption in AI was that the rules would eventually converge. Two systems are now moving in opposite directions at once. The European Union has passed the most comprehensive AI law in the world and started enforcing it. The United States, having failed to pass a federal framework, is actively working to roll back regulation — including the state laws that filled the vacuum. That split is the subject of a growing literature; it is also a concrete operating problem for any company selling AI internationally.
The instinct, faced with contradictory signals from the two largest markets, is to wait for clarity. That instinct is wrong here, and understanding why starts with seeing what each side has actually done.
The EU AI Act — Regulation (EU) 2024/1689 — is not guidance, a framework or a set of principles. It is directly applicable law across all twenty-seven Member States, with a risk-tiered structure, real penalties and, crucially, extraterritorial reach. Its obligations attach to what is placed on the Union market, not to where the provider is incorporated. A model trained in California and served to European users is inside the Act's scope the moment it reaches those users.
The timetable is already running. Prohibited practices have applied since February 2025. Obligations for general-purpose AI model providers — including the duty of third-country providers to appoint an EU authorised representative — have applied since August 2025. The high-risk obligations were deferred to 2027–2028 by a 2026 simplification package, but the structural requirements did not move, and the GPAI track did not move at all.
The United States moved the other way. Attempts to legislate a federal framework failed; a proposed ten-year moratorium on state AI laws, attached to a 2025 budget bill, was stripped out on a 99–1 Senate vote. In its place came a deregulatory federal posture. On 11 December 2025, Executive Order 14365, "Ensuring a National Policy Framework for Artificial Intelligence," directed federal agencies to discourage and challenge state AI laws seen as onerous — conditioning certain federal funds, directing the FTC to clarify how existing law applies, and pressing for a lighter national touch.
But the states did not stand still. California's Transparency in Frontier AI Act and Texas's Responsible AI Governance Act both took effect on 1 January 2026, and the executive order expressly left lawful state laws — on child safety, infrastructure and government use — in place. The American picture, in other words, is not "no rules." It is contested rules: a federal government pulling one way, a patchwork of states pulling another, and genuine legal uncertainty about who prevails.
One directly applicable regulation, extraterritorial by design, with designated authorities and a published enforcement calendar. Predictable in shape, if demanding in substance.
No federal statute; an executive push to preempt state law; a live patchwork of state regimes. Lighter in aggregate, but unsettled and jurisdiction-by-jurisdiction.
Here is the trap. A US-based founder reads the American headlines — moratorium attempts, deregulation, an executive order against "onerous" rules — and concludes that the regulatory pressure is easing. For the US market, that reading may hold. For the European market, it is irrelevant. The AI Act does not ask where you are regulated at home; it asks whether your system is placed on the Union market. If it is, the Act applies in full, and a permissive US posture provides no shelter whatsoever.
This is the well-documented Brussels effect: because the EU regulates market access rather than companies, its rules reach anyone who wants European customers. The transatlantic divergence therefore does not create a choice between two regimes. For a company selling into Europe, it creates one unavoidable regime — the strict one — plus a home market that happens to be looser. You do not get to average them.
The opposite is true. A lighter US environment frees attention and budget — and the EU obligations, especially for GPAI providers, are already live. The deferral of the high-risk timetable to 2027 is a window to do the structural work calmly, not a reason to postpone it.
The AI Act, like the rest of EU product law, rests on one premise: for anything on the Union market, there must be a person established in the Union who answers for it. If your company has no EU establishment, that person does not exist yet. Creating it is a corporate decision, and there are two instruments — which you need depends on what you are actually doing in Europe.
The role you occupy under the Act — provider, deployer, importer, distributor — is a question of fact, and it drives everything downstream. That is exactly the kind of determination that is cheap to get right up front and expensive to unwind after contracts are signed.
Role and risk classification, the choice between an authorised representative and a Spanish entity, incorporation, tax activation and registration — carried as one file by one accountable team.
If a European footing is unavoidable, the question becomes where. Spain made an early, deliberate move: AESIA — the Agencia Espanola de Supervision de la Inteligencia Artificial, created by Royal Decree 729/2023 — was the first supervisory body in the EU dedicated specifically to AI, operational since 2024. While most Member States were still designating authorities, Spain already had a dedicated agency, published guidance and a regulatory sandbox.
Whatever Washington does to its own rulebook, selling AI into Europe means answering to Europe's. The companies that treat the 2027 window as time to build — rather than time to wait — will be the ones already established when the strict obligations arrive.