TY - JOUR
T1 - From policy to action: a cross-regulatory conceptual framework to address data and AI regulations
AU - Yu, Fangzhou
AU - Carton, Fergal
AU - Xiong, Huanhuan
N1 - © 2026, The Author(s). Published by Informa UK Limited, trading as Taylor & Francis Group. This is an Open Access article distributed under the terms of the Creative Commons Attribution License (http://creativecommons.org/licenses/by/4.0/), which permitsunrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited. The terms on which this article has been published allowthe posting of the Accepted Manuscript in a repository by the author(s) or with their consent.
PY - 2026/5/17
Y1 - 2026/5/17
N2 - Organisations operating in data- and AI-intensive environments face an increasingly fragmented and overlapping EU regulatory landscape, including the GDPR, AI Act, etc. Existing research largely addresses these regimes in isolation, offering limited guidance on integrated organisational compliance. This study develops a cross-regulatory integration framework that translates multi-regulatory obligations into structured organisational capabilities, explicitly assigning clear actors and responsibilities. Drawing on Actor-Network Theory (ANT) and a Strategic-Tactical-Operational (STO) decision-layer model, this study conceptualises compliance as a networked and multi-level governance process. The framework supports organisations in aligning ethical criteria, technical controls, and governance responsibilities across regulatory domains, advancing enterprise-wide digital governance and compliance management through both operational and functional processes.
AB - Organisations operating in data- and AI-intensive environments face an increasingly fragmented and overlapping EU regulatory landscape, including the GDPR, AI Act, etc. Existing research largely addresses these regimes in isolation, offering limited guidance on integrated organisational compliance. This study develops a cross-regulatory integration framework that translates multi-regulatory obligations into structured organisational capabilities, explicitly assigning clear actors and responsibilities. Drawing on Actor-Network Theory (ANT) and a Strategic-Tactical-Operational (STO) decision-layer model, this study conceptualises compliance as a networked and multi-level governance process. The framework supports organisations in aligning ethical criteria, technical controls, and governance responsibilities across regulatory domains, advancing enterprise-wide digital governance and compliance management through both operational and functional processes.
KW - Actor-Network Theory
KW - AI ACT
KW - Cross-regulatory compliance
KW - GDPR
KW - [CUBS]
UR - https://www.scopus.com/pages/publications/105038958964
U2 - 10.1080/12460125.2026.2669329
DO - 10.1080/12460125.2026.2669329
M3 - Article
AN - SCOPUS:105038958964
SN - 1246-0125
VL - 35
SP - 1
EP - 10
JO - Journal of Decision Systems
JF - Journal of Decision Systems
IS - 1
M1 - 2669329
ER -