Navigating Global AI Regulation
The regulatory landscape for AI in 2026 is simultaneously maturing and fragmenting. Where early 2020s AI regulation was mostly absent or skeletal, significant frameworks have now emerged: the EU AI Act is in force, China has published comprehensive generative AI regulations, and the United States is developing sectoral approaches. Yet instead of converging on global standards, these regimes are diverging, creating a patchwork of requirements that any organisation operating across borders has to navigate deliberately rather than by accident.
Why Fragmentation Is Both Problem and Opportunity
This creates both challenge and opportunity. The challenge is obvious: maintaining compliance across different jurisdictions is complex and costly, and the cost falls hardest on smaller organisations that cannot absorb a dedicated compliance function. The opportunity is less obvious but more durable. Organisations that navigate the complexity effectively end up building more responsible AI systems than they otherwise would, establish competitive differentiation on the strength of that, and gain standing to influence the direction of future regulation.
By the end of this lesson you should understand the major regulatory regimes and the logic behind each, what they imply for how you develop and deploy AI, and how to build compliance strategies that work across jurisdictions without paralysing innovation. The path to current AI regulation was not inevitable. Early optimists thought industry self-regulation would suffice. That proved insufficient, and incidents of biased hiring systems, non-consensual deepfakes and opaque algorithmic decision-making catalysed regulatory action.
The Regulatory Landscape: Where We Are in 2026
The European Union: Prescriptive and Comprehensive
The EU AI Act represents the world's most comprehensive AI regulation, and it is the template many other jurisdictions reference when drafting their own. Its core logic is risk-based categorisation. Rather than regulating AI as a single technology, it sorts systems by what they are used for and how much damage a failure could do, then attaches obligations proportionate to that tier. Understanding the tiers is the first practical step for any organisation that touches the European market.
Prohibited systems. Certain applications are banned outright. This includes real-time facial recognition in public spaces, with narrow exceptions for security, social credit scores that restrict access to opportunities on the basis of behaviour scoring, and manipulative systems designed to undermine autonomy, for example AI-generated deepfakes of political leaders during elections. These are not compliance problems to be managed. They are categories of product that cannot be shipped into that market at all.
High-risk systems. These affect fundamental rights or access to critical services, which is the common thread running through an otherwise varied list: AI used for hiring, educational placement, lending decisions, law enforcement and migration. What unites them is that a wrong output changes what a person is allowed to do or have, rather than merely inconveniencing them. These systems remain permitted, but they carry the heaviest obligations in the Act, and meeting those obligations is engineering and documentation work that has to be planned for rather than retrofitted:
- Undergo conformity assessment, broadly similar in spirit to product safety testing
- Meet technical documentation requirements
- Implement bias monitoring and performance tracking
- Have human oversight mechanisms in place
- Maintain detailed records and provide transparency
Limited-risk systems. AI that interacts directly with people, such as chatbots and content recommendation, must disclose that it is AI, so that people can make informed choices about whether and how to engage with it. Minimal-risk systems. Most other AI applications face minimal regulatory requirements, which is worth stating plainly because a great deal of ordinary business automation sits here and does not need to be treated as a compliance event.
Penalties for violations are steep, and they are tiered by the seriousness of the breach, with the heaviest reserved for prohibited practices and lighter tiers attaching to conformity and transparency failures. Rather than working from a remembered percentage, treat the enforcement risk as material enough that the classification exercise deserves legal input, and confirm the applicable figures against the current text of the instrument before you rely on them in a board paper.
The EU AI Act in Practice
The Act created immediate practical impact well beyond Europe. Organisations worldwide began reclassifying their AI systems. Many concluded that systems they had thought of as routine met high-risk criteria and needed overhauls. Entire compliance and audit functions emerged to handle the work. Even companies not operating in the EU often implement EU-compliant systems globally, on the straightforward logic that compliance with a strict requirement typically exceeds the less strict alternatives elsewhere.
China: Content Control and Authority
China's approach to AI regulation differs fundamentally from the EU's, and the difference is not one of strictness but of what the rules are trying to achieve. Rather than focusing on technical safety and fairness, it prioritises content governance and state control of powerful AI systems. That means a system can be technically excellent, thoroughly tested and demonstrably fair, and still be non-compliant, because those are not the questions being asked. The generative AI regulations require:
- Government approval for training algorithms before deployment, which is pre-deployment control rather than post-incident correction
- Disclosure of synthetic media created by AI systems
- Prohibition of content that violates socialist values, Chinese law, or state sovereignty
- Data localisation, meaning training data and user data must be stored in China
- Compliance with core values around political content, national security and social stability
This is a more prescriptive, authority-based approach than the EU's testing-based framework. An AI system does not need to prove that it is safe or fair in the European sense; it needs to demonstrate that it will not generate politically problematic content, and that the organisation has governmental blessing to operate it. The evidence a regulator wants to see is therefore entirely different in kind, not merely in quantity.
For international organisations this creates a central problem. The Chinese requirement for data localisation sits in direct tension with the restrictions European data protection law places on transfers and on how training data may be handled. A single training pipeline built to satisfy one regime can be structurally incapable of satisfying the other. Organisations operating in both regions therefore often maintain separate systems rather than trying to reconcile the two in one architecture.
The Divergence Problem
As jurisdictions regulate AI differently, the globally integrated digital infrastructure that let companies serve multiple markets with identical products becomes infeasible. A company might need EU-compliant AI, China-compliant AI and US-compliant AI, and each additional variant increases complexity and cost significantly. The divergence is the strategic fact of this decade: the assumption that one product can be shipped everywhere is the thing that has quietly stopped being true.
United States: Sectoral and Flexible
The US regulatory approach differs sharply from both the EU and China, and it is the one most often misread from outside. Rather than enacting a comprehensive AI law, the US applies existing sectoral regulation to AI, which means the relevant rules depend on what the system does rather than on the fact that it is AI. An employment screening tool and a diagnostic imaging tool sit under entirely different regulators with entirely different expectations, and neither is unregulated:
- The FDA regulates AI in medical devices
- The EEOC addresses discrimination in employment AI
- The FTC takes enforcement action against deceptive AI practices
- The CFPB regulates AI in lending and credit
The NIST AI Risk Management Framework provides guidance and best practice rather than legal requirements. This creates flexibility, in that organisations do not need permission to innovate, but it also creates uncertainty. An AI system might be lawful under current interpretations and still become the subject of enforcement action if regulators shift how they read existing statutes. The US approach favours innovation over precaution, enabling rapid AI development while leaving questions of liability and responsibility unsettled until court cases or enforcement actions provide clarity.
Building Global Compliance Strategies
Organisations operating internationally face three strategic options for handling divergent requirements. They are not mutually exclusive, and the most effective organisations combine all three deliberately, but it helps to understand each on its own terms before blending them, because each carries a distinct cost profile and a distinct failure mode. Choosing implicitly, which is what happens when nobody makes the decision, tends to produce the most expensive combination: the complexity of jurisdictional variation without the optimisation benefit that was supposed to justify it.
Strategy 1: Compliance Floor, or Single Global Standard
Apply the strictest applicable requirement globally. If you operate in the EU, build to EU AI Act standards everywhere, including in markets that would not have required it. If you operate in China, ensure systems meet Chinese requirements globally. The advantages are simplicity of operations, a single consistent system to maintain and reason about, the removal of localisation complexity from both engineering and legal review, and the fact that it often produces more responsible AI overall as a side effect of aiming at the highest bar rather than the nearest one.
The disadvantages are real. Building to high standards costs more than building minimally compliant systems. The result may be more restrictive than necessary in less regulated markets, and it can slow innovation in regions with lighter-touch regulation. Most major technology companies use this approach anyway, because the alternative of maintaining separate systems for separate regions is complex and creates security and quality risks of its own.
Strategy 2: Jurisdictional Variation
Maintain different systems optimised for different regulatory regimes. An EU version of a system meets EU AI Act requirements, a US version is built around the relevant sectoral requirements, and a China version meets Chinese requirements. The advantage is that it enables more aggressive optimisation against specific regulatory constraints, and it can be economically efficient where that optimisation unlocks significant business value.
The disadvantages compound quickly. It dramatically increases complexity. It creates security risks, because different codebases are harder to maintain and patch consistently. It requires robust governance to ensure that all versions remain compliant rather than just the one anybody is currently looking at. It increases testing and audit costs. This approach is viable for organisations with existing global compliance infrastructure and enterprise customers willing to accept regional variation. It is much less practical for consumer-facing applications.
Strategy 3: Risk Segmentation
Apply different governance intensity to different systems based on regulatory and business risk. High-risk systems, meaning those affecting fundamental rights or operating in heavily regulated sectors, meet the highest applicable standards. Lower-risk systems face proportional governance. The advantage is balance: compliance rigour where it matters, operational efficiency where it does not, resources directed to the highest-risk systems, and faster innovation on the rest.
The disadvantage is that it depends entirely on the quality of your risk assessment at the individual system level, which is a harder discipline than it appears and one that quietly rewards optimism. Segmentation done well is the most efficient pattern available to any organisation with more systems than reviewers. Segmentation done badly produces uneven governance, in which the systems that most needed scrutiny turn out to be the ones classified as routine, and nobody discovers the misclassification until an incident surfaces it on someone else's terms.
The Compliance Stack
Most effective organisations combine all three. They establish a compliance floor that meets the strictest applicable requirement globally. They risk-segment systems on top of that floor and apply additional governance to high-risk ones. They maintain jurisdiction-specific variations only where the economics genuinely justify it and where the governance to keep every variant compliant actually exists. The stack, in that order, is the pattern worth copying.
Critical Compliance Domains Across Jurisdictions
Despite very different regulatory philosophies, the major jurisdictions converge on a small set of critical domains, and the convergence is more useful strategically than any individual requirement. Where three regimes that agree on almost nothing else all care about the same thing, that thing is close to a permanent feature of the landscape rather than a policy fashion. Building the capability once serves all three, it is unlikely to be regulated away later, and it gives you a defensible answer in a jurisdiction that has not yet legislated at all.
| Domain | European Union | United States | China |
|---|---|---|---|
| Transparency and disclosure | Detailed documentation for high-risk systems; disclosure to users for limited-risk systems | FTC enforcement against deceptive practices requires truthful disclosure of AI use | Synthetic media must be labelled as AI-generated |
| Fairness and bias assessment | Formal fairness testing and monitoring requirements for high-risk systems | Existing discrimination law applies, enforced through bodies such as the EEOC and FTC | Less emphasis on fairness metrics, more on content appropriateness |
| Data governance | Extensive requirements under GDPR covering consent, purpose limitation and data minimisation; the AI Act adds training data documentation | Sector-specific requirements, including healthcare data privacy and financial data security | Data localisation and state access requirements |
| Human oversight and accountability | High-risk systems require human oversight with the ability to override decisions | Implied in discrimination law, on the principle that people should have recourse if wronged | Content governance involves human review of sensitive outputs |
The convergence on transparency suggests it is foundational rather than jurisdictional, so organisations should build transparency mechanisms across all systems rather than only the ones currently in scope somewhere. On fairness, implementing fairness testing across every system and documenting the results is the safe approach for anyone operating globally, because it addresses all three regimes at once and produces the evidence you would need if any of them asked.
On data, robust governance that documents provenance, quality and use is essential for compliance across all jurisdictions, and it is also the thing most often missing when an organisation discovers it cannot answer a regulator's first question. On oversight, implementing clear human oversight, especially for decisions affecting people's rights, is universally protective. There is no regime in which having a human able to review and override a consequential automated decision makes your position worse.
Building Regulatory Intelligence and Governance
The regulatory landscape changes constantly, and a compliance posture built once and then left alone will decay without anyone deciding that it should. New instruments arrive, guidance clarifies obligations that were previously ambiguous, and enforcement actions reveal how regulators actually read the text they wrote. Effective organisations therefore build a standing capability to track and respond to that change, rather than treating each new instrument as an unexpected crisis project staffed by whoever happens to be available when the headline lands.
Regulatory Scanning
Designate responsibility for monitoring emerging regulation. Most organisations assign this to legal and compliance with support from business unit leaders, because the legal function knows what is changing and the business leaders know which systems it touches. Quarterly regulatory scans should identify new or proposed regulations that might apply to existing systems, regulatory guidance that clarifies existing requirements, and enforcement actions that signal where regulatory priorities are actually landing. Enforcement patterns are often more informative than the text of the rules.
Impact Assessments
When new regulations emerge, assess how they affect current systems before deciding anything. Which systems are affected? What must change to achieve compliance? What timeline is required, and does it align with the instrument's own transition period? What resources are needed across engineering, legal and audit? Answering these four questions in writing turns an alarming headline into a scoped piece of work, and it prevents the two common failure modes: panicked over-reaction across the whole estate, and quiet inaction because nobody owned the question.
Adaptive Governance
Rather than static policies, implement governance that can absorb new requirements without a redesign. In practice that means flexible documentation standards that can be extended as regulations evolve, monitoring infrastructure that can track new metrics as they become required, and review processes with deliberate space for new considerations. The organisations that suffer most when a regime changes are the ones whose documentation and monitoring were built to satisfy exactly one rule and nothing else.
The Strategic Opportunity
While regulatory compliance is almost always framed internally as cost and friction, well-executed compliance creates strategic advantages that are easy to overlook when you are looking at the invoice for it. The framing matters, because a function understood purely as overhead gets funded defensively and staffed by whoever can be spared, which then produces exactly the grudging, minimal compliance that confirms the original assumption. Four advantages are worth making explicit when you argue for the investment:
- Trust and reputation. Organisations known for responsible AI attract more customers, partners and talent. As regulation tightens globally, being ahead of requirements becomes valuable brand positioning rather than merely a defensive posture.
- Reduced litigation risk. Documented compliance and governance reduce vulnerability to lawsuits and regulatory enforcement, and the documentation is worth most precisely at the moment you most need it.
- Market access. Some jurisdictions, the EU especially, increasingly require compliance certification for AI products. Organisations that build the infrastructure early gain access advantages over competitors building it under deadline.
- Influence on regulation. Organisations with demonstrated compliance expertise are consulted as regulators develop frameworks, which is the difference between shaping the next decade of requirements and absorbing them.
Anti-Patterns
Compliance by remembered figure. Teams quote penalty percentages, commencement dates and thresholds from memory, from a conference slide or from an article of uncertain vintage, then build a business case on top of them. Regulatory figures and timetables are amended, staged and clarified, and the version that circulated most widely is frequently a draft rather than the enacted text. Verify against the current instrument, or against counsel, before any specific number reaches a decision document, and be particularly wary of figures that have become memorable through repetition.
Assuming the regime follows the company's address. Comprehensive AI regulation can reach systems whose outputs affect people inside the regulating jurisdiction regardless of where the developer is incorporated or where the servers sit. Deciding you are out of scope because you have no office there is the most expensive assumption available in this area, and it is usually made informally, by an engineer or a founder, long before anyone with a legal background is asked. Establish scope deliberately and write down the reasoning.
Treating the US as unregulated. The absence of a single comprehensive AI statute is not the absence of law, and reading it that way is a common error among teams whose mental model of regulation is European. Medical, employment, consumer protection and credit regulators all apply existing authority to AI systems already. The sectoral rules that bind you may turn out to be considerably more specific about your particular use case than a general AI framework would ever have been.
Building for exactly one rule. Documentation and monitoring designed to satisfy a single named regime have to be rebuilt from scratch every time anything changes, which guarantees that each new instrument arrives as an expensive project rather than an adjustment. Build the capability so that it can be extended, capture information that serves several regimes at once, and prefer general structures such as documented data provenance over narrow artefacts produced solely to answer one question in one jurisdiction.
Segmenting risk without a real assessment. Risk segmentation is only ever as good as the classification underneath it, and classification is the step most likely to be rushed because it feels administrative. Without a genuine system-level assessment, with stated criteria and someone accountable for applying them, segmentation quietly becomes a mechanism for exempting the things nobody wanted to govern. The tell is an estate in which almost everything has been classified as low risk.
Maintaining regional variants without the governance to match. Jurisdictional variation multiplies codebases, and every additional variant is another artefact that can drift out of compliance while attention is somewhere else entirely. Variants also diverge in undocumented ways, so that a fix applied to one is not applied to the others. If you cannot demonstrate on request that every variant is currently compliant, what you have is fragmentation that happened to you rather than a strategy you chose.
Confusing guidance with law, in either direction. A voluntary risk management framework is not a statute, and treating it as one wastes effort on obligations nobody imposed. Equally, following recognised guidance is often the most defensible evidence available that you acted reasonably, particularly in a jurisdiction where the standard is reasonableness rather than a checklist. Dismissing it because it is technically voluntary is its own mistake, and the more common one among engineering-led teams.
Practice Prompts
Classify your estate. List every AI system you operate and place each one into the EU risk tiers: prohibited, high-risk, limited-risk and minimal-risk. Where you are genuinely unsure between two tiers, write down which way you would rather be wrong and why, since that reasoning is the thing you will want on record later. The systems that generate real disagreement inside the room are precisely the ones that need legal input, and the exercise is worth doing mainly because it surfaces them.
Map jurisdiction to system. For each system, record which jurisdictions it touches, working from where users are located, where data is stored and processed, and whose decisions or opportunities it affects. Notice that these three can point in different directions for the same system. Reach for whose rights are affected rather than where your office is registered, because that is generally the question the regulation actually asks, and the answer is frequently broader than the commercial footprint.
Draft your compliance floor. Write down the single standard you would apply globally if you adopted the compliance floor approach, then estimate qualitatively what it would take to raise every system to that line, in engineering effort, documentation and review capacity. Compare that against the governance burden of maintaining regional variants across the same estate. Most organisations doing this honestly for the first time find the floor cheaper than they assumed, because they had been pricing the alternative optimistically.
Build the convergence checklist. Using the four convergent domains, transparency and disclosure, fairness and bias assessment, data governance, and human oversight, write down the one capability per domain that would satisfy all three regimes simultaneously. Be specific enough that someone could be assigned to build it. Those four capabilities are your no-regret investments, and they are the right things to fund first when the budget is smaller than the ambition.
Run a quarterly scan once. Do a single deliberate pass looking for new or proposed regulations affecting your systems, guidance clarifying existing requirements, and enforcement actions that signal where attention is landing. Note how long the pass took you and what it surfaced. That elapsed time is your ongoing quarterly cost for regulatory intelligence, and it is almost always smaller than the figure people imagine when they decline to start.
Write one impact assessment. Pick a regulation you already know is coming and answer the four questions in writing: which systems are affected, what must change to achieve compliance, what timeline is required, and what resources are needed across engineering, legal and audit. Then circulate it to the people who would have to act on it. An assessment that sits unread in a folder has not reduced any risk, and the circulation is what converts analysis into a decision.
Reflection
Which of your AI systems would you be uncomfortable explaining to a regulator in detail, and what specifically is the source of the discomfort? Discomfort is a more reliable classifier than most formal criteria, because it draws on everything you know about the system rather than only what fits the rubric. In practice it points at one of two things: a system whose decisions affect people's access to something that matters to them, or a system whose training data provenance nobody in the building can now fully account for.
Consider the compliance floor honestly. If you applied the strictest standard you are subject to across everything you operate, what would actually break? If the answer is nothing much, the floor is cheaper than you assumed and you should adopt it. If the answer is that several products would become uneconomic, that is worth knowing precisely, because it means you are running a jurisdictional variation strategy whether or not you chose one.
Finally, ask who in your organisation would actually notice if a relevant rule changed next quarter, and by what route the news would reach the people who would have to act on it. If the honest answer is nobody in particular, and the assumed route is that someone will read about it somewhere, then regulatory intelligence is not a capability you have. It is a task you are hoping somebody does, and hoping has no owner, no cadence and no record of what it found.
Glossary
- Risk-based categorisation. Regulating AI by what a system is used for and how much harm a failure could cause, then attaching proportionate obligations, rather than regulating the technology uniformly.
- High-risk system. Under the EU AI Act, a system affecting fundamental rights or access to critical services, including AI used in hiring, educational placement, lending, law enforcement and migration.
- Conformity assessment. A pre-deployment evaluation that a high-risk system meets required standards, broadly similar in spirit to product safety testing.
- Limited-risk disclosure. The obligation on AI that interacts directly with people, such as chatbots, to disclose that it is AI so that users can make informed choices about engaging with it.
- Compliance floor. A strategy of applying the strictest applicable regulatory standard across all markets, on the logic that meeting the strictest requirement exceeds the looser ones.
- Jurisdictional variation. Maintaining separate system versions optimised for separate regulatory regimes, trading operational complexity for local optimisation.
- Risk segmentation. Applying governance intensity in proportion to assessed system risk, so that scrutiny concentrates where the potential harm is greatest.
- Data localisation. A requirement that data be stored within a specific country's borders, which can conflict directly with other regimes' restrictions on cross-border transfers.
- Sectoral regulation. The approach of applying existing domain regulators and statutes to AI according to what the system does, rather than enacting one comprehensive AI law.
- Regulatory intelligence. A standing capability for scanning proposed regulation, guidance and enforcement actions, and translating them into impact assessments.
- Adaptive governance. Policies, documentation standards and monitoring built to be extended as requirements evolve, rather than fixed to a single current rule.
Related Lessons
This lesson sits at the outward-facing end of the governance arc. Responsible AI at Scale: Framework and Implementation supplies the internal machinery, the model registries, monitoring and escalation paths, that a multi-jurisdictional compliance posture actually runs on, and it is worth reading first if your estate has grown past what one person can hold in their head. AI Policy Development for Industry Impact covers the influence side, which is where the strategic opportunity described above is realised.
For the specific instruments, Regulatory Compliance: GDPR, CCPA, and Industry Standards and Data Privacy Obligations for Small Businesses go considerably deeper on the data protection obligations that the AI-specific rules layer on top of. Bias Auditing and Fairness in AI Systems covers the fairness testing that the convergence analysis identifies as a no-regret investment, and Building AI Governance Structures covers who decides what. Regulatory Landscape and Future Compliance and The Future of AI Ethics: Preparing for What's Next both look forward from here.
Closing
The instinct to wait for the regulatory picture to settle before investing in compliance is understandable and wrong. It is not settling. Three major regimes have now committed to fundamentally different philosophies, technical prescription in the EU, content control in China, sectoral flexibility in the US, and none of them is likely to abandon its approach to converge on someone else's. Fragmentation is the steady state, not a transitional phase.
What that implies practically is encouraging. Because you cannot wait for convergence, the winning move is to build the capabilities the regimes agree on, transparency, fairness testing, documented data governance and genuine human oversight, and to build them so they can be extended. Those four hold their value whatever any individual instrument does next, and they happen to be the same four that make AI systems better rather than merely defensible.
Key Takeaways
- Global AI regulation is fragmenting rather than converging, with the EU pursuing technical prescription, China pursuing content control and state authority, and the US pursuing sectoral flexibility.
- The EU AI Act works through risk-based categorisation: prohibited practices are banned outright, high-risk systems carry conformity assessment, documentation, bias monitoring, human oversight and record-keeping obligations, limited-risk systems must disclose that they are AI, and most other applications face minimal requirements.
- Comprehensive AI regulation can reach systems affecting people in the regulating jurisdiction regardless of where the developer is based, so being incorporated elsewhere is not a scope exemption.
- China's data localisation requirements sit in direct tension with European restrictions on data transfers, which is why organisations operating in both regions often maintain separate systems.
- The absence of a comprehensive US AI statute is not the absence of regulation. The FDA, EEOC, FTC and CFPB all apply existing authority, and the NIST AI Risk Management Framework provides guidance rather than binding law.
- Three compliance strategies exist: a global compliance floor, jurisdictional variation, and risk segmentation. Most effective organisations combine all three, in that order of priority.
- Four domains converge across all major regimes: transparency and disclosure, fairness and bias assessment, data governance, and human oversight with the ability to override. Build these once and they serve everywhere.
- Regulatory intelligence is a standing capability, built from quarterly scanning, written impact assessments and governance designed to be extended rather than replaced.
- Well-executed compliance is not only cost. It produces trust and reputation, reduced litigation exposure, market access in regulated jurisdictions, and a seat at the table when the next rules are written.
Frequently Asked Questions
What are the key requirements of the EU AI Act?
The EU AI Act uses risk-based categorisation. Prohibited systems, including real-time facial recognition in public, social credit scores and manipulative AI, are banned. High-risk systems, covering areas such as hiring, lending, education placement and law enforcement, must undergo conformity assessment, maintain technical documentation, implement bias monitoring and human oversight, and maintain audit trails. Limited-risk systems must disclose that they are AI. Penalties are substantial and tiered by the seriousness of the violation. The Act applies to AI systems affecting EU residents even where the company is based elsewhere.
How do China's regulations differ from EU regulations?
China's approach focuses on content control and government authority rather than technical safety. It requires pre-deployment government approval of training algorithms, mandatory labelling of synthetic media, prohibition of content violating socialist values or national security, data localisation, and compliance with political guidance. The EU approach is testing-based and performance-focused, meaning prove it is safe and fair. China's is authority-based, meaning obtain government permission. These approaches are fundamentally different, which often makes simultaneous compliance with both difficult for a single system.
What is the difference between the EU, China and US regulatory approaches?
The EU uses comprehensive, prescriptive rules that define prohibited and high-risk systems and specify obligations for each. China uses prescriptive rules focused on content control and government authority. The US uses sectoral regulation, with the FDA covering medical devices, the EEOC covering employment and so on, plus guidance rather than a comprehensive statute, favouring innovation flexibility. The EU is the most restrictive, China the most focused on control, and the US the most flexible. You need to understand which approach applies to your systems and where you operate.
What compliance strategy works for global organisations?
Most global organisations use a compliance floor approach: establish standards that exceed all applicable requirements and meet the strictest applicable regulation everywhere. This simplifies operations and often results in more responsible AI. For high-risk systems, risk segmentation adds additional governance on top. Jurisdiction-specific variations can work but require careful governance and increase complexity. The key decision is whether the economic benefit of localised optimisation exceeds the operational complexity it creates. For most consumer-facing AI, the answer is no.
What should a multi-jurisdictional compliance strategy address?
Six things. Jurisdictional mapping, meaning which regulations apply to which systems. Compliance floor establishment, meaning what standard exceeds all applicable requirements. Documentation systems that capture the information needed across multiple regimes at once. Technical implementation, ensuring systems can actually meet differing requirements such as data localisation. Monitoring and updates, tracking regulatory change and updating processes. And incident response, with procedures for addressing violations in different jurisdictions, since the notification obligations are not the same everywhere.
How should organisations prepare for evolving regulation?
Establish regulatory intelligence through routine scanning, impact assessment processes that translate a new instrument into scoped work, and adaptive governance with policies flexible enough to absorb new requirements without a complete redesign. Design documentation and monitoring systems to capture information relevant to multiple regulations, which reduces the cost of adapting each time. Building compliance infrastructure early provides strategic advantages: market access in regulated jurisdictions, brand differentiation, and potential influence on how the next regulations are written.
Skill.re