Home Technology EU’s New AI Act Regulates Providers, Not Individual Rights

EU’s New AI Act Regulates Providers, Not Individual Rights

197
0
European Union flag waving in front of a modern office building with AI data streams visible in the background.

The European Union’s AI Act, which came into effect on August 1, 2024, operates as a product regulation framework rather than a rights-based statute. This distinction is fundamental to understanding the law’s scope and limitations. Unlike legislation that creates private causes of action for citizens, the Act imposes obligations on those who develop and deploy AI systems in professional contexts.

Under this regulatory structure, individuals are beneficiaries of enforcement actions rather than plaintiffs with direct legal standing. A citizen cannot sue an AI company under this law.

Instead, the Act mandates that providers of high-risk AI systems conduct conformity assessments and meet security and transparency standards. If these requirements are not met, regulators—not individual citizens—take action. The Act’s architects deliberately excluded certain applications. Military, national security, and research uses of AI are exempt.

Non-professional use also falls outside the law’s scope. The focus remains squarely on commercial and institutional deployment, following the same logic applied to consumer products like toasters and car brakes: regulate at the point of supply rather than the point of harm.

A four-tier risk classification system forms the backbone of the regulation. Unacceptable risk applications face outright bans. High-risk systems must undergo rigorous conformity assessments and disclose their capabilities and limitations.

Limited-risk applications face lighter transparency requirements. Minimal-risk applications carry no obligations at all.

An additional category exists for general-purpose AI systems. The Act’s provisions will take effect gradually over a period ranging from six to thirty-six months. This phased implementation allows industry time to adapt and gives regulators opportunity to build enforcement capacity across all twenty-seven member states, each with different legal traditions.

Critics may argue the Act falls short by not granting individual rights or enabling private enforcement. However, the drafters chose a product regulation approach specifically because it can be updated more easily than a rights-based framework and enforced more consistently across diverse legal systems.

The transparency obligations for limited-risk applications deserve particular attention. Providers must clearly articulate what their systems can and cannot do. While not burdensome, this requirement forces companies to define their technology’s boundaries, potentially reducing overclaiming and misrepresentation in the marketplace.

The Act covers most AI systems across numerous sectors, though the exemptions for military, national security, research, and non-professional use are significant. The law targets AI deployed by businesses and public bodies to perform work, where systemic harm risks are greatest.

With the law now in force, providers of high-risk systems must begin conformity assessments. The phased rollout means different obligations will apply at different times, but the trajectory is clear: Europe has chosen to regulate AI as a product, not as a set of individual rights, a decision that will shape technological development in the EU for years to come.