Author: Rama Singh Rathore
AI surgical robots are assisting in surgeries with precision to save lives yet on the other hand due to a flawed AI surveillance system many innocent black men were wrongfully arrested. AI is expanding rapidly to which the consequence could be beneficial or detrimental, but one thing is certain that it is powerful, but unlike other powerful forces in history, this has no conscience and holds no legal standing toward anyone therefore it cannot be punished or questioned which causes an urgent need for regulations to restore balance. This article covers how different jurisdictions like the European Union, United Kingdom, United States and India have their own approach towards regulating Artificial Intelligence.
Why do we need AI Regulations?
AI is a complex tool which although can generate opportunities yet can prompts concerns towards multiple areas which needs regulations to restore the stability, those areas are:
- Infringement of Privacy– To manage complex analytics and accuracy, AI requires massive datasets which often includes personal information, Unauthorised access and a lot of personal data which infringes the right of privacy.
- Zero accountability- Although AI is a complex tool however it retains no conscience and holds no legal standing of its own as it only runs on command of others, therefore it can not be held accountable for any data breach or mishap.
- Biases in decision making- Even though AI has no conscience of their own yet it can show biases towards a specific gender or community due to various reasons like historical datasets and model training.
- Black-box nature of AI systems- AI does not provide transparency to its users as because its internal working process is a mystery, one can give the input and get the output but they cannot understand how the AI comes to that conclusion. Even the makers of AI do not know the learning process of the AI.
Comparative AI regulatory model Across different Jurisdiction
In this article there will be a comparative analysis of four different jurisdictions: European Union, United Kingdom, United States and India on the basis of their own AI regulation model.
AI Regulating framework in EU
AI regulation of the EU is the most comprehensive and advanced jurisdiction among all the four jurisdictions. Since 2018 they have initiated the foundational strategy related to AI regulations, their approach is more human-centric which ensures that this technology respects the fundamental rights, safety and security of their people. In the year of 2021 the European commission submitted its first AI regulatory proposal called The AI Regulatory Act and one of its core concepts was the “Risk Management Approach” which obligates the users on the basis of the level of risks they carry. These risks are classified into four categories, which are:
- Unacceptable Risk- AI systems that come under this category are totally banned and cannot be used under the European Union because they are against human rights. Example:- Social Scoring which is a practice of using artificial intelligence to classify different people on the basis of their behaviour, status and characteristics.
- High Risk- It includes those AI systems which have a heavy impact on the safety , security and the fundamental rights of the people and are highly risky to be used. Example:- Matters related to education, health, unemployment or law enforcement as non-compliance with these can highly impact the people.
- Limited Risk- AI systems that are commonly used by deployers or developers on a day to day basis have transparency risks. Example:- Chatbots and Deepfakes
- Minimal Risk- As the name suggests, those AI applications which consider minimal risks and cannot harm or impact human rights. Example:- Spam filters and AI enabled video games.
In 2024 the European Union AI Act was passed.
Even though it is the most comprehensive AI regulatory model in the world yet their EU AI Act still gets criticized for slowing down the innovation and putting heavy burden on the small companies and markets.
AI regulatory model of UK
Unlike The European AI regulatory model, the UK has chosen a more liberal and flexible approach rather than comprehensive and restrictive. It also chooses a sector based approach which is innovation-friendly and focuses on economic growth without much restrictions. In the UK instead of one central regulatory body they are divided into different sectors of their own domain and rely on them, for example Ofcom to regulate online services. In the year of 2023 the UK government published an AI white paper which rejected the central AI regulatory model and cleared the sectoral bodies that will manage the regulations according to these five principles:
- Safety
- Transparency
- Accountability
- Fairness and
- Contestability
However, this flexibility and liberty is an actual concern and weakness of the UK AI regulation model because without a central binding AI law can create certain gaps between the different sectoral bodies and can cause harm without accountability.
AI Regulatory Model of USA
Just like the United Kingdom regulatory model, the United States also does not have a single federal AI regulatory model, instead every individual state has their own regulations, which scholars described as a “Patchwork of the legislation” across the country. In the year 2020 US first federal AI law was passed called “National AI Initiative Act” which was related to research and development but it was not a regulation. Former President Joe Biden signed an executive order on AI in 2023 because of which agencies could access the AI risk and he also directed the AI companies to share safety test results with the government, however in 2025 Trump administration has reversed the order and replaced it with innovation-first approach. In the states also over 800 bills related to AI have been introduced since 2019 but only 30 federal laws have been enacted and yet none of them are able to establish a broad regulatory authority for AI because of which an inconsistency between the state laws has been created as a person’s right are only depend entirely where they live.
AI Regulatory Model In India
India has the largest AI market in the world yet has the least developed AI Regulatory framework among the four jurisdictions because there is no dedicated AI law in India instead there are three laws through which AI is regulated indirectly and those laws are:
- IT Act 2000- This act was enacted in 2000 which is way before AI existed therefore the provisions that are given under this act are not specifically made for AI.
- DPDP Act 2023- This is “Tha Digital Personal Data Protection Act” which is related to data protection and consent, this does not specifically regulate how an AI system does.
- NITI Aaayog’s national strategy of AI- This is just a policy not a binding law therefore it does not have any enforcement.
Due to the lack of a dedicated AI law there are various risks and gaps that can harm the human rights of users like no framework for accountability, no policy for privacy violations and no transparency which makes this jurisdiction weakest among all.
Unlike the European Union, United Kingdom and United States who are consistently working on their AI models and trying to maximise their potential, India is still Remaining inactive and waiting for the problems to escalate before taking any response.
| Basis | EU | UK | US | India |
| Type of Regulation | One binding comprehensive regulation | It has sector based approach and not binding | No federal regulations only voluntary framework | No AI regulatory model at all |
| Approach towards AI regulation | Have risk management approach and restrictive approach | Have liberal and flexible approach not rigid | More focused on innovation that regulation | No framework exists for regulation |
| Priority | Human rights and safety first | Economic growth and innovation | Innovation first | Only digital growth |
| Development Stage | Most advanced and fully enacted | Still developing as no binding law | No federal law, fragmented | Not even started to make regulations |
Comparative Analysis
- The fundamental Difference- All the four jurisdictions have the idea that AI is a powerful tool and need regulations but all of them have different philosophies towards it like European Union wants the restriction first because human rights comes first for it, UK and US both puts innovation first and believes in flexibility whereas India does not have any philosophy yet.
- Common Problem- Even after having different approaches and regulations none of them are able to solve the problem of accountability, they have comprehensive and flexible regulations but still they do not know who will be accountable for the harm caused by AI, India left its largest AI market fully exposed as it neither have any approach nor any aim for making an approach.
- My Own Opinion- If I would be asked which approach should I choose, my choice will be the EU approach because it is the closest to removing all the risks that we discussed above and I know innovation is also important but cannot come at the price of human rights and safety. A restrictive approach not only saves the personal data but also reduces the harm before it occurs. India is the one that needs to learn the most from the EU regulative model.
Conclusion
After analysing all the four jurisdictions by their model, approach and priorities one thing is certain that even after having comprehensive regulations and flexible processes a perfect AI model did not exist yet. An ideal framework should address all the issues that are generated because of AI like privacy violations, accountability or transparency otherwise it will impact both the users and non-users . At least all other countries are working towards it but India is the one who needs to work on its approach the most, India should begin by enacting a dedicated AI law that builds on the foundation of the DPDP Act 2023 and adopts a risk-based approach similar to the EU model . Not just some countries but all the countries that are using AI extensively should take the responsibility and generate an AI regulation model that addresses all the issues and concerns without harming human rights.