Conflict Between United States and European Law

Introduction:

The world of Artificial Intelligence (“AI”) in business is multinational which creates significant issues for the businessperson seeking to understand which laws apply to the use of AI created products. The Federal government and certain states, such as California, have radically different sets of restrictions and enforcement provisions, as discussed in other articles on this website, and it is currently unclear if the Federal government will be able to take control of the legal realm imposed upon AI by the states. It may be expected that over the next decade there will be a series of cases that will better define their respective roles in creating laws that relate to AI, but for now the regime of both the State and the Federal government will apparently pertain. 

But the matter becomes even more complicated when it is realized that the use of the internet for transactions and sales makes any transaction potentially international in scope. Even though your company may be based entirely in the United States.  If your product or service is obtained by a citizen or entity located in the European Union (“EU”) then that law may apply. The EU ARTIFICIAL INTELLIGENCE ACT (hereafter “ACT”) pertains “…to users located in the EU and third country users where the AI system’s output is used in the EU.”  It is not where you are located.  It is where the AI product is used.  

Thus, the business or individual seeking to utilize AI for a product or business that could be utilized in the EU must recognize that those laws might very well be applied to the transaction and should take the time to learn the basic law of the EU as to AI.

The Basic System:

It may be argued that the EU has the most complete and protective system of legislation developed for AI.  Give the current administration’s extremely business friendly approach, almost no laws have been passed federally, and each state now has its own system. Such confusion and ideologically driven inaction does not apply in the EU and they have adopted a powerful, complete and thought-out system of regulations, most of which are explained online in lay terms.

Europe’s primary legislation is the EU Artificial Intelligence Act. It is the world’s first comprehensive, legally binding framework for AI, enforcing a risk-based classification system for all developers and deployers: Note that the law pertains to those who develop or deploy AI, not to those who are users.

The three categories of risk are as follows:

  • Unacceptable Risk (Prohibited): Systems such as social scoring, subliminal behavioral manipulation, and untargeted internet scraping for facial recognition are illegal. 
  • High Risk: Systems used in employment (e.g., CV ranking), education, critical infrastructure, and law enforcement require strict technical documentation, human oversight, and registration in an EU database. 
  • Limited Risk: Generative AI (such as ChatGPT) and deepfakes must comply with transparency and copyright rules, requiring you to disclose when content is AI-generated. 

The strictest laws and regulations apply to providers (developers) of high-risk AI systems.

Users are natural or legal persons (limited liability entities, for example) that deploy an AI system in a professional capacity.

But note that users (“Deployers”) of high-risk AI systems have some obligations, though less than providers (“Developers”). High risk AI systems thus impose rules upon both the Developer and User and those obligations can result in serious penalties if violated. Thus, it is vital to know if the particular AI being utilized would fall into the High Risk category and, of course, Unacceptable Risk Category must be avoided entirely. 

Prohibited AI:

The following types of AI system are ‘Prohibited’ according to the Act:

The Act prohibits any AI systems that:

  • Deploying subliminal, manipulative, or deceptive techniques to distort behavior and impair informed decision-making, causing significant harm.
  • Exploiting vulnerabilities related to age, disability, or socio-economic circumstances to distort behavior, causing significant harm.
  • Biometric categorization systems inferring sensitive attributes (race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation), except labelling or filtering of lawfully acquired biometric datasets or when law enforcement categories biometric data.
  • Social scoring, i.e., evaluating or classifying individuals or groups based on social behavior or personal traits, causing detrimental or unfavorable treatment of those people.
  • Assessing the risk of an individual committing criminal offenses solely based on profiling or personality traits, except when used to augment human assessments based on objective, verifiable facts directly linked to criminal activity.
  • Aompiling facial recognition databases by untargeted scraping of facial images from the internet or CCTV footage.
  • Inferring emotions in workplaces or educational institutions, except for medical or safety reasons.
  • ‘Real-time’ remote biometric identification (RBI) in publicly accessible spaces for law enforcement, except when:
    • Searching for missing persons, abduction victims, and people who have been human trafficked or sexually exploited;
    • Preventing substantial and imminent threat to life, or foreseeable terrorist attack; or
    • Identifying suspects in serious crimes (e.g., murder, rape, armed robbery, narcotic and illegal weapons trafficking, organized crime, and environmental crime, etc.). Using AI-enabled real-time RBI is only allowed when not using the tool would cause considerable harm and must account for affected persons’ rights and freedoms.

    It is worthwhile to consider the breadth of section 1, above. That definition of prohibited action would apply to any ‘deceptive” technique to “distort behavior and impair informed decision making…”  That definition would seem to apply to almost all advertising or promotional materials that is considered “deceptive.”  In the United States it would likely encounter Constitutional challenges as to interfering with free speech but in the EU such rights are often subsumed into protecting the public (as in the United States at times…crying fire in a crowded theater is not protected speech…)

    These very broad criteria will undoubtedly be limited in the future, but for now prohibited activity for AI in the EU is remarkably unclear and extensive. 

    General purpose AI (GPAI):

    All GPAI model providers must provide technical documentation, instructions for use, comply with the Copyright Directive, and publish a summary about the content used for training.

    Free and open license GPAI model providers only need to comply with copyright and publish the training data summary, unless they present a systemic risk.

    All providers of GPAI models that present a systemic risk – open or closed – must also conduct model evaluations, adversarial testing, track and report serious incidents and ensure cybersecurity protections.

    Before deployment, police must complete a fundamental rights impact assessment and register the system in the EU database, though, in duly justified cases of urgency, deployment can commence without registration, provided that it is registered later without undue delay.

    Before deployment, they also must obtain authorization from a judicial authority or independent administrative authority, though, in “duly justified cases of urgency”, deployment can commence without authorization, provided that authorization is requested within 24 hours. If authorization is rejected, deployment must cease immediately, deleting all data, results, and outputs.

    High Risk AI Systems

    Some AI systems are considered ‘High risk’ under the AI Act. Providers of those systems will be subject to additional requirements.

    High risk AI systems are those used as a safety component or a product covered by EU laws in Annex I AND required to undergo a third-party conformity assessment under those Annex I laws: OR

    listed under Annex III use cases (below), except if:

    The AI system performs a narrow procedural task.

    Improves the result of a previously completed human activity.

    Detects decision-making patterns or deviations from prior decision-making patterns and is not meant to replace or influence the previously completed human assessment without proper human review; or

    Performs a preparatory task to an assessment relevant for the purpose of the use cases listed in Annex III.

    AI systems listed under Annex III are always considered high-risk if it profiles individuals, i.e. automated processing of personal data to assess various aspects of a person’s life, such as work performance, economic situation, health, preferences, interests, reliability, behavior, location or movement.

    High risk AI providers must establish a risk management system throughout the high-risk AI system’s lifecycle and, further:

    • Conduct data governance, ensuring that training, validation and testing datasets are relevant, sufficiently representative and, to the best extent possible, free of errors and complete according to the intended purpose.
    • Draw up technical documentation to demonstrate compliance and provide authorities with the information to assess that compliance.
    • Design their high-risk AI system for record-keeping to enable it to automatically record events relevant for identifying national level risks and substantial modifications throughout the system’s lifecycle.
    • Provide instructions for use to downstream deployers to enable the latter’s compliance.
    • Design their high-risk AI system to allow deployers to implement human oversight.
    • Design their high-risk AI system to achieve appropriate levels of accuracy, robustness, and cybersecurity.
    • Establish a quality management system to ensure compliance.

    Enforcement: 

    • The AI Office will be established, sitting within the Commission, to monitor the effective implementation and compliance of GPAI model providers.
    • Downstream providers can lodge a complaint regarding the upstream providers’ infringement to the AI Office.
    • The AI Office may conduct evaluations of the GPAI model to:
    • assess compliance where the information gathered under its powers to request information is insufficient.
    • Investigate systemic risks, particularly following a qualified report from the scientific panel of independent experts.

    Requirements Imposed by August 2026

    • Article 50 of the EU AI Act may affect more organizations than almost any other provision. It introduces transparency obligations on providers and deployers of certain AI systems, under which users must be informed when they are interacting with an AI system or where content is AI-generated. These obligations extend to providers and deployers of open-source AI systems, which are not exempt.
    • Transparency obligations are not limited to systems classified as “high-risk”: they apply to any AI system used in the four situations the Article covers. In practice, Article 50 is relevant to every business that uses generative AI to produce content. 
    • Article 50 of the EU AI Act introduces transparency obligations in four situations:
      • when AI interacts directly with people,
      • when AI generates synthetic content,
      • when AI is used for emotion recognition or biometric categorization, and
      • when AI creates deepfakes or text published on matters of public interest.

      These obligations apply to all AI systems used in the four situations set out in Article 50, not just to high-risk systems.

      The Commission has published draft Guidelines on the scope and application of Article 50, and a Code of Practice on AI-generated content is being developed to provide practical solutions on marking and labelling.

      Rules for Providers:

      • Providers of chatbots, virtual assistants and other systems intended to interact with people must design them so that users are informed they are interacting with AI.
      • Providers of generative AI systems — producing text, images, audio, video — must mark outputs in a machine-readable format and ensure they are detectable as artificially generated or manipulated. A standardized EU label is being developed.

      Rules for Deployers:

      • Deployers of emotion recognition or biometric categorization systems must inform exposed individuals.
      • Deployers using AI to create deepfakes must disclose that the content has been artificially generated or manipulated. Deployers publishing AI-generated text with the purpose of informing the public on matters of public interest must disclose that the text is AI-generated, unless it has been subject to human review and editorial responsibility.

      Note that much of the AI Act focuses on high-risk AI systems, including conformity assessments, technical documentation and CE marking requirements. But high-risk status only applies to a subset of AI uses.

      Article 50 works differently. Its transparency obligations apply broadly, to any AI system used in the four situations it covers. An organization with no high-risk AI may still have significant obligations under Article 50: for example, because it develops a customer-facing chatbot, deploys an AI tool that generates news content for publication, or relies on a system that produces deep-fake imagery.

      The four transparency obligations

      1. Informing people they are interacting with AI (Article 50(1))

      When an AI system is intended to interact directly with people (such as chatbots, virtual assistants and automated phone systems), its provider must design and develop it so that users are informed they are interacting with an AI. The draft Guidelines confirm that AI agents fall within Article 50(1), and where the provider cannot reliably predict whether the agent will interact with a human, it should be designed to disclose its AI nature in every such situation.

      There is an exception where it is “obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect” that an AI is involved — but this should not be over-relied on. The draft Guidelines set out a two-step approach to establish this: first, assess the target audience, and second, examine how reasonably well-informed, observant and circumspect an average member of that group is. There is also an exception for AI systems that are lawfully authorized to detect, prevent, investigate or prosecute criminal offences, unless those systems are available for the public to report a criminal offence.

      2. Marking AI-generated synthetic content (Article 50(2))

      Providers of AI systems (including general-purpose AI systems) that generate synthetic audio, image, video, or text must ensure that outputs are both marked in a machine-readable format and detectable as AI-generated. This is a technical obligation aimed at provenance: enabling detection tools to verify whether content is AI-generated.

      Note that this obligation does not apply where the AI system performs only an assistive function for standard editing (e.g. grammar correction) or where it does not substantially alter the input data or its semantics. There is also a carve-out for systems authorized by law to detect, prevent, investigate or prosecute criminal offences.

      3. Disclosing emotion recognition and biometric categorization (Article 50(3))

      When an AI system is used specifically to recognize people’s emotions or categorize them biometrically (for example to assess stress, sentiment, or demographic characteristics), deployers must inform the natural persons exposed to it. 

      This obligation is distinct from the prohibition on emotion recognition in workplaces and education institutions under Article 5, which is already in force. Outside of those settings, emotion recognition is generally permitted, and Article 50(3) disclosure obligations apply. A carve-out applies for systems permitted by law to detect, prevent or investigate criminal offences.

      4. Labelling deepfakes and AI-generated public interest text (Article 50(4))

      This is the most scrutinized part of Article 50. It imposes obligations on deployers (in this context, often the publisher or content producer using AI systems) and covers two distinct cases:

      Deepfakes. Deployers using AI to create deepfakes (defined in Article 3(60) as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear authentic or truthful) must disclose this. The draft Guidelines clarify that clearly fantastical or physically impossible content (e.g. dragons or humans flying unaided) falls outside the deepfake definition. The proposed approaches include persistent visual labels, opening disclaimers for video, and audible warnings for audio. Where deepfake content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programmed, the disclosure obligation is reduced: it is limited to disclosing the existence of the generated or manipulated content “in an appropriate manner that does not hamper the display or enjoyment of the work”.

      However, this obligation does not apply where the use is authorized by law to detect, prevent, investigate or prosecute criminal offences.

      AI-generated text published on matters of public interest. Where deployers publish AI-generated or manipulated text with the purpose of informing the public on matters of public interest, they must disclose that the text is artificially generated or manipulated. The trigger turns on the publisher’s purpose, not merely the subject matter. The obligation does not apply where the AI-generated content has undergone a process of human review or editorial control, and a natural or legal person holds editorial responsibility for the publication. Such checks must be substantive and not limited to superficial matters or cursory approval.

      Practical Steps:

      • If you provide a customer-facing chatbot or virtual assistant: review your current disclosure practices. Ensure users are informed they are interacting with AI at the start of every interaction. Review your interface design — the disclosure should be clear and not buried.
      • If you provide generative AI systems: begin assessing your technical capacity for machine-readable marking of outputs. Engage with the Code of Practice process and ensure your systems will produce compliant output markings at scale.
      • If you deploy emotion recognition or biometric categorization systems: screen first for the Article 5 prohibitions, then design clear notice for exposed individuals and ensure processing meets other legal requirements.
      • If you publish AI-generated content: inventory your content production workflows. Identify where AI-generated content is published externally (website, social media, reports, marketing materials). For deepfake imagery, audio or video, plan disclosure from the outset. For text, assess whether it is being published with the purpose of informing the public on matters of public interest, and whether you can rely on the human-review and editorial-responsibility carve-out.

      Providers

      For systems that interact directly with people, ensure clear AI disclosure at the time of first interaction, in a manner that meets accessibility requirements.

      For generative AI systems (including GPAI), implement machine-readable marking of synthetic outputs across all modalities (audio, image, video, text).

      Deployers

      For emotion recognition or biometric categorization, screen each use case against the Article 5 prohibition before considering Article 50(3) disclosure.

      For permitted uses, design notice mechanisms that inform exposed individuals in clear and distinguishable form.

      For deepfake-capable systems, map all use cases producing image, audio or video content that may meet the “deepfake” definition and design appropriate disclosure.

      Inventory text outputs published and identify those published with the purpose of informing the public on matters of public interest. For in-scope text, either implement disclosure or establish the process for human review and editorial responsibility to rely on the carve-out.

      Above all, have your legal department or attorney learn Article 50.

      Conclusion: 

      As of this writing in 2026 the Federal government has done little to establish a unified system as to AI in the United States while some states, such as California, have adopted far more stringent and complex rules that apply. The EU, as seen above, has gone beyond both jurisdictions in adopting far reaching obligations.

      It may be tempting for developers and users to rely on the current lack of rules in the United States federal system but that would be short sighted, indeed. More likely, under a more balanced administration, rules akin to California are likely to be adopted and the international aspect of the use of AI is likely to involve even “domestic” developers and users in the United States to understand that the product and uses are likely to be considered subject to the regimes above.

      Some jurisdictions may never have effectively enforced regulations. Some jurisdictions may remain business friendly and not demonstrate interest in protecting the consumer. But it is likely that the larger jurisdictions in which the largest markets prevail will follow the example set by the EU and the wise business will take steps to conform to the requirements now.