Code After AI

Part IV - The Governance Engine

Richard Yan Richard Yan
· 38 min read

Design, Propagation, and the Incorporation Heuristic

Part III mapped a world organized around three incompatible governance stacks — internally coherent, externally misaligned, and dependent on intermediaries to function across borders.
Part IV turns to those intermediaries.

The Translation Layer is not a metaphor. It is an institutional, legal, financial, and operational architecture through which the G3 stacks make contact — the apparatus that determines which rules travel, which are filtered, and which are blocked at the border. This Part examines how that apparatus works, where it concentrates, and why its design determines who governs AI in practice.

The Translation Layer operates as a structured pipeline that converts legal directives into machine‑executable form. The full sequence — from rule articulation through interpretation,
specification, constraint encoding, system integration, operational enforcement, and evidentiary‑artifact generation — varies in ordering across institutions, but the functional
stages remain consistent.

In practice, the pipeline consolidates into three phases: interpretation, in which legal and regulatory language is converted into operational categories and compliance specifications;
encoding, in which those specifications are embedded as constraints within systems, workflows, and technical architectures; and verification, in which resulting behavior is measured, documented, and attested through audit logs, system‑generated activity traces, and exception reports. These phases frequently overlap or recur, but together they describe the
dominant structure through which rules become operational.

Law firms anchor the interpretive phase, converting statutory obligations into the categories that organizes downstream compliance. Consultancies and technical integrators execute the
encoding phase, embedding constraints into the systems through which AI operates. Accounting networks provide the measurement and recognition frameworks that determine what counts as compliant behavior and how it is reported. Together, these actors form a continuous pipeline — from rule to constraint to evidence — producing the operational records on which governance visibility depends.

I. Why the World Needs a Place Where Systems Can Talk

For most of the twentieth century, translation between governance systems was informal.
London handled finance, Geneva handled diplomacy, New York handled capital, Singapore handled trade — a stylized geography reflected in the historical scholarship on international
financial centers and global command nodes. The system worked because the underlying infrastructures were similar enough that informal mediation could bridge them.[1]

AI removes that buffer. A model trained in California can influence a factory in Guangdong, trigger a regulatory response in Brussels, and move a pension fund in Oslo — all within a single decision loop. When incompatible stacks are forced into continuous contact at machine speed, translation becomes infrastructure rather than improvisation.

The new scarcity is optionality. If the leading stacks cannot interoperate natively, every other jurisdiction is pushed toward compatibility with one or more of them. The world needs sites
where multiple stacks can be observed, compared, priced, and reconciled without collapsing into any single one.

Hong Kong functions as a reference implementation of this capability — a jurisdiction positioned at the intersection of the U.S., Chinese, and IFRS‑aligned European stacks while maintaining its own legal, financial, and regulatory architecture. Its evolving political conditions have placed pressure on the dual‑system framework on which that intermediary role historically depended, but the underlying function — intermediation between incompatible legal and economic regimes — remains analytically distinct from the jurisdiction that currently performs it. Other countries could develop comparable capabilities; the conditions for doing so emerge from the analysis that follows.

II. The Architecture of the Translation Layer

Hong Kong’s Translation Layer operates through three structural capabilities that interact as a system.

The first is legal duality. Hong Kong’s common‑law tier governs contracts, commercial reasoning, and dispute resolution. Its PRC‑law tier governs constitutional authority and national security. The two legal grammars coexist with domain‑specific boundaries rather than clean separation — enabling rights, obligations, and enforcement pathways to move across otherwise incompatible legal systems.[2]

The second is tri‑grammar financial mediation. HKFRS — Hong Kong’s implementation of IFRS — functions as an operational bridge between the G3 accounting regimes. CAS industrial realism becomes legible to global capital; GAAP intangible logic becomes interpretable to Mainland regulators. Firms can present coherent financial identities across divergent accounting systems, reducing the translation loss that occurs when moving between incompatible measurement grammars.[3]

The third is a buffered topology for data and compute. Hong Kong is a jurisdiction where Western cloud services, Mainland cloud services, and global routing paths converge under a legal regime that permits controlled interaction between data sovereignties. Model weights
can move without raw data crossing borders; inference can run on Western compute against
Chinese‑origin data; and federated training can occur with mutual verification — subject to evolving export‑control and licensing constraints.[4]

This combination is difficult to replicate because the barriers are foundational rather than incremental. Singapore has deep administrative capacity but lacks Hong Kong’s RMB‑native
financial infrastructure and reciprocal civil‑judgment enforcement with Mainland courts. Dubai International Financial Centre (DIFC) can scale common‑law adjudication but has no PRC‑facing enforcement pathways or CAS–HKFRS accounting corridor. London retains IFRS/GAAP depth and dispute‑resolution leadership but lacks offshore RMB infrastructure and PRC enforcement reciprocity. New York has unmatched GAAP capacity and capital‑market scale but faces structural barriers — sanctions, national‑security architecture, data‑sovereignty constraints — to any PRC‑facing integration. Shanghai and Shenzhen anchor CAS industrial logic but cannot host dual‑grammar legal execution within the current constitutional framework.

These barriers are real, but not permanent. Network‑level alternatives — decentralized identity systems, cross‑border regulatory sandboxes, distributed compliance mechanisms — are emerging, but they remain instruments rather than autonomous governance systems.

Substitution is possible in principle; in practice, it requires rebuilding an interface that Hong
Kong already operates.

III. The Valuation Translator — How HKFRS Bridges GAAP and CAS

A GAAP investor reads a CAS‑based AI firm as undercapitalized; a Mainland regulator reads a GAAP‑narrated technology firm as over‑financialized. The same enterprise becomes a different economic object depending on the accounting grammar applied — and AI‑driven firms, whose value depends on data, software, and forward‑looking development capacity, expose this incompatibility most acutely.

HKFRS — Hong Kong’s implementation of IFRS — functions as a voltage converter between these systems. It renders CAS‑grounded industrial performance legible to global capital, allows GAAP‑familiar intangible narratives to be interpreted within a prudential framework, and enables fair‑value logic to coexist with conservative balance‑sheet discipline. Hong Kong completed full IFRS convergence in 2005; China introduced the modern Accounting Standards for Business Enterprises beginning in 2006 as part of a broader alignment with international standards. CAS remains distinct in several areas, but the reform created substantial technical compatibility — and with it, a narrow but durable reconciliation corridor.

Hong Kong’s professional ecosystem operates within that corridor. Drawing on the tri‑grammar mediation described above, it reconciles CAS‑native financials into HKFRS without violating Mainland prudential expectations, while presenting disclosures in forms that GAAP‑trained global investors can interpret without systematic mispricing. The result is a jurisdiction with a uniquely interoperable financial language — one that bridges measurement grammars rather than choosing between them.

Valuation, however, is only half the translation. Financial statements encode rights — and those rights must be executable across legal systems. That is the work of the legal translator.

Cross‑border capital structures require a jurisdiction where common‑law and Mainland administrative‑law grammars can both function without displacing one another. Hong Kong
provides that environment. Its legal order preserves private‑law autonomy, commercial adjudication, and international arbitration under common law while remaining embedded within the PRC’s sovereign constitutional structure under the Basic Law. The layers operate in parallel, creating a hybrid jurisdiction in which commercial rights formed under one grammar can interface with enforcement institutions governed by the other.

The enforcement mechanisms extend beyond court judgments. Arbitral awards issued through the Hong Kong International Arbitration Centre (HKIAC) can be enforced in Mainland courts under the 1999 Arrangement on Mutual Enforcement of Arbitral Awards and its 2020 Supplementary Arrangement. Both corridors — judgment recognition and arbitral enforcement — contain statutory scope limitations and public-policy safeguards, but together they provide the cross-border enforcement framework on which the Translation Layer depends.[5]

A simplified example illustrates the pathway. A U.S. venture fund invests in a Shenzhen robotics company through a Hong Kong holding structure; the shareholders’ agreement is governed by Hong Kong law; disputes are resolved under HKIAC rules; and any resulting award is enforceable in Mainland courts under the cross‑border arbitration arrangements. The investor operates within a common‑law contractual framework while the operating company remains fully subject to PRC sovereign regulations.

Capital moves between the systems without forcing either to abandon its own legal grammar.
The same logic applies to derivatives, structured products, and cross‑border financing instruments — each traversing the corridor without requiring either legal order to rewrite its
internal logic. Contracts and rights can cross the divide; the data and computational infrastructure they govern must be able to do the same. That is the work of the physical translator.

V. The Physical Translator — Hong Kong as Data Port in the AI Era

Earlier eras of globalization required translation between commercial systems — trade through logistics, contracts through jurisdiction, valuations through accounting. Data introduces a different constraint. The storage and processing of data are bound to specific hardware and legal regimes, yet AI development routinely requires computational workflows that span them. The major digital powers — the U.S. through export controls and sector‑specific governance, China through the Cybersecurity Law, Data Security Law, and PIPL, and the European Union through the GDPR — operate data‑sovereignty frameworks that are not designed to interoperate.[6]

Hong Kong functions as a physical interface where these frameworks converge without collapsing. Western and Mainland cloud providers maintain regional infrastructure in close
proximity. Model weights and trained parameters can move even when the underlying datasets cannot. Inference workloads can run on external compute while sensitive training data remains within Mainland borders. Federated training architectures allow collaborative model development across borders with verification conducted through Hong Kong's legal and institutional framework. This topology is reinforced by ongoing infrastructure investment, including the AI Supercomputing Centre at Cyberport, and policy initiatives facilitating controlled cross-boundary data flows.

China is positioned to generate some of the world's richest industrial datasets; the U.S. continues to dominate global model-deployment ecosystems. Hong Kong sits between them as one of the few jurisdictions where both systems can interact without collapsing into either
one's regulatory gravity.

A simplified example illustrates the pathway. A model trained on Mainland industrial data exports its trained weights to Hong Kong following security review under China's data-export framework. Those weights are then deployed on external compute for global inference — without the underlying raw data leaving the Mainland. The pathway remains subject to evolving export-control and sector-specific conditions, but it demonstrates how AI pipelines can satisfy multiple sovereignty regimes simultaneously.

This is the Data Port — an emerging institutional form in which cross-sovereign computation occurs within a jurisdiction capable of hosting it physically, legally, and infrastructurally. As AI systems require continuous interaction between incompatible data regimes, jurisdictions that can provide this buffered interface become critical nodes in the global AI economy.[7]

VI. The Systemic Risk of Losing the Interface

The interface depends in part on both technological ecosystems continuing to treat Hong Kong as a distinct operational environment. A shift in classification — through export‑control categories, cloud‑deployment policies, capital‑routing rules, sanctions frameworks, or audit‑recognition regimes — can narrow this function even when no physical infrastructure changes. Disconnection in such systems is primarily logical rather than physical.

These classifications are embedded in the compliance systems of private actors: banks, exchanges, cloud providers, auditors, and index compilers. They operationalize risk through
internal models, standardized templates, and automated methodologies. When those models shift, the interface contracts independently of formal political decisions.

A neutral scenario illustrates the mechanism. A global cloud provider updates its internal risk model and downgrades Hong Kong’s interoperability profile. Cross‑region replication is. reduced; high‑performance workloads face new restrictions. Enterprise compliance teams update templates governing Hong Kong–hosted infrastructure. Financial institutions adjust
operational pathways. Auditors revisit exposure classifications. Index providers reconsider weighting methodologies. Capital‑allocation systems begin to reprice the jurisdiction. No
law changes. No infrastructure disappears. Yet a classification adjustment propagates through interdependent systems, tightening constraints incrementally.

If the interface degrades materially, the effects can cascade outward. China faces higher friction in accessing global risk capital. Global investors lose visibility into Mainland industrial performance. Emerging markets lose one of the few neutral pathways into both stacks. Cross‑border M&A becomes more expensive as translation premiums accumulate.

For jurisdictions that control neither stack, the interface preserves strategic optionality — the ability to operate across systems without forced alignment.

The Translation Layer preserves systemic coherence under divergence. But coherence does not determine governance. Interfaces enable systems to interact; they do not decide which rules ultimately govern those interactions. To understand why some sovereign rules propagate globally while others remain confined to their origins, the analysis turns from the mechanics of translation to the logic of incorporation.

VII. The Sovereignty Paradox: Maps versus Networks

Legal sovereignty and operational control no longer coincide. Every state retains the formal authority to regulate AI, but the systems it seeks to govern operate across the globe
simultaneously, following a network architecture that no single country controls. In this gap, authority migrates toward the operational compliance frameworks maintained by global
firms — composite rule‑sets embedded in the internal templates of hyperscalers, financial institutions, and multinational platforms, continuously updated to reconcile hundreds of
overlapping regulatory regimes into a single executable system.

A routine AI‑mediated commercial system makes the divergence concrete. A model trained in Seattle on data drawn from dozens of countries is executed on weights distributed across
cloud regions in Oregon, Ireland, and Singapore; invoked by a customer in Lagos; routed through an API gateway in Frankfurt; and used to determine whether a Brazilian manufacturer receives financing. Multiple jurisdictions can plausibly assert authority, yet none — by itself — governs the system in full. The system’s behavior follows its network construct rather than any single territorial perimeter.

This dynamic becomes clearer when examining how global compliance systems absorb — or ignore — regulatory demands. A global privacy template illustrates the logic. It incorporates the GDPR because enforcement visibility and penalties are high; the California Consumer Privacy Act because the U.S. market cannot be ignored; and the PIPL because access to China’s ecosystem requires it. But it omits the data‑protection frameworks of more than one hundred other nations. Each rule enters the template for a different reason — enforcement visibility, operational feasibility, or market gravity — but the logic is consistent: a rule is incorporated only when the cost of ignoring it exceeds the cost of implementing it across global systems.

The result is structural asymmetry. A citizen in South Africa or Indonesia is effectively governed by a hybrid of European, American, and Chinese rule‑sets — the gravitational centers whose norms propagate through platforms, markets, and supply chains. Their own parliament may pass an AI Act, but unless that Act is absorbed into the global compliance template, it remains symbolic sovereignty: law that exists on paper but never reaches operational force.

This is the Sovereignty Paradox. The political map recognizes nearly two hundred sovereign nations. The AI economy organizes itself around a far smaller number of regulatory gravity
centers whose rules propagate unevenly through global systems. The difference is not rhetorical; it reflects structural properties that determine whether a rule becomes visible, executable, and unavoidable. The Incorporation Heuristic formalizes those properties — explaining why certain rules enter the global runtime and why most do not.

VIII. The Incorporation Heuristic

The System‑Selection Logic of Global Power
The Translation Layer describes how rules travel across incompatible systems. The Incorporation Heuristic explains which rules survive the journey.

The heuristic can be formalized as a decision function. Incorporation likelihood is a function of three variables — Visibility, Workability, and Necessity — each exerting directional, threshold, and interaction effects. Visibility increases incorporation probability because rules cannot operate on activity the State cannot reliably detect. Workability increases it because rules that cannot be operationalized cannot take effect. Necessity increases it because rules that carry no meaningful consequence for omission are unlikely to be incorporated even when visible and workable.73

Each variable functions as a gate: below a practical threshold of visibility, workability, or necessity, incorporation becomes unlikely. The variables also interact: visibility amplifies the
effect of workability; necessity increases the incentive to improve visibility; and high necessity can drive redesign to make otherwise unworkable rules workable. The Incorporation Heuristic is not a descriptive law but an analytical model of how rules compete for incorporation in a dynamic, multi‑jurisdictional environment.

This competition operates beneath the diplomatic surface of the international system. It emerges not through treaties but through the internal compliance engineering of global firms
— the operational triage performed by lawyers, auditors, and risk architects whose mandate is to minimise exposure while maintaining functionality across the widest possible set of markets. The heuristic formalizes the logic through which these compliance architects determine whether a national rule must be compiled into the global baseline or can remain locally bounded.

For any rule that enters the cross‑border compliance environment, incorporation likelihood can be expressed as:

I = V×W×N

The multiplicative structure is deliberate. A national rule enters the global template only when it satisfies three conditions simultaneously. It must be visible — detectable by institutions managing cross‑border liability, with credible enforcement behind the detection. It must be workable — capable of being operationalized as a procedure across heterogeneous regimes.
And it must be necessary — such that omission would trigger unacceptable legal or market risk.

The Incorporation Heuristic — including the multiplicative structure I = V × W × N and the sequential-gate interpretation — is an original formulation of this manuscript, drawing on traditions in systems reliability, institutional decision theory, and global compliance practice.

The variables are continuous, not binary. Visibility ranges from near zero — where regulators lack monitoring capacity or credible sanction authority — to near one, where enforcement is
instrumented, specialized, and existentially credible. Visibility itself decomposes into a paired subsystem:

V = f (detection, sanction)

Detection without sanction produces weak signals; sanction without detection produces random ones. Visibility registers only when both operate together with sufficient credibility
to influence institutional risk calculations. Workability and necessity are similarly graduated:
rules may be fully compiled into global templates, partially parameterized for specific markets, or isolated within local sandboxes.

Because the variables are multiplicative, failure at any stage is dispositive. A visible but unworkable rule stalls at the execution gate — for example, when a jurisdiction can detect
non‑compliance but lacks the technical specification needed to tell firms what compliance requires. A visible and workable but dispensable rule fails at the necessity gate. Only rules
that remain non-zero across all three variables propagate into global application.

Other factors—enforcement severity, reputational spillovers, geopolitical alignment — operate by modifying one of the three variables rather than constituting independent considerations. Enforcement severity amplifies visibility by raising expected penalties. Reputational spillovers increase necessity by adding non‑market exit costs. Geopolitical alignment can shift all three simultaneously by altering coordination expectations. The three‑variable formulation captures the operative variance in observed compliance practice while remaining analytically tractable.

The heuristic does not claim that public authority disappears. States continue to legislate, regulate, and enforce within their territories. What it formalizes is the mechanism through
which certain national rules extend beyond those territories and become embedded in the operational templates that govern cross‑border AI. Regulatory power is exercised not only
through formal jurisdiction but through the probability that a rule becomes incorporable — and the Incorporation Heuristic describes the arithmetic of that probability.

A. Visibility (V): The Detection Test

Visibility measures whether a rule’s violation will be detected and whether detection will trigger consequences that alter incentives. The first question a compliance architect asks is
not “Is this illegal?” but “If this rule is broken, will anyone see it — and will it matter?”

Many countries have enacted AI‑specific legislation — prohibiting algorithmic discrimination, mandating explainability, requiring human oversight — without building the capacity to observe violations. Where regulators lack model‑audit capability, access to inference logs, inspectors with machine‑learning expertise, and enforcement budgets sufficient to sustain investigations, the rules exist formally but produce no credible compliance risk. To the compliance architect, such rules are effectively invisible, and invisible rules are unlikely to enter global templates.

Contrast this with regulatory regimes that invest directly in observation. The EU’s Digital Services Act (DSA) combines standardized transparency reporting, vetted researcher access to platform data, algorithmic‑audit requirements, and systemic‑risk assessment obligations — backed by fines reaching six percent of global turnover. The result is a regulatory environment where opacity is not a viable defense. Compliance architects cannot safely ignore rules enforced through this level of instrumentation. The telescope is pointed directly at them.[8]

Visibility is not a function of sovereign size; it is a function of institutional instrumentation.
Several smaller jurisdictions have demonstrated this. Singapore’s Monetary Authority of
Singapore (MAS) deploys machine‑readable reporting and conducts on‑site technical supervision. Israel’s National Cyber Directorate (INCD) operates real‑time cyber‑telemetry
pipelines. Norway’s Data Protection Authority (Datatilsynet) conducts high‑resolution technical investigations. The UK’s Information Commissioner’s Office (ICO) maintains specialized algorithmic‑auditing teams.[9]

Individually, these efforts are modest. Collectively, these examples show that observation can be engineered and institutionalized — even by countries with comparatively small populations — when the mandate is clear and technical capacity is built deliberately.

Visibility is therefore the first gate. Only rules that produce credible detection signals enter the evaluation set. The remaining variables — workability and necessity — determine whether those observable rules can be operationalized and sustained within global compliance systems.

B. Workability (W): The Implementation Test

If visibility determines whether a rule enters the evaluation set, workability determines whether it can be operationalized. The second question a compliance architect asks is technical: Can this rule be converted into machine‑testable controls, repeatable audit procedures, and scalable compliance workflows?

Many countries publish AI principles that are normatively meaningful but operationally indeterminate. A statute declaring that AI must be “fair,” “just,” or “aligned with cultural values” cannot be implemented as a control variable. A compliance system cannot audit “respect for human dignity” without defined metrics, nor evaluate cultural alignment without measurable criteria. When rules lack operational specificity, institutions respond predictably: the rule is documented, localized, and treated as a jurisdiction‑specific exception rather than incorporated into the global template.

By contrast, rules with explicit technical thresholds translate directly into compliance systems. The U.S. Department of Commerce, Bureau of Industry and Security (BIS) advanced-computing export controls specify performance and interconnect-bandwidth thresholds for controlled semiconductors, requiring a license when those thresholds are exceeded. The compliance instruction is therefore relatively unambiguous and can be integrated directly into screening systems, workflows, and audit procedures, even though the thresholds, licensing policies, and country frameworks have been revised repeatedly since the original 2022 rule.[10]

As with visibility, workability does not depend on national size. It depends on whether legal text is drafted in a form that can be translated into operational controls. Japan's Personal Information Protection Commission (PPC) issues detailed guidance on cross-border data transfers under the APPI. Singapore's Personal Data Protection Commission (PDPC) provides structured guidance on data-protection compliance for AI systems. Switzerland's Financial Market Supervisory Authority (FINMA) mandates standardised liquidity-reporting requirements. Chile's Financial Market Commission (CMF) publishes open-banking standards. The United Arab Emirates' Telecommunications and Digital Government Regulatory Authority (TDRA) establishes defined information-security requirements. These jurisdictions exert regulatory influence not through economic scale but through drafting clarity. Their regulations can travel.[11]

Workability is the second gate. A rule that is visible but cannot be operationalized stalls at the implementation stage. Only rules that pass both the detection test and the implementation
test reach the final variable — necessity.

C. Necessity (N): The Market Gravity Test

If visibility determines whether a rule can be observed and workability determines whether it can be operationalized, necessity determines whether it must be obeyed. Necessity is
economic rather than technical. It measures the cost of exiting a market relative to the cost of complying with its regulations — a market’s exit elasticity. When exit is inexpensive,
compliance treats a rule as optional; when exit is prohibitively costly, the rule becomes unavoidable.

Consider a small island state that mandates local data centers for all cloud providers. With a population of roughly 100,000 and a GDP near $100 million, the cost of constructing even a
modest Tier II facility — often $12–15 million before operating expenses — would exceed any plausible revenue. The rule remains valid domestic law, but its incorporation weight within global compliance approaches zero. The outcome is not punitive; it is arithmetic.

The opposite dynamic emerges in markets whose scale or strategic position makes exit economically irrational. China’s PIPL imposes data‑localization requirements, restrictions on
outbound transfers, granular consent obligations, mandatory security assessments, and requirements for local legal representation. These obligations are specific, operational, and
enforceable — conditioning access to China’s domestic AI ecosystem on compliance with an institutionally backed regulatory perimeter. For firms operating at global scale, abandoning the market would impose losses far exceeding the cost of implementation. Compliance teams absorb the costs and execute the rule‑set.[12]

The Necessity variable is not binary; it operates on a gradient shaped by enforcement credibility, penalty magnitude, and reputational exposure. Jurisdictions that combine high
penalties with active enforcement generate stronger Necessity signals. Those with formal rules but weaker enforcement generate weaker ones. The following regimes illustrate the gradient: China's Personal Information Protection Law, India's Digital Personal Data Protection Act, Brazil's LGPD, Indonesia's Personal Data Protection Law, Nigeria's Data Protection Act, and California's consumer-privacy statutes. Each regime generates Necessity pressure, but the intensity depends on whether the enforcement machinery behind the rule is credible, resourced, and active.

Necessity emerges not from GDP alone but also from market gravity: the degree to which a market's economic opportunity or strategic position makes exit irrational. India's Digital Personal Data Protection Act (DPDPA) shapes access to one of the world's largest digital populations. Brazil's Lei Geral de Proteção de Dados (LGPD) influences compliance across Latin America's payments and fintech ecosystems. Indonesia's Personal Data Protection Law (PDP Law) governs a rapidly expanding cloud-services market. Nigeria's Data Protection Act (NDPA) affects the trajectory of African digital finance. California's Consumer Privacy Act (CCPA) and Privacy Rights Act (CPRA) shape national data-handling practices through regulatory spillover. These jurisdictions do not compel compliance through force alone; they compel it through significance.[13]

Necessity is the third gate. A rule that is visible and workable but governs a market with low exit costs remains optional. Rules backed by sufficient market gravity are far more likely to become binding. Together, visibility, workability, and necessity determine which national rules enter the global compliance template and which remain confined to their originating jurisdiction.

D. The Result: The Framework Sort

Applying the Incorporation Heuristic across the world’s regulatory environments produces a distribution that is directionally decisive. The pattern emerges not from political preference
but from structural convergence: global firms gravitate toward rule‑sets that minimise ambiguity, reduce operational friction, and limit exposure to enforcement risk.

The GDPR illustrates full incorporation. It scores highly on all three variables—strong enforcement visibility, machine‑testable operational requirements, and substantial
market‑exit costs — and functions as a de facto baseline for many multinational firms. U.S.
GAAP demonstrates the same dynamics in capital‑market contexts: maximal enforcement visibility, precisely defined requirements, and indispensable market access produce dominant incorporation.

Singapore's Model AI Governance Framework shows a different trajectory. Its guidance is operationally clear, and tools such as AI Verify support implementation. Yet because the
framework is voluntary and the domestic market comparatively small, necessity remains low.
Singapore shapes global discourse more than it determines global practice.[14]

Brazil’s LGPD illustrates partial incorporation. Operational clarity and a strengthening enforcement regime give the LGPD meaningful regional influence, particularly across Latin
America’s digital and financial sectors. Yet Brazil’s market gravity does not compel universal adoption. The result is selective incorporation by firms that handle Brazilian data.

Geopolitical constraints can override the heuristic entirely. Following comprehensive sanctions on Russia, more than a thousand multinational firms were tracked by Yale CELI as having curtailed or withdrawn operations, regardless of local regulatory quality. When firms are legally or politically compelled to withdraw, necessity collapses to zero and the heuristic loses force irrespective of visibility or workability.[15]

Across the global landscape, most national rules sit far from the upper bound of incorporability. The distribution reflects an evident reality: only rules that achieve sufficient visibility, operational clarity, and market gravity travel beyond their home jurisdiction. The Incorporation Heuristic does not evaluate the merits of any country’s choices. It identifies which rules global firms actually embed in operations — and which remain legally valid but practically inert.

E. Raising Your Score — Strategies for Increasing Incorporation Weight

The three variables of the Incorporation Heuristic are not independent levers. Institutional changes that raise one score often impose costs on the others. But because incorporation
weight is multiplicative, improvements in any single variable can materially increase the probability that a rule enters the global template. Across jurisdictions that succeed, five design strategies recur.

The first is instrumentation. Visibility increases when regulatory obligations become observable to external evaluators. Countries that invest in supervisory technology, standardized disclosures, monitoring pipelines, and machine‑readable reporting create rules that external systems can detect. Instrumentation turns abstract obligations into operational signals.

The second is precision. Workability improves when statutes can be decomposed into specific checks, measurable actions, and processes that firms can implement at scale. Clear definitions, stable interfaces, and executable compliance steps allow external actors to translate legal requirements into operational controls.

The third is control over coordination bottlenecks. Necessity increases when a country controls a scarce coordination point — a licensing gate, a settlement platform, a data chokepoint, or a certification regime on which external actors depend. Market gravity is not solely a function of GDP; it is a function of indispensability.

The fourth is alignment with a legal center. Countries that anchor new rules in a dominant legal tradition — common law, civil law, or administrative law — reduce interpretive overhead and increase incorporability. Coherence lowers translation costs and allows external actors to apply familiar analytical tools rather than constructing new interpretive frameworks.

The fifth, and most consequential for smaller nations, is routing through a translation node:
a hub whose legal, accounting, and professional‑services ecosystem functions as a visibility amplifier, a workability converter, and a normative validator. The mechanism is concrete.

Vietnam's AI Law begins with a low incorporability profile. The statute exists only in Vietnamese and lacks an official English translation. its definitions are framed within domestic administrative concepts, and its terminology reflects Vietnam-specific regulatory priorities. Without authoritative translation, the law has limited legibility for global compliance systems.[16]

Now imagine routing the same obligations through Hong Kong's professional-services ecosystem. None of the substance changes; what changes is the interface. Once rewritten in
common-law language, cross-referenced to HKFRS-aligned disclosure requirements, and embedded in documentation that international evaluators already understand, the rule becomes detectable, interpretable, and structurally compatible with existing compliance pipelines.

Hong Kong often renders PRC obligations legible to global markets without altering their content — a pattern observed across finance, arbitration, and cross‑border commercial law. The translation node does not replace domestic authority; it extends its operational reach.

These strategies do not transform Fiji into Brussels — and they do not need to. They move a nation from peripheral rule production to incorporated rule production: from rules that remain
locally legible but externally inert to rules that external systems can interpret, execute, and rely upon. Incorporation is not granted by larger states. It is built — through institutional choices that allow domestic rules to enter the systems global firms depend on.

IX. The Power Hierarchy — Root Access, Admin Access, and User Access

Applied across the world’s regulatory environments, the Incorporation Heuristic reveals a hierarchy of operational influence that does not map onto the political geography of sovereign
equality. Every state remains sovereign in the formal sense; but within the stack that governs global AI, sovereignty behaves as a gradient of access privileges — a spectrum determining how far a state’s rules travel beyond its borders.

The gradient resolves into three tiers. Root‑access jurisdictions write the defaults that propagate across multiple system‑critical domains — data governance, capital markets, and
frontier‑model deployment. Their incorporation weight is highest globally, and their rules function as the baseline against which others are measured.

Admin-access jurisdictions shape or constrain system behaviour within particular sectors or at specific chokepoints. Their incorporation weight is above zero but domain-specific — a
semiconductor licensing gate, a financial clearing corridor, a certification regime on which external actors depend. The Taiwan Semiconductor Manufacturing Company (TSMC) is not
a geopolitical superpower, yet it is a single point of failure in advanced chip fabrication.
Advanced Semiconductor Materials Lithography (ASML) is the sole supplier of extreme-ultraviolet lithography systems. Admin access is also a form of power.[17]

User‑access nations — the majority of the world’s states — retain full legal authority within their borders but lack the visibility, workability, or market gravity to project their rules into global AI systems. Their sovereignty is complete; their incorporation weight is low.

The AI economy therefore operates in two geometries simultaneously: the territorial map of formal authority and a permission structure layered on top of it, determining which rules can
steer the global machinery of data, capital, and frontier models. The heuristic does not diminish sovereignty. It identifies which nations possess the operational permissions to shape AI governance beyond their own borders — and which do not.

A. The Three Global Centers (Root Access)

Three jurisdictions currently operate at Root level — each projecting rules along a distinct propagation axis.

The U.S. anchors the valuation core. Its influence projects through U.S. GAAP, SEC disclosure regimes, and the extraterritorial reach of export controls. AI firms seeking access
to U.S. equity or debt markets must present growth, risk, and performance in terms legible to American capital markets, because the deepest capital pool sets the grammar in which
value is measured. The propagation channel is necessity, reinforced by the workability of a detailed, rules-based system that global investors can reliably interpret.[18]

China occupies the infrastructure core. Its influence channels through data-localisation mandates, cybersecurity classifications, and a state-defined network perimeter that governs
what data may cross the border and what computation may occur within it. Foundation-model licensing rules and inference-server controls extend this perimeter into AI development itself.
Access requires accommodation; the alternative is exclusion.[19]

The EU defines the standards core. Its influence is transmitted through the GDPR, the EU AI
Act, and a procedural apparatus that treats classification, documentation, conformity assessment, and product design as sequential requirements. For frontier AI labs, exclusion
from a 450‑million‑person and affluent market is rarely viable — and maintaining a single
EU‑compliant system is typically more efficient than engineering regulatory divergences.

Together, these three cores define the default operating environment of the AI‑era global order. Valuation rules determine how firms measure success and allocate capital. Infrastructure constraints determine where AI can be deployed and where data may reside. Compliance regimes determine how deployment must be documented, evaluated, and justified. The global operating paradigm emerges from the interplay of these forces — not from territorial authority but from the structural conditions that determine which rules propagate.

B. The Power Users (Admin Access)

Admin‑access countries do not usually set global defaults. They shape how those defaults are implemented, interpreted, or routed — reaching a localized peak of incorporability within a
specific domain. In software terms, they resemble power users: they cannot rewrite the core, but they can configure how the system behaves. In global AI, the same logic applies. These
states do not define the baseline rules, but they meaningfully shape how those rules operate in practice.

Three pathways tend to produce this form of influence.

The first is workability as power. Singapore's regulatory institutions do not author global standards, but they implement them with exceptional precision. MAS converts frameworks
such as Basel III and Financial Action Task Force (FATF) recommendations into high-clarity, low-ambiguity guidance that multinational banks use as operational benchmarks. Singapore does not write the world's financial rules; it produces a highly executable version of them, and executability becomes a form of influence.

The first is workability as power. Singapore’s regulatory institutions do not author global standards, but they implement them with exceptional precision. MAS converts frameworks
such as Basel III and FATF recommendations into high‑clarity, low‑ambiguity guidance that multinational banks use as operational benchmarks. Singapore does not write the world’s financial rules; it produces the most executable version of them — and executability becomes a form of influence.[20]

The second is translation as power. The UK cannot match Brussels in regulatory scale or Silicon Valley in AI investment, but it retains a deep commercial-law tradition, centuries of precedent, and the global language of contracts. English law remains the predominant governing law for International Swaps and Derivatives Association (ISDA) Master Agreements in cross-border transactions, and many commercial disputes are heard in London. The UK provides a stable legal interface through which global actors coordinate, reducing interpretive uncertainty between jurisdictions.[21]

A Swiss variant exists: Switzerland's institutional neutrality, reinforced by the Bank for International Settlements (BIS) headquarters in Basel, offers a trusted venue for financial coordination where competing powers can cooperate without ceding political advantage. In
this model, neutrality itself becomes infrastructure.[22]

The third is necessity as power — influence created when a jurisdiction controls a function the global system cannot easily replace. TSMC in advanced semiconductor fabrication and ASML in extreme‑ultraviolet lithography are the clearest examples; Chile and the Democratic Republic of the Congo occupy similar positions in critical minerals, Kenya in regional fiber‑optic landing stations, and Iceland in stable, low‑cost compute and energy.

These actors hold admin-level influence because they control non-substitutable capacity. But bottleneck power is unstable: concentration invites diversification. TSMC's dominance has
already triggered fabrication initiatives under the U.S. CHIPS and Science Act, the EU Chips
Act, and Japan's Rapidus program.[23]

Admin access matters because most states will not reach Root level — but they need not remain at User level either. Meaningful influence does not require writing global rules. It requires controlling a domain where others depend on you: for operational clarity, for legal translation, or for irreplaceable capacity. In the AI economy, systemic criticality is not a function of GDP; it is a function of placement within the stack.

The remaining tier — User access — comprises the majority of the world’s states. These countries retain full sovereign authority within their borders, and their legal systems govern
domestic life completely. But their rules rarely propagate beyond their territory. They lack the enforcement instrumentation to generate visibility, the drafting precision to achieve workability, or the market gravity to compel necessity — and in the multiplicative logic of the heuristic, weakness in any single variable is sufficient to prevent incorporation.

These nations are locally sovereign but globally uncompiled. The Incorporation Heuristic does not diminish their authority. It identifies the structural conditions they would need to change — conditions the strategies for raising incorporation weight, examined earlier in this Part, are designed to address.

C. The Permission Matrix — A Hierarchy That Is Real, but Not Closed

The hierarchy is real but not closed. Root access is rare and slow to form — the product of decades of institutional accumulation, market gravity, and positional centrality. Admin access
is attainable through specialization, regulatory precision, or control of non-substitutable capacity. And User‑access jurisdictions are not permanently confined to that tier. The strategies for raising incorporation weight — instrumentation, precision, bottleneck control, legal‑tradition alignment, and routing through translation nodes — describe a structured pathway from local sovereignty to global compilation.

In AI governance, authority follows critical functions rather than territorial lines. Formal sovereignty remains universal, but operational influence concentrates around the actors who
manage the permissions through which AI systems execute. The topology can be mapped; it can also be changed. That is the hierarchy’s most consequential feature — not that it exists,
but that it admits movement.

X. Gateway Rules — How Global Norms Move Across the World

Root access determines who writes rules that travel. A Gateway Rule is a regulatory requirement whose compliance forces changes to foundational design — data schemas, reporting formats, documentation pipelines, network configurations, or contractual defaults. Ordinary regulations function as local parameters, shaping conduct within the enacting jurisdiction. Gateway Rules alter the underlying frameworks on which other systems depend. When those frameworks shift, the effects radiate outward through supply chains, software stacks, and operational workflows, transforming practices in countries that never adopted the
rule directly.[24]

Gateway Rules travel through the same three channels mapped in the Root-access analysis.
Reporting-format dependencies propagate through the U.S. valuation core, altering how systems measure. Network-layer dependencies move through the Chinese infrastructure core,
altering what systems connect to. Compliance-process dependencies transmit through the
European standards core, altering how systems demonstrate conformity.

Each channel operates on a different tier of the global system — measurement, infrastructure, or governance — and each generates a compliance cascade: a chain of secondary obligations
that firms must satisfy together to maintain market access. Impact assessments, disclosure procedures, consent management, localization requirements, and audit documentation cluster
into bundles that become embedded in product design. Once embedded, these bundles resist unwinding; removing one component often requires dismantling the entire compliance framework or exiting the market that created the rule.

Not all countries absorb Gateway Rules passively. Most adapt domestic systems to external dependencies, incorporating compliance cascades as they arrive. A smaller group takes a
different approach — anticipating where new dependencies will land and building the institutional, technical, or legal frameworks through which those rules are executed. Singapore and the UK already occupy this position: they do not author Gateway Rules, but they control the channels through which Gateway Rules are implemented. India is building the institutional capacity to do the same.

The result is a governance framework in which a small number of nations shape the behavior of AI systems operating across sovereign borders — not through diplomatic consensus but through the technical and institutional patterns that global systems must adopt in order to function.

A. Why Gateway Rules Spread — The Economics of Convergent Design

Gateway Rules spread because large‑scale AI systems converge toward minimal divergence.
Uniformity is not a preference; it is the operational equilibrium that reduces maintenance overhead, testing permutations, and failure modes.

The GDPR’s Right to Be Forgotten is a useful illustration of the dynamic. To satisfy a single deletion request from a German user, a global AI system may need to purge personal data
from active storage, scrub multi‑year backups, notify downstream processors, reconcile the deletion with countries that mandate retention, remove references from indices and ranking
systems, and generate an auditable record of the sequence. The exact steps vary by platform, but deletion in every case requires a system-wide engineering capability.[25]

Once that capability exists, the platform faces a design‑level choice: maintain fragmented, country‑specific branches or unify around a single framework calibrated to the strictest requirement. Fragmentation compounds operational complexity with each additional jurisdiction. Unification produces the opposite cost curve — once a capability is built, extending it across additional regions approaches near‑zero marginal cost.

At scale, the gap becomes unsustainable. The deletion capability becomes a global feature.
Users in Brazil, Indonesia, or India receive the functional equivalent of the Right to Be Forgotten — not because their legislatures enacted it, but because the platform will not maintain parallel systems. The EU legislated for 450 million; the effect extends to billions.

The pattern generalizes. Once components such as data‑protection impact assessments, data‑subject access portals, consent‑tracking modules, or transfer‑assessment workflows are
embedded in cloud platforms and enterprise software, they become default modules in the global stack — and once embedded, they exhibit strong path dependence. Removing them is
more expensive than maintaining them. Engineering changes undertaken to satisfy one jurisdiction’s rule become woven into global infrastructure, extending that rule’s practical effects far beyond its formal intent and scope.

This dynamic creates a strategic opening for mid‑power nations. Countries that understand where these compliance capabilities must run can position themselves along the pathways —
building the services, standards, and institutions that convergent designs depend on. Influence need not come from writing the rule; it can come from becoming indispensable to its implementation.

B. The Golden Image — How Templates Spread the Rule

Gateway Rules spread not only through engineering design but through the global advisory ecosystem — the major law firms, audit networks, and multinational consultancies that build
and maintain compliance systems for global firms.

The internal economics of these networks push toward standardization. Every deviation increases liability exposure, complicates audit defensibility, and raises delivery cost across
distributed client portfolios. The result is what systems administrators call a Golden Image:
a preconfigured baseline — master service agreements, audit protocols, data-protection addenda, cross-border transfer mechanisms — replicated across deployments to ensure consistency and reduce configuration risk. These templates anchor an organization's canonical compliance regime, the baseline against which all local deviations must be justified.[26]

Embedded within these templates are controls drawn from multiple regulatory cores. U.S.
anticorruption provisions from the Foreign Corrupt Practices Act sit alongside European privacy obligations from the GDPR, Chinese data-governance requirements from the Cybersecurity Law, and U.K. financial-crime controls shaped by the Bribery Act. The resulting image is composite, portable, and enforceable — assembled from the regulatory requirements of multiple jurisdictions.[27]

When a bank in Nigeria hires a London law firm to update its cloud contracts, it receives this
Golden Image — complete with FCPA clauses and GDPR-aligned processing terms it never explicitly requested. The controls arrive because the law firm deploys a common baseline across its portfolio. Removing them would require abandoning the template entirely — an option that increases legal cost, operational complexity, and professional liability.

The template persists because deviation is expensive. Once embedded in clause banks, contract libraries, audit frameworks, and regulatory checklists, these standards exhibit the same path dependence as the engineering capabilities described above. They travel with every contract, audit protocol, and governance framework deployed across multinational systems.

C. Three Ways Rules Travel

Gateway Rules reshape systems through three distinct mechanisms, each operating at a different layer of the stack.

The first is measurement-format dependency. The converged revenue-recognition standards
— ASC 606 under U.S. GAAP and IFRS 15 under international standards — require firms to record income when performance obligations are satisfied rather than when payments are
received. Implementing this standard often forces redesign across sales-contract structures, commission frameworks, CRM workflows, billing logic, and financial-reporting pipelines —
and in AI-enabled firms, it reshapes the enterprise data, labels, and model inputs used in forecasting, risk-scoring, and automated decision systems.[28]

Once a parent company standardises these structures, subsidiaries inherit the same configurations, contract templates, reporting logic, and AI-model inputs. A pair of converged
standards issued in Norwalk, Connecticut and London can therefore reshape sales, reporting, and prediction workflows across global organisations, even where the legal obligation originates in only two jurisdictions.

The second is network-layer dependency. China's data-governance framework requires certain categories of personal or sensitive data collected domestically to remain within national borders. For a global AI platform, compliance begins with the most expensive step: building a China-specific data stack — dedicated storage, separate compliance workflows, local operational teams, and independent audit controls.

That first partition often pushes the system toward federation. Once federation exists, the economics shift. Each subsequent localisation mandate — Russia, Saudi Arabia, Vietnam,
Indonesia — arrives at dramatically lower marginal cost. The system has already been engineered for partition; adding a new country becomes an incremental extension. A structure
that was once unified begins to resemble a constellation of regional enclaves.

The third is process-layer dependency. European AI regulation requires certain high-risk systems to undergo conformity assessment before market entry, including documentation of
training-data provenance, testing procedures, and risk-management protocols. These obligations create what can be described analytically as build-time irreversibility: the relevant compliance record is most reliably generated during model construction, and the compliance window narrows once training is complete.[29]

Build-time irreversibility does not mean that models are fixed or behaviourally static after training. Post-training alignment techniques — including RLHF, constitutional tuning, and preference optimisation — can meaningfully steer surface-level behaviour, and inferencetime controls can constrain or redirect outputs.

But these mechanisms operate on top of a pre-established representational structure. They shape expression more than provenance, and they modulate tendencies more than they
reconstruct the training history embedded in the model. The foundational properties of a system — including the statistical imprint of its training corpus, the structure of its learned representations, and capabilities that emerge with scale — are set during the building phase and only partially alterable afterward.

The regulatory effect operates as a consequence of this structure. Because much of the required compliance documentation is most reliably generated during model construction,
the rule shapes design long before a product reaches the EU and before any audit or supervisory exposure arises. A startup that implements data lineage from day one may be
effectively aligning with the EU AI Act before it has a single European user, because retrofitting later often requires retraining models or rebuilding workflows. Though drafted for the European market, the rule's effects extend wherever standardised systems are deployed.

D. From Description to Design

The dynamic described in the preceding sections — where legal text becomes system constraint and then propagates as standardised infrastructure — is not only a feature of the
current ecosystem. It is the mechanical pathway that any viable governance model must coopt. The framework proposed in this manuscript relies on this same causal chain.

The sequence begins with the regulation itself, which defines the substantive obligation. It specifies the requirements that frontier-scale models must satisfy: auditability, provenance,
interruption, network identity, and safety-case disclosure. These obligations exist prior to any technical implementation and function as legal and constitutional commitments.

The Gateway Rule converts the obligation into an systematic requirement, operationalising the regulation by making access to shared compute, credentialled identity, or interoperability
conditional on compliance. The Gateway Rule does not create new duties; it enforces existing ones by tying them to the chokepoints through which high-risk systems must pass.

The Golden Image propagates the resulting compliance pattern — a standardised implementation template that satisfies the Gateway Rule and can be adopted, forked, or
extended by operators. The Golden Image does not originate or enforce the obligations; it distributes them, ensuring that the same compliance logic is applied across multiple operators
without bespoke engineering at each site.

The causal chain — Regulation → Gateway Rule → Golden Image — is the mechanism through which governance decisions made at the legal layer shape the long-term architecture
of AI systems.

E. Strategies for Non‑G3 Countries — Designing for Incorporation

For countries outside the G3, Gateway Rules define a design space rather than a constraint.
The dominant regulatory cores set the system foundations — valuation frameworks, infrastructure boundaries, compliance procedures — but the cascade still depends on
operational layers that no single core controls: audit capacity, verification infrastructure, interoperability mechanisms, and compliance tooling. Countries that position themselves
within these pathways gain leverage. Three strategic patterns have emerged as especially salient.

The first is the early-adopter strategy. When a major jurisdiction signals that it will require algorithmic audits or system certification, a country can move early — enacting aligned
requirements and building the institutional capacity to implement them before the mandate spreads. When it does, the early adopter is not absorbing compliance cost; it is supplying
verification capacity.

Certification ecosystems exhibit economies of scale: once an audit framework exists, marginal assessments become cheaper than establishing new capacity elsewhere. The UAE's positioning around AI assurance frameworks reflects this dynamic. India's engagement with AI standard-setting through the Bureau of Indian Standards — including the work of the Artificial Intelligence Sectional Committee (LITD 30) and its adoption of ISO-aligned AI management-system and AI-application standards — illustrates the same trajectory. This strategy carries an inherent risk: credibility must match ambition. Early adoption without institutional depth erodes trust rather than building advantage.[30]

The second is the safe-harbor strategy. When regulatory environments demand stronger verification of counterparties, countries can position themselves as trusted intermediaries —
supplying registries, certification services, or governance frameworks that reduce compliance friction for global transactions. Financial markets offer precedent: jurisdictions such as Luxembourg and the Cayman Islands became structurally embedded as global financial hubs not by writing the rules, but by supplying the legal, custody, due-diligence, and intermediation structures those rules required.[31]

Canada's emerging role in AI model evaluation and safety benchmarking, anchored in the Canadian Artificial Intelligence Safety Institute (CAISI), reflects the same logic — credibility as a service. The risk is proportional to the role: verification hubs attract scrutiny, as financial hubs have learned through sustained OECD and FATF pressure. Their durability depends on whether the verification function provides enough systemic value to justify the attention.[32]

The third is the federation strategy. As data-localisation requirements and infrastructure partitioning increase, global AI systems are becoming progressively federated — operating
as multiple country-specific deployments that must interconnect. Countries that provide the legal, technical, or institutional capabilities enabling partitioned systems to communicate
gain structural importance.

Hong Kong has historically performed this function for cross-boundary financial and data flows between mainland China and international markets. Singapore's trusted-data-intermediary frameworks pursue a similar objective. The risk is inherent to the role: interoperability layers add complexity, and their value depends on whether they reduce friction elsewhere in the system.

These strategies do not require contesting the dominant cores. They require identifying where the cascade depends on capabilities the cores do not supply — and building them. Rulemaking authority in AI governance is concentrated; operational influence is distributed. The gap between the two is where non-G3 countries find agency.

XI. Conclusion — The Invisible Constitution

A. The Age of Unseen Power

The pattern that emerges from Part IV is structural. Three regulatory cores write the defaults that govern global AI. Gateway Rules propagate those defaults through measurement
formats, network architectures, and compliance procedures. The Golden Image distributes them through the translation ecosystems of Big Law, Big Four accounting networks, and major advisory firms. The result is an engineered order — a functional rule-set produced not by legislatures alone but by compliance engineers, cloud platforms, and the propagation logic
of convergent design.

This is the Invisible Constitution: the operational rulebook that governs global AI regardless of what formal law provides. It is not fully democratic, not fully negotiated, and not equal in its distribution of influence. But it functions — and it functions at global scale, because the alternative — a fully fragmented regulatory landscape — would impose coordination costs
that frontier AI systems cannot sustain.

The Invisible Constitution resolves a coordination challenge. It does not solve a legitimacy problem. Execution capacity has become a source of governing authority, but execution capacity is not the same as democratic mandate. That gap — between functional governance and legitimate governance — is the subject of Part V.

B. The Strategic Design Space

For countries outside the G3, the Invisible Constitution is a constraint — but it is also a design space. The cores are already established, yet the global system depends on operational
infrastructure that no single core supplies. Countries that build capacity in those layers become part of the implementation machinery through which AI governance actually operates.

The Incorporation Heuristic provides the design logic: build verifiable regulatory capacity, implement rules that integrate cleanly across systems, and position yourself where coordination becomes unavoidable. The preceding sections have shown what this looks like in practice — early adoption of assurance standards, construction of verification infrastructure, development of federation and interoperability capabilities, and alignment with the advisory templates through which global firms operate. These are not peripheral activities. They are the operational layers on which the Invisible Constitution depends.

Influence in this framework does not come from rewriting the cores. It comes from supplying components the system cannot operate without. For most nations, that is not a consolation. It
is an invitation — one that requires institutional depth, technical capacity, and sustained investment, but one that remains structurally available to any country prepared to build what
the system needs.

C. The Rules That Execute

Public authority in the AI era is shaped less by what is declared than by what is compiled into the systems through which global AI runs. The Invisible Constitution, the Incorporation Heuristic, the Gateway Rules, and the Golden Image are not abstractions. They are the machinery through which governance now functions — and they operate whether or not any
legislature has endorsed them.

The Translation Layer cannot, on its own, constitute a governance order capable of managing the material foundations of AI. Its function is descriptive and mediating: it renders model behaviour legible to existing institutional forms, but it does not supply the institutional authority or enforcement capacity required to govern machine intelligence at scale.

Translation stabilises visibility; it does not generate the normative commitments, auditability conditions, or procedural guarantees that a full governance framework requires. And rules,
however well they travel, govern behaviour — they do not directly allocate the compute, data, and models on which AI power ultimately depends, even where they shape access to
those resources indirectly through procurement constraints or export controls.

Without deliberate State intervention — including the creation of an Audit Tier, the specification of ex ante obligations, and the establishment of enforceable oversight pathways — the Translation Layer remains a conduit rather than a constitutional foundation. Part V moves from description to construction: from how rules travel to whether a governance architecture adequate to the material foundations of AI power can be built.


  1. Y. Cassis, Capitals of Capital (2006); S. Sassen, The Global City (2001).↩︎
  2. Arrangement on Reciprocal Recognition and Enforcement of Judgments in Civil and Commercial Matters (2019).↩︎
  3. HKICPA, IFRS Convergence Framework.↩︎
  4. AWS Hong Kong Region; Alibaba Cloud Hong Kong Region.↩︎
  5. Arrangement on Mutual Enforcement of Arbitral Awards (1999); Supplementary Arrangement (2020). PRC Cybersecurity Law (2017); Data Security Law (2021); Personal Information Protection Law (2021);↩︎
  6. Regulation (EU) 2016/679 (GDPR); U.S. Export Control Reform Act (2018) and BIS semiconductor-export rules.↩︎
  7. PRC Measures for Security Assessment of Outbound Data Transfers (2022). Hong Kong SAR Government, AI Supercomputing Centre at Cyberport (policy announcement). The concept of the Data Port is this manuscript's contribution.↩︎
  8. Regulation (EU) 2022/2065 (Digital Services Act).↩︎
  9. MAS, Technology Risk Management Guidelines (revised 2021); INCD, Annual Report (2025); Datatilsynet,Investigation Report: Grindr Case (2021); ICO, AI Auditing Framework: Draft Guidance for Consultation (2020).↩︎
  10. U.S. Department of Commerce, Bureau of Industry and Security (BIS), Implementation of Additional Export Controls: Certain Advanced Computing and Semiconductor Manufacturing Items, 87 Fed. Reg. 62186 (2022) (subsequently revised).↩︎
  11. PPC, Guidelines on Cross-Border Transfer of Personal Data under the APPI (as amended 2022); PDPC,Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems (2024); FINMA, Liquidity Risks — Banks (Circular 2015/2, as amended); CMF, Open Banking Standards (2022); TDRA, UAE Information Assurance Standards (2020).↩︎
  12. Personal Information Protection Law of the People’s Republic of China (2021).↩︎
  13. On the global proliferation of data-protection regimes generating market-gravity Necessity, see Digital Personal Data Protection Act (India, 2023), as implemented by subsequent rules; Lei Geral de Proteção deDados (Brazil, 2018, as amended); Personal Data Protection Law (Indonesia, 2022); Nigeria Data Protection Act (2023); California Consumer Privacy Act (2018), as amended by the California Privacy Rights Act (2020).↩︎
  14. IMDA and PDPC, Model AI Governance Framework (2d ed. 2020); IMDA and PDPC, AI Verify Testing Framework and Toolkit (2022).↩︎
  15. Yale Chief Executive Leadership Institute (CELI), List of Companies Leaving and Staying in Russia (maintained continuously since March 2022). The database grades more than 1,000 companies across a spectrum of disengagement and continued operation.↩︎
  16. Vietnam, Law on Artificial Intelligence (Law No. 134/2025/QH15, enacted 10 December 2025, effective 1 March 2026).↩︎
  17. C. Miller, Chip War (2022); S.M. Khan, A. Mann & D. Peterson, 'The Semiconductor Supply Chain: Assessing National Competitiveness,' CSET (2021). The characterisation of TSMC and ASML as single points of failure is this manuscript's analytical description.↩︎
  18. SEC Form 20-F, Items 8, 17, and 18; SEC Release No. 33-8879 (2007).↩︎
  19. CAC et al., Interim Measures for the Management of Generative Artificial Intelligence Services (2023); Cybersecurity Law of the People's Republic of China (2017); Data Security Law (2021); Personal Information Protection Law (2021).↩︎
  20. MAS Notice 637, Risk-Based Capital Adequacy Requirements (as revised); MAS Notice 626, Prevention of Money Laundering and Countering the Financing of Terrorism. FATF, Mutual Evaluation of Singapore (2016).↩︎
  21. ISDA, 2018 Choice of Court and Governing Law Guide; ISDA Master Agreement, Section 13 (governing law and jurisdiction).↩︎
  22. BIS, About the BIS (institutional overview).↩︎
  23. U.S. CHIPS and Science Act (2022); EU Chips Act (2023); Rapidus Corporation (est. 2022), a Japanese government-backed initiative targeting 2nm fabrication capacity.↩︎
  24. "Gateway Rules" is an original analytic category developed in this manuscript. It extends the Incorporation Heuristic by isolating the mechanism through which certain regulatory requirements propagate across borders via system design rather than formal national adoption.↩︎
  25. Regulation (EU) 2016/679, art. 17. First established in Case C-131/12, Google Spain (CJEU, 13 May 2014).↩︎
  26. The application of the Golden Image concept to global compliance template propagation is an original formulation in this manuscript. The term is borrowed from systems administration.↩︎
  27. U.S. Foreign Corrupt Practices Act (1977, as amended); EU General Data Protection Regulation (Regulation 2016/679); PRC Cybersecurity Law (2017); U.K. Bribery Act (2010).↩︎
  28. FASB, ASC 606, Revenue from Contracts with Customers; IASB, IFRS 15. Both effective from 1 January 2018.↩︎
  29. "Build-time irreversibility" is an original analytic term introduced in this manuscript to describe compliance obligations that are most reliably satisfied during AI model construction and whose evidentiary assurance diminishes once training is complete.↩︎
  30. ISO/IEC 42001:2023, Artificial Intelligence Management System — Requirements. Bureau of Indian Standards, Artificial Intelligence Sectional Committee (LITD 30), including Indian Standards IS/ISO/IEC 42001:2023 and IS/ISO/IEC 5339:2024.↩︎
  31. R. Palan, R. Murphy & C. Chavagneux, Tax Havens: How Globalization Really Works (Cornell University Press, 2010).↩︎
  32. Government of Canada, Canadian Artificial Intelligence Safety Institute (CAISI).↩︎
Share this post
Richard Yan
Richard Yan

Test BIO

Join the discussion

Become a member of Code After AI to start commenting.

Sign up now
On this page
Series