Compliance · Practical guide
Global AI Regulation for Enterprises: EU AI Act, GDPR, China, and Brazil
Four regulatory regimes now shape how a global enterprise deploys AI: the EU AI Act, the GDPR, China's binding algorithm rules, and Brazil's risk-based bill. The practical answer is not four separate compliance programs — it is one governance chassis (inventory, risk classification, documentation, human oversight) with market-specific overlays. This guide maps what each regime requires and how to build that chassis once.
In this guide · 8 steps
- 01By the numbers
- 02One perimeter, four regimes
- 03The EU AI Act: the reference architecture
- 04GDPR: the regime you already answer to
- 05China: vertical rules, binding early
- 06Brazil: risk-based convergence with the EU model
- 07Honest objections: the case for waiting, steelmanned
- 08The read: build one chassis, then localize
If your enterprise runs AI in more than one market, you are already inside at least four regulatory perimeters: the EU AI Act, now generally applicable; the GDPR and its national siblings, which have governed automated decisions about people for years; China's AI-specific rules, which bound providers earlier than any Western regime; and Brazil's risk-based AI bill, which tracks the EU model. The right response is one governance chassis with per-market overlays — not four parallel compliance programs.
This guide is written for the people who fund and defend that program: the CIO or chief AI officer who owns the portfolio, the CISO who inherits its attack surface, and the general counsel who signs the risk acceptance. The unit of analysis throughout is a decision — what to inventory, classify, and document, and where a use case is simply off the table.
1. By the numbers
The EU AI Act's top penalty tier — up to €35 million or 7% of annual worldwide turnover, whichever is higher, for violations of the prohibited-practice rules.[^ec-ai-act-qa-2026]
European Commission AI Act Q&A
The date the AI Act became generally applicable, having entered into force on August 1, 2024 — with prohibitions applying since February 2, 2025 and general-purpose AI obligations since August 2, 2025.[^ec-ai-act-framework-2026]
European Commission
AI practices the AI Act prohibits outright — including social scoring, emotion recognition in workplaces and schools, and untargeted scraping of facial images — as posing a clear threat to people's safety, livelihoods, and rights.[^ec-ai-act-framework-2026]
European Commission
Read those numbers together and the shape of the problem appears. The penalty ceiling is calibrated to global revenue, not local presence, so exposure scales with the size of the enterprise, not the EU deployment. The dates mean the era of "the rules are coming" is over — the core regime is live, with remaining high-risk obligations phasing in on published dates. And the prohibition list means some use cases are not a compliance problem to manage but a product decision to reverse.
2. One perimeter, four regimes
The four regimes are often presented as a fragmented mess; the more useful observation is how much they overlap. Three of the four are risk-based: the EU AI Act tiers obligations by the harm an AI system can do; Brazil's Bill 2338 would classify systems by risk, ban those posing excessive risk, and regulate high-risk applications in a design the OECD describes as akin to the EU AI Act;[3] and the GDPR's rules on automated decision-making key off whether a decision has legal or similarly significant effects on a person.[4] China is the structural outlier: instead of one horizontal law, it regulates by vertical — recommendation algorithms, synthetic media, generative services — with binding obligations that arrived earlier than any of the others.[3]
| Regime | Model | Status | Who it binds | First question for your program |
|---|---|---|---|---|
| EU AI Act | Horizontal, risk-tiered | In force; generally applicable, with high-risk rules phasing in on published dates[^ec-ai-act-framework-2026] | Providers and deployers, inside and outside the EU, whose systems reach the EU market[^ec-ai-act-qa-2026] | Which of our systems land in the prohibited or high-risk tiers? |
| GDPR / UK GDPR | Horizontal data-protection law with AI-relevant provisions | Long established; regulator guidance on automated decisions is mature[^ico-automated-decisions] | Any controller or processor handling personal data of people in scope | Which decisions are solely automated with significant effects on people? |
| China (CAC rules) | Vertical, per-technology binding rules | Binding rules in effect for recommendation algorithms and synthetic media[^oecd-gsg-2024] | Providers of in-scope services in China | Do we operate or ship algorithmic services into China at all? |
| Brazil (Bill 2338 + LGPD) | Risk-based AI bill layered on an existing data-protection law | Bill proposed May 2023, still in the legislative process as of the OECD's 2024 review[^oecd-gsg-2024] | Would reach AI systems deployed to Brazilian users | Does our EU AI Act classification work reuse cleanly here? |
The diagonal through that table is the finding that matters. Every regime, in its own vocabulary, asks for the same four artifacts: an inventory of what AI you run, a classification of how risky each system is, documentation that proves you assessed and mitigated that risk, and a human oversight mechanism a regulator can inspect. That convergence is what makes a single chassis viable — and what makes building four separate programs a waste of money.
3. The EU AI Act: the reference architecture
The AI Act is worth understanding in detail even if your EU exposure is small, because it has become the template other jurisdictions copy. It sorts AI systems into four tiers. At the top, nine practices are prohibited outright — the European Commission's list includes harmful AI-based manipulation and deception, exploitation of vulnerabilities, social scoring, individual criminal-offense risk prediction, untargeted scraping of the internet or CCTV footage to build facial recognition databases, emotion recognition in workplaces and education institutions, biometric inference of protected characteristics, real-time remote biometric identification in public spaces for law enforcement, and AI generation of non-consensual intimate imagery or child sexual abuse material.[2] These are framed as a clear threat to the safety, livelihoods and rights of people, and most have been banned since February 2, 2025.[2]
The second tier — high-risk — is where most enterprise compliance work concentrates, because it covers systems enterprises actually buy and build: AI safety components in critical infrastructure, AI used in education, employment and worker-management tools, systems gating access to essential private and public services (credit scoring sits here), remote biometrics, law enforcement, migration and border control, and the administration of justice.[2] If a hiring screen, a credit model, or an infrastructure controller in your portfolio touches the EU, assume this tier until proven otherwise.
For high-risk systems, the Commission's stated obligations are concrete enough to turn directly into a program backlog:[2]
- Adequate risk assessment and mitigation systems, maintained across the lifecycle.
- High-quality datasets feeding the system, to reduce the risk of discriminatory outcomes.
- Logging of activity so results are traceable.
- Detailed documentation covering the system and its purpose.
- Clear and adequate information to the deployer.
- Appropriate human oversight measures.
- A high level of robustness, cybersecurity, and accuracy.
The third tier is transparency risk: when people interact with systems such as chatbots, they must be made aware they are dealing with a machine, and AI-generated content must be identifiable — with deep fakes and AI-written text published to inform the public requiring clear and visible labels.[2] The fourth tier — minimal risk — is where the Commission says the vast majority of AI systems currently used in the EU sit, citing examples like AI-enabled video games and spam filters.[2] The classification exercise mostly ends in relief; the point of rigor is finding the systems where it does not.
General-purpose AI models carry their own obligations, applicable since August 2, 2025: transparency and copyright rules for all GPAI providers, plus a duty on providers of models posing systemic risks to assess and mitigate those risks.[2] In July 2025 the Commission published three instruments to make this operational — guidelines clarifying the scope of GPAI obligations, a voluntary GPAI Code of Practice, and a template requiring providers to publish an overview of the data used to train their models.[2] For enterprises this cuts mostly one way: the burden falls on your model vendors, and the Code of Practice and training-data template give your procurement team new artifacts to demand during vendor evaluation.
The remaining runway is specific. Rules for systems in certain sensitive high-risk areas apply from December 2, 2027, and rules for AI embedded in physical products apply from August 2, 2028.[2] Penalties are tiered: up to €35 million or 7% of annual worldwide turnover for prohibited-practice violations, up to €15 million or 3% for breaches of other obligations (the same ceiling applies to GPAI providers), and up to €7.5 million or 1% for supplying misleading information to authorities.[1]
Extraterritorial by design
The Act applies to public and private actors inside and outside the EU whenever an AI system or general-purpose model is placed on the EU market or its use affects people in the EU, and it binds deployers as well as providers.[1] A US enterprise that never incorporated in Europe but exposes an in-scope system to EU users is in scope — and so is the team that merely deploys a third-party system. "Our vendor handles compliance" is not a defensible position; deployer obligations are yours.
4. GDPR: the regime you already answer to
While AI Act deadlines get the headlines, the sharpest near-term constraints on enterprise AI in Europe come from data-protection law that has been enforced for years. Article 22 of the GDPR (mirrored in the UK GDPR) restricts making decisions about people solely by automated means where those decisions have legal or similarly significant effects — the ICO's canonical examples of automated decision-making are an online decision to award a loan and a recruitment aptitude test using pre-programmed algorithms and criteria.[4] Such decisions are lawful only through one of three gateways: the decision is necessary for entering into or performing a contract, it is authorized by law applicable to the controller, or it rests on the individual's explicit consent.[4]
The gateways come with safeguards that read like a product-requirements document for any AI decision system. Per ICO guidance, you must provide meaningful information about the logic involved in the decision-making, along with its significance and envisaged consequences; ensure individuals can obtain human intervention, express their point of view, and obtain an explanation of the decision and challenge it; and run regular checks that the system works as intended, with measures against errors, bias, and discrimination.[4] Because this processing is considered high risk, a data protection impact assessment is required before you start.[4] Note what this does to the perennial "right to explanation" debate: whatever the academic argument about the GDPR's text, the operating regulator's guidance already requires explanation and contestability mechanics, so building them is not optional.
Personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
Data minimization is the second pressure point. Article 5(1) requires personal data to be adequate, relevant, and limited to what is necessary for the stated purpose, and Article 5(2) makes the controller responsible for demonstrating compliance with all of the processing principles.[5] That accountability duty is the quiet enforcement mechanism: it converts "we think our training pipeline is proportionate" into "show me the records." For AI teams this pushes toward documented purpose statements per dataset, pseudonymization or anonymization where the purpose allows it, and retention rules for profiles and training corpora. The deeper architectural patterns — and how to reconcile minimization with the data appetite of model training — are covered in /guides/personal-data-protection-ai.
The DPIA is the hinge artifact
One assessment format can serve multiple regimes. A well-built DPIA already inventories the system, states its purpose, classifies its risk, documents mitigations, and names the human oversight path — which is most of what the AI Act's high-risk documentation and Brazil's proposed impact assessments ask for. Extend your DPIA template with AI-specific fields (model provenance, evaluation results, failure modes) rather than inventing a parallel assessment.
5. China: vertical rules, binding early
China's approach inverts the EU's. Rather than one horizontal statute, the Cyberspace Administration of China has issued binding rules per technology vertical, and issued them early. The 2021 Provisions on the Management of Algorithmic Recommendations in Internet Information Services created an algorithmic registry requiring companies to disclose the types and provenance of the data used to train AI systems, so the government can trace how content is disseminated.[3] The 2022 Provisions on the Administration of Deep Synthesis Internet Information Services require generative AI content to be labeled and require providers to implement safeguards against the creation and circulation of disinformation.[3]
Enforcement is content-forward and hands-on. The OECD reports that the Chinese government has imposed parameters on training-data content for generative AI and has audited large language models produced by Alibaba, ByteDance, and others to verify that outputs comply with the country's "core socialist values" — and notes that these transparency and accountability requirements do not extend to the Chinese public sector.[3] These AI-specific rules sit on top of China's broader personal-information-protection and data-security statutes, which govern consent, data handling, and cross-border data flows and add a data-localization dimension to any China deployment.
For a multinational, the program implications are structural. First, scope is a business decision before it is a compliance one: if you do not provide recommendation, synthetic-media, or generative services into China, most of these rules do not reach you, and keeping it that way may be the cheapest control available. Second, if you do operate in scope, plan for regulator-facing disclosure of training-data provenance and for output-content constraints that differ materially from Western content policies — which usually forces a separately governed model stack for the China market rather than a config flag on the global one. Third, treat the registry and labeling duties as evidence obligations: the artifacts your global chassis already produces (data lineage, model documentation, output labeling) are the raw material, but the filing workflow is China-specific and needs local legal ownership.
6. Brazil: risk-based convergence with the EU model
Brazil matters for two reasons: it is a large market in its own right, and it is the clearest test of whether the EU's risk-tiered design becomes the international default. Bill 2338, proposed in May 2023, would classify AI systems based on risk, ban systems posing an excessive risk, and subject high-risk applications to regulation — a design the OECD characterizes as akin to the EU AI Act.[3] As of the OECD's October 2024 review the bill had not yet passed,[3] so the posture is preparation rather than deadline management: track the bill through local counsel, but do not wait for enactment to organize the work.
The reason not to wait is that the foundation layer already exists. Brazil's general data-protection law, the LGPD, governs personal-data processing under a national data-protection authority (the ANPD), and any AI system touching Brazilian users' personal data answers to it today — much as GDPR governed European AI deployments for years before the AI Act arrived. An enterprise that has done honest GDPR work holds most of the LGPD cards already: lawful-basis analysis, data-subject rights handling, impact assessments, and processing records translate with local-law adjustments rather than rework.
The convergence bet, then, is straightforward: classify your Brazil-facing systems with the same risk rubric you built for the EU AI Act, reuse your DPIA-derived assessment format, and localize the deltas — Portuguese-language user disclosures, ANPD-facing documentation conventions, and whatever the enacted text ultimately changes about tier boundaries. If the final law diverges from the EU model, you will have spent little on the divergence; if it converges, you are already done with the expensive part.
7. Honest objections: the case for waiting, steelmanned
There is a respectable argument against investing heavily now. It runs: enforcement capacity is unproven and young regimes historically under-enforce at first; the highest-stakes EU high-risk rules have runway, with sensitive-area obligations applying from December 2, 2027 and embedded-product rules from August 2, 2028;[2] Brazil's bill is not law; and regulatory texts are still being clarified through guidance, so early builds risk conforming to interpretations that shift. Money spent on compliance scaffolding for rules that may soften is money not spent shipping AI capability, in a period of intense competitive pressure to ship.
Three facts blunt the argument. First, the binding core is already live: the EU prohibitions have applied since February 2025 and GPAI obligations since August 2025,[2] Article 22 safeguards are current regulator expectations rather than proposals,[4] and China's rules are in effect with audits to show for it.[3] Second, the expensive parts of compliance — inventory, classification, documentation habits, oversight wiring — have lead times measured in quarters and are cheapest when built into systems rather than retrofitted; waiting converts a program into an emergency. Third, the same artifacts are what limit your loss when an AI system fails in public: liability for harmful outputs does not wait for a regulator's docket, as the incident patterns in /insights/ai-output-risk-and-liability make clear. The honest version of the objection supports sequencing, not deferral.
8. The read: build one chassis, then localize
The synthesis this supports is a two-layer program. The chassis layer is jurisdiction-neutral and should be anchored to a published framework rather than invented: the NIST AI Risk Management Framework — voluntary, released in January 2023, and organized around the Govern, Map, Measure, and Manage functions[6] — is the natural spine, because its function structure maps cleanly onto what every regime in this guide requests. Govern holds your policies and accountability assignments; Map holds the inventory and risk classification; Measure holds evaluation and bias testing; Manage holds mitigation, oversight, and incident response. International principles work points the same direction: the OECD AI Principles, the first multilateral AI standard and the foundation for the 2019 G20 AI principles, center transparency, robustness, and accountability[3] — the same triad the binding regimes operationalize.
Inventory and classification
One register of every AI system — built, bought, and embedded in SaaS — with a risk tier per system per market. This single artifact serves EU tiering, Article 22 screening, China scope decisions, and Brazil preparation.
Documentation and evidence
An extended DPIA/impact-assessment template covering purpose, data provenance, evaluation results, mitigations, and failure modes. Written once, filed per regime's format.
Oversight and contestability
Named human owners per high-risk system, an intervention and appeal path users can actually invoke, and logging that makes decisions traceable after the fact.
Market overlays
The genuinely local residue: EU conformity and transparency mechanics, China registry filings and content constraints, Brazil's Portuguese-language disclosures and ANPD conventions. Thin by design, owned by local counsel.
The overlay layer is where jurisdictions genuinely differ, and it should be as thin as the chassis is thick. Note what this implies for agentic systems: agents that take actions — not just make predictions — stress every element of the chassis at once, because a multi-step autonomous run is harder to inventory, log, oversee, and explain than a single scoring call. If agents are in your roadmap, the governance patterns in /guides/agent-governance-guide are the natural companion to this piece: the regulatory chassis described here is the compliance-facing half of the same control system.
Vendor selection is the final lever, and the cheapest one. Every obligation here becomes easier or harder depending on what your platform stack surfaces by default: audit logs, model documentation, training-data summaries, output labeling, human-review workflows, data-residency options. A vendor that cannot produce GPAI transparency artifacts, or offers no hook for human intervention in consequential decisions, is not merely a weaker product — it is a compliance liability you are choosing to absorb. Put these requirements into RFPs now, while regimes are young enough that vendors are still deciding how seriously to invest.
How to apply this
- Stand up a single AI system register covering built, bought, and SaaS-embedded AI; assign each entry a risk tier per market it touches.
- Screen the register twice: against the EU AI Act's prohibited list (anything matching is a product decision, not a compliance task) and against Article 22 (solely automated decisions with significant effects on people).
- Extend your DPIA template with AI-specific fields — model provenance, evaluation results, failure modes, oversight owner — and make it the one assessment format for all markets.
- For each high-risk system, implement the EU obligation set as your global baseline: risk management, dataset quality controls, activity logging, documentation, deployer information, human oversight, and robustness testing.
- Wire user-facing transparency now: disclose chatbot interactions, label AI-generated content, and build a working human-intervention and appeal path for consequential decisions.
- Decide China scope explicitly at the business level; if in scope, fund a separately governed model stack, registry filing process, and local legal owner.
- Assign Brazil to whoever owns your EU classification work, with a standing brief to track Bill 2338's progress and localize disclosures once the text is final.
- Add regulatory artifacts to procurement: demand training-data summaries, audit logging, documentation, and oversight hooks in every AI RFP, and score vendors on them.
- Anchor the whole program to NIST AI RMF's Govern/Map/Measure/Manage structure so internal roles and evidence map onto a published, defensible framework.
Sources
Every quantitative or attributed claim above is linked to a primary source. Last verified at publication.
- [1]Artificial Intelligence — Questions and AnswersEuropean Commission · accessed
- [2]AI Act — Shaping Europe's digital futureEuropean Commission · accessed
- [3]
- [4]Rights related to automated decision making including profilingInformation Commissioner's Office (ICO) · accessed
- [5]A guide to the data protection principlesInformation Commissioner's Office (ICO) · accessed
- [6]AI Risk Management FrameworkNIST · accessed