The EU AI Act: Risk-Based Regulation
The EU AI Act is the world's first comprehensive AI regulation and establishes a risk-based framework that will shape global AI governance for years to come. Adopted in 2024, it categorizes AI systems into four risk tiers, each with escalating requirements.
Unacceptable risk systems are banned outright. These include social scoring systems used by governments, real-time remote biometric identification in public spaces (with narrow law enforcement exceptions), AI that exploits vulnerabilities of specific groups (children, elderly, disabled persons), and subliminal manipulation techniques that cause harm. High-risk systems face the heaviest compliance burden and include AI used in critical infrastructure, education, employment, essential services (credit scoring, insurance), law enforcement, migration management, and the administration of justice. Limited risk systems (like chatbots) have transparency obligations — users must be informed they're interacting with AI. Minimal risk systems (like spam filters or AI in video games) face no specific requirements.
High-risk AI systems must satisfy extensive requirements before being placed on the EU market. These include: a risk management system maintained throughout the AI lifecycle, data governance requirements for training and validation datasets, technical documentation detailed enough for authorities to assess compliance, record-keeping and automatic logging of system operations, transparency provisions ensuring users can interpret outputs, human oversight measures enabling operators to intervene, and requirements for accuracy, robustness, and cybersecurity.
The Act also introduced obligations for general-purpose AI (GPAI) models, including foundation models and LLMs. All GPAI providers must provide technical documentation, comply with EU copyright law, and publish summaries of training data. GPAI models deemed to pose systemic risk (currently defined as those trained with >10^25 FLOPs) face additional obligations: model evaluations, adversarial testing, incident reporting to the European AI Office, and adequate cybersecurity measures. For AI PMs, the EU AI Act means conducting a risk classification analysis for every AI product or feature, building compliance documentation into your development process, and budgeting for conformity assessments.
US AI Regulation and State-Level Laws
Unlike the EU's comprehensive approach, US AI regulation has developed through a patchwork of executive orders, agency guidance, sector-specific rules, and increasingly, state-level legislation. Understanding this landscape is essential for AI PMs operating in the US market.
The Biden Executive Order on AI (October 2023) established broad directives including: requiring developers of powerful AI systems to share safety test results with the government, directing NIST to develop standards for red-teaming and safety evaluation, addressing AI's impact on the labor market, and promoting responsible government use of AI. While executive orders set direction, they rely on agency rulemaking for enforcement and can be modified by subsequent administrations.
At the state level, legislation is accelerating rapidly. Colorado's AI Act (2024) requires deployers of high-risk AI systems to conduct impact assessments and provide consumer notifications. New York City's Local Law 144 mandates annual bias audits for automated employment decision tools. California has pursued multiple AI bills addressing deepfakes, AI training data transparency, and AI safety requirements for frontier models. Illinois' AI Video Interview Act requires consent before using AI to analyze video interviews. This patchwork creates compliance complexity — your product may face different requirements in different states.
Federal agency guidance adds another layer. The FTC has taken enforcement actions against companies making deceptive AI claims and using biased AI systems, applying existing consumer protection law to AI. The EEOC has issued guidance on AI in employment decisions, emphasizing that Title VII liability applies even when discrimination results from AI tools. The FDA has developed a framework for AI/ML-based medical devices. The SEC has proposed rules on AI in financial services. For AI PMs, this means tracking requirements across multiple jurisdictions and agencies, and building products flexible enough to comply with the most stringent applicable standard — what practitioners call "regulation to the highest bar."
GDPR, Data Protection, and AI
The General Data Protection Regulation (GDPR) was enacted before the current AI boom, but its provisions have profound implications for AI systems. Any AI product processing personal data of EU residents must comply with GDPR, and several provisions are particularly relevant to AI.
Article 22 gives individuals the right not to be subject to decisions based solely on automated processing that significantly affect them. This means AI systems making consequential decisions (credit, employment, insurance) must provide meaningful human involvement or obtain explicit consent. The right to explanation — while debated in its exact scope — requires that individuals can obtain "meaningful information about the logic involved" in automated decisions. For black-box models, this creates a tension between model complexity and explainability requirements.
The lawful basis for processing training data is a critical challenge. Most AI training relies on legitimate interest as the legal basis, but this requires a balancing test weighing the organization's interests against individuals' rights. Consent is difficult to obtain for training data scraped from the web. Several data protection authorities have challenged AI companies' use of personal data for training, with the Italian DPA temporarily banning ChatGPT in 2023 over GDPR concerns.
Data Protection Impact Assessments (DPIAs) are mandatory for high-risk processing, which includes systematic profiling, large-scale processing of sensitive data, and automated decision-making with legal effects — categories that frequently apply to AI systems. A DPIA must describe the processing, assess its necessity and proportionality, identify risks to individuals, and detail mitigation measures. Data minimization and purpose limitation principles mean you should only collect and use personal data strictly necessary for the AI system's purpose, and not repurpose data without additional justification. For AI PMs, GDPR compliance requires close collaboration with legal and privacy teams from the design phase — retrofitting compliance into an existing AI product is far more expensive than building it in from the start.
Sector-Specific AI Regulations
Beyond horizontal AI regulations, several sectors have domain-specific rules that AI PMs must navigate. These often predate modern AI but are being interpreted and updated to address AI-specific challenges.
Healthcare is one of the most heavily regulated domains for AI. The FDA regulates AI/ML-based Software as a Medical Device (SaMD) and has approved over 900 AI-enabled medical devices as of 2024. The FDA's predetermined change control plan framework allows manufacturers to describe anticipated modifications to the AI algorithm, enabling iterative improvement without requiring new clearance for each update. HIPAA governs the use of protected health information in AI training and inference. The 21st Century Cures Act addresses interoperability and information blocking. AI PMs in healthcare must navigate a complex approval process that balances innovation speed with patient safety.
Financial services face oversight from multiple regulators. The OCC, FDIC, and Federal Reserve issued joint guidance on model risk management (SR 11-7 / OCC 2011-12) that applies to AI models used in lending, fraud detection, and risk assessment. The Fair lending laws (ECOA, Fair Housing Act) require explainability for credit decisions — a significant constraint on black-box AI models. The SEC has proposed rules requiring broker-dealers to eliminate conflicts of interest in AI-driven investment recommendations. Anti-money laundering (AML) regulations like the Bank Secrecy Act affect how AI can be used in transaction monitoring.
Other regulated sectors include education (FERPA protects student data, and the Department of Education has issued guidance on AI in schools), transportation (NHTSA regulates autonomous vehicles, and the FAA oversees AI in aviation), and employment (EEOC applies Title VII to AI hiring tools, and several states require disclosure of AI in hiring). For AI PMs, the key takeaway is that sector-specific regulations often impose requirements beyond horizontal AI laws. Your compliance strategy must layer sector rules on top of general AI regulation — and the most restrictive rule wins.
International AI Governance and Compliance Strategies
AI governance is a global challenge with no single international framework, creating a complex compliance landscape for AI products with international reach. Understanding regional approaches helps AI PMs develop efficient compliance strategies.
China has taken an active regulatory approach with sector-specific AI rules. The Algorithmic Recommendation Regulation (2022) requires transparency in recommendation systems and gives users the right to opt out of personalized recommendations. The Deep Synthesis Regulation (2023) governs deepfakes and synthetic media. The Generative AI Measures (2023) require AI-generated content to reflect "core socialist values" and mandate security assessments before public deployment. The Global AI Governance Initiative positions China as an advocate for developing-country participation in AI governance.
The UK has adopted a "pro-innovation" approach, favoring sector-specific guidance over comprehensive legislation. Rather than creating a new AI regulator, existing regulators (FCA, Ofcom, CMA, ICO) apply AI principles within their domains. The AI Safety Institute (AISI) focuses on frontier model evaluation. Canada's AIDA (Artificial Intelligence and Data Act) takes a risk-based approach similar to the EU. Japan emphasizes industry self-regulation and "agile governance." Brazil, India, and South Korea are all developing their own frameworks, often borrowing elements from the EU approach.
For AI PMs building products with international reach, practical compliance strategies include: Regulatory mapping — cataloging all applicable regulations for each market you serve. Highest-bar compliance — building to the most stringent standard (usually the EU AI Act) as your baseline, then adding market-specific requirements. Modular compliance architecture — designing your system so that compliance features (transparency, explainability, logging, human oversight) can be activated or configured per jurisdiction without rebuilding the core product. Regulatory monitoring — establishing a process to track new and evolving regulations across your markets. Compliance documentation as code — automating the generation of required documentation (model cards, impact assessments, risk analyses) as part of your ML pipeline rather than treating it as a separate manual process.
The international landscape is evolving rapidly, and regulatory divergence creates both challenges and opportunities. Companies that build robust, flexible compliance frameworks now will have a significant competitive advantage as regulations mature.