The regulation of artificial intelligence

Giusella Dolores FinocchiaroView original
HighlightsBalancedlynda voice
Alan Turing posed his famous test in 1950 to sidestep an unanswerable question — not "can a machine think?" but "can we tell the difference?" Seventy years later, the European Union is still wrestling with the same problem. Before you can write a law governing artificial intelligence, you have to define what it is. Giusella Finocchiaro opens by insisting that definition is not a formality — it is where regulation either succeeds or fails. She finds Turing's framing still most convincing: rather than define intelligence directly, Turing assessed outcomes. If a process requires intelligence when done by a human, call it intelligent when done by a machine. Finocchiaro also flags Floridi's blunter alternative — "I know it when I see it." While this might be honest, it is a liability in a courtroom. Her deeper worry is anthropomorphism. Words like "learning" and "intelligence" quietly import assumptions about subjectivity. Those assumptions can warp legal reasoning before a single clause is drafted. With that problem established, she poses the fork every regulator faces: do you pass one horizontal law covering artificial intelligence as a whole, or regulate specific applications sector by sector? The EU's April 2021 proposal took the first path. Finocchiaro argues that this choice is as much geopolitical as it is philosophical. Europe is not an artificial intelligence powerhouse. The EU accounts for just seven percent of global annual investment in artificial intelligence and blockchain, while eighty percent sits in the United States and China, leaving an estimated ten billion euro gap. So the EU did what it had done with data protection — it moved to write the rules. The General Data Protection Regulation became the template, an instance of what scholar Anu Bradford calls the "Brussels effect": setting global standards through market leverage rather than technological dominance. The Artificial Intelligence Act's extraterritorial scope follows exactly that playbook. Finocchiaro contrasts this with the United States' self-regulatory model and China's state-directed approach, making clear that artificial intelligence governance is a soft-power competition, not merely an ethics debate. The regulation layers a three-tier risk system on top of four existing pillars — data protection law, digital services and markets rules, digital identity frameworks, and the Artificial Intelligence Act itself. Unacceptable-risk applications, like social-scoring systems and real-time biometric surveillance in public spaces, are banned outright. High-risk systems face conformity assessments, logging requirements, and human oversight interfaces. Lower-risk applications mostly require transparency: tell people when they are talking to a machine or watching a deepfake. Finocchiaro identifies structural problems with all of this. A horizontal classification system freezes today's categories into tomorrow's law. The compliance burden — documentation, certification, notices — falls regardless of company size, and small firms and startups bear costs that the proposal's fee-reduction provisions do not adequately offset. Certification also substitutes for individual rights, routing protection through existing General Data Protection Regulation tools like access and erasure rather than enforceable artificial intelligence-specific remedies. And liability has been deferred to the separate Artificial Intelligence Liability Directive, which adopts a fault-based, minimum harmonization approach limited to burden-of-proof rules, leaving substantive gaps unresolved. The tension at the heart of this project is the one Finocchiaro identified at the start. She warns the regulation will "inevitably be subject to review." The Brussels effect may export these rules globally — but if the rules themselves age poorly, the export accelerates the problem. This lecture was created by ennepō. Go to https://ennepo.ai to Discover, Create and Follow the latest research in your field. Read when you can. Listen when you want to.

Alan Turing posed his famous test in 1950 to sidestep an unanswerable question — not "can a machine think?" but "can we tell the difference?" Seventy years later, the European Union is still wrestling with the same problem. Before you can write a law governing artificial intelligence, you have to define what it is. Giusella Finocchiaro opens by insisting that definition is not a formality — it is where regulation either succeeds or fails. She finds Turing's framing still most convincing: rather than define intelligence directly, Turing assessed outcomes. If a process requires intelligence when done by a human, call it intelligent when done by a machine. Finocchiaro also flags Floridi's blunter alternative — "I know it when I see it." While this might be honest, it is a liability in a courtroom. Her deeper worry is anthropomorphism. Words like "learning" and "intelligence" quietly import assumptions about subjectivity. Those assumptions can warp legal reasoning before a single clause is drafted. With that problem established, she poses the fork every regulator faces: do you pass one horizontal law covering artificial intelligence as a whole, or regulate specific applications sector by sector? The EU's April 2021 proposal took the first path. Finocchiaro argues that this choice is as much geopolitical as it is philosophical.

Europe is not an artificial intelligence powerhouse. The EU accounts for just seven percent of global annual investment in artificial intelligence and blockchain, while eighty percent sits in the United States and China, leaving an estimated ten billion euro gap. So the EU did what it had done with data protection — it moved to write the rules. The General Data Protection Regulation became the template, an instance of what scholar Anu Bradford calls the "Brussels effect": setting global standards through market leverage rather than technological dominance. The Artificial Intelligence Act's extraterritorial scope follows exactly that playbook. Finocchiaro contrasts this with the United States' self-regulatory model and China's state-directed approach, making clear that artificial intelligence governance is a soft-power competition, not merely an ethics debate. The regulation layers a three-tier risk system on top of four existing pillars — data protection law, digital services and markets rules, digital identity frameworks, and the Artificial Intelligence Act itself. Unacceptable-risk applications, like social-scoring systems and real-time biometric surveillance in public spaces, are banned outright. High-risk systems face conformity assessments, logging requirements, and human oversight interfaces. Lower-risk applications mostly require transparency: tell people when they are talking to a machine or watching a deepfake.

Finocchiaro identifies structural problems with all of this. A horizontal classification system freezes today's categories into tomorrow's law. The compliance burden — documentation, certification, notices — falls regardless of company size, and small firms and startups bear costs that the proposal's fee-reduction provisions do not adequately offset. Certification also substitutes for individual rights, routing protection through existing General Data Protection Regulation tools like access and erasure rather than enforceable artificial intelligence-specific remedies. And liability has been deferred to the separate Artificial Intelligence Liability Directive, which adopts a fault-based, minimum harmonization approach limited to burden-of-proof rules, leaving substantive gaps unresolved. The tension at the heart of this project is the one Finocchiaro identified at the start. She warns the regulation will "inevitably be subject to review." The Brussels effect may export these rules globally — but if the rules themselves age poorly, the export accelerates the problem. This lecture was created by ennepō. Go to https://ennepo.ai to Discover, Create and Follow the latest research in your field. Read when you can. Listen when you want to.

More in Social Sciences