Source-linked AI summary
Global AI Regulations for FAIR and Ethics in High-Risk Use Cases: A Comparative Review
Aasish Kumar Sharma, Dimitar Koysev, Christopher Anich, Roshni Kumari Ojha, Julian Kunkel
TL;DR
High-risk AI governance remains fragmented across jurisdictions, with ambiguous classification and uneven FAIR operationalisation. This paper compares binding obligations across the EU, US, and China and stress-tests them across three use cases, identifying machine-interpretable compliance mechanisms as the central technical gap. It recommends interoperable, machine-checkable compliance artefacts for audit-ready governance.
Problem
AI governance remains fragmented, with classification ambiguity, uneven FAIR operationalisation, and incompatible enforcement models across jurisdictions and emerging high-risk use cases.
Method
The study qualitatively compares binding regulatory obligations across the EU, US, and China for three high-risk use cases using four analytical dimensions.
Results
The comparison identifies recurring gaps in classification clarity, cross-regime operationalisation, interoperability, and governance for critical digital infrastructure use cases.
Takeaways & Limitations
The paper recommends interoperable, machine-checkable compliance artefacts, alongside traceable data-model-decision links and continuous bias monitoring.
Takeaways & Limitations
The qualitative study covers three use cases, faces rapidly evolving regulation and enforcement-practice gaps, and relies on secondary sources for some Chinese enforcement data.
Abstract
from arXiv · showhide
AI governance is shifting from voluntary ethics to enforceable, risk-based regulation, yet cross-jurisdictional divergence creates compliance uncertainty for operators of high-stakes AI. We present a comparative matrix for the EU, US, and China that maps (i) risk classification triggers, (ii) binding obligations, (iii) enforcement and accountability mechanisms, and (iv) the degree to which FAIR principles are operationalised in practice. We stress-test the matrix on three high-impact domains: Electroencephalography (EEG)-guided rehabilitation robotics, AI-enabled debt collection in prospective Central Bank Digital Currency (CBDC) ecosystems, and AI-driven allocation of scarce Graphics Processing Unit (GPU) resources in emerging AI Factory infrastructures. Using primary legal texts and implementation evidence, we identify three recurring gaps: weak interoperability mandates, difficult operationalisation of cross-regime obligations (AI + sector regulation + data protection), and under-specified governance for critical digital infrastructure use cases. To bridge the implementation gap, we outline Knowledge Blocks, a machine-checkable compliance artefact pattern based on Resource Description Framework/Web Ontology Language (RDF/OWL), Shapes Constraint Language (SHACL), and Provenance Ontology (PROV-O), enabling audit-ready compliance-by-design across multiple regimes.
I. INTRODUCTION · II. BACKGROUND AND RELATED WORK · A. High-Risk AI and Regulatory Philosophies
The paper examines how major jurisdictions classify and govern high-risk AI, focusing on FAIR principles, persistent cross-domain governance gaps, and machine-checkable Knowledge Blocks as a partial operationalisation. It frames this analysis against the shift toward risk-based, enforceable regulation and divergent EU, US, and Chinese approaches.
- I. INTRODUCTION: High-risk AI failures or bias can affect fundamental rights, safety, and societal trust while mediating access to essential services.The paper argues governance must balance innovation with enforceable safeguards.
- I. INTRODUCTION: The EU Artificial Intelligence Act establishes a risk-based horizontal framework for AI governance.The passage identifies Regulation (EU) 2024/1689 as the relevant legal instrument.
- I. INTRODUCTION: The paper asks how major AI governance regimes classify high-risk AI, embed FAIR principles in binding obligations, and retain governance gaps across domains and jurisdictions.These are stated as research questions RQ1, RQ2, and RQ3.
- I. INTRODUCTION: Its contributions include a reproducible jurisdiction-agnostic evaluation matrix, cross-domain stress testing, and partial operationalisation of governance deficits through Knowledge Blocks.The stress testing uses three high-risk use cases to expose blind spots invisible in sector-isolated analyses.
- A. High-Risk AI and Regulatory Philosophies: AI regulation has shifted toward risk-based, enforceable frameworks.The paper presents this as the broader regulatory trend motivating its comparison.
- A. High-Risk AI and Regulatory Philosophies: The EU AI Act defines high-risk systems through Annex III, including biometric identification, employment, credit, and critical infrastructure.These sectors are listed as examples of Annex III coverage.
- A. High-Risk AI and Regulatory Philosophies: The US and China lack a unified high-risk AI definition but address elevated risk through sectoral and administrative mechanisms, respectively.The comparison distinguishes the US sectoral approach from China’s administrative approach.
- A. High-Risk AI and Regulatory Philosophies: Regulatory philosophies diverge, with the EU described as rights-based and precautionary, the US as market-driven and sectoral, and China as an administrative model.The passage explicitly characterizes the EU and US approaches and introduces China’s characterization before truncation.
B. FAIR Principles and Machine-Checkable Compliance … A. UC1: EEG-Guided Robotic Neurorehabilitation (Healthcare)
The section links FAIR principles to machine-checkable compliance evidence and examines three cross-jurisdictional high-risk use cases, beginning with EEG-guided rehabilitation robotics. In UC1, EU obligations are binding and layered with medical-device and data-protection rules, while US and Chinese governance relies on different regulatory combinations and all jurisdictions lack machine-checkable verification.
- B. FAIR Principles and Machine-Checkable Compliance: FAIR principles support transparency and auditability through traceable data, accessible documentation, and portable compliance evidence, but current artefacts are rarely machine-checkable.This weakens cross-border auditability, particularly for Interoperability; Knowledge Blocks are proposed as a modular compliance response.
- III. METHODOLOGY: The comparative design examines three high-risk use cases across the EU, US, and China using the EU AI Act as a consistent classification reference.The cases are UC1 EEG-guided rehabilitation robotics, UC2 AI-enabled debt collection in CBDC systems, and UC3 AI-driven resource allocation in AI Factories.
- IV. USE CASE ANALYSIS: The selected cases reflect clear EU AI Act high-risk characteristics and functional relevance across jurisdictions.The methodology therefore spans healthcare, finance, and HPC infrastructure applications.
- A. UC1: EEG-Guided Robotic Neurorehabilitation (Healthcare): UC1 uses a wearable exoskeleton and EEG to infer motor intent, mapping EEG patterns to actuator commands within a human-in-the-loop workflow.EEG is health and biometric information, making medical-device classification and special-category data processing central governance issues.
- A. UC1: EEG-Guided Robotic Neurorehabilitation (Healthcare): EU UC1 is high-risk under Article 6(1) of the AI Act, requiring risk management, data governance, technical documentation, transparency, human oversight, and robustness.These duties apply concurrently with the Medical Device Regulation and GDPR, alongside relevant IEC, ISO, and ISO/IEC 42001 standards.
- A. UC1: EEG-Guided Robotic Neurorehabilitation (Healthcare): US UC1 governance follows the FDA medical-device pathway, while AI-specific guidance is largely non-binding and fairness and lifecycle controls rely on voluntary frameworks.HIPAA addresses health data in covered-entity contexts.
- A. UC1: EEG-Guided Robotic Neurorehabilitation (Healthcare): China combines NMPA medical-device regulation with algorithmic governance, while PIPL treats EEG data as sensitive personal information subject to strict processing and cross-border-transfer constraints.Across jurisdictions, documentation, data provenance, and human-oversight verification lack machine-checkable compliance artefacts.
B. UC2: AI-Enabled Debt Collection in CBDC Systems (Finance)
AI-enabled debt collection in prospective CBDC systems can create high-risk concerns when it affects creditworthiness, payment constraints, or enforcement priorities. Across jurisdictions, fragmented regimes leave unresolved how to constrain programmable enforcement while preserving due process, contestability, proportionality, and nondiscrimination.
- Risk profile: CBDC debt-collection AI becomes high-risk when it influences creditworthiness, payment constraints, or enforcement priorities, amplifying discrimination and due-process concerns.Programmable money and realtime settlement support automated enforcement in the prospective CBDC ecosystem.
- EU: In the EU, debt-collection AI may be high-risk when it affects access to essential services, requiring coherent runtime coordination of AI, payment, and data-protection obligations.The relevant framework intersects the EU AI Act, Digital Euro legislative package, GDPR, and payment regulation.
- US: The US has no deployed CBDC; FDCPA, FCRA, ECOA, FTC, and CFPB mechanisms provide ex post accountability but limited AI-specific ex ante lifecycle obligations.Governance is mediated through sectoral statutes and agency enforcement rather than a CBDC-specific framework.
- China: China’s deployed e-CNY offers the most mature CBDC reference, combining strong administrative oversight with potential CAC filing requirements, PIPL, and cybersecurity controls for algorithmic profiling.CAC requirements may apply where debt collection relies on algorithmic profiling.
- Cross-jurisdictional gap: Across jurisdictions, the unresolved challenge is constraining programmable enforcement while preserving contestability, proportionality, and nondiscrimination.This issue is summarized in Table II.
C. UC3: AI-Driven Resource Allocation in AI Factories (HPC)
AI-driven allocation of scarce GPU resources raises fairness, contestability, and accountability concerns because opaque, feedback-driven systems may disadvantage emerging research groups. Regulatory coverage remains fragmented across the EU, US, and China, making machine-checkable compliance artefacts central to auditable governance.
- Governance challenge: Opaque ML allocation and feedback loops can reinforce institutional hierarchies or disadvantage emerging research groups, extending governance beyond efficiency to fairness, contestability, and accountability.The concern arises specifically in AI Factory infrastructures where GPU resources are scarce.
- EU: EU Annex III does not explicitly cover HPC allocation, although foreseeable misuse or systemic effects on access and careers could support high-risk classification.Potential obligations would include data governance, bias monitoring, transparency, human oversight, and contestation rights.
- US: The US has no horizontal AI regime for HPC scheduling, leaving governance primarily to institutional policies and voluntary frameworks such as the NIST AI RMF.Consequently, fairness depends on local policy and audit capacity.
- China: China’s algorithmic governance may require registration and anti-discrimination measures for systems with public or societal impact, but its application to HPC allocation remains indirect.Bias attribution is technically difficult because outcomes depend on workload characteristics and institutional history.
- Implementation gap: The main implementation bottleneck is the lack of standardized, machine-checkable compliance artefacts for allocation decisions.Knowledge Blocks can encode inputs, constraints, explanations, and appeal traces as auditable semantic artefacts.
V. CROSS-CUTTING ANALYSIS … C. Cross-Cutting Gaps
The comparative analysis shows that governance logics shape cross-border enforceability and evidence production, while FAIR support remains uneven and interoperability weak. Four gaps recur across use cases: classification uncertainty, limited implementation guidance, heterogeneous enforcement, and missing machine-checkable compliance artefacts.
- A. Regulatory Philosophy Comparison: Governance logics determine what becomes enforceable and how readily compliance evidence can be produced across borders.
- B. FAIR Support Across Jurisdictions: Findability is strongest in China through registries, conditional in the EU, and largely voluntary in the US across UC1 to UC3.
- B. FAIR Support Across Jurisdictions: Accessibility is explicit in China, conditional in the EU, and fragmented in the US, while reusability is stronger in the EU and China through documentation mandates.Reusability still lacks standardized formats.
- B. FAIR Support Across Jurisdictions: Interoperability remains the weakest FAIR dimension because compliance evidence is rarely portable or machine-checkable across jurisdictions.
- C. Cross-Cutting Gaps: UC3 is a boundary case where systemic impact supports a high-risk interpretation not explicitly covered by Annex III, while UC2 awaits legislative resolution.
- C. Cross-Cutting Gaps: Obligations provide limited implementation guidance: UC3 fairness metrics are nonstandardized, UC1 EEG explainability is underspecified, and UC2 automated enforcement lacks concrete constraints.
- C. Cross-Cutting Gaps: The EU emphasizes ex ante compliance, China combines registration with administrative control, and the US relies on ex post sectoral enforcement, producing incompatible multinational audit expectations.
- C. Cross-Cutting Gaps: Compliance documentation is rarely structured for automated validation or cross-border portability, motivating compliance-by-design approaches such as Knowledge Blocks.
VI. DISCUSSION · A. Insights from the Use Cases
The use cases reveal distinct governance patterns: regulated AI products have clearer classification pathways, while financial AI and infrastructure allocation expose unresolved cross-regime and classification challenges. Across the cases, ethical gaps are most visible when AI mediates access to services or infrastructure, reflecting missing operational guidance rather than absent principles.
- A. Insights from the Use Cases: UC1 benefits from clear classification and established conformity pathways for regulated AI products.Compliance remains burdensome because the AI Act, MDR, and GDPR must be integrated without a single auditing standard.
- A. Insights from the Use Cases: UC1’s multi-layer compliance across the AI Act, MDR, and GDPR creates integration burdens.The passage identifies the absence of a single auditing standard as a practical limitation.
- A. Insights from the Use Cases: CBDC-embedded debt collection creates regime coupling among AI regulation, payment services law, and data protection.The obligations must be operationalised coherently at runtime.
- A. Insights from the Use Cases: No current framework provides joint compliance guidance for the obligations governing financial AI embedded in CBDC systems.The gap concerns coherent runtime operationalisation across AI regulation, payment services law, and data protection.
- A. Insights from the Use Cases: UC3 exposes a governance gap for AI-driven infrastructure allocation because classification is ambiguous in the EU, internalized in the US, and indirect in China.The passage links these systems to high-stakes effects on research access and career outcomes.
- A. Insights from the Use Cases: Across all three cases, ethical gaps are most visible where AI mediates access to services or infrastructure.The central limitation is described as the absence of operational governance rather than a lack of declared principles.
B. Research Question Synthesis
The review finds that the EU, China, and US diverge in high-risk AI classification and binding FAIR obligations, with infrastructure AI exposing framework limits. Four recurring governance gaps undermine consistent, auditable compliance across jurisdictions.
- RQ1: High-risk classification: The EU uses preventive lifecycle governance, China mandatory administrative registration and oversight, and the US sectoral, reactive enforcement to classify and regulate high-risk AI.These approaches shape both what is classified as high-risk and when obligations apply.
- RQ1: High-risk classification: Infrastructure AI exposes framework limits: EU Annex III is under-specified, US governance is institutional, and Chinese provisions apply indirectly.The passage identifies infrastructure AI as UC3.
- RQ2: FAIR obligations: FAIR support is asymmetric: findability is strongest in China, conditional in the EU, and largely voluntary in the US; interoperability is weakest across all three.Accessibility is explicit in China, conditional in the EU when AI is high-risk, and fragmented in the US; reusability is stronger where documentation mandates exist.
- RQ3: Governance gaps and enforcement: Four recurring gaps are classification ambiguity, operationalisation deficits, enforcement heterogeneity, and absent machine-checkable compliance artefacts.Together, these gaps limit cross-border auditability and create incompatible compliance expectations in multinational deployments.
C. Limitations · VII. CONCLUSION AND RECOMMENDATIONS
The study identifies limitations from qualitative scope, rapidly changing regulation, and enforcement gaps, while recommending machine-checkable compliance, clearer infrastructure classification, and operational fairness monitoring. Future work will deploy Knowledge Blocks in operational settings.
- C. Limitations: The study is qualitative and constrained by rapidly evolving regulation and gaps between formal rules and enforcement practice.It covers three use cases and requires empirical validation for broader generalization, especially fairness measurement in infrastructure systems.
- C. Limitations: Broader generalization requires empirical validation, particularly for fairness measurement in infrastructure systems.Enforcement data, especially for China, relies on secondary sources.
- VII. CONCLUSION AND RECOMMENDATIONS: AI governance remains fragmented despite convergence in principles, with classification ambiguity, uneven FAIR operationalisation, and incompatible enforcement models limiting effectiveness.These weaknesses affect emerging use cases across current regulatory regimes.
- VII. CONCLUSION AND RECOMMENDATIONS: The absence of machine-interpretable compliance mechanisms is the central technical gap, especially before EU AI Act full applicability in August 2026.The gap is particularly pressing for large-scale infrastructures such as AI Factories.
- VII. CONCLUSION AND RECOMMENDATIONS: Operators should perform early classification assessments, trace data-model-decision links, and implement continuous bias monitoring.These measures are presented as operational recommendations for improving accountability and fairness.
- VII. CONCLUSION AND RECOMMENDATIONS: Policymakers should clarify high-risk classification for infrastructure AI and mandate interoperable, machine-checkable compliance artefacts as audit standards.Research should prioritize standardized fairness metrics and semantic auditing tools for infrastructure-level AI.
APPENDIX
The appendix outlines the EU AI Act’s two pathways for defining high-risk AI and summarizes China’s algorithm-registration framework and filing activity. EU classification covers regulated-product safety components and specified Annex III domains, while Chinese filings require classification, domain, logic, training-data sources, and self-assessment.
- EU high-risk classification: The EU AI Act defines high-risk AI through two pathways: regulated-product safety components requiring third-party conformity assessment and systems listed across eight Annex III domains.Annex III systems may be exempt when limited to preparatory or supportive roles without influencing outcomes, except when profiling natural persons is involved.
- China algorithm registry: China’s CAC registry recorded over 1,400 algorithms from 450+ entities as of January 2026.Major registrants include Tencent, Alibaba, ByteDance, Baidu, and JD.com.
- China algorithm registry: Registry filings require algorithm classification, application domain, core logic, training data sources, and a self-assessment report.The requirements are defined in China’s algorithmic-recommendation, deep-synthesis, and generative-AI provisions.
- China algorithm registry: Recommendation algorithms comprised 64% of Chinese registry filings, followed by search/filtering at 18%, generative AI at 12%, and others at 6%.These figures describe the category distribution reported in the January 2026 CAC registry.