
In AI trade, what exactly is being regulated?
Tokens vs. Content
Once you understand that tokens are the billing unit of AI services, a naive-sounding question follows: are tokens "data"? Can they be freely "imported and exported"? The question cuts straight to the core of AI regulation: Tokens themselves are not the object of regulation. The content they carry is.
Think of it this way: no law regulates the "liter" as a unit. The law cares about what's in the barrel — gasoline or milk. Likewise, when you call a foreign AI API, what actually crosses the border is your input and the model's output. Tokens are just how we count it.
Three Jurisdictions, Three Philosophies
Three jurisdictions, three philosophies (a simplified framework — in practice, all three keep borrowing from and adjusting to each other):
🇨🇳 China regulates data leaving the country. Under its data laws, sending text to an overseas AI API is, legally, a "cross-border data transfer" — requiring a security assessment, standard contract, or certification. This is a key reason foreign models face high compliance hurdles in China. Notably, recent rules are getting more specific about AI training data exports.
🇪🇺 The EU regulates personal data. GDPR's premise: individuals control their own data, and that control doesn't expire at the border. If an AI prompt or output contains identifiable personal information, cross-border API calls fall under GDPR.
🇺🇸 The US regulates the upstream. Not conversations — strategic assets: advanced chips and model weights, treated like precision machine tools under export controls. (Whether model weights should be export-controlled at all remains hotly debated, and the rules keep shifting.)
In short: China and the EU regulate the water flowing through the pipes. The US regulates the equipment that builds the waterworks.
How Rules Shape the Market
** These rules aren't just compliance homework — they actively shape the market: → Market fragmentation. Because sending data abroad triggers regulation, foreign models can't simply enter strictly regulated markets. Local models get a layer of institutional shelter — much like non-tariff barriers in traditional trade. → Compliance as a real cost. For enterprise buyers, adopting AI now means legal assessments, data classification, and localization plans. All of that goes into the total cost of ownership — and it's why "private deployment" has become a business of its own. → Supply chain as leverage. Export controls on chips and model weights decide which countries can even train frontier models. This is no longer a consumer question; it's industrial policy played between states.
The Answer in Two Halves
So, back to the opening question — the answer has two halves: No, an API call won't be stopped for "containing tokens." But yes, if the content it carries — personal information, sensitive data — moves from servers in one jurisdiction to another, it falls squarely under cross-border data rules.
Regulators target two things: the information itself, and the upstream assets that produce it — never the unit of measure. Trade law governs the cargo, not the "tons" and "boxes" it's counted in.
Put this together with cost and pricing, and you get the full picture of AI economics: markets set the price; regulation sets the boundaries.
Takeaways
Tokens themselves are not the object of regulation. The content they carry is.
In short: China and the EU regulate the water flowing through the pipes. The US regulates the equipment that builds the waterworks.
Trade law governs the cargo, not the "tons" and "boxes" it's counted in.
Was this useful?