⚖️ AI Ethics, Society & Careers · Lecture 9 of 17

AI Regulation and Governance: The EU AI Act and Beyond

Governments and organisations are creating rules for AI. We survey risk-based regulation with the EU AI Act, data-protection law, international principles and standards, and how organisations build AI governance in practice.

For years, AI development was governed mostly by voluntary principles. That era is ending. Governments are adopting binding rules, standards bodies are publishing management frameworks, and organisations — including humanitarian and development agencies — are creating internal AI governance. As an AI professional, you need a working knowledge of this landscape: it shapes what you may build, how you must document it, and how you must monitor it.

(This lecture summarises the landscape for educational purposes; it is not legal advice, and regulations evolve — always check the current text and seek legal counsel for specific cases.)

The EU AI Act#

Adopted in 2024, the EU Artificial Intelligence Act is the first comprehensive horizontal AI law. It applies to providers and deployers of AI systems placed on the EU market or whose outputs are used in the EU, with obligations phased in over several years. It follows a risk-based approach:

Risk levelExamplesObligations
Unacceptable (prohibited)Social scoring by public authorities; manipulative techniques exploiting vulnerabilities; untargeted scraping of facial images to build recognition databases; emotion recognition in workplaces and schools (with exceptions); most real-time remote biometric identification in public spaces for law enforcement (narrow exceptions)Banned
High riskAI in critical infrastructure, education (e.g. exam scoring), employment (CV screening), access to essential services and benefits, credit scoring, law enforcement, migration, asylum and border control, administration of justice, certain medical devicesRisk management, data governance, technical documentation, logging, transparency to deployers, human oversight, accuracy/robustness/cybersecurity, conformity assessment, registration, post-market monitoring
Limited risk / transparencyChatbots, deepfakes and AI-generated contentDisclose AI interaction; label synthetic content
Minimal riskSpam filters, AI in video gamesNo specific obligations (voluntary codes)

General-purpose AI (GPAI) models — such as large language models — have their own obligations: technical documentation, information for downstream providers, a copyright policy and a summary of training content; models with systemic risk (very high training compute) face additional duties including evaluations, adversarial testing, incident reporting and cybersecurity.

Note that migration, asylum and border control, and access to public assistance, are explicitly listed high-risk areas — directly relevant to humanitarian and public-service contexts.

Data protection law#

Many AI systems process personal data, so data-protection law applies regardless of AI-specific rules:

  • GDPR (EU) principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability.
  • Special categories (health, biometrics, ethnicity, religion…) require stronger protection.
  • Automated decision-making (Article 22): individuals have rights regarding decisions based solely on automated processing that significantly affect them, including human intervention and contesting the decision.
  • Data Protection Impact Assessments for high-risk processing.

Many countries have comparable laws (e.g. Brazil's LGPD, India's Digital Personal Data Protection Act 2023, and data-protection legislation developing in Bangladesh and elsewhere). International organisations often have their own data-protection policies and frameworks.

Other frameworks around the world#

  • OECD AI Principles (2019, updated 2024) — adopted by many countries.
  • UNESCO Recommendation on the Ethics of AI (2021) — adopted by all UNESCO member states; emphasises human rights, inclusion and environmental sustainability.
  • United States: sector-specific rules and agency guidance, the NIST AI Risk Management Framework (voluntary: Govern, Map, Measure, Manage), and state-level laws.
  • China: regulations on recommendation algorithms, deep synthesis (deepfakes) and generative AI services.
  • Council of Europe Framework Convention on AI and Human Rights (2024) — the first international treaty on AI.
  • International standards: ISO/IEC 42001 (AI management systems), ISO/IEC 23894 (AI risk management).

Building AI governance in an organisation#

Regulation sets the floor; good governance builds on it:

  1. Inventory: know which AI systems you develop, buy and use.
  2. Risk classification: identify high-impact systems (those affecting rights, safety, access to services).
  3. Policies and roles: who approves, owns, monitors and can shut down each system.
  4. Impact assessments: algorithmic/AI impact assessments covering human rights, fairness, privacy and security, with stakeholder input.
  5. Documentation: datasheets, model cards, system cards, decision logs.
  6. Human oversight: meaningful review with authority and competence, not rubber-stamping.
  7. Procurement standards: require documentation, testing evidence and audit rights from vendors.
  8. Incident management: report, investigate and learn from failures.
  9. Training: AI literacy for staff (the EU AI Act includes AI-literacy obligations for providers and deployers).
JA
Written by

Janin A Apurba

B.Sc. in CSE, AUST · Advanced ICT Officer, CNRS-UNHCR. Teaching AI, ML and Deep Learning to the next generation of engineers and researchers.

Keep learning

Related lectures

⚖️ AI Ethics, Society & Careers

AI Security: Data Poisoning, Prompt Injection, Model Theft and Defences

AI systems introduce new attack surfaces. We survey threats across the ML lifecycle — data poisoning and backdoors, evasion, model extraction, privacy attacks, prompt injection and supply-chain risks — and practical defences.

Advanced⏱ 6 min#264
⚖️ AI Ethics, Society & Careers

AI for Humanitarian Action and Social Good

AI can help humanitarian organisations anticipate crises, map needs and serve people in their own languages — but the stakes and risks are exceptionally high. We survey applications, principles, pitfalls and how students can contribute responsibly.

Beginner⏱ 5 min#266
⚖️ AI Ethics, Society & Careers

AI Safety and Alignment: Making Capable Systems Do What We Intend

As AI systems grow more capable, ensuring they pursue intended goals becomes critical. We cover specification gaming, reward hacking, goal misgeneralisation, current alignment techniques, interpretability, evaluations and governance of frontier models.

Intermediate⏱ 6 min#263