Global AI Assurance · Jurisdiction engine
Jurisdictional Intersection Engine
Sovereignty is not where the server sits. The wrong question is which country's law applies. The right question is which combination of jurisdictions, laws and regulatory obligations applies to this specific AI activity.
A global group does not become subject to its parent's regime because the parent owns the platform. Each entity, each user population, each data class and each transaction brings its own regime, and they have to be resolved together.
Published as reference architecture. Control weights, grading rubrics and the full control set are set per engagement.
Foundational rule
Cabier does not determine jurisdiction solely from where an AI model, server or company is located. It determines applicable requirements from the combined relationship between entity, activity, data, user, model, infrastructure, transaction, jurisdiction, sector and consequence.
Where regimes overlap
Where multiple jurisdictions apply, Cabier identifies cumulative obligations, conflicts, higher standards, localisation requirements and sovereignty constraints before determining whether an AI system or model may operate.
Sixteen inputs per activity
This is deliberately not a country selector. A selector would give the wrong answer for every transnational group.
Where is it developed?
Development location carries export, ownership and provenance consequences that survive deployment.
Where is it hosted?
Hosting sets the first set of compulsion and access exposures, but it does not settle the question.
Where is inference performed?
Inference is where the data actually moves; it is frequently not where the contract says the service sits.
Where does the data originate?
Origin fixes the transfer analysis and often the lawful basis.
Where is the data stored?
Storage drives residency and localisation duties independently of processing.
Who owns the data?
Ownership determines who can consent, who can be compelled, and who must be notified.
Where is the user?
Many regimes follow the person, not the provider. This is the input most often omitted.
Which legal entity operates it?
The operating entity carries the licence conditions and the supervisory relationship.
Which entity is responsible?
Operating and responsible entities are frequently different, and only one of them is accountable to the board.
Where is the customer?
Customer location triggers consumer, conduct and disclosure duties that the entity's own jurisdiction does not.
What sector is involved?
Sector regulation usually imposes the higher standard, above general AI or privacy law.
Which jurisdictions' laws apply?
The output of the first eleven inputs, not an assumption made at the start.
Are there cross-border restrictions?
Transfer, onward transfer and remote-access restrictions each behave differently.
Are there localisation requirements?
Localisation can bind data, processing, human approval and evidence separately.
Are there foreign access or government compulsion risks?
Lawful access by another state is a control question, not a contractual one.
What sovereignty level is required?
The requirement is set by the workload and the classification, then tested against what the model can offer.
Permitted
The activity operates under the applicable regimes with the standing control set.
Permitted with conditions
Named additional controls, approvals or restrictions must be in place and evidenced before use.
Sovereign deployment required
The workload may proceed only where compute, inference, data and evidence remain within the required jurisdiction.
Restricted
Permitted for a narrower purpose, data class or user population than requested.
Prohibited
No configuration available to the institution satisfies the applicable requirements.
The transnational overlay
An entity tree, then eight lenses laid across it. Illustrative group; the structure holds wherever home and host supervisors both have standing.
Group parent
Holding company; owns the global AI platform and central inference capacity
Supervisors
Home prudential supervisor · Home markets regulator
AI posture
Centralised AI platform, three model providers, one shared evidence vault
Canadian subsidiary
Regulated deposit taking and advisory
Supervisors
Federal prudential supervisor · Federal and provincial privacy authorities
AI posture
Consumes central platform; local model validation required
Conflict
Evidence for validated models is currently held outside the jurisdiction.
UK subsidiary
Investment services
Supervisors
Conduct regulator · Prudential regulator
AI posture
Consumes central platform; senior-manager accountability mapped per AI use
EU operations
Licensed entity plus branch network
Supervisors
National competent authority · Data protection authority
AI posture
High-risk uses declared; local documentation and oversight set
Conflict
Central inference path crosses the border for two high-risk uses.
Japan operations
Branch, corporate clients
Supervisors
Financial supervisor · Privacy authority
AI posture
Local approval required for automated decisions
Conflict
Approving person currently sits outside the jurisdiction.
Singapore operations
Regional hub and treasury
Supervisors
Financial supervisor
AI posture
Regional inference permitted; evidence retention set to the longest applicable period
Data jurisdiction
Where the data originated, is stored, and may be transferred.
Customer jurisdiction
Consumer, conduct and disclosure duties following the customer.
Employee jurisdiction
Worker monitoring, consultation and employment duties where AI touches staff.
Model jurisdiction
Provider ownership, development location and contractual restrictions.
Hosting jurisdiction
Infrastructure, subprocessors and lawful-access exposure.
Transaction jurisdiction
Where the economic act lands, including settlement and booking.
Regulatory jurisdiction
Which supervisors hold standing over the activity, home and host.
Sector jurisdiction
The sector rules that usually set the higher standard.
Highest applicable standard
Per obligation, the engine states whether requirements are cumulative, superseded, conflicting, or set by the higher standard, and what that means operationally.
Pre-deployment evaluation of a high-risk AI use
Higher standard appliesEU · UK · US federal supervisory guidance
The most prescriptive evaluation and documentation set governs the whole activity; the group does not run three evaluations.
Human oversight of an automated decision
CumulativeEU · Canada · Japan
Oversight must exist and, in one jurisdiction, must be exercised locally. Both requirements stand together.
Cross-border transfer of customer data for inference
ConflictingEU · India · Group internal policy
One regime requires local processing while the platform is centralised. Resolution is a regional inference path, not a policy waiver.
Retention of model decision evidence
CumulativeUK · Singapore
Longest retention period governs, and one jurisdiction requires the evidence to remain in country.
Third-party AI provider notification
SupersededEU · US state law
The group-level notification satisfies both once the narrower state requirement is mapped into it.
Incident reporting on an AI-caused outage
CumulativeEU · UK · Japan · Australia
Four clocks start at different hours from the same trigger; a single detection event must fan out to four filings.
What localisation actually binds
Localisation is five separate requirements that institutions routinely treat as one.
Data must remain local
Storage and backup location, including disaster recovery.
Processing must be separated
Whether inference for one population can occur on shared infrastructure.
A sovereign model is required
Whether the workload's classification permits any foreign-controlled inference at all.
Human approval must occur locally
Where the approving person sits, and under whose employment and supervision.
Evidence must remain within jurisdiction
Where the control record and the audit trail are held and who can compel them.
An enterprise system and the frontier model underneath it are assessed on identical terms.
Apply the same test to the model