Lenavix
← Back to Blog

The jurisdiction problem nobody talks about

An AI product can encounter overlapping privacy, AI, employment, consumer-protection, cybersecurity, and sector rules. Which instruments apply depends on the product, parties, data, decisions, sectors, and places involved.

Asking only how many jurisdictions a product touches produces a misleadingly simple answer. The practical question is which rules attach to each role, data flow, system, decision, sector, and market connection. A single label such as "GDPR" cannot answer it.

The stacking problem

Consider a company offering a workforce-analytics product in Europe. Depending on its facts, the review may need to test several distinct layers:

  • EU regulations that may apply directly, including the GDPR and, by role and classification, the AI Act.
  • Directives implemented through national law, including NIS2 for covered entities and sectors.
  • More specialized EU instruments: the DSA for covered intermediary services and DORA for specified financial entities and ICT arrangements.
  • National employment, workplace, contract, procedural, and sector-specific rules.
  • Non-binding regulator guidance, standards, and research taxonomies that can inform—but do not replace—the legal analysis.

Not every layer applies to every company. That is the point: scope must be established before obligations can be compared, and no single badge or framework resolves the analysis.

"GDPR" is shorthand for "the part of the iceberg my last lawyer mentioned."

Why it's not just more regulations

The instinct is to model this as a checklist that grows: 5 rules become 50 become 500. But scaling is the easy part. The harder part is that the rules interact.

Retention duties can interact with deletion requests. Data-transfer restrictions can affect technical architecture and discovery planning. AI Act classification can add role- and risk-specific duties, while the lawful basis for personal-data processing remains a separate GDPR analysis. The resulting contracts and controls must address each applicable instrument on its own terms.

You don't compose this by hand. You can't even compose it with a spreadsheet, because the cells aren't independent — they constrain each other. Compliance in this shape is closer to constraint solving than checklist execution.

What changes when you treat jurisdiction as a graph

A useful mental model treats each candidate obligation as a node and each dependency or tension as an edge. The graph organizes review; it does not decide which paths are legal without verified facts and professional judgment.

That sounds abstract, but the output is concrete. A product team asks whether a feature may be offered in a market. The review links product facts and data flows to candidate instruments, records source versions, and shows counsel what still needs to be resolved. When an official source changes, affected conclusions can be queued for reassessment rather than silently treated as current.

That's the shift: not automated legal conclusions, but a reviewable structure that helps lawyers reason across connected facts, sources, and prior decisions.

The honest cost

None of this is free. Maintaining the graph means monitoring official publications, preserving source and version metadata, and routing changes for legal review. Press releases and summaries can help discovery, but controlling text and authoritative guidance must anchor the record. The sources referenced here are listed in the Regulatory source register.

Continue exploring

Lenavix maps the jurisdictional graph so your team can stop guessing.

Book a demo