Legal Governance for Systemic Artificial IntelligenceLegal Governance for Systemic Artificial Intelligence

1. AI as normative infrastructure

Artificial intelligence can no longer be understood as a stand-alone automation tool. It should be treated as a decision-making infrastructure that allocates access, risk, power, rights, and responsibility. In public administration, finance, healthcare, labour markets, and competition policy, AI does not merely execute instructions. It reshapes the environment in which decisions are made.

The European Commission’s COM(2018) 237 final, Artificial Intelligence for Europe defined AI as systems that display intelligent behaviour by analysing their environment and taking actions, with some degree of autonomy, to achieve specific goals. That definition covered both software-based systems and AI embedded in hardware, such as robots, autonomous vehicles, drones, and internet-of-things applications.

That early framing has now moved into a more mature regulatory phase. The central question is no longer just how to define AI, but how to impose risk-based duties, supervisory mechanisms, liability rules, and technical standards across the entire system lifecycle.

The legal significance of computational infrastructure is especially visible in quantum computing. In Valentin Jeutner, “The Quantum Imperative: Addressing the Legal Dimension of Quantum Computers”, Morals & Machines, vol. 1, no. 1, 2021, pp. 52–59, quantum computers are treated as legally relevant objects because their development and operation may reshape social relations, power distribution, and individual autonomy.

Jeutner’s quantum imperative requires regulators and developers to ensure that quantum computing does not create or worsen inequality, does not undermine individual autonomy, and does not develop without consultation with those who may be affected.

The same logic applies to advanced AI. Technical infrastructure is not neutral. Compute capacity, data access, model architecture, interface design, training conditions, and provider concentration all produce regulatory effects, even when they do not look like law in the traditional sense.

2. Europe’s new regulatory core: the AI Act, liability, data, and cyber resilience

The AI Act: from ethical guidance to binding legal architecture

The most important European development is Regulation (EU) 2024/1689, widely known as the AI Act. It entered into force on 1 August 2024 and will apply in full from 2 August 2026, with important phased exceptions. Prohibited practices and AI literacy duties started applying on 2 February 2025. Governance rules and obligations for general-purpose AI models started applying on 2 August 2025. Certain high-risk AI systems embedded in regulated products benefit from an extended transition period until 2 August 2027.

The AI Act turns AI governance in the European Union into a risk-based legal system. It distinguishes between prohibited practices, high-risk systems, transparency obligations, general-purpose AI models, and general-purpose AI models with systemic risk. Its architecture combines fundamental-rights protection, safety, traceability, technical documentation, human oversight, risk management, and post-market monitoring.

In 2025, the European Commission also issued guidance on prohibited AI practices and on the definition of an AI system. These documents are important because the first phase of enforcement depends on technically and legally coherent interpretation, particularly around unacceptable uses, AI literacy, and the scope of systems covered by the Regulation.

In July 2025, the Commission presented the General-Purpose AI Code of Practice, designed to help providers comply with the AI Act’s obligations on safety, transparency, and copyright. Its safety and security chapters are especially relevant for advanced model providers whose systems may pose systemic risk.

Product liability: software, defects, and cybersecurity

A second major European development is Directive (EU) 2024/2853, adopted on 23 October 2024, on liability for defective products. It replaces the older Product Liability Directive and modernises strict liability for digital environments.

Its significance lies in the express inclusion of software within the concept of product. The Directive clarifies that no-fault liability for defective products applies to movable goods, including software, whether embedded in another product or connected to a broader digital ecosystem. It also makes cybersecurity requirements relevant when assessing defectiveness.

This matters directly for AI systems deployed as components in connected products, medical devices, vehicles, robots, digital infrastructure, and software-based services.

Defectiveness can no longer be assessed only in mechanical or physical terms. It must also include digital safety, updates, data dependency, interoperability, and cyber resilience.

The Data Act and Europe’s data economy

Regulation (EU) 2023/2854, known as the Data Act, applies from 12 September 2025. It is central to Europe’s attempt to build a fairer and more innovative data economy.

Its relevance to AI is structural. AI systems depend on data access, interoperability, reuse rights, and contractual terms that determine who can extract value from connected products and related services. The Data Act therefore shapes the economic and competitive conditions under which AI systems are trained, deployed, and scaled.

Platforms, digital markets, and algorithmic competition

The Digital Markets Act, Regulation (EU) 2022/1925, creates rules for gatekeeper platforms and aims to make digital markets more contestable and fair. The Commission initially designated Alphabet, Amazon, Apple, ByteDance, Meta, and Microsoft as gatekeepers on 6 September 2023.

The DMA becomes increasingly relevant as large digital ecosystems integrate foundation models, personal assistants, cloud infrastructure, marketplaces, app stores, and advertising systems. AI can strengthen intermediary power, deepen dependence among business users, and enable self-preferencing or market foreclosure through algorithmic design.

The Digital Services Act, Regulation (EU) 2022/2065, complements this framework by regulating the responsibilities of digital services, content moderation, transparency, and enhanced duties for very large online platforms. Although it is not an AI statute, it directly affects recommender systems, advertising systems, systemic-risk assessments, and governance of algorithmically amplified content.

The Cyber Resilience Act and digital-product security

Regulation (EU) 2024/2847, known as the Cyber Resilience Act, introduces cybersecurity requirements for products with digital elements. Its conformity assessment rules, independence requirements, and obligations for competent assessment bodies are directly relevant to AI systems embedded in connected products.

Together, the AI Act, the new Product Liability Directive, and the Cyber Resilience Act create an important institutional consequence: AI safety can no longer be reduced to model accuracy. It must include cybersecurity, robustness, resilience, conformity assessment, technical records, and corrective capacity.

3. Global governance: human rights, technical standards, and foundation models

Council of Europe: the first legally binding international AI treaty

The Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law is the first legally binding international treaty on AI. It was opened for signature on 5 September 2024 and aims to ensure that activities across the AI system lifecycle remain fully consistent with human rights, democracy, and the rule of law.

This instrument matters because it shifts the global debate from voluntary principles toward binding intergovernmental commitments. It does not replace sectoral regulation, but it provides a cross-cutting legitimacy framework built around lifecycle governance, fundamental rights, democracy, the rule of law, and monitoring.

United Nations: global political consensus

In 2024, the United Nations General Assembly adopted Resolution A/RES/78/311, focused on safe, secure, and trustworthy AI systems for sustainable development. The resolution frames the AI lifecycle broadly, covering pre-design, design, development, evaluation, testing, deployment, use, sale, procurement, operation, and decommissioning.

Although non-binding, the resolution is politically significant. It places AI within the 2030 Agenda, international cooperation, digital-divide reduction, and human-rights protection. Its main contribution is to consolidate a global vocabulary of safe, secure, and trustworthy AI.

OECD: updated principles for generative and general-purpose AI

The OECD AI Principles were adopted in 2019 and updated in 2024. They remain one of the most influential intergovernmental frameworks for trustworthy AI that respects human rights and democratic values.

The 2024 update is particularly important because it reflects the rise of generative and general-purpose AI. The revised principles are intended to provide global interoperability for AI policy while keeping public authorities aligned with rapid technological development.

UNESCO: a global ethics baseline

UNESCO’s Recommendation on the Ethics of Artificial Intelligence, adopted in 2021, remains a major global soft-law reference. It is framed as the first global standard on AI ethics, with human rights and human dignity at its core.

Its value lies in widening AI governance beyond technical safety. It foregrounds fairness, human oversight, transparency, sustainability, cultural diversity, and protection of vulnerable groups. In jurisdictions without binding AI legislation, it functions as a policy blueprint.

G7 Hiroshima AI Process: advanced models and conduct rules

The Hiroshima Process International Code of Conduct for Organizations Developing Advanced AI Systems, published in 2023, provides voluntary guidance for organisations developing advanced systems, including foundation models and generative systems. Its purpose is to promote safe, secure, and trustworthy AI globally.

In 2024 and 2025, the process moved toward structured reporting. A reporting framework was launched in February 2025, followed by the publication of company responses in April 2025. This signals a shift from high-level principles toward observable organisational commitments.

United States: competitive leadership and federal AI governance

Recent US AI policy has changed direction. Executive Order 14110, issued in 2023 on safe, secure, and trustworthy AI, was rescinded on 20 January 2025. It was followed by Executive Order 14179, Removing Barriers to American Leadership in Artificial Intelligence, issued on 23 January 2025, which reoriented federal policy toward global AI leadership and the removal of perceived barriers to innovation.

Federal governance has not disappeared. It has been reframed. The OMB Memorandum M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust, issued in April 2025, gives federal agencies guidance on responsible AI adoption, privacy, civil rights, civil liberties, and risk mitigation in public-sector AI use.

At the technical level, NIST remains central. The AI Risk Management Framework 1.0, published in January 2023, provides a structured, flexible, and measurable process for managing AI risk. In July 2024, NIST also published the Generative AI Profile, NIST AI 600-1, as a companion resource for risks specific to generative AI.

China: targeted regulation of generative AI

China adopted the Interim Measures for the Management of Generative Artificial Intelligence Services in 2023. They apply to publicly available generative AI services in mainland China that generate text, images, audio, video, or other content.

These measures reflect a distinct regulatory model: early, targeted regulation of public generative AI services, with duties linked to national security, public order, content governance, data, and provider responsibility. Their global significance is that generative AI has become an explicit regulatory object, not just a technical subcategory.

ISO/IEC: technical standardisation for AI management systems

ISO/IEC 42001:2023 is presented by ISO as the world’s first AI management-system standard. It provides a structured way to manage AI-related risks and opportunities while balancing innovation and governance.

Further developments followed in 2025. ISO/IEC 42005:2025 provides guidance for AI system impact assessments, with attention to effects on individuals, groups, and society. ISO/IEC 42006:2025 establishes requirements for the auditing and certification of AI management systems.

This technical standardisation is essential. Without standards, legal obligations on risk management, traceability, oversight, and auditability risk remaining abstract.

4. Automated public decision-making and algorithmic due process

Public-sector automation requires heightened scrutiny. A public authority using AI is not simply improving internal efficiency. It may affect rights, welfare benefits, sanctions, criminal investigations, access to essential services, and procedural guarantees.

Markku Suksi, in “Administrative due process when using automated decision-making in public administration: some notes from a Finnish perspective”, Artificial Intelligence and Law, vol. 29, 2021, pp. 87–110, warns that many due-process guarantees were designed for human decision-makers and may become ineffective when automated administrative decision-making is introduced.

Recent regulatory developments reinforce that concern. The AI Act pays special attention to high-risk systems, including many systems used in public or quasi-public contexts. The Council of Europe Convention adds an international human-rights, democracy, and rule-of-law foundation. OMB M-25-21 shows that even a pro-innovation US federal policy still preserves requirements around privacy, civil rights, civil liberties, and risk-appropriate safeguards.

A formal doctrine of algorithmic due process should require:

  • An express legal basis for high-impact automated public decisions.
  • Clear identification of the responsible public authority.
  • Sufficient technical and legal documentation.
  • Explainability designed for challenge and review, not merely technical intelligibility.
  • Auditable records of data, versions, rules, outcomes, and modifications.
  • Fundamental-rights impact assessment.
  • Qualified human review.
  • Effective remedy before an independent authority or competent court.

Digital administration is compatible with the rule of law only when it preserves accountability, reasoning, contestability, review, and control.

5. Algorithmic markets, intellectual property, fintech, and competition

Intellectual property and generative models

Noam Shemtov’s A study on inventorship in inventions involving AI activity, commissioned by the European Patent Office in 2019, concluded that none of the jurisdictions examined allowed an AI system to be recognised as an inventor under patent law. Inventorship remained tied to an intelligent and creative contribution made by a person.

The most important regulatory update is that the AI Act introduces specific duties for general-purpose AI models, including obligations linked to transparency and copyright. The 2025 General-Purpose AI Code of Practice was designed to support compliance with legal duties on safety, transparency, and copyright.

The question is therefore no longer only who counts as an inventor or author. It is also what providers of advanced models must disclose, document, monitor, and control regarding training data, generated content, third-party rights, systemic risks, and downstream deployment.

Fintech and model supervision

Financial AI enables credit scoring, robo-advisory services, automated trading, fraud detection, climate-risk modelling, and prudential supervision. Yet the risks of indirect discrimination, opacity, model drift, and provider concentration have intensified.

The European framework affects fintech through several channels: the AI Act for qualifying high-risk systems, the Data Act for data access and use, the new Product Liability Directive where AI operates as defective software or product component, the DMA where platform infrastructure affects contestability, and technical standards such as ISO and NIST frameworks for risk management.

From a supervisory standpoint, model validation must go beyond statistical accuracy. It should cover fairness, explainability, robustness, cybersecurity, data documentation, third-party control, and traceability of adverse decisions.

Competition and algorithmic pricing

Julian Nowag, in “Algorithmic Price-Setting by Platforms”, Oxford Business Law Blog, 2018, distinguishes the simple case of an algorithmic cartel, where competitors agree to coordinate prices through an algorithm, from more complex cases in which a platform sets prices through its own algorithm.

Europe’s updated regulatory environment makes this problem more significant. The DMA provides tools for gatekeeper markets, while the AI Act imposes duties on AI systems and general-purpose models. In platform-dominated markets, coordination no longer needs to rely on explicit communication between competitors. It may arise from architecture, incentives, data access, ranking design, recommender systems, and automated pricing rules.

The competition authority of the future must be able to audit not only conduct, but algorithmic market architectures.

6. Health, labour, and sustainable finance as critical domains

Health: AI, the EHDS, and health data

Titti Mattsson, in “eHealth and the Law”, in eHealth Opportunities and Challenges: A White Paper, Lund University, 2016, pp. 13–18, had already identified the need to adapt healthcare law without sacrificing privacy, integrity, legal certainty, and non-discrimination.

The most important European regulatory development is Regulation (EU) 2025/327, establishing the European Health Data Space. It was published in the Official Journal on 5 March 2025 and entered into force on 26 March 2025, beginning a phased implementation period.

The EHDS aims to improve individual access to and control over electronic health data while enabling certain forms of secondary use for research, innovation, policymaking, and regulatory purposes.

For healthcare AI, this is decisive. Diagnostic, triage, clinical decision-support, biomedical research, and personalised-medicine systems all depend on high-quality health data. The EHDS creates a legal and technical architecture that may accelerate innovation, but it also demands strict governance of privacy, secondary access, interoperability, and authorised use.

Labour: algorithmic management and automated supervision

AI in the workplace raises risks in hiring, performance evaluation, monitoring, task allocation, occupational safety, and dismissal. Although the AI Act is not a general labour statute, its high-risk approach may apply to systems used in employment, worker management, and access to professional opportunities.

Labour law should incorporate four structural safeguards:

  • Transparency over algorithmic criteria affecting essential employment conditions.
  • Impact assessments on equality and non-discrimination.
  • Strict limits on permanent monitoring and workplace surveillance.
  • A substantive right to human review of adverse decisions.

Algorithmic management must not become opaque subordination. If an employer exercises managerial power through AI, it must retain full legal responsibility for the system’s effects.

Sustainable finance and climate risk

Financial Risk Management and Modeling, edited by Constantin Zopounidis, Ramzi Benkraiem, and Iordanis Kalaitzoglou, frames risk as a central source of uncertainty for investors, debtholders, and corporate managers. Proper risk valuation and management are essential for sound financial decision-making.

The regulatory and technical update is that AI in sustainable finance must now align with data governance, model traceability, cybersecurity, and auditability. Artificial Intelligence for Sustainable Finance and Sustainable Technology, edited by Abdalmuttaleb M. A. Musleh Al-Sartawi, connects AI, digitalisation, fintech, sustainability, governance, big data, blockchain, and security in the digital economy.

AI can improve climate-risk identification, ESG analysis, fraud detection, transition-risk assessment, and capital allocation. But it can also produce algorithmic greenwashing if indicators are opaque, data are incomplete, or models optimise reputational performance rather than material impact.

Sustainable AI therefore requires materiality, comparability, auditability, explainability, and consistency with verifiable public objectives.

7. Conclusion: from declaratory ethics to verifiable governance

Between 2023 and 2026, AI governance entered a new phase. It is no longer dominated by broad ethical principles. In Europe, the AI Act, the new Product Liability Directive, the Data Act, the Cyber Resilience Act, the DMA, the DSA, and the EHDS now form a dense and cumulative regulatory ecosystem.

Internationally, the Council of Europe has introduced the first binding AI treaty, the UN has consolidated global political consensus, the OECD has updated its principles, UNESCO maintains a universal ethics baseline, the G7 has articulated conduct rules for advanced models, the United States has reoriented federal AI policy, and China has regulated public generative AI services.

The core thesis is now stronger: high-impact AI must be governed as critical decision-making infrastructure in both public and private domains.

Effective governance requires:

  • Ex ante rules to classify prohibited, high-risk, and transparency-bound uses.
  • Ex post liability attributable to operators, producers, integrators, providers, and public authorities.
  • Independent audit, both technical and legal.
  • Evidentiary traceability through proportionate and verifiable records.
  • Lifecycle risk management.
  • Qualified human oversight, not symbolic review.
  • Impact assessments for fundamental rights, society, and sustainability.
  • Real public-sector capacity to understand the systems being regulated.

Algorithmic innovation will be legitimate only if it remains legally accountable, technically verifiable, institutionally supervisable, and democratically contestable.

 

References and Further Reading

The foundational concepts explored in this article draw on the AI & Law curriculum offered by Lund University.

For readers seeking deeper insight into AI governance, financial risk, sustainable technology, and regulatory accountability, the following works are recommended:

  • Al-Sartawi, A. M. A. M. (Ed.). (2022). Artificial Intelligence for Sustainable Finance and Sustainable Technology: Proceedings of ICGER 2021 (Lecture Notes in Networks and Systems, Vol. 238). Springer Nature Switzerland AG.
    This collection connects artificial intelligence with sustainable finance, digitalisation, big data, blockchain, governance, and the technological infrastructure of the digital economy.
  • Zopounidis, C., Benkraiem, R., & Kalaitzoglou, I. (Eds.). (2021). Financial Risk Management and Modeling. Springer Nature Switzerland AG.
    This volume provides a rigorous foundation for analysing financial uncertainty, risk modelling, and decision systems relevant to AI-enabled financial governance.

 

Regulatory and Technical References

The following instruments provide a cross-jurisdictional reference framework for the governance, accountability, safety, and assessment of AI systems. They do not replace jurisdiction-specific legal advice.

European Union

  • European Parliament and Council of the European Union. (2025). Regulation (EU) 2025/327 of 11 February 2025 on the European Health Data Space.
  • European Parliament and Council of the European Union. (2024). Regulation (EU) 2024/2847 of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act).
  • European Parliament and Council of the European Union. (2024). Directive (EU) 2024/2853 of 23 October 2024 on liability for defective products.
  • European Parliament and Council of the European Union. (2024). Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act).
  • European Parliament and Council of the European Union. (2023). Regulation (EU) 2023/2854 of 13 December 2023 on harmonised rules on fair access to and use of data (Data Act).
  • European Parliament and Council of the European Union. (2022). Regulation (EU) 2022/2065 of 19 October 2022 on a Single Market for Digital Services (Digital Services Act).
  • European Parliament and Council of the European Union. (2022). Regulation (EU) 2022/1925 of 14 September 2022 on contestable and fair markets in the digital sector (Digital Markets Act).

International and Multilateral Frameworks

  • Council of Europe. (2024). Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225).
  • United Nations General Assembly. (2024). Resolution A/RES/78/311: Enhancing International Cooperation on Capacity-Building of Artificial Intelligence.
  • United Nations General Assembly. (2024). Resolution A/RES/78/265: Seizing the Opportunities of Safe, Secure and Trustworthy Artificial Intelligence Systems for Sustainable Development.
  • Organisation for Economic Co-operation and Development. (2024). Recommendation of the Council on Artificial Intelligence (OECD/LEGAL/0449).
  • UNESCO. (2021). Recommendation on the Ethics of Artificial Intelligence.
  • Group of Seven. (2023). Hiroshima Process International Code of Conduct for Organizations Developing Advanced AI Systems.

United States

  • Executive Office of the President. (2025). Executive Order 14179: Removing Barriers to American Leadership in Artificial Intelligence.
  • Office of Management and Budget. (2025). Memorandum M-25-21: Accelerating Federal Use of AI through Innovation, Governance, and Public Trust.
  • National Institute of Standards and Technology. (2024). Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1).
  • National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0; NIST AI 100-1).

China

  • Cyberspace Administration of China. (2023). Interim Measures for the Management of Generative Artificial Intelligence Services.

International Technical Standards

  • ISO/IEC. (2025). ISO/IEC 42006:2025: Information Technology (Artificial Intelligence) Requirements for Bodies Providing Audit and Certification of Artificial Intelligence Management Systems.
  • ISO/IEC. (2025). ISO/IEC 42005:2025: Information Technology (Artificial Intelligence) AI System Impact Assessment.
  • ISO/IEC. (2023). ISO/IEC 42001:2023: Information Technology (Artificial Intelligence) Management System.

Deja un comentario

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *

error: Content is protected !!