Compliance, Not Technology, Is Biggest Hurdle for Chinese AI Firms Going Global, Lawyer Says(Yicai) Aug. 28 -- Compliance, rather than technology, is often the first major obstacle Chinese artificial intelligence companies encounter when expanding overseas, according to a senior Chinese lawyer.
Broadening national security scrutiny, cross-border data rules, and differing regulatory regimes mean Chinese AI firms need to build compliance into their products and operations from the outset, Gu Zhaoqin, a partner at Duan & Duan Law Firm's Hongqiao branch, said at a Global Media Dialogue event held by Yicai in Shanghai today. The Global Media Dialogue is a Shanghai-hosted series that brings together industry experts and journalists to discuss major economic and business issues.
Gu cited WuXi AppTec's legal challenge against the US Department of Defense as an example. The pharmaceutical services provider sued after the DoD added it to its Section 1260H list of "Chinese military companies" on June 8. On Aug. 7, a US judge granted WuXi AppTec a preliminary injunction, finding the designation was likely "arbitrary and capricious" and temporarily blocking its enforcement while the case proceeds.
Gu said the dispute illustrates why Chinese companies need stronger and more verifiable compliance systems as national security reviews become broader and increasingly affect commercial competition.
Although WuXi AppTec operates in a different industry, Gu cited the case to illustrate how the scope of national security reviews is expanding. "National security, in the legal systems of many countries, is essentially a black box," he said. "If a government decides your company touches on its national security, it can bypass the legislature or normal legal procedures and impose sanctions directly."
This trend of broadening the scope of national security is spreading from geopolitical considerations into industrial competition, posing a real risk to AI companies that similarly face scrutiny over cross-border data flows, Gu said.
Gu voiced clear support for WuXi AppTec's decision to challenge the designation in court rather than accept it. "We very much hope to represent Chinese companies in pushing back and mounting a defense overseas, and to compete with international lawyers on the same playing field," he said.
Data Has No Checkpoint
Traditional goods crossing borders pass through customs, providing a clearly defined regulatory checkpoint, while cross-border data flows have no equivalent, Gu noted.
Gu grouped the overseas expansion models used by Chinese AI companies into three categories: continuing to use servers based in China, deploying both data and models entirely overseas, and adopting a hybrid model combining a local knowledge base with remote inference.
Across all three models, overseas regulators focus not simply on whether data crosses borders, but on where the data is stored, where models are trained, and whether data leaves the local jurisdiction during inference, Gu said.
"What they care about is how you collect the data, whether you're limiting collection to what's strictly necessary, who can access it, and who is accountable if something goes wrong," he said.
Gu noted a clear divide in compliance capabilities based on company size. State-owned enterprises and large technology companies generally have relatively well-developed compliance systems, while the greatest exposure lies with the small and mid-sized private firms that make up the bulk of Chinese companies expanding overseas, he said.
Many companies default to compliance after the fact rather than incorporating it into every stage of product design and research and development, Gu said.
"Evidence is where a lot of Chinese companies fall short," he said, noting that once a dispute enters litigation or an administrative proceeding, companies often cannot produce documentation proving that they were in compliance at the time.
No One-Size-Fits-All Template
There is no single compliance template that can be replicated across overseas markets, Gu cautioned.
In the European Union, the Artificial Intelligence Act combined with the General Data Protection Regulation (GDPR) creates what he described as the strictest regulatory environment Chinese AI firms currently face. In the US, risks stem more from differences among state-level laws combined with scrutiny conducted in the name of national security.
Southeast Asia, by comparison, is a region where Chinese AI has achieved relatively high penetration and local attitudes toward Chinese companies are comparatively favorable, Gu said. Industrial parks catering to Chinese companies and facilitating engagement between businesses and local governments have emerged in countries including Thailand and Indonesia, he added.
But regional goodwill does not amount to a regulatory exemption, Gu cautioned, noting that Southeast Asian countries are also tightening data localization and algorithm registration requirements.
Gu recommended that Chinese companies build localized and verifiable compliance systems. They should classify data according to risk levels, collect and store information according to the "minimum necessary" principle, transparently disclose how data is stored and models are trained, undergo third-party audits, and establish local compliance teams in target markets rather than simply replicating their domestic practices overseas.
The preliminary injunction in the WuXi AppTec case is only the first round, and the ultimate outcome remains uncertain, Gu said. But the case itself shows that when companies confront the "black box" of national security, technological strength alone is never enough of a moat, he added.
Editor: Emmi Laine
