When AI regulation fragments faster than organizations can adapt
Level
Medium
Timing
Pre deployment
What this risk is
The coexistence of multiple, incompatible AI regulatory frameworks across jurisdictions creating compliance complexity, regulatory arbitrage opportunities, enforcement gaps, and situations where AI harms fall through jurisdictional cracks — governed by nobody.
This is the meta-governance problem: even if every individual framework were well-designed, their incompatibility creates systemic vulnerabilities.
How it occurs · Mechanisms
| Jurisdiction | Primary Framework | Status | Key Difference |
|---|---|---|---|
| EU | EU AI Act | In force (phased) | Risk-based, prescriptive, mandatory |
| UK | Pro-innovation AI regulation | Framework only, no single law | Sector-led, voluntary, flexible |
| US | NIST AI RMF + EO 14110 | Voluntary framework + EO | Voluntary, sector-specific, fragmented |
| China | Multiple AI regulations | Mandatory | Focus on content, generative AI, platforms |
| Brazil | AI Act (in progress) | Legislative process | EU-influenced but not identical |
| India | Advisory frameworks | Non-binding | Sector-specific guidance |
| Japan | AI Guidelines | Non-binding | Agile governance, light-touch |
| Canada | AIDA (stalled) | Uncertain | Originally proposed mandatory framework |
Key finding: No two major jurisdictions have compatible mandatory AI governance frameworks. The EU AI Act is the only enacted comprehensive mandatory framework.
Risk you cannot name is risk you cannot manage.
Map your AI portfolio against this taxonomy with Zertia.
