Ethics and bias · Read 8 min

AI regulation, explained for people who are not lawyers

Europe classifies it by risk; others move more slowly. No legal jargon: what is changing and what you should watch as a user or a company.

Regulating artificial intelligence is, deep down, a simple exercise: instead of asking "what technology is this?", lawmakers ask "how much harm can it cause if it goes wrong?". The more possible harm, the more rules. That shift, from regulating the machine to regulating the risk, is the idea Europe turned into law in 2024 and that now sets the pace for the rest of the world. Everything else is a detail of that same question.

For years the conversation about rules for AI was pure conference smoke: pretty principles, statements of good will, no consequences. That is over. In 2024 the first broad legal text with teeth appeared, and suddenly companies all over the world had to ask themselves something very concrete: does what I am building force me to comply with someone? Here is the map, without the legal Latin.

01 · the ideaRegulate by risk, not by technology

The approach that won the day is called risk based regulation. Instead of writing one rule for "chatbots" and another for "image models" (technologies that change every six months and would leave the law obsolete at birth), each use of AI is classified according to the harm it could cause people. A spam filter and a system that decides who gets a loan are broadly the same "technology", but they do not play in the same league of consequences.

Europe formalized this idea in four levels. Think of them as a traffic light with an extra step: what is banned, what is watched closely, what only needs to be transparent, and what is left free.

The question is no longer what the machine does, but who it can harm if it fails.

Figure 1 · the four risk levels of the European regulation
UNACCEPTABLE HIGH RISK LIMITED RISK MINIMAL RISK banned strict obligations notify the user no new rules
The higher up, the more possible harm and the more obligations. Most everyday uses (a text corrector, a music recommender) fall at the base: minimal risk, no new rules.

This design has a political virtue: almost nobody argues that a system that gives citizens a social score should be allowed, nor that a spam filter should be left alone. The fight, as we will see, is on the middle step.

02 · the textWhat the European law actually says

The rule is called Regulation (EU) 2024/1689, better known as the AI Act. It was published in the Official Journal of the European Union on 12 July 2024 and entered into force on 1 August of that year [1]. It does not all apply at once: it arrives in stages over several years, and that phased calendar is exactly what is worth watching.

The first thing to activate were the bans. Since 2 February 2025 the European Union has prohibited certain uses considered incompatible with fundamental rights [1]: social scoring in the style of a ranking of citizens, subliminal manipulation to alter behavior, or the mass and indiscriminate scraping of faces from the internet to build facial recognition databases. These are the uses at the red tip of the pyramid.

The heart of the law, however, is high risk. That is where systems that decide on serious matters fall: access to education, hiring, credit scoring, medical devices, infrastructure management. They are not banned, but to sell or operate them you must meet concrete obligations: technical documentation, reviewable training data, real human oversight, event logging and a conformity assessment before reaching the market.

Figure 2 · what each level requires (practical summary)
Obligations by risk level in Regulation (EU) 2024/1689. Explanatory summary; the legal text prevails over this table.
LevelExample usesWhat the law requires
UnacceptableSocial scoring, subliminal manipulation, mass scraping of facesBanned in the EU
HighHiring, credit, education, medical devicesDocumentation, reviewable data, human oversight, pre market control
LimitedChatbots, generated images or videosDisclose that you are interacting with an AI or that the content is synthetic
MinimalSpam filters, recommenders, video gamesNo new obligations
Source: Regulation (EU) 2024/1689 (European Union AI Act) [1]. Classification depends on the use, not on the product name.

For the ordinary citizen, the level that shows up most is limited risk: the transparency obligation. If you talk to a chatbot, they have to tell you. If an image or a video was generated by AI, they have to label it. The idea is simple and as old as journalism: you have the right to know whether what you see is real or fabricated.

A nuance that confuses many: the reach

The AI Act is European, but its radius is wider than it looks. It reaches any company, wherever it is, whose AI system is used or whose outputs affect people inside the European Union. It is the same mechanism that made the GDPR data regulation famous: a Latin American startup that sells a hiring system to a client in Spain lands on the radar. That is why it is worth reading even if you do not live in Europe.

03 · the rest of the worldThose moving more slowly (and why)

Europe legislated with a binding regulation. The rest of the world, for now, prefers a different path: voluntary frameworks and sector by sector rules, not a single law. It is not necessarily laziness; it is a different political bet on how not to smother innovation while learning from the field.

In the United States, instead of a broad federal law, the most cited instrument is the NIST AI Risk Management Framework, published in January 2023. It is a technical, voluntary guide to help organizations identify and manage the risks of their AI systems [2]. It does not bind anyone on its own, but it has become a de facto standard that many contracts and insurers already require.

Before all of them, in 2019, the OECD adopted the Principles on AI, the first set of intergovernmental standards on the subject, adopted by dozens of countries and updated in 2024 [3]. They are not law, but they are the common vocabulary (transparency, robustness, accountability, human oversight) that almost every national regulation that came afterwards draws from.

The map, then, is not "Europe regulates and the others do not". It is "Europe chose binding rules and most chose, for now, voluntary guides and sector laws". Two speeds, same direction: that high impact AI is held accountable.

04 · youWhat you should watch, whether user or company

Let us get down to specifics, which is where this conversation stops being news and starts to matter to you.

If you are a user, you have two rights you can already exercise where the European law applies, and that are worth demanding everywhere: knowing when you are talking to a machine and not a person, and knowing when a piece of content was generated by AI. If a system makes an important decision about you (a loan rejection, a screening rejection), you have grounds to ask for an explanation and a human review. They will not always give it with a smile, but the framework exists.

If you run a company, the operational question is only one: which step of the pyramid does what I use or build fall on? A sales email drafted by AI is minimal risk and forces nothing new on you. A system that screens resumes or sets prices for specific customers can escalate fast. Before fearing fines, take the inventory: which AI systems you use, what they decide, and who they affect if they get it wrong.

You do not need a lawyer to take the first step: you need an honest list of what AI decides in your operation.

That inventory (which systems, with what data, deciding what about whom) is the basis both of compliance and of responsible AI in general. Curiously, almost everything the law requires matches what any sensible organization would want to know about its own tools even if there were no law at all.

The regulation of artificial intelligence will keep changing; the European deadlines stretch over years and other countries will publish their own rules. But the compass is already set and easy to remember: the more possible harm, the more accountability. Whoever understands that sentence understands, without being a lawyer, almost everything that is coming.

Sources

  1. European Parliament and Council of the European Union (2024). Reglamento (UE) 2024/1689 por el que se establecen normas armonizadas en materia de inteligencia artificial (Ley de Inteligencia Artificial). Official Journal of the European Union, 12 July 2024; in force since 1 August 2024. EUR-Lex: eur-lex.europa.eu/eli/reg/2024/1689/oj.
  2. National Institute of Standards and Technology, USA (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1, January 2023. doi.org/10.6028/NIST.AI.100-1.
  3. OECD (2019, updated 2024). Recommendation of the Council on Artificial Intelligence (OECD/LEGAL/0449). OECD Principles on AI. oecd.ai/en/ai-principles.

Learn more about AI

See all Learn AI