/

  / DPIA vs Risk Assessment Under GDPR

DPIA vs Risk Assessment Under GDPR

The CNIL‘s screening rule sounds simple: hit two of the nine high-risk criteria, and you owe a full Data Protection Impact Assessment (DPIA). The trouble starts when you hit one or none, because the GDPR never says that skipping the DPIA means skipping assessment altogether.

Plenty of processing falls outside the CNIL’s screening rules: operations below the two-criteria threshold, activities on the CNIL’s exemption list, processing already covered by an earlier DPIA, and controllers who answer to a different supervisory authority altogether. In every one of those cases, the Article 35 GDPR DPIA obligation may fall away while the risk assessment obligations under Articles 24 and 32 stay exactly where they were. This article maps the scenarios where CNIL criteria don’t apply and what a defensible assessment strategy looks like when they don’t.

DPIA vs Risk Assessment Under GDPR

DPIA vs General Risk Assessment: Core Distinctions Under GDPR

These two assessments get conflated constantly, and the mix-up has real consequences. They rest on different legal bases, serve different purposes, and trigger under different conditions.

Article 35 GDPR requires a DPIA where processing is “likely to result in a high risk” to people’s rights and freedoms, and it requires the assessment before processing begins. The DPIA looks outward. It evaluates the necessity and proportionality of the processing and the risks it creates for data subjects: discrimination, identity theft, financial loss, reputational damage, loss of control over personal data. The measuring stick throughout is harm to people.

Article 32 GDPR requires controllers and processors to put in place technical and organizational measures (TOMs) appropriate to the risk of the processing. You can’t know what’s appropriate without assessing that risk first, so Article 32 carries an implicit risk assessment duty for every processing operation you run, high risk or not. Its focus is security: the confidentiality, integrity, availability, and resilience of the systems handling personal data.

Article 24 completes the picture by making the controller responsible for implementing measures proportionate to risk and able to demonstrate compliance. That’s the accountability principle at work.

So risk assessment is universal, and the DPIA is the escalated version you reserve for processing that crosses the high-risk line. The real question is which assessment to run and how deep to go.

You don't need a six-figure budget to be GDPR compliant. You need a clear plan and someone to do the work.

Affordable GDPR Compliance Services

The CNIL Criteria: A Quick Recap

The Article 35(3) Baseline and the 9 Criteria

Article 35(3) names three situations where a DPIA is always mandatory: systematic and extensive automated evaluation of individuals, including profiling, with legal or similarly significant effects; large-scale processing of special categories of data (Article 9) or criminal conviction data (Article 10); and large-scale systematic monitoring of a publicly accessible area.

Beyond those, the WP29 guidelines on DPIAs (WP248 rev.01), endorsed by the European Data Protection Board (EDPB), list nine criteria that indicate likely high-risk processing: evaluation or scoring, including profiling; automated decision-making with legal or similarly significant effect; systematic monitoring; sensitive data or data of a highly personal nature; processing on a large scale; matching or combining datasets; data concerning vulnerable data subjects (employees, patients, children); innovative use or application of new technological or organizational solutions; and processing that prevents data subjects from exercising a right or using a service or contract.

The “Two Criteria” Threshold Rule

The CNIL’s position is that processing meeting at least two of the nine criteria requires a DPIA as a general rule. WP248 leaves room on both sides of that line: a controller can conclude that processing meeting two criteria still isn’t high risk, and in some cases a single criterion is enough to trigger the obligation. Either way, the reasoning has to be documented. Where there’s genuine doubt, the CNIL’s advice is simple: do the DPIA.

CNIL’s List of Processing Operations Requiring a DPIA

The CNIL also maintains a mandatory list under Article 35(4), adopted through Deliberation No. 2018-327 of October 11, 2018. It names 14 types of processing that require a DPIA outright, including systematic employee monitoring, whistleblowing schemes, profiling that can exclude people from a contract, and large-scale processing of health data. If your processing appears on this list, you can skip the criteria math because the DPIA is mandatory regardless.

Insider Note: The CNIL’s sectoral “referentials” do more work than most DPOs realize. If your processing fully complies with an applicable referential, the CNIL accepts the position that residual risk isn’t high, which takes Article 36 prior consultation off the table. Checking for a referential before scoping a DPIA can remove the most painful step of the entire process.

When CNIL Criteria Don’t Apply: Key Scenarios

Processing Falling Below the Two-Criteria Threshold

Most B2B processing lives here. A standard CRM, a newsletter list, routine supplier management: these might touch one criterion (large scale, perhaps) without hitting a second. No DPIA is required, but the screening itself is a compliance artifact. Record which criteria you tested, what you concluded, and why. If the CNIL inspects, the absence of a DPIA is defensible only when the screening decision is on paper.

Operations on CNIL’s Exemption List

Article 35(5) lets supervisory authorities publish “whitelists” of processing that doesn’t require a DPIA. The CNIL adopted one in 2019 after an EDPB opinion, covering categories such as routine HR management in organizations with fewer than 250 employees (without profiling, biometrics, or sensitive data), badge-based physical access control without biometrics, and time management systems that don’t process biometric data. France is one of only a few member states with a formal whitelist, which matters for cross-border groups: the same HR system can be exempt in France and assessable case by case in Luxembourg.

Processing Authorized by Specific Legal Provisions

Article 35(10) carves out processing based on a legal obligation or public interest task under Article 6(1)(c) or (e), where the legal basis regulates the specific operation and a general impact assessment was already carried out when that law was adopted. It’s a narrow exemption. It doesn’t cover processing that merely relates to a legal obligation; the law itself has to govern the operation in question.

Pre-Existing DPIAs Covering Similar Processing

Article 35(1) allows a single assessment to cover a set of similar processing operations presenting similar high risks. The CNIL confirms that where the nature, scope, context, and purposes of a new operation closely match processing already assessed, whether by you or by a third party such as a public authority or a group of controllers, the earlier DPIA’s results can be reused. Document the similarity analysis rather than just asserting it.

Processing Governed by Other Supervisory Authorities

CNIL lists bind processing under the CNIL’s jurisdiction. A controller whose main establishment sits in Ireland or Germany deals with its own lead supervisory authority under the one-stop-shop mechanism, and each authority publishes its own Article 35(4) list. The nine WP248 criteria still apply everywhere, since the EDPB treats them as the consistency backbone behind every national list, but the national additions and exemptions differ. The ICO’s DPIA guidance, for instance, adds UK-specific triggers such as innovative technology combined with any WP248 criterion.

What to Do When a DPIA Isn’t Triggered: The Risk Assessment Path

Even without a DPIA, three obligations remain.

  • First, conduct the Article 32 risk assessment. Map the data flows, identify realistic threats (unauthorized access, loss, alteration, unavailability), rate likelihood and severity, and select TOMs proportionate to what you find: encryption, pseudonymization, access controls, backup and recovery, and regular testing of those measures. Established methodologies work fine here; ISO/IEC 29134 provides privacy impact assessment guidance, and the NIST Privacy Framework offers a structure many teams pair with their existing security program.
  • Second, document why no DPIA was performed. Organizations skip this step more than any other, and it tends to be the first thing an inspector asks for. A one-page screening record referencing the criteria, the exemption relied on, and the date of the decision is usually enough.
  • Third, keep the accountability machinery running. The processing goes in your Records of Processing Activities (ROPA), privacy by design and by default under Article 25 still applies, and data subject rights are untouched by any DPIA exemption.

Pro Tip: Build DPIA Screening into your ROPA Workflow

Build DPIA screening into your ROPA workflow instead of treating it as a separate exercise. Add three fields to each ROPA entry: criteria met, DPIA yes/no, and rationale. You get a permanent, dated audit trail with almost no extra effort, and periodic reassessment becomes a filter query instead of a project.

Comparing the Two Approaches Side-by-Side

Methodology differs too. DPIAs typically follow the CNIL’s PIA methodology or ISO/IEC 29134 and demand structured stakeholder involvement: the DPO’s advice must be sought, processors have to assist under Article 28, and data subjects’ views should be gathered where appropriate. Article 32 assessments plug into whatever risk framework your security team already uses (ISO 27005, NIST, EBIOS) and can stay internal.

Practical Decision Framework: DPIA or Risk Assessment?

Step 1: Screen against the lists first. Check Article 35(3), then the applicable supervisory authority’s mandatory list. A hit at this stage ends the analysis; the DPIA is required.

Step 2: Check the exemption routes. The whitelist, the Article 35(10) legal-provision exemption, and reusable prior DPIAs. If one applies, record which one and why.

Step 3: Count the criteria. Score the processing against the nine WP248 criteria. Two or more points to a DPIA. Meeting just one deserves a documented judgment call, keeping WP248’s caveat in mind that a single criterion can be enough for genuinely risky processing.

Step 4: Choose the assessment and calendar the review. DPIA if triggered, Article 32 assessment if not. In both cases, set a reassessment trigger: material change to the processing, new data categories, new technology, or three years, whichever comes first.

DPIA vs Risk Assessment

Common Pitfalls When CNIL Criteria Don’t Apply

Assuming No Assessment Is Needed at All

The most common failure. Articles 24 and 32 apply to a two-person newsletter list the same way they apply to a biometric access system, differing only in depth. Concluding that you don’t need a DPIA settles the scoping question and nothing else.

Confusing DPIA Exemption with Compliance Exemption

The CNIL states this explicitly in its whitelist materials, and the EDPB repeats it in every whitelist opinion: exempt processing must still satisfy the Article 5 principles, lawful basis requirements, and data subject rights. If you’re weighing the broader difference between a formal standard and a legal obligation, our breakdown of DPIA exemption versus compliance exemption is worth a read.

Important: An Article 35(5) whitelist entry exempts you from one document. It doesn’t touch lawfulness, minimization, transparency, security, or breach notification. Treating the whitelist as a safe harbor is how routine HR processing ends up in an enforcement decision.

Overlooking Sector-Specific Guidance

EDPB guidelines, CNIL referentials, and codes of conduct under Article 40 can all shift the analysis. Article 35(8) requires compliance with an approved code of conduct to be taken into account when assessing impact. Ignoring the sectoral layer produces screening decisions that look fine on paper but fall apart once the sector context comes in.

You don't need a six-figure budget to be GDPR compliant. You need a clear plan and someone to do the work.

Affordable GDPR Compliance Services

Cross-Jurisdictional Considerations

Controllers established outside France aren’t bound by CNIL lists for processing under another authority’s jurisdiction. What travels is WP248: the EDPB required every national list to state that it complements and further specifies those guidelines, so the nine criteria function as the common denominator across the EU.

EDPB Guidelines 4/2019 on data protection by design and by default add the other half of the frame. Whatever assessment you run, Article 25 requires safeguards to be designed in from the start, not bolted on after the risk analysis.

For multi-jurisdictional processing, two practical rules hold. Identify your lead supervisory authority under the one-stop-shop mechanism, and where a single processing operation spans several member states’ lists, apply the most demanding trigger among them. A DPIA that meets the strictest list will hold up everywhere else, and that logic doesn’t work in reverse.

Worth Knowing: EDPB published a Draft EU-wide DPIA

In April 2026, the EDPB published a draft EU-wide DPIA template and opened a public consultation running to June 2026. It doesn't change when a DPIA is required, but it signals convergence on how DPIAs get documented, and national authorities may adopt it as a standard. It's worth tracking if you maintain DPIA templates across several jurisdictions.

Conclusion: Building a Defensible Assessment Strategy

The CNIL criteria answer one question: does this processing need a DPIA? When they don’t apply, the question changes shape instead of going away. Article 32 still demands a security risk assessment, Article 24 still demands proof of proportionate measures, and the screening decision itself becomes the document that protects you. A defensible strategy is boring by design: screen every new processing operation, record the outcome either way, run the assessment the outcome calls for, and revisit on change or every three years. Controllers get in trouble far more often for having no paper trail than for choosing the lighter assessment.

Frequently Asked Questions

Is a risk assessment mandatory even if no DPIA is required?

Yes. Article 32 obliges every controller and processor to assess risk and implement appropriate technical and organizational measures for all processing of personal data. A DPIA exemption takes one document off your list. The underlying duty stays.

You can. The CNIL’s free PIA tool is built around the DPIA methodology, so it’s heavier than an Article 32 assessment needs, but its risk mapping module works well for structuring a security-focused analysis. Many teams use it for both and skip the necessity and proportionality sections for non-DPIA processing.

Failing to carry out a required DPIA is sanctionable on its own, with fines of up to 10 million euros or 2% of global annual turnover under Article 83(4). Supervisory authorities have also treated missing DPIAs as aggravating factors in broader enforcement. A documented, good-faith screening decision materially improves your position even when a regulator disagrees with the conclusion.

Duration depends on the size of the organization, the complexity of its processes, the number of sites, and the industry risk profile — with audit time calculated under ISO/IEC 17021-1 guidance. A small organization might face a Stage 2 audit of one to two days and shorter surveillance visits, while a large multi-site operation requires considerably more.

An internal audit is conducted by or for the organization itself to check and improve its own EMS. An external audit is conducted by an outside party — either a certification body awarding or maintaining the certificate, or a second party such as a customer assessing a supplier.

Yes, a free template is a reasonable starting point, but treat it as a skeleton. Any generic template must be adapted to your significant environmental aspects, your compliance obligations, and your operations — and as of 2026 it must be updated for the new and revised clauses. An unedited template will leave gaps that produce findings.

You analyze the cause, define corrections and corrective actions, and implement them. Certification bodies typically require this within a set window after the audit and then verify it. Major nonconformities must be closed before a certificate is granted or maintained. Minor nonconformities are usually verified at the next surveillance visit.

Axipro Author

Picture of Pedro Dias

Pedro Dias

Pedro has been writing online for over 10 years. With experience in all things programming, cyber security, and compliance, he is our editor-in-chief at Axipro.

Blog Highlights

Explore More Articles

Enforcement of the EU AI Act’s core rules started on 2 August 2026, and ISO/IEC 42001:2023 is the standard companies reach for when they need to prove their AI governance actually holds up. It’s the first certifiable standard for an Artificial Intelligence Management System (AIMS), and consultancies package help with it in two ways. A gap analysis tells you how far you are from the standard. Full implementation support builds the management system with you until you’re ready for certification. The two engagements differ enormously in cost, duration, and how much of the work the consultant carries, so picking the wrong one is expensive in both directions. Buy implementation when you only needed a roadmap and you pay for work your team could have done themselves. Buy a gap analysis when you have nobody to close the gaps and the report sits in a drawer while your certification deadline slips past. This article covers what each service includes, what each costs, who should pick which, and how the two combine. What Is an ISO 42001 Gap Analysis? A gap analysis is a structured baseline assessment. A consultant reviews your current AI governance practices against the requirements of ISO 42001: the management system clauses (4 through 10) and the Annex A controls, of which there are 38 grouped under nine control objectives. You end up with a clear picture of what already satisfies the standard, what partially satisfies it, and what doesn’t exist at all. The purpose is diagnostic, not corrective. Nobody writes your AI policy during a gap analysis. What you get is a gap report with maturity scoring against each clause and control, a prioritized remediation roadmap, an early view of your likely AIMS scope and Statement of Applicability (SoA), and an estimate of the effort certification will take. Timeframes are short. A standalone ISO 42001 gap analysis usually takes one to three weeks, with a few days of consultant time and a modest internal commitment: stakeholder interviews, access to documentation, and someone who can describe how AI is actually used across the business. Standalone assessments on the market typically run in the low four figures. Axipro bundles one into its free 30-day Compliance Accelerator Plan, so in practice you can get the diagnostic without spending anything. A gap analysis is the right entry point when you already have governance maturity to build on. Companies with an existing ISO 27001 ISMS often find heavy overlap in the management system clauses, since both standards follow the same Plan-Do-Check-Act (PDCA) structure. It also fits when you have internal compliance expertise to execute the roadmap, when budget needs phasing, or when you want an accurate scope before committing to a bigger project. Insider Note: The step that consistently takes longer than anyone expects is the AI system inventory. Most companies walk into a gap analysis confident they know where AI is used, then discover marketing has been running LLM tools on customer data, and engineering has embedded a third-party model nobody scoped. Budget real time for discovery before the control review starts. What Is ISO 42001 Full Implementation Support? Full implementation support is an end-to-end engagement that takes you from your current state to certification readiness. The consultant identifies the gaps, then closes them with you, building the AIMS piece by piece and owning the project through to the external audit. The deliverables list is long. A typical engagement covers the AI policy and governance framework, an AI risk assessment methodology, completed AI risk assessments and AI impact assessments for your in-scope systems, the Statement of Applicability, the applicable Annex A controls put in place (data governance, human oversight, transparency, and so on), the documentation and evidence set an auditor will ask for, staff training, an internal audit, a management review, and corrective action plans for whatever the internal audit surfaces. Most providers, Axipro included, also coordinate directly with the accredited certification body through the Stage 1 and Stage 2 audits. Most organizations need roughly three to six months. It’s shorter where an ISO 27001 ISMS already exists to integrate with, longer for complex or high-risk AI portfolios. Consultant involvement is heavy and sustained, but your team doesn’t disappear from the project. Internal subject-matter experts still make the real decisions about AI use cases, data handling, and acceptable risk. On cost, consultant-led ISO 42001 implementations commonly run well into five figures. Axipro’s ISO 42001 readiness engagement costs $4,500, which is one of the reasons the honest comparison below matters: at that price, the “just buy the gap analysis to save money” logic gets a lot weaker. Full implementation is the right call when you’re starting an AIMS from scratch, when nobody internal can carry the workload, when a certification deadline is fixed by an enterprise deal or regulatory exposure, or when your AI use cases are risky enough that getting the controls wrong has real consequences. The EU AI Act’s requirements for high-risk AI systems entered into application in August 2026, and companies in that category rarely get the luxury of a slow, self-paced build. Key Differences Between the Two Services Scope and depth A gap analysis assesses; implementation support executes. The gap analysis stops at the roadmap, no matter how detailed. Implementation carries every roadmap item through to a working, evidenced control. That distinction sounds obvious, but it’s the single most common source of buyer disappointment: a gap report doesn’t make you certifiable, and some companies find that out only after they’ve scheduled a Stage 1 audit. Consultant involvement and internal effort In a gap analysis, the consultant works in short, concentrated bursts and your team’s effort is measured in hours of interviews and document gathering. In full implementation, the consultant drafts, builds, and project-manages, yet your team still spends real time reviewing policies, making risk decisions, and generating evidence. Any provider promising certification with zero internal effort is describing a paper AIMS that won’t survive an audit or an incident. Cost and time to readiness A gap analysis finishes

The Average Cost of ISO 42001 Consulting

Here are real numbers to anchor on: Axipro delivers ISO 42001 readiness for $4,000 if you’re under 50 employees and $5,500 if you’re over, and the GRC platform plus accredited audit adds roughly $4,000 to $7,000 on top. A mid-sized tech firm lands at around $10,000 to $15,000 all-in for year one. A small team comes in under $10,000. If you’ve been researching this topic, those figures probably look wrong to you. Published cost guides quote $85,000 to $320,000 for mid-market ISO 42001 certification. This article explains the gap: those guides price a traditional consulting-led engagement, where consultants bill day rates to build everything by hand. Automation-supported delivery, where a GRC platform collects the evidence and a fixed-fee team does the thinking, produces a completely different number. We break down both models phase by phase so you can budget against the delivery model you actually intend to buy. What ISO 42001 Consulting Includes for Mid-Sized Tech Firms ISO/IEC 42001 is the first certifiable international standard for an AI Management System (AIMS). Published in December 2023, it applies the familiar ISO management system structure to AI governance: scoped policies, AI risk and impact assessments, Annex A controls, a Statement of Applicability, internal audits, and a two-stage certification audit by an accredited certification body. Scope of Consulting Engagements A typical engagement covers five things: scoping the AIMS and building an AI system inventory, running a gap analysis against the standard, designing and documenting the management system, supporting control rollout, and preparing for the Stage 1 and Stage 2 audits. Under the traditional model, consultants hand-build each phase and bill for the hours. Under the automation-supported model, a fixed-fee readiness package covers the same ground while the platform does the mechanical work. Typical Deliverables from an ISO 42001 Consultant​ Expect a defined AIMS scope statement, an AI system inventory and risk register, AI impact assessments for in-scope systems, a policy and procedure set mapped to Annex A, a Statement of Applicability, training materials, an internal audit report, and audit-day support. If a proposal can’t name its deliverables this concretely, that tells you something about how well the consultant knows the standard. How Mid-Sized Tech Firms Differ from Startups and Enterprises Mid-sized firms sit in an awkward middle. They run more AI systems across more teams than a 15-person startup, so scoping, interviews, and evidence collection all take longer, and fixed-fee providers price them in a higher tier as a result. Unlike enterprises, though, they rarely need multi-site audit sampling or a dedicated AI governance function, so the six-figure quotes written for enterprises don’t apply to them either. Average Cost of ISO 42001 Consulting Typical Price Range for Mid-Sized Tech Firms​ Two delivery models, two price ranges. Automation-supported, fixed-fee delivery: readiness consulting at $4,000 for companies under 50 employees and $5,500 for companies over 50, covering the engagement from gap analysis through certification support. The GRC platform and accredited audit add roughly $4,000 to $5,000, so a mid-sized firm’s first-year total comes to around $10,000 to $12,000. Traditional consulting-led delivery: $25,000 to $80,000 in consulting fees alone for a mid-sized firm, built on day rates of $1,000 to $1,800 across 15 to 40 consultant days. This is the model behind the $85,000-plus totals in most published guides. It still makes sense in a few situations: on-prem infrastructure the platforms can’t see, heavy regulatory overlays, or a board that wants a named Big Four partner on the engagement. The market is young enough that quotes for identical scope can differ by a factor of five. ISO 42001 certificates only started appearing in volume in 2024, and plenty of consultants quoting today have never taken a client through a Stage 2 audit. Insider Note: When a mid-sized firm shows us a $90,000 quote for ISO 42001, the line items usually reveal hand-built work the platform now automates: manual evidence collection, policy drafting from scratch, spreadsheet-based risk registers. What you’re actually paying a consultant for is scoping, impact assessment methodology, and audit judgment. The mechanical work has been commoditized, and pricing that ignores this is pricing from 2023.  Hourly vs Project-Based Consulting Rates Experienced AI governance consultants charge $150 to $300 per hour in the North American and UK markets. Hourly billing works for targeted needs: reviewing an impact assessment methodology, answering auditor questions, validating a control design. For a full implementation it’s a false economy, since open-ended hours remove any incentive to compress the work. Fixed-fee delivery flips that incentive, and that’s a big part of why it prices so much lower. Fixed-Fee vs Retainer Engagement Models Model Typical cost Best for Watch out for Fixed-fee readiness package $4,000 (under 50 employees) / $5,500 (over 50) First certification with defined scope Packages that exclude audit facilitation Traditional fixed-fee project $25,000 to $80,000 Complex scopes, heavy regulatory overlay Paying consulting rates for automatable work Monthly retainer $2,000 to $8,000/month Spreading work over 6 to 12 months Engagements that drift without a certification date Hourly / ad hoc $150 to $300/hour Targeted reviews, audit-day support Costs compounding on open-ended work Fractional AI governance officer $3,000 to $10,000/month Post-certification ownership without a hire Thin coverage if the fractional lead is overloaded Fixed-fee is the right default for a first certification. It moves delivery risk to the provider and forces both sides to agree scope upfront. Fractional arrangements earn their keep after certification, once the work shifts from building the AIMS to running it. Cost Breakdown by Consulting Phase The figures below show what each phase costs when you buy it separately from a traditional consultancy. Inside a fixed-fee package, all five phases sit within the single $4,000 or $5,500 engagement fee, and that’s exactly why the totals diverge so sharply. Readiness and Gap Assessment Fees Standalone price: $2,000 to $15,000, often more than an entire fixed-fee engagement. Either way, this is the highest-value work relative to its cost. The AI system inventory and gap analysis determine everything that follows, including whether you need the rest of the engagement

Global AI regulation is not converging. Four distinct regulatory models have hardened over the past two years: the EU’s single horizontal law, China’s fast-moving sequence of targeted rules, the American patchwork of state laws and voluntary frameworks, and the Gulf’s procurement-driven approach, where the state shapes the market by being its biggest customer. Anyone waiting for these to merge into one global rulebook will be waiting well past 2030. That fragmentation, not any single law, is the defining trend in AI regulatory compliance. The practical question for 2026 through 2028 is no longer “which regulation applies to us” but “which regulatory model does each of our markets follow, and what carries over between them.” This article maps the four models, with extra time on the Gulf version because it gets far less coverage than it deserves. It also argues that ISO standards, led by ISO/IEC 42001, are becoming the only compliance credential that travels across all four. The Four Models of AI Regulation Most trend pieces treat AI regulation as one global movement running at different speeds. It’s more useful to treat it as four philosophies that answer the same question in incompatible ways.   European Union China United States Gulf (KSA, UAE) Instrument One horizontal law (EU AI Act) Sequence of targeted departmental rules State laws, voluntary frameworks, sector rules Data law plus procurement requirements Enforcer Commission, national authorities, notified bodies CAC and partner ministries States, regulators, courts, buyers SDAIA, NDMO, central banks, tender owners Core concern Fundamental rights, product safety Content security, data sovereignty Liability, consumer protection National strategy, data sovereignty, state procurement Speed Slow to write, long lead times Fast, iterative, hardening Uneven, litigation-led Fast: effective when a tender says so What travels Conformity assessment, technical files Filings and labeling rarely reusable Assurance reports, questionnaires ISO certification as procurement signal The European Union: One Law for Everything The EU chose a single horizontal statute, Regulation (EU) 2024/1689, better known as the EU AI Act. It classifies AI systems into risk tiers, bans a short list of practices outright, and attaches heavy obligations to high-risk systems: risk management, data governance, human oversight, technical documentation, and conformity assessment. It applies extraterritorially, so a Bahraini or American provider whose system reaches EU users is in scope. The model’s strength is predictability, and its weakness is pace. Prohibitions have applied since February 2025 and general-purpose AI obligations since August 2025, with Commission enforcement beginning in August 2026. The 2026 digital omnibus agreement then deferred the main high-risk deadlines to December 2027 and August 2028. The EU writes slowly, publishes a timetable, and expects the world to plan around it. China: Regulation One Risk at a Time China has no single AI statute and doesn’t appear to want one yet. Instead, the Cyberspace Administration of China and partner ministries have issued targeted rules in rapid sequence: algorithmic recommendation provisions in 2022, deep synthesis rules in 2023, interim measures for generative AI services the same year, AI content labeling requirements in September 2025, and rules for anthropomorphic AI interaction services that took effect in July 2026. Each rule attacks one risk scenario, takes effect quickly, and gets refined through practice. The direction of travel matters more than any single measure. China’s revised Cybersecurity Law, effective January 2026, wrote AI research, training data, computing infrastructure, and risk monitoring into a foundational statute for the first time. Soft guidance is hardening into binding law, and the organizing logic throughout is content security, data sovereignty, and platform accountability rather than individual rights. For foreign companies, the compliance burden is operational: filings, security assessments, and labeling obligations that arrive with short notice and almost no grace period. The United States: The Market as Regulator The US still has no federal AI statute, and the vacuum is being filled from two directions. States are legislating, with Colorado’s AI Act as the most complete example, and sector regulators are stretching existing consumer protection, employment, and financial rules to cover AI. The NIST AI Risk Management Framework sits underneath as the voluntary vocabulary everyone borrows. In practice, the binding force in America is commercial. Enterprise buyers, insurers, and litigators enforce AI governance through security questionnaires, vendor reviews, and lawsuits long before any statute does. For a company selling into the US, the real regulator is the procurement team of your largest prospect. The Gulf: The State as Customer The Gulf model is the least covered and, for anyone selling into the region, the most misunderstood. Saudi Arabia has no horizontal AI act. It regulates AI through data law and through the state’s position as the dominant buyer in the economy. The Saudi Data and Artificial Intelligence Authority (SDAIA), established in 2019 and reporting directly to the Prime Minister, runs the show: it sets national strategy, publishes the frameworks, and steers what government tenders ask for, a far more hands-on role than most regulators play. The load-bearing rules are the Personal Data Protection Law, enforced since September 2023, and its cross-border transfer regime. Around them sit SDAIA’s AI Ethics Principles, generative AI guidelines for government entities, and the AI Adoption Framework, published in November 2025 as a mandatory baseline for public sector bodies, with a four-tier risk classification and lifecycle auditing for high-impact systems. A draft Responsible AI Policy went through public consultation in May 2026, confirming that a formal, operational regime is coming. The Kingdom designated 2026 its Year of Artificial Intelligence, and the direction across the region matches: the UAE runs an AI Seal program and its central bank requires bias testing at financial institutions, Oman’s National AI Policy entered into force in April 2025, and Bahrain has a proposed AI law in progress. The defining feature is speed through procurement. A requirement in a Saudi government tender takes effect the day the tender document is published, with no transition period and no parliamentary debate. High-risk use cases increasingly require self-assessments before tenders or go-lives. Regulation by purchase order moves faster than regulation by statute, and in state-led