Legal Insights & Current Topics

How can International Companies organise AI in a compliant way within a group?

Artificial intelligence has become part of everyday business operations. Employees use AI for writing, analysis or software development, sometimes with official approval and sometimes in an uncontrolled manner as “shadow IT”. At the same time, AI systems are evolving from supporting tools into “agents” that independently pursue objectives and cover entire business processes.

Therefore, AI has long since ceased to be purely an IT matter. Incorrect output, data leakage, the processing of personal data and autonomous actions raise new questions of liability and governance. In an international context, there is the additional challenge that a centrally developed or procured system may be subject to different rules depending on the country in which it is used.

The EU AI Act as a north star, but not as a global uniform solution

As a product safety and regulatory law, the EU AI Act establishes a comprehensive, risk-based standard. As one of the first AI laws, it addressed issues such as risk classification, data quality, documentation, transparency, human oversight and technical security. For this reason, many companies already use it as a reference framework for group-wide AI governance.

However, this does not resolve the international compliance problem. More and more countries are introducing their own AI laws, guidelines or sector-specific requirements. These often address similar fundamental questions but differ in terms of their scope, risk categories and obligations. They may, for example, impose additional transparency or registration obligations, require local representatives or introduce requirements concerning domestic data processing.

This creates additional complexity for corporate groups. An AI system should be operated as standardized as possible while still complying with different local requirements. Setting up a separate compliance project for every new law is neither efficient nor scalable.

Thailand as an Example of Regulatory Diversity

Thailand demonstrates how national regulations can adopt international models while also setting their own priorities. The draft Thai AI law published in July 2026 also follows a risk-based approach. It provides, among other things, for prohibited applications, high-risk systems and systems subject to special transparency obligations. The draft is also intended to cover systems developed or operated outside Thailand where they affect persons in Thailand.

In addition to risk management, documentation and human oversight, the draft contains potential local particularities. These include the appointment of a local coordinator or representative, disclosure obligations for AI-generated content, data localisation and mandatory contractual requirements for services provided to public authorities or critical infrastructure. The envisaged enforcement measures include not only fines, but also the suspension, recall or blocking of an AI system.

This example illustrates the core problem: a Swiss company may use the same AI system in Switzerland, the European Union and Thailand. The technical application remains largely identical, and the legal requirements are somewhat similar, but not exactly the same.

Group-Wide AI Governance as a Base Layer

The answer to this regulatory diversity is robust, group-wide AI governance. It forms a common base layer with binding minimum standards. Local requirements are then added on top as an additional regulatory layer.

The base layer determines how AI systems are recorded, classified, procured, approved, monitored and taken out of operation across the corporate group. Clear responsibilities must also be defined between executive management, IT, data protection, legal, compliance and the relevant business departments.

Whenever a new national law is introduced, the company assesses which existing controls are already sufficient and which local additions are necessary. Group-wide governance therefore does not replace local legal review. However, it prevents the company from having to start from zero whenever a new regulation is introduced.

Proven IT processes as the starting point

The path towards AI compliance does not begin in a vacuum. It builds on existing IT compliance. At its core, every AI system is software that runs on technical infrastructure, processes data and accesses other systems. Consequently, the same basic review mechanisms that apply when introducing conventional software continue to apply initially.

Companies that already have established processes for software procurement, information security, access management and data governance can use these as a foundation and supplement them specifically with AI-related requirements. Where such a foundation is missing or has only been inadequately documented, this groundwork must first be completed.

The new and more complex legal questions raised by AI cannot be answered reliably if it is already unclear where the data is stored, who is permitted to access it or what risks the software in use creates.

Therefore, the basic assessment continues to examine the traditional IT layers:

  • Infrastructure: Where are the AI system and the data operated? Are cloud services or the company’s own data centre capacity being used? In which countries are the systems located, and which providers or group companies are given access?
  • Data and databases: What are the quality, origin and legal basis of the processed data? For which purposes may the data be used? In the case of AI, the additional question arises as to whether data is used for training, fine-tuning or improving a model.
  • Software and applications: What legal and security-related risks does the solution pose? Is it a SaaS or an on-premises solution? Which access rights does the system receive, and which data may it retrieve, modify or pass on?

Only once these layers have been properly reviewed and documented does the actual AI compliance assessment begin. The existing IT assessment is therefore not replaced. AI compliance is added on top as an additional assessment layer.

AI Compliance

The new AI layer sits on top of the IT foundation. It introduces two new dimensions in particular.

First, AI generates new and sometimes unpredictable information. For example, where a human resources department uses AI to pre-select job applications, the system generates a recommendation. It must then be assessed whether an automatic rejection based on that recommendation violates employment law or data protection requirements. Furthermore, it must be assessed whether the system can be influenced by prompt injection, unsuitable data or algorithmic bias.

Second, the autonomy of these systems is increasing. AI no longer merely generates information but may, as act as an “agent” and independently intervene in business processes.

AI agents act autonomously and create a new liability risk. Unlike a mere tool, they can carry out legally relevant actions that may be attributed to the company. A human is no longer positioned between the system and the outside world at every step. This, in turn, requires additional rules.

As a practical example, an autonomous purchasing agent could manage a company’s inventory. Because AI agents make decisions independently, they require clear technical and organisational guardrails.

The agent could, for example, be permitted to place orders only with pre-approved suppliers and for approved products. A defined budget threshold could also be set, with manual approval required for any amount above it. This would not completely eliminate errors, but it would limit the potential damage.

In an international context, it must additionally be clarified whether the agent may be granted the same powers everywhere, which group company is acting in legal terms and whether local rules require stricter controls.

The dynamic nature of AI turns Compliance into an ongoing process 

The greatest challenge does not lie in the initial assessment, but in operationalising a compliance approach that has previously been relatively static. Models are updated, system prompts are modified, new data sources are connected and functions are expanded. Thus, initial assessments can quickly become outdated. The AI may suddenly do more than the original assessment covered.

This problem becomes more acute in international corporate groups. A centrally rolled-out change can affect several group companies and jurisdictions at the same time. A new function may result in the system being newly classified as a high-risk system under local law or may trigger additional transparency, registration or reporting obligations in some other jurisdictions.

This requires new compliance processes. Similar to employee policies, clear boundaries must be set for the system. Unlike in the past, however, the compliance department cannot simply issue a policy in PDF format. The rules must be technically translated and integrated directly into the system through automated guardrails or compliance as code. Manual monitoring alone cannot keep pace with this level of complexity and change.

Such technical guardrails can block prohibited inputs, prevent access to confidential data, restrict transactions, enforce financial thresholds or require human approval. The group-wide base layer should define these controls as uniformly as possible. Local group companies can supplement them where national law imposes stricter requirements. 

Continuous monitoring is also required. Not every minor adjustment can be reviewed manually. Automated alerts should be triggered in the event of anomalies, budget overruns, blocked prompts or unusual access. Without proactive monitoring of the system architecture and its guardrails, there is a risk of a gradual breach of legal requirements.

Conclusion: Active Monitoring as a Strategic Advantage

The legally compliant and internationally scalable use of AI is not a one-off project, but the result of a structured and continuous process. It is based on established software, data and IT compliance, supplemented by an AI-specific assessment layer.

The EU AI Act can serve as a reference framework for this purpose. However, as more and more countries introduce their own regulations, relying exclusively on a single legal framework is not sufficient. Companies require group-wide AI governance as a stable base layer onto which local requirements can be added in a targeted manner.

The decisive factor is the ability to manage the dynamic nature of AI software. Companies must move from a static project mentality to a dynamic monitoring process. In this way, they create the conditions for robust and trustworthy AI applications, can adapt more efficiently to new national regulations and turn the fulfilment of regulatory obligations into a strategic competitive advantage.