Companies deploying artificial intelligence across their operations are finding themselves caught between accelerating adoption and a fragmented regulatory landscape that shows no sign of harmonising any time soon.
The European Union’s AI Act, which came into force in stages throughout 2025 and 2026, imposes tiered obligations based on risk classification. High-risk applications face conformity assessments, transparency requirements, and human oversight mandates. Meanwhile, the United States continues to rely on a sectoral patchwork of executive orders and agency-level guidance rather than a single comprehensive statute.
“The compliance burden is real and growing,” said Dr Elena Vasquez, a technology governance researcher at the London School of Economics. “We are seeing mid-market firms spend roughly 12 to 15 per cent of their AI project budgets on legal and compliance work alone. That figure was below 5 per cent just three years ago.”
The disparity between jurisdictions is particularly acute for businesses operating across borders. A facial recognition system that clears regulatory hurdles in Singapore may face outright prohibition in parts of the EU. An algorithmic hiring tool compliant in one member state can trigger enforcement action in another if documentation standards differ.
The OECD has tracked more than 1,000 AI-related policy initiatives across 70 countries since 2017. While the volume signals that governments are taking the technology seriously, critics argue the sheer number of overlapping frameworks is itself becoming a barrier to innovation.
“We have moved from too little regulation to too much, too fast, with insufficient coordination,” noted James Merrick, a partner at City law firm Calder & Rowe. “Clients are spending more time mapping regulatory obligations than actually building useful systems.”
Some industry groups have called for mutual recognition agreements between major trading blocs, similar to those used in pharmaceutical and food safety regulation. The UK government’s white paper on AI governance, published earlier this year, explicitly endorsed this approach, though negotiations with the EU and US remain at an early stage.
For now, businesses are advised to build compliance into AI projects from the outset rather than treating it as an afterthought. The cost of retrofitting governance controls, several studies suggest, is roughly three times higher than embedding them during development.