INNOVAREModule 4 · Applied

Case 5: Rules Nobody Has Written Yet

Regulation cannot keep pace with AI. What governs AI behaviour in the gap between what the technology can do and what the law says it must not?

July 2026 · Case 5 of 6
As you read — hold this question

If regulations differ by jurisdiction, change frequently, and cannot keep pace with AI development — what does "compliance" actually mean for an organisation deploying AI globally?

#2 barrier
in the Russell Reynolds H2 2023 Global Leadership Monitor survey (N=1,287 CEOs and board directors): Governance, Compliance, and Legal — second only to knowledge and expertise.

The arrival of ChatGPT and generative AI brought regulatory compliance from a specialist concern to a front-page business issue. Suddenly, every organisation deploying AI had to contend with data regulations that vary across jurisdictions, governance frameworks that are still being written, and legal exposure that no one had fully mapped. The challenge is structural: AI capability advances in months; regulation advances in years. The gap between what AI can do and what the law clearly governs is not a temporary inconvenience — it is a permanent feature of the current period, and organisations that wait for the gap to close before adopting will simply fall behind. The question is not whether to proceed in regulatory uncertainty, but how.

Regulatory and market challenges
Quiz: Regulation / Market

Two external challenge domains that organisations cannot control — only navigate

Regulatory Challenges

Data regulations vary across jurisdictions. A global organisation collecting data from users in multiple countries must comply with frameworks that contradict each other. Regulations change frequently, and the compliance posture that was correct last quarter may need revision. No complete international standardisation of AI governance exists. Trust in AI requires a clear regulatory framework — but governments cannot create frameworks faster than the technology is advancing. This creates an urgent need for inclusive dialogue and internal governance that does not wait for external regulation.

Market Challenges

Competitive pressure drives premature AI adoption — organisations deploy before they are ready because they fear falling behind. AI platform vendors are primarily focused on model innovation rather than enterprise adoption support, which means the guidance organisations need most is often the guidance vendors are least equipped to provide. Market uncertainty about which AI tools will win long-term creates a platform risk that is difficult to manage: organisations that commit too early to one ecosystem may find themselves locked into a technology that the market has moved past.

What regulation lag actually means

The structural gap between AI capability and AI governance

Regulation lag is not a bug in the regulatory process — it is structural. Legislatures require evidence, consultation, and time. AI development requires neither. The gap produces a period in which organisations make consequential decisions — about bias, privacy, liability, and accountability — without external standards to measure against.

Regulatory pressure The challenge The internal response
Jurisdictional inconsistency Data protection laws differ across countries and even states. A deployment compliant in one market may breach regulations in another. Organisation must either build market-specific compliance architectures or constrain AI to the most restrictive applicable standard globally
Frequent change Compliance posture is not a one-time project — it requires ongoing legal and regulatory monitoring as standards evolve Dedicated regulatory intelligence function; legal team must be AI-literate, not just AI-cautious
Incomplete standardisation No global AI governance framework exists. The EU AI Act is the most comprehensive attempt; other jurisdictions vary widely. Internal AI policy and governance frameworks must fill the gap — organisations cannot outsource this to regulators who haven't caught up
Trust deficit Trust in AI cannot be built without a clear framework to govern it. Without trust, adoption fails regardless of capability. Transparency-by-design: organisations must proactively disclose AI use, bias testing, and decision accountability even when not legally required to do so
The CEO view — top barriers to GenAI implementation

What 1,287 leaders said was hardest about AI adoption

The Russell Reynolds H2 2023 Global Leadership Monitor surveyed CEOs, C-level executives, next-generation leaders, and board directors (N=1,287) on the top barriers to implementing generative AI. The regulatory dimension appears multiple times in the top five — as a standalone concern and embedded in data security.

  1. #1
    Knowledge and Expertise — leaders do not have enough internal understanding of AI to make confident strategic decisions about it
  2. #2
    Governance, Compliance, and Legal — regulatory uncertainty, internal governance gaps, and legal liability exposure
  3. #3
    Data Security and Privacy — protecting sensitive data in AI systems; regulatory compliance around data use
  4. #4
    Integration with Existing Systems — technical and operational complexity of connecting AI to current infrastructure
  5. #5
    Technical Skills — scarcity of people who can design, build, and maintain AI systems within the organisation
The Trust Argument
Regulation is ultimately about trust. Organisations that cannot demonstrate how their AI makes decisions, what data it uses, and how bias is tested and addressed, will face a trust deficit with customers, employees, and regulators — regardless of whether a specific regulation requires disclosure. The organisations navigating this best are not waiting for regulation to force them into transparency. They are building transparency-by-design, establishing governance frameworks before external pressure demands it, and treating ethical AI as a competitive advantage rather than a compliance obligation.
Take this away

Regulation cannot keep pace with AI. That gap is not closing soon. Organisations that build internal AI governance frameworks — covering bias, privacy, accountability, and transparency — before external regulation requires it are better positioned than those that treat compliance as a destination rather than an ongoing practice. Governance, compliance, and legal is the #2 barrier to GenAI adoption for global CEOs. It is not a side issue.

Quick recall — without looking back

Test yourself on this case

Question 1 of 3

What is "regulation lag" — and why is it a structural feature of the current AI environment rather than a temporary gap that will close?

Regulation lag is the gap between what AI technology can do and what law clearly governs. It is structural because legislative processes require evidence, consultation, and time — AI development requires none of these. Legislatures produce frameworks in years; foundation AI models now advance in months. The gap will not close by the time the next model generation arrives. This means organisations are making consequential decisions — about bias, privacy, liability, and accountability — without external standards to measure against. The appropriate response is not to wait for regulation but to build internal governance frameworks that fill the gap proactively.
Question 2 of 3

Name the top five barriers to implementing generative AI identified in the Russell Reynolds H2 2023 Global Leadership Monitor (N=1,287) — in order.

1. Knowledge and Expertise — insufficient internal understanding to make confident AI strategy decisions. 2. Governance, Compliance, and Legal — regulatory uncertainty, governance gaps, legal liability exposure. 3. Data Security and Privacy — protecting sensitive data; regulatory compliance around data use. 4. Integration with Existing Systems — technical and operational complexity of connecting AI to current infrastructure. 5. Technical Skills — scarcity of people capable of designing, building, and maintaining AI systems internally.
Question 3 of 3

Why do jurisdictional differences in data regulation create a specific challenge for global AI deployments — and what are two internal responses an organisation can take?

Jurisdictional differences mean that data practices that are compliant in one market may breach regulations in another. A global AI deployment collects and processes data from users across multiple legal environments simultaneously, and no single compliance posture satisfies all requirements at once. The challenge is compounded by frequent regulatory change — compliance is an ongoing function, not a one-time project. Two internal responses: (1) Build market-specific compliance architectures that apply the most restrictive applicable standard globally, treating this as a foundation decision rather than an afterthought; (2) Establish a dedicated regulatory intelligence function and ensure the legal team is AI-literate (not just AI-cautious), so the organisation can monitor and respond to regulatory changes as they occur rather than discovering non-compliance after the fact.

Module 4 Video

Module 4 · Video Walkthrough

Sources

Russell Reynolds
Russell Reynolds Associates (2023). H2 2023 Global Leadership Monitor. N = 1,287 CEOs, C-level executives, next-generation leaders, and board directors.
Module slides
BUSN9049 Module 4 — Challenges in AI Implementation. Flinders University, 2026.
Module transcript
BUSN9049 Module 5 Part 1 — Example of ethical and legal issues. Flinders University, 2026.
European Commission
European Commission (2024). EU Artificial Intelligence Act. Regulation (EU) 2024/1689.