From COBOL to agentic AI, governed and built to last.
I help leaders in banking, insurance, healthcare and technology across India, the US, the UK, Europe and Asia move legacy systems into the AI era, govern AI with confidence across every market they serve, and design adaptive systems that keep working. I have built enterprise software since 1988 and written two books on how intelligent systems are really made.
Author · The Algorithms of LifeAuthor · Modernization with IntelligenceForbes Technology CouncilW3C member since 199830+ enterprise implementationsDelivered in 10 countries
IndiaBengaluru--:--—
United StatesSan Diego--:--—
United KingdomEdinburgh--:--—
Three practices
One idea, put to work three ways.
Most AI programs stall between the pilot and production: on legacy systems, on governance, or on designs that break under real use. Each practice tackles one of those blockers. Every engagement is led by me personally.
Modernize
Legacy to AI-native
Move core systems forward without a big-bang rewrite. Decide component by component what to keep, refactor, or replace with AI, and build the business case your CFO will sign.
Anchored in Modernization with Intelligence and COBOL migration work since 1991.
Modernization AssessmentKeep, refactor or replace with AI; roadmap and investment case4 weeks
Program oversightIndependent quality gates and steering for a live programMonthly
Govern
Accountable AI leadership
Give AI a senior owner, a policy and a plan the board understands. Build one program that meets India's DPDP Act, the EU AI Act, UK and US rules and sector regulators, before the auditor asks.
Drawn from board, SEC-compliance and M&A experience.
Global AI Governance Blueprint18-month roadmap, operating model, AI policy, and a map of obligations across your markets on an ISO/IEC 42001 backbone6–8 weeks
Fractional Chief AI OfficerPortfolio, vendors, governance and board reporting2–6 days a month
AI due diligenceFor PE, VC and M&A: AI claims, data rights, regulatory exposure2–3 weeks per deal
Design
Adaptive, agentic systems
Design agentic AI as an ecosystem, not a monolith: the right level of autonomy, real observability, security that behaves like an immune system, and accessibility from day one.
Anchored in The Algorithms of Life and neural-network work since 1998.
Accessible AI reviewWCAG and ADA expectations for AI features and assistants2 weeks
Books · 2026
The thinking behind the practice, written down.
One book looks at what nature teaches AI. The other is a field manual for modernizing enterprise software with AI.
The Algorithms of Life
How Nature's Oldest Code Is Shaping the Future of AI
A nine-chapter exploration of nature, mind and machine intelligence, with reflections on ancient wisdom, mandalas and sutras
Nine chapters that trace deep learning, swarm systems, agentic AI and AI security back to patterns living systems have run for billions of years: evolution, swarms, the brain, the immune system and ecosystems. A closing chapter shows how classical Indian, Chinese and Japanese thought described attention and inference long before AI did.
"Nature is not metaphor for AI. It is blueprint."
Paperback ISBN 979-8-90479-892-5 · Hardcase ISBN 979-8-90560-817-9
Applying the SBOTT™ Model to Re-imagine Applications in the Age of AI
2026 edition · A workbook for technology leaders
A practical guide to moving legacy systems forward without breaking them. It works through every modernization decision with three lenses: AI to modernize the work, AI to improve the product, and AI-leveraged solutions that shrink what needs migrating. It closes with anti-patterns, a 90-day starter playbook and a chapter on building the investment case.
"The cheapest code to migrate is the code you decide not to migrate."
Built around the SBOTT™ model: Strategy, Build, Operate, Train, Transition.
Hear the ideas first: a book talk for your leadership team, a half-day workshop, or the free scorecard below.
Hours
AI Readiness & Risk Diagnostic
Use-case inventory, data and risk review, the five best opportunities and a board-ready readout. Fixed fee.
3 weeks
Assessment or blueprint
A modernization assessment, a governance blueprint or an architecture review, depending on what the diagnostic finds.
3–8 weeks
Ongoing leadership
Fractional Chief AI Officer or program oversight, so the plan actually gets delivered.
Monthly
Speaking
Talks that change how leaders think about AI.
Each talk draws on one of the books and ends with practical steps. Available in person across India, the US and the UK, or online.
From Modernization with Intelligence
The cheapest code to migrate is the code you don't migrate
Why the most valuable question in any modernization is which components to replace with AI instead of moving them, and when not to.
For CIOs, CTOs and CFOsFrom Modernization with Intelligence
Legacy to agentic, without breaking the business
Three lenses on every modernization decision, the autonomy ladder from assistant to agent, and the anti-patterns that sink programs.
For engineering and IT leadershipFrom The Algorithms of Life
Nature is not a metaphor for AI. It is a blueprint.
What evolution, swarms, the brain and ecosystems teach about building AI that adapts, cooperates and lasts.
For executives, boards and general audiencesFrom The Algorithms of Life
Security as an immune system
Layered defense, zero trust and self-healing systems through the lens of biology, and why over-reaction is the most dangerous failure.
For CISOs and security teams
FormatsKeynote, 45–60 minFireside chatHalf-day workshopBoard briefingBook signingInvite me to speak
Available on site
Ready to travel to 83 countries and territories
Based in Bengaluru, and ready to travel to the countries below for talks, workshops and engagements, subject to scheduling. For any other country, please allow extra lead time for visa processing.
Type a country to see how quickly I can be there.
Americas & Caribbean 20
Argentina, Bahamas, Barbados, Belize, Chile, Colombia, Costa Rica, Dominica, Dominican Republic, El Salvador, Grenada, Haiti, Jamaica, Mexico, Panama, Peru, Saint Lucia, Saint Vincent and the Grenadines, Trinidad and Tobago, United States of America
Europe & Central Asia 11
Albania, Georgia, Ireland, Kazakhstan, Kyrgyzstan, Montenegro, North Macedonia, Serbia, Turkey, United Kingdom, Uzbekistan
Middle East & North Africa 6
Bahrain, Egypt, Jordan, Oman, Saudi Arabia, United Arab Emirates (UAE)
Clinical decision support, population health, precision medicine and pharma analytics. Rules to plan for: HIPAA, DPDP for health data, EU AI Act rules for medical devices, and US state limits on AI use by health insurers.
Banking, payments & insurance
Core systems · credit · fraud · claims · open finance
Debit processing, smartcard loyalty and brokerage automation. Rules to plan for: RBI FREE-AI, MAS FEAT, EU high-risk rules for credit scoring, Colorado's automated decision law and fair-lending law.
AI features that pass enterprise security reviews. Rules to plan for: EU transparency duties, content labeling in India, China and Korea, and state chatbot laws in the US.
Global capability centers & investors
GCCs · PE · M&A · board oversight
Indian centers building AI for global parents, and investors assessing AI in deals. One governance program that satisfies every market the group serves.
Global AI, privacy and ethics
Build one governance program that works in every market you serve.
AI and data rules now differ across India, Europe, the UK, the US and Asia, and they keep moving. The good news: they ask for the same few things. I help clients build one program around that common core, then add each market's specifics.
Digital Personal Data Protection Act and DPDP Rules
Binding
Rules notified 14 Nov 2025 · consent managers from 14 Nov 2026 · core duties from 14 May 2027
Notice, consent, security safeguards, breach reporting, children's data and individuals' rights all apply to personal data used to train or run AI. Significant data fiduciaries face audits and extra duties.
India AI Governance Guidelines (MeitY)
Guidance
Released 5 Nov 2025
Seven principles, called sutras: trust, people first, innovation over restraint, fairness and equity, accountability, understandable by design, and safety, resilience and sustainability. India prefers targeted amendments and sector regulators over a single AI law, with an AI Governance Group and an AI Safety Institute.
IT Rules amendments on AI-generated content
Binding
In force 20 Feb 2026
Platforms must label synthetic content clearly, embed metadata where feasible, stop users removing labels, and take down harmful deepfakes within as little as two hours.
RBI FREE-AI framework for financial services
Supervisory guidance
Published 26 Aug 2025
Seven sutras and 26 recommendations for banks and lenders covering governance, audit, incident reporting, bias and data privacy in AI used for credit, fraud and customer service.
EU AI Act
Binding
Prohibitions and AI literacy since Feb 2025 · general-purpose AI since Aug 2025 · transparency since 2 Aug 2026 · Annex III high-risk from 2 Dec 2027 · Annex I from 2 Aug 2028
Risk-based rules with extraterritorial reach: anyone placing AI on the EU market or whose AI output is used in the EU. The 2026 Digital Omnibus delayed the high-risk dates but kept the framework intact.
GDPR
Binding
In force since 2018 · changes proposed in the Nov 2025 Digital Omnibus
Lawful basis for training data, limits on solely automated decisions, data protection impact assessments. Watch the Omnibus proposals on AI training and legitimate interest.
Council of Europe Framework Convention on AI
Treaty
EU ratified 15 May 2026
The first binding international AI treaty, on human rights, democracy and the rule of law. Signed by the EU, UK, US, Japan, Canada and others.
Principles-based, regulator-led approach
Guidance
No single AI Act
The ICO, FCA, CMA, MHRA and others apply five cross-sector principles in their own sectors: safety, transparency, fairness, accountability and contestability.
Data (Use and Access) Act 2025
Binding
Automated decision-making reforms in force 5 Feb 2026
Automated decisions are now allowed on more lawful bases for ordinary data, but people must still be told, able to make representations, get meaningful human review and contest the result. Sensitive data stays tightly restricted.
Federal policy
Executive action
Executive order Dec 2025
No federal AI law. A December 2025 executive order created an AI Litigation Task Force to challenge state AI laws it considers burdensome, while leaving child safety and data-center rules to states.
State AI laws
Binding
More than 100 new state AI laws in the first half of 2026
California and New York require frontier-model safety frameworks and incident reports; 14 states regulate companion chatbots; at least six restrict how health insurers use AI.
Colorado automated decision-making law (SB 26-189)
Binding
Signed 14 May 2026 · effective 1 Jan 2027
Notice before use, an explanation within 30 days of an adverse decision, and human review where reasonable, for AI in employment, lending, insurance, healthcare, housing, education and government services.
Sector rules
Binding
Long-standing
HIPAA for health data, fair-lending and consumer-protection laws for credit and pricing, and existing anti-discrimination law all apply to AI decisions.
South Korea AI Basic Act
Binding
In force 22 Jan 2026 · one-year grace period on fines
Impact assessments and human oversight for high-impact AI, labels on generative AI output, and a local representative for large foreign providers.
China AI content labeling measures
Binding
In force 1 Sep 2025
Visible labels and embedded metadata on AI-generated text, images, audio and video, alongside earlier rules for generative AI services.
Singapore agentic AI framework
Guidance
Launched 22 Jan 2026
Bound agents' risks up front, keep humans accountable, apply technical controls across the life cycle, and be transparent with users. MAS FEAT principles guide AI in finance.
Japan, Vietnam and Taiwan
Mixed
Japan May 2025 · Taiwan Dec 2025 · Vietnam in force 1 Mar 2026
Japan's AI Promotion Act is promotional with no penalties. Taiwan passed an AI Basic Act. Vietnam's AI law sets three risk tiers with fines.
Gulf data protection laws
Binding
Saudi PDPL enforced since Sep 2024 · UAE federal PDPL
Personal data used in AI needs a lawful basis and meets cross-border transfer limits; Saudi Arabia also publishes national AI ethics principles.
Brazil
Pending
AI bill passed the Senate Dec 2024; still in the Chamber
The AI bill is not law yet. The LGPD data protection law already applies to AI.
Canada
Pending
No federal AI law since AIDA lapsed in 2025
Federal and provincial privacy laws apply, including Quebec's rules on notice of automated decisions.
ISO/IEC 42001
Certifiable standard
Published 2023
A management system for AI that auditors can certify. The most practical backbone for a single program across many regimes.
NIST AI Risk Management Framework
Voluntary
2023, with a generative AI profile in 2024
Govern, map, measure, manage. Widely used in the US and by global firms as a shared risk vocabulary.
OECD AI Principles and UNESCO ethics recommendation
Intergovernmental
OECD 2019, updated 2024 · UNESCO 2021
The ethical foundations most national frameworks, including India's sutras, build on: human rights, transparency, robustness, accountability.
Status as at September 2026. Summaries for orientation only; not legal advice. I work alongside your counsel.
The common core: seven things almost every regime asks for
Know your AI and its risk.An inventory and a risk tier for every system: EU risk classes, Korea's high-impact AI, Colorado's consequential decisions.
Tell people.Disclose AI interactions and label synthetic content: EU transparency duties, India's IT Rules, China's labels, Korea's generative AI rules.
Keep a human accountable.Human review and a way to contest decisions: UK automated decision rules, Colorado, the EU AI Act, Singapore's agentic framework.
Protect personal data.Lawful basis, consent and rights: DPDP, GDPR, UK GDPR, HIPAA, PDPL, LGPD.
Test for fairness.Bias testing and non-discrimination: India's sutras, RBI FREE-AI, US anti-discrimination law, EU high-risk rules.
Secure it and report incidents.Security safeguards and breach or incident reporting: DPDP, GDPR, US frontier-model laws.
Document and govern.Policies, records and a named owner: ISO/IEC 42001, NIST AI RMF, the EU AI Act, RBI FREE-AI.
I have lived every era of enterprise computing, from mainframes to agents.
I started writing software in the USA in 1988, built COBOL code translators for clients in Switzerland, Scotland and Japan in the early 1990s, set up neural-network solutions at Computer Associates in 1998, and have led more than 30 enterprise implementations as a CTO. That range is why I can help a bank with a 30-year-old core and a team building AI agents in the same week. Along the way I have delivered work in ten countries across four continents.
I hold an MS and BS in Computer Science from Indiana University of Pennsylvania, sit on the Forbes Technology Council, and have been a W3C member since 1998. I work from Bengaluru, San Diego and Edinburgh.
Five eras, one lesson from each
2009 → nowHealthcare, governance and AI
Accountability lives with people, not models.
As a CTO I have led more than 30 implementations, from hospital systems and pharmacogenetics insight to insurance automation and legal e-discovery, and served on the board through an M&A transaction with Dalrada Financial Corporation.
What it means for youAI governance that a board, an auditor and a clinician can all live with.
2000 → 2019Networks, cloud and automation
Automation you cannot observe is automation you cannot trust.
At Cisco I launched CiscoWorks Small Network Management Solution, an early AIOps platform. The companies I founded next took Data Center in a Box to more than 2,500 installations and moved enterprises onto hybrid cloud.
What it means for youAgentic systems designed with observability and guardrails from day one.
1998 → 2000The first wave of AI
I have seen an AI hype cycle before.
At Computer Associates I founded the company's first Neugents Factory on neural-network technology and built a 70-person team delivering predictive analytics across four continents.
What it means for youClear-eyed advice on what AI will really do for your business, and what it will not.
1995 → 1998Payments and trust
Systems that move money have to be right every time.
At VeriFone I delivered debit card processing for NCR Canada, wrote smartcard loyalty specifications for Visa International and worked with Diebold on ATMs.
What it means for youFinancial-services AI built for fraud, fairness and the regulator.
1988 → 1995Mainframes and migration
Old code holds institutional wisdom.
After starting out in the USA, I built automated COBOL translators at Tata Consultancy Services for the European Broadcasting Union, United Distillers and NTT Japan.
What it means for youModernization that keeps what works and replaces only what should go.
Boards and bodiesForbes Technology CouncilW3C, since 1998Financial Data Exchange (FDX)Metaverse Standards ForumEqualGenius Foundation, BoardRotary International, Past President
AI readiness scorecard · 8 questions · 3 minutes
How ready is your organization to scale AI?
Answer honestly. Your score updates as you go and nothing leaves this page.
Essays · from the books
The Accountable AI Brief
Short, practical essays adapted from my books for leaders who have to make AI work in real organizations.
Modernization · adapted from Modernization with Intelligence, chapter 9
The cheapest code to migrate is the code you don't migrate
Stand in front of a legacy application and ask what it actually does. Not how, but what. A rules engine routing claims. A search bar trying to find a product. A form asking a customer twenty-five questions. When those were built, explicit code was the only way to solve the problem. In 2026, for many of them, there is another path.
Most modernization programs ask two questions: how can AI speed up the migration work, and what AI features should the new product have? The third question is usually worth more: which parts of the legacy system should not be migrated at all, because an AI-leveraged component can do the same job with far less code?
Where AI-leveraged replacement works
Business rules engines. Thousands of accumulated rules become a learned model, an explicit policy layer for anything regulated, and an explanation surface for users and auditors.
Search and knowledge bases. Custom search and FAQ trees become semantic retrieval that understands questions, not just keywords.
Form-driven workflows. Complex, infrequent journeys such as claims or onboarding become guided conversations. Routine forms for expert users stay as they are.
The long tail of reports. Hundreds of rarely viewed dashboards collapse into a natural-language analytics layer. The most-used dashboards remain.
Document processing, data preparation and triage. One document-understanding service replaces many bespoke parsers; classifiers route tickets and alerts, and humans review only the uncertain cases.
A five-question test for every component
What does this component actually do for users or the business?
Which AI-leveraged pattern could serve that function?
Is there enough data of the right quality to support it?
What does a wrong answer cost, and what is the fallback?
Does the replacement cut total cost, add user value, or both?
A component that passes all five is a candidate for replacement. One that fails any of them is migrated the classical way.
When not to replace
Keep deterministic rules as code where a regulator or a contract needs them explained. Be wary of small-looking components that hide years of operational subtlety. And where data is thin or the stakes are high, such as a medical or financial decision, classical engineering and strong human oversight remain the responsible choice.
Done with discipline, the payoff is twofold. In the programs I have seen, components where replacement was appropriate typically saw 20 to 40 percent lower direct migration cost. The new system also gains capabilities the old one never had: a rules engine could never tell you which of its rules contradicted each other. Those savings are paid for with real AI engineering: evaluation harnesses, monitoring, guardrails and governance. Skip that, and the savings come back as incidents.
Execution · adapted from Modernization with Intelligence, chapter 15
Eight ways modernization programs fail
Tolstoy said every unhappy family is unhappy in its own way. For modernization he was wrong: failed programs look strikingly alike. What varies is how the failure was explained at the time. Here are the patterns I see most often, how to spot them and what to do instead.
The big-bang rewrite
Spot it: a multi-year plan with all the value at the end. Fix: a sequence of smaller migrations, each with its own cutover and its own value.
Lift, shift and forget
Spot it: the app moved to the cloud with no refactoring, and the cloud bill is higher than the data center. Fix: budget deeper modernization for the components that need it as a planned phase.
The AI feature parade
Spot it: a feature list that reads like a technology demo. Fix: for every AI feature, name the user, the workflow, the metric and the success test.
The model wrapper
Spot it: an AI feature that is one line of integration code with no retrieval, evaluation or monitoring. Fix: treat every AI feature as a small system in its own right.
The unmonitored agent
Spot it: an agent with broad write access and an audit trail nobody reads. Fix: add autonomy one action at a time, each with a risk review and a way to reverse it.
The last-week training sprint
Spot it: training appears only in the final sprint. Fix: build training into every iteration; AI makes good training content cheap to produce.
The vendor dependency trap
Spot it: one named model vendor at the center of the architecture, with no alternative tested. Fix: vendor-neutral interfaces, and regular proof that the alternatives still work.
Compliance after the fact
Spot it: AI features with no documented compliance review. Fix: a standing compliance gate for every feature, model update and prompt change.
Almost all of these share one root cause: confusing activity with progress. Rewrites, rehosting, feature launches and training videos are activities. Outcomes are what users and the business can do that they could not do before. Keep outcomes in front of every decision, and most of these patterns never get started.
Governance · adapted from Modernization with Intelligence, chapter 10
Assistant, copilot or agent? Pick the lowest level that works
Boards keep asking when their company will "deploy agents". It is the wrong first question. The right one is: what level of autonomy does this problem actually need?
Three levels of embedded intelligence
Assistant. Answers questions and drafts within a session. It sees context but takes no actions. The easiest level to deploy safely, and the most likely to feel bolted on if it is not wired into the product's real data.
Copilot. Works alongside the user: suggests the next step, fills the next field, drafts the next message, and acts only with explicit consent. It blurs who did what, so consent and undo must be designed in.
Agent. Pursues a goal across several steps and systems without constant supervision. The most powerful level and the most dangerous. It needs clear limits on what it may do, what it must escalate, what it must log and how its actions are reversed.
Don't deploy an agent to solve an assistant problem. Each step up adds new ways to fail and new governance to run. Start at the lowest level that solves the user's problem, prove its value, and move up only when trust has been earned.
Design rules that get skipped under deadline
Any action taken for the user needs clear consent that says exactly what will happen.
Undo should sit right next to the AI's output. Irreversible actions, such as payments, need deliberate confirmation.
Write a voice and tone guide covering how the assistant handles uncertainty and admits its limits.
Design for accessibility and multiple languages from day one. An assistant can be one of the best accessibility tools a product has.
Trust ratchets up slowly and breaks quickly. Governance is what lets you climb the ladder without falling off it.
Security · adapted from The Algorithms of Life, chapter 5
Your security stack is trying to become an immune system
While you read this, your body is under attack. Viruses, bacteria and rogue cells are probing your defenses, and you notice none of it. One of the most remarkable distributed systems ever evolved is running quietly in your bloodstream, with no central controller. It learns as it fights and remembers threats it has not seen for decades. Every security team is, knowingly or not, trying to build a digital version of it.
The parallels are close
Signatures are antigens. Fast and precise against known threats, blind to new ones.
Behavioral analytics is innate immunity. It learns what normal looks like and flags what looks wrong, without knowing exactly what it is.
Zero trust is the immune checkpoint. Identity is verified at every boundary; trust is never granted once and for all.
Self-healing infrastructure is tissue repair. Failed components are replaced without central coordination.
Incident playbooks are immune memory. Mature teams encode what they learned so the next response is faster.
Beware autoimmunity
The most dangerous failure of a powerful defense is not missing an attack. It is attacking what it was meant to protect. Over-aggressive automated responses lock out real users, quarantine legitimate services and shut down critical flows. As AI takes over more of security response, precision matters more than power.
The immune system is also calm. Most infections are contained without ever reaching your awareness. A mature security operation should work the same way: most incidents resolved quietly, and only the ones that matter reaching a human. Less alarm fatigue, more signal.
The design principles carry straight over: layered defense instead of a single wall, learning from every encounter, memory that speeds the next response, precise separation of self from non-self, and distributed response because central coordination is too slow. Your body runs the most sophisticated zero-trust architecture ever deployed. It is worth studying.
Agentic AI · adapted from The Algorithms of Life, chapter 6
The future of AI is a forest, not a tree
Walk into a forest and stand still. It is far more than a collection of trees. Nobody designed it and nobody manages it, yet it has stayed productive and resilient over timescales that make our longest-running software look like fireflies.
Until recently most AI behaved like a solitary organism: a prompt went in, an answer came out, and the interaction ended. Agentic AI changes that. Systems now plan, act, observe the result and adjust, over long periods, alongside people and other agents. The question stops being "what does the model output?" and becomes "what does this system of models, tools, people and data do over time?" That is an ecological question.
Three principles from ecology
Diversity is a feature. Monocultures are fragile. A single model on a single data source optimizing a single goal will eventually meet a problem it cannot handle. Diverse agents have blind spots that do not all line up.
Observability is survival. Tracing, logging, evaluation and interpretability are the senses of an AI system. The cost of not seeing your system is measured in surprises.
Small interventions have large effects. Ecologists restore a keystone species rather than rebuild a habitat. In AI, the equivalent is a careful prompt, a better tool or a smarter protocol.
Find your keystone
Remove sea otters from a kelp forest and the urchins they eat multiply until the forest collapses. Your AI stack has keystones too: a single evaluation pipeline, a shared dataset, a coordination protocol. Identify them, protect them and invest in them.
A factory foreman optimizes a known process. A gardener tends a system that changes with the weather: weeding, watching, watering, pruning, and never trying to turn a tomato into a pear tree. The organizations that thrive with agentic AI will stop thinking like model builders and start thinking like gardeners.
Picture a bank that runs AI in India, the UK and the US, with a technology center in Bengaluru serving all three. Its compliance team starts three separate AI projects: one for India's data protection rules, one for the EU AI Act because some customers are in Europe, and one for a patchwork of US state laws. Each has its own spreadsheet, its own consultants and its own deadlines.
That is the expensive way to do it. Read the rules side by side and the same seven requests keep appearing: know your AI and its risk; tell people when AI is involved; keep a human accountable; protect personal data; test for fairness; secure the system and report incidents; and document who owns what.
Build the core once
Put those seven capabilities into one program, ideally on an ISO/IEC 42001 management system with the NIST AI Risk Management Framework as a shared vocabulary. One AI inventory. One risk-tiering method. One set of human-review, testing and incident processes. Then add a thin layer for each market:
India: DPDP notice, consent and breach duties from May 2027, labels on synthetic content under the 2026 IT Rules, and RBI's FREE-AI expectations for lenders.
European Union: AI Act transparency now, high-risk conformity work before December 2027, and GDPR for training data.
United Kingdom: the reformed automated decision rules, with notice, human review and the right to contest.
United States: state laws such as Colorado's automated decision-making law from January 2027, plus HIPAA and fair-lending rules.
Asia-Pacific: Korea's AI Basic Act, China's labeling rules and Singapore's guidance for agentic AI.
India as the bridge
India's global capability centers now build AI for parent companies everywhere. They sit exactly where these regimes meet: Indian data law at home, their parents' market rules abroad. A center that runs the common core well becomes a compliance asset for the whole group, not a risk.
There is a nice echo here. India's AI Governance Guidelines call their seven principles sutras, the same word the ninth chapter of The Algorithms of Life explores: short threads that hold a larger idea together. Good governance works the same way. A few well-chosen threads, applied consistently, hold more than a thousand market-specific rules ever will.