What is the EU AI Act?
The European Union (EU) recently finalized their all encompassing legal framework that addresses the risks that AI poses and ensures human-centric AI development. However, the act has sparked controversy over its scope and potential unintended consequences.
The Act takes a risk-based approach in order to categorize AI systems based on the level of risk they pose on society. They are categorized into the following four levels:
Figure 1: EU AI Act Risk Levels
Minimal Risk: The act does not impose new rules for AI that is deemed this level of risk. A majority of AI within the EU falls into this category.
Limited Risk: AI that fall under this category are obligated to be disclosed to humans when introduced into the markets. This allows the person to make an informed decision knowing that they are interacting with a machine.
High Risk: AI that poses serious health risks and/or a threat to basic human rights. High-risk AI systems must follow strict obligations including but not limited to detailed documentation, appropriate human oversight, and cybersecurity measures.
Unacceptable Risk: AI that is considered a clear threat to the safety and livelihood of society.
High-risk AI systems must undergo phases in order to be put on the market. First, it must undergo a conformity assessment and comply with AI requirements that go with it. Then, it must be registered within the EU database as a stand-alone AI system. Finally, a “declaration of conformity” must be signed by the provider. If the AI changes substantially after these steps have been completed, it must repeat the entire process again. The Act also requires that the providers of the AI be upheld to transparency and copyright standards. The power to enforce this Act is given to the European AI Office as well as state authorities.
What are other countries doing?
The European Union is not the only large entity who has tried to approach AI regulation. Other countries have taken other approaches to the problem:
The US has taken the opposite approach to the EU and have consistently been valuing innovation over regulation. Rather than enacting sweeping legislative frameworks like the EU, the U.S. has relied on a patchwork of sectoral policies and voluntary guidelines. This laissez-faire approach has left a majority of ethical standards and risk mitigation to private countries, which has prompted many concerns about accountability and public oversight.
The UK has adopted a more tailored approach to AI governance. Rather than a “one size fits all” approach, the UK focused more on sector-specific guidelines to AI. This flexible model allows regulators to work more closely with industry experts in order to adjust oversight accordingly based on contextual needs. Although it boasts agility and responsiveness, it has also raised many questions about long-term enforceability across all sectors.
Australia has been much more cautious in their regulation due to overwhelming industry support for light regulation in order to avoid hampering technological progress. Instead, the country has used principle-based frameworks with not binding legal obligations behind them. Although it reflects Australia’s desire to support innovations, it has left critical gaps in enforcement and public protection.
Differing from their Western counterparts, China has opted for a state-led model in order to emphasize rapid AI development through centralized human oversight. The government plays an active role setting funding research and strategic priorities, and enforces implementation through bodies such as the Cyberspace Administration of China. This approach not only allows for swift policy execution, but aligns with national goals such as economic growth and national security. However, it raises concerns of surveillance and privacy for the public due to the direct involvement of the government.
The different approaches to AI regulation may prove to be a problem. AI is not confined by borders—it transcends national boundaries and necessitates coordinated regulations and ethical standards. Rather than enacting their own vision on how to regulate AI, countries should be working together to find common ground. Otherwise, the disparities in regulation may lead to regulatory loopholes and undermine regulation.
What is wrong with the Act?
Critics argue that although the Act does aim to ensure safety and accountability, it may do more harm than good. Their main argument boils down to two main problems: industry pushback and population outflow.
According to a recent analysis by DLA Piper, a global law firm with extensive expertise in technology regulation and compliance, many industries have started to push back on the act since the amount of regulations could significantly slow innovation and reduce profit margins. Some have even objected to the legality of these requirements, citing the compliance materials as being against the original intent of the law. These concerns have persisted despite the European Commission’s many provisions that have substantially reduced costs and fees for the industries. However, the pressure has been overwhelming and has made the EU reconsider pushing the Act out. Although these concerns reflect genuine challenges, they also reveal the underlying truth that industry resistance is often less about feasibility and more about preserving profit margins. The pushback signals a reluctance to give up control.
DLA Piper also notes that the EU is worried that with the addition of stricter requirements for AI development, many industries may opt to move their headquarters to another country with more lenient regulations. This would greatly decrease the economic growth of the EU and would lead to the opposite effect that the regulations intended to have. The fear of such an outcome has contributed to calls for pausing and even getting rid of the Act altogether. These concerns shouldn’t stop progress, but instead should motivate the EU to work with outside countries in order to ensure economic competitiveness.
The Act also tries to encompass all of AI ethics within a risk-tiering system—however, that may prove to be much more rigid than necessary. Without some nuance, there is no way to account for context-dependent harms where the problem does not fit nicely within a tier. A one-size-fits-all approach may provide clarity, but on the flip side, it struggles to address the fluid and evolving nature of AI systems. Rather than the technical design of the model, what should also be considered are the outcomes that these designs produce. An algorithm can very well pass all formal checks, yet still produce historical biases. However, bias is not an unsolvable flaw. It can be used as a diagnostic tool in order to see where systems fail, which gives us valuable insight as to the broader structural inequalities within the system. With intentional design, AI systems can be more accurate and equitable.
Additionally, the AI Act also relies on a top-down rollout process. This means that rather than getting engagement from the people that the AI will affect, they instead use experts in the field to draft legislation such as the EU AI Act. These experts often include representatives of large technological firms and governmental AI task forces, which sidelines the perspectives of labor unions, advocacy organizations, and civil society groups. This leaves little room for civic oversight and goes against the reason for the Act entirely—to make sure that the public is knowledgeable and safe from the rapid expansion of AI. Without oversight, the tools made may reinforce structural inequality under the radar. California has already made this step forward by recently signing into law the California AI Transparency Act (NYT 2024). This Act requires companies to disclose whether decision-making tools are being automated or not, and sets a precedent on how states can lead AI systems to be more transparent and accountable.
So, if the regulation is not working, should we just get rid of it altogether?
No, since some regulation is still necessary in order to protect our human rights and help the public feel safe. As proof of this, just last week US lawmakers and policymakers alike voiced concern about the proposed 10 year freeze of state and local AI regulation bill. The rapid growth of AI has left them wary of losing the ability to respond in real time. Their constituents are scared of not just the present but the government’s future ability to respond to growing digital threats. A 10 year freeze would hinder that ability and in turn leave communities vulnerable to technological harm.
Rather than the rigid structure that the EU AI Act proposed, we should instead opt for a more adaptive and empirical based framework. Instead of relying on private companies in order to define the future of AI governance, we should instead give a voice to the individuals and communities who have been displaced by automation and are subject to algorithmic bias. This means creating regulatory processes that can respond to new risks as they emerge rather than trying to anticipate them. Countries such as Canada and Germany have started to use participation models in tech governance in order to foster civic oversight (Government of Canada 2019). Parallel industries such as bioethics and environmental regulation have long incorporated similar oversight mechanisms (NIH 2000). Building a “living document” of AI governance requires not just collaboration across nations, but also a commitment to democratic engagement at every step of the policymaking process.
Despite fierce opposition from industries, public anxiety around AI remains high. This is not just a European concern, as advocacy groups and citizens around the world are voicing the same message that rapid expansion of the digital age cannot come at the cost of safety and accountability.
This global pushback highlights the tension around AI’s biggest problem—how to regulate AI without leaving the public behind. The EU AI Act may be the first major attempt to answer that, but the debate is far from over. What happens next will shape not just the future of technology, but the public trust in it.