This article is about the structure of multi-jurisdiction obligations, not a survey of jurisdictions. Every national or regional fact used below was read at the administering body's own source and is named as such. Where a jurisdiction is not mentioned, that is not a statement about that jurisdiction, by implication or otherwise. Nothing here is legal advice in any jurisdiction, and the operative wording must be read in the original before any decision is taken on it.
- Obligations come in two shapes. Standards can be exceeded. Acts cannot be pre-performed. Building to the strictest standard satisfies the first kind everywhere and the second kind nowhere.
- There is no single strictest regime, because regimes are not ordered on one axis. They prohibit different things and impose obligations of different kinds, so the union of all prohibitions is not any one country's law.
- Disclosure duties are owed to a person in a place, in a language, at a moment. That is a deployment property, and it does not travel with a build however well engineered.
- Reporting duties differ in artefact and addressee, not only in speed. Meeting the shortest deadline does not produce another regime's annual filing or register entry.
- Evidence transfers between regimes. Determinations never do: scope, role, exemption, and every filing that follows from them are per-jurisdiction and dated.
- The structure that works is one evidence base and N determinations, where the determination page carries a last-checked date, because regimes move on legislatures' calendars rather than yours.
Section 1. The two shapes of obligation
Almost every argument about multi-jurisdiction compliance becomes clearer once one distinction is made, and the distinction is not about strictness at all.
Some obligations are standards. They describe a quality that conduct must reach: perform a risk assessment, ensure appropriate human oversight, maintain technical documentation, test for accuracy and robustness, govern the data. Standards can be exceeded. A risk assessment written to the most demanding available specification will satisfy a less demanding one, and the surplus is not wasted; it is evidence.
Other obligations are acts. They describe a thing that must be done, to a named body, in a form, by a date: register the system, designate an authorised representative, appoint and publish a contact point, notify an authority within a fixed window, make an entry in a database, submit a report in a prescribed template. An act cannot be exceeded and it cannot be pre-performed. There is no quantity of excellent governance that constitutes having filed.
The strictest-regime plan is a plan for the first kind of obligation applied to a world that contains both. Its characteristic output is an organisation whose documentation would satisfy any inspector and which has made no filing, designated nobody and registered nothing outside its home market. That combination is worse than it sounds, because the substantive quality is invisible until somebody looks, whereas a missing registration is visible to a supervisor who has looked at nothing but a register.
The one minute test. Take the list of obligations your programme believes it has discharged, and mark each one either S or A. Standards are S: they describe how well something must be done. Acts are A: they describe something that must be sent, filed, designated or entered somewhere. Then check how many of the A items have a date, a reference number and a named person. In most programmes built on a global control set, the S column is strong and the A column is empty outside one jurisdiction.
Section 2. There is no strictest regime
The plan also assumes something that is not true of the field: that regimes can be ranked. They cannot, because they are not measuring the same thing.
Consider a single practice, the inference of emotional state from workplace signals. In the European Union this is not a matter of documentation standards at all. Article 5(1)(f) of Regulation (EU) 2024/1689 prohibits the placing on the market, putting into service or use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the system is intended to be used for medical or safety reasons. That prohibition has applied since 2 February 2025 and sits at the top penalty tier under Article 99, up to EUR 35,000,000 or 7 per cent of total worldwide annual turnover, whichever is higher, with the lower of the two figures applying to small and medium-sized enterprises and start-ups.
A jurisdiction without that prohibition is not therefore less strict overall. It may impose duties the EU does not. Saudi Arabia's data and AI authority publishes, in its own text, that high-risk AI systems must undergo pre-conformity and post-conformity assessments. Korea's AI Basic Act, Act No. 20676, promulgated 21 January 2025 and in force since 22 January 2026, sets out eleven categories of high-impact AI in Article 2(4), a list that does not match the EU's Annex III and was not derived from it.
So a globally uniform build faces a choice that the strictest-regime framing conceals. Either it is constrained by the union of every prohibition everywhere, which is a more restrictive product than any single regulator asked for and may be commercially unviable, or it is constrained by one regime's set, in which case it is non-compliant somewhere by construction. Neither is wrong as a decision. Both are decisions, and the point is that the strictest-regime plan makes one of them without noticing.
Our comparison of liability standards, which is the same structural point applied to what happens after harm occurs, is at strict liability for AI deployers, and where it now exists.
Section 3. Disclosure is owed to a person, not satisfied by a design
The third failure mode is the one engineering teams find most counterintuitive, because it is the one where the system genuinely is built correctly.
Transparency, notification, explanation and complaint duties are discharged when a particular individual receives a particular thing. That means the right content, in a language they can read, at a moment when it can affect their decision, through a channel the local regime recognises, from an entity they can identify. Each of those is a property of the deployment rather than of the model or the platform.
In the EU the transparency obligations in Article 50 have applied since 2 August 2026, and they split by role: paragraphs 1 and 2 bind providers, paragraphs 3 and 4 bind deployers. The instruments supporting them are now final, which is a materially different position from the high-risk regime, and the current status of each is recorded at agentliability.eu, on which AI Act instruments are final and which are not. A global product team can build machine-readable marking once and deploy it everywhere. It cannot build a local-language notice appearing at the right point in a locally configured flow once and deploy it everywhere, because that notice is assembled by whoever set up the local instance.
This is why disclosure is the most commonly failed obligation in otherwise strong programmes. It is engineered centrally, delivered locally, and documented nowhere, and the organisation's own evidence of compliance is a screenshot of the wrong locale.
Section 4. Clocks and artefacts conflict rather than nest
The fourth failure mode is arithmetic. A deadline is the one dimension on which over-performance genuinely works: a report filed in two days satisfies a fifteen day requirement. Nothing else about a reporting obligation behaves that way.
Article 73 of the EU AI Act requires providers of high-risk AI systems placed on the Union market to report serious incidents to the market surveillance authorities of the Member States where the incident occurred. As displayed on the Commission's AI Act Service Desk on 28 August 2026, the structure is: not later than 15 days after the provider or deployer becomes aware of the incident in the general case, not later than 2 days in the case of a widespread infringement or a serious and irreversible disruption of critical infrastructure, and not later than 10 days in the event of death.
An organisation that can meet the two day case has built a genuinely valuable capability, and it has produced exactly one artefact, addressed to one class of authority, in one form. It has not thereby produced a periodic filing that another regime wants annually, an entry on a register that a third regime maintains, or a report to a sectoral supervisor in a prescribed local format. Those are different documents to different addressees, and a fast incident process does not generate them.
Penalty structures diverge in the same way, which matters because programmes are usually sized against the largest number anyone can find. The EU's Article 99 sets tiered ceilings of EUR 35,000,000 or 7 per cent, EUR 15,000,000 or 3 per cent, and EUR 7,500,000 or 1 per cent, whichever is higher in each case. Korea's Act No. 20676 takes a different shape entirely: Article 43 sets a single maximum of KRW 30 million, attaching to three specified failures. Brazil's PL 2338, which remains a bill rather than an enacted law, provides at Article 50(II) for fines up to BRL 50 million per infraction or 2 per cent of Brazilian gross revenue.
Read those three together and the sizing problem is obvious. A programme calibrated to the EU ceiling will spend heavily on the substantive controls that reduce EU exposure and will not, on that logic, spend anything on the modest administrative acts that discharge obligations elsewhere, because the arithmetic says they do not matter. The arithmetic is right about the fine and wrong about the consequence, since a missing registration in a market is a market access problem before it is a penalty problem.
| Failure mode | Why over-compliance does not fix it | What does |
|---|---|---|
| Administrative acts | An act cannot be pre-performed by doing something else better | A dated per-jurisdiction list of acts with owners |
| Divergent prohibitions | Regimes are not ordered on one axis, so there is no maximum to build to | An explicit decision on union of prohibitions or per-market variance |
| Local disclosure | The duty is owed to a person in a place, not satisfied by a design | Evidence captured at the local instance, per locale |
| Conflicting artefacts and clocks | Speed nests, artefacts and addressees do not | An artefact map: what goes to whom, in what form, when |
Section 5. What transfers, and what never does
None of this means the global control set is wasted. Most of it is genuinely reusable, and knowing precisely which part is the difference between an efficient programme and a duplicated one.
Evidence transfers. The artefacts describing what your system is and how it is governed can be produced once and offered to anyone: the inventory entry, the risk assessment record, the data governance record, the testing and evaluation record, the human oversight arrangement, the change history, the incident record. These are facts about your system. They do not become different facts in a different jurisdiction, and the same pack answers a regulator, a procurement questionnaire and an underwriting submission. Our fuller treatment of what carries across frameworks is at build the evidence once.
Determinations never transfer. Everything built on top of the evidence is jurisdictional and dated: whether this system is inside a given high-risk list, what role you occupy under that regime and whether that regime's roles even map onto the provider and deployer distinction, whether an exemption applies, and every registration, designation, notification and disclosure that follows. A determination is a legal conclusion about one text at one moment, and it expires when the text changes.
The role point deserves emphasis because it causes real errors. A global programme that has decided it is a "deployer" tends to carry that label everywhere. It is a term of art in Regulation (EU) 2024/1689 with a specific definition, set out at agentliability.eu, on the Article 3 definitions, and other regimes use different concepts that overlap without matching. Importing the conclusion along with the vocabulary is how a programme ends up confidently answering a question that was never asked.
Section 6. One evidence base, N determinations
The structure that follows from all of this is unglamorous and cheap, and it is the one thing in this article worth acting on this quarter.
Run one global control set that produces the transferable artefacts continuously. This is where most of the effort and nearly all of the value sits, and it should be built to a high standard because the standard is reusable. The change control and evidence disciplines that produce it are set out at agentcertified.eu, on change control as evidence, and the retirement half of the same discipline is at agentcertified.eu, on decommissioning an agent.
Then run a thin determination layer, one page per jurisdiction where you actually operate, with five fields:
- Which of our systems are in scope in this jurisdiction, and on what reading of which text.
- What role do we occupy under this regime, in that regime's own vocabulary rather than an imported one.
- Which obligations attach, split into standards and acts.
- Which acts are outstanding, with an owner and a date for each.
- When was this page last checked against the administering body's own source, and by whom.
Field five is the one that decays and the one everybody omits. Regimes move on legislatures' calendars, not on review cycles, and a determination page with no check date is an assertion dressed as a record. This desk learned that expensively: an audit of our own jurisdiction guides on 17 August 2026 found that a large share of what had been written about national regimes was out of date, unverifiable, or built on instruments that had been repealed or renamed. The response was to stop publishing that series until every claim could be read at a national source, and the response for an operator is the same in miniature. A page you have not re-read is a page you do not know the contents of.
Section 7. The mistake in the other direction
One corollary is worth stating explicitly because it is the assumption underneath the whole strictest-regime plan: that the European Union is the ceiling and everything else is a subset.
It is a reasonable prior and it is not a rule. Saudi Arabia's published position on pre-conformity and post-conformity assessment for high-risk systems is one counterexample. Korea's eleven high-impact categories are a different list, not a shorter one, and its Article 34 duties are its own. Japan's AI Promotion Act, Law No. 53 of 2025, promulgated 4 June 2025 and fully in force from 1 September 2025, takes a different approach again, setting out five policy principles in Article 3 rather than a prohibition and penalty structure. And in the United States, Colorado's SB 24-205 has an effective date of 30 June 2026 following the extension made by SB25B-004, which is a live sub-national obligation that no EU-calibrated programme will have looked for.
The mirror error is planning around instruments that are not yet law. Brazil's PL 2338 is a bill. It contains twelve categories at Article 14, two risk categories rather than three, and no territorial scope provision at all, which means an operator outside Brazil reasoning about whether it reaches them is reasoning about something the text does not address. Singapore's Personal Data Protection Commission Advisory Guidelines, issued 1 March 2024, state at paragraph 2.2 that they are not legally binding. Neither observation makes those instruments unimportant. Both make them a different kind of thing from an obligation, and a programme that files them in the same column as the EU AI Act will misallocate effort in both directions.
Section 8. The point in one sentence
Doing more of a good thing discharges standards and nothing else, so a global AI programme is only as compliant as its shortest list of completed administrative acts, and that list is the one nobody is looking at because it is not interesting. The evidence work is the expensive part and it genuinely transfers. The filing work is the cheap part and it transfers not at all, which is exactly why it is the part that gets missed.
Questions
Does building to the EU AI Act make us compliant in other countries?
Not by itself, and the reason is structural rather than a matter of degree. Some obligations are standards, which can be exceeded. Others are acts, which cannot be pre-performed: registering a system, designating a representative, filing a notification with a named body within a fixed window, entering something on a register. Building to the strictest standard satisfies the first kind everywhere and the second kind nowhere. The characteristic failure of a highest common denominator programme is a system that would pass every substantive test in every market and has performed no administrative act in any of them, which is also the failure a supervisor detects most easily.
Is there such a thing as the strictest AI regime?
No, because regimes are not ordered on one axis. They prohibit different things, address different populations and impose obligations of different kinds. Article 5(1)(f) of the EU AI Act prohibits using AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where intended for medical or safety reasons, and has applied since 2 February 2025 at the top penalty tier. A jurisdiction with no such prohibition is not thereby less strict overall. Saudi Arabia's own published position is that high-risk AI systems must undergo pre-conformity and post-conformity assessments. The assumption that non-EU means lighter is itself a failure mode.
What actually transfers between AI regulatory regimes?
Evidence transfers. Determinations do not. The artefacts that travel describe what your system is and how it is governed: the inventory entry, the risk assessment record, the data governance record, the testing record, the oversight arrangement, the change history and the incident record. Each can be produced once and offered to any authority, procurement team or insurer. What never transfers is the legal characterisation built on top: whether a system falls inside a given high-risk list, what role you occupy, whether an exemption applies, and every filing that follows. One evidence base, N determinations, is the shape that works.
Why do disclosure obligations not travel with the system?
Because they are owed to a person rather than satisfied by a design. A transparency or notification duty is discharged when a specific individual is told a specific thing, in a language they can read, at a moment when it is useful, through a channel their jurisdiction recognises. A system engineered to the most demanding disclosure standard still fails if the notice appears in the wrong language or at the wrong point in the flow. Disclosure is a deployment property, not a model property, and it is the part of a global build most reliably delegated to whoever configured the local instance and least reliably documented.
Do the strictest reporting deadlines cover the others?
No, because reporting duties differ in artefact and addressee, not only in speed. Article 73 of the EU AI Act requires serious incidents to be reported to the market surveillance authorities of the Member States where the incident occurred, on a structure of not later than 15 days in the general case, not later than 2 days for a widespread infringement or a serious and irreversible disruption of critical infrastructure, and not later than 10 days in the event of death. Meeting a two day clock does not produce another jurisdiction's annual filing, its register entry, or a report to a sectoral supervisor in a prescribed local format.
What structure should a multinational AI governance programme use instead?
One global control set producing evidence artefacts continuously, plus a thin per-jurisdiction determination layer that is dated, owned and reviewed. The determination layer is a page per jurisdiction with five fields: which systems are in scope there, what role we occupy under that regime, which obligations attach split into standards and acts, which acts are outstanding with owners and deadlines, and when the page was last checked against the administering body's own source. That last field is the one that decays, because regimes move on legislatures' calendars rather than yours.