← All Field NotesThe Geopolitical Blind Spot in AI Inventories: Why Use Case, Not Model Name, Decides Regulatory Exposure

Field Notes

The Geopolitical Blind Spot in AI Inventories: Why Use Case, Not Model Name, Decides Regulatory Exposure

Shekhar Attri

Shekhar Attri

Co-Founder & CTO

·July 19, 2026·Updated August 23, 2026
Share via Email

TL;DR: AI regulatory exposure turns on what a deployment does, not which model powers it. The EU, Colorado, and China classify identical technology under different tests, so the same deployment can be unregulated, high-risk, or subject to mandatory labeling depending only on jurisdiction and use case.

Key takeaways:

  • The Council of the European Union delayed the AI Act's standalone high-risk obligations from August 2, 2026 to December 2, 2027, in a decision finalized June 29, 2026.
  • New York City's labor department flagged one of thirty-two companies reviewed for hiring-algorithm violations; auditors working the same files found seventeen, per a December 2, 2025 Comptroller audit.
  • Colorado's AI Act effective date moved from February 1 to June 30, 2026, after a special legislative session on algorithmic discrimination reform collapsed in August 2025.
  • China's AI content-labeling rules, effective September 1, 2025, apply based on whether a service carries "public opinion attributes," not on model identity.

The Council of the European Union delayed the AI Act's standalone high-risk obligations on June 29, 2026.¹ Seven months earlier, a New York State Comptroller audit exposed how loosely the city enforced its own hiring-algorithm law.² Neither event involved a model ban. Both turned on how one deployment was classified once it touched a real applicant in a real jurisdiction, an axis most corporate AI registers still do not track.

The Council of the European Union signed off on a delay June 29, 2026, pushing the AI Act's standalone high-risk obligations from August 2, 2026 to December 2, 2027, a deferral that applies to a category of use case, not to any named vendor or model.
The Council of the European Union signed off on a delay June 29, 2026, pushing the AI Act's standalone high-risk obligations from August 2, 2026 to December 2, 2027, a deferral that applies to a category of use case, not to any named vendor or model.

The Geostrategic Gap Between Vendor Lists and Regulatory Reality

Enterprise AI inventories built over the last three years capture vendor name, model version, license terms and cost center. That register answers procurement and security questions, but not what regulators now ask: what a deployment does, to whom, in which jurisdiction, under which legal tier. Calling "AI regulation" one line item hides that a general-purpose model can be unregulated in a customer-support workflow and high-risk the moment the same weights sit behind a hiring filter. That gap is a geopolitical risk exposure indistinguishable from a sanctions or export-control blind spot: it depends on which government's use-case test applies.

  • Same model, different tier. The EU AI Act's Annex III lists specific functions as high-risk, including "recruitment or selection of natural persons," creditworthiness evaluation, and biometric categorisation, regardless of which model powers them.³ A model absent from that list in one workflow can appear in it for another inside the same company.
  • Delays apply to categories, not vendors. The Council's December 2027 deferral covers standalone high-risk systems as a class; embedded high-risk systems inside regulated products get until August 2, 2028.¹ Colorado's SB 24-205 saw a parallel postponement to June 30, 2026, after a special legislative session on algorithmic discrimination reform collapsed.⁴
  • Enforcement targets the affected population, not the procurement record. The Comptroller's review of Local Law 144, covering July 2023 through June 2025, found the city agency never consulted its own technology office on automated-decision determinations and could not spot non-compliance unless an employer posted a bias audit.²
  • Jurisdictions diverge on what triggers scrutiny. China's generative AI rules key obligations to whether a service carries "public opinion attributes," a different test from the EU's individual-rights framework or Colorado's consequential-decision standard.⁵
A New York State Comptroller audit published December 2, 2025 found the city's own labor department had flagged just one of thirty-two companies reviewed for hiring-algorithm violations, while auditors working from the same files identified seventeen.
A New York State Comptroller audit published December 2, 2025 found the city's own labor department had flagged just one of thirty-two companies reviewed for hiring-algorithm violations, while auditors working from the same files identified seventeen.

The Geostrategic Logic Behind Divergent Classification Regimes

Three governments sort the same technology through three different mechanisms, each built on its own governing anxiety. The EU's Annex III sorts by function against an enumerated list: employment, credit, biometric identification, healthcare eligibility, law enforcement risk assessment.³ A model is high-risk because of what it decides, not what it is built from, so the same GPT-class deployment can sit in two tiers inside one firm depending on whether it screens résumés or drafts marketing copy.

Colorado's statute sorts by outcome category, what it calls "consequential decisions": employment, housing, credit, healthcare and legal services, with duties of reasonable care assigned to developers and deployers alike. Its twice-delayed effective date, now June 30, 2026, signals that the fight in Denver is over how tightly liability attaches to the deployer, not whether AI gets regulated at all.⁴

China sorts differently again, by whether a system can shape public opinion or mobilize social behavior, pulling recommendation algorithms and generative content services into registration and labeling duties unrelated to employment or credit decisions.⁵ A multinational running the same foundation model across three markets faces three separate sorting logics, and none can be resolved by looking at a contract number.

Colorado's Consumer Protections for Artificial Intelligence Act saw its effective date postponed twice, from February 1 to June 30, 2026, after a special legislative session on algorithmic discrimination reform collapsed in August 2025.
Colorado's Consumer Protections for Artificial Intelligence Act saw its effective date postponed twice, from February 1 to June 30, 2026, after a special legislative session on algorithmic discrimination reform collapsed in August 2025.

The Geostrategic Fix: Map the Chain, Not the Catalog

A vendor-and-model catalog cannot answer "are we exposed" because exposure depends on eight linked variables that shift independently of the underlying technology. The chain that does answer it: model, use case, data type processed, affected population, jurisdiction of deployment, regulatory classification under that jurisdiction's test, effective date of the applicable obligation, and the named accountable owner inside the business.

  • Model to use case. Record every distinct workflow a model touches; one model can generate multiple entries.
  • Use case to data type. Note whether the workflow processes biometric, employment, credit or health data, since that determines which country's high-risk list applies.
  • Data type to affected population. Job applicants, credit applicants and patients trigger different statutory duties even under the same model.
  • Population to jurisdiction and classification. The same use case can be prohibited in one state, high-risk with audit duties in a second, and unregulated in a third.
  • Classification to effective date and owner. Each classification carries its own compliance clock, Colorado's June 30, 2026 and the EU's December 2, 2027 among them, and each needs a named owner, not a shared legal distribution list.

The register that survives an audit is built around that chain, reviewed per use case against legislative and regulator status, not the one that lists "ChatGPT enterprise license" once and calls the inventory complete.

Fortius Intel note: Boards asking "which AI tools do we use" are asking the wrong question. The register that matters tracks which use cases touch a regulated population in a regulated jurisdiction, and which named executive owns the date on that calendar.

Methodology: Analysis draws on the Council of the European Union's June 29, 2026 press release on the AI Act omnibus, the New York State Comptroller's December 2, 2025 audit of Local Law 144 enforcement, EU AI Act Annex III text, Clark Hill's August 28, 2025 client alert on Colorado's SB 24-205 delay, and White & Case's AI Watch tracker on China's generative AI rules. All cited sources are publicly available.


Footnotes

1 Council of the European Union, "Artificial intelligence: Council gives final green light to simplify and streamline rules," Press release, 29 June 2026. High-risk AI system obligations for standalone systems deferred from 2 August 2026 to 2 December 2027; obligations for high-risk AI systems embedded in regulated products deferred to 2 August 2028. Available at https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/

2 Office of the New York State Comptroller, "Enforcement of Local Law 144, Automated Employment Decision Tools," Report 2024-N-6, 2 December 2025. Audit of the NYC Department of Consumer and Worker Protection covering July 2023 through June 2025 found DCWP flagged one non-compliance issue among 32 companies reviewed, while auditors identified at least 17 instances of potential non-compliance in the same files. Available at https://www.osc.ny.gov/state-agencies/audits/2025/12/02/enforcement-local-law-144-automated-employment-decision-tools

3 EU Artificial Intelligence Act, "Annex III: High-Risk AI Systems Referred to in Article 6(2)," Regulation (EU) 2024/1689. Lists recruitment and candidate selection, evaluation of creditworthiness, and biometric categorisation among high-risk use cases irrespective of the underlying model. Available at https://artificialintelligenceact.eu/annex/3/

4 Clark Hill PLC, "Colorado's AI law delayed until June 2026: What the latest setback means for businesses," 28 August 2025. Colorado's Consumer Protections for Artificial Intelligence Act (SB 24-205) effective date postponed from 1 February 2026 to 30 June 2026 after a special legislative session failed to produce compromise amendments. Available at https://www.clarkhill.com/news-events/news/colorados-ai-law-delayed-until-june-2026-what-the-latest-setback-means-for-businesses/

5 White & Case LLP, "AI Watch: Global regulatory tracker - China." China's AI-Generated Content Labeling Rules took effect 1 September 2025, requiring explicit and implicit labeling of generative AI outputs, building on the Interim Measures for the Management of Generative AI Services effective 15 August 2023. Available at https://www.whitecase.com/insight-our-thinking/ai-watch-global-regulatory-tracker-china

6 EU Artificial Intelligence Act, "Implementation Timeline." Prohibitions on certain AI practices and AI literacy requirements applied from 2 February 2025; general-purpose AI model obligations and governance requirements applied from 2 August 2025. Available at https://artificialintelligenceact.eu/implementation-timeline/

Run Free Scan

About the author

Shekhar Attri, Co-Founder & CTO. An Indian Army Special Forces veteran with 21 years of service and a gallantry medal, Shekhar's corporate security advisory work spans Singapore, India, the Philippines, and the UAE, alongside PhD research on machine intelligence under incomplete information.