Cross-Border Agentic AI Compliance (CBAAC): Embedding Regulatory and Cultural Risk Compliance into Agentic Communication
Matt Pagett, Tomoko Mitsuoka · Team Matt Pagett and Tomoko Mitsuoka
Submitted to The Technical AI Governance Challenge. Sprint projects are early-stage work by participants, not Apart Research publications.
AI regulations (EU AI Act, Japan METI, Korea AI Basic Act) require providers to certify compliance — but how can businesses verify that the agents they use, and sub-agents in the chain, actually comply? Current approaches rely on costly audits, additional external agreements, or trust — and do not scale well to a world of millions of agents which can spawn on demand. We propose demand-side verification: a protocol enabling agents to automatically check compliance of other agents before sharing data. Our framework supports regulatory compliance (GDPR, AI Act, GPAI) and optional cultural/ethical benchmarks addressing behavioral risks such as unconsented user profiling and emotional manipulation. We extend Project NANDA's AgentFacts schema with self-certification questionnaires for EU, Japan, and Korea jurisdictions, plus cultural competency assessments addressing behavioral risks documented in AI governance failures. We provide an open implementation and demo at [https://cross-border-agentic-compliance.solve.it.com/]. Keywords: Multi-agent alignment, AI security, compliance infrastructure
Reviews
The low evidence gained from self-certification is further degraded by agentic endpoints which do not actually know, themselves, the true answer to how user data will be handled. I share excitement about third-party audited approaches. I’d like to understand better how TEE-based runtime attestation works, and how it would integrate with this approach.
I would be interested to understand what implications this approach might have on system latency; if users will be left waiting for a long time for agents to down and up the chain sharing attestations.
I’m not convinced that the full subjectivity of cultural compliance is appreciated here. There could be important differences in cultural expectations between different contexts even within regions like Japan. With unlimited resources, I can imagine using agents to verify this through mock interactions before proceeding to actual users. I can also imagine a trusted and competition assistant could act as a cultural translator to insulate the user from offense as well as inform downstream agents of cultural priorities.
Read full reviewShow less
Well-scoped project! Liked the demand-side verification approach and the cultural/behavioral safeguards angle is a nice addition many governance frameworks miss. Next steps would be pushing toward even one fully functional attestation tier (with real signing, not mocked) and making the behavioral criteria testable. Great work for a sprint!
Cite this project
@misc{pagett2026crossborder,
title = {{Cross-Border Agentic AI Compliance (CBAAC): Embedding Regulatory and Cultural Risk Compliance into Agentic Communication}},
author = {Matt Pagett and Tomoko Mitsuoka},
year = {2026},
month = feb,
note = {Submitted to The Technical AI Governance Challenge, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/crossborder-agentic-ai-compliance-cbaac-embedding-regulatory-and-cultural-risk-compliance-into-agentic-communication-p4oo}},
url = {https://apartresearch.com/sprints/projects/crossborder-agentic-ai-compliance-cbaac-embedding-regulatory-and-cultural-risk-compliance-into-agentic-communication-p4oo}
}More from The Technical AI Governance Challenge
- 1st placeView project: LidaSim: Testing AI Policies With Persona-Based Simulations
LidaSim: Testing AI Policies With Persona-Based Simulations
Lida Safety
We simulate well-known figures in AI and politics with agents, scraping large amounts of data to get realistic simulations. Then, we test questions and proposed policies against these public figures, to see which …
- 2nd placeView project: Markov Chain Lock Watermarking: Provably Secure Authentication for LLM Outputs
Markov Chain Lock Watermarking: Provably Secure Authentication for LLM Outputs
MCL
We present Markov Chain Lock (MCL) watermarking, a cryptographically secure framework for authenticating LLM outputs. MCL constrains token generation to follow a secret Markov chain over SHA-256 vocabulary partitions. …
- 3rd placeView project: Political Intelligence for AI Safety: The AI Risk Attitudes Survey (AIRAS)
Political Intelligence for AI Safety: The AI Risk Attitudes Survey (AIRAS)
AIRAS
The AI safety and governance community is making progress on defining red lines around existential risk from advanced AI systems, and building verification infrastructure to support this objective. However, this is only …