Control and its limits

Can one AI system comply with several regulatory regimes at once?

Short answerYes, where the rules live at one control point as configuration. Where every application carries its own copy of the rules in code, each difference between regimes means rebuilding applications. The deciding factor is where enforcement sits.

Rules about AI break into two parts that usually get discussed as one. The policy covers which data may be used, which decisions need a human, and what must be disclosed. It is genuinely jurisdictional and can differ in every regime. The enforcement point is the place in a system where a rule is checked before something happens. That is an architectural choice, and it is the same choice everywhere.

So what a system is permitted to do varies by jurisdiction. Where that permission is checked can stay the same.

Where the cost of compliance comes from

A system that enforces rules inside each application has to be rebuilt for each divergent rule. A system that routes every request through a single control point treats a divergent rule as configuration: a different rule set applied in a different deployment, on the same machinery. The cost of operating under several regimes is set largely by where enforcement sits, and much less by how many regimes there are.

Left: four applications, each with its own rule, each talking to the models directly; a rule change means editing and redeploying four applications. Right: the same four applications route through one control point that holds the rule as configuration; a rule change is one edit.
Same applications, same models. Only the position of the rule differs, and with it the cost of every jurisdictional change. A new regime on the right is a new rule set.

This is a property of the architecture. It holds for any supplier's stack, and for one built in-house.

More than one regime already applies

An organization operating internationally already faces more than one regime, because the EU AI Act applies to conduct touching the European market wherever the organization is based. A US company serving European customers is inside it today.

Within the United States, whether federal law will preempt state AI rules is an open fight. Attempts to attach preemption to the annual defense authorization ran through 2025 and 2026, and a White House framework in March 2026 called for it. Whichever way that ends, an organization with international customers keeps more than one rule set.

What to decide

  • Separate the two parts in your planning. Which rules differ by market is a question for legal and compliance. Where they are checked is an engineering decision, made once.
  • Put the check where every request passes. With one control point, a new regime arrives as a new rule set.
  • Keep one record across regimes. Each regime asks for evidence. One record of every request, tied to who made it, answers each of them from the same place.

Sources

  1. Congressional Research Service, Regulating Artificial Intelligence: U.S. and International Approaches (R48555).
  2. Roll Call, White House AI framework calls for preemption of state laws, 20 March 2026; Holland & Knight and Ropes & Gray analyses of the same framework.
  3. StateScoop and Fisher Phillips on the 2025 and 2026 attempts to attach AI preemption to the National Defense Authorization Act.
  4. European Union, Artificial Intelligence Act.

Reviewed