We have always treated compliance like a fence. You are either inside the yard dealing with the regulators, or you are outside building software and letting your clients worry about the rules.
That fence is falling down.
If you look at the major shifts happening right now across UK financial regulation, EU privacy courts, and the United Nations, a very clear pattern emerges. The regulatory perimeter is expanding, and legal responsibility is bleeding outward into vendor dependencies and global data routes.
Here is why risk models need a serious update.
The Vendor Blind Spot
Look at what is happening in the UK. The FCA recently backed the Mills Review, and the findings point straight at a massive gap in how we handle unregulated AI vendors. The review anticipates that by 2030, consumers will navigate their finances almost entirely through AI agents.
The problem is that the developers building these AI tools often sit completely outside traditional financial oversight. If an unregulated AI model determines a customer's risk profile or creates hyper-personalized pricing, who takes the fall when the model hallucinates or discriminates?
Right now, human accountability is the only anchor. Regulated banks and financial institutions are on the hook for the consumer harm created by their tech vendors. But you can bet those institutions will push that liability right back onto the AI builders through brutal contracts and compliance audits. If you build AI tools for regulated industries, you are being pulled into the regulatory net through dependency. You can no longer just say "we only sell software."
Surviving the Courtroom
This shifting perimeter also changes how we have to prove compliance. The Irish High Court’s recent ruling on TikTok’s data transfers is a perfect example.
The court upheld a massive €530 million fine regarding how TikTok handled data transfers to China. The judges made it explicitly clear that relying on Standard Contractual Clauses as a paper shield will not save you anymore. Companies have to actually prove their risk assessments can survive a legal fight.
But there is a twist. The court also ordered the data regulator to reconsider their outright ban on those data transfers because the regulator ignored an expert opinion provided by TikTok. This shows that data-transfer law is no longer just about where the servers are located. It is about procedural fairness and the weight of your evidence. Your compliance strategy is only as strong as your ability to defend it on appeal.
Digital Diplomacy at the UN
While national courts fight over the details, the actual rulebook is being rewritten globally. The UN just kicked off its first Global Dialogue on AI Governance in Geneva.
For the last couple of years, the tech world has just watched what the EU and the US were drafting. That dynamic is finally changing. For those of us building legal tech in India and the broader Global South, this is a critical shift. AI governance is turning into digital diplomacy. It is a negotiation over infrastructure, compute access, and safety standards. The countries and organizations that get a seat at this table will dictate the rules for everyone else.
The days of simple check-the-box compliance are gone. If your code shapes a regulated decision, trains on international data, or touches global infrastructure, you are already inside the perimeter. It is time to stop asking if we are regulated and start mapping out exactly where our hidden liabilities are.
