Abstract
This paper conducts a comparative doctrinal analysis of AI governance in three jurisdictions that have adopted fundamentally different regulatory philosophies: the European Union's binding, risk-tiered AI Act; the United States' sectoral and increasingly contentious federal-state patchwork; and India's principle-based, soft-law-first approach built around sectoral guidance and industrial capacity-building. Artificial intelligence has evolved from experimental technology to a routine input in decisions affecting employment, healthcare, and the legal system. Despite having different initial philosophies, the paper argues that all three jurisdictions have a structural weakness based on primary legislative instruments, regulatory developments through mid-2026, and relevant case law: none of them currently offers a clear, enforceable answer to who is liable when an AI system causes harm that does not neatly fit within existing legal categories. The report also identifies a second convergence: courts in all three jurisdictions are becoming more concerned with verifying AI-generated content rather than just regulating it. It concludes with specific recommendations for India, arguing that although the country's current soft-law approach is a deliberate and acceptable choice, a framework of settled responsibility cannot be permanently replaced by it.
Introduction
Background.
Significant choices that were previously solely made by human institutions include whether a loan is approved, if a job application is shortlisted, whether a defendant is granted bail, and increasingly, how a judge determines and summarizes precedent. These decisions now include artificial intelligence technologies. AI has shown to be an incredibly fast-moving target; a tool created in a year might become functionally obsolete in two. In the past, new technology has only been regulated after it has altered behavior. This lag isn't speculative. Over the past eighteen months, all three of the countries under examination have been forced to modify, postpone, or rethink their own AI governance measures due to litigation, industry opposition, or operational unpreparedness.
Research Question(s).
This study poses two connected questions. First, how do the fundamental philosophies of the US, EU, and India differ with regard to AI governance? Do they primarily see AI as a subject for binding ex ante regulation, sector-by-sector federalist discussion, or voluntary guidance in conjunction with industrial policy? Second, despite this divergence, do the three jurisdictions share comparable underlying problems in how they assign guilt for harm produced by AI?
Objective & Methodology.
Adopting a doctrinal and comparative methodology, the paper examines primary legal instruments (statutes, regulations, executive orders, and judicial decisions) supplemented by recent regulatory developments and secondary commentary. The analysis is current as of mid-2026 and focuses on each jurisdiction's binding and soft-law instruments rather than speculative future legislation. The goal is to go beyond a simple listing of each jurisdiction's AI-related instruments toward an evaluative comparison of their underlying regulatory logic and practical implications.
I. The European Union — Binding Regulation and Its Liability Gap
The European Union has pursued the most legislatively ambitious approach among the three jurisdictions. The EU Artificial Intelligence Act entered into force on 1 August 2024 and establishes a tiered, risk-based framework: practices posing an "unacceptable risk," such as social scoring by public authorities, are prohibited outright, applicable since 2 February 2025; "high-risk" systems, including those used in employment, education, credit scoring, and law enforcement under Annex III, face extensive obligations on risk management, technical documentation, and human oversight; and "limited-risk" systems, such as chatbots, face narrower transparency duties[1]. Obligations on providers of general-purpose AI models became applicable from 2 August 2025[2].
Even this framework has proven difficult to implement on schedule. Annex III high-risk obligations were originally due to take full effect on 2 August 2026, but delays in designating national competent authorities and finalising harmonised technical standards led the Commission to propose a "Digital Omnibus" amendment in November 2025[3]. Following political agreement on 7 May 2026, Annex III obligations have been deferred by sixteen months, to 2 December 2027, while obligations for high-risk systems embedded in regulated products (Annex I) move to 2 August 2028[4]. The delay corrects any assumption that comprehensive legislation, once enacted, translates smoothly into operative law; even the jurisdiction with the clearest statutory mandate has needed nearly two additional years to make its central obligations enforceable.
A more significant gap concerns liability rather than compliance. The Commission had proposed a companion AI Liability Directive in September 2022 to ease the burden of proof for individuals harmed by AI systems[5]. Unable to secure legislative agreement among Member States, the Commission formally withdrew the proposal in February 2025[6]. Fault-based liability for AI-caused harm a discriminatory hiring algorithm, a flawed diagnostic tool now depends entirely on the tort law of each of the twenty-seven Member States, undermining the harmonisation the AI Act was meant to deliver. Part of the gap is addressed indirectly: the revised Product Liability Directive, which Member States must transpose by 9 December 2026, extends strict product liability to software and AI systems classified as "products"[7]. But strict product liability and fault-based liability serve different claimants and different harms, and the withdrawal leaves discrimination, privacy, and purely economic-loss claims without a dedicated EU remedy. The European model is comprehensive at the level of ex ante compliance and considerably less settled at the level of ex post accountability.
II. The United States — A Contested Federal-State Patchwork
The United States does not have a comprehensive federal AI law. Rather, governance is the responsibility of general-purpose sectoral regulators, such as the Federal Trade Commission's jurisdiction over unfair and deceptive acts, current anti-discrimination legislation, and an increasingly controversial body of state laws. Federal executive policy has proven unpredictable in and of itself: President Biden's speech in October 2023 President Trump revoked Executive Order 14110 on AI safety on January 20, 2025. On December 11, 2025, President Trump issued a new order titled "Ensuring a National Policy Framework for Artificial Intelligence," directing the Department of Justice to establish an AI Litigation Task Force to challenge state AI laws as unconstitutional burdens on interstate commerce and instructing the FTC and FCC to adopt a "minimally burdensome" federal approach. The final text of the directive exempts some categories from preemption, such as child protection. Full federal preemption has been consistently and independently rejected by Congress, as seen by the National Defense Authorization Act and the "One Big Beautiful Bill Act." Despite ongoing federal pressure, state AI laws are currently legal since federal preemption usually requires congressional action rather than just an executive order. The Wisconsin Supreme Court held in State v. Loomis that the use of a proprietary recidivism-risk algorithm by a sentencing court did not violate due process as long as the tool's limits were acknowledged and it was not determinative.
The volatility this causes at the state level is exemplified by Colorado's experience. Modelled in part on the risk-based framework of the EU AI Act, the Colorado AI Act (SB 24-205) was the first complete state law governing "high-risk" AI systems used in significant choices, including employment, housing, credit, healthcare, and education. It was signed into law in May 2024. Since then, the date of its implementation has been postponed three times. The date was changed from February 1, 2026, to June 30, 2026, after a special legislative session failed. The AI firm xAI filed a lawsuit in April 2026 to prevent enforcement, and on April 27, 2026, a federal court halted enforcement while Colorado's Attorney General filed a lawsuit. agreeing not to enforce the statute until rulemaking concluded[8]. On 14 May 2026, Colorado's Governor signed SB 189, further postponing the effective date to 1 January 2027 while substantially narrowing the law's scope[9]. Within roughly two years of enactment, the same statute has been law, litigated, stayed, and rewritten leaving both regulated businesses and the individuals it was meant to protect without a settled rule. The American model is not an absence of regulation so much as a live, ongoing contest over which government gets to regulate at all.
III. India — Principle-Based Soft Law and Sectoral Patching
In India, there isn't a single AI law. Artificial intelligence-related behavior is governed by a number of general-purpose, technology-neutral laws, including the Information Technology Act of 2000, the Digital Personal Data Protection Act of 2023 and the Digital Personal Data Protection Rules of 2025, which impose a "consent-first" framework on "Data Fiduciaries" processing personal data, and the Bharatiya Nyaya Sanhita of 2023. The Digital India Act, which was intended to supersede the IT Act of 2000 and specifically address digital technology, including artificial intelligence, had not yet been passed as of mid-2026. Since 2023, it has been in draft form.
Due to the absence of legally required horizontal legislation, India's strategy has changed in two ways. The first is voluntary and principle-based: the India AI Governance Guidelines, which were introduced at the India AI Impact Summit in February 2026, list seven guiding principles and give voluntary self-certification and standards like ISO/IEC 42001 precedence over required compliance. The second is more targeted but still binding, focusing on specific injuries as they happen. On February 10, 2026, the Ministry of Electronics and Information Technology released revised IT Intermediary Guidelines, which went into effect on February 20, 2026. In order to prevent deepfakes and impersonation, these recommendations first include "synthetically generated information" (AI-generated text, images, audio, and video) in intermediaries' due-diligence requirements. Sectoral financial regulators have moved similarly: the Reserve Bank of India's FREE-AI Committee Report (2025) sets out twenty-six recommendations for responsible AI in banking and fintech, and the Securities and Exchange Board of India separately requires AI/ML system reporting from market intermediaries[10]. Alongside this sits substantial industrial policy: the IndiaAI Mission, backed by an outlay exceeding ₹10,372 crore, funds sovereign compute capacity, curated datasets, and an AI Safety Institute a sequencing in which capacity-building is prioritised ahead of binding regulation[11].
The judiciary has engaged with AI both as a subject of regulation and as a user of the technology, and the two roles are now converging. On 3 June 2026, the Supreme Court released Draft Regulations for the Use of Artificial Intelligence in Courts, 2026 for public consultation, confining tools such as SUPACE and SUVAS to assistive functions while withholding any decisional role from AI[12]. The draft rules follow documented incidents in which unverified, AI-generated case citations were relied upon in Indian proceedings; both Chief Justice Surya Kant and Justice B.V. Nagarathna have separately flagged instances of fictitious case references surfacing in court filings[13]. Running beneath all of this is Justice K.S. Puttaswamy (Retd.) v. Union of India, which recognised privacy as a fundamental right under Article 21 and is now regularly invoked despite predating the current AI debate as the constitutional foundation for arguments about algorithmic accountability and data protection[14]. India's overall posture is pro-innovation and techno-legal: comprehensive legislation is treated as a later-stage project, while soft law and sector-specific rules absorb the most urgent harms in the interim.
Findings / Discussion
Comparing the three jurisdictions reveals a genuine, not merely cosmetic, difference in regulatory thought. The European Union sees AI governance as primarily a matter of mandatory, ex ante, rights-based accountability, even in situations where implementation has fallen short of the statute's own objectives. The United States sees it as a live federalist contest, with the question being not what the regulation should say, but rather which government has the authority to create it at all. India views it as a sequencing issue, prioritizing local AI capability while postponing complete binding legislation and managing the most obvious problems through sectoral regulations and voluntary guidance.
The three jurisdictions share one structural flaw despite their disparate beginnings: none of them presently offer a precise, enforceable guideline for allocating liability when an AI system causes harm that does not cleanly fit into an established legal category. Fault-based claims are now subject to disjointed national tort law due to the demise of the EU's specific liability instrument. The case of Colorado demonstrates how the United States' response is contingent upon an unresolved federal-state struggle that may alter within a single legislative cycle. India lacks particular AI liability laws since it relies on fundamental tort and consumer protection principles that were not developed with autonomous decision-making in mind. There are three different ways to address a fundamentally similar accountability gap: sectoral patchwork, soft-law sequencing, and comprehensive regulation.
Judges and regulators in all three jurisdictions are grappling with a second-order issue: verifying the accuracy of what AI-generated legal text actually says, rather than just regulating AI as an external topic of law. Another, less researched convergence is this one. The occurrence of judicial hallucinations in India is the most prominent example, although the same problem exists in every jurisdiction this paper examines.
Conclusion
Regarding the legal framework for artificial intelligence, the United States, India, and the European Union have all reached quite different conclusions: binding regulation, contested federalism, and principled soft law, respectively. None of these tactics are obviously wrong; rather, they all reflect valid institutional and political constraints. The distinction between regulatory philosophy and regulatory completeness is highlighted by the comparison: even the most comprehensive regulation may fall short in addressing basic accountability concerns. India's current soft-law position has a short lifespan but is a legitimate, deliberate choice rather than the product of inertia. As AI systems are increasingly incorporated into critical decision-making, the absence of a clear responsibility framework will be harder to justify as transitory and more likely to be seen as permanent.
References
[1]European Commission, "AI Act," Shaping Europe's Digital Future, digital-strategy.ec.europa.eu, accessed July 2026.
[2]Ibid.
[3]DLA Piper GENIE, "The Digital AI Omnibus: Proposed Deferral of High Risk AI Obligations Under the AI Act," knowledge.dlapiper.com, updated 2026.
[4]Morgan Lewis, "EU Approves Delays and Other Amendments to Certain EU AI Act Obligations: What Businesses Should Know," morganlewis.com, 24 June 2026.
[5]LegalClarity, "AI Liability Directive: What It Was and Why It Was Withdrawn," legalclarity.org, 1 June 2026.
[6]IAPP, "European Commission Withdraws AI Liability Directive From Consideration," iapp.org, 28 May 2026.
[7]LegalClarity, supra note 5 (discussing Directive (EU) 2024/2853).
[8]StateScoop, "Colorado Attorney General to Delay Enforcing AI Law After xAI Lawsuit," statescoop.com, 29 April 2026.
[9]Hunton Andrews Kurth, "Colorado AI Act Amended and Effective Date Delayed," hunton.com, 22 May 2026.
[10]Regulations.ai, supra note 15 (FREE-AI Committee Report and SEBI reporting circular).
[11]Regulations.ai, supra note 15 (IndiaAI Mission outlay and AI Safety Institute).
[12]The Cyber Blog India, "The Draft Court Rules on AI: Human Primacy, Data Privacy, and Institutional Infrastructure," cyberblogindia.in, 22 June 2026.
[13]Ibid.
[14]Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 (India).