Invisible Cross-Border Data: Employees' Daily AI Operations Are Quietly Triggering Compliance Obligations
Over the past two years, generative AI tools have rapidly evolved from a "novelty" into everyday office tools. From writing emails, creating PPTs, coding, to organizing meeting minutes—employees may interact with AI in almost every aspect of their work. However, many companies still operate in a phase where AI usage is "employee-initiated, department-tolerated, and company-unaware." For multinational enterprises, especially those with operations or employees in both China and the U.S., this laissez-faire approach is amplifying risk exposure. The EU AI Act's General-Purpose AI (GPAI) rules have entered the enforcement phase; U.S. AI regulation presents a fragmented landscape of "federal restraint, state proliferation"; and cross-border data flows between China and the U.S. are further compounded by each country's data security and export control rules, making this one of the most overlooked and perilous areas for many companies.