Open Review of Management, Banking and Finance

«They say things are happening at the border, but nobody knows which border» (Mark Strand)

The EU AI Act as ‘Conditional Regulation’: The Challenges of Enforceability and Algorithmic Risk

by Tiziano Forlin* and Andrea Miglionico**

Abstract: This article examines the tenets of the EU Artificial Intelligence Act through the lens of conditional regulation. It argues that the enforceability of the obligations applicable to ‘high-risk’ AI systems is achieved through the adoption of harmonised standards. Following the proposal advanced by the Commission, the Digital Omnibus reform package makes the application of those regulatory instruments conditional upon their availability, while at the same time defining the distinctive features of that notion. By distinguishing the structural, temporal, and qualitative dimensions of conditionality, the article demonstrates that such conditionality persists even after technical implementation, potentially posing risks to the detection of algorithmic flaws. With the advent of generative artificial intelligence—including deepfakes and discriminatory outputs—the central issue is no longer merely the vagueness of ex ante obligations, but rather the inadequacy of a preventive regulatory approach where the risk arises from the use of the technology itself. As a result, a key aspect of the regulatory framework concerns responsibility for the automated decisions generated by algorithmic systems.

Summary:1. Introduction. – 2. Controversial aspects of the EU Artificial Intelligence Act. – 3. Limitations of open-structured enforceability. – 4. The effects of conditionality. – 5. Generative artificial intelligence and the issue of responsibility. – 6. Liability of deepfake content creators and social media platforms. – 7. Conclusion.

1.         Regulation (EU) 2024/1689 (the AI Act) has introduced a comprehensive regulatory framework governing artificial intelligence addressing the algorithmic risks related to the use of automated systems. Its regulatory architecture (whose substantive component is largely traceable to the New Legislative Framework)[1] identifies obligations according to the different level of risk, distributes them throughout the value chain, and entrusts their implementation to technical standardisation.

The substantive requirements (risk management, data governance, traceability and human oversight), however, will become fully applicable only once the external instruments intended to give them concrete effect have been developed.

The Digital Omnibus on AI, adopted in June 2026, removes the express condition previously attached to their application and establishes new compliance deadlines calibrated to the expected availability of the technical and regulatory instruments necessary to support the effective governance of AI systems.[2] As a result, conditionality remains embedded in the substance of the Regulation itself. This questions whether technical standardisation is capable of ensuring the protection of fundamental rights which, in the most widespread applications of AI technology, the Regulation does not appear fully to guarantee.

2.      The governance of the algorithmic risk under the AI Act develops along three principal lines: the horizontal nature of the regulatory framework, the graduation of obligations according to the level of risk and their distribution throughout the value chain, and the reliance upon harmonised standards for their technical implementation.

The choice of a harmonised regulatory framework reflects the need for a uniform legal regime[3] and remains consistent with the nature of the phenomenon being regulated; AI systems may be deployed in radically different contexts, without the sector of application being, in itself, determinative of the level of risk.[4] Accordingly, the Regulation establishes a common framework based upon a deliberately broad definition of an AI system (Article 3(1))[5], from which depend both the risk assessment architecture and the identification of the relevant duty holders (providers, deployers, importers and distributors, each defined according to their relationship with the AI system).

At first sight, the terminology adopted by the EU legislation characterises and reinforces the hybrid nature of its regulatory approach. Nevertheless, horizontality does not imply a uniform intensity of obligations; rather, such obligations are calibrated according to the specific level of risk associated with each system. Subject to limited exceptions, AI practices regarded as incompatible with the values of the Union are prohibited (Article 5). By contrast, high-risk AI systems[6] – namely, those capable of significantly affecting health, safety or fundamental rights – are subject to a considerably more stringent regulatory regime (Articles 6–49).

A further category of systems and uses, identified according to the manner in which they interact with natural persons or generate and manipulate content – such as chatbots, emotion recognition systems and deepfakes – is subject solely to transparency obligations (Article 50). Outside these cases, AI systems are not subject to specific regulatory obligations, save for the voluntary adherence to codes of conduct (Article 95).[7]

A distinct regulatory regime applies to general-purpose AI models (GPAI). These are governed independently of the classification of any individual AI system, with the applicable obligations deriving from the characteristics of the model itself and becoming progressively more stringent where models present systemic risk (Articles 51 et seq.).

Complementing the graduation of obligations is their allocation throughout the value chain. The AI Act identifies a plurality of relevant actors – providers (those who develop or place AI systems on the market), deployers (those who use AI systems under their authority), importers, distributors and authorised representatives – and defines their respective obligations by combining three criteria: effective control over the system, proximity to the relevant risk, and the capacity to intervene[8].

Horizontality, risk-based graduation and the allocation of obligations along the value chain together define a coherent regulatory framework, although not a self-sufficient one. While the essential requirements applicable to high-risk AI systems (Articles 8–15)[9] represent the area of greatest uncertainty, a broader examination reveals that several provisions of the Regulation establish only a core set of normative principles – sometimes more detailed, sometimes less so – the translation of which into objectively verifiable compliance criteria necessarily requires external normative supplementation[10].

The original architecture of the Regulation conceived conditionality merely as a matter of timing (Article 113), on the assumption that the general principles would subsequently be translated into concrete technical specifications. The Digital Omnibus on AI introduces new implementation dates for the obligations applicable to high-risk AI systems, thereby reinforcing the conditional nature of the Regulation.

Three dimensions of such conditionality deserve particular attention.From a structural perspective, conditionality constitutes an inherent feature of the regulatory model. The reference to elements external to the legislative text, consistent with the logic of the New Legislative Framework, raises not so much an issue of legal validity as one of regulatory completeness, since the binding force of the substantive requirements remains suspended pending their technical specification.

From a temporal perspective, should the instruments intended to render the essential requirements operational for high-risk AI systems not become available within the deadlines established by the new regime, a further postponement of their effective application appears likely. Whereas the structural and temporal dimensions of conditionality are, respectively, intrinsic to the Regulation and destined to disappear once the harmonised standards have been published, its qualitative dimension appears considerably more resistant to technical implementation. It cannot simply be assumed – and the risk is readily apparent – that technical standards will, by themselves, be sufficient to bridge the gap between the normative prescription and the objective verification of compliance.

3.         Further grounds for analysis are provided by Articles 9 and 14, which, with regard to high-risk AI systems, regulate two cornerstones of the regulatory framework: risk management and human oversight. In both cases, the technical benchmark must engage with indeterminate legal concepts, and the principal limitation lies not so much in the absence of technical standards as in the characteristics of the object being regulated, over which technical standardisation, in practice, cannot exercise complete control.

Article 9 requires the provider of a high-risk AI system to establish, implement, document and maintain a risk management system throughout the entire lifecycle of the system.

More specifically, the provision comprises a technical component (the identification, analysis, assessment and mitigation of reasonably foreseeable risks), a procedural component (documentation, systematic review and updating), and a general clause (the assessment of the acceptability of the residual risk).[11] These three components respectively determine what must be done, how the process is to be maintained over time, and when the outcome may be regarded as adequate.

The process culminates in an assessment of the acceptability of the residual risk, a notion that is far from self-evident and requires a balancing of the probability of harm, its severity, reversibility and the expected benefits.

With regard to risks affecting health and safety, the New Legislative Framework has, over decades of regulatory practice, developed reliable assessment methodologies. Such experience, however, is difficult to transpose to the protection of fundamental rights, which the AI Act nevertheless purports to safeguard. The balancing exercise required is particularly complex, as it must be carried out ex ante and involves values that are not susceptible to a common metric and are, in all likelihood, beyond the reach of purely technical regulation[12].

Article 9 therefore reflects an underlying indeterminacy. A provider may formally satisfy the prescribed requirements, while effective compliance remains difficult to verify because excessively broad and scarcely challengeable margins are left to the provider’s own self-assessment.  

The same pattern emerges under Article 14, where the obligated party–the deployer –retains a margin of discretion that technical specifications may delimit but cannot eliminate. The provision requires high-risk AI systems to be designed in such a way as to enable effective human oversight throughout their entire period of use, and identifies the essential functions of such oversight: understanding the functioning and limitations of the system, correctly interpreting its outputs, being able to intervene, including by interrupting the operation of the system, and exercising independent judgement with regard to the final decision.

The provision specifies the categories of measures required, but not their operational content, which is entrusted partly to technical specifications and, ultimately, also to indeterminate legal concepts, such as an understanding of the system’s “relevant capacities and limitations”, awareness of the “tendency of automatically relying or over-relying on the output produced by a high-risk AI system (automation bias)”, and the correct interpretation of that output.

Several issues therefore remain unresolved: the object of human oversight (whether directed at the output, the decision-making process, the risk profile, or the dynamic interaction between the AI system and human decision-making, Article 14(4)(a)-(c)); its timing (whether ex ante, contemporaneously with the decision, or ex post), which the Regulation merely associates in general terms with the “period in which they are in use” (Article 14(1)); and the competence, autonomy, training and resources of those entrusted with exercising such oversight.

This indeterminacy is compounded by an asymmetry in the allocation of responsibilities. The provider designs the system so as to make human oversight possible (through the interface, information and instructions for use required under Article 13), whereas the deployer is responsible for exercising such oversight in practice by designating the relevant personnel, organising the operational environment, and ensuring adequate time and decision-making autonomy. Formally, the allocation of responsibilities appears clear; in practice, however, it gives rise to difficult issues of legal attribution[13], particularly in relation to the deployer, who remains responsible for the concrete use of the system, for example vis-à-vis third parties.

The emphasis placed upon human oversight, combined with the opacity of AI systems, complicates the causal chain, making it difficult to identify both the person responsible for the damage and the party legally liable for it. Thus, the obligation of human oversight, given the uncertainty surrounding its normative content, risks falling precisely upon the actor who exercises the least control over the internal logic of the system while simultaneously being the one most exposed to the legal consequences arising from its use.

Unless the regulatory paradigm itself changes, technical standards will undoubtedly intervene. Yet, as regards the key safeguards – the evaluative judgement required under Article 9, the human oversight mandated by Article 14, and the related issues of liability – there is a substantial risk that technical standardisation will prove incapable of providing an effective solution. The limits of enforceability therefore lie not in the incompleteness of the legal provisions themselves, but rather in the very architecture of the Regulation, which, in practice, falls short of ensuring effective protection.

4.      The AI Act embodies a form of conditional regulation that is, to a large extent, unavoidable. Such conditionality stems from the original regulatory design, which was conceived on the assumption that artificial intelligence could be governed ex ante and that its potential impact upon fundamental rights, if appropriately calibrated, could likewise be anticipated.

While the underlying legislative objective was sound, its practical implementation has proved uncertain. As subsequent developments have demonstrated, the Regulation risks imposing obligations without measurable standards, delegated to technical specifications that remain undefined–or perhaps incapable of being defined–thereby postponing the costs of regulatory transition while immediately generating profound legal uncertainty.

The regulated actors–providers, deployers, importers and distributors–remain uncertain because they do not know the benchmark against which their compliance will ultimately be assessed. Equally, and perhaps more importantly, fundamental rights themselves remain without genuinely effective protection.

To this must be added a structural difficulty. Obligations formulated as general principles and entrusted to technical standardisation risk increasing opacity rather than dispelling it. Concepts such as the acceptability of residual risk (Article 9), the effectiveness of human oversight (Article 14), and the impact on fundamental rights (Article 27)[14] remain inherently indeterminate and are therefore left, to a significant extent, to the judgement of the regulated entities themselves.[15]

The regulatory framework thus becomes largely self-referential, creating the risk – already identified in legal scholarship – of a mere “theatre of compliance”[16], in which compliance is formally declared, whereas its substantive verification becomes exceedingly difficult and, ultimately, unattainable. A challenging task.[17]

5.        Nevertheless, one aspect appears outside the regulatory approach adopted by the AI Act: Generative Artificial Intelligence (GenAI)[18], namely those models capable of generating, in a flexible manner, textual, audio, visual or audiovisual content and of adapting to a plurality of tasks, whose dissemination over recent years has been both rapid and pervasive.

GenAI, which enables an indefinite plurality of applications to be developed from a single underlying model, was absent from the Commission’s proposal and entered the final Regulation through the regime governing general-purpose AI models (Articles 51 et seq.), complemented by the transparency obligations laid down in Article 50. Under this framework, providers are subject to documentation and information obligations (Article 53), while providers of models presenting systemic risk are additionally required to comply with enhanced obligations relating to risk assessment, risk mitigation and cybersecurity (Article 55).[19]

These safeguards remain centred upon procedural obligations and governance practices, whereas the real issue lies not in the model itself but in the manner in which it is used. Further, GenAI demonstrates that the impact upon fundamental rights is not an intrinsic property of the model, but rather the result of the interaction between its generative capabilities, the context in which it is deployed, the input data provided, and the conduct of the user.

Synthetic content–including discriminatory outputs, deepfakes and information manipulation–progressively erodes the integrity of the information ecosystem while multiplying the risks of disinformation, fraud and deception[20], with potentially significant consequences for human dignity, privacy, the principle of non-discrimination and individuals’ freedom of self-determination.

If ex ante regulation is unable to establish an appropriate standard, the focus inevitably shifts to liability[21]; in the case of GenAI, moreover, this is not merely one possible option among others, but the only safeguard capable of functioning in practice, since the harm becomes apparent only after it has materialised. It would therefore be appropriate to rethink a regulatory safeguard that extends beyond the technical functionalities of the system and instead addresses its actual use.

The difficulty inherent in such an approach–as illustrated by the withdrawal of the proposed AI Liability Directive, which sought to link fault to the infringement of the obligations laid down by the AI Act–[22] lies precisely in identifying the appropriate legal standard upon which liability arising from, and for the use of, artificial intelligence may be founded.

The rigidity of a strict liability regime cannot be regarded as a satisfactory solution[23]. Such an approach merely reproduces an excessively precautionary conception of technological risk, while failing adequately to weigh the loss of attractiveness for the European Union that such a regime would inevitably entail. A more balanced solution must therefore be sought elsewhere.

It is instead the guiding principles of the Regulation – understood also as its ultimate objectives – that should direct the development of a “human-centric and trustworthy” artificial intelligence (Article 1(1)), an objective that cannot realistically be achieved unless due account is taken of the interaction between the human and the artificial components of decision-making.

One such principle already appears to emerge from Article 14, where the obligation of human oversight is inserted into the production chain of AI-generated outputs and constitutes the point at which legal responsibility is anchored.

Human oversight, understood as the principle that a human act must intervene between the AI system and its effects, is expressed through a series of positive duties distributed along the value chain: upstream, through data governance and the mitigation of bias; during operation, through effective human control; and downstream, through the critical assessment of the system’s output. These duties do not, however, imply that every harmful outcome is, per se, unlawful.

Accordingly, legal blameworthiness should not be attached to the outcome itself – which, by reason of the generative nature of AI systems, frequently escapes prior foreseeability – but rather to the level of human oversight that could reasonably be expected in the specific circumstances. The relevant inquiry concerns what it was possible, at the time of deployment, to understand, control or disregard.

This leads to a dual allocation of responsibility among the various actors involved. Upstream, liability rests upon the party who failed to implement the safeguards required in relation to the AI system itself. Downstream, liability falls upon the person who relied upon the AI-generated output and acted upon it–where that output proves harmful–without carrying out the assessment that could reasonably have been expected, but only where such assessment was in fact within that person’s capacity.

The development of a legal framework capable of defining this form of liability undoubtedly requires further doctrinal elaboration. Such an effort, however, appears indispensable if effective protection of fundamental rights is to be ensured in an era characterised by an ever closer integration between human and artificial intelligence.

From a more practical perspective, conditional regulation reflects a legislative framework that lacks a sufficiently precise normative standard – not least because of its extensive reliance upon excessively general clauses. In the absence of an adequate body of implementing rules, the resulting opacity of AI systems may, at present, frustrate the ordinary operation of the law of civil responsibility.

Finally, the balance between what has aptly been described as “paper compliance” and the necessity of identifying a legally responsible actor cannot dispense with an appropriate criterion of attribution. Such a criterion should be found in a fault-based standard centred upon the use of AI, assessed both with regard to the manner in which the system was deployed (ex ante) and to the evaluation of its output (ex post).

6.         As discussed in the previous sections, the AI Act shows limitations to accommodate liability for AI-generated harms. EU regulators have not provided a clear definition of malicious deepfakes, making meaningless any responsibility of the deepfake supply chain. Deepfakes can be useful in generating realistic simulations in education, news reporting and the arts. However, the emergence of malicious deepfakes in financial services has raised concerns on the quality and reliability of information provided to prospective customers.

There is consensus that deepfakes generate content and produce outputs that are not explicitly programmed and are occasionally inaccurate with the intent to cause distress or alarm to the recipient. This poses multifaceted challenges for public authorities, particularly around legal and ethical implications such as consent, misleading content and cybersecurity. Extant debates focus on holding deepfake content creators and distributors such as social media companies accountable. There are, however, challenges with this.

Copyright laws and data protection laws seem inadequate to impose liability on creators of deepfakes due to questions of anonymity and authorship, as well as difficulties in bringing action for copyright infringement of any underlying copyright works.

Distributors of deepfakes such as social media companies are immune from liability of deepfakes disseminated on their platforms under Section 230 of the US Communication Decency Act of 1996.[24] Developers and manufacturers of AI deepfake software interplay with the liability for the deepfake content creators, suggesting various detection measures to hold responsible those actors involved in harmful synthetic media.

Digital solutions such as blockchain technology and watermarking should be implemented for source verification and authentication of data. Blockchain technology can verify the origins and distribution of videos by storing digital signatures in a ledger which is difficult to manipulate.[25] Watermarking techniques such as hashing are forgery methods to detect the integrity of content by tracing files with a short string of numbers that is lost if the video or audio is deepfaked.[26] It is noted that digital platforms exert significant control over the content published on their platforms through their terms of service, content moderation policies, and algorithmic promotion of content.[27]

Senior managers can be held liable for negligence if they do not adequately implement risk management processes. Failure to employ watermarks and digital forensic techniques in deepfakes amounts to gross negligence, which results in personal liability for individuals accountable for careless supervision of content authenticity.

In Public Prosecutor v. Zheng Jia, the Singapore High Court held that directors are liable for breaching their duties if they knowingly or intentionally fail to exercise control or supervision over company affairs.[28] The case involved the proceeds of scams which were routed through the bank accounts of the company: the director was found guilty of “purely negligent breaches” of the duty to exercise reasonable diligence.

The interaction between content creators and digital platforms allocates a shared liability for allowing the production and dissemination of deepfakes. However, content creators are mostly anonymous which makes it difficult to hold them liable at various stages of deepfake creation.

At the UK level, the Cyber Security and Resilience Bill 2024,[29] which updated the Network and Information Systems (NIS) Regulations 2018,[30] established a set of provisions that impose obligations to managed service providers (IT service providers and managed security services),[31] holding responsible those firms for failure to take effective technical and organisational measures (e.g., contractual requirements, security checks, or continuity plans), and to manage risks posed to the security of the network, infrastructure and information systems.[32] The UK experience reported a rapid surge in online fraud offences which enabled criminal organizations to disrupt the IT systems of banks, technology and telecom companies.[33]

In China, Provisions on the Administration of Deep Synthesis of Internet-based Information Service 2023 introduced specific obligations and responsibilities on service providers, users and online platforms for the management of synthetic media technologies.[34] This legislative framework would provide procedures for identifying, assessing, and mitigating the harmful consequences of malicious deepfake content with regulatory tools that expedite coordination between enforcement mechanisms, intelligence agencies and stakeholders.

The involvement of content creators in malicious deepfake scams raise questions about the liability of online social media platforms involved in investment scams. This scenario explores how such platforms operate and how big tech companies identify vulnerabilities in AI models and assess their safety performance. Cryptocurrency scams have become a recurrent fraud perpetrated through fake celebrity endorsements and phishing schemes. Social media platforms are leveraged as profitable networks for investment scammers to exploit the market of crypto assets.[35]

Cryptocurrency scams such as “pig butchering scams” assume various forms of impersonators by claiming payments in exchange for false promises of imminent businesses or utility companies.[36] Social engineering tactics to catch innocent investors into fictitious financial deals amplify information asymmetries in digital transactions which result in abusive and manipulative practices.[37]

Emerging technologies in digital platforms allow scammers to refine their strategies, exacerbating user exposure and inflating consumer vulnerability.[38] Specifically, technological advancements in cryptocurrencies (e.g., blockchain systems) increase the incentive for psychological manipulation and fraudulent activities.[39] Online platforms show a gatekeeper role in channelling personalised recommendations to consumers and dispensing information supplied by service providers.

Social media platforms can spread misleading information by their design and create contact between scammers and users through the websites and downloads. Persuading fraudsters benefit from well-known platform designs to distort content and deceive users. A new legal paradigm for platform liability has been proposed to allocate design negligence in deception-related harms against users.[40] This approach aims to identify the degree of liability for social media companies when they fail to avoid malicious actors manipulating their design which may result in harmful scams. Acting as infomediaries of generated content, online platforms should hold the responsibility to monitor the performance of AI software although they can avoid liability by claiming that they are not under a duty to run editorial control about the accuracy and impartiality of information.[41]

7.        The widespread use of sophisticated AI systems to mimic human ability has resulted in exploiting user vulnerabilities and inflating online frauds. Advances in generative computing software provide firms with greater opportunities to create smarter services for customers but they also give more powerful tools to scammers, fraudsters and deepfakes.[42] GenAI content can disseminate poor information or ‘hallucinations’ which are not factually accurate, and it is difficult to detect how it reached a particular decision.[43]

Malicious deepfakes operate at different stages of the AI supply chain through digital platforms, which makes meaningless the identification of frauds. Victims of scams are more exposed to the risk that big tech companies have perverse incentives with some groups integrating advertisements into their tools in the search for profitable revenues. As noted, ‘scammers are good at what they do and use different methods to target people and make them more vulnerable’.[44]

Innovative software systems such as DeepSeek are used by financial firms to control data and validate artificial intelligence patterns before running misleading content in business relationships.[45] For example, Google DeepMind runs specialised evaluations and training for factual accuracy to ensure models provide truthful responses.[46]

Microsoft launched safety benchmarks for developers to rank iterations from a range of providers in view to build trust with cloud customers.[47] The safety metric evaluates whether a model can be used for malicious purposes: this testing programme based on rankings enables users to understand the risks posed by AI applications. It is an innovative mechanism to monitor GenAI products by ensuring they cannot be used to cause harmful content. The safety system assesses the level of fairness, biases and mistakes of AI products, and the risk of ‘hallucinations’ in investment scams.

Although financial firms are responsible for processing payments, much of purchase deception comes from false advertisements disseminated on social media platforms.[48] Imposing tech companies to pay for the harmful consequences of scams and bear their share of the responsibility would prevent platforms from hosting content creators, developers and software manufacturers of GenAI.


Authors:

Tiziano Forlin is Lecturer in Master’s Degree Programme in Regulation of financial activities and markets at LUISS University of Rome.

Andrea Miglionico is Associate Professor of law, University of Reading.

This article is the result of joint reflections and shared thoughts developed by the authors. Sections 1-5 were elaborated by Tiziano Forlin; sections 6-7 were drafted by Andrea Miglionico.

[1] The AI Act adopts the legislative technique of laying down essential requirements and of giving them concrete expression through harmonised standards, in accordance with the approach traditionally followed in European technical legislation (the so-called New Legislative Framework). On this point, see S. de Vries, O. Kanevskaia, R. de Jager, Internal Market 3.0: The Old «New Approach» for Harmonising AI Regulation, in European Papers, 2023, vol. 8, no. 2, 583.

[2] See the Regulation amending the AI Act (the Digital Omnibus VII Package), adopted by the Council on 29 June 2026. As regards its legislative background, see the provisional political agreement between the Parliament and the Council of 7 May 2026 and the Council press release, Artificial Intelligence: Council and Parliament agree to simplify and streamline rules (consilium.europa.eu), which explains that the reform is intended to simplify the implementation of harmonised rules and to coordinate the application of the rules governing high-risk AI systems with the availability of the necessary standards and technical instruments.

[3] On the fragmentation of the EU digital regulatory framework and the need to ensure coordination between the AI Act and other areas of Union law, see C. Novelli, P. Hacker, J. Morley, J. Trondal, L. Floridi, A Robust Governance for the AI Act: AI Office, AI Board, Scientific Panel, and National Authorities, in European Journal of Risk Regulation, 2025, vol. 16, pp. 566; H. Graux, K. Garstka, N. Murali, J. Cave, M. Botterman, Interplay between the AI Act and the EU Digital Legislative Framework, Study for the European Parliament, ITRE Committee, 2025.

[4] For the notion of risk under the AI Act, see Article 3(2) of Regulation (EU) 2024/1689, which defines risk as “the combination of the probability of an occurrence of harm and the severity of that harm”.

[5] Pursuant to Article 3(1), an AI system is defined as “a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments”. This deliberately broad definition substantially aligns – albeit with some modifications – with the definition of AI system adopted by the OECD in its Recommendation of the Council on Artificial Intelligence of 22 May 2019 (OECD/LEGAL/0449), as updated in 2024.

[6] The classification criterion is twofold. It covers, on the one hand, AI systems operating as safety components of products falling within the Union harmonisation legislation listed in Annex I and which, under that legislation, are subject to third-party conformity assessment (Article 6(1)); and, on the other hand, AI systems intended for the areas listed in Annex III (Article 6(2)), namely biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice, and democratic processes.

[7] On the logic underlying the graduated risk-based approach and its limitations, particularly the risks of under-inclusion of AI applications relevant to the rule of law and democracy, see N. Rangone, L. Megale, Risks Without Rights? The EU AI Act’s Approach to AI in Law and Rule-Making, in European Journal of Risk Regulation, 2025, vol. 16, pp. 1082.

[8] For the definitions of the actors within the AI value chain, see Article 3 of Regulation (EU) 2024/1689; for their respective obligations, see Articles 16–27. The rule providing for the reclassification of the deployer as a provider in the event of a substantial modification of the AI system or a change in its intended purpose is laid down in Article 25. On the allocation of obligations among importers, distributors and deployers, as well as on the circumstances in which those obligations are extended or realigned with those of the provider, see K. Kiejnich-Kruk, Obligations of Importers, Distributors and Deployers of High-Risk AI Systems under the AI Act, in Ius Novum, 2025, vol. 19, no. 4, 121.

As regards high-risk AI systems, the principal body of obligations rests upon the provider (Articles 16 et seq.), consistently with the rationale that the entity controlling the design of the system is responsible for ensuring ex ante compliance. However, equally significant obligations are imposed on the deployer (Article 26), who, by virtue of its proximity to the actual use of the system, must ensure that it is operated in accordance with the provider’s instructions and the declared intended purpose. Importers and distributors, by contrast, are entrusted primarily with documentary verification functions (Articles 23 and 24).

[9] The expression is used here in the sense attributed to it under the New Legislative Framework. The Regulation lays down essential requirements, while their technical specification is entrusted to harmonised standards, which give rise to a presumption of conformity. See Article 40 and Recital 121 of Regulation (EU) 2024/1689; S. de Vries, O. Kanevskaia, R. de Jager, Internal Market 3.0: The Old «New Approach» for Harmonising AI Regulation, in European Papers, op. cit.; R. Kilian, L. Jäck, D. Ebel, European AI StandardsTechnical Standardisation and Implementation Challenges under the EU AI Act, in European Journal of Risk Regulation, 2025, vol. 16, 1038.

[10] Consider, for example, Article 50, which entrusts the marking of synthetic content and the detectability of deepfakes to labelling solutions capable of being standardised, or Article 51, which classifies as a systemic-risk AI model any model possessing “high impact capabilities evaluated on the basis of appropriate technical tools and methodologies, including indicators and benchmarks” (Article 51(1)(a)), thereby leaving the very criterion for classification to external technical instruments.

[11] See J. Schuett, Risk Management in the Artificial Intelligence Act, in European Journal of Risk Regulation, 2024, vol. 15, 367, who reconstructs the structure and function of Article 9; K. Yeung, Can Risks to Fundamental Rights Arising from AI Systems Be «Managed» Alongside Health and Safety Risks? Implementing Article 9 of the EU AI Act, SSRN Working Paper, 2025, which examines the difficulties of integrating risks to health, safety and fundamental rights within a single risk-management framework.

[12] On the difficulties of extending to fundamental rights a risk-management paradigm originally designed for the health and safety risks underpinning the New Legislative Framework, see K. Yeung, Can Risks to Fundamental Rights Arising from AI Systems Be «Managed» Alongside Health and Safety Risks? Implementing Article 9 of the EU AI Act..

[13] The dependence of human oversight upon the transparency of the AI system is highlighted by L. Enqvist, «Human oversight» in the EU Artificial Intelligence Act: What, When and by Whom?, in Law, Innovation and Technology, 2023, pp. 508 ff., who links the effectiveness of oversight to the characteristics of the AI system, its degree of transparency and the operational conditions under which the human supervisor performs that function. On the data-governance requirements laid down in Article 10 as an instrument enabling the provider both to identify risks and to demonstrate compliance, see H.M. Holtz, J. Ledendal, AI Data GovernanceOverlaps Between the AI Act and the GDPR, in Law, Innovation and Technology, 2026.

[14] Article 27(1) of Regulation (EU) 2024/1689 requires a Fundamental Rights Impact Assessment (FRIA) to be carried out, on the one hand, by public bodies and private entities providing public services in relation to the high-risk AI systems listed in Annex III (with the exception of critical infrastructure under point 2); and, on the other hand, irrespective of the nature of the entity concerned, by deployers of AI systems used for creditworthiness assessment or for risk assessment and pricing in life and health insurance (Annex III, point 5(b) and (c)). On the procedural structure of the assessment and the absence of shared substantive criteria capable of rendering its outcome objectively verifiable, see A. Mantelero, The Fundamental Rights Impact Assessment (FRIA) in the AI Act: Roots, Legal Obligations and Key Elements for a Model Template, in Computer Law & Security Review, 2024, vol. 54 (available online).

[15] On self-assessment as a form of self-referential compliance and on the need to strengthen independent and participatory oversight mechanisms, see Weizenbaum Institute, Harmonised Standards and Conformity Assessments in the AI Act: Strengthening Independent and Participatory Oversight, Weizenbaum Policy Paper n. 17, November 2025. On the legitimacy and limits of harmonised standards under the AI Act, see A. Leyden, Standards and the EU AI Act: Legitimacy, State of Play, and Future Challenges, in Information & Communications Technology Law, 2025.

[16] K. Yeung, Can Risks to Fundamental Rights Arising from AI Systems Be «Managed» Alongside Health and Safety Risks? Implementing Article 9 of the EU AI Act. The notion of theatre of compliance, here extended to the regulatory framework as a whole, captures the tension between procedural compliance and the substantive protection of fundamental rights that the Regulation seeks to achieve.

[17] G. Noto La Diega, L. C. T. Bezerra, Can there be responsible AI without AI liability? Incentivizing generative AI safety through ex-post tort liability under the EU AI liability directive, in International Journal of Law and Information Technology, 2024, 1, observe that the AI Act has been criticised for relying upon the impossible task of predicting ex ante the impact of AI systems on fundamental rights, thereby establishing a preventive approach that undertakings may readily circumvent–for example, by contractually shifting liability.

[18] J.P. Quintais, Generative AI, Copyright and the AI Act, in Computer Law & Security Review, 2025.

[19] Compliance with these obligations is entrusted to voluntary codes of practice, which facilitate the demonstration of compliance without addressing the remedial dimension. The General-Purpose AI Code of Practice (10 July 2025) specifies the transparency and copyright-protection measures required under Article 53 and, for systemic-risk models, the evaluation, mitigation and security measures required by Article 55. The Code of Practice on Transparency of AI-Generated Content (10 June 2026) further specifies the obligations concerning the marking, detection and labelling of synthetic content pursuant to Article 50.

[20] See Noto La Diega – Bezerra, Can there be responsible AI without AI liability? Incentivizing generative AI safety through ex-post tort liability under the EU AI liability directive, 5. The Authors describe generative AI as a family of artificial neural networks capable of generating content on the basis of training data and identify its specific risks, including deepfakes that are difficult to distinguish from human-generated content and that may facilitate pornographic uses and identity theft; hallucinations and uncertainty in the outputs of multimodal models; infringements of copyright and privacy resulting from web scraping; and the reproduction of social biases and discriminatory outcomes. See also A. Buick, Copyright and AI training datatransparency to the rescue? in Journal of Intellectual Property Law & Practice, 2025, 182; and J.P. Quintais, Generative AI, Copyright and the AI Act, in Computer Law & Security Review, 2025.

[21] According to G. Noto La Diega – Bezerra, Can there be responsible AI without AI liability? Incentivizing generative AI safety through ex-post tort liability under the EU AI liability directive, there can be no responsible AI without AI liability. The safety of AI systems requires a remedial framework capable both of incentivising safer technological solutions and of ensuring that victims enjoy effective access to compensation. From this perspective, the proposed AI Liability Directive – subsequently withdrawn – would have harmonised non-contractual liability, thereby encouraging diligent conduct while facilitating compensation for damage suffered. The Authors nevertheless point out the proposal’s shortcomings, arising from its fault-based structure and from the limited ability of presumptions of causation to address the inherent unpredictability of generative AI systems.

[22] The proposed AI Liability Directive (COM(2022) 496 final, also referred to as the AILD) sought to facilitate fault-based claims for damages. In relation to high-risk AI systems, it introduced rules on the disclosure and preservation of evidence and allowed fault to be inferred from the breach of specific obligations laid down in the AI Act. More generally, it established a rebuttable presumption of causation between the fault and the AI-generated output from which the damage arose. Its withdrawal, announced in the Commission’s 2025 Work Programme, was formally confirmed on 6 October 2025. At present, no revised proposal has been submitted. See A. Bertolini, Artificial Intelligence and Civil Liability. A European Perspective, Study for the European Parliament, JURI Committee, July 2025.

[23] G. Noto La Diega – Bezerra, Can there be responsible AI without AI liability? Incentivizing generative AI safety through ex-post tort liability under the EU AI liability directive. While their premises concerning the unpredictability of damage caused by generative AI and the difficulty of linking such damage to the breach of a specific duty of care are persuasive, their proposed solution of strict liability is less convincing. Such an approach risks imposing liability upon the provider for downstream uses lying entirely beyond its control, while simultaneously increasing compliance costs and litigation risks. In a sector in which the European Union already faces a significant competitive disadvantage, such regulatory rigidity may ultimately weaken rather than strengthen the European innovation ecosystem.

[24] See https://www.congress.gov/crs-product/R46751. For commentary see Paul Ehrlich, ‘Communications Decency Act Sec. 230’ (2002) 17 Berkeley Technology Law Journal 401; Kimberly A. Gry, ‘The Fate of Section 230’ (2024) 22(2) Colorado Technology Law Journal, 361; Nicholas O’Donnell, ‘Have We No Decency? Section 230 and the Liability of Social Media Companies for Deepfake Videos’ (2021) 2 University of Illinois Law Review 701.

[25] Mika Westerlund, ‘The Emergence of Deepfake Technology: A Review’ (2019) 9(11) Technology Innovation Management Review 46.

[26] Liam Kearns, Abu Alam, Jordan Allison, ‘Synthetic Media Authentication Threats: Detection using a Combination of Neural Network and Blockchain Technology’ (2023), https://ssrn.com/abstract=4658121.

[27] Sharon Choi, ‘Assessing the Efficacy of Third-Party Liability Copyright Doctrines Against Platforms That Host AI-Generated Content’ (2025) 66(3) Boston College Law Review 1087, 1117.

[28] Public Prosecutor v. Zheng Jia [2025] SGHC 76. See https://www.elitigation.sg/gd/s/2025_SGHC_76.

[29] See https://www.gov.uk/government/collections/cyber-security-and-resilience-bill.

[30] See https://www.legislation.gov.uk/uksi/2018/506.

[31] The Bill imposes liability on the managed service providers (IT service providers, IT remote support and systems integration and management, managed security operations centre etc.), which expands the category of digital service providers of under NIS Regulations 2018 Regulation. The Bill does not specifically mention the liability of senior managers which may be inferred in the operational functions of those firms. Senior managers and directors are responsible under The Cyber Governance Code of Practice (https://www.gov.uk/government/publications/cyber-governance-code-of-practice/cyber-governance-code-of-practice), which complements the Bill 2024 in governing cyber security risks. See the editorial ‘In cyber attacks, humans can be the weakest link’ Financial Times (London, 26 May 2025), https://www.ft.com/content/4349b16a-8ec1-44d9-a295-3a51523805a8.

[32] Jonathon Ellison, ‘Cyber Security and Resilience Policy Statement to strengthen regulation of critical sectors’ (1 April 2025), https://www.ncsc.gov.uk/pdfs/blog-post/cyber-security-resilience-bill-policy-statement.pdf.

[33] Georgina Quach, ‘Banks and tech groups commit to live data-sharing in UK fraud clampdown’ Financial Times (London, 31 March 2025), https://www.ft.com/content/12bbd99e-ed46-418d-bc15-04433e13db30.

[34] See https://www.pkulaw.com/en_law/90cff392df74a3ebbdfb.html. For commentary see Yinuo Geng, ‘Comparing “Deepfake” Regulatory Regimes in the United States, the European Union, and China’ (2023) 7(1) Georgetown Law Technology Review 157, 169-170.

[35] FCA, ‘Crypto investment scams’, https://www.fca.org.uk/consumers/crypto-investment-scams.

[36] Federal Trade Commission Consumer Advice, ‘What To Know About Cryptocurrency and Scams’ (May 2022), https://consumer.ftc.gov/articles/what-know-about-cryptocurrency-and-scams#scams.

[37] Hannah Murphy, ‘Deepfakes and misinformation — how to tell the facts from the fiction’ Financial Times (London, 10 June 2025), https://www.ft.com/content/ee975ff0-531f-43be-9c2b-4aed39c4def5.

[38] David Krause, ‘The Rise of Online Scams and Consumer Protections: A Comparative Analysis of the U.S. and Singapore’ (2025), https://ssrn.com/abstract=5134496.

[39] See D’Aloia v Persons Unknown [2024] EWHC 2342 (Ch); Crypto Open Patent Alliance v Wright [2024] EWHC 1809 (Ch).

[40] Sabriyya Pate, ‘Platform Liability for Platform Manipulation’ (2025) 125(4) Columbia Law Review 908-909. It is argued that social media companies should be liable for platform manipulation harms facilitated by their platform designs.

[41] See R. (on the application of GB News Ltd) v Office of Communications (OFCOM) [2025] EWHC 460 (Admin).

[42] Stephen Bush, ‘Are we human or are we spammer?’ Financial Times (London, 24 June 2025), https://www.ft.com/content/07ed552a-e681-472a-8eba-c4b3a7938027.

[43] Cristina Criddle, ‘How to get the best out of AI’ Financial Times (London, 10 June 2025), https://www.ft.com/content/d2f1fa02-025c-41ff-814f-00f22ed5c6d3.

[44] Becca Cawthorne, ‘How to deal with online problems’ Financial Times (London, 10 June 2024), https://www.ft.com/content/f8937d6c-2a48-419e-b024-902b1c1f6590.

[45] Kimberley Long, ‘China’s banks cautiously adopt AI as state pushes DeepSeek rollout’ The Banker (21 March 2025), https://www.thebanker.com/content/4f23d80e-28bc-4ecc-9d96-a13f440aba42.

[46] Melissa Heikkilä, ‘The problem of AI chatbots telling people what they want to hear’ Financial Times (London, 12 June 2025), https://www.ft.com/content/72aa8c32-1fb5-49b7-842c-0a8e4766ac84.

[47] Rafe Uddin and Cristina Criddle, ‘Microsoft to rank ‘safety’ of AI models sold to cloud customers’ Financial Times (London, 7 June 2025), https://www.ft.com/content/02f39b33-fa6e-4bb7-b1f4-8171b50738af.

[48] Akila Quinio and George Parker, ‘Labour plans to force tech giants to compensate online fraud victims’ Financial Times (London, 28 June 2024), https://www.ft.com/content/16232add-cf64-44c1-bf04-635fd730b8e9.

Information

This entry was posted on 28/07/2026 by in Senza categoria.

Navigation