Module 05

The European AI Act and the global race

The world's first comprehensive regulatory framework for AI: what it includes, what's missing, and how it compares to other approaches.

9 min3 resources

On 13 March 2024, the European Parliament approved the AI Act — the world's first comprehensive regulatory framework for artificial intelligence. It is a historic moment, comparable to the 2016 GDPR for data protection. Like the GDPR, the AI Act could become a global model — or remain a European exception in a world dominated by more permissive approaches.

The AI Act adopts a risk-based approach. AI systems are classified into four levels. Unacceptable risk: banned systems, such as government social scoring, subliminal manipulation and real-time mass biometric recognition in public spaces. High risk: systems in sensitive areas (justice, healthcare, credit, education, hiring) that must comply with rigorous requirements for transparency, documentation, human oversight and risk management. Limited risk: systems with transparency obligations (e.g. chatbots must declare they are AI). Minimal risk: most AI systems, with no specific requirements.

The AI Act has significant strengths. The ban on social scoring and subliminal manipulation establishes clear limits on unacceptable uses. The transparency requirement for high-risk systems is an important step towards accountability. The requirement for fundamental rights impact assessment for high-risk systems is innovative. And the penalties — up to 7% of global turnover — are potentially deterrent.

But it also has important gaps. Exceptions for national security and law enforcement are broad: facial recognition is banned "in real time" but allowed "retrospectively", a distinction difficult to enforce. The classification of generative systems (like GPT) was subject to lengthy negotiations and the result is a compromise: foundation models have transparency obligations but are not classified as "high risk" by default. Moreover, implementation will be gradual (rules will fully enter into force in 2026) and enforcement will depend on national authorities, with the risk of unequal enforcement across member states.

Globally, approaches vary greatly. The United States has adopted a fragmented approach: presidential executive orders, NIST guidelines, state-level legislative proposals, but no comprehensive federal framework. China has selective regulation: restrictions on deepfakes and data collection, but the government itself is the primary user of AI for surveillance. Post-Brexit UK has chosen a "pro-innovation" approach based on principles rather than specific rules.

Global fragmentation creates a risk of "race to the bottom": countries compete to attract AI companies by lowering standards. Without international coordination — such as that proposed at the Bletchley Park AI Safety Summit in 2023 — the most protective regulations risk being nullified by corporate mobility.

Key takeaways

  • The AI Act classifies AI systems by risk: unacceptable, high, limited, minimal
  • Strengths: clear bans, transparency, penalties up to 7% of global turnover
  • Limitations: security exceptions, compromises on generative models, gradual implementation
  • Global fragmentation creates risks of a "race to the bottom" in regulation

Reflection prompt

Do you think the AI Act is too restrictive, too permissive or balanced? Which AI uses you know of would you classify as "unacceptable risk"? Are there some missing from the AI Act's list?

Further reading