A new arXiv paper posted on 18 August 2026 maps how AI regulation across the EU, US and China has diverged, identifying three recurring compliance gaps that leave operators of high-stakes AI systems without a single rulebook S¹. The authors propose a machine-checkable fix called Knowledge Blocks, but no regulator has tested it S¹. Whether the concept works depends on a question the paper itself cannot answer.
My read: This is the first comparative study I have seen that takes the divergence problem seriously enough to propose a concrete technical artefact rather than another policy recommendation. The three stress-test domains are deliberately exotic, and that is both the strength and the weakness. EEG robotics and CBDC debt collection are prospective, which means the paper is mapping terrain that barely exists yet. I do not buy the claim that Knowledge Blocks will solve cross-regime compliance until someone shows it working against a real regulator's audit checklist. But the three gaps the authors identify, weak interoperability, tangled cross-regime obligations, and under-specified infrastructure governance, are real and familiar to anyone building AI systems across borders.
Three jurisdictions, three rulebooks
The paper's central claim is that AI governance has moved past the era of voluntary ethics frameworks and into enforceable, risk-based regulation, but the three biggest jurisdictions are not converging S¹. The EU, US and China each classify AI risks differently, impose different binding obligations, enforce those obligations through different mechanisms, and operationalise the FAIR principles (Findable, Accessible, Interoperable, Reusable) to different degrees S¹.
The authors build a comparative matrix to map these differences across four dimensions: what triggers a risk classification, what obligations bind operators, how enforcement and accountability work, and how much of the FAIR data principles actually show up in practice S¹. The matrix is the paper's backbone. It lets the authors hold the three regimes side by side and show where they align and where they fracture.
A companion GitHub repository by Katherine Elkins, created in November 2025, carries a related comparative analysis of AI regulation in the EU, China and the US, examining risk frameworks and enforcement approaches P³. That independent work covers similar ground. The divergence problem is attracting attention beyond this single paper.
Where the matrix gets stress-tested
The authors do not stop at mapping. They run their matrix against three high-impact domains that sit at the intersection of AI, sector-specific regulation and data protection S¹.
The first is EEG-guided rehabilitation robotics, systems that read brain signals to control prosthetic or therapeutic devices. The second is AI-enabled debt collection in prospective Central Bank Digital Currency ecosystems, digital currencies issued by central banks that do not yet exist in fully operational form. The third is AI-driven allocation of scarce GPU resources in emerging AI Factory infrastructures, the large compute clusters now being built to serve AI workloads S¹.
All three are prospective. The CBDC domain is explicitly described as prospective in the source material. The AI Factory concept is emerging. EEG robotics exists in research labs but is not a mass-market product. The paper is stress-testing a matrix against futures that have not fully arrived, which is useful for anticipating gaps but limits how much weight the findings can carry today.
Three gaps that keep appearing
Across all three stress tests, the authors identify three recurring gaps S¹.
First, interoperability mandates are weak. The rules in one regime do not cleanly connect to rules in another, so an operator complying in the EU has no guarantee that the same compliance artefact satisfies US or Chinese regulators.
Second, cross-regime obligations are hard to operationalise. An AI system in healthcare, for example, may need to satisfy AI-specific regulation, medical device regulation and data protection law simultaneously. The paper argues that these overlapping regimes create obligations that are individually clear but collectively tangled.
Third, governance for critical digital infrastructure use cases is under-specified. The GPU allocation domain is the clearest example: when an AI system decides who gets compute and who does not, existing regulation has little to say about how that decision should be governed, audited or challenged.
Knowledge Blocks: a compliance artefact, not a policy
The paper's proposed fix is technical rather than political. The authors outline Knowledge Blocks, a machine-checkable compliance artefact pattern built on three existing web standards: RDF/OWL (a framework for describing data relationships), SHACL (a language for validating data shapes), and PROV-O (an ontology for tracking where data came from and how it was processed) S¹.
The idea is that an operator could encode its compliance obligations as structured, machine-readable artefacts, and those artefacts could be automatically checked against the requirements of multiple regulatory regimes. The authors call this audit-ready compliance-by-design across multiple regimes S¹.
The concept is clean. The execution is unproven, and no regulator has endorsed, piloted or even acknowledged Knowledge Blocks. The paper presents them as a pattern, not a deployed system. There is no evidence in the source material of any real-world implementation or test against an actual regulatory audit.
What to do about it
Consider a company that runs an AI Factory, a GPU cluster serving inference workloads for clients across the EU, US and China. The company uses an AI scheduler to decide which clients get priority access to scarce compute during peak demand. Under the paper's framework, that scheduler sits in a regulatory grey zone: it is an AI system making allocation decisions about critical digital infrastructure, and no single regime has clear rules for how those decisions should be governed or audited S¹.
For a company in that position, the practical takeaway from the paper is not to wait for regulators to converge. It is to start building compliance documentation that is structured, traceable and portable across jurisdictions. The FAIR principles the paper examines give a starting framework: if your compliance artefacts are not interoperable across regimes today, they will not become so by accident.
One concrete step: map your AI system's data lineage, what data it uses, where it came from, how it was processed, using a provenance standard like PROV-O. If you cannot trace the data path, you cannot demonstrate compliance to any regulator, let alone three.
What we don't know yet
The paper is an arXiv preprint, not a peer-reviewed publication S¹. Its analytical conclusions, the three gaps, the divergence diagnosis, the Knowledge Blocks proposal, are the authors' own and have not been independently corroborated.
The comparative matrix covers only the EU, US and China. It does not include Australia, the UK, Japan, India or any other jurisdiction with active AI regulation. The generalisations the paper draws may not hold for regulatory environments outside those three.
The three stress-test domains are largely prospective. CBDC-based debt collection is not operational. AI Factory GPU allocation is emerging but not yet a mature, regulated activity. EEG-guided rehabilitation robotics is a research field, not a commercial market. The gaps the paper identifies in these domains may be real, but they are gaps in futures that have not fully materialised.
Knowledge Blocks is a concept without a deployment. No regulator has tested it. No operator has built it. Whether machine-checkable compliance artefacts can actually satisfy an audit by a real regulator remains an open question.
The next signal: a separate arXiv paper, An Evaluation Framework for National AI Regulation (arXiv:2608.15417), offers a related framework for evaluating national AI regulation P⁴. If that work gains traction or is cited by regulators, it could provide an independent test of whether comparative frameworks like the one in this paper hold up under scrutiny. We will watch for follow-up work and any regulator response.
If this kind of regulatory analysis is useful to you, subscribe. We will keep tracking how AI rules diverge, converge and land on the people building with them.
Sources: S1 — Global AI Regulations for FAIR and Ethics in High-Risk Use Cases: A Co · P2 — Global AI Regulations for FAIR and Ethics in High-Risk Use Cases: A Co · P3 — KatherineElkins/global-ai-regulation-comparative-study · P4 — An Evaluation Framework for National AI Regulation · P5 — yuchenlwu/PersonalizedSafety
More from Not A Tech Guy
- AI lock-in is already happening, researchers warn
- OpenAI's Defender's Window: AI reshapes cyber defense
- AI generates synthetic health data across multiple tables
Generated from an audited evidence pack with primary-source research. Social-media items are discussion signals, not verified facts. Nothing here is financial, legal or medical advice.