The multinational playbook — and the open questions for 2027+

Lesson 5 of 5 in Summits, Safety Institutes, and Comparing Regimes Like a Pro.

Time to convert analysis into strategy. Your firm ships one generative-AI assistant and wants it live in China, South Korea, Japan, Singapore and Brazil simultaneously. Here is what each market actually demands of that one product — read the table, then we choose a strategy.

One GenAI chatbot, five markets (as of September 2026)
MarketBefore launchOngoingBinding?

China

Security assessment; algorithm filing with the CAC; training-data legality checks; labeling implementation (explicit + embedded)

Content moderation to Chinese content rules; label integrity; rectification exposure

Yes — the thickest pre-launch gate on Earth

South Korea

Determine high-impact status; appoint a domestic representative if foreign; GenAI transparency and labeling readiness

Safety/assurance duties if high-impact or above compute thresholds; MSIT fact-finding exposure; fines up to KRW 30M

Yes — in force since 22 Jan 2026

Japan

Nothing mandatory — align with the AI Guidelines for Business

Duty to cooperate with government policy; investigate-and-name exposure, no fines

Statute exists; obligations effectively soft

Singapore

Nothing mandatory — Model GenAI Framework alignment; AI Verify / Moonshot testing strengthens market position

PDPA and sectoral rules (MAS FEAT if in finance)

No — voluntary by design

Brazil

LGPD compliance (lawful basis for training and personal data); monitor PL 2338

If PL 2338 passes: preliminary GPAI assessment, transparency, copyright duties

Privacy law yes; AI statute pending

Two strategies dominate practice, with a third forced on you by China.

Highest common denominator: build once, to the strictest applicable rule in each dimension — Chinese-grade labeling, Korean-grade documentation, EU-grade risk management if Europe is on the roadmap. Cheapest to operate (one build), most expensive to create, and it over-complies in Tokyo and Singapore — which costs speed but buys trust.

Core plus wrappers: one governance core — an ISO 42001-style management system generating a single evidence base, mapped via crosswalks to the NIST RMF and national regimes — with thin market-specific wrappers: the CAC filing here, the Korean domestic representative there, the Brazilian LGPD records underneath. This is what mature multinationals actually run.

The forcing exception: some obligations are incompatible, not just stricter. Chinese content-moderation duties cannot be ‘complied up to’ from a global build that must also satisfy other markets’ expression norms — they demand a separate instance or an exit. Strictness you can stack; contradiction you must partition.

Choose your multinational compliance strategy

Interactive decision tree — outcomes:

  • Highest common denominator

    One global build to the strictest rule in every dimension. Expensive to create, cheap to run, and it converts compliance into a trust asset in lenient markets. Re-check whenever a new market adds a rule that is incompatible rather than stricter — that breaks this strategy.

  • Core plus wrappers

    One governance core (management system, single evidence base, crosswalk mappings) with thin market-specific wrappers: filings, labels, local representatives, market-specific assessments. The industry-standard architecture for mature multinationals — its failure mode is wrapper drift, so fund the regulatory-watch function.

  • Partitioned instance for the incompatible market

    Run the incompatible market (typically China) as a separate product instance with its own moderation, filing and data arrangements, and a core-plus-wrappers build everywhere else. Watch cross-instance leakage: shared models, shared training pipelines and shared logs can quietly re-couple what you partitioned.

  • Do not launch in the incompatible market

    If you can neither reconcile nor partition, the compliant answer is absence. Firms that launch anyway are betting the enforcement gap — in China’s case, against a regulator that removes apps first and discusses later.

  • Sequence your markets

    Launch first where obligations are light (Japan, Singapore), build governance maturity on real operations, then enter the heavy markets with a core-plus-wrappers architecture. Slower, humbler — and far more common than launch decks admit.

Tool: Regulatory Time Machine — Run the Time Machine to replay the 2017–2026 buildout — then test your predictions for 2027 against the open questions above.

Key terms: Brussels effect, Council of Europe Framework Convention on AI, ISO/IEC 42001, NIST AI Risk Management Framework, Hiroshima AI Process

Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.