Policy & Regulation 11 min read

Regulating Artificial Intelligence Across Borders

J

Jared Clark

March 27, 2026


The world is trying to govern a technology that doesn't respect borders, and the seams are starting to show.

In March 2026, legal scholar Lee Tiedrich published a detailed analysis through The Regulatory Review examining both global and domestic regulatory approaches to general-purpose AI. The piece arrives at exactly the right moment: a period when the regulatory landscape for artificial intelligence is not converging, as many once hoped, but actively diverging. Different jurisdictions are making fundamentally different bets about what AI governance should look like, and the consequences of that fragmentation are landing on every organization that builds, deploys, or depends on AI systems.

This isn't just a policy story. It's a business story, a geopolitical story, and, ultimately, a story about what kind of future we're collectively designing.


Why Cross-Border AI Regulation Is So Hard to Get Right

To understand why governing AI across borders is uniquely difficult, it helps to understand what makes AI different from previous technologies that attracted international regulatory attention.

Prior technologies, pharmaceuticals, aviation, financial instruments, could be governed at the point of production or distribution. A drug has a manufacturer. A plane has an operator. An AI system, particularly a general-purpose one, is different: it's trained in one country, fine-tuned in another, deployed via APIs globally, and used in ways its original developers never anticipated. The supply chain for a single AI model can span dozens of jurisdictions before it reaches an end user.

A growing number of countries have adopted or are actively developing national AI strategies or regulatory frameworks.

The core challenge is a philosophical one: governments disagree not just about how to regulate AI, but about what AI regulation is fundamentally for. Is it primarily a safety instrument? A competitiveness instrument? A human rights instrument? The answer to that question shapes everything downstream.


The Three Dominant Regulatory Models

To navigate this landscape, it helps to think in terms of three dominant regulatory paradigms currently taking shape globally.

1. The Risk-Tiered Compliance Model (EU)

The European Union's AI Act, the world's first comprehensive horizontal AI regulation, entered into force in August 2024 and is phasing in through 2027. It establishes a tiered risk framework: AI systems are categorized as unacceptable risk (banned outright), high risk (subject to mandatory conformity assessments), limited risk (transparency obligations), and minimal risk (essentially unregulated).

The EU AI Act defines "general-purpose AI models" with systemic risk as those trained using more than 10^25 FLOPs of compute, a threshold that currently captures only a handful of frontier models from companies like OpenAI, Google, and Anthropic.

This is a compliance-first model. It places obligations on providers and deployers, requires documentation, human oversight mechanisms, and post-market monitoring. It is, in short, borrowed heavily from the EU's experience regulating pharmaceuticals and medical devices.

2. The Sectoral, Principles-Based Model (US)

The United States, by contrast, has largely pursued a fragmented, sector-by-sector approach. Executive Order 14110 from 2023 established broad principles and tasked federal agencies to develop domain-specific guidance. The Biden administration's AI Safety Institute (AISI) at NIST took on voluntary evaluation frameworks. The Trump administration has since signaled a lighter regulatory touch, emphasizing innovation and American competitiveness over prescriptive oversight.

A 2025 Stanford HAI report found that U.S. federal AI regulations remain predominantly voluntary and guidance-based, with fewer than 10 binding rules specifically targeting AI systems enacted at the federal level.

This means that in the U.S., AI governance is currently happening more through liability exposure, contract law, and sector-specific regulators (the FTC, SEC, EEOC, FDA) than through purpose-built AI legislation. It's a permissive environment, intentionally so, but it creates significant ambiguity for organizations trying to understand their obligations.

3. The State-Led Sovereignty Model (China + Others)

China represents a third model: sovereignty-first AI governance. China has enacted a series of targeted regulations, on algorithmic recommendations (2022), deep synthesis (deepfakes, 2022), and generative AI (2023): that prioritize state oversight, content control, and national security. The framework is less about protecting individual users from AI harms and more about ensuring AI systems align with state objectives.

Several other countries, including Russia, the UAE, and parts of Southeast Asia, are developing analogous models that blend innovation promotion with strong state oversight mechanisms.

Model Primary Driver Key Mechanism Examples
Risk-Tiered Compliance Safety & Fundamental Rights Mandatory conformity assessments, documentation EU AI Act
Sectoral / Principles-Based Innovation & Competitiveness Voluntary frameworks, sector guidance United States
State Sovereignty National Security & Control Targeted regulations, content oversight China, UAE
Emerging / Hybrid Varies by context Combination of above India, Brazil, UK

General-Purpose AI: The Hardest Case

Tiedrich's analysis in The Regulatory Review focuses specifically on general-purpose AI (GPAI), and this is where the regulatory challenge becomes most acute.

GPAI models like GPT-4, Claude, Gemini, and their successors are not designed for a single use case. They are trained on broad datasets to perform a vast range of tasks, and they're deployed into pipelines where downstream applications multiply the potential for both benefit and harm. Governing them requires regulators to make decisions about systems whose full range of uses, and misuses, is genuinely unknowable at the time of regulation.

This creates a fundamental problem: the traditional regulatory strategy of governing at the point of use breaks down when a single model can be the foundation for thousands of different applications simultaneously.

The EU's approach is to regulate at the model level for frontier systems, and at the application level for high-risk uses. But this creates a seam: who is responsible when a general-purpose model is fine-tuned by a third party for a high-risk application in a country with different standards? The liability chain becomes murky, and enforcement becomes practically very difficult.


What International Coordination Looks Like — and Where It Falls Short

There are active efforts to build international coordination on AI governance, and it would be misleading to suggest the world is going in entirely opposite directions. Several mechanisms deserve attention:

The Bletchley Declaration (2023) brought together 28 countries, including the U.S., UK, EU, and China — to agree on shared principles around frontier AI safety. It was a political statement, not a binding instrument, but it demonstrated that even geopolitical rivals can find common ground on AI safety framing.

The OECD AI Principles, adopted by 46 countries, establish non-binding norms around transparency, accountability, robustness, and human-centric values. The OECD's AI Policy Observatory is building one of the most comprehensive comparative databases of AI policy globally.

The G7 Hiroshima AI Process produced the International Code of Conduct for Advanced AI Systems in 2023 — eleven voluntary principles aimed at frontier model developers.

The Council of Europe's AI Convention (Framework Convention on Artificial Intelligence, opened for signature in 2024) is the first legally binding international AI treaty, focused specifically on human rights, democracy, and the rule of law. It extends beyond Council of Europe members, allowing non-European countries to join.

The honest assessment: these mechanisms represent meaningful progress in norm-setting, but they do not constitute a coherent global governance architecture. They are fragmented, overlapping, mostly non-binding, and frequently bypassed in favor of unilateral national action when economic or security interests diverge.

The gap between the rhetoric of international AI cooperation and the reality of diverging national regulations is one of the defining governance tensions of this decade.


What This Means for Your Organization

If your organization builds, deploys, or procures AI systems, the fracturing regulatory landscape isn't an abstract policy concern — it translates into concrete operational and strategic challenges.

Compliance cost multiplication. Organizations operating across jurisdictions must navigate overlapping and sometimes contradictory requirements. The EU AI Act's documentation requirements, the U.S.'s sector-specific obligations, China's generative AI registration requirements — these don't harmonize neatly. Companies that once built a single compliance program now need regionally differentiated ones.

Liability ambiguity in the supply chain. When your AI system is built on a foundation model from one jurisdiction, fine-tuned by a vendor in a second, and deployed in a third, the question of who bears liability for harms becomes genuinely unclear. Courts and regulators are only beginning to work through these questions, and early decisions are likely to be inconsistent across jurisdictions.

Regulatory arbitrage — and its risks. The divergence in national approaches creates opportunities for regulatory arbitrage: locating development, training, or deployment in more permissive jurisdictions to avoid stricter requirements. This is already happening. But organizations that pursue this strategy should be aware that regulators in stricter jurisdictions are developing extraterritorial reach — the EU AI Act, like GDPR before it, applies based on where users are located, not where providers are incorporated.

Procurement and vendor due diligence. Organizations that don't build AI but procure it face a different challenge: they need to understand what regulatory exposure their vendors' systems carry. A foundation model trained on data scraped in violation of EU copyright norms, or a system that lacks the documentation required under the EU AI Act, becomes their problem when they deploy it in covered markets.


The Deeper Question: Can AI Governance Go Global?

There's a reasonable case to be made that meaningful global AI governance is structurally very difficult to achieve — not because of lack of political will, but because of genuine disagreements about values.

The EU's AI Act is grounded in a fundamental rights framework: it's designed to protect individuals from discriminatory, opaque, or dangerous AI decisions. The U.S. approach is grounded in a market competition framework: it's designed to let innovation flourish while using liability and sector-specific enforcement as guardrails. China's framework is grounded in a national governance framework: it's designed to ensure AI serves the state's developmental and security objectives.

These aren't just different regulatory techniques. They reflect different answers to foundational questions: What is AI governance for? Who does it serve? What counts as an AI harm?

Until those underlying philosophical questions have more convergence — and that's a political and cultural process, not just a technical one — the best we can expect from international coordination is norm-setting at the margins and mutual recognition agreements on specific technical standards. Real harmonization is likely a decade or more away, if it comes at all.

In the meantime, organizations and policymakers need to operate in the world as it is: a fragmented, overlapping, rapidly evolving patchwork of national AI regulations that is genuinely difficult to navigate.


What to Watch in the Next 12–18 Months

Several developments will be particularly significant for anyone tracking AI governance across borders:

  • EU AI Act enforcement milestones. The prohibition on unacceptable-risk AI systems took effect in February 2025. Obligations on general-purpose AI model providers are phasing in through August 2025. High-risk system requirements apply fully from August 2026. How the European AI Office exercises its enforcement authority against non-EU providers will be defining.

  • U.S. federal legislation. Congress has introduced dozens of AI-related bills, but none have become law. The current political environment makes comprehensive federal AI legislation unlikely in the near term, but sector-specific rules from agencies like the FTC and EEOC are continuing to develop.

  • Council of Europe Convention ratifications. Which non-European countries choose to join the Framework Convention on Artificial Intelligence will signal how broadly the human rights framing of AI governance can spread.

  • China-U.S. AI governance dialogue. Despite geopolitical tensions, there are quiet diplomatic conversations about AI safety norms. Whether these produce any concrete agreements — or whether AI governance becomes another arena of strategic competition — will shape the global landscape significantly.

  • Emerging market positions. India, Brazil, Indonesia, and the African Union are all developing AI governance frameworks. Their choices about which model to adopt — or whether to develop genuinely new approaches — will matter enormously for global norm-setting.


The Bottom Line

The vision of a unified global framework for AI governance remains, for now, aspirational. What we have instead is a complex, evolving patchwork of national regulations, voluntary international principles, and emerging binding instruments — all moving at different speeds and pulling in different directions.

For organizations navigating this landscape, the imperative is clarity about where your AI systems touch regulated markets, humility about how fast the rules are changing, and genuine investment in governance infrastructure that can adapt as the landscape shifts.

For policymakers, the imperative is more coordination than competition — recognizing that AI harms don't stop at borders, and that fragmented governance creates gaps that bad actors can exploit as surely as it creates burdens that good-faith organizations struggle to meet.

The technology is already global. The question is whether governance can catch up — and who gets to write the rules in the meantime.


Last updated: 2026-03-27

J

Jared Clark

Founder, Prepare for AI

Jared Clark is the founder of Prepare for AI, a thought leadership platform exploring how AI transforms institutions, work, and society.