Cross-Jurisdiction AI Compliance
AI regulations vary dramatically across jurisdictions. If your product operates across borders, you need to understand what each jurisdiction actually requires, not just what the marketing says.
Most compliance guides tell you which certifications to get. This tool tells you what those certifications actually cover, and more importantly, what they do not.
Select your product type below to see which regulations apply, where the enforcement gaps are, and what your product can do that no current standard addresses.
What are you building?
Select a product type to see jurisdiction-specific requirements.
Gap Analysis
What your product can do that no current jurisdiction adequately addresses.
What this means
Jurisdiction Reference
Detailed breakdown of each jurisdiction's AI regulatory landscape. This is not legal advice. It is an analytical framework to help you understand the terrain.
European Union
Primary framework: EU AI Act (Regulation 2024/1689)
Status: In force. High-risk system requirements apply from August 2026. General-purpose AI requirements apply from August 2025.
Approach: Risk-based classification. AI systems are categorised as unacceptable risk (banned), high-risk (heavy regulation), limited risk (transparency obligations), or minimal risk (no specific requirements).
What it actually requires for high-risk systems: Conformity assessment before market placement. Risk management system. Data governance. Technical documentation. Record-keeping. Transparency to users. Human oversight measures. Accuracy, robustness, and cybersecurity requirements. Post-market monitoring.
| Strength | Gap |
|---|---|
| Most comprehensive classification system globally | Enforcement timeline lags deployment reality |
| Explicit prohibition of certain AI uses (social scoring, real-time biometric surveillance) | Conformity assessments can be self-assessed for some categories |
| Mandatory transparency for AI-generated content | Cross-border enforcement mechanisms untested |
| Fines up to 7% global turnover | Does not address autonomous agent coordination |
United States
Primary frameworks: Executive Order 14110 (2023), NIST AI RMF, state-level legislation (Colorado AI Act, various California bills)
Status: Fragmented. Federal framework is voluntary. State legislation is inconsistent. Executive order established reporting requirements for frontier models but limited enforcement.
Approach: Sectoral and voluntary. No comprehensive federal AI legislation. Existing regulators (FTC, FDA, SEC) apply current authorities to AI within their domains.
What it actually requires: For most AI systems, nothing mandatory at federal level. NIST AI RMF provides voluntary risk management categories. FTC can act against deceptive AI practices under existing consumer protection authority. FDA regulates AI in medical devices. SEC oversees AI in financial services. Colorado AI Act (effective 2026) requires impact assessments for high-risk AI decisions affecting consumers.
| Strength | Gap |
|---|---|
| Strong sector-specific regulation (healthcare, finance) | No comprehensive federal AI law |
| FTC enforcement against deceptive AI practices | NIST AI RMF is voluntary with no enforcement |
| Active state-level legislation | State fragmentation creates compliance complexity |
| Established IP and liability frameworks | No federal requirements for autonomous agents |
United Kingdom
Primary framework: Pro-innovation AI regulation white paper (2023), sector regulator guidance
Status: Deliberately non-legislative. The UK has chosen not to create AI-specific legislation, instead asking existing regulators to apply five principles within their domains.
Approach: Principles-based, regulator-led. Five cross-sector principles: safety/security/robustness, transparency/explainability, fairness, accountability/governance, contestability/redress.
What it actually requires: No new legal requirements specific to AI. Existing regulators (FCA, Ofcom, ICO, CMA) interpret and apply the five principles within their existing mandates. Coverage depends entirely on which sector your AI operates in. The ICO provides AI guidance under existing data protection law (UK GDPR). The FCA regulates AI in financial services. Ofcom covers AI in communications. Sectors without a strong regulator have no AI-specific oversight.
| Strength | Gap |
|---|---|
| Strong data protection via UK GDPR and ICO | No AI-specific legislation |
| Financial AI well-regulated through FCA | Coverage depends on sector, creating blind spots |
| Flexible, avoids premature regulation | Flexibility means no baseline for unregulated sectors |
| Alan Turing Institute provides technical guidance | No enforcement mechanism for cross-sector AI harms |
Australia
Primary framework: Voluntary AI Ethics Principles (2019), proposed mandatory guardrails (2024 consultation)
Status: Largely voluntary. Government has signalled intent to introduce mandatory guardrails for high-risk AI but has not legislated them. Existing consumer law provides some coverage.
Approach: Principles-based, moving toward mandatory. Eight voluntary AI ethics principles: human/societal/environmental wellbeing, human-centred values, fairness, privacy/security, reliability/safety, transparency/explainability, contestability, accountability.
What it actually requires: No AI-specific mandatory requirements. Australian Consumer Law (ACL) applies to AI-generated misleading or deceptive conduct. Privacy Act covers personal information handling by AI. Sector-specific regulations (TGA for health, APRA for finance) apply within their domains. The proposed mandatory guardrails would require risk assessments and transparency for high-risk AI, but have not been legislated.
| Strength | Gap |
|---|---|
| Strong consumer protection law (ACL) applicable to AI | No AI-specific mandatory requirements |
| Privacy Act provides data handling baseline | Voluntary principles have no enforcement |
| Government actively consulting on mandatory guardrails | Mandatory guardrails not yet legislated |
| Sector regulators (TGA, APRA) active in their domains | Autonomous agents not addressed in any framework |
China
Primary frameworks: Algorithmic Recommendation Regulation (2022), Deep Synthesis Regulation (2023), Generative AI Regulation (2023), Global AI Governance Initiative
Status: Most prescriptive globally. Multiple overlapping regulations targeting specific AI applications. Mandatory compliance for AI services offered to the public.
Approach: Application-specific, state-controlled. Regulations target algorithmic recommendations, deepfakes/synthetic content, and generative AI separately. Strong emphasis on content control and "socialist core values."
What it actually requires: Algorithmic assessment filings with the Cyberspace Administration of China (CAC). Content generated by AI must be labelled. Generative AI services must undergo security assessments before launch. Training data must be lawfully obtained. AI outputs must not subvert state power, advocate terrorism, or violate other content restrictions. Users must be verified with real identity.
| Strength | Gap |
|---|---|
| Mandatory algorithmic assessments | Regulations designed for state control, not user protection |
| Content labelling requirements for AI-generated material | Content restrictions based on political alignment, not harm |
| Security assessment before launch | No independent oversight of assessment process |
| Real-identity verification for users | Privacy implications of mandatory identity systems |
This tool provides an analytical framework. It is not legal advice. Regulations change. Consult qualified legal counsel for specific compliance decisions.
CC BY-SA 4.0, NOEVA Foundation, 2026