Plans
Learn Library

The Whole World Is Writing the Rules for AI — Is Your Company Keeping Up?

An overview of AI regulation across the EU, China, and India, with five compliance questions companies using AI commonly face, from data privacy to cross-border transfers.

ai-marketingaigc
2026-09-27SupaMarketers6 min read

A while back, a friend of mine who runs a cross-border e-commerce business took me out to dinner. Over the meal, he excitedly told me his company had gone all-in on AI: customer service was AI, copywriting was AI, even résumé screening was AI.

I asked him one question: is all that customer data you're collecting compliant?

He froze. The rest of that dinner was a lot less fun.

I completely understand him. AI is genuinely a thrill to use — your efficiency climbs by leaps and bounds. But a lot of people keep their foot on the gas and forget to watch the traffic lights. And over the past two years, the "traffic lights" around the world have been lighting up all at once.

A stick-figure driver on a winding road approaching three traffic lights, each paired with a jurisdiction signpost: EU with the AI Act booklet, China with a stacked set of PIPL booklets, and India with a DPDP booklet still on scaffolding.

The EU: Rules First, Then Drive

Let's start with the strictest of the three.

The EU's AI Act took effect on August 1, 2024. Here's what made the act clever: it sorted AI into risk tiers.

What does sorting by risk mean?

It means not all AI gets regulated the same way. Think of traffic management: driving a private car comes with one set of requirements, driving a school bus with another — and a tanker truck carrying hazardous materials gets the strictest inspection of all.

AI works the same way. The act divides AI systems into four tiers: unacceptable risk, high risk, limited risk, and minimal risk. Applications like facial recognition and automated algorithmic decision-making fall into the "high risk" tier, where you must deliver on transparency, accountability, and fairness — no exceptions.

And note: this act doesn't stand alone. It works in tandem with the EU's famous GDPR data protection law. In other words, if you use AI in the EU, you have to clear both checkpoints — AI and data protection. Two ledgers, settled together.

China: The Regulatory Trio Is Complete

Now let's look at China.

Honestly, China's rule system for AI and personal information protection ranks among the most complete in the world. PIPL (Personal Information Protection Law), the algorithm recommendation regulations, the generative AI management measures — all three pieces of the set are in place.

These three regulations draw the red lines with total clarity: anything that endangers national security is out; anything that disrupts social order is out; anything that violates individual rights is out.

So if you do business in China, or your partners do, this trio is a required course, not an elective.

India: Still Under Construction

Third, India.

India's situation differs from the other two: its regulatory framework is still under construction. It released a national AI strategy in 2018, and its Digital Personal Data Protection Act (DPDP Act) is also in the works, but so far it hasn't fully landed. For now, the existing Information Technology Act is holding the fort, and the rules are fairly scattered.

But don't be fooled by how loose it looks right now. Once the DPDP Act is fully implemented, its impact on how AI systems collect and process data will be enormous.

Loose today doesn't mean loose tomorrow. Those who prepare early are always the ones who stay composed.

If Your Company Uses AI, You Can't Dodge These Five Questions

Alright — having looked at the three big markets, let's turn back to you.

No matter where you do business, if you use AI in your company, there are a few legal questions you're almost guaranteed to run into. Let me count them off.

First, the privacy of customer data. Your AI customer service and AI marketing tools collect customer information every day. In the EU, it's governed by GDPR; in China, by PIPL; in California, by CCPA (California Consumer Privacy Act); in India, down the road, by DPDP. You're not using AI in a vacuum — you're using it inside legal jurisdictions.

Second, cross-border data transfer. If your business spans countries, each one has its own data localization requirements about whether data can leave the country and where it may be stored. Get this question wrong once, and the price is steep.

Third, user consent. Before you use AI tools to collect data, did you get users' explicit authorization? Plenty of companies stumble at this most basic step.

Fourth, bias and discrimination. When AI screens résumés, scores credit, or profiles your users, it may quietly and systematically treat certain groups differently. New AI regulations generally require you to audit these systems regularly. Machines don't apologize, but the bill still lands on the company.

Fifth, cybersecurity. The more you rely on AI, the larger your attack surface. Once sensitive data leaks, the legal consequences and the business consequences arrive together.

A stick figure holding a large hand-drawn clipboard with a five-item checklist: Privacy with a padlock, Cross-border transfer with crossing arrows, Consent with a ticked box, Bias with tilted scales, and Cybersecurity with a shield.

None of these five is meant to scare you.

Here's What I'd Advise You to Do

So what to do? A few pieces of practical advice.

First, put an AI use policy in place. Who in the company can use AI, what they can use it for, how data gets handled — write it all down in black and white. Don't rely on unspoken understanding.

Then run legal audits on a regular schedule. The rules keep changing, and so does the way you use AI. Check today's systems against today's rules, at least once a year.

And don't skimp on training. Plenty of risks aren't policy loopholes — they're one careless share by an employee. Walk every AI user through the legal red lines.

If you have the resources, set up an AI ethics committee. Not for show — a real one that reviews every AI deployment proposal and keeps a close eye on the risks.

If you use third-party AI vendors, do your due diligence. Whether they're compliant or not, when things go wrong, it lands on you too. Choosing a partner means choosing risk.

One last step, which many people overlook: dig out your contracts with customers and third parties and read them again. Who owns the data, who pays when something goes wrong, how liability gets capped, who holds the intellectual property — every one of these clauses needs a fresh review in the AI era. Old contracts can't manage new problems.

Finally, My Own Take

Some people tell me: won't regulations this strict strangle innovation?

I don't see it that way. Look at it from the other side: it's precisely because the rules are clear that people who do serious work get certainty. Whoever builds the strongest compliance foundation early gets to run with peace of mind. Regulation looks like a brake, but it's really a guardrail. The guardrail doesn't stop driving — it keeps you from going off the cliff.

Just like my friend. Before that dinner ended, he said something that stuck with me: "Had I known it was this complicated, I should have found someone who understood the law from the very beginning."

I said, yes. But the better time is now.

May you keep your foot on the gas — and still see the red lights.

Continue reading