As a global race to develop and commercialize artificial intelligence technologies heats up, the European Union has adopted what it claims is the world’s first comprehensive law to regulate AI. Approved by the European Parliament in 2024, the EU AI Act introduces sweeping new obligations for businesses, classifying AI systems according to their intended use and associated risk.
Proponents say it sets an ethical gold standard for the responsible development and use of AI around the world. Critics counter that the legislation could become a bureaucratic straitjacket on Europe’s already struggling digital economy — an innovation-killing echo of the GDPR that will leave the continent’s tech industry on the sidelines.
What Is the AI Act?
The AI Act is a legislative framework that categorizes artificial intelligence systems based on their perceived risk level to individuals and society. Passed in 2024 by the European Parliament, the law requires AI developers and users to meet certain standards depending on the category into which their system falls.
These range from outright bans on “AI practices that have an unacceptable risk” to the rights of European citizens and residents (such as AI-assisted social scoring and manipulative behavioral surveillance) to transparency obligations and human oversight requirements for “high-risk” systems.
Low-risk systems like spam filters are largely exempt. The categories are as follows:
- Unacceptable Risk: Banned outright (AI systems designed to manipulate human behavior in ways that undermine autonomy and consent or systematically exclude people based on sensitive traits or data).
- High Risk: Subject to extensive documentation, human oversight and monitoring requirements (law enforcement, recruitment, hiring, education, health assessment, creditworthiness assessment, critical infrastructure, significant effective systems).
- Limited Risk: Transparency obligations apply, e.g., traceable “gigapixel-scale” or AI-generated content or interactive chatbots (e.g., AI content or chatbots that can impact people’s rights).
- Minimal Risk: All other systems that present minimal or no risk to individuals (e.g., spam filters).
First introduced in 2021, the AI Act was refined over several years and underwent several revisions, with risk categories changing several times before the final version was agreed by the European Parliament in 2024. Rights groups and some tech executives have welcomed the AI Act’s risk-based approach and emphasis on transparency and human control. However, AI Act critics have raised concerns that the new law is too broad, too vague, and overregulates by applying the high-risk label to several applications.
AI Governance Beyond Europe
The EU’s AI Act makes the European Union the first major geopolitical bloc to regulate artificial intelligence at scale. The approach it takes will help set a middle course between the laissez-faire, market-led regime in Silicon Valley and a more surveillance-driven system in China. The emphasis placed on human rights and dignity in the AI Act has drawn praise from human rights and development organizations, which hope it will nudge the global conversation on AI governance in a democratic and ethical direction.
Supporters of the Act claim that, as with the EU’s earlier General Data Protection Regulation privacy law, Europe has a chance to set a global standard. Enshrining a values-based approach to AI development through the use of risk management, human oversight, and transparency requirements, the EU aims to “shape practices beyond its borders” with what one commentator called a form of “regulatory soft power.”
In practice, the EU has most likely missed a key opportunity to set the global tone. While the AI Act was under discussion, other governments from Canada and Japan to Brazil and Nigeria, and supranational organizations like UNESCO and the OECD developed their own proposals to regulate AI. As such, the Act is likely to have a limited influence on other national regulatory approaches, although it is likely to be highly influential in future international treaties and digital trade agreements.
A Bureaucratic Burden for Business?
On paper, the AI Act is an impressively rights-based law. Critics have raised two major concerns. First, the Act could impose a heavy and costly bureaucratic burden on firms that wish to comply, particularly small and medium-sized enterprises and startups. Rules around the development and use of “high-risk” AI systems in law enforcement, education, healthcare, and employment require a wide range of risk management, human oversight, system documentation, and monitoring commitments. Additionally, significant fines are attached to non-compliance.
Opponents say these will place European companies at a disadvantage when competing with firms in other markets that do not face similar regulatory obligations. Second, many question the definition of what constitutes an AI system and a high-risk AI system under the law, which is broader than both those used by leading AI safety and rights experts and previous AI regulations like the U.S. AI Bill of Rights. A wide range of lower-risk technologies are potentially ensnared by the AI Act’s definitions, creating a risk of “overengineering” solutions and hampering the timely deployment of AI systems in healthcare, education, and public transport.
The speed of AI development will also create difficulties for regulators. The EU and its member states must develop new enforcement and monitoring expertise to keep pace with fast-changing and developing AI systems that were not on the horizon when most of the Act was drafted. In short, the Act risks quickly becoming a patchwork of guidelines that are outdated and unworkable in practice.
Europe’s Innovation Dilemma
EU lawmakers have moved to regulate AI amid widespread concerns about Europe’s digital economy. Europe lags well behind the United States, China, and even Russia in AI startups, digital platforms, and homegrown tech giants.
Its ability to regulate the sector responsibly and establish trust in the use of AI technology is crucial to redressing this imbalance. Too heavy a regulatory touch, however, could backfire. As digital markets grow more important, policymakers face the prospect of presiding over a digital economy that they are unable to support domestically, with Brussels instead left to manage the social and economic impact of AI technology developed and controlled elsewhere.
Ethical Leadership or Self-Sabotage?
On the other hand, proponents of the AI Act argue that its rigorous approach will give European firms an edge. In an era of public skepticism about opaque algorithms and biases, major research has shown that consumers and investors are increasingly placing their trust and dollars in ethical businesses.
The Act’s emphasis on human oversight, transparency, and risk management could, with the right implementation, give European companies an important marketable advantage. There is still significant uncertainty over how the law will be implemented and applied in practice. A newly created European AI Office will have significant work cut out for it to coordinate the AI Act’s enforcement across the EU’s 27 member states.
But in both Brussels and local capitals, the law is only as good as the willingness of companies to play ball and go beyond the bare minimum requirements. Without buy-in and an active commitment to the AI Act’s central principles and not just a box-checking mentality, Europe’s AI industry is unlikely to reach its potential.
Conclusion: Blueprint or Bureaucratic Trap?
The EU AI Act has the potential to become the first widely used model for regulating artificial intelligence. At present, there is little real evidence of its impact. What is clear, however, is that the AI Act has reframed the terms of global debate on AI ethics, regulation, and innovation. Whether the AI Act will enhance Europe’s competitiveness or further marginalize its digital economy is yet to be seen.