Researchers map AI regulation gaps across EU, US and China

A new comparative review builds a regulatory matrix that lines up AI governance rules in the European Union, the United States and China side by side. For each jurisdiction the matrix maps four things: what triggers a risk classification, what binding obligations follow from it, how enforcement and accountability mechanisms work, and how far FAIR principles, meaning that data and systems should be findable, accessible, interoperable and reusable, are actually operationalised in practice rather than stated as aspiration.

The authors stress-test this matrix against three high-impact domains rather than leaving it abstract. The first is EEG-guided rehabilitation robotics: hardware that reads a patient's brain signals to drive a rehabilitation device. The second is AI-enabled debt collection inside prospective Central Bank Digital Currency (CBDC) ecosystems, where an automated system could flag or act on a citizen's digital-currency debt. The third is AI-driven allocation of scarce GPU resources inside emerging AI Factory infrastructure, the compute clusters that train and run large models.

Working from primary legal texts and implementation evidence, the authors identify three recurring gaps that cut across the domains and jurisdictions they examined: interoperability mandates are weak, obligations that span multiple regimes at once (AI-specific rules, sector regulation and data protection law together) are hard to operationalise, and governance for critical digital infrastructure use cases is under-specified.

To bridge that implementation gap, the paper outlines Knowledge Blocks: a machine-checkable compliance artefact pattern built on three existing web standards. RDF/OWL (Resource Description Framework/Web Ontology Language) represents the knowledge, SHACL (Shapes Constraint Language) validates it against rules, and PROV-O (Provenance Ontology) tracks where facts and decisions came from. The stated goal is audit-ready compliance-by-design that works across multiple regulatory regimes at once, instead of a separate compliance layer built per jurisdiction.

Key facts

  • The comparative matrix maps four dimensions per jurisdiction: risk classification triggers, binding obligations, enforcement and accountability mechanisms, and how far FAIR principles are operationalised.
  • The matrix covers the EU, the US and China.
  • It is stress-tested on three domains: EEG-guided rehabilitation robotics, AI-enabled debt collection in prospective CBDC ecosystems, and AI-driven GPU allocation in AI Factory infrastructure.
  • The authors identify three recurring gaps: weak interoperability mandates, difficult operationalisation of cross-regime obligations (AI plus sector regulation plus data protection), and under-specified governance for critical digital infrastructure.
  • They propose Knowledge Blocks, a machine-checkable compliance artefact pattern built on RDF/OWL, SHACL and PROV-O, aimed at audit-ready compliance-by-design across multiple regimes.

Why it matters

AI governance is moving from voluntary ethics codes to enforceable, risk-based regulation, but the EU, US and China are doing it differently, and that divergence creates real compliance uncertainty for anyone running high-stakes AI systems across borders. Rather than describing each regime in the abstract, this review builds a structured matrix and tests it against three concrete high-risk use cases, which is what turns a legal comparison into something an operator could actually check a system against.

Who it affects

Compliance and legal teams at organisations running high-risk AI across the EU, US and China; specifically, operators building EEG-guided rehabilitation robotics, systems that manage debt collection inside CBDC ecosystems, and providers allocating GPU capacity in AI Factory infrastructure. It also speaks to policymakers designing interoperable rules and to researchers building compliance tooling.

How to use it

There is no product or price here, only a proposed pattern. Knowledge Blocks are meant to be built from existing web standards: system descriptions modelled in RDF/OWL, obligations encoded as SHACL constraints that check those descriptions, and PROV-O used to keep an audit trail of where each fact and decision came from. The paper does not give a timeline or adoption plan for putting this into practice.

How solid is it

This is a comparative legal and technical analysis, drawn from primary legal texts and implementation evidence rather than secondary summaries, according to the authors. The source text gives no author names or institutional affiliations, and no peer-review status is stated. No empirical results or case-study outcomes are reported for applying the matrix, or Knowledge Blocks, to the three stress-test domains; the domains illustrate the framework rather than validate it with data.

Risks and caveats

The paper does not report which jurisdiction, EU, US or China, comes out ahead on any dimension, only that the matrix can be applied to all three. Knowledge Blocks is presented as a proposed pattern, not a deployed or tested system, and no timeline or adoption path is given. Since compliance obligations are set by regulators, actual uptake depends on decisions outside the authors' control.