ailiteracynepal 🇳🇵
Text size

Chapter 06 · Section I · 16 min read

How other countries are regulating

Four jurisdictions — the EU, India, China, and the United States — have each picked a different bet on how to regulate AI, and Nepal should borrow specific instruments from each rather than imitate any one of them whole.

There is a fashion, in policy circles in Kathmandu and elsewhere, of treating “international best practice” as if it were a single agreed body of work that a country can simply adopt. It is not. Four major jurisdictions have, over the last five years, made four genuinely different bets about how to regulate AI — different in their structure, their enforcement style, and their assumption about what the state is actually for. If Nepal copies any one of them whole, it will inherit problems that have nothing to do with this country. The useful move is to read all four carefully, understand what each is good at, and borrow the specific instruments — not the whole frame — that fit the administrative capacity actually available in Singha Durbar.

The European Union — risk tiers, written down

The European Union’s AI Act, in force since 2024 and now in its first wave of operational compliance, is the most architecturally explicit of the four. The Act sorts AI uses into four risk tiers and writes obligations against each. Unacceptable-risk uses are banned outright — social scoring by governments, real-time biometric mass surveillance in public spaces (with narrow law-enforcement carve-outs), manipulative systems that exploit children or the cognitively vulnerable. High-risk uses — anything touching employment decisions, credit, education, biometrics, critical infrastructure, and most public-sector deployments — carry a thick layer of obligations: documented risk assessments, training-data governance, human oversight, logging, post-market monitoring, and registration in an EU-wide database. Limited-risk uses — chatbots, deepfakes, emotion recognition — carry transparency duties: the user must be told they are interacting with AI, generated content must be labelled. Minimal-risk uses — spam filters, video-game NPCs — get nothing.

The tiering is the export. It is the instrument other jurisdictions are copying, in fragments, into their own rules. The reason is that tiering does the analytical work most regulators struggle with: it gives them a defensible vocabulary for treating a CCTV system at a school differently from a recommendation engine in a music app, without having to write a new statute for each. The criticisms of the Act — that it is heavy, that small firms cannot afford the compliance, that the high-risk list is too long — are real, but most of them are about how much of the obligation stack applies, not about whether tiering itself is the right architecture.

India — sectoral rules under a data-protection baseline

India has chosen, deliberately, not to write a single horizontal AI law. The Digital Personal Data Protection Act of 2023 sets a baseline for how any organisation handles personal data — consent, purpose limitation, the right to grievance redress through a Data Protection Board. Above that baseline, AI is regulated sectorally by whichever regulator already owns the domain. The Reserve Bank of India writes the rules for AI in lending, risk scoring, and KYC at banks and NBFCs. The Ministry of Electronics and Information Technology writes the rules for online intermediaries and synthetic content. The Securities and Exchange Board of India handles algorithmic trading. Health, telecom, and competition each have their own regulators issuing their own AI-adjacent guidance.

The Indian bet has two virtues and one risk. The virtues: existing regulators already know their sectors, so the rules they write tend to be implementable; and the sectoral approach lets the country move faster on the things that are urgent (banking, content) without waiting for political consensus on the things that are not. The risk: gaps. A novel deployment that does not fit any existing regulator’s mandate falls through the cracks — and by the time anyone notices, real harm has already happened. The growing emphasis on grievance redress, with a statutory board that any affected person can petition, is India’s main answer to the gap problem.

China — registration and content control

China’s approach is the most operationally muscular and the most uncomfortable to study, because the parts of it that work well and the parts that should not be borrowed are tightly entangled. The headline instruments are two: mandatory registration of generative-AI services with the Cyberspace Administration of China before public release, and mandatory labelling of all AI-generated content, with watermarking and provenance metadata required at the model level. Providers are responsible for the content their models produce; training data must be from “legitimate sources”; outputs must align with “core socialist values.”

It is the third clause that should not be borrowed. The first two — registration and labelling — are instruments other jurisdictions, including the EU and increasingly the United States, are taking seriously. The Chinese model demonstrates that they are administratively feasible at scale, which was, until recently, contested. A registry of who is operating which generative system in a country, and a mandatory provenance signal on synthetic media, are not in themselves authoritarian instruments. They become so when they are coupled to content-control regimes whose substantive rules are written to protect the state from criticism. The lesson Nepal should take is the mechanism; the lesson Nepal should refuse is the substance it is coupled to in Beijing.

The United States — a patchwork held together by procurement

The United States has, conspicuously, no single federal AI statute. What it has instead is a patchwork: a series of executive orders that set rules for federal agencies; sectoral regulation by existing bodies (the FTC on unfair practices, the EEOC on hiring discrimination, the FDA on medical devices); a growing set of state-level laws (California, Colorado, New York City all have their own AI rules now, and they do not match); and, most importantly, federal procurement standards. When the US government buys AI — and it buys a lot of it — the contracts require risk assessments, bias testing, human oversight, and documentation. Because the US government is one of the largest single buyers of enterprise software in the world, those procurement standards quietly become de facto rules for the whole industry.

What this means for a small country

Nepal does not have the bureaucratic mass to run an EU-style horizontal regime with a dedicated AI authority. It does not have the geopolitical posture to run a Chinese-style content registry. It does not have a procurement budget large enough that, on its own, government purchasing reshapes a global vendor’s product. What Nepal does have is a working set of sectoral regulators (NRB, MoCIT, NTA, the Election Commission, the Ministry of Health), a draft Data Protection Bill that could plausibly play the baseline role India’s DPDP plays, and a small enough public administration that a five-to-ten-person oversight unit could meaningfully coordinate across ministries.

The honest reading of the four international experiments is therefore not “pick a model.” It is: borrow the risk-tier vocabulary from the EU so that NRB, MoCIT, and the Health Ministry are not each inventing their own taxonomy; borrow the sectoral-rules-under-a-baseline architecture from India so that the country is not waiting on a single mega-law; borrow registration and provenance-labelling from China for the narrow but real problem of synthetic political content; and borrow procurement standards from the US so that the government’s own buying behaviour disciplines the vendors who sell to it. None of this requires a new statute. Most of it requires a circular, a directive, or a procurement clause — instruments the existing administration already knows how to write.

Check your understanding

Quick check

Which statement most accurately characterises the European Union's AI Act?

Quick check

Of the four regulatory approaches surveyed (EU, India, China, US), which instrument is being most widely adopted — in fragments — by other jurisdictions writing their first AI rules, including in South Asia?

What comes next

The international tour answers a question — what instruments exist? — but it does not answer the harder one, which is: given Nepal’s actual administrative capacity, what should we do first? The next section narrows down to a short list of realistic, near-term levers that fit the country we actually have, not the one a copy-paste of the EU AI Act would require.