DATASCI 101: Introduction to AI Applications

Lecture 18: AI Regulation and Standards Around the World

Danilo Freire

Department of Data and Decision Sciences
Emory University

Welcome back! 🌍

Recap of last class

  • Last time: bias in AI systems, and who pays for it
  • Robert Williams, Detroit 2020: a facial recognition match, 30 hours in a cell
  • Six types: historical, representation, measurement, aggregation, evaluation and deployment
  • Delete race from the data and the proxies do the work: ZIP code, test scores
  • The impossibility theorem: no model satisfies every fairness criterion at once
  • Today: fairness is a values question, so how are governments responding?

Lecture overview

What we will cover today

Part 1: Why regulate AI?

  • The case for government intervention
  • Different regulatory philosophies

Part 2: The EU AI Act

  • Risk-based approach
  • Prohibited, high-risk, and low-risk systems
  • Compliance requirements

Part 3: The US approach

  • Sectoral regulation vs comprehensive laws
  • Executive orders and agency guidance
  • State-level initiatives

Part 4: Other approaches

  • China’s AI regulations
  • The global race for AI governance
  • What this means for practitioners

Meme of the day 😄

Source: r/agi

Why regulate AI? 🤔

The case for intervention

Market failures:

  • Information asymmetry: users can’t evaluate AI systems
    • How accurate is this hiring algorithm? Nobody knows
    • Is this chatbot hallucinating? Hard to tell
  • Externalities: harms fall on people who never chose the system, like deepfake victims
  • Collective action problems: company A deploys unsafe AI, company B must follow or lose market share

Rights and dignity:

  • Some uses violate fundamental rights
  • Facial recognition in public spaces
  • Manipulation of democratic processes

“Move fast and break things” maybe works for social media features. It’s less appealing when the things being broken are people’s careers (or even lives)!

The case against (heavy) intervention

Innovation concerns:

  • Regulation slows development
  • Compliance costs burden small companies
  • Innovation may move to laxer jurisdictions

Technical challenges:

  • Technology moves faster than law
  • General-purpose systems defy categorisation
  • Enforcement needs technical expertise

Existing laws may suffice:

  • Discrimination and consumer protection laws already apply
  • The question is where to draw the line and who gets to draw it

Source: X.com

Regulatory philosophies

Approach Philosophy Example
Precautionary Prove safety before deployment EU AI Act’s prohibited uses
Innovation-first Regulate only after harms emerge Early US approach to internet
Risk-based Stricter rules for higher-risk uses EU AI Act’s tiered system
Sectoral Different rules for different industries US healthcare vs finance AI
Self-regulation Industry develops own standards Many current AI ethics guidelines

No single approach dominates

  • EU leans precautionary/risk-based
  • US leans sectoral/innovation-first (but changing)
  • China mixes state control with innovation goals
  • Most countries are still figuring it out

The EU AI Act 🇪🇺

The world’s first comprehensive AI law

Timeline:

  • April 2021: European Commission proposal
  • December 2023: deal struck; March 2024: Parliament vote
  • August 2024: Entry into force
  • 2025: Bans (February) and General Purpose AI rules (August) apply
  • July 2026: Digital Omnibus delays high-risk rules to December 2027 (August 2028 for products)

Scope:

  • Extraterritorial reach: any AI sold in the EU, wherever it was built
  • Covers providers, deployers, importers, distributors
  • The EU market is large, so many companies may apply EU rules worldwide

Approach:

  • Risk-based: rules depend on potential harm
  • Horizontal and technology-neutral: all sectors, no named techniques

The risk pyramid

Unacceptable risk (banned):

  • Social scoring, public or private
  • Real-time face ID in public by police (with exceptions)
  • Emotion recognition at work and school
  • Predictive policing by profiling alone
  • From December 2026: nudifier apps and AI child abuse imagery

High risk (strict requirements):

  • Biometric identification
  • Critical infrastructure
  • Employment and worker management
  • Essential services (credit, insurance)
  • Law enforcement and border control
  • Justice and democratic processes

Limited risk (transparency only):

  • Chatbots (must disclose AI)
  • Emotion recognition (must inform)
  • Deep fakes (must label)

Minimal risk (no requirements):

  • Most consumer applications: spam filters, video games, etc

High-risk system requirements

Before deployment:

  • Conformity assessment and risk management system
  • Technical documentation
  • Logging and traceability

During operation:

  • Human oversight capability
  • Accuracy, robustness, cybersecurity
  • Register in EU database; report serious incidents

For deployers (users of high-risk AI):

  • Follow the instructions and ensure human oversight
  • Monitor for issues and inform affected individuals

Data governance:

  • Training data: relevant, representative, as error-free as possible
  • Must be examined for biases
  • Must demonstrate compliance

Transparency:

  • Clear information on capabilities and limitations
  • Instructions for use
  • Contact details for oversight

General-Purpose AI (GPAI) rules

The Act sets special rules for foundation models like GPT-5, Claude, and Gemini

All GPAI providers must:

  • Maintain technical documentation
  • Provide information to downstream deployers
  • Respect copyright, including creators’ opt-outs
  • Publish training content summaries

“Systemic risk” GPAI (more powerful models) must also:

  • Conduct model evaluations including adversarial testing
  • Assess and mitigate systemic risks
  • Track and report serious incidents
  • Ensure adequate cybersecurity

Open-source models: a partial exemption

  • Release weights under a free licence and you skip the documentation duties
  • You must still respect copyright and publish a training summary
  • Models of systemic risk (over 1025 FLOPs) still face the stricter tier
  • Open models allow independent scrutiny, a partial substitute for regulatory oversight
  • Supports European open-source research

Criticism:

  • A potential loophole: open models can still cause harm once third parties deploy them
  • The deployer bears responsibility, but small deployers may lack resources to comply

Example: Mistral is a French AI company that releases many open models. Epoch AI estimates its largest (like Mistral Large) passed the systemic-risk threshold, so they face the stricter rules. Its smaller open models would be largely exempt.

Penalties and enforcement

Maximum fines:

Violation Max fine
Prohibited AI practices €35M or 7% global turnover
High-risk non-compliance €15M or 3% global turnover
Incorrect information €7.5M or 1% global turnover

For comparison:

  • GDPR (General Data Protection Regulation) maximum: €20M or 4% turnover
  • EU AI Act is stricter for the worst violations

Enforcement:

  • National market surveillance authorities
  • New AI Office at EU level for GPAI
  • Complaints mechanism for affected individuals
  • Regulatory sandboxes for testing

Source: BBC News (a competition probe, not an AI Act case)

For a company like Google (2024 revenue ~$350B), a 7% fine would be ~$24.5 billion. That gets attention.

Where would these fit? 🤔

Quick reference for the four risk levels:

  • Prohibited: uses that threaten fundamental rights
  • High risk: affects safety or fundamental rights in specific domains
  • Limited risk: interacts with people directly, so users must be told they are dealing with AI
  • Minimal risk: low-stakes uses with no specific requirements
  1. ChatGPT used for customer service
  • Limited risk – must disclose it’s AI
  1. An AI system that scores job applicants
  • High risk – employment decisions
  1. Spotify’s music recommendation algorithm
  • Minimal risk – entertainment
  1. Facial recognition at airport security
  • Depends: scanning crowds is high risk; a 1:1 passport check is not

The classification often depends on context and use, not just the technology itself

The US approach 🇺🇸

No comprehensive federal AI law (yet)

The US took a different path from the EU: no single AI authority

Sectoral approach:

Recent developments:

Philosophy:

  • Innovation-friendly compared to EU
  • Voluntary commitments from companies
  • Existing laws apply to AI uses

Source: Law.com

Biden’s Executive Order (2023)

Requirements:

  • Developers of powerful AI must share safety test results with government
  • Standards for red-teaming AI systems
  • Guidelines for watermarking AI-generated content
  • Protections against AI-enabled fraud

Focus on national security:

  • Report large training runs
  • Cloud providers must report foreign customers
  • Protect critical infrastructure

Limitations:

  • The next president can reverse it (and did!)
  • Many provisions are voluntary or guidance
  • Congress hasn’t passed comprehensive legislation

Biden’s AI meeting, June 2023. Summary: Congress.gov

America’s AI Action Plan (2025)

Priorities:

  • American AI dominance over global competitors
  • Reduce regulatory barriers to development
  • Focus on national security applications
  • Energy infrastructure for AI data centres
  • Streamlined permitting for AI facilities
  • March 2026 framework: asks Congress to pre-empt state AI laws

Changes from Biden era:

  • Less emphasis on AI safety requirements
  • More focus on competition with China
  • Voluntary industry commitments over mandates
  • Concern about “overregulation” slowing innovation

Implications:

  • US-EU regulatory divergence may increase
  • Companies face different rules in different markets
  • “Race to the bottom” concerns
  • Debate continues about appropriate balance

State-level action

With limited federal action, states are filling gaps:

Colorado AI Act (2024):

  • First comprehensive state AI law, with impact assessments
  • Replaced in May 2026 by a narrower law: notices, explanations, human review (from 2027)

California:

  • SB 53 (2025): frontier AI developers must publish safety plans and report incidents
  • Often sets national trends

Illinois and New York City:

Executive Order 14365 (December 2025) tells the Justice Department to challenge state AI laws. Companies want one federal rule, not a patchwork.

Global perspectives 🌏

China’s AI governance

China has been very active on AI regulation:

Features:

Contradictions:

  • Regulates facial recognition but deploys it extensively
  • Restricts AI manipulation but uses AI for surveillance
  • Rules for companies, exceptions for government
  • Innovation priorities clash with content control

Source: Corporate Compliance Insights

China’s approach: regulate commercial AI carefully, but state use is largely unrestricted

Other approaches

United Kingdom:

Canada:

Brazil:

International coordination:

Initiative Focus
OECD AI Principles Soft law, voluntary
G7 Hiroshima Process International norms
UN Scientific Panel on AI Global evidence, dialogue
Council of Europe AI Convention Human rights focus
ISO/IEC 42001 Technical standards

No global consensus on AI governance. The “Brussels Effect” (EU rules becoming global standards) may apply, as with GDPR.

Comparing approaches

Aspect EU US China UK
Framework Comprehensive law Sectoral Multiple regulations Guidance + sectors
Philosophy Risk-based, precautionary Innovation-first State control + innovation Pro-innovation
Enforcement AI Office + national bodies Existing agencies Cyberspace Admin Sector regulators
Prohibited uses Social scoring, some biometrics Few explicit bans Political content Minimal
GPAI rules Yes, tiered Voluntary (federal) Yes, content-focused AI Security Institute
Extraterritorial Yes Limited Yes No

The EU passed the first comprehensive, binding law; South Korea’s and Vietnam’s took effect in 2026. If your company sells AI in both the EU and the US, you will need two separate compliance strategies.

What this means for practitioners

Practical implications

If you’re building AI systems:

  • Know your use case classification
  • Document training data and development
  • Build in human oversight
  • Plan for audits early

If you’re deploying AI systems:

  • Understand what system you’re using
  • Ensure appropriate human review
  • Inform affected individuals
  • Know your liability

If you’re affected by AI systems:

  • You may have transparency rights
  • Challenge automated decisions
  • Report problems to authorities

Compliance as competitive advantage:

Companies that document their data and build in oversight now will have less to fix later

The regulatory trajectory

Where we’re heading:

  • More jurisdictions will regulate AI
  • Convergence likely around high-risk categories
  • Interoperability challenges will persist
  • Technical standards will matter more

Open questions:

  • Can regulation keep pace with technology?
  • What about AI systems that don’t fit categories?

What we do know:

  • Every major economy is working on AI rules
  • Companies that sell globally will face multiple regimes
  • The EU’s rules will likely shape other countries, as GDPR did for data protection

Source: LinkedIn

Summary

Main takeaways

Why regulate?

  • Market failures: information asymmetry, externalities
  • Rights protection and human dignity

EU AI Act

  • World’s first comprehensive AI law
  • Four risk tiers, strict rules for high-risk systems
  • Fines up to 7% of global turnover

US approach

  • Sectoral rules, no comprehensive law
  • States filling the gaps
  • Innovation-first philosophy

Global picture

  • No international consensus
  • EU likely to set de facto global standards
  • China extensive but contradictory

For practitioners

  • Know your use case classification
  • Build compliance in from the start
  • Document everything and plan for human oversight

How do you hold someone accountable for a decision made by a machine? Every framework we covered today is trying to answer that!

… and that’s all for today! 🎉