AI, Regulation, Geopolitics and Global Competition
Two outside forces shape what any company can do with AI. Rules decide what you may do in each market, and they are diverging and moving. Geopolitics decides what you can get, from chips to models, and it can change overnight. Map both for each use in each market, build once where the rules agree, and switch where they conflict.
After this chapter you can
- Distinguish rules, which govern what a company may do, from geopolitical access, which governs what it can obtain.
- Compare the EU, US, Chinese and Korean approaches to AI regulation and name their key dates as of October 2026.
- Explain why the legal calendar moves, using the 2026 EU Omnibus and the US federal preemption push, and why preemption is not repeal.
- Build a use-by-market map that shows how one AI feature carries different duties in different jurisdictions.
- Explain how chip export controls and model availability by country create indirect exposure for AI users.
- Choose between building once to the strictest rule, market switches and a separate stack.
Picture the one-page AI rules calendar that the legal team of a retailer selling in Europe, the United States and South Korea might have put in front of its board in January 2026. Every date on it was the official date at the time. The page itself is a mock-up; the dates are not.
By October, three of the five rows were wrong. The sharpest change was in Europe. The high-risk duties for systems used in hiring, credit and essential services had been due on 2 August 2026. A regulation amending the AI Act entered into force on 27 July 2026, six days earlier, and moved them to 2 December 20271. In Colorado, the first US state law aimed at algorithmic discrimination was replaced before it ever took effect2. In Washington, the White House was asking Congress to override state AI laws altogether3.
None of this was treated as a crisis. It was the year’s normal motion, and for a company using AI across borders the outside world is a moving input to the plan.
Two forces, not one
Executives often fold everything external into one word, regulation. It helps to separate two forces, because they behave differently and call for different responses.
Rules are laws, regulations and binding guidance about what you may do in a market, usually for a particular use: telling people they are talking to a machine, labeling a generated image, auditing a hiring tool. They arrive with dates, drafts and consultations, even when the dates later move.
Access is the supply side: whether you can buy the chips, rent the compute, use a given model, keep data in a given place or sell in a given country. Trade policy and national security decisions shape it, and they can arrive by announcement. Export controls are themselves law, so the two overlap, but they ask different questions. Rules ask “are we allowed?” Access asks “will we still have it?”
Four rulebooks, not one
There is no global AI law. Four approaches show the range a company operating internationally faces in 2026, and they rest on different ideas of what the problem is.
The European Union has a single statute, the AI Act, which sorts systems by risk and assigns duties by role: provider or deployer4. Its obligations for general-purpose model providers, described in The Evolution of AI Models, are only one layer of it.
The United States has no federal AI statute. The rules that bite are state and city laws, such as New York City’s bias-audit rule for hiring tools, plus sector regulators. Federal policy is now pulling the other way: Executive Order 14365 of December 2025 set up a Justice Department task force to challenge state AI laws, and the March 2026 National Policy Framework asked Congress to preempt “burdensome” ones53.
China regulates generative AI services offered to the public, which need security assessment and filing. Since 1 September 2025, generated text, images, audio and video must carry both a visible label and a machine-readable one6.
South Korea’s AI Basic Act, in force since 22 January 2026, is a framework law in the EU’s spirit but lighter: notice of AI use and AI-generated content, extra duties for high-impact uses such as hiring and credit, and a local representative for foreign providers7.
A Council of Europe treaty on AI and human rights sits above all four, but it binds only countries that ratify it8.
The calendar moves
The second lesson of the hook is that the legal calendar is not fixed. The EU’s own timeline shows how much has changed since the Act entered into force in August 2024.
The amendment, known as the Digital Omnibus on AI, also added two prohibited uses and softened the AI-literacy duty. It kept the transparency duties at 2 August 2026, with one short transition: generative systems already on the market have until 2 December 2026 for machine-readable marking19. A company that had paused all work waiting for the Act to “settle” would have missed the dates that did not move.
The US pattern is different. Executive orders and frameworks signal direction, but they are not statutes, and they do not repeal state laws. Until Congress or the courts act, New York City’s hiring rule still applies, and Colorado’s replacement law takes effect on 1 January 20272. A preemption push is a reason to watch, not a reason to stop complying.
Classify the use, market by market
The practical consequence of four rulebooks is that the same feature carries different duties in different markets. A risk classification, as AI Inventory and Risk Classification in Module 07 set out, tells you how dangerous a use is. A market map tells you what each jurisdiction requires of it.
Two things stand out. The duties attach to the use, not the model: the same model behind a product-copy tool and a hiring screen produces two very different compliance burdens. And the duties cluster. Disclosure and labeling now appear in three of four rulebooks, while hiring tools are treated as high-risk or high-impact almost everywhere they are regulated. Those clusters are where one design can serve many markets.
Geopolitics: access, not permission
The second force is harder to see from a retailer’s head office, because it usually arrives through suppliers. The clearest example is advanced chips.
In January 2025 the US government issued a rule to license advanced chips worldwide in three tiers of countries. It was rescinded in May 2025, before it applied, while controls on China continued10. In April 2025 Nvidia was told it needed a license to sell its H20 chip to China, and booked a 4.5 billion dollar charge for inventory it could no longer sell1112. In December 2025 the President announced that H200 chips could be sold to approved Chinese customers with a quarter of the revenue going to the US government, and in January 2026 the Commerce Department moved to case-by-case review1314.
A retailer does not export chips. But it rents the compute those chips provide, so the cost and capacity it can buy depend on these decisions. The same is true of models: whether a given model can be used depends on the country, and its provider can change that. The model you build on is part of your market access.
Governments call the control of these things sovereignty. For a company it comes down to six questions about each critical AI capability: where the data is stored and processed, under whose law the model provider operates, where the compute runs, where the chips come from, which market rules apply, and what the tested alternative is if the model vanished from one market tomorrow.
Build once where rules agree, switch where they conflict
How should a product team respond to four rulebooks and unstable access? The legal scholar Anu Bradford named one answer the Brussels effect: firms selling into the EU often adopt its rules everywhere, because one global standard is cheaper than several15. That works when the rules point the same way. It fails when they conflict.
Labels and disclosures are the clearest build-once case. Telling a customer that the assistant is an AI, and marking generated images visibly and in metadata, satisfies the EU, Korea and China at once, and costs little more than doing it for one market. Bias audits for hiring tools are a strictest core with local extras: test once to a high standard, then publish or file in the form each jurisdiction asks for.
Market switches are for genuine conflicts. A model that is not available in a market, a data path that may not cross a border, or a filing that a foreign service cannot make all call for a different configuration by market, not one design for all. And sometimes the cost of a separate stack is high enough that the right answer is to stay out of a market for that use. That is a board decision, and it should be made explicitly. How to keep a tested path to a second provider is covered in Model and Third-Party Risk, Module 06; it is the precondition for every switch.
Story: an assistant that reached Europe eighteen months late
Meta launched its AI assistant, Meta AI, inside WhatsApp, Messenger and Instagram in the United States in September 202316. People in the European Union did not get it until March 2025, and then only in part. The eighteen months in between show both forces of this chapter acting on one product.
The first force was rules. In June 2024 Meta planned to train its models on public posts by adult Facebook and Instagram users in the EU. Ireland’s Data Protection Commission, its lead regulator, raised concerns on behalf of other European authorities, and Meta paused the training17. Meta called the pause “a step backwards for European innovation”18. When the assistant arrived in 41 European countries in March 2025, it offered text chat only, in six languages19. In May 2025 the regulator said it would not stop training from 27 May, after Meta had sent new notices to users, made its objection form easier to find and lengthened the notice period17. What unlocked the market was notice, a way to say no and documentation: the disclosure-and-control cluster that can be built once.
The second force was access, and here Meta was the one deciding. In July 2024 it said it would release a multimodal Llama model “but not in the EU due to the unpredictable nature of the European regulatory environment”20. When Llama 3.2 appeared in September 2024, its license did not grant the right to use the multimodal models to individuals or companies based in the EU21. A European company building on an openly licensed model found the vision versions closed to it, not by a statute but by its provider’s reading of the rules.
Read the case through the floor-or-switch matrix. Meta ran different configurations by market: the full assistant in the United States, text chat only in Europe, and a model license with an EU carve-out. Those were explicit, company-level decisions about where to switch and where to stay out, and their price was time. The outside world, not the product plan, set the European timetable. For a company that uses AI rather than builds it, the lesson runs the other way too: the model you build on can come with its own map of where you may use it, and that map can change.
What this means for leaders
The argument comes down to four habits. Separate the two forces: for each critical AI capability, ask what the rules require and what could cut off access, and give the two questions different owners. Keep a market map rather than a global answer, classifying each use in each market and updating it when a dated duty arrives or moves. Build to the clusters, making disclosure, labels and logs standard everywhere and keeping switches and separate stacks for genuine conflicts. And treat preemption and policy swings as signals, not exemptions: comply with what is in force, and watch what is coming.
Check yourself
- The EU AI Act’s high-risk duties for hiring systems have applied since August 2026.
- A US executive order can, by itself, cancel a state AI law.
- The same AI feature can carry different legal duties in different markets.
- Chip export controls matter only to chipmakers and cloud providers.
- Building to the strictest rule everywhere is always the cheapest approach.
- Both China and the EU now require AI-generated content to be labeled.
Reflection: draw your own calendar
What comes next
Rules move, access swings, and neither can be forecast with confidence. Leaders still have to commit money and people now. The next chapter, Preparing for AI Uncertainty and Strategic Change, turns that uncertainty into a planning discipline: how to decide when capabilities, costs, rules and competitors are all changing faster than the annual plan.
Laws referenced
Not legal advice. Laws change; verify before relying on this, and consult counsel for decisions.
EU AI Act · EU
Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744
Risk-based rules. Prohibited practices include social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). High-risk systems (Annex III: biometrics, safety components of critical infrastructure such as energy, water and traffic, employment and worker management, credit, education, essential services, law enforcement, migration, justice) need risk management, data governance, documentation, logging, human oversight, human oversight that keeps people able to understand the system, notice automation bias (over-reliance on its output), override it or stop it (Art. 14(4)), appropriate accuracy, robustness and cybersecurity (Art. 15), automatic logging of events (Art. 12), a provider quality-management system (Art. 17) and conformity assessment. An Annex III system is not high-risk if it poses no significant risk of harm, for example a narrow procedural or preparatory task that does not replace human assessment; systems that profile people are always high-risk, and a provider relying on this exception must document it and register (Art. 6(3)). Deployers of high-risk AI must use it as instructed, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents (Art. 26); employers must inform workers' representatives (Art. 26(7)). Public bodies, private providers of public services, and deployers of credit-scoring or life and health insurance pricing systems must carry out a fundamental-rights impact assessment before first use (Art. 27). Providers must run post-market monitoring (Art. 72). A deployer that puts its name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk takes on the provider's obligations (Art. 25(1)). A substantial modification (Art. 3(23)) of a high-risk system needs a new conformity assessment, unless the change was pre-determined and documented at the first assessment, as with planned continuous learning (Art. 43(4)). Providers of general-purpose AI models (from 2 Aug 2025) must keep technical documentation, have a policy to comply with EU copyright law including text-and-data-mining opt-outs, and publish a sufficiently detailed summary of training content (Art. 53). Research, testing and development before a system is placed on the market or put into service is outside the Act, except testing in real-world conditions (Art. 2(8)). Since the 2026 Omnibus, the Art. 4 AI-literacy duty is an obligation of effort (take measures to support literacy), not of result. Fines reach EUR 35 million or 7% of global turnover for prohibited practices.
- 2024-08-01 — Entered into force
- 2025-02-02 — Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply
- 2026-07-27 — Omnibus softens Art. 4: providers and deployers must take measures to support AI literacy; no specific level must be guaranteed
- 2025-08-02 — General-purpose AI model obligations apply; governance and penalties regime in place
- 2026-08-02 — Transparency duties (Art. 50) apply: disclose AI interaction, label synthetic and deepfake content (marking for generative systems already on the market: 2 Dec 2026)
- 2027-12-02 — High-risk obligations for Annex III systems (e.g. hiring, credit, education, essential services) - moved from 2 Aug 2026 by the 2026 Omnibus
- 2028-08-02 — High-risk obligations for AI in products regulated under Annex I
Last verified 2026-10-06 · official text
EU Digital Omnibus on AI · EU
Regulation (EU) 2026/1744
First amendment to the AI Act. Defers high-risk obligations (Annex III to 2 Dec 2027, Annex I to 2 Aug 2028), adds two prohibited categories, softens the Art. 4 AI-literacy duty to "take measures to support", and simplifies some compliance duties. Art. 50 transparency duties still apply from 2 Aug 2026, with one transition (new Art. 111(4)): providers of generative AI systems placed on the market before 2 Aug 2026 must meet the Art. 50(2) marking duty by 2 Dec 2026.
- 2026-07-24 — Published in the Official Journal
- 2026-07-27 — Entered into force
- 2026-12-02 — Grace period ends for safeguards against two new prohibited uses (non-consensual intimate imagery, child sexual abuse material)
- 2026-12-02 — Art. 50(2) marking duty applies to generative AI systems placed on the market before 2 Aug 2026 (Art. 111(4))
Last verified 2026-10-10 · official text
US federal AI policy and state-law preemption push · US - federal
Executive Order 14365 (11 Dec 2025); White House National Policy Framework for AI (20 Mar 2026)
The federal government is seeking to override "burdensome" state AI laws and has asked Congress for a national framework. These are executive actions and recommendations, not a federal AI statute. State laws such as NYC LL144 still apply until changed by law or the courts.
Last verified 2026-10-06
Colorado AI law · US - Colorado
SB 24-205, repealed and re-enacted by SB 26-189 (signed 14 May 2026)
The first US state law aimed at algorithmic discrimination in consequential decisions. It was delayed and then replaced by a narrower, notice-based framework before it ever took effect. Expect further change.
- 2027-01-01 — Operative requirements of SB 26-189 take effect
Last verified 2026-10-06
NYC Local Law 144 (automated employment decision tools) · US - New York City
NYC Local Law 144 of 2021; DCWP rules
An automated tool that substantially assists hiring or promotion decisions needs an independent bias audit within the past year, a published summary of results, and notice to candidates at least ten business days before use. Penalties USD 500 to 1,500 per violation.
- 2023-07-05 — Enforcement began
Last verified 2026-10-06 · official text
Korea AI Basic Act · South Korea
Framework Act on the Development of AI and Establishment of Trust
Notice of AI use and AI-generated content, impact assessments and risk management with human oversight for high-impact AI (healthcare, energy, employment, credit, public services), and a local representative for foreign providers. Fines up to KRW 30 million.
- 2026-01-22 — In force
- 2027-01-22 — Grace period on penalties ends
Last verified 2026-10-06
China generative AI rules · China
Interim Measures for the Management of Generative AI Services (2023); Measures for Labeling AI-Generated Synthetic Content (in force 1 Sep 2025)
Generative AI services offered to the public in China need security assessment and filing. Generated text, images, audio and video must carry visible and machine-readable labels.
Last verified 2026-10-06
Council of Europe Framework Convention on AI · International treaty
CETS No. 225 (opened for signature 5 Sep 2024)
The first binding international treaty on AI and human rights, democracy and the rule of law. It applies to countries that ratify it.
Last verified 2026-10-06
US export controls on advanced AI chips · US
BIS AI Diffusion Rule (Jan 2025), rescinded 12-13 May 2025; advanced-computing controls on China continue
The tiered global licensing rule was withdrawn before it applied; no formal replacement had been issued by mid-2026. Controls on exports of advanced chips to China and related guidance remain in force.
Last verified 2026-10-06
References
- European Union. Regulation (EU) 2026/1744 (Digital Omnibus on AI) amending Regulation (EU) 2024/1689. Official Journal of the European Union. 2026.
- McDermott Will & Schulte. Colorado AI law in flux: Comprehensive replacement bill signed after federal court blocks predecessor's enforcement. McDermott Will & Schulte. 2026.
- Holland & Knight. White House Releases a National Policy Framework for Artificial Intelligence. Holland & Knight. 2026.
- European Parliament and Council of the European Union. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union. 2024.
- Executive Office of the President. Executive Order 14365: Ensuring a National Policy Framework for Artificial Intelligence. Federal Register, 90 FR 58499. 2025.
- Covington & Burling (Inside Privacy). China Releases New Labeling Requirements for AI-Generated Content. Covington & Burling. 2025.
- Cooley. South Korea's AI Basic Act: Overview and Key Takeaways. Cooley LLP. 2026.
- NicFab. The EU Ratification of the Framework Convention on AI: AI Act, Fundamental Rights and the New Regulatory Architecture. NicFab. 2026.
- Gibson Dunn. EU AI Act Omnibus Agreement - Postponed High-Risk Deadlines and Other Key Changes. Gibson, Dunn & Crutcher. 2026.
- Akin Gump. BIS Rescinds Its AI Diffusion Rule and Issues Compliance Guidance Regarding Advanced Computing Items. Akin Gump Strauss Hauer & Feld. 2025.
- NVIDIA Corporation. Form 8-K (H20 export license requirement). U.S. Securities and Exchange Commission (EDGAR). 2025.
- NVIDIA Corporation. NVIDIA Announces Financial Results for First Quarter Fiscal 2026. NVIDIA (press release filed on Form 8-K). 2025.
- Al Jazeera. Trump clears way for sale of powerful Nvidia H200 chips to China. Al Jazeera. 2025.
- U.S. Department of Commerce, Bureau of Industry and Security. Department of Commerce Revises License Review Policy for Semiconductors Exported to China. Bureau of Industry and Security (press release). 2026.
- Anu Bradford. The Brussels Effect: How the European Union Rules the World. Oxford University Press. 2020.
- Axios. Meta debuts new AI assistant and chatbots. Axios. 2023.
- Data Protection Commission (Ireland). DPC statement on Meta AI. Data Protection Commission. 2025.
- The Hacker News. Meta Pauses AI Training on EU User Data Amid Privacy Concerns. The Hacker News. 2024.
- Meta Platforms. Europe, Meet Your Newest Assistant: Meta AI. Meta Newsroom. 2025.
- Axios. Scoop: Meta won't offer future multimodal AI models in EU. Axios. 2024.
- Hugging Face. Llama can now see and run on your device - welcome Llama 3.2. Hugging Face blog. 2024.
Further reading
- Anu Bradford. The Brussels Effect: How the European Union Rules the World. Oxford University Press. 2020.
- Gibson Dunn. EU AI Act Omnibus Agreement - Postponed High-Risk Deadlines and Other Key Changes. Gibson, Dunn & Crutcher. 2026.
- Holland & Knight. White House Releases a National Policy Framework for Artificial Intelligence. Holland & Knight. 2026.
- Akin Gump. BIS Rescinds Its AI Diffusion Rule and Issues Compliance Guidance Regarding Advanced Computing Items. Akin Gump Strauss Hauer & Feld. 2025.
Sources last verified 2026-10-08.