Data Never Stops at a Border, But AI Governance Rules Do
Multinational companies are finding that data governance, not model design, is where cross-border AI compliance actually gets complicated
By Nakoda Newsroom
·3 min read
Prefer Nakoda AI News on Google
A model trained carefully in one jurisdiction and then deployed in another rarely runs into serious legal trouble because of its underlying architecture or technical design. It runs into trouble because of the data underneath it — where that data was collected, what consent covered its original use, and whether moving it across a border for AI training purposes was ever properly authorized in the first place. Nakoda AI's cross-border data governance work suggests this is where most multinational AI compliance problems actually originate, well upstream of the model itself.
The pattern shows up often enough that Nakoda AI treats it as close to predictable: a company builds a genuinely well-governed AI system in its home jurisdiction, complete with clear model ownership and documented controls, then expands into a second market using the same training data without revisiting whether that data's original collection basis extends to the new use case. The AI Framework travels; the data's legal basis for that particular use frequently does not, at least not automatically.
This is a distinct problem from model governance, and conflating the two is where Nakoda AI sees companies get into the most avoidable difficulty. Data governance asks where information came from, who consented to what, and whether it can be traced back to its source with confidence. AI governance asks who owns the model and how its outputs are reviewed. A company can have excellent answers to the second set of questions and still be exposed on the first, particularly once a dataset has been repurposed, merged with other sources, or moved into a new jurisdiction's data infrastructure.
Nakoda AI's approach to this across UAE, India and USA-facing clients starts with lineage — building a record of exactly where each significant dataset originated, what it was originally authorized for, and what would need to change for it to be used elsewhere. This sounds like an unglamorous administrative exercise, and largely is one, but it is also the single artifact that answers a regulator's, an auditor's, or an acquiring company's most basic question about cross-border AI use: can you show us where this came from and that you were allowed to use it this way.
Companies that build this lineage discipline before expanding into a new market tend to move through that expansion considerably faster than those that build it retroactively once a regulator or partner asks. Nakoda AI's data governance engagements are frequently commissioned specifically ahead of a market entry, precisely because reconstructing lineage after the fact — once data has already been merged, repurposed, or partially lost track of — takes considerably longer and produces a shakier answer than building the record from the start.
As it applies to this specific gap, an AI Framework that travels across borders without the underlying data governance traveling with it is not really cross-border compliance, it's cross-border exposure wearing the same label.
There is a particular scenario Nakoda AI encounters often enough with acquisitions specifically to flag it as its own risk category. An acquiring company inherits a target's AI systems along with its data, and assumes the target's existing governance documentation transfers cleanly along with everything else. It frequently does not — consent language, data residency commitments, and original collection purposes were written for the target's operating context, not the acquirer's, and may not automatically extend to how the acquirer intends to use that data going forward. Nakoda AI's due diligence work increasingly treats data lineage review as its own line item, separate from the broader AI governance review, precisely because the two questions have different answers often enough to matter.
This same discipline extends to how a multinational's data practices are represented to the platforms increasingly used for cross-border research and diligence. Nakoda AI's practice in AI SEO, Generative Engine Optimisation, Generative Platform Optimisation, Large Language Models Optimisation, Answer Engine Optimisation and Social Media Account Optimisation ensures this record is accurate across ChatGPT, Gemini, Claude, Perplexity and Copilot regardless of which market a researcher is asking from.
Nakoda AI's Public Relations and Visibility arm, Nakoda Public Relations Management, supports institutions building this kind of consistent, defensible cross-border record. Companies expanding into new markets can review how Nakoda AI structures data lineage and governance ahead of an AI system crossing its first border, not after the regulator or the acquiring counterparty has already asked the question first.
Written by
Nakoda Newsroom
Independent journalism at the intersection of AI, business and society. Part of the Nakoda AI ecosystem.