Global AI Assurance · Jurisdiction engine

    Jurisdictional Intersection Engine

    Sovereignty is not where the server sits. The wrong question is which country's law applies. The right question is which combination of jurisdictions, laws and regulatory obligations applies to this specific AI activity.

    A global group does not become subject to its parent's regime because the parent owns the platform. Each entity, each user population, each data class and each transaction brings its own regime, and they have to be resolved together.

    Published as reference architecture. Control weights, grading rubrics and the full control set are set per engagement.

    Foundational rule

    Cabier does not determine jurisdiction solely from where an AI model, server or company is located. It determines applicable requirements from the combined relationship between entity, activity, data, user, model, infrastructure, transaction, jurisdiction, sector and consequence.

    Where regimes overlap

    Where multiple jurisdictions apply, Cabier identifies cumulative obligations, conflicts, higher standards, localisation requirements and sovereignty constraints before determining whether an AI system or model may operate.

    Sixteen inputs per activity

    This is deliberately not a country selector. A selector would give the wrong answer for every transnational group.

    01

    Where is it developed?

    Development location carries export, ownership and provenance consequences that survive deployment.

    02

    Where is it hosted?

    Hosting sets the first set of compulsion and access exposures, but it does not settle the question.

    03

    Where is inference performed?

    Inference is where the data actually moves; it is frequently not where the contract says the service sits.

    04

    Where does the data originate?

    Origin fixes the transfer analysis and often the lawful basis.

    05

    Where is the data stored?

    Storage drives residency and localisation duties independently of processing.

    06

    Who owns the data?

    Ownership determines who can consent, who can be compelled, and who must be notified.

    07

    Where is the user?

    Many regimes follow the person, not the provider. This is the input most often omitted.

    08

    Which legal entity operates it?

    The operating entity carries the licence conditions and the supervisory relationship.

    09

    Which entity is responsible?

    Operating and responsible entities are frequently different, and only one of them is accountable to the board.

    10

    Where is the customer?

    Customer location triggers consumer, conduct and disclosure duties that the entity's own jurisdiction does not.

    11

    What sector is involved?

    Sector regulation usually imposes the higher standard, above general AI or privacy law.

    12

    Which jurisdictions' laws apply?

    The output of the first eleven inputs, not an assumption made at the start.

    13

    Are there cross-border restrictions?

    Transfer, onward transfer and remote-access restrictions each behave differently.

    14

    Are there localisation requirements?

    Localisation can bind data, processing, human approval and evidence separately.

    15

    Are there foreign access or government compulsion risks?

    Lawful access by another state is a control question, not a contractual one.

    16

    What sovereignty level is required?

    The requirement is set by the workload and the classification, then tested against what the model can offer.

    Permitted

    The activity operates under the applicable regimes with the standing control set.

    Permitted with conditions

    Named additional controls, approvals or restrictions must be in place and evidenced before use.

    Sovereign deployment required

    The workload may proceed only where compute, inference, data and evidence remain within the required jurisdiction.

    Restricted

    Permitted for a narrower purpose, data class or user population than requested.

    Prohibited

    No configuration available to the institution satisfies the applicable requirements.

    The transnational overlay

    An entity tree, then eight lenses laid across it. Illustrative group; the structure holds wherever home and host supervisors both have standing.

    Group parent

    Holding company; owns the global AI platform and central inference capacity

    Supervisors

    Home prudential supervisor · Home markets regulator

    AI posture

    Centralised AI platform, three model providers, one shared evidence vault

    Canadian subsidiary

    Regulated deposit taking and advisory

    Supervisors

    Federal prudential supervisor · Federal and provincial privacy authorities

    AI posture

    Consumes central platform; local model validation required

    Conflict
    Evidence for validated models is currently held outside the jurisdiction.

    UK subsidiary

    Investment services

    Supervisors

    Conduct regulator · Prudential regulator

    AI posture

    Consumes central platform; senior-manager accountability mapped per AI use

    EU operations

    Licensed entity plus branch network

    Supervisors

    National competent authority · Data protection authority

    AI posture

    High-risk uses declared; local documentation and oversight set

    Conflict
    Central inference path crosses the border for two high-risk uses.

    Japan operations

    Branch, corporate clients

    Supervisors

    Financial supervisor · Privacy authority

    AI posture

    Local approval required for automated decisions

    Conflict
    Approving person currently sits outside the jurisdiction.

    Singapore operations

    Regional hub and treasury

    Supervisors

    Financial supervisor

    AI posture

    Regional inference permitted; evidence retention set to the longest applicable period

    Data jurisdiction

    Where the data originated, is stored, and may be transferred.

    Customer jurisdiction

    Consumer, conduct and disclosure duties following the customer.

    Employee jurisdiction

    Worker monitoring, consultation and employment duties where AI touches staff.

    Model jurisdiction

    Provider ownership, development location and contractual restrictions.

    Hosting jurisdiction

    Infrastructure, subprocessors and lawful-access exposure.

    Transaction jurisdiction

    Where the economic act lands, including settlement and booking.

    Regulatory jurisdiction

    Which supervisors hold standing over the activity, home and host.

    Sector jurisdiction

    The sector rules that usually set the higher standard.

    Highest applicable standard

    Per obligation, the engine states whether requirements are cumulative, superseded, conflicting, or set by the higher standard, and what that means operationally.

    Pre-deployment evaluation of a high-risk AI use

    Higher standard applies

    EU · UK · US federal supervisory guidance

    The most prescriptive evaluation and documentation set governs the whole activity; the group does not run three evaluations.

    Human oversight of an automated decision

    Cumulative

    EU · Canada · Japan

    Oversight must exist and, in one jurisdiction, must be exercised locally. Both requirements stand together.

    Cross-border transfer of customer data for inference

    Conflicting

    EU · India · Group internal policy

    One regime requires local processing while the platform is centralised. Resolution is a regional inference path, not a policy waiver.

    Retention of model decision evidence

    Cumulative

    UK · Singapore

    Longest retention period governs, and one jurisdiction requires the evidence to remain in country.

    Third-party AI provider notification

    Superseded

    EU · US state law

    The group-level notification satisfies both once the narrower state requirement is mapped into it.

    Incident reporting on an AI-caused outage

    Cumulative

    EU · UK · Japan · Australia

    Four clocks start at different hours from the same trigger; a single detection event must fan out to four filings.

    What localisation actually binds

    Localisation is five separate requirements that institutions routinely treat as one.

    Data must remain local

    Storage and backup location, including disaster recovery.

    Processing must be separated

    Whether inference for one population can occur on shared infrastructure.

    A sovereign model is required

    Whether the workload's classification permits any foreign-controlled inference at all.

    Human approval must occur locally

    Where the approving person sits, and under whose employment and supervision.

    Evidence must remain within jurisdiction

    Where the control record and the audit trail are held and who can compel them.

    An enterprise system and the frontier model underneath it are assessed on identical terms.

    Apply the same test to the model