AI regulation (the EU AI Act)
/ AY-eye reg-yoo-LAY-shun, the EE-yoo AY-eye akt /
AI regulation means governments writing enforceable rules about how AI may be built, sold, and used. The most prominent example is the European Union's AI Act, agreed in 2024 — the world's first broad, binding law specifically for AI. Its central design is a risk-based ladder: rather than treating all AI the same, it sorts systems by how much harm they could do and applies heavier obligations the higher the stakes.
The ladder has four rungs. At the top, a short list of uses is banned outright — for example, government "social scoring" of citizens and most real-time face-scanning of crowds in public. Below that sit high-risk systems — AI used in hiring, credit, medical devices, education, or law enforcement — which are allowed but must meet strict duties: risk management, quality data, human oversight, documentation, and transparency. Then limited-risk tools (like chatbots and deepfake generators) mainly carry disclosure duties — you must be told you're dealing with AI or AI-made content. Everything else is minimal-risk and largely unregulated. Separately, the Act adds rules for general-purpose models like large language models.
Why it matters: the Act is a bet that AI can be governed like cars or medicines — with safety requirements proportional to danger — and because of the EU's market size, its rules tend to ripple worldwide (the "Brussels effect"). But be candid about the limits. Laws move slowly while the technology sprints, so rules risk being outdated on arrival; "risk category" lines are contested and lobbied over; and a law on paper means little without inspectors and penalties that actually bite. Regulation is a tool, not a guarantee — and the rest of the world is taking very different approaches, from lighter-touch to none at all.
Under the Act, a company selling AI to screen job applicants is in the high-risk tier: it must document its training data, test for bias, keep logs, ensure a human can meaningfully review decisions, and register the system. Selling the same kind of tool to a school to grade exams falls under the same strict bucket — while a movie-recommendation engine faces almost no obligations.
Same technology, different rules — obligations scale with how much the use could harm people.
Don't confuse the EU AI Act with GDPR. GDPR is the EU's data-privacy law (about personal data); the AI Act is about AI systems and their risks. They overlap but are separate, and the AI Act phases in over several years — so "the EU regulates AI" is true in principle but still partly a work in progress in practice.