Global AI Compliance in Practice: How Multinationals Navigate the EU AI Act, U.S. Standards, and Chinese Rules (2023–2026)
Authors/Creators
Description
This working paper presents a comparative framework for understanding how multinational enterprises design and operate AI compliance architectures under three major regulatory systems: the EU AI Act, the U.S. standards-led model, and China’s administrative regime, spanning the period from 2023 to 2026.
Drawing on legislative texts, standards, and public corporate disclosures, it argues that firms are converging toward an EU-first documentation spine, reinforced by U.S. evaluation practices and China-specific localization overlays.
The paper proposes the “core + overlays” model: a single compliance infrastructure capable of speaking three legal dialects —documentation, evaluation, and recognition —without fragmenting product integrity. Conceptually, it situates this design within theories of polycentric and experimentalist governance, showing how firms act as translators of legality across jurisdictions.
Originally developed as the author’s bachelor’s thesis at the University of Messina, this version has been expanded and reframed as an independent research working paper to support comparative AI governance scholarship.
Methods (English)
The research employs qualitative comparative analysis (QCA) across three jurisdictions (EU, U.S., PRC).
Primary sources include binding regulations (e.g., Regulation (EU) 2024/1689), official guidance (NIST AI RMF 1.0 & Generative AI Profile), and administrative measures issued by the Cyberspace Administration of China.
Secondary evidence draws on law-firm briefings, think-tank reports, and publicly available corporate disclosures (trust-center statements, bias-audit reports, and filing registries).
A three-dimension coding framework (D1–D3) structures comparison:
D1 = legal form & extraterritorial pull,
D2 = implementation tools (standards, filings, audits),
D3 = organizational impact (policies, roles, artefacts, gates).
Data are mapped into a Compliance Matrix (0–2 scale) and validated through case snapshots (OpenAI, HireVue/Workday, Digital Diagnostics).
The analysis produces an operational synthesis, documentation → evaluation → recognition, capturing how assurance currencies translate across regimes.
Table of contents (English)
| Chapter | Title | Description |
|---|---|---|
| 1 | Introduction | Defines the global compliance problem: one product, three rulebooks. States the research question, scope (2023–2026), and hypotheses. |
| 2 | Theory & Related Work | Builds the analytical toolbox, compliance theory, regulatory models, diffusion and experimentalist governance, introduces D1–D3 framework. |
| 3 | The EU AI Act as a Corporate Compliance Regime | Translates the Act’s legal duties (risk, data, documentation, oversight) into corporate controls and introduces the EU “documentation factory.” |
| 4 | The U.S. AI Compliance Environment | Explains the standards-led approach (NIST RMF, GenAI Profile, OMB M-24-10) and how evaluation evidence replaces pre-market certification. |
| 5 | The China AI Compliance Environment | Analyzes CAC filings, labeling, and security-review obligations; conceptualizes legibility as compliance. |
| 6 | Three Currencies of AI Compliance – The Comparative Matrix | Presents the 0–2 scoring matrix mapping how obligations cluster (documentation |
| 7 | Case Snapshots | Empirical illustrations (OpenAI GPAI, HireVue HR AI, Digital Diagnostics IDx-DR) showing how firms adapt proofs of readiness across regimes. |
| 8 | Speaking in Three Dialects: Implications for Global AI Compliance | Proposes the core + overlays operating model—an EU documentation spine with U.S. and PRC overlays—for scalable corporate compliance. |
| 9 | Conclusion – One Spine, Three Dialects | Synthesizes findings, revisits hypotheses, and theorizes compliance as design within experimentalist global governance. |
Files
Global AI Compliance Guide 2023-2026.pdf
Files
(2.2 MB)
| Name | Size | Download all |
|---|---|---|
|
md5:9e9fc9402a9b45a5e7533a97490dcded
|
2.2 MB | Preview Download |
Additional details
Dates
- Created
-
2024-09-10Initial drafting
- Submitted
-
2025-09-18Final revision
- Available
-
2025-10-15Publication date
References
- Abbott, K. W., & Snidal, D. (2001). International "standards" and international governance. Journal of European Public Policy, 8(3), 345–370. https://doi.org/10.1080/13501760110056013
- Abbott, K. W., & Snidal, D. (2010). International regulation without international government: Improving IO performance through orchestration. Review of International Organizations, 5(3), 315–344. https://doi.org/10.1007/s11558-010-9092-3
- Abbott, K. W., & Snidal, D. (2013). International regulation without international government. Review of International Organizations, 8(3), 315–344.
- Apple Inc. (2024, September 16). Legal—iCloud GCBD terms (China Mainland). https://www.apple.com/legal/internet-services/icloud/en/gcbd-terms.html
- Apple Inc. (2025, April 15). Learn more about iCloud in China Mainland. https://support.apple.com/en-us/111754
- Ayres, I., & Braithwaite, J. (1992). Responsive regulation: Transcending the deregulation debate. Oxford University Press.
- Baldwin, R., Cave, M., & Lodge, M. (2012). Understanding regulation: Theory, strategy, and practice (2nd ed.). Oxford University Press. https://doi.org/10.1093/acprof:osobl/9780199576081.001.0001
- Beck, U. (1992). Risk society: Towards a new modernity. Sage.
- Black, J. (2001). Decentring regulation: Understanding the role of regulation and self-regulation in a "post-regulatory" world. Current Legal Problems, 54(1), 103–146. https://doi.org/10.1093/clp/54.1.103
- Bowker, G. C., & Star, S. L. (1999). Sorting things out: Classification and its consequences. MIT Press. https://doi.org/10.7551/mitpress/6352.001.0001
- Bradford, A. (2015). The Brussels Effect. Northwestern University Law Review, 107(1), 1–68. https://scholarlycommons.law.northwestern.edu/nulr/vol107/iss1/1/
- Bradford, A. (2020). The Brussels effect: How the European Union rules the world. Oxford University Press. https://doi.org/10.1093/oso/9780190088583.001.0001
- Büthe, T., & Mattli, W. (2011). The new global rulers: The privatization of regulation in the world economy. Princeton University Press.
- Cavoukian, A. (2011). Privacy by Design: The 7 foundational principles—Implementation and mapping of fair information practices. Information & Privacy Commissioner of Ontario. https://privacy.ucsc.edu/resources/privacy-by-design---foundational-principles.pdf
- CEN-CENELEC JTC 21. (2025, June). AI standards: Complete detailed overview. https://jtc21.eu/wp-content/uploads/2025/06/CEN-CENELEC-JTC21-AI-Standards-Complete-Detailed-Overview.pdf
- China Aerospace Studies Institute. (2023). Interim Measures for the Management of Generative Artificial Intelligence Services (English translation). Air University. https://www.airuniversity.af.edu/Portals/10/CASI/documents/Translations/2023-08-07%20Interim%20Measures%20for%20the%20Management%20of%20Generative%20Artificial%20Intelligence%20Services.pdf
- China Law Translate. (2022a, January 4). Provisions on the management of algorithmic recommendation for Internet information services [English translation]. https://www.chinalawtranslate.com/en/algorithms/ China Law Translate. (2022b, August 12). List of domestic Internet information service algorithm filings (public registry). https://www.chinalawtranslate.com/en/algorith-listing/
- China Law Translate. (2022c, December 11). Provisions on the administration of deep synthesis Internet information services [English translation]. https://www.chinalawtranslate.com/en/deep-synthesis/
- China Law Translate. (2023, July 10). Interim measures for the management of generative artificial intelligence services [English translation]. https://www.chinalawtranslate.com/en/generative-ai-interim/
- Colorado General Assembly. (2024). Senate Bill 24-205: Consumer protections in interactions with artificial intelligence systems. https://leg.colorado.gov/sites/default/files/2024a_205_signed.pdf
- Creemers, R. (2017). Cyber China: Upgrading propaganda, public opinion work and social management for the twenty-first century. Journal of Contemporary China, 26(103), 85–100. https://doi.org/10.1080/10670564.2016.1206281
- Cyberspace Administration of China. (2022). Provisions on the administration of deep synthesis internet information services [English translation, China Law Translate]. https://www.chinalawtranslate.com/en/deep-synthesis/
- Cyberspace Administration of China. (2023a, July 13). Interim measures for the management of generative artificial intelligence services [Chinese original]. http://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm
- Cyberspace Administration of China. (2023b, July 13). Interim measures for the management of generative artificial intelligence services [English translation, China Law Translate]. https://www.chinalawtranslate.com/en/generative-ai-measures/
- Cyberspace Administration of China. (2025, March 14). Measures for labeling of AI-generated synthetic content [English translation, China Law Translate]. https://www.chinalawtranslate.com/en/ai-labeling/
- DCI Consulting Group. (2023, August 14). New York City Local Law 144 "Bias Audit" for HireVue [Independent audit report]. https://cdn.pfizer.com/pfizercom/CareersEmploymentDocs/HireVue_2023_Bias_Report_14AUG2023.pdf
- DCI Consulting Group. (2025, August 18). New York City Local Law 144 "Bias Audit" for HireVue [Independent audit report]. https://seo.nlx.org/burlington/pdf/HireVue%20Audit%20Results%208.18.25.pdf
- Department of Enterprise, Trade and Employment (Ireland). (2025, February). AI act—SME test. https://enterprise.gov.ie/en/publications/publication-files/sme-test-ai-act.pdf
- Digital Diagnostics. (2018a, April 12). FDA permits marketing of LumineticsCore® (formerly known as IDx-DR) for automated detection of diabetic retinopathy in primary care. https://www.digitaldiagnostics.com/fda-permits-marketing-of-lumineticscore-formerly-known-as-idx-dr-for-automated-detection-of-diabetic-retinopathy-in-primary-care/
- Digital Diagnostics. (2018b, June 26). University of Iowa Health Care first to adopt LumineticsCore® (formerly known as IDx-DR) in a diabetes care setting. https://www.digitaldiagnostics.com/university-of-iowa-health-care-first-to-adopt-lumineticscore-formerly-known-as-idx-dr-in-a-diabetes-care-setting/
- Digital Diagnostics. (2018c, October 23). Topcon's Harmony imaging platform users in Europe now have access to LumineticsCore® (formerly known as IDx-DR). https://www.digitaldiagnostics.com/topcons-harmony-imaging-platform-users-in-europe-now-have-access-to-lumineticscore-formerly-known-as-idx-dr/
- Digital Policy Alert. (2025, May 19). Published eleventh CAC domestic deep synthesis service algorithm filing list (and subsequent batches). https://digitalpolicyalert.org/event/30130-published-eleventh-cac-domestic-deep-synthesis-service-algorithm-filing-list
- DigiChina (Stanford University Cyber Policy Center). (2022a, March 1). Translation: Internet information service algorithmic recommendation management provisions—effective March 1, 2022. https://digichina.stanford.edu/work/translation-internet-information-service-algorithmic-recommendation-management-provisions-effective-march-1-2022/
- DigiChina (Stanford University Cyber Policy Center). (2022b, April 11). Translation: Notice on conducting the "Clear 2022" comprehensive governance of algorithms special action. https://digichina.stanford.edu/work/translation-notice-on-conducting-the-clear-2022-comprehensive-governance-of-algorithms-special-action/
- DigiChina (Stanford University Cyber Policy Center). (2022c, July 8). Translation: Outbound data transfer security assessment measures—effective September 1, 2022. https://digichina.stanford.edu/work/translation-outbound-data-transfer-security-assessment-measures-effective-sept-1-2022/
- DiMaggio, P. J., & Powell, W. W. (1983). The iron cage revisited: Institutional isomorphism and collective rationality in organizational fields. American Sociological Review, 48(2), 147–160. https://doi.org/10.2307/2095101
- Edelman, L. B. (2016). Working law: Courts, corporations, and symbolic civil rights. University of Chicago Press. https://doi.org/10.7208/chicago/9780226400938.001.0001
- European Commission. (2022). The "Blue Guide" on the implementation of EU product rules (2022 edition). https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52022XC0629(04)
- European Commission. (2024, January 24). Commission Decision establishing the European Artificial Intelligence Office (C/2024/390). https://eur-lex.europa.eu/eli/C/2024/1459/oj/eng
- European Commission. (2025a, February 4). Commission publishes the guidelines on prohibited artificial intelligence (AI) practices, as defined by the AI Act. https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act
- European Commission. (2025b, February 6). Commission publishes guidelines on AI system definition to facilitate the first AI Act's rules application. https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application
- European Commission. (2025c, July 10). General-purpose AI code of practice now available [Press release]. https://ec.europa.eu/commission/presscorner/detail/en/ip_25_1787
- European Commission. (2025d, July 10). The general-purpose AI code of practice. https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai
- European Commission. (2025e–i). European AI office, explanatory notices, and guidelines for general-purpose AI models. Retrieved from https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers
- European Commission. (2025j, September 26). AI Act: Commission issues draft guidance and reporting template for serious AI incidents (consultation). https://digital-strategy.ec.europa.eu/en/consultations/ai-act-commission-issues-draft-guidance-and-reporting-template-serious-ai-incidents-and-seeks
- European DIGITAL SME Alliance. (2025). AI act conformity tool. https://www.digitalsme.eu/ai-act-conformity-tool/
- European Parliament and Council of the European Union. (2012). Regulation (EU) No 1025/2012 of 25 October 2012 on European standardisation. Official Journal of the European Union, L 316, 12–33. https://eur-lex.europa.eu/eli/reg/2012/1025/oj/eng
- European Parliament and Council of the European Union. (2024). Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union, L 2024/1689. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- Levi-Faur, D. (2005). The global diffusion of regulatory capitalism. The Annals of the American Academy of Political and Social Science, 598(1), 12–32. https://doi.org/10.1177/0002716204272371
- Minzner, C. (2011). Formalism and campaign-style legal implementation in China. The China Quarterly, 205, 83–101. NIST. (2023–2024). Artificial Intelligence Risk Management Framework (AI RMF 1.0) and Generative AI Profile (AI 600-1). https://doi.org/10.6028/NIST.AI.100-1
- Ostrom, E. (2010). Beyond markets and states: Polycentric governance of complex economic systems. American Economic Review, 100(3), 641–672. https://doi.org/10.1257/aer.100.3.641
- Power, M. (1997). The audit society: Rituals of verification. Oxford University Press.
- Sabel, C. F., & Zeitlin, J. (2008). Learning from difference: The new architecture of experimentalist governance in the EU. European Law Journal, 14(3), 271–327. https://doi.org/10.1111/j.1468-0386.2008.00415.x
- Scott, J. C. (1998). Seeing like a state: How certain schemes to improve the human condition have failed. Yale University Press.
- Star, S. L., & Griesemer, J. R. (1989). Institutional ecology, "translations" and boundary objects: Amateurs and professionals in Berkeley's Museum of Vertebrate Zoology, 1907–39. Social Studies of Science, 19(3), 387–420. https://doi.org/10.1177/030631289019003001