Apple recently made headlines for collaborating with Alibaba on its own large language model (LLM) for the Chinese market. The move makes Apple the first foreign company Beijing has cleared to deploy its proprietary AI model inside China. Crucially, Apple tailor-made this LLM for China.
Seventy-two countries now have AI policies, and all 50 U.S. states have introduced AI legislation, according to Responsible AI Labs. Many of those policies are at odds with each other. This type of regulatory divergence will become increasingly severe as more countries and regions release their own AI guidelines.
Chief information officers (CIOs) managing multiregional deployments must address architectural questions:
- Are we planning for a future where we need fundamentally different AI products for different regulatory theaters?
- Will fragmentation cause a production crisis?
Apple had a decade of cash, a captive audience of 1 billion devices, and 18 months of lead time. Yet the organization still had to scramble to deploy a tailor-made LLM for the Chinese market. Why? The regulatory landscape is to blame.
On the one hand, the EU AI Act requires organizations to disclose how high-risk AI systems were trained. These systems must be subject to human override at key decision points.
On the other hand, China's framework requires that certain content decisions follow state-mandated policy regardless of what a human overseer wants. This content must be preapproved before it can be released.
An AI deployer cannot honor both mandates—"the human can override this" and "the human cannot override state content requirements"—for the same output.
China's preapproval requirement isn't a public audit. What gets flagged, adjusted, or excluded during review isn't typically disclosed to the public. That policy differs from the EU's documentation requirement, which calls for the LLM training process to be made auditable.
This should ring alarm bells for CIOs. Even with its massive store of resources, Apple could not build a product to satisfy both sets of requirements.
Most businesses aren't governing the AI they've already deployed inside one set of rules.
The ServiceNow Enterprise AI Maturity Index 2026, based on a survey of roughly 4,500 executives across 19 countries, put the average AI maturity score at 51 out of 100. But of seven pillars measured, AI-enabled workflows, the one assessing whether AI runs inside a governed process, scored just 40.
More than half (59%) of organizations use agentic AI tools. However, these same organizations are failing to build AI testing, auditing, and risk assessment into their workflows, according to our research.
Contradictory governance requirements will only make the situation worse. A business that can't reliably supervise one agentic workflow under one rulebook has little chance of maintaining three or four versions of that workflow, each one governed to a different standard.
The EU’s General Data Protection Regulation (GDPR) forced a similar fork in 2018. And California's privacy law followed two years later. Companies added consent layers and regional flags rather than building separate products.
Those earlier laws only controlled how a product could be used; they didn't dictate what the product had to be. AI regulations do. A weaker encryption key is still the same basic tool, just a limited version of it.
An AI model that doesn’t allow a human to override it isn’t a limited version of the same system; it’s a different system entirely. That's why this kind of fragmentation can't be added on after the fact. It has to be part of the design from the start.
With that in mind, here’s what CIOs should do to adapt:
- Stop waiting for the rules to converge. Instead, map which AI systems count as high risk under each jurisdiction you operate in. The EU AI Act's obligations are triggered by use case, not intent. A model screening resumes or flagging claims fraud can trigger disclosure and override requirements even if nobody built it thinking of it as "regulated."
- Pick an architecture before enforcement picks one for you. Build modularly so that training data, override logic, and content policy sit apart from the core model. Or concentrate on the handful of jurisdictions that matter most, and build fully separate products for each, the way Apple did for China.
- Fold legal review into engineering from the first training run, not after launch. And start budgeting for a second build now, for whichever market carries the most exposure.
None of these steps is easy or cheap, but doing them now will be far more efficient than doing them twice.
Find out how ServiceNow can help you enforce runtime governance for AI at scale.