Asia’s AI rulebooks are diverging — here is what operators must know

Singapore, Tokyo, Seoul, Beijing and New Delhi are writing five different futures for artificial intelligence. Companies operating across the region need a compliance map, not a compliance memo.
Kuala Lumpur skyline representing Asian metropolitan policy jurisdictions

Five jurisdictions. Five different answers to the same question. Companies operating across Asia are discovering that there is no regional AI compliance position — only five national ones, held simultaneously, with different documentation, different risk taxonomies, and different enforcement postures.

This is not a problem that resolves by waiting. The divergence is structural, and it is accelerating.

What each jurisdiction actually did

The five approaches share almost nothing at the level of mechanism:

  • Singapore took the voluntary-standards route — model governance frameworks, sector guidance, and a certification pathway that companies adopt because procurement demands it rather than because law compels it
  • Japan legislated lightly, focusing on disclosure and transparency obligations for generative systems while leaving risk classification to industry bodies
  • South Korea passed a comprehensive act with explicit high-risk categories, conformity assessment requirements, and defined penalties
  • China regulates by service type — separate regimes for recommendation algorithms, deep synthesis, and generative AI, each with filing obligations and content requirements
  • India has moved through advisory and platform rules rather than dedicated statute, with enforcement arriving through existing consumer and IT law

Singapore, Tokyo, Seoul, Beijing and New Delhi are writing five different futures for artificial intelligence. Companies operating across the region need a compliance map, not a compliance memo.

Where the divergence actually hurts

Different laws are manageable. Different assumptions are not. Three areas produce real operational friction:

Risk classification. A credit-scoring model is high-risk under the Korean act, subject to sector guidance in Singapore, and largely unaddressed in Japan. The same system carries different obligations depending on where it is deployed — and increasingly, where its outputs are used.

Documentation. Model cards, training data provenance records, evaluation logs, and incident registers are all required somewhere in the region. None are required in the same format everywhere. A company maintaining five separate documentation sets is spending more on compliance engineering than on model engineering.

Extraterritorial reach. The Chinese filing regime attaches to services offered to Chinese users regardless of where the provider sits. The Korean act has extraterritorial provisions. A Singapore-based company serving both markets has obligations in neither’s domestic law and both’s reach.

The compliance map approach

Organisations that have handled this well share a pattern. They stopped trying to find a common denominator and started mapping obligations per deployment.

In practice that means a register keyed on model, jurisdiction, and use case — not on model alone. Each entry carries the classification that jurisdiction assigns, the documentation it requires, the notification it triggers, and the enforcement exposure it creates.

It is more work than a single framework. It is also the only thing that survives an audit in two jurisdictions in the same quarter.

What operators should do now

Four actions, in order of urgency:

  • Inventory every AI system by deployment jurisdiction, not by development site — the two are increasingly different
  • Identify which systems fall into any jurisdiction’s high-risk category, and treat the strictest applicable regime as the baseline
  • Build documentation once, in a format that can be transformed rather than rewritten per jurisdiction
  • Assign named ownership for each jurisdiction. Regional AI governance roles do not work when the obligations are national

Where this goes

Convergence is unlikely in the near term. Each jurisdiction is optimising for a different thing: Singapore for hub status and adoption, Japan for industrial competitiveness, Korea for consumer protection and domestic industry, China for content control and technological sovereignty, India for scale and access.

Those objectives do not conflict loudly. They simply do not align — and regulatory systems built on different objectives produce different rules even when the technical subject matter is identical.

The operating assumption for the next five years should be sustained divergence, managed deliberately.

Share this story

Leave a Reply

Your email address will not be published. Required fields are marked *