What the legal framework around AI is made of
AI law and regulation · Lesson 1 / 21
There is no single AI law in your life
When a company first thinks about the legal side of AI, it usually goes looking for one document that says what is allowed and what is not. No such document exists in any jurisdiction. The legal framework around AI is built from several layers, and dedicated AI regulation is the thinnest and youngest of them.
Four layers that apply at the same time
- General law. Contract, tort, corporate. It applies to AI exactly as it applies to any other tool: someone promised a result, someone caused harm, someone is answerable for it.
- Data and fundamental rights regimes. Data protection, non-discrimination, consumer protection, employment law. This is where most of your real obligations come from, simply because AI almost always runs on data about people and makes decisions about people.
- Sector requirements. Health, finance, transport, education, public procurement. If your sector is already regulated, AI inside it inherits everything the sector demands: validation, oversight, reporting.
- Dedicated AI regulation. Risk classification, transparency duties, documentation, impact assessment. It sits on top of the earlier layers rather than replacing them.
The practical conclusion is simple. If you start from the question of what the AI law says, you will almost certainly miss nine out of ten obligations you already have. Start from the bottom instead: from data, from the consumer, from the worker, from your sector.
Insight. Most of the prohibitions you will meet are older than any AI regulation. You could never covertly profile employees, mislead a consumer, or process personal data without a basis. All of that was true long before generative models arrived.
What this looks like in practice
Layer map for a single use case 1. What the use case is, in one sentence 2. Whose data is involved 3. Who the decision ultimately lands on (customer, employee, applicant) 4. The sector and what it already demands 5. AI-specific duties (transparency, labelling, documentation) 6. Where you will verify the current wording of the requirements
Common mistake. Assuming that because you merely use someone else's service you owe nothing. Being a deployer is a role with its own duties, and it is usually the deployer who answers to the person the decision affected.
Pro tip. Keep one table of sources: for each jurisdiction, a link to the official text and the date you last checked it. Second-hand summaries in articles go stale faster than new versions are published.
Cheat sheet
- The AI legal framework is a stack of layers, not one law.
- Most obligations come from data protection and sector rules.
- Dedicated AI regulation adds duties but removes none.
- Work from the primary source in your jurisdiction, not from a summary.
1. Why is hunting for a single AI law a poor starting point?
2. Which layer usually produces the most practical obligations?
3. What is true about how the layers relate?