Fragmented AI Rules Are Testing Eurasia's Digital Ambitions
Divergent national approaches to artificial intelligence regulation are raising compliance costs and reshaping investment, digital infrastructure and industrial strategy across Eurasian markets.
Sarah Al-Rashid
Published on September 11, 2026
Fragmented AI Rules Are Testing Eurasia's Digital Ambitions
Divergent national approaches to artificial intelligence governance are raising compliance costs and reshaping investment, digital infrastructure and industrial strategy across Central Asia, the Caucasus, Eastern Europe and Türkiye.
Executive Summary
- Governments and international organisations have responded to the rapid advance of artificial intelligence with a wave of frameworks, strategies and draft laws, but the result is inconsistency rather than convergence.
- The European Union is implementing the first comprehensive horizontal legal framework for AI systems across its member states, while other jurisdictions rely on voluntary principles, sector-specific guidance, national strategies or legislation still under review.
- The practical consequence for companies is not a single compliance standard but an overlapping set of obligations that follow the customer, the data and the end market.
- Fragmented rules are becoming a factor in foreign direct investment decisions, digital infrastructure siting, vendor management and the competitiveness of export-oriented services.
- Central Asia and the Caucasus remain lightly represented in global AI rule-making to date, which creates both flexibility and risk for the region's digital ambitions.
- The next three to five years will determine whether mutual recognition and technical standards reduce the compliance burden or whether divergence deepens.
Introduction
Artificial intelligence has moved from research laboratories into commercial practice with unusual speed. Increases in computational power, combined with advances in machine learning, have produced new ways of doing business and, alongside them, new categories of risk. These range from unintended impacts on individuals, such as an algorithmic error affecting a person's credit score or public reputation, to deliberate misuse by third parties, including manipulation of AI systems to generate inaccurate output or the production of deepfakes.
Regulators have had to react quickly to avoid building frameworks that are obsolete before they are enforced. International organisations including the G7, the United Nations, the Council of Europe and the OECD have issued their own AI frameworks, and the United Kingdom convened the first global AI Safety Summit in November 2023 in an attempt to establish some degree of international consensus. White & Case's AI Watch regulatory tracker, which examines the state of play jurisdiction by jurisdiction, concludes that these efforts are already struggling to keep pace with technological development, and that the divergent approaches taken by individual jurisdictions have increased the risk businesses face from a fragmented and inconsistent regulatory environment.
Main Analysis
Divergence, not convergence
The most consequential finding for corporate planners is a negative one: there is no single emerging global standard. Most jurisdictions say they want to encourage AI innovation and investment while protecting against harm, but they have chosen substantially different instruments to pursue those goals. Some have enacted binding, horizontal legislation. Others have issued voluntary ethics principles. Others still rely on national strategies that carry no direct legal obligation, or on sector regulators who address AI incidentally through existing rules on finance, health or data protection.
The result is that a company selling the same AI-enabled product into several markets may face different definitions of what counts as a high-risk system, different documentation and testing expectations, different disclosure duties and different supervisory authorities. For a multinational, the compliance question is no longer whether AI is regulated, but by whom, on what theory of harm, and with what timetable.
Where the rules are taking shape
The European Union is furthest advanced. It is implementing the first comprehensive horizontal legal framework for the regulation of AI systems across EU member states. EU member states in Central and Eastern Europe are treating transposition into national law as a primary task; the Czech Republic, for example, has made successful implementation of the EU AI Act its main focus, supported by a national AI strategy. Germany continues to evaluate whether AI-specific legislation is needed while engaging in international initiatives, while France has pursued sector-specific proposals alongside active participation in international efforts. Italy remains at the stage of political discussion about future legislation.
Beyond Europe, the pattern is equally varied. China's Interim AI Measures represent the country's first specific administrative regulation on the management of generative AI services. Canada's proposed AIDA is expected to regulate AI at the federal level, although provincial legislatures have yet to introduce accompanying rules. Brazil's proposed AI regulation remains uncertain, with compliance requirements still pending review. India has relied on national frameworks supplemented by sector-specific initiatives in finance and health. Japan has adopted a soft-law approach to governance while lawmakers advance proposals for hard-law treatment of certain harms. Australia's voluntary AI Ethics Principles guide responsible development, with reforms under consideration.
At the multilateral level, the Council of Europe is developing a convention on AI intended to safeguard human rights, democracy and the rule of law in the digital space, covering governance, accountability and risk assessment. The G7 framework requires member states to comply with international human rights law and relevant international frameworks, and the African Union's Continental AI Strategy sets out a unified approach to governance across the continent.
Where Eurasia sits — and where it does not
The tracker treats the United States as a jurisdiction in its own right within a crowded field of national and regional regimes, reflecting the reality that the regulatory trajectory of the world's largest AI market continues to evolve and will materially influence how standards develop elsewhere.
Notably, the jurisdictions profiled in depth are dominated by the European Union, the G7 economies and large emerging markets. Central Asia and the Caucasus feature only marginally. That reflects both the relative size of those markets and the early stage of domestic AI rule-making in much of the region. It also means that businesses operating in Eurasian markets outside the EU will often find themselves regulated indirectly — through the contractual requirements of European customers, through the data protection regimes of trading partners, or through the procurement conditions attached to multilateral financing.
This indirect regulation is easy to underestimate. A logistics software provider in the Caucasus, a business process outsourcer in the Western Balkans, or a fintech developer in Central Asia may never file an AI compliance return with a domestic regulator, yet still be required to document model governance, data provenance and human oversight in order to retain a European or North American client.
Business Impact
The first-order effect is on cost structures. Compliance with horizontal AI regulation requires legal review, technical documentation, risk assessment, staff training and, in many cases, external audit. These are fixed costs that scale poorly for smaller enterprises, which raises a question about market concentration: larger firms can absorb compliance overheads, while smaller vendors may be pushed out of regulated procurement chains.
Corporate strategy is affected in more subtle ways. Product roadmaps are increasingly shaped by the strictest jurisdiction a company intends to serve, not by its home market. Engineering teams build to the highest applicable standard because maintaining divergent product versions is inefficient. This dynamic, familiar from data protection, tends to export one jurisdiction's regulatory preferences globally through commercial rather than legal channels.
Supply chain management is also changing. Buyers are extending AI-related due diligence into their vendor networks, requesting information on training data, model evaluation and incident reporting. For manufacturers adopting industrial automation, machine vision or predictive maintenance, this means that the software embedded in production equipment now carries a governance dimension as well as a technical one.
Investment implications follow. Capital allocation in digital infrastructure, including data centres and cloud capacity, is sensitive to regulatory predictability. Jurisdictions that can offer clear rules, credible supervision and mutual recognition with major markets are better positioned to attract long-term investment in AI-adjacent assets. Fragmentation raises the cost of capital by increasing legal uncertainty, and it complicates valuation for investors assessing technology companies with cross-border revenue.
The labour market dimension is equally relevant. Compliance and assurance functions are new sources of demand for specialised skills, and economies that can train or attract such talent — in law, data engineering, security and model evaluation — will capture a disproportionate share of regional AI activity.
Regional Perspective
For the European Union, the AI Act is as much an instrument of external influence as an internal market measure. Its application across member states, including those in Central and Eastern Europe, creates a large regulated bloc whose standards suppliers elsewhere must accommodate if they wish to serve European customers. The candidate countries of the Western Balkans face a familiar alignment challenge: adopting the acquis, including digital and AI-related rules, is a condition of accession, which effectively imports a regulatory framework before domestic capacity to supervise it is fully developed.
Türkiye occupies an intermediate position, with a substantial technology sector, deep trade ties to the EU and a domestic policy agenda that must reconcile industrial ambition with regulatory alignment. For the Caucasus, AI governance is intertwined with the broader project of regional connectivity: digital customs, paperless trade and corridor management systems all rely on data-intensive tools whose deployment raises questions about cross-border data handling and public procurement.
In Central Asia, governments have placed digital government, e-commerce and data governance on their policy agendas, and several have pursued substantial digitalisation programmes. The absence of dedicated AI legislation in most of the region is not necessarily an obstacle to adoption, but it does create uncertainty for investors about future obligations, particularly where data localisation requirements interact with cloud-based AI services.
Across the Caspian and the wider Eurasian corridor network, AI has a specific and practical relevance. Trade facilitation depends on document processing, risk scoring at borders, and the integration of rail, port and road information systems. These are precisely the applications that benefit most from machine learning, and precisely the applications where errors carry legal and commercial consequences. The governance gap in much of the region is therefore not a distant regulatory question but an operational one for the logistics and trade sector.
Future Outlook
Over the next three to five years, three dynamics are likely to shape the outlook for Eurasian markets.
The first is the uneven implementation of existing frameworks. The EU AI Act's staged application will generate the region's most detailed body of compliance practice, and the experience of member states in Central and Eastern Europe will serve as an early test of whether horizontal regulation can be applied proportionately outside the largest economies. Delays, guidance gaps and supervisory capacity constraints are plausible outcomes alongside effective enforcement.
The second is the emergence of a technical standards layer. International standards bodies, assurance providers and industry consortia are developing evaluation methodologies, documentation formats and audit protocols. If these converge, they could reduce the practical burden of legal divergence by allowing a single body of evidence to satisfy multiple regulators. If they fragment along geopolitical lines, compliance costs will rise further.
The third is the widening of sector-specific rules. Finance and health are the most likely areas for early AI-specific supervision outside the EU, following the pattern already visible in India and elsewhere. For Eurasian financial markets, this matters directly: credit scoring, insurance underwriting and anti-money-laundering systems are all candidates for tighter oversight, with implications for cross-border finance and regional investment flows.
On connectivity and digital economy questions, the more probable trajectory is incremental. Regional trade corridors will continue to adopt data-intensive tools for customs and logistics, driven by efficiency rather than by regulation, and governance frameworks will follow rather than lead. Whether Central Asia and the Caucasus develop dedicated AI rules, rely on data protection and sector regulation, or align with external frameworks will determine how attractive they appear to foreign investors in technology and digital infrastructure.
Conclusion
The global regulatory picture for artificial intelligence is not converging on a single model. It is dividing into distinct traditions: comprehensive horizontal legislation in the European Union, administrative regulation of specific services in China, federal proposals with subnational gaps in Canada, soft law with selective hardening in Japan, and voluntary principles in Australia. International organisations have provided frameworks and vocabulary, but not binding harmonisation.
For Eurasian businesses, the strategic response is not to wait for clarity that is unlikely to arrive on a convenient timetable. It is to treat regulatory exposure as a design parameter: mapping which markets and customers trigger which obligations, building documentation and governance practices that can be adapted rather than rebuilt, and pricing compliance into investment decisions. For policymakers in Central Asia, the Caucasus, Türkiye and the Western Balkans, the choice is whether to shape domestic rules early enough to influence how external requirements are applied locally, or to absorb them indirectly through trade and finance. The former offers more room to protect regional competitiveness. The latter is the default.
Key Takeaways
- AI regulation is fragmenting rather than harmonising, and the divergence is now a material business risk rather than a theoretical one.
- The EU AI Act is the most developed horizontal framework and will shape compliance practice well beyond EU borders, including in candidate countries and trading partners.
- Eurasian businesses outside the EU are often regulated indirectly, through customer contracts, data protection regimes and procurement conditions.
- Compliance costs favour larger firms, raising questions about market concentration and access for smaller vendors in regional supply chains.
- Central Asia and the Caucasus remain lightly covered by dedicated AI rules, creating flexibility but also uncertainty for technology and infrastructure investors.
- Technical standards and assurance mechanisms are the most plausible route to reducing the practical cost of legal divergence over the next three to five years.
SEO Keywords
Eurasia Business, Eurasia Economy, Artificial Intelligence Regulation, Digital Economy, Cross-Border Trade, Foreign Direct Investment, Infrastructure, Logistics, Supply Chain, Industrial Development, Business Strategy, Investment, Regional Connectivity, Trade Corridors, Capital Markets, Economic Development, Emerging Markets, EU AI Act, Data Governance, Technology Policy
Sources
- White & Case, "AI Watch: Global regulatory tracker – United States" — https://www.whitecase.com/insight-our-thinking/ai-watch-global-regulatory-tracker-united-states