Global AI regulation splits: what compliance teams face

Global AI regulation splits what compliance teams face

Artificial intelligence is advancing faster than the frameworks built to control it, and a new whitepaper from LexisNexis Regulatory Compliance, titled ‘Navigating the challenges of AI regulation’ suggests the gap is creating a fractured and uncertain environment for the businesses that build, deploy and rely on the technology.

With jurisdictions diverging sharply in their approach, firms operating across borders now face the prospect of satisfying several very different regulatory philosophies at once.

The report points to a set of structural problems that continue to frustrate policymakers. There is still no agreed definition of AI for regulatory purposes, many systems operate as opaque “black boxes” that resist auditing, and the technology routinely crosses national boundaries. Regulators must also walk a fine line between overregulation, which risks choking innovation, and under-regulation, which could leave harms unchecked. The outcome is a patchwork: a prescriptive AI Act in the EU, a principles-based and regulator-led model in the UK, a collection of state laws in the US, and a number of countries retreating from previously planned mandatory regimes.

In the UK, the government has opted against a single AI statute. Instead, existing regulators apply five high-level principles within their own remits: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. Dedicated legislation remains some way off, with a UK AI Bill now not expected before the second half of 2026.

That does not mean firms are operating in a vacuum. The Online Safety Act 2023 is described as one of the most operationally significant regimes affecting AI, covering recommender systems, content moderation tools, search algorithms and generative AI. Ofcom has signalled that algorithmic decision-making falls within the regulated service, meaning governance failures could quickly become enforcement risk, including where AI is supplied by third parties. The Data (Use and Access) Act 2025, meanwhile, stops short of restricting the use of copyrighted material in AI training, instead committing the government to report on policy options within nine months.

Further change is on the horizon. The proposed Frontier AI Bill would turn the AI Safety Institute into a statutory body with legal powers, potentially allowing it to require developers to share models for testing before release. The Blueprint for AI regulation, announced in October 2025, introduced plans for an AI Growth Lab, a cross-economy sandbox to test AI in sectors such as healthcare, transport and professional services.

Globally, the divergence is stark. The EU’s AI Act takes a risk-based approach, banning systems deemed to pose unacceptable risk and imposing strict requirements on high-risk applications, overseen by a new AI Office. The US has no single federal AI law, with its July 2025 AI Action Plan prioritising global dominance, while state-level rules create inconsistency. China has introduced generative AI measures and mandatory content labelling from September 2025, though vague references to “socialist values” raise concerns about self-censorship.

The whitepaper covers various a range of areas on the evolving AI regulatory landscape. It explores how the UK’s five AI principles are being applied, the existing UK regimes that affect AI systems, how the EU AI Act’s risk-based approach compares to the fragmented US landscape, the key challenges facing regulators and practical steps businesses can take to build responsible AI practices.

For more insights, the whitepaper can be downloaded here.

Read the daily RegTech news

Copyright © 2026 RegTech Analsyt

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.