In Practice: AI in the Enterprise | Day 45: Regulatory Arbitrage in AI: How Different Jurisdictions Are Creating Different Rules

There is a quiet, significant problem emerging in global AI governance that most enterprise leaders haven’t fully reckoned with yet.

It’s this: different jurisdictions are making different rules, and those rules are creating incentives that don’t align with good AI governance. These are emerging patterns and observations, not predictions—regulatory landscapes remain highly uncertain.

This is not new. We’ve seen it in data privacy (GDPR vs. state-by-state US regulation vs. no regulation in some jurisdictions), in financial services (different countries have different capital requirements, different lending regulations), in environmental compliance. But in each of those domains, organizations eventually learned to operate or consolidated around the strictest requirements.

With AI, the governance picture is different. It’s more fragmented, the rules are less settled, and the cost of compliance in different jurisdictions is much higher. The result is regulatory arbitrage—situations where global enterprises can choose which rules they want to follow, based on which jurisdiction they operate in, and that choice has material impact on their risk profile and their competitive position.

What This Looks Like

The EU is implementing the AI Act. It has risk tiers, requirements for high-risk systems, documentation mandates, audit trails. It’s comprehensive and it’s coming.

The US has sector-specific guidance (from the SEC on AI risk disclosure, from OCC on model risk management, from FTC on bias) but no unified framework. It’s fragmented, and the rules are softer.

The UK is taking a “principles-based” approach—you should follow these principles, but we’re not going to prescribe how. Even softer.

China is taking a content-control approach, focused on the model’s outputs rather than its governance. Different problem entirely.

For a global enterprise, this creates an obvious problem: you can’t have one governance framework if different jurisdictions require different things. But you can make architectural choices about where systems run, where data is processed, and which governance structures you invest in.

Here’s the incentive that emerges: invest heavily in EU-grade governance if you’re primarily serving EU customers, because you have to. Invest lightly in US governance, because you don’t have to and the rules are unclear. Operate the same systems differently in different regions, or operate systems in less-regulated jurisdictions with lower governance standards.

This is regulatory arbitrage. And it creates real problems.

The Three Kinds of Problems This Creates

First, it creates governance inconsistency. A multinational enterprise might have two identical AI systems doing identical jobs in two different regions, governed completely differently. One has quarterly bias audits and explicit decision appeals processes. The other doesn’t. Why? Because it can. This isn’t sustainable as an ethical matter, and it’s not sustainable as a legal matter. Eventually, one of the looser regions will have an incident, and the question will be “why didn’t you use the governance structure you were using elsewhere?”

Second, it creates incentive misalignment. If the cost of operating a high-risk AI system is significantly lower in Region A than Region B, organizations will route decisions through Region A. Not explicitly—nobody makes that decision consciously. But the incentives point that way. If your customer base is split between regions, and your finance team says “governing this system for the EU costs 40% more,” your product team will find reasons to process more decisions in less-regulated regions.

Third, it creates a coordination problem. Imagine you’re a financial services company operating globally. The GDPR required privacy-by-design, and you built that into your systems. The EU AI Act requires transparency and explainability. You’re building that in. But a competitor in a less-regulated market is not. They’re shipping faster, with lower compliance costs. They have an advantage. The only way to level the field is if everyone plays by the same rules. But that’s not happening.

Why This Matters

The stable outcome is likely to be that global enterprises operating in multiple jurisdictions consolidate around the strictest requirements. This happened with privacy. It’s happening with financial regulation. It may happen with AI, eventually.

But not before there’s a transition period—maybe a long one—where different organizations make different governance choices based on where they operate. And not before the looser jurisdictions either tighten their rules (expensive, usually late), or the strict jurisdictions’ rules leak out to everyone (through litigation, customer pressure, reputational risk).

The other stable outcome is fragmentation: different enterprises follow different rules, and the market becomes harder to coordinate. This is expensive and it’s unstable.

What To Do

If you’re a global enterprise, this is not something you can solve unilaterally. But you can do some things:

First, assume that looser rules now become stricter rules later. Build for the strictest jurisdiction you operate in, globally. This is the bet that the EU rules will eventually become standard. You might lose near-term speed. You won’t have to rebuild later.

Second, don’t create policy gaps. If you have different governance structures in different regions, document why. Make the decision explicitly. “We’re using lighter governance in Region A because regulation is lighter” is a defensible decision. “We accidentally built different systems” is not.

Third, participate in governance conversations. If you operate globally, you have influence in these conversations. You have standing to say “here’s what companies need to operate effectively” or “here’s what we’ve learned works well.” Use it. The alternative is waking up in five years with incompatible rules that cost you more than they would have cost now.

Fourth, watch the frontier. The organizations that will win are the ones that see regulatory change coming and adjust before they have to. The ones that will struggle are the ones that optimize for today’s rules and then have to retrofit.

The Conversation Worth Having

If you operate globally, your risk and compliance teams should be having regular conversations about regulatory divergence. Not “what are the minimum rules we need to follow?” but “what rules are converging and what rules are diverging, and what does that mean for our architecture?”

The organizations that are ahead right now are the ones that made governance choices years ago, before the rules were clear, and those choices happen to align with what regulators are now requiring. That’s luck. The ones that will be ahead in five years are the ones that assume luck won’t last, and are building accordingly.

Regulatory arbitrage is a real phenomenon. The question is whether you’re going to let it shape your strategy, or whether you’re going to choose your governance standard and stick with it globally.

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.