The AI rules are already here. The map is the mess.

The AI rules are already here. The map is the mess.

The rules are already in force. The map is the mess.

If you operate across borders, AI law is not a 2028 item. The EU AI Act is live. China's generative rules have been on since 2023. The U.S. is still sector cops: FTC, FDA, EEOC. Brazil, Canada, and the UK are writing their own versions. A system that is fine in one country can be restricted in the next.

Waiting for one global standard is not a strategy. There is not one coming.

Four places this bites first

Risk tier under the EU Act. Unacceptable, high, limited, minimal. Hiring, credit, healthcare, and critical infrastructure sit in high-risk: documentation, human oversight, third-party checks before you ship. If you sell into Europe, know the tier before go-live. The Act is the strictest rule on the books, so it is a decent floor for planning everywhere else.

Where the data lives. China keeps some categories in-country. GDPR limits sending personal data to places without an adequacy story. India's DPDP adds another layer. You need a data-flow map for every system that touches personal information.

Your industry rules did not go away. A bank using models for credit still has consumer-finance law in every market. A health company using diagnostics still has device rules. AI compliance is not one workstream that replaces those. Name an owner per domain and geography.

Can you explain the decision? The EU Act wants technical docs on high-risk systems. GDPR Article 22 lets people contest purely automated calls. Similar language is showing up in Latin America. If your stack cannot produce an audit trail, that is the gap.

A structure that does not wait for clarity

Inventory every model you run or buy, including the ones a business unit signed up for on a credit card. For each: countries, data, decisions. Map that to the law. Legal owns the map. Tech owns architecture and flows. The business names the use and who is affected.

  • Classify with the EU tiers as the reference.
  • Mark cross-border and residency risk on the data map.
  • Assign a regulatory owner per major market.
  • Review the rule changes at least quarterly.
  • Read vendor contracts for documentation and audit rights, not just the feature list.

The EU Act can fine up to 35 million euros or 7% of global turnover. Past the fine, weak governance is starting to show up in procurement, banking, and investor questions. Teams that build the map once stop restarting legal review from zero on every new tool.

Inventory. Map the data. Name owners. Do it before enforcement writes the timeline for you.

Subscribe to NetNerd AI

Sign up now to get access to the library of members-only issues.
Jamie Larson
Subscribe