Back to Home
cnnews

Invisible Cross-Border Data: Employees' Daily AI Operations Are Quietly Triggering Compliance Obligations

I. Three Most Common Compliance Risks in Employee AI Usage

1. Sensitive Data Leakage

Employees, aiming to get more accurate AI assistance, habitually paste customer lists, contract terms, financial data, source code, internal strategy documents, and more directly into chat interfaces. If public AI tools are used, this data may be retained by the service provider or even used for model training, leaving companies with little control over data flow. This risk is often not "malicious leakage" but rather unconscious behavior driven by employees' pursuit of efficiency.

2. Broken Compliance Chain in Personal Information Processing

When employees input personal information—such as names, ID numbers, contact details, health information—into AI tools for analysis or content generation, they are essentially initiating a new personal information processing activity. This raises two layers of issues: first, whether there is a lawful basis for processing and whether it exceeds the purposes communicated at the time of initial collection; second—if the AI server is deployed overseas—whether this input constitutes a cross-border transfer of personal information, requiring corresponding compliance pathways.

3. Reliability and Accountability of Output Content

AI-generated content may contain factual errors, biased statements, or even fabricated citations and data (the "hallucination" problem). If employees use AI-generated content in external reports, contract terms, or public statements without verification, how is liability determined? This issue remains a gap in many companies' policy frameworks.

II. EU AI Act and GPAI Regulation: What Companies Need to Know

For companies operating in the EU or using models subject to the AI Act, employee AI usage may directly trigger legal obligations. In simple terms, the direct impact on employee AI use: purely internal use where employees are aware of the AI tool may qualify for the "context apparent" transparency exemption, but disclosure obligations arise when interactions involve customers, job applicants, or the public; high-risk scenarios such as recruitment screening and credit assessment, even if the mandatory application date is postponed, it is advisable to prepare technical documentation and human oversight mechanisms in advance according to high-risk standards.

III. U.S. AI Regulatory Landscape: Fragmented Federal Restraint and State Proliferation

Unlike the EU's top-down unified legislative approach, the U.S. currently has no comprehensive federal AI legislation. Regulation is advanced through three parallel tracks: presidential executive orders, federal agency guidance, and state legislation, resulting in a fragmented landscape that makes compliance more challenging for companies.

For companies, this means that if employee or AI system usage involves "high-risk" decisions in areas like recruitment, credit, education, or healthcare, even within the same company, branches in different states may face different disclosure, assessment, and record-keeping obligations. Companies need to establish a "state-by-state comparison table" rather than relying on a single national standard.

IV. Special Risks of AI Use and Cross-Border Data Between China and the U.S.

For companies with operations, employees, or data processing activities in both China and the U.S., employee AI usage can easily and unknowingly trigger cross-border data rules in both countries, and this triggering is often bidirectional.

1. U.S. Restrictions on Data Flowing to China

Executive Order 14117, "Preventing Access to Americans' Bulk Sensitive Personal Data and Government-Related Data by Countries of Concern," issued in February 2024 and effective April 8, 2025, is implemented by the Department of Justice through the Data Security Program rules. Key points include:

Practical implications for corporate AI use: If the AI tools, cloud services, or data processing chains used by the company involve access by China-related parties to the above bulk sensitive data—for example, U.S. team employee data, customer health or financial information entered into an AI system or third-party analytics tool with access by China-affiliated parties—even if employees are merely "using AI for efficiency," this may fall within the scope of the rules. Companies need to assess whether their vendors and data processing chains contain such hidden "countries of concern" access points.

2. China's Outbound Data Compliance Requirements for Data Transferred Abroad (Including the U.S.)

Conversely, when Chinese domestic companies or their employees input content containing personal information or important data of individuals in China into AI tools deployed in the U.S. (e.g., many mainstream large models have servers and processing nodes in the U.S.), this triggers outbound data transfer compliance requirements under China's Personal Information Protection Law (PIPL) and the Measures for Security Assessment of Outbound Data Transfers and the Measures for Standard Contracts for Outbound Transfer of Personal Information: personal information transfers exceeding certain volume thresholds require security assessment by the Cyberspace Administration of China; transfers below the threshold but involving personal information can use the standard contract filing or personal information protection certification; transfers involving "important data" generally require security assessment, and the identification standards and scope are still being refined in practice.

A point often overlooked by companies: When employees directly use overseas AI tools in daily work (especially through personal accounts or "shadow AI" channels not subject to corporate procurement and evaluation) and input content containing personal information of individuals in China, this is essentially an employee's individual act triggering the company's outbound transfer compliance obligations as the personal information processor—and this triggering often occurs without the knowledge of compliance, legal, or IT departments, making it a uniquely Chinese characteristic of "shadow AI" risk.

3. The Practical Intersection of Two Regulatory Frameworks: Companies Need to "Bidirectionally Scrutinize" Data Flows

For companies with operations in both China and the U.S., it is recommended that when evaluating any AI tool, they ask questions in two directions:

  • Data flowing into the U.S.: Does this tool transfer personal information or important data from China to overseas (typically the U.S.) for processing? Has at least one of the following been completed: security assessment, standard contract filing, or certification?
  • Data flowing to China-related parties: Do the tool's developer, cloud service provider, or subcontractors have access to bulk sensitive U.S. personal data by China-related parties? Does it fall within the prohibited or restricted transactions under the DOJ Data Security Program?

The answers to these questions often depend on the specific technical architecture and data processing locations of the AI service provider, not merely on the service provider's nationality or brand—many "American-brand" AI tools have overseas subsidiaries or subcontractors processing data, and some "Chinese-brand" tools have computing or storage located overseas. Companies should require vendors to provide a specific data processing map rather than relying on brand perception.

V. Key Actions for Corporate AI Compliance Governance

1. Establish Data Classification and Corresponding AI Usage Rules, Adding the "Data Flow" Dimension

On top of existing data sensitivity classifications, add the "data flow" dimension: whether the data may flow to the U.S., whether it may be accessed by China-related parties, and whether it involves sensitive data categories under DOJ rules. It is recommended to establish at least three tiers of usage permissions:

  • Public information and general knowledge questions: may use company-approved public AI tools
  • Internal general documents: limited to AI services that have signed data processing agreements, have clear data retention and training policies, and have transparent data flow paths
  • Data involving personal information, customer information, trade secrets, or U.S. sensitive data categories: in principle, prohibited from being input into overseas AI tools that have not undergone outbound transfer compliance assessment; if necessary, use internally deployed private models or complete the corresponding compliance procedures before use

2. Develop and Publish Clear "Employee AI Usage Guidelines"

The policy should at least cover: a list of permitted and prohibited use scenarios, red lines for input data, a list of approved AI tools with their applicable scope and data flow attributes, verification obligations before using AI-generated content externally, and consequences for violations.

3. Vendor Due Diligence: Require a "Data Processing Map," Not Just Contract Review

When procuring third-party AI services, the compliance department should require vendors to clearly specify: the geographic location of actual data storage and processing, whether there is access by overseas subcontractors or affiliates, whether personal information is transferred abroad and the corresponding lawful transfer mechanisms, the vendor's role and compliance status under the EU AI Act, and whether it falls within the restricted transaction scope of the DOJ Data Security Program. This information often does not appear proactively in standard service agreements and requires proactive inquiry and documentation by compliance and legal teams.

4. Combine Technical and Institutional Measures

It is recommended to deploy enterprise-grade AI gateways or proxies to identify and block sensitive information in inputs; implement access controls on domains of unapproved public AI tools; establish log audit mechanisms to trace every AI call involving sensitive data and its actual data flow, especially to identify "shadow AI" scenarios where employees use personal accounts.

5. Training Should Cover Multi-Jurisdictional Scenarios, Not Just Single-Policy Briefings

It is recommended to conduct training based on real scenarios, especially for roles with frequent cross-border collaboration and data exchange between China and the U.S. (e.g., cross-border HR, finance, customer service). Training should explain why "copy-pasting a piece of customer data into an AI to ask a question" may simultaneously trigger compliance obligations in both countries, rather than simply stating "company policy prohibits it."