The EU AI Act deal
On December 9, 2023 European lawmakers reached a tentative deal on the world’s first comprehensive AI law, enacted the following year.
Chapter 7 of the AI Index 2024 covers 2023, the year AI policy discourse went global. Legislative attention roughly doubled worldwide, the US Congress proposed 181 AI-related bills and passed one, and the work that actually landed came from executive agencies — 25 federal regulations, up 56.3% in a single year. The numbers:
The AI Index Steering Committee’s selection of the most significant AI-related policy events of 2023. China regulated first, the US Senate drafted, the White House ordered, Britain convened, and Brussels closed the year with a deal.
China introduces regulations aimed at deep synthesis technology to tackle security issues around realistic virtual entities and multimodal media, including deepfakes. They apply to both providers and users across media types and mandate preventing illegal content, verifying user identities, securing consent for biometric editing, safeguarding data security, and enforcing content moderation.
The bipartisan bill clarifies and solidifies the Department of Defense’s authority to acquire AI-based endpoint security tools so it can automatically detect and mitigate threats to its networks and digital infrastructure, and adopt commercial technology fast enough to match adversaries.
The National AI Commission Act calls for a commission tasked with crafting a comprehensive AI regulatory framework. The bipartisan initiative stresses expert input given AI’s speed and complexity, and focuses on mitigating risks while preserving US leadership in AI research and development.
The Biden-Harris administration obtains voluntary pledges from Google, Microsoft, Meta, Amazon, OpenAI, Anthropic, and Inflection. The commitments cover internal and external security assessments before launch, sharing information on identified risks, enabling public reporting of issues, and disclosing when content is AI-generated.
The act would establish the National Artificial Intelligence Research Resource (NAIRR), a national infrastructure giving researchers and students access to compute, curated datasets, educational tools, and AI testbeds — aimed at strengthening the country’s ability to test and evaluate AI systems.
The updated policy takes a more targeted approach, regulating applications with public implications rather than everything. The language shifts from directives like “ensure the truth, accuracy, objectivity, and diversity of the data” to “employ effective measures to enhance the quality of training data,” and the revised rules encourage generative AI development instead of leading with punishment.
The bipartisan Protect Elections from Deceptive AI Act seeks to prohibit using AI to create materially deceptive content that falsely represents federal candidates in political advertisements, banning distribution of deceptive AI-generated audio or visual material about candidates for federal office.
The Competition and Markets Authority proposes principles to keep AI markets competitive while protecting consumers: accountability for AI outputs, continuous access to essential inputs, a diversity of business models, choice for businesses, flexibility to switch between models, and fair practices to prevent anticompetitive behavior.
The order sets new benchmarks for AI safety and security, privacy protection, equity and civil rights, competition and innovation. It mandates a national security memorandum on military and intelligence use of AI, tasks the Department of Education with AI’s safe use in education, encourages the FCC to assess AI’s impact on telecommunications, and instructs NIST to formulate guidelines and best practices for developing and deploying secure, reliable, ethical AI.
The taskforce forms new alliances with leading AI organizations and advances the UK’s AI Research Resource, to be known as Isambard-AI, a supercomputer built for compute-intensive safety research. The report also describes partnerships giving the taskforce early access to leading companies’ models.
The summit produces the Bletchley Declaration, endorsed by 28 countries including China and the United States — a significant global agreement on AI safety. The UK also unveils the world’s first AI Safety Institute. Reactions are mixed, with some experts calling for more ambitious measures.
The first government-supported entity dedicated to advancing AI safety in the public interest aims to build the sociotechnical framework needed to understand and govern the risks of advanced AI, conduct fundamental safety research, and create the technical tools required for effective AI governance — positioning the UK as a global center for safety research.
European lawmakers reach a tentative deal on the AI Act, which establishes a risk-based regulatory framework: systems with unacceptable risks such as behavioral manipulators are prohibited, high-risk systems are classified into product-based and critical sectors, generative AI must meet transparency standards, and low-risk AI including deepfake technology carries basic transparency obligations. The act was enacted in 2024.
The AI Index tracked legislation containing the term “artificial intelligence” in 128 countries from 2016 to 2023. Attention rose almost everywhere; enacted law did not follow at the same speed — least of all in Washington.
Of the 128 countries analyzed, only 32 have enacted at least one AI-related bill, for a global total of 148 laws since 2016. The annual figure actually fell in 2023, to 28 from 39 the year before, though it remains far above the single bill of 2016. Belgium led 2023 with five laws; France, South Korea, and the United Kingdom passed three each. Cumulatively the United States leads with 23, followed by Portugal (15) and Belgium (12). And most of this legislation is not really about AI: of the 28 bills passed in 2023, just two were coded as highly relevant to AI and 18 as medium relevance.
In the US Congress, proposed AI-related bills more than doubled, from 88 in 2022 to 181 in 2023. One passed. Interest is easier to see in committee reports: AI was mentioned 48 times in the 118th session by the end of 2023, and because that session was only about halfway through — it ran to January 2025 — the AI Index judged it on pace to surpass every session since tracking began in 2001. Appropriations and Science, Space, and Technology led the House with seven mentions each; Senate Appropriations led with nine.
State legislatures proposed 150 AI-related bills in 2023, up from 61 in 2022, and enacted 38 of them — a far higher hit rate than the federal level. California led with seven new laws, followed by Virginia (five) and Maryland (three). Across 2016 to 2023 California has passed 13 in total, ahead of Maryland (10) and Washington (7), which means more than half of California’s eight-year output arrived in 2023 alone.
Regulations are the detailed directives executive agencies craft to enforce legislation. Congress passed one AI bill in 2023; agencies issued 25 AI-related regulations, and they leaned restrictive.
The AI Index searched the Federal Register — a repository covering more than 436 agencies — for “artificial intelligence” and found 25 AI-related regulations in 2023, against just one in 2016. The past year alone accounted for 56.3% growth. They came from 21 different agencies, up from 17 in 2022, and the newcomers say something about how far AI has spread: the Department of Transportation, the Department of Energy, and the Occupational Safety and Health Administration all issued their first AI-related regulation in 2023. The Executive Office of the President and the Commerce Department led with five each, followed by the Department of Health and Human Services and the Bureau of Industry and Security with four each.
In 2023 there were 10 restrictive AI regulations against just three expansive ones — an inversion of 2020, when four were expansive and one restrictive. The regulations are also getting closer to their subject: four of the 25 were coded as highly relevant to AI, the most since tracking began in 2016. A high-relevance example is the Copyright Office and Library of Congress’ registration guidance for works containing AI-generated material; a medium-relevance one is the SEC’s cybersecurity risk management and incident disclosure rule. By subject matter, foreign trade and international finance came first with three, followed by health, commerce, and science, technology and communications with two each.
The instruments policymakers reached for during the year — an act, an executive order, a summit, a set of pledges, two Chinese rulebooks, and 75 national strategies. Tap a card for the detail.
On December 9, 2023 European lawmakers reached a tentative deal on the world’s first comprehensive AI law, enacted the following year.
Signed October 30, 2023, the most notable US AI policy initiative of the year — and the reason so many agencies started writing AI rules.
The UK AI Safety Summit on November 1 produced a declaration endorsed by 28 countries, including China and the United States.
On July 21 the Biden-Harris administration obtained voluntary commitments from seven major AI firms — five months before the EU closed its deal.
Deep synthesis rules in January, then an August revision of the generative AI measures that traded blanket control for a targeted approach.
Canada published the first in March 2017. By January 2024 the count stood at 75, with eight added during 2023.
US federal AI R&D funding and AI contract spending both moved only slightly in 2023. Spending on the microelectronics underneath AI rose by more than half in a single year.
The National Science and Technology Council reports the public-sector AI R&D budget across the agencies in the NITRD Program and the National AI Initiative. In fiscal year 2023, US government agencies allocated $1.8 billion to AI research and development, a figure that has risen every year since FY 2018 and more than tripled from the $0.56 billion of that year. For FY 2024 the request was $1.9 billion. Among agency requests for FY 2024, the National Science Foundation was highest at $531 million, followed by DARPA at $322.1 million and the National Institutes of Health at $284.5 million. These reports exclude classified AI R&D, so they are a floor rather than a total.
The Department of Defense separately publishes what it requests for nonclassified, AI-specific research, development, test, and evaluation. For FY 2024 it asked for $1.8 billion, a significant increase on the $1.1 billion requested for FY 2023 — a single department requesting about as much as the entire NITRD AI R&D budget.
Headline findings from Chapter 7 · Policy and Governance.
In 2023, there were 25 AI-related regulations in the United States, up from just one in 2016. Last year alone, the total number of AI-related regulations grew by 56.3%.
The year 2023 witnessed a remarkable increase in AI-related legislation at the federal level, with 181 bills proposed, more than double the 88 proposed in 2022.
Mentions of AI in legislative proceedings across the globe have nearly doubled, rising from 1,247 in 2022 to 2,175 in 2023.
The number of US regulatory agencies issuing AI regulations increased to 21 in 2023 from 17 in 2022, indicating a growing concern over AI regulation among a broader array of American regulatory bodies.
The European Union reached a deal on the terms of the AI Act, a landmark piece of legislation enacted in 2024. Meanwhile, President Biden signed an Executive Order on AI, the most notable AI policy initiative in the United States that year.
Chapter 7 (sections 7.1–7.5) with every figure and citation is free from Stanford HAI. Or head back to the report highlights and the nine-chapter overview.
Open the AI Index 2024 →