The EU AI Act, sectoral regulators, and what has to be demonstrable.
35documents on this topic
22organizations represented
5issues named
12sourced citations
6sourced statistics
The state of it
One of 7 topics within Governance & oversight.
35 documents from 22 organizations engage with AI regulation. They agree on almost nothing about what to do, and the disagreement is structural rather than editorial: the EU legislated comprehensively, the United States produced a state patchwork with scope-specific federal rules, and China went straight to strict operator liability. There is no single compliance posture that satisfies all three.
What the research does converge on is quieter and more useful. Obligations under the EU AI Act attach to the role you occupy - provider, deployer, distributor - rather than to the system you run, and most organizations have not classified themselves. Meanwhile the most common enterprise response to regulatory uncertainty is not capability but avoidance: half of Deloitte's respondents reported steering away from use cases that might attract scrutiny at all.
The gap nobody has closed is liability. Clifford Chance is direct about it: the more autonomous the system, the harder it becomes to attribute an action to a human, and no major jurisdiction has resolved who answers for the harm.
The issues, by agreement
How many independent organizations name each issue as a problem. An issue is only as real as the number of separate publishers that identify it, so the count is the ranking. Bars are organizations, not documents. Where the count reads ours, no publisher here states the issue and the analysis is our own.
The chart above counts positions; this shows whose they are. Read down a column for what one organization holds across the whole topic, and across a row for who lines up on one issue. Where a cell carries more than one position, the strongest is shown and the rest are in the tooltip.
Ddisputes itQqualifies itNnames it as a problemPproposes a fix
Regulatory compliance: 5 issues against the 6 organizations cited on them. The number under each name is how many of these issues it is cited on.
A dot means this organization is not cited on that issue. It does not mean they are silent on it: an organization is cited where its document takes a position we could locate, and the absence of a citation is the absence of a finding, not a finding of absence. Who is represented lists everyone working on this topic, including those not cited above.
Where they disagree
No contradictions recorded on this topic yet.
The issues in full
Each issue carries the organizations that name it, the numbers behind it, and the remedies proposed - with the concrete steps under each. Every citation points at a section of a named document, so any count here can be checked.
Issue 012 organizations name it2 qualifies itnewest evidence Apr 2026
The three major regimes are not reconcilable into one compliance posture
The EU legislated comprehensively and ex ante, the United States produced a state patchwork plus scope-specific federal rules, and China holds operators strictly accountable for outcomes. A single global control set satisfies none of them well.
Most enterprise compliance programmes are built on the assumption that the strictest regime can be adopted globally and will cover the rest. That works for privacy far better than it works here, because the regimes differ in kind rather than in severity - ex ante conformity assessment, sectoral disclosure duties, and strict operator liability impose structurally different obligations.
Run a global baseline with explicit jurisdictional deltas
Adopt one control baseline, then maintain a short, named delta list per jurisdiction - rather than pretending the strictest regime is a superset.
Done when One baseline control set is defined with each system mapped to where it is deployed, and each operating jurisdiction has a named delta list whose entries each carry an owner and a monitoring source.
Define the baseline control set and where each system is deployed.0-30 daysLegal
Write the delta list per operating jurisdiction; keep it to obligations that genuinely differ in kind.30-90 daysLegal
Assign each delta an owner and a monitoring source.30-90 daysRisk
The evidence — 4 documents
Organization
Document
Position
Boston Consulting GroupConsultancy · April 2025
How boards can navigate AI geopoliticsOur reading Frames divergence as a geopolitical rather than purely legal problem for boards to navigate.Boards and AI geopolitics
names it
Clifford ChanceConsultancy · May 2025
Agentic AI responsibilitiesOur reading Describes China's 2022-23 rules on deepfakes and generative AI as imposing obligations on developers and platforms while leaning toward holding companies and operators strictly accountable for outcomes.Comparative regulation: EU, China, private law
names it
AWSHyperscaler · April 2026
Governance, risk and compliance for responsible AI in financial servicesOur reading Widens the picture by listing what a regulated firm is already tracking, and the length of that list undercuts the idea of three blocs - though the items are not equivalent regimes. In the United States alone it names a federal executive order, a federal bill, the NIST framework, a securities regulator notice, statutes in Colorado and Texas, and a privacy regulator's automated decision-making rules in California. The United Kingdom appears not as a statute but as a government department and two regulators publishing separately. Asia-Pacific carries national laws in South Korea and Japan, Australian guidance alongside a voluntary safety standard, a Singapore consultation aimed at financial institutions, two Hong Kong publications and an ASEAN guide. The list is offered as non-exhaustive and omits China entirely, so it is a picture of the tracking burden rather than a census.Counted out, it is not three regimes
qualifies it
Boston Consulting GroupConsultancy · November 2024
Exec playbook on AI riskOur reading Treats the EU Act as the reference standard and works its compliance detail against that regime alone, without addressing whether one control set can serve the others.Deep dive: EU AI Act
qualifies it
Issue 021 organization name itnewest evidence Apr 2026
Regulatory monitoring is nobody's standing job
The rules are moving faster than any annual policy review, and in most organizations no named person is accountable for noticing a change in time to act on it.
Assign regulatory monitoring to a named individual with a defined source list and a reporting line into the risk committee.
Done when A named individual owns regulatory monitoring against a written list of regulators, jurisdictions and sources, reports into a standing risk committee slot, and system classifications are re-run whenever a tracked obligation changes.
Name the owner and write down the specific regulators, jurisdictions and sources they track.0-30 daysLegal
Set a standing agenda slot for material changes, with a bias to reporting nothing when nothing changed.30-90 daysRisk
Re-run system classifications whenever a tracked obligation changes.ongoingLegal
The evidence — 3 documents
Organization
Document
Position
DeloitteConsultancy · August 2024
State of generative AI in the enterpriseOur reading Monitoring regulatory requirements and ensuring compliance is named as a top challenge by 49% of respondents.Challenges to scaling
names it
Association of Corporate CounselInstitution · June 2025
Toolkit for in-house AI legalOur reading Provides a standing checklist structure - impact assessment, risk factor evaluation, product assessment - intended as recurring practice rather than a one-off review.Checklists and toolkit structure
proposes a fix
AWSHyperscaler · April 2026
Governance, risk and compliance for responsible AI in financial servicesOur reading Makes keeping compliance practitioners current a mechanism the organization is expected to run rather than something absorbed by whoever notices, on the reasoning that the techniques, the laws and the expectations all keep moving. Its own regulatory appendix is the argument in miniature: assembled at a moment, marked as incomplete, and already carrying entries only months old.Someone has to be kept current, deliberately
proposes a fix
Issue 031 organization name itnewest evidence Nov 2024
Obligations attach to a role you may not have worked out you occupy
Under the EU AI Act what you must do depends on whether you are a provider, deployer or distributor of a system - not on what the system does. Most organizations have never formally classified themselves, and the same company often occupies different roles for different systems.
This is the most consequential and least discussed point in the regulatory material. An organization that fine-tunes a bought model may become a provider; one that rebrands a vendor system almost certainly does. The classification determines whether you owe conformity assessment, registration and third-party audit, or essentially transparency alone - and it is decided per system, not per company.
Run the provider/deployer/distributor test against each deployed system and record the answer. It is a different answer for a bought chatbot than for a fine-tuned model you rebranded.
Done when The estate register carries a role column recording provider, deployer, distributor or out of scope for every system, anything fine-tuned or rebranded is flagged, and the obligation set sits with each system owner rather than in a central policy document.
Take the estate register and add a role column: provider, deployer, distributor, or out of scope.0-30 daysLegal
Flag every system where fine-tuning, rebranding or substantial modification may have made you the provider.0-30 daysLegal
Attach the resulting obligation set to each system owner, not to a central policy document.30-90 daysRisk
Tier by the Act's categories, not your own
Map systems onto the unacceptable / high-risk / limited / minimal tiers as defined, rather than an internal severity scale that will not map to an examiner's question.
Done when Every system is classified against the Act's own tiers with the reasoning recorded rather than the result alone, and anything landing in high-risk carries a costed conformity assessment and registration in the budget.
Classify each system against the Act's tiers and record the reasoning, not just the result.30-90 daysLegal
For anything landing in high-risk, cost the conformity assessment and registration before the next budget round.30-90 daysCFO
The evidence — 2 documents
Organization
Document
Position
Boston Consulting GroupConsultancy · November 2024
Exec playbook on AI riskOur reading Obligation to ensure compliance is dependent on role (provider vs distributor); the Act addresses the entire value chain with separate requirements for systemic-risk models.Deep dive: EU AI Act sets new global standard for RAI
names it
IBMHyperscaler
Agentic AI risk and opportunityOur reading Proposes goal-oriented guardrails that bind an agent to regulatory obligations at run time rather than relying on classification alone.Navigating risks and mitigations
proposes a fix
Issue 041 organization name itnewest evidence Nov 2024
Regulatory uncertainty is being managed by avoiding use cases, not by building capability
The most common response to unclear rules is to steer away from anything that might attract scrutiny, and to cut off staff access to tools. That is a strategy with a cost nobody is measuring.
Deloitte found half of organizations avoiding use cases that could require additional regulatory scrutiny, and a substantial share shutting off access to specific tools. Avoidance is rational for an individual decision and corrosive in aggregate: the capability to comply is never built, the avoided use cases are usually the high-value ones, and blocking tools reliably produces shadow use rather than abstention.
Avoidance is invisible because nothing is recorded. Make the declined use case a logged decision with an owner and a review date.
Done when A log records every use case declined on regulatory grounds with the specific obligation feared, an owner and a review date, and it goes to the risk committee quarterly with an estimated value.
Log every use case declined on regulatory grounds, with the specific obligation feared.0-30 daysRisk
Report the list and its estimated value to the risk committee quarterly.30-90 daysRisk
Re-open the log when guidance clarifies - avoided use cases otherwise stay avoided by default.ongoingLegal
Build the compliant path instead of blocking the tool
Blocking access produces unsanctioned use rather than abstention. A sanctioned route with logging and data controls is the only durable version.
Done when One sanctioned route with logging and data controls is live for the most commonly blocked use, and its adoption is measured against known unsanctioned volume rather than assumed.
Stand up one sanctioned, logged, data-controlled route for the most commonly blocked use.30-90 daysCIO
Measure adoption of the sanctioned route against known unsanctioned volume.90-180 daysCISO
The evidence — 2 documents
Organization
Document
Position
DeloitteConsultancy · August 2024
State of generative AI in the enterpriseOur reading Avoiding use cases that could require additional regulatory scrutiny is reported by 50% of organizations; others shut off access to specific GenAI tools for staff or limit data exposure.How organizations are preparing for regulatory changes
names it
Boston Consulting GroupConsultancy · November 2024
Exec playbook on AI riskOur reading Frames risk management as an enabler to unlock value rather than a brake on innovation.Manage AI risks
proposes a fix
Issue 051 organization name itnewest evidence May 2025
No major jurisdiction has settled who is liable when an autonomous system causes harm
The more autonomous the system, the harder it becomes to attribute its action to a person - and private law has not resolved the gap. Deployments are running ahead of the answer.
Clifford Chance names this directly as the AI responsibility gap: as the causal distance between a human decision and a system output grows, ascribing responsibility to that human becomes harder. Proposals to close it have not survived - the EU's AI Liability Directive was not carried through, and the idea of granting AI systems a separate legal status attracted heavy criticism. The default assumption everywhere remains that a human or a company answers, without agreement on which one.
Where the law is unsettled, the allocation of loss is whatever your contracts say. Most AI vendor contracts currently say very little.
Done when AI vendor contracts have been reviewed for indemnity, liability caps and allocation of loss from model output, a minimum acceptable position is written down, and the insurer has confirmed in writing whether cover responds to an autonomous system action.
Review AI vendor contracts for indemnity, liability caps and allocation of loss from model output.0-30 daysLegal
Set a minimum acceptable position and stop signing below it.30-90 daysLegal
Check insurance responds to loss caused by an autonomous system action.30-90 daysRisk
Bound what the system can do without a human
An unresolved liability question is an argument for a smaller action space, not for waiting.
Done when Each agentic system enumerates the actions it can take unaided and the value at risk in each, human authorisation is required above a stated threshold with every crossing logged, and a kill switch has been exercised in a test.
For each agentic system, enumerate the actions it can take unaided and the value at risk in each.0-30 daysCIO
Require human authorisation above a stated threshold and log every crossing.30-90 daysRisk
Verify a kill switch exists and has been exercised in a test.30-90 daysCIO
The evidence — 1 document
Organization
Document
Position
Clifford ChanceConsultancy · May 2025
Agentic AI responsibilitiesOur reading Identifies the accountability gap that widens with autonomy, notes the proposed AI Liability Directive and the criticised "electronic personhood" idea, and observes the default assumption remains human or corporate responsibility.The AI responsibility gap; AI Liability Directive
names it
Who is represented
This dossier is drawn from 22 organizations working on the subject, 6 of which are cited directly in the issues above.
Consultancy — 9
Boston Consulting Group 3Deloitte 2Clifford Chance 1Accenture 2Capgemini 2EY 1McKinsey & Company 1PwC Malaysia 1UST 1
Institution — 6
Association of Corporate Counsel 1Cloud Security Alliance 3NIST 3Institute of Directors 1Moody’s 1World Economic Forum 1