Skip to content
Review Open access

Navigating the patchwork: A cross-jurisdictional legal compliance framework for U.S. corporations deploying high-risk AI systems

Aug 2026 · International journal of applied research in social sciences · 0 citations

Abstract

U.S. corporations that deploy high-risk AI systems face a growing problem. AI regulation now comes from many sources at once: federal executive orders, agency guidance, state statutes and international rules such as the EU AI Act. These sources define key terms differently, impose different procedures and set different liability standards. As a result, corporations struggle to build compliance programs that satisfy every applicable rule. This study aims to build a cross-jurisdictional legal compliance framework for U.S. corporations that deploy high-risk AI systems. The framework identifies the rules that apply, shows where those rules conflict and proposes a single compliance structure that can meet multiple regulatory demands at once. The study uses doctrinal legal research combined with comparative regulatory analysis. This paper examines primary legal texts, including the EU AI Act, Executive Order 14110, the NIST AI Risk Management Framework, EEOC and CFPB guidance and state and local AI laws. The analysis proceeds in three stages: first, each regulatory instrument is reviewed to list its obligations; second, these obligations are compared across instruments to find overlaps, conflicts and gaps; third, a compliance framework is built to address the conflicts and gaps using ideas from corporate compliance theory. The study finds 47 distinct compliance obligations across eight major regulatory instruments. These obligations fall into five groups: pre-deployment assessment, technical documentation, ongoing monitoring, human oversight and disclosure and reporting. The EU AI Act imposes the broadest set of obligations, while U.S. federal agencies impose more detailed sector-specific rules. The study also finds 14 points of direct conflict among the instruments, most notably around public disclosure, liability standards and audit independence. A three-layer framework, built around risk classification, compliance mechanisms and governance, addresses 43 of the 47 obligations through five unified mechanisms. The remaining four obligations require separate steps specific to EU AI Act compliance. The study concludes that no single regulatory instrument can guide AI compliance on its own. Corporations need a risk-based system that is built into everyday legal and business practice, not treated as a one-time project. Keywords: AI Regulation, High-Risk AI, Cross-Jurisdictional Compliance, Algorithmic Accountability, Corporate Legal Compliance, AI Governance, Federal AI Policy, State AI Legislation, Risk Classification, Algorithmic Impact Assessment.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.