JSTAcademy
0 XP
Dashboard
Future Systems
The Regulatory Future
13 min
PhD+165 XP
Future Systems · PhD

The Regulatory Future

AI legislation globally, data sovereignty, GDPR, and what's coming in the next 5 years
13 min read+165 XP on completionCert: Future Systems
Tap any word in the text below to start reading from there.

The Regulatory Future

AI regulation is moving from an open, largely ungoverned frontier to a complex, jurisdiction-specific compliance landscape. For businesses deploying AI and individuals working with it, understanding the regulatory trajectory is as important as understanding the technology itself.

The EU's Regulatory Leadership

The European Union has consistently been the most aggressive jurisdiction in regulating technology, and AI is no exception. The EU AI Act, passed in 2024, is the world's most comprehensive AI regulatory framework and will shape global AI governance through what regulators call the "Brussels Effect" the tendency for EU standards to become de facto global standards because companies building for the EU market build compliant products that they then deploy globally.

Risk categorization under the EU AI Act:

  • Unacceptable risk (prohibited): Real-time biometric identification in public spaces, social scoring by governments, AI that exploits psychological vulnerabilities
  • High risk (strict requirements): AI used in critical infrastructure, education, employment, essential services, law enforcement, migration, and administration of justice. These systems must maintain risk management records, use high-quality training data, provide transparency documentation, allow human oversight, and achieve accuracy benchmarks
  • Limited risk (transparency obligations): Chatbots must disclose they are AI; deepfakes must be labeled
  • Minimal risk (largely unregulated): AI in video games, spam filters, most consumer applications

The implementation timeline runs through 2027, with prohibitions on unacceptable-risk systems taking effect first, high-risk requirements phased in over subsequent years.

US Regulatory Approach

The United States has taken a more fragmented approach no comprehensive federal AI law yet, but sector-specific guidance:

  • Executive Order on AI (2023): Required safety assessments for advanced AI models before deployment, established AI safety reporting requirements
  • SEC guidance on AI in financial services
  • EEOC guidance on AI in hiring
  • FTC enforcement actions against companies making misleading AI claims

The US approach favors voluntary commitments and industry self-regulation over binding requirements, creating a significant divergence from EU regulatory philosophy that will require multinational companies to maintain different compliance postures for different markets.

Data Sovereignty and Cross-Border Data Flows

GDPR established the framework: EU citizen data is protected by EU law wherever it goes. The Schrems II decision (2020) invalidated the EU-US Privacy Shield framework, which had allowed EU data to flow to the US, finding that US surveillance law did not provide equivalent protection to EU data privacy rights. The EU-US Data Privacy Framework (2023) replaced it, but legal challenges are ongoing.

For AI specifically: LLMs trained on data scraped from the internet have faced regulatory scrutiny over whether this training constitutes unlawful processing of personal data. Italy temporarily banned ChatGPT in 2023 over GDPR concerns. The question of whether an individual's data contributed to training an AI model and what rights they have over that use is actively litigated.

Developing country data sovereignty: Jamaica and CARICOM nations are not passive observers in this dynamic. The Caribbean Community's approach to data governance will shape whether regional data and digital economic activity benefit regional citizens and governments or flow primarily to US and EU platforms. The Caribbean has an opportunity to establish data protection frameworks that attract investment while protecting citizens if it moves proactively.

What Businesses Need to Prepare For

Within 2-3 years:

  • AI-generated content labeling requirements will be widespread
  • High-risk AI systems used in employment or financial decisions will require bias audits and human oversight mechanisms
  • Generative AI companies will face requirements to disclose training data sources

Within 5 years:

  • Sector-specific AI liability frameworks (who is responsible when an AI-assisted medical diagnosis is wrong?)
  • Mandatory incident reporting for AI system failures in critical sectors
  • International mutual recognition agreements (or continued fragmentation) between EU, US, and Asian AI regulatory regimes
  • Carbon disclosure requirements for large AI training runs

What Individuals Should Understand

The regulatory future gives individuals new rights they need to exercise:

  • Right to explanation: In jurisdictions with algorithmic accountability requirements, if an AI system denied your loan or rejected your job application, you have the right to know what factors drove the decision
  • Right to opt out of automated decision-making: GDPR's Article 22 provides a right not to be subject to purely automated decisions in certain contexts
  • Data deletion rights: Training data rights are contested, but existing laws give you rights over personal data held by companies
0%