Open Framework Last updated: February 2026

Cross-Jurisdiction AI Compliance

AI regulations vary dramatically across jurisdictions. If your product operates across borders, you need to understand what each jurisdiction actually requires, not just what the marketing says.

Most compliance guides tell you which certifications to get. This tool tells you what those certifications actually cover, and more importantly, what they do not.

Select your product type below to see which regulations apply, where the enforcement gaps are, and what your product can do that no current standard addresses.

What are you building?

Select a product type to see jurisdiction-specific requirements.

Jurisdiction Reference

Detailed breakdown of each jurisdiction's AI regulatory landscape. This is not legal advice. It is an analytical framework to help you understand the terrain.

European Union

Primary framework: EU AI Act (Regulation 2024/1689)

Status: In force. High-risk system requirements apply from August 2026. General-purpose AI requirements apply from August 2025.

Approach: Risk-based classification. AI systems are categorised as unacceptable risk (banned), high-risk (heavy regulation), limited risk (transparency obligations), or minimal risk (no specific requirements).

What it actually requires for high-risk systems: Conformity assessment before market placement. Risk management system. Data governance. Technical documentation. Record-keeping. Transparency to users. Human oversight measures. Accuracy, robustness, and cybersecurity requirements. Post-market monitoring.

StrengthGap
Most comprehensive classification system globallyEnforcement timeline lags deployment reality
Explicit prohibition of certain AI uses (social scoring, real-time biometric surveillance)Conformity assessments can be self-assessed for some categories
Mandatory transparency for AI-generated contentCross-border enforcement mechanisms untested
Fines up to 7% global turnoverDoes not address autonomous agent coordination

United States

Primary frameworks: Executive Order 14110 (2023), NIST AI RMF, state-level legislation (Colorado AI Act, various California bills)

Status: Fragmented. Federal framework is voluntary. State legislation is inconsistent. Executive order established reporting requirements for frontier models but limited enforcement.

Approach: Sectoral and voluntary. No comprehensive federal AI legislation. Existing regulators (FTC, FDA, SEC) apply current authorities to AI within their domains.

What it actually requires: For most AI systems, nothing mandatory at federal level. NIST AI RMF provides voluntary risk management categories. FTC can act against deceptive AI practices under existing consumer protection authority. FDA regulates AI in medical devices. SEC oversees AI in financial services. Colorado AI Act (effective 2026) requires impact assessments for high-risk AI decisions affecting consumers.

StrengthGap
Strong sector-specific regulation (healthcare, finance)No comprehensive federal AI law
FTC enforcement against deceptive AI practicesNIST AI RMF is voluntary with no enforcement
Active state-level legislationState fragmentation creates compliance complexity
Established IP and liability frameworksNo federal requirements for autonomous agents

United Kingdom

Primary framework: Pro-innovation AI regulation white paper (2023), sector regulator guidance

Status: Deliberately non-legislative. The UK has chosen not to create AI-specific legislation, instead asking existing regulators to apply five principles within their domains.

Approach: Principles-based, regulator-led. Five cross-sector principles: safety/security/robustness, transparency/explainability, fairness, accountability/governance, contestability/redress.

What it actually requires: No new legal requirements specific to AI. Existing regulators (FCA, Ofcom, ICO, CMA) interpret and apply the five principles within their existing mandates. Coverage depends entirely on which sector your AI operates in. The ICO provides AI guidance under existing data protection law (UK GDPR). The FCA regulates AI in financial services. Ofcom covers AI in communications. Sectors without a strong regulator have no AI-specific oversight.

StrengthGap
Strong data protection via UK GDPR and ICONo AI-specific legislation
Financial AI well-regulated through FCACoverage depends on sector, creating blind spots
Flexible, avoids premature regulationFlexibility means no baseline for unregulated sectors
Alan Turing Institute provides technical guidanceNo enforcement mechanism for cross-sector AI harms

Australia

Primary framework: Voluntary AI Ethics Principles (2019), proposed mandatory guardrails (2024 consultation)

Status: Largely voluntary. Government has signalled intent to introduce mandatory guardrails for high-risk AI but has not legislated them. Existing consumer law provides some coverage.

Approach: Principles-based, moving toward mandatory. Eight voluntary AI ethics principles: human/societal/environmental wellbeing, human-centred values, fairness, privacy/security, reliability/safety, transparency/explainability, contestability, accountability.

What it actually requires: No AI-specific mandatory requirements. Australian Consumer Law (ACL) applies to AI-generated misleading or deceptive conduct. Privacy Act covers personal information handling by AI. Sector-specific regulations (TGA for health, APRA for finance) apply within their domains. The proposed mandatory guardrails would require risk assessments and transparency for high-risk AI, but have not been legislated.

StrengthGap
Strong consumer protection law (ACL) applicable to AINo AI-specific mandatory requirements
Privacy Act provides data handling baselineVoluntary principles have no enforcement
Government actively consulting on mandatory guardrailsMandatory guardrails not yet legislated
Sector regulators (TGA, APRA) active in their domainsAutonomous agents not addressed in any framework

China

Primary frameworks: Algorithmic Recommendation Regulation (2022), Deep Synthesis Regulation (2023), Generative AI Regulation (2023), Global AI Governance Initiative

Status: Most prescriptive globally. Multiple overlapping regulations targeting specific AI applications. Mandatory compliance for AI services offered to the public.

Approach: Application-specific, state-controlled. Regulations target algorithmic recommendations, deepfakes/synthetic content, and generative AI separately. Strong emphasis on content control and "socialist core values."

What it actually requires: Algorithmic assessment filings with the Cyberspace Administration of China (CAC). Content generated by AI must be labelled. Generative AI services must undergo security assessments before launch. Training data must be lawfully obtained. AI outputs must not subvert state power, advocate terrorism, or violate other content restrictions. Users must be verified with real identity.

StrengthGap
Mandatory algorithmic assessmentsRegulations designed for state control, not user protection
Content labelling requirements for AI-generated materialContent restrictions based on political alignment, not harm
Security assessment before launchNo independent oversight of assessment process
Real-identity verification for usersPrivacy implications of mandatory identity systems

This tool provides an analytical framework. It is not legal advice. Regulations change. Consult qualified legal counsel for specific compliance decisions.

CC BY-SA 4.0, NOEVA Foundation, 2026