The AI rulebooks will not merge. Your evidence layer should.
Updated: Aug 26
Part Two of Three.
Plenty of organisations move full steam ahead with AI only to find they have to retrofit the hard yards of governance after something has already shipped. The controls land as friction, a brake on something already moving. The risk keeps compounding while they catch up.
Like everyone else, I am currently living through this problem. Thinking back though, cyber security went through the same arc, from a bolt-on you added after the fact to the way things get built. Privacy went through it again when data-protection law fragmented across jurisdictions and every organisation had to work out how to answer several regulators at once. The lesson that stayed with me from both experiences is that good governance, brought in early enough, works as an enabler. The organisations that treated it as a capability moved faster than the ones that treated it as a tax.
Part One of this series set out AI readiness as a balance rather than a build, held between three groups who read the same reality differently: the board that oversees, the company that runs the operating model and the external entities that enforce compliance. It argued that the framework you already run is largely enough, once you accept that the work has shifted from build-and-assess to a balance held in real time. What goes wrong in that shape of work is rarely a bad decision. It is drift, the three views sliding apart faster than the quarterly and annual rhythms built to catch them.
Part Two (this piece) goes deeper on the external frame to illustrate how it is the one fracturing fastest, because the rules it enforces are splitting apart jurisdiction by jurisdiction. Holding the balance now means holding it against a compliance landscape that will not sit still.
Each jurisdiction is now writing down a different theory of what AI risk is.
The reason the rules around AI risk will not converge is that they are not answers to the same question. Each major jurisdiction has committed to a different theory of what AI risk fundamentally means to them and they are setting out what machinery needs to be built around each theory.
Sector regulators sit a layer below all of this. A central bank or financial regulator takes its national government's rules as the floor, then overlays stricter operational controls of its own, such as deactivation switches, mandatory human oversight and model governance. These reach a general business only indirectly, when a regulated customer passes the obligations down its supply chain.
The movement in the jurisdictions' positions on governing AI risk is not gradual either. Korea's AI Basic Act came into force in January. Colorado rewrote its own AI Act in May, narrowing it before it had taken effect. The EU's Digital Omnibus became law in July and pushed its high-risk deadlines out past 2027. In the same month, Australia turned back toward mandatory standards. Several of those moves loosen rather than tighten, which the posture question below has to reckon with.
By the time you finish reading this, things may have moved on again. Part Two may be out of date in these jurisdiction call-outs.
Where your business is headquartered doesn't dictate how your obligations arrive.
Foreign rules reach in through three routes the organisation does not choose:
Extraterritorial law reaches any system that touches a protected population.
Contract clauses import a regulated customer's obligations onto its supplier as a condition of the deal.
Assurance demands arrive through procurement. A large customer cannot inspect your AI directly, so it asks for certification against a shared standard as a stand-in for the trust it cannot verify itself.
The strictest set of rules in your commercial orbit, rather than those of your home jurisdiction, tends to set your real baseline. This holds even where a government is actively deregulating. The clearest case is the United States, where the federal government has spent the past year trying to lower the floor and override the stricter state laws beneath it, so far without success in Congress. The binding obligations still sit with California, Colorado and the other active states. A deregulatory push at the top does not lower your baseline while the stricter layer underneath still has force.
The rules differ, but the evidence they ask for shares a large common core.
The framework is the governance base you already run. The evidence layer becomes the part of it that turns what your systems did into proof a regulator can read. Set the regional language aside and a large part of what the regulators want is the same underlying record. They need to know:
What did the system do
In what order
On whose authority
That behavioural core sits underneath most reporting, whatever the theory of risk is that sits on top of it.
There is more to it, of course. For example, a United States discrimination disclosure wants population-level statistics across protected groups, which is a property of many decisions rather than a trace of any one. This is not part of the core itself, nor even a thin extension that melds onto it. It is a thicker piece, built in its own right. What the shared core still does, though, is remove the duplicated foundation that would otherwise sit under every report.
Rules are diverging while the evidence underneath them is largely converging.
This is why chasing each new rule as it lands is the wrong response. Treat the differences as durable because political settlements do not converge the way engineering practices do. They are not a problem to be solved but rather a condition to absorb. Think back to when data-protection law fragmented across jurisdictions. The organisations that stayed sane did not stand up a separate compliance stack per country. They extended one framework, mapped the common core once and wrapped the regional differences around it as they arose. Governing AI is that same move reaching a newer domain, which is the argument Part One made in principle and the regulatory year has now made in practice.
Two levers ride on top of the framework, posture and a live register.
Posture: choose your regulatory posture rather than inherit it. There is an easy temptation to go all in one direction. You either meet the strictest rule everywhere, which is simple but means obeying heavy rules in places that never asked for them, or you follow each country’s rules exactly, which fits every market but means running many sets of rules at once. One way wastes effort, the other creates a mess to manage and neither is what you want. The better answer is to split one question into two. First, what you actually do. Meet the toughest version of the rules that most countries share, since doing that once is cheap and covers most of the map. Then handle each country separately only where its rules are genuinely different and costly enough to be worth the extra work. Second, how you report it. That is the part that usually makes handling many countries expensive. and it is exactly what the evidence layer takes away, because you record what happened once and produce each country’s report from that single record. So the answer is not one extreme or the other. It is a high standard almost everywhere, a few exceptions where they are worth it and one place all the reporting comes from. The board-level test is short, “Which AI rules reach us today, through law, through contract or through the supply chain? Which of those are we treating as if they do not?”
Live register: carry the exposure on the risk register you already run rather than a parallel one. What changes is the speed the risk register mechanics have to move at. Regulatory risk now shifts with the pace of the AI work rather than the cadence of governance meetings, so a rating set at the last quarterly review may be describing a landscape that has moved twice since. The register earns its keep only when material change triggers escalation between meetings rather than waiting for the next agenda.
Both levers point at one evidence layer, which Part Three builds.
Posture and register both run into the same limit where every jurisdiction wants a different report from the same underlying system. Producing each by instrumenting the system again does not scale past the second or third report request. The balancing itself, being the interpretive work of keeping the three views reading the same reality the same way, is not something a tool does.
We are early in all of this. Nobody is running a mature version of it yet. Most of what is happening now is reactive, being teams meeting each new requirement as it lands and building to it one report at a time. Any claim to a mature setup is worth treating with suspicion, given how fast the ground is still moving. Underneath the reactivity a shared answer is forming. Build the record once and let each jurisdiction read from it is close to the standard reply now, sold by a whole tooling market. This piece is deliberately agnostic about that market, because the record of what your systems did is yours. The tools that read it are replaceable. A tool you cannot swap out is the one to avoid. What is not commodity is what the record has to hold and how the three views stay aligned around it, which is where the common core does its work. A conformity file for one, a disclosure report for another, an examination pack for a central bank, all drawn from one record rather than several separate builds, with the thinner jurisdiction-specific evidence added around each and the thicker pieces, such as population-level bias analysis, built as capabilities of their own. Part Three builds this out.
You do not have to wait for the evidence layer to act.
Both levers are available now, using only the framework you already run. The first act is the mapping the posture rests on, being an honest account of which rules already reach you and which you are choosing to leave out of scope. From there, posture becomes a decision rather than an inheritance, while the register carries the exposure with the mandate to escalate when the frame moves. None of it needs a new committee or a new tool. What it needs is the external frame treated as something read continuously, which is the balance held against the view now moving fastest.
The same layer that absorbs the rules can also win the work.
There is a commercial reading of all this, not only a defensive one. This is where the lesson from cyber and privacy pays off. In both, the organisations that got governance in early turned a compliance burden into something that moved deals. The same thing is starting to happen here. A buyer asking for certification before it will sign is running a sales gate as much as a compliance one. The company that answers it from a layer already built responds in days. The company still retrofitting, the one from the top of this piece, responds in weeks, or loses the deal to whoever answered first. Entering a new market works the same way. When the layer is built once and read many times, each new jurisdiction is an adapter rather than a rebuild, so you move first while a competitor is still instrumenting. It is also the clearest return on an AI spend that often struggles to show one, because it removes the thing that slows regulated deals down. None of that makes it a growth strategy on its own. It is the difference between the rules being a brake and being something you clear faster than the rest of the field.
The rulebooks will not merge, so extend the framework you already run.
The rulebooks will not be merging, so waiting for a global policy to settle is not a strategy. Underneath the different demands, most of what every regulator wants is the same record, which is the part you build once. The jurisdiction-specific pieces sit on top, some thin and some substantial. The response is not to chase each rule as it lands but to hold the balance from the framework you already run, extended for the fracturing external frame rather than rebuilt for each rule. Build the shared evidence layer once and let each jurisdiction read from it. Done early, this is the same enabler that good governance turned out to be in cyber and in privacy, rather than the overhead it becomes when it arrives late.
Frequently asked questions.
What does "converging evidence, diverging rules" mean?
The rules different countries write for AI are diverging, because each is built on a different idea of what AI risk is, so they will not merge into one global standard. What those rules demand as proof is largely the same underlying record of what a system did and on whose authority. You cannot standardise the rules. You can standardise the evidence, which is the practical way through.
Will AI regulation harmonise globally?
Unlikely, at least not soon. These rules encode political settlements about what a society fears from AI, not technical choices a standards body can reconcile. Technical standards converge because engineers broadly agree on what works. Political settlements do not, because they reflect different values. Planning for durable divergence is safer than waiting for a global rulebook that may never arrive.
Isn't it too early to build this?
It is early, with nobody yet running a mature version. That is the argument for starting, not for waiting. Designing the record in while it is cheap beats retrofitting it later as friction. Because the build-once answer is now common, the advantage is no longer in having the idea. It is in what the record holds and how well the views stay aligned around it, which is the harder part to copy.
We only operate in one country. What should we do first?
Assume you are in scope until you have checked, because the routes in have little to do with where you are based. From there the action is no different from anyone else's, being the mapping and the posture choice above, run for a single business rather than many.
Isn't one evidence layer just vendor lock-in by another name?
It is a fair worry. It turns on ownership, not the number of records. Keeping one record is not lock-in. Letting a single vendor own the format that record lives in is the lock-in to avoid. So build it around open standards. Part Three gets specific about which ones.
Sources.
Each points to the issuing body or the instrument itself, since these move fast.
European Union. AI Act (Regulation (EU) 2024/1689) and the Digital Omnibus deferral (Regulation (EU) 2026/1744). Commission overview: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
United Kingdom. A pro-innovation, principles-based approach with no single AI Act; existing sector regulators apply five principles and the AI Security Institute oversees frontier models. UK Parliament research briefing: https://researchbriefings.files.parliament.uk/documents/CBP-10003/CBP-10003.pdf
United States, Colorado. SB 26-189: https://leg.colorado.gov/bills/sb26-189
United States, California. SB 53, the Transparency in Frontier Artificial Intelligence Act: https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53
United States, federal. Executive Order, Ensuring a National Policy Framework for Artificial Intelligence (11 December 2025): https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy/
Brazil. Bill PL 2338/2023 (Marco Legal da Inteligência Artificial), a risk-based and rights-based framework approved by the Senate in December 2024 and sent to the Chamber of Deputies in March 2025. Senate tracking page: https://www25.senado.leg.br/web/atividade/materias/-/materia/157233
China. Interim Measures for the Management of Generative AI Services (Cyberspace Administration of China and six other agencies), in force since 2023 and still the operative filing framework, with public-facing services registered through the CAC's algorithm-filing system. Full text via China Law Translate: https://www.chinalawtranslate.com/en/generative-ai-interim
China. Measures for Labeling of AI-Generated Synthetic Content and the mandatory standard GB 45438-2025 (issued by the CAC and three agencies, in force 1 September 2025). Full text via China Law Translate: https://www.chinalawtranslate.com/en/ai-labeling/
Japan. AI Promotion Act (Act on Promotion of Research and Development and Utilization of Artificial Intelligence-related Technology, Act No. 53 of 2025), in force September 2025, innovation-first with no penalties. Official English translation, Japanese Law Translation (Ministry of Justice): https://www.japaneselawtranslation.go.jp/en/laws/view/5066/en
Singapore. Model AI Governance Framework (IMDA), first issued 2019 and extended for generative AI in 2024 and agentic AI in 2026: https://www.imda.gov.sg/resources/press-releases-factsheets-and-speeches/press-releases/2026/new-model-ai-governance-framework-for-agentic-ai
ASEAN. ASEAN Guide on AI Governance and Ethics (2024, expanded for generative AI in 2025), a voluntary regional framework across ASEAN member states that builds on Singapore's Model Framework: https://asean.org/book/asean-guide-on-ai-governance-and-ethics/
South Korea. AI Basic Act (Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trust), passed 26 December 2024, in force 22 January 2026. MSIT press release (issuing ministry, Korean): https://www.msit.go.kr/eng/bbs/view.do?sCode=eng&mId=4&mPid=2&bbsSeqNo=42&nttSeqNo=1071&searchOpt=ALL
Australia. Office of AI and national AI standards (July 2026): https://www.pm.gov.au/media/ai-australias-interests
New Zealand. New Zealand's Strategy for Artificial Intelligence: Investing with Confidence, with the companion Responsible AI Guidance for Businesses (MBIE, July 2025). The approach is light-touch and adoption-first: no AI-specific law, voluntary guidance under existing rules, indigenous data sovereignty and cultural IP treated as areas to monitor rather than regulate. MBIE: https://www.mbie.govt.nz/about/news/artificial-intelligence-strategy-and-business-guidance-now-available



Comments