AI Policy

How enterprises can address AI compliance challenges through a multi-dimensional framework

Based on analysis from Bloomberg Law, this article explores how enterprises can use a four-dimensional framework (geography, industry, stakeholder roles, and risk categories) to address increasingly complex AI regulations, and uses California regulations as an example to demonstrate the practical application of the framework.

Industry Background

Global AI regulation is emerging at an accelerating pace—from the EU's AI Act to state-level legislation, the number of regulations is growing far faster than enterprises' ability to update their compliance systems. The traditional approach of tracking regulations one by one is no longer viable. What enterprises need is not "which rules apply today," but a methodology to efficiently and reliably answer "how do the rules affect us."

An opinion article in Bloomberg Law notes that Agatha Liu of Duane Morris LLP proposed a compliance framework based on four dimensions: geography and industry, stakeholder role, and risk category. This framework can describe nearly all AI compliance obligations while maintaining stability and portability, even as specific rules evolve.

Market Impact

The lack of a compliance framework is becoming a major obstacle to enterprise AI deployment. According to the framework analysis, model deployers—entities that integrate AI into products—bear the largest share of compliance obligations, even if they did not develop the underlying model. This directly affects corporate decisions to purchase and integrate third-party AI services, prompting companies to add compliance clauses in procurement contracts.

For investors, enterprises that can demonstrate mature compliance systems are more attractive in financing and M&A. Regulatory uncertainty is shifting from a risk factor to a competitive barrier—companies that establish frameworks first will gain a first-mover advantage.

Competitive Landscape

Who Benefits - Legal tech and compliance consulting firms: The framework methodology can be translated into SaaS tools and services, helping clients quickly map compliance requirements. - AI model development platforms (e.g., OpenAI, Anthropic): Platforms with strong transparency and documentation capabilities are more likely to be adopted by deployers, reducing downstream compliance burdens. - Cloud service giants (e.g., AWS, Azure, GCP): Cloud platforms that offer compliance "out of the box" will attract enterprise customers.

Who Faces Pressure - Data brokers: California SB 361 requires disclosure of personal information sold or shared to AI developers; increased transparency in the data supply chain will compress the gray market. - Model developers lacking documentation: AB 2013 requires public disclosure of training data summaries; small teams relying on undisclosed data sources are at risk. - High-risk industry enterprises (healthcare, finance): Industry-specific regulations (e.g., California SB 1120) impose stricter obligations and increase compliance costs.

Who May Follow - EU member states and other states (e.g., New York, Colorado) may draw on California's four-dimensional framework to refine local regulations. - Industry associations (e.g., ISO, NIST) may incorporate this framework into AI risk management standards.

Enterprise ImplicationsCompanies should take the following actions immediately: 1. Define their role: Clarify whether they are data owners, model developers, model deployers, end users, or a combination of these roles in the AI value chain. 2. Map the risk landscape: Evaluate risks across the entire system lifecycle according to seven risk categories (bias, privacy violations, IP infringement, opacity, inaccuracy, deception, complacency). 3. Build a compliance program: Design control measures based on the framework, ensuring that new regulations can be quickly mapped onto existing systems rather than starting from scratch each time. 4. Cross-department collaboration: Legal, risk management, and technical teams must work together, as compliance obligations span data collection, model training, deployment, and use.

Future Outlook

  • 12 months: More states will follow California’s lead in enacting AI transparency and accountability regulations, and the four-dimensional framework will become the standard compliance methodology for enterprises.
  • 24 months: Several implementation details of the EU AI Act will take effect, and the framework can be seamlessly transferred to the EU context, especially regarding obligations for high-risk AI systems.
  • 3 years: Global AI regulation will converge; companies will no longer debate “which rules apply,” but will compete on the efficiency and maturity of their compliance systems. Early movers will turn compliance into a competitive advantage, while those who hesitate may face market access restrictions and heavy fines.

*The information in this article is based on the views of Agatha Liu published by Bloomberg Law and does not represent the stance of this publication.*

---

References Liu, Agatha. "Companies Can Tackle AI Compliance by Using Multipart Framework." *Bloomberg Law News*, June 18, 2026. https://news.bloomberglaw.com/legal-exchange-insights-and-commentary/companies-can-tackle-ai-compliance-by-using-multipart-framework-1

Article context · aiindustryreview

aiindustryreview frames this note through AI Models / Model releases and capability claims / Evaluation, safety, and benchmark signals. AI Models / Model releases and capability claims / Evaluation, safety, and benchmark signals explains the local editorial angle; dates, names and status changes still need checking. Source links should be opened before the summary is reused.

Source links

  1. https://news.bloomberglaw.com/legal-exchange-insights-and-commentary/companies-can-tackle-ai-compliance-by-using-multipart-framework-1Primary

Related articles

Back to channel