
UpTrajectory Review
Henna Virkkunen, the EU's tech chief, has offered a striking reframing of transatlantic AI governance: the US and Europe are converging on similar protections, but through entirely different mechanisms. Where Brussels writes rules in advance through the AI Act, Washington lets courts and state legislatures do the work piecemeal. Virkkunen made this case at the G20 innovation ministerial in South Africa, the same summit where the US unveiled the Carolina Principles—a document urging governments globally to avoid creating new AI regulations. The tension is hard to miss: American officials are actively lobbying against the very approach Virkkunen represents, even as she insists the outcomes will align.
For small-business operators, this divergence in method matters enormously. If you serve customers on both sides of the Atlantic, you are already navigating the EU's risk-based AI Act tiers—prohibited, high-risk, limited risk, minimal risk—with compliance costs that favor larger players who can afford legal teams and conformity assessments. The US patchwork, by contrast, means you might face Colorado's algorithmic discrimination law, California's pending bills, Illinois's biometric rules, or common-law liability emerging from jury verdicts, all without a unified federal framework. Virkkunen's optimism about convergence offers cold comfort when your actual compliance burden is bimodal: prescriptive in Europe, unpredictable in America.
What is genuinely contested here is whether court-driven and state-driven regulation actually produces equivalent protections. Virkkunen's claim is diplomatically convenient for Brussels, which has faced sustained criticism that the AI Act stifles innovation while the US lets tech companies run loose. But the equivalence is questionable. Litigation is reactive, slow, and accessible mainly to those with resources to sue. State legislation creates a compliance maze that small businesses struggle to navigate. The Carolina Principles themselves—launched at the very summit where Virkkunen spoke—represent an explicit US government effort to discourage other nations from following Europe's regulatory path. That is not convergence; it is competition over regulatory models.
The second-order effects ripple outward in ways neither Virkkunen nor her American counterparts emphasized. For AI startups seeking investment, the US patchwork creates uncertainty that venture capitalists price into term sheets. For EU-based companies hoping to enter the US market, the absence of federal rules does not mean freedom—it means fifty potential regulatory regimes plus an evolving body of tort law. Meanwhile, developing nations at the G20 face a genuine dilemma: adopt Brussels-style frameworks and risk alienating US trade relationships, or wait for American courts and hope for the best. The Carolina Principles are not neutral technical guidance; they are a soft-power push to freeze regulatory development elsewhere.
What to watch: whether the incoming US administration softens or hardens the anti-regulatory stance embodied in the Carolina Principles, and whether any state—California most likely—moves aggressively enough to create a de facto national standard by market weight. For operators, the practical move is to build compliance architecture around the EU AI Act's risk tiers now, as that framework is the most detailed and likely to influence whatever emerges elsewhere. Document your AI use cases, assess risk levels, and maintain audit trails. If Virkkunen is right about convergence, that preparation will serve you in American courts too. If she is wrong, you will at least have one coherent system mastered rather than none.
Virkkunen's argument deserves skepticism. Convergence through different mechanisms is not convergence if the mechanisms produce different timetables, different certainty, and different distributions of compliance cost. Small businesses know this intuitively: a rule you can read and implement is not the same as a lawsuit you might face someday. The EU's approach has genuine flaws—overbreadth, slow adaptation, barriers to entry—but the American alternative is not a planned alternative at all. It is an accident waiting to happen, with the accidents litigated after the damage. For operators, the lesson is to prepare for the rulebook that exists, not the one diplomats wish into being.
“the US and the EU keep arriving at similar AI protections, Europe by regulating in advance and America through courts and state law” — The Next Web
Takeaway: Build your AI compliance around the EU AI Act's risk tiers now—it's the most detailed framework and will likely influence whatever emerges elsewhere.
Excerpt from the original — The Next Web
Henna Virkkunen told Axios at the G20 innovation ministerial that the US and the EU keep arriving at similar AI protections, Europe by regulating in advance and America through courts and state law. She made the argument at the summit where Washington launched the Carolina Principles urging governments not to create new AI rules or […]
This story continues at The Next Web …