What is actually being regulated about AI?
Increasingly, the use rather than the technology — regulators have largely converged on assessing what a system is used for and how much harm it could cause, rather than attempting to regulate the underlying methods.
The risk-based approach, which the EU AI Act exemplifies and which has influenced thinking elsewhere:
Unacceptable risk — prohibited outright. Includes social scoring by public authorities, manipulative techniques exploiting vulnerabilities, and certain biometric categorisation and untargeted facial image scraping.
High risk — permitted with substantial obligations. Covers systems used in employment, education, credit, essential services, law enforcement, migration and critical infrastructure, plus safety components of regulated products. Obligations include risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, and conformity assessment.
Limited risk — transparency obligations. Users must be told they are interacting with an AI system, and synthetic content must be marked.
Minimal risk — largely unregulated, which covers most applications.
General-purpose models carry their own obligations around documentation, copyright policy and — above a capability threshold — systemic risk assessment.
What applies regardless of any AI-specific law, which people persistently overlook:
Data protection law, covering training data, lawful basis, and rights around automated decision-making with legal or similarly significant effects.
Equality law, since a discriminatory outcome is unlawful however it was produced.
Consumer protection, covering misleading claims about capability.
Sector regulation — financial, medical device, employment — which already governs decisions in those domains.
Product liability and negligence.
Copyright, which is the most actively litigated area and remains unsettled on both training and output.
The different national approaches: a comprehensive statutory regime in the EU; a sector-regulator-led approach in the UK, with existing regulators applying principles within their remits; and a patchwork of state laws and executive action in the US.
The practical position for organisations: inventory your AI uses, classify them by impact, and document decisions. General information, not legal advice.