When AI regulation fragments faster than organizations can adapt

Level Medium Timing Pre deployment

What this risk is

The coexistence of multiple, incompatible AI regulatory frameworks across jurisdictions creating compliance complexity, regulatory arbitrage opportunities, enforcement gaps, and situations where AI harms fall through jurisdictional cracks — governed by nobody.

This is the meta-governance problem: even if every individual framework were well-designed, their incompatibility creates systemic vulnerabilities.

How it occurs · Mechanisms

Jurisdiction Primary Framework Status Key Difference
EU EU AI Act In force (phased) Risk-based, prescriptive, mandatory
UK Pro-innovation AI regulation Framework only, no single law Sector-led, voluntary, flexible
US NIST AI RMF + EO 14110 Voluntary framework + EO Voluntary, sector-specific, fragmented
China Multiple AI regulations Mandatory Focus on content, generative AI, platforms
Brazil AI Act (in progress) Legislative process EU-influenced but not identical
India Advisory frameworks Non-binding Sector-specific guidance
Japan AI Guidelines Non-binding Agile governance, light-touch
Canada AIDA (stalled) Uncertain Originally proposed mandatory framework

Key finding: No two major jurisdictions have compatible mandatory AI governance frameworks. The EU AI Act is the only enacted comprehensive mandatory framework.

Risk you cannot name is risk you cannot manage.

Map your AI portfolio against this taxonomy with Zertia.