Core thesis
We keep talking about AI as software.
Governments are starting to regulate it as power.
AI is no longer just a productivity tool sitting inside a browser. It is being connected to:
- robots that move through physical spaces
- drones that film, map, and collect data
- connected vehicles that know where people go
- government systems that affect benefits, tax, migration, health, policing, and services
- hiring, lending, education, and insurance decisions
- synthetic media that can manipulate trust
- critical infrastructure and national security systems
Different countries are using different legal tools, but the pattern is the same:
AI is being judged by what it can affect in the real world.
The practical question is no longer only:
Is this model intelligent?
It is:
Where does it operate, what does it control, what does it collect, who can influence it, and who is accountable when it goes wrong?
1. United States: AI, robots, drones and connected systems are becoming national-security issues
1.1 The US has restricted foreign-produced advanced robotic devices
The US has added foreign-produced advanced robotic devices to the FCC Covered List.
This includes categories such as:
- humanoid robots
- four-legged or quadruped robots
- other mobile advanced robotic systems
Plain English version:
The US is not treating some robots as ordinary gadgets anymore.
It is treating them as mobile sensor platforms that can:
- move through buildings
- map spaces
- collect video, audio, location, LiDAR, thermal, and environmental data
- receive software updates
- connect to cloud systems
- potentially be remotely accessed or disrupted
This does not mean the US has banned every robot from entering America.
The nuance matters:
- the restrictions focus on certain foreign-produced advanced robotic devices
- new models may need FCC authorisation before they can be imported, marketed, or sold
- existing or previously authorised devices may not be automatically affected
- conditional authorisation may still be possible in some circumstances
The concern is not just that the robot can walk. It is that the robot can see, map, record, transmit, update, and act inside real-world spaces.
Official sources:
- FCC Covered List:
- FCC FAQs: robots and inverters:
- FCC robotics national security determination PDF:
- FCC fact sheet PDF:
1.2 The US has also restricted certain foreign-produced drones and drone components
Foreign-produced uncrewed aircraft systems, commonly called drones, and critical drone components have also been added to US national-security restrictions.
Plain English version:
A drone is not just a flying camera.
It can:
- film from the air
- map infrastructure
- track location and movement
- collect operational data
- inspect sensitive sites
- connect to remote systems
- be updated or controlled through software
That makes drones part of the same regulatory pattern as robots.
Governments are starting to see drones as flying sensor platforms, not consumer toys.
Official sources:
- FCC Covered List:
- FCC fact sheet PDF:
1.3 The US is regulating connected vehicles because cars are now data platforms
The US Department of Commerce / Bureau of Industry and Security has rules around connected vehicles.
The concern is that connected vehicles combine:
- sensors
- cameras
- software
- location data
- communications systems
- remote updates
- physical-world control
Plain English version:
A modern connected vehicle is not just transport.
It is a rolling computer with cameras, microphones, maps, communications systems, and software that can influence movement.
Once a machine can collect data, connect to networks, and move through the physical world, governments start asking who controls it.
Official source:
- BIS connected vehicles:
1.4 US federal AI policy is shifting toward AI leadership, infrastructure and national security
The US federal AI policy direction changed in 2025.
The White House released America’s AI Action Plan in July 2025.
A January 2025 Executive Order, Removing Barriers to American Leadership in Artificial Intelligence, revoked and reoriented some previous Biden-era AI policy.
Plain English version:
The US is trying to move fast on AI while also protecting national security.
Its focus includes:
- AI leadership
- deregulation and innovation
- data centres and infrastructure
- export controls
- national security
- competition with strategic rivals
- maintaining American technological advantage
The US wants to accelerate AI, but it also wants to control who gets access to the most powerful systems and supply chains.
Official sources:
- White House: America’s AI Action Plan:
https://www.whitehouse.gov/releases/2025/07/white-house-unveils-americas-ai-action-plan
- Federal Register: Removing Barriers to American Leadership in Artificial Intelligence:
- NIST AI Risk Management Framework:
1.5 US states are creating their own AI rules
Because the US does not have one single federal AI Act, state laws matter.
Two important examples are Colorado and California.
Colorado: high-risk AI and algorithmic discrimination
Colorado passed SB24-205, focused on high-risk AI systems and algorithmic discrimination.
Plain English version:
If AI is used to make or influence important decisions about people, companies need to manage the risk of unfair outcomes.
Official source:
- Colorado SB24-205:
California: generative AI transparency and training data
California has passed laws around generative AI transparency and training data disclosure.
Plain English version:
California is pushing companies to be clearer about:
- what data was used to train generative AI systems
- whether content was AI-generated
- provenance, labelling, and disclosure around synthetic content
Official sources:
- California AB 2013 bill text:
https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB2013
- California SB 942 bill page:
https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942
- California SB 53 bill text:
https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53
In the US, AI regulation is becoming a patchwork: federal national-security controls plus state-level rules on harm, transparency, discrimination, and synthetic media.
2. European Union: the EU AI Act regulates AI by risk
The EU has created one of the most comprehensive AI laws in the world: the EU AI Act.
The EU approach is risk-based.
Plain English version:
The EU does not treat every AI system the same.
It asks:
How much harm could this system cause?
Then it applies stronger rules as the risk increases.
Official sources:
- EU AI Act official text:
- European Commission AI regulatory framework:
https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- European Commission prohibited AI practices guidance:
2.1 The EU bans some AI practices outright
The EU AI Act prohibits certain AI uses considered unacceptable.
These include categories of AI that can seriously threaten rights, autonomy, privacy, safety, or democratic trust.
Plain English version:
Some AI uses are not just risky. The EU says they should not be allowed.
Examples include certain forms of:
- manipulative or deceptive AI
- exploitation of vulnerable people
- social scoring-like systems
- certain biometric identification or categorisation uses
- systems that undermine fundamental rights
The EU is drawing a line between “AI that needs rules” and “AI that should not be used this way at all.”
2.2 High-risk AI is allowed, but heavily governed
High-risk AI can be used, but organisations must meet stricter obligations.
High-risk contexts may include areas such as:
- employment
- education
- law enforcement
- migration
- critical infrastructure
- access to essential services
- health and safety-related uses
Plain English version:
If AI can meaningfully affect someone’s life, the EU wants proof that it has been tested, documented, monitored, and governed.
High-risk AI obligations can include:
- risk management
- data governance
- technical documentation
- record keeping
- transparency
- human oversight
- accuracy and cybersecurity requirements
- monitoring after deployment
In Europe, high-risk AI is not banned. But you need to be able to show your work.
2.3 General-purpose AI models have obligations too
The EU AI Act also covers general-purpose AI.
This matters because foundation models can be used across many downstream products and sectors.
Plain English version:
A model provider cannot say, “We just built the engine. We are not responsible for how anyone uses it.”
The EU is creating obligations for powerful model providers too.
If your AI model becomes infrastructure for everyone else, governments will start treating you like infrastructure.
2.4 The EU can impose significant penalties
The EU AI Act includes serious fines for non-compliance.
Plain English version:
This is not just guidance. It is enforceable law.
Europe is turning AI ethics into compliance.
3. Australia: AI is not covered by one single AI Act yet — but rules are tightening
Australia does not currently have a single EU-style AI Act that covers every AI system.
Instead, Australia is building AI control through a mix of:
- voluntary AI safety standards
- proposed mandatory rules for high-risk AI
- privacy law
- government AI-use policies
- automated decision-making reforms after Robodebt
- criminal law for AI-generated sexual deepfakes
- critical technology and supply-chain security rules
Plain English version:
Australia is not saying, “AI is banned.”
Australia is saying:
If AI affects people’s rights, services, privacy, safety, government decisions, or national security, you need stronger governance, transparency, accountability, and human oversight.
That matters because Australia is moving in the same direction as the EU and US, but in a more staged, consultation-heavy way.
3.1 Australia has a Voluntary AI Safety Standard
Australia released a Voluntary AI Safety Standard to help organisations use AI safely and responsibly.
It includes 10 guardrails for organisations that develop, deploy, or use AI.
Plain English version:
If a business uses AI, it should be able to explain:
- who is responsible for it
- what risks it creates
- what data it uses
- how it is tested
- whether a human can intervene
- whether people are told AI is being used
- whether people can challenge decisions
- whether suppliers are transparent
- whether records are kept
- whether fairness, bias, and harm have been considered
This is voluntary for now, but it reads like a preview of future regulation.
Official sources:
- Voluntary AI Safety Standard:
https://www.industry.gov.au/publications/voluntary-ai-safety-standard
- The 10 guardrails:
https://www.industry.gov.au/publications/voluntary-ai-safety-standard/10-guardrails
Australia is giving businesses a checklist before it gives them a rulebook.
3.2 Australia is considering mandatory guardrails for high-risk AI
The Australian Government has consulted on mandatory guardrails for AI in high-risk settings.
This is the important bit.
Low-risk AI, like summarising notes or drafting content, is unlikely to be heavily regulated.
But high-risk AI — AI used in hiring, healthcare, education, banking, government services, policing, safety, or other consequential decisions — is where mandatory rules are likely to appear.
Plain English version:
Australia is moving toward:
The more impact AI has on someone’s life, the more rules it should have.
Examples of high-risk AI could include systems that influence:
- whether someone gets a job
- whether someone gets a loan
- whether someone gets access to government support
- whether a patient is prioritised
- whether a student is assessed
- whether someone is flagged as a risk
- whether a business or person is investigated
Official source:
- Mandatory guardrails for safe and responsible AI:
https://www.industry.gov.au/news/mandatory-guardrails-safe-and-responsible-ai-have-your-say
Australia is not trying to regulate every chatbot. It is trying to regulate AI when the consequences become serious.
3.3 Australian Government agencies have their own AI-use policy
The Australian Government has a Policy for the Responsible Use of AI in Government.
This applies to many Commonwealth government entities and creates mandatory requirements around responsible AI use.
Government agencies need things like:
- accountable officials
- transparency statements
- AI use-case registers
- staff training
- impact assessments
- clear governance
- risk-based controls
Plain English version:
If government uses AI, it should not be hidden in the background.
There should be a person responsible for it, a record of how it is used, and an assessment of the risks.
Official source:
- Policy for the responsible use of AI in government:
If AI is helping government make decisions, government needs to know where it is, who owns it, what risk it creates, and how it is being checked.
3.4 Australia has a national AI assurance framework for government
Australia also has a National Framework for the Assurance of Artificial Intelligence in Government.
This is a joint Australian, state, and territory government framework.
It is about making sure AI used by government is:
- ethical
- safe
- lawful
- transparent
- accountable
- properly assessed
Plain English version:
This is less about “can we use AI?” and more about “how do we prove the AI system is fit for purpose?”
Official source:
- National framework for the assurance of AI in government:
Assurance means government should not just trust the AI tool. It should verify it.
3.5 Robodebt changed the Australian conversation around automated decisions
Australia’s AI and automation rules are heavily shaped by the Robodebt Royal Commission.
Robodebt was not “generative AI” in the ChatGPT sense, but it showed what can happen when automated systems are used in government services without enough fairness, transparency, legal safeguards, or human accountability.
The Attorney-General’s Department consulted on reforms for automated decision-making in government.
Plain English version:
Australia learned the hard way that automated decisions can cause real harm when people cannot understand, challenge, or correct them.
This is directly relevant to AI.
Official sources:
- Automated Decision-Making Reform consultation:
- OAIC submission on automated decision-making by government:
Robodebt is Australia’s warning label for automated government decisions.
Useful line for content:
The lesson from Robodebt is simple: if a system can affect a person’s life, someone human must still be accountable for it.
3.6 Australian privacy law already applies to AI
AI systems that collect, use, store, disclose, or train on personal information must comply with Australia’s Privacy Act 1988.
The OAIC has made it clear that organisations cannot just use personal information for AI because it is convenient.
Important points:
- personal information is broad
- sensitive information usually needs consent
- Australia does not have a broad “legitimate interests” excuse like Europe
- “de-identified” data can still carry re-identification risk
- organisations need to think about privacy early, not after the AI product is built
Plain English version:
If your AI uses people’s data, privacy law already matters.
You cannot treat training data like free raw material just because it is available.
Official source:
- OAIC: Can personal information be used to develop or train GenAI?
In Australia, personal data does not become harmless just because it is being used by AI.
3.7 Australia has criminal law for AI-generated sexual deepfakes
Australia passed the Criminal Code Amendment (Deepfake Sexual Material) Act 2024.
This strengthens offences around the non-consensual sharing of sexual material, including material created or altered using AI.
Plain English version:
If someone creates or shares sexually explicit AI-generated material of another person without consent, that can be a criminal issue.
This is one of the clearest examples of Australia regulating AI by harm, not by technology type.
Official sources:
- Parliament of Australia bill page:
- Attorney-General’s Department fact sheet:
https://www.ag.gov.au/crime/publications/fact-sheet-police-non-consensual-sharing-sexual-material
- eSafety image-based abuse information:
The law is not focused on whether the image is “real”. It is focused on the harm caused when sexual material is created or shared without consent.
3.8 Australia treats AI, robotics, autonomy, and related technologies as critical technologies
Australia has a national-interest lens around critical technologies.
This includes areas such as:
- artificial intelligence
- autonomous systems
- robotics
- advanced communications
- quantum
- cyber
- sensing and positioning technologies
- advanced manufacturing
This does not mean Australia has banned foreign robots like the US is now restricting certain foreign-produced advanced robotic devices.
But it does mean Australia is thinking about AI and robotics through a national security, supply-chain, research, and capability lens.
Official sources:
- Critical Technology Supply Chain Principles:
- Critical technology — enhanced visa screening measures:
https://www.homeaffairs.gov.au/nat-security/Pages/critical-technology.aspx
- List of Critical Technologies in the National Interest:
https://www.industry.gov.au/publications/list-critical-technologies-national-interest
Australia is not just asking, “Is this technology useful?” It is asking, “Who controls it, who supplies it, where does the data go, and could it affect national security?”
3.9 Australia has supply-chain principles for critical technology
The Department of Home Affairs has released Critical Technology Supply Chain Principles.
These are voluntary for industry, but the government uses them in its own decision-making.
The principles focus on:
- security by design
- transparency
- supplier trust
- autonomy and integrity
- foreign influence risk
- knowing who is inside your supply chain
Plain English version:
If your AI system, robot, drone, sensor platform, or automation tool depends on overseas suppliers, Australia wants organisations to understand the risk.
The issue is not just the product.
It is:
- who made it
- who updates it
- who has remote access
- where the data flows
- who could influence the supplier
- whether the supply chain is transparent
Official source:
- Critical Technology Supply Chain Principles:
A robot is not just hardware. It is sensors, software, data, cloud access, updates, and supplier control.
3.10 What Australia has not done yet
Important nuance:
Australia has not yet created a single law equivalent to the EU AI Act.
Australia has not announced a broad ban on foreign-made robots entering the country like the US restrictions discussed earlier.
Australia has not banned general AI tools.
The current pattern is more practical and targeted:
- voluntary standards now
- mandatory guardrails likely for high-risk AI
- stronger rules for government use
- privacy law already applies
- automated decision-making reform is underway
- deepfake sexual abuse is criminalised
- critical technology supply chains are being watched closely
Australia is regulating AI by context. Not every AI tool is treated the same. The question is: what does it affect?
4. Cross-country pattern
The US, EU, and Australia are not regulating AI in exactly the same way.
But they are converging around the same questions.
4.1 What does the system affect?
If AI affects content drafts, productivity, or low-risk internal workflows, the rules are lighter.
If AI affects jobs, finance, education, healthcare, government services, safety, surveillance, infrastructure, or legal rights, the rules become stronger.
Plain English version:
The more AI affects someone’s life, the more governments want accountability.
4.2 Does the system move through the physical world?
Robots, drones, vehicles, autonomous systems, and sensor platforms are treated differently from ordinary software.
Plain English version:
Once AI can move, see, map, record, or control physical systems, governments become much more cautious.
4.3 What data does it collect?
Governments are paying close attention to systems that collect:
- personal information
- biometric data
- location data
- video and audio
- environmental data
- infrastructure data
- workplace data
- health data
- behavioural data
Plain English version:
Data collection is becoming one of the main reasons AI systems are regulated.
4.4 Who controls the supply chain?
AI regulation is increasingly linked to supply-chain trust.
This includes:
- where hardware is made
- who wrote the software
- who provides the cloud
- who can push updates
- who has remote access
- whether foreign governments could influence suppliers
Plain English version:
Governments are not only regulating the AI output. They are regulating the chain of control behind it.
4.5 Can people understand, challenge, or appeal the outcome?
A major theme across the EU, Australia, and US state laws is contestability.
Plain English version:
If AI helps make a decision about a person, that person may need a way to:
- know AI was used
- understand the decision
- correct bad data
- challenge the outcome
- reach a human
- seek review
If AI can affect your life, you should not be trapped inside a black box.
5. Founder checklist: questions to ask before using AI
For founders, operators, and AI builders, the useful question is not “Is AI legal?”
The better checklist is:
- What does the AI system do?
Is it drafting, recommending, deciding, ranking, scoring, detecting, predicting, moving, or controlling?
- Who does it affect?
Staff, customers, patients, students, citizens, applicants, children, vulnerable people, or the public?
- What data does it use?
Personal data, sensitive data, biometric data, location data, health data, financial data, or scraped data?
- What happens if it is wrong?
Mild inconvenience, reputational damage, discrimination, financial loss, denial of service, safety risk, legal harm, or public harm?
- Is a human meaningfully involved?
Can a person override, review, intervene, or explain the decision?
- Can someone challenge the outcome?
Is there a clear process for correction, appeal, or review?
- Do users know AI is being used?
Is disclosure needed? Is generated content labelled? Are people told when they are interacting with AI?
- Who supplied the system?
Is the vendor transparent? Where is the data processed? Who can update the model? Who has remote access?
- Have we documented the risks?
Is there an AI register, impact assessment, testing record, monitoring process, or accountability owner?
- Would we be comfortable explaining this publicly?
If not, the governance is probably not strong enough.
6. Content angle for Merilyn
Strong hook
We keep talking about AI as software.
Governments are starting to regulate it as power.
Expanded angle
In the US, that shows up in restrictions on foreign-produced robots, drones, and connected vehicles.
In Europe, it shows up in the AI Act and its risk-based rules.
In Australia, it shows up in high-risk AI guardrails, privacy law, government AI policies, Robodebt-driven automated decision-making reform, deepfake laws, and critical technology supply-chain controls.
Different countries are using different legal tools, but the pattern is the same:
AI is being judged by what it can affect in the real world.
Practical close
The future-readiness question for founders is not:
Can we use AI?
It is:
What does this system decide, collect, influence, control, and who is accountable when it goes wrong?
7. Source list
United States
- FCC Covered List:
- FCC FAQs: robots and inverters:
- FCC robotics national security determination PDF:
- FCC fact sheet PDF:
- BIS connected vehicles:
- White House: America’s AI Action Plan:
https://www.whitehouse.gov/releases/2025/07/white-house-unveils-americas-ai-action-plan
- Federal Register: Removing Barriers to American Leadership in Artificial Intelligence:
- NIST AI Risk Management Framework:
- Colorado SB24-205:
- California AB 2013:
https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB2013
- California SB 942:
https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942
- California SB 53:
https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53
European Union
- EU AI Act official text:
- European Commission AI regulatory framework:
https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- European Commission prohibited AI practices guidance:
Australia
- Voluntary AI Safety Standard:
https://www.industry.gov.au/publications/voluntary-ai-safety-standard
- The 10 guardrails:
https://www.industry.gov.au/publications/voluntary-ai-safety-standard/10-guardrails
- Mandatory guardrails for safe and responsible AI:
https://www.industry.gov.au/news/mandatory-guardrails-safe-and-responsible-ai-have-your-say
- Policy for the responsible use of AI in government:
- National framework for the assurance of AI in government:
- Automated Decision-Making Reform consultation:
- OAIC submission on automated decision-making by government:
- OAIC: Can personal information be used to develop or train GenAI?
- Parliament of Australia: Criminal Code Amendment (Deepfake Sexual Material) Bill 2024:
- Attorney-General’s Department fact sheet on non-consensual sharing of sexual material:
https://www.ag.gov.au/crime/publications/fact-sheet-police-non-consensual-sharing-sexual-material
- eSafety image-based abuse information:
- Critical Technology Supply Chain Principles:
- Critical technology — enhanced visa screening measures:
https://www.homeaffairs.gov.au/nat-security/Pages/critical-technology.aspx
- List of Critical Technologies in the National Interest:
https://www.industry.gov.au/publications/list-critical-technologies-national-interest
8. Suggested next assets
This research can be repurposed into:
- LinkedIn post: “Governments are starting to regulate AI as power, not software.”
- Carousel: “The new AI regulation map: US, EU, Australia.”
- Newsletter: “Why AI regulation is really about control, data, and accountability.”
- Founder checklist: “10 questions to ask before deploying AI in your business.”
- Short video script: “AI regulation is not about chatbots. It is about what AI can affect.”