Global Risk WatchSTANDARD RISK GLOBAL
Daily global markets & geopolitics brief
Sign inSign up
Enquire
SRG · Standard Risk Global — Thought Leadership · Deep Dive
March 13, 2026Research Article7 chapters

The Compliance Avalanche: When Every Jurisdiction Regulates at Once

The EU has enacted ten major digital and sustainability regulations in 24 months. China has amended its Cybersecurity Law, expanded AI governance, and operationalised cross-border data certification. The US is simultaneously retreating on climate disclosure and accelerating on AI and privacy at the state level. Global AML compliance costs exceed $180 billion annually — yet detect less than 2% of illicit finance. For international businesses, the question is no longer whether to comply, but whether compliance at...

202
RISK TRENDS 6
24 m
The EU has enacted ten major digital and sustainability regulations in onths.
$180 billion
Global AML compliance costs exceed annually — yet detect less than 2% of illicit finance.
2
In the European Union alone, ten major regulations — the Digital Services Act, Digital Markets Act, AI Act...
6
China's amended Cybersecurity Law (effective January 202) introduces penalties of up to RMB 10 million and brings AI...

EXECUTIVE SUMMARY

The EU has enacted ten major digital and sustainability regulations in 24 months. China has amended its Cybersecurity Law, expanded AI governance, and operationalised cross-border data certification. The US is simultaneously retreating on climate disclosure and accelerating on AI and privacy at the state level. Global AML compliance costs exceed $180 billion annually — yet detect less than 2% of illicit finance. For international businesses, the question is no longer whether to comply, but whether compliance at...

The EU has enacted ten major digital and sustainability regulations in 24 months.

The global regulatory landscape has entered a phase of unprecedented acceleration.

The European Union has produced the most ambitious programme of digital and sustainability regulation in history.

China's regulatory acceleration in 2025-2026 represents a shift from the framework-building phase of 2017-2023 to an enforcement and refinement phase.

The Bottom Line

The EU has enacted ten major digital and sustainability regulations in 24 months.

Ten Frameworks in 24 Months

The European Union has produced the most ambitious programme of digital and sustainability regulation in history. Between 2024 and 2028, at least ten major frameworks require compliance from companies operating in or serving EU markets — each with significant penalties and extraterritorial application.

Exhibit 1
EXHIBIT: Exhibit 1: Ten EU regulations with extraterritorial reach — penalties up to 10% of global turnover per regulation

Digital Markets and Services

The Digital Markets Act (DMA), fully applicable since March 2024, carries penalties of up to 10% of global turnover (20% for repeat offences) and has already generated enforcement actions — Apple paid EUR 500 million for App Store steering violations in 2025. Meta deployed 11,000 employees and invested over 600,000 engineering hours in DMA compliance. Google assigned approximately 3,000 employees for two years on compliance with a single article (Article 5(2)). The Digital Services Act (DSA), applicable since February 2024, carries penalties of up to 6% of global turnover and has produced its first major enforcement: a EUR 200 million penalty against Meta for its "pay or consent" data-sharing model.

From Legislation to Enforcement

China's regulatory acceleration in 2025-2026 represents a shift from the framework-building phase of 2017-2023 to an enforcement and refinement phase. Five major regulatory developments have converged within 12 months, creating a compliance step-change for any business operating in or processing data from China.

Exhibit 2
EXHIBIT: Exhibit 4: China's five major regulatory frameworks converging in 2025-2026

The amended Cybersecurity Law, effective January 1, 2026, is the first major revision since the law's original enactment in 2017. It introduces tiered penalties with fines of up to RMB 10 million for critical infrastructure failures, expands extraterritorial application, and — in a development with potentially far-reaching implications — brings AI explicitly into national law through amended Article 20, which addresses algorithm development and AI infrastructure. The alignment of penalty thresholds across the CSL, Data Security Law, and Personal Information Protection Law creates a unified enforcement framework with consistent severity levels.

China's generative AI governance has advanced rapidly. New Measures for Labelling of AI-Generated and Synthetic Content, jointly issued in March 2025, took effect on September 1, 2025 — requiring both implicit and explicit labelling of AI-generated content. Three national AI security and governance standards were released in April 2025, effective November 2025, with China targeting 50+ AI standards by 2026. Cross-border data transfer rules were operationalised with the issuance of final Measures for Certification of Cross-Border Personal Information Transfer in October 2025, establishing three transfer pathways: security assessment (mandatory for large-scale transfers), standard contractual clauses, and a new certification mechanism with three authorised institutions announced in December 2025. Enforcement has become increasingly active: in May 2025, a multinational company was penalised for unlawfully transferring user personal information to France without proper assessment or certification.

Federal Retreat, State Advance

The US regulatory landscape in 2025-2026 is defined by a paradox: federal regulators are retreating from climate and sustainability disclosure while state regulators — particularly California — are accelerating on AI, privacy, and cybersecurity. The SEC voted in March 2025 to end its defence of its climate disclosure rules, effectively abandoning the most ambitious federal attempt at mandatory climate reporting. SEC enforcement priorities for 2026 have shifted toward individual prosecutions for insider trading, accounting fraud, and market manipulation, with cybersecurity designated as a "perennial examination priority" but climate disclosure de-emphasised.

California has moved to fill the federal vacuum. In 2025, the state enacted 18 new AI laws — establishing the first frontier AI law and companion chatbots legislation nationally. The CCPA regulations finalised in September 2025, effective January 1, 2026, impose personal accountability on designated individuals for privacy, AI, and cybersecurity practices. Qualified individuals must be executive management team members who submit filings to the California Privacy Protection Agency under penalty of perjury. The requirements include annual cybersecurity audits, data privacy risk assessments, and pre-use notice for automated decision-making technology. SB 253, requiring Scope 1 and 2 emissions reporting for companies with over $1 billion in revenue, targets August 2026 for initial compliance.

The anti-ESG movement at the state level has produced 192 anti-ESG bills proposed versus 76 bills supporting ESG as of September 2025. Thirteen red states have enacted 24 anti-ESG investing laws, while 17 Democratic-leaning states have urged asset managers to continue considering climate and ESG factors. This regulatory fragmentation creates a compliance patchwork that varies not only by topic but by political geography — a dynamic that compounds the compliance burden for companies operating across multiple US states.

$5.5 Billion in Penalties

Global financial regulatory penalties reached $5.5 billion in 2025, according to Fenergo's Global Enforcement Review. While this represented an 18% decline from 2024's $4.6 billion (and well below 2023's $6.6 billion), the pattern masks a significant shift in enforcement geography and intensity. H1 2025 fines surged 417% year-over-year to approximately $1.23 billion, driven by increased EMEA and APAC enforcement activity. The largest single enforcement action — EUR 835 million ($985 million) against a Swiss bank for AML failings — demonstrated that penalties now reach system-threatening levels for mid-sized institutions.

Exhibit 3
EXHIBIT: Exhibit 2: Global regulatory penalties reached $5.5B in 2025 — with a 417% H1 surge driven by EMEA and APAC

The penalty distribution by category reveals the expanding scope of regulatory enforcement: conduct of business penalties led at $2.47 billion, followed by financial crime and regulatory obligations at $1.59 billion, corporate governance at $1.28 billion, privacy and cybersecurity at $1.21 billion, and data protection and privacy failures at approximately $650 million. The growth of privacy and cybersecurity penalties reflects the maturation of enforcement under GDPR, NIS2, and equivalent frameworks — a trend that will accelerate as AI Act and DORA enforcement mechanisms become operational.

$450 Billion and Rising

The total cost of compliance for international businesses has reached an estimated $450 billion annually and is growing at 12-20% per year across major categories. Anti-money laundering and KYC compliance alone exceeds $180 billion annually — yet studies consistently find that less than 2% of illicit financial flows are detected and interdicted. This efficiency gap is the central paradox of modern compliance: the cost is enormous, the regulatory intent is legitimate, but the effectiveness is marginal.

Exhibit 4
EXHIBIT: Exhibit 5: The compliance cost stack — $450B+ annually across five major categories

Global cybersecurity spending is projected to reach $240 billion in 2026, a 12.5% increase over 2025. Banks allocate between 2.9% and 8.7% of non-interest expenses to compliance, with annual costs ranging from millions for smaller institutions to over $200 million for the largest. Audit and assurance costs continue to escalate: 71% of enterprise organisations spend over $100,000 per year on audits alone. The D&O insurance market, while experiencing a buyer-friendly cycle in 2025 (with an average 5.2% premium decline), faces emerging risk drivers that will reverse this trend: AI-related securities filings doubled in 2024, and fintech, cryptocurrency, and VC-backed firms already pay two to three times the premiums of mainstream peers.

The RegTech Response

The RegTech market — regulatory technology solutions that automate, streamline, or enhance compliance processes — was valued at $19.1 billion in 2025 and is projected to reach $105 billion by 2034, growing at a 20% compound annual growth rate. The AI-powered compliance segment is growing at 40% annually, with AI-led systems reducing false positives in transaction monitoring by 90-95% and enabling real-time detection of sophisticated money laundering patterns. Cloud-based deployment now accounts for approximately 75% of the RegTech market.

Exhibit 5
EXHIBIT: Exhibit 3: RegTech market projected to reach $105B by 2034 — AI-powered compliance growing at 40% annually

The sector is consolidating rapidly. In December 2024, CUBE completed its acquisition of Thomson Reuters Regulatory Intelligence and Oden businesses, creating a platform that now serves approximately 1,000 customers — including 40% of Tier 1 financial institutions globally. CUBE's workforce doubled to approximately 700 employees across 15 countries, and subsequent acquisitions of Kodex AI (Berlin, October 2025) and 4CRisk (Silicon Valley) added agentic AI and advanced risk analytics capabilities. The consolidation pattern signals that compliance technology is transitioning from point solutions to integrated platforms — a maturation that mirrors the evolution of enterprise software in previous decades.

Strategic Implications for International Businesses

The compliance avalanche presents three strategic imperatives for international businesses. First, regulatory architecture must be treated as a core business capability, not a cost centre. Companies that invest in unified compliance frameworks — capable of simultaneously satisfying EU, US, and Chinese regulatory requirements — will achieve structural cost advantage over competitors managing compliance as a jurisdiction-by-jurisdiction exercise. The companies deploying AI-powered RegTech solutions are already seeing 90%+ reductions in false positives and significant improvements in detection rates.

Second, the personal accountability trend requires board-level attention. California's CCPA regulations impose personal liability on designated executives from January 2026. The UK's Economic Crime and Corporate Transparency Act creates corporate criminal liability for associates' fraud from September 2025. The EU's CSDDD carries penalties of 5% of worldwide turnover. D&O insurance premiums, currently in a soft market, will reprice as AI-related securities filings and ESG litigation accelerate. Directors must understand their personal exposure under each jurisdiction in which the company operates.

Third, the efficiency paradox of current compliance frameworks — particularly in AML/KYC, where $180 billion in annual spending detects less than 2% of illicit finance — creates both a reform opportunity and a technology imperative. Regulators are beginning to acknowledge this inefficiency: FinCEN's August 2025 request for information on AML compliance costs for non-bank financial institutions signals an interest in burden reduction. Companies that can demonstrate effective, technology-driven compliance may gain regulatory favour over those relying on manual, resource-intensive approaches. The strategic imperative is clear: invest in compliance technology now, or face escalating costs, enforcement risk, and competitive disadvantage as every jurisdiction regulates at once.

This analysis draws on Fenergo Global Enforcement Review data, European Commission regulatory publications, SEC press releases and court filings, California legislative records, CAC regulatory announcements, Mayer Brown and Linklaters legal analysis, IMARC Group and Mordor Intelligence market research, FinCEN publications, and OFAC enforcement data. All figures in US dollars unless otherwise noted.

This page preserves the original historical SRG article text and exhibits while reformatting the structure for the current Global Risk Watch deep-dive template.

Charts and source-register language are retained from the source article where available.

Historical deep-dive format normalized for Global Risk Watch; original charts and exhibits preserved.

Disclaimer

This article was produced by the Standard Risk Global / SRGi Pro research platform's automated research, fact-checking and writing pipeline, with no human editorial review before publication.

It is published for informational and educational purposes only. It does not constitute investment, legal, accounting or tax advice, nor a recommendation or solicitation to buy or sell any security or financial instrument, and it should not serve as the basis for any commercial decision.

Figures are verified against publicly available sources at the time of publication; however, the completeness, timeliness and accuracy of the information are not guaranteed. Markets move continuously — data may be outdated by the time it is read.

Forward-looking statements reflect model-generated scenario analysis as of the publication date. They are inherently uncertain and are not predictions or assurances of future outcomes.

Third-party sources are cited for attribution only. Standard Risk Global does not control, and is not responsible for, the content of third-party sites.

To the maximum extent permitted by law, Standard Risk Global and SRGi Pro accept no liability for any loss arising from the use of, or reliance on, this material. Reading this page creates no client or advisory relationship.