The Global AI Rulebook Is Fragmenting and Getting Harder to Navigate
A practical look at the EU AI Act, global policy divergence, and what AI teams need to do now.
Written by Mercial
Global AI policy is moving quickly, but it is not moving in one direction. Governments and international organizations are developing multiple rulebooks with different definitions, timelines, risk categories, and enforcement models.
Companies should not wait for one universal AI standard. The practical requirement is a governance system that can adapt across products, risk levels, and jurisdictions.
Europe moved first with binding law
The EU AI Act entered into force on August 1, 2024, with obligations applying in phases. Its framework categorizes systems by risk and creates requirements around prohibited practices, general-purpose AI, transparency, documentation, oversight, and high-risk use cases.
- Prohibited-practice and AI-literacy provisions began applying in February 2025.
- General-purpose AI obligations entered the implementation timeline in August 2025.
- Many core obligations are scheduled to apply by August 2026.
For companies serving EU users or deploying systems in the European market, AI governance is now a product, legal, data, and operational issue.
International agreements set direction, not uniform enforcement
United Nations initiatives and other multilateral agreements create shared language around safety, inclusion, human rights, and responsible development. They can influence national policy, procurement standards, and expectations for large technology companies.
However, broad international principles do not produce identical laws. Businesses still need to understand the requirements that apply to each market and use case.
National strategies are diverging
Different governments are prioritizing different combinations of:
- innovation speed and investment attraction;
- national security and critical infrastructure;
- consumer protection and accountability;
- data sovereignty and domestic technology capacity.
This creates operational friction for teams attempting to ship one AI-enabled product across several regions. A feature considered low-risk in one jurisdiction may require additional controls, disclosures, or documentation in another.
What businesses need to do now
Teams need an internal policy and evidence layer that can evolve without rebuilding the entire product whenever rules change.
- Inventory AI models, providers, data sources, and product use cases.
- Map each use case against jurisdiction-specific risk categories.
- Document development, testing, deployment, monitoring, and human oversight.
- Assign accountability for incidents, model changes, and vendor review.
- Build versioned controls that can vary by region or customer type.
Policy adaptability is becoming a competitive capability
The next phase of AI competition will not be determined only by model performance. Companies that can explain how systems work, demonstrate controls, and adjust to changing obligations will be better positioned to enter regulated markets and maintain customer trust.
Work with Mercial
Turn policy requirements into workable systems
Mercial helps teams design software, data flows, permissions, and operational controls that are easier to document and maintain.
Explore Software Development