The regulatory toolbox: bans, obligations, disclosure, certification, liability

Lesson 3 of 5 in How AI Governance Works: Laws, Standards, and Everything Between.

Strip the philosophy away and every AI law is assembled from the same handful of tools. Regulators have been using them for a century — on drugs, cars, food, aircraft — and AI law recycles them all. Five dominate.

Bans simply prohibit a practice. The EU AI Act’s Article 5 bans social scoring by public authorities, untargeted scraping of facial images for recognition databases, and emotion recognition in workplaces and schools. Bans are the bluntest tool: maximal protection, zero flexibility — which is why they are reserved for practices judged incompatible with fundamental values at any benefit.

Obligations (ex ante requirements) let a practice proceed if conditions are met: risk management, data-quality controls, documentation, human oversight, accuracy testing. This is the workhorse of risk-based regulation — the EU AI Act’s Articles 8–15 for high-risk systems are one long obligation list. The trade: strong protection, heavy compliance cost, and rules that must be written before all the evidence is in.

Disclosure doesn’t restrict the practice at all; it forces information into the open and lets people and markets react. Tell users they are talking to a machine (EU AI Act Article 50). Label AI-generated content (China’s 2025 labeling measures; California’s AI Transparency Act). Publish safety frameworks (California SB 53; New York’s RAISE Act). Cheap, innovation-friendly — and only as strong as the audience’s ability to act on the information.

Certification interposes a gatekeeper: someone must verify conformity before the product reaches the market. The EU’s conformity assessment regime — self-assessment for most high-risk AI, notified-body review for some — is certification machinery inherited directly from EU product-safety law, CE mark and all. Audited ISO/IEC 42001 certification is its private-sector cousin.

Liability works after the fact: no gate, no checklist — but if your system injures someone, you pay. Product-liability rules (the EU’s updated Product Liability Directive extends to software and AI), negligence, and contract law all apply to AI today. Liability’s elegance is that it prices harm without prescribing methods; its weakness is that opaque systems make causation brutally hard for victims to prove — which is exactly why the EU updated its directive to ease the evidentiary burden.

Around the big five sit supporting tools: regulatory sandboxes (supervised spaces to test innovative systems — EU AI Act Articles 57–63 require every member state to run one), registration (the EU’s public database of high-risk systems), and procurement rules (governments using their buying power to impose standards contract by contract).

The five core instruments compared
InstrumentHow it worksWhen it bitesAI exampleStrengthWeakness

Ban

Prohibits the practice outright

Before anything happens

EU AI Act Art 5 — social scoring, untargeted face-scraping

Absolute protection; no case-by-case fights

Blunt; hard to amend; boundary disputes migrate into definitions

Obligation

Permits the practice subject to requirements

Before and during deployment

EU AI Act Arts 8–15 for high-risk systems

Calibrated protection; creates audit trails

Compliance cost; rules ossify; favours large players

Disclosure

Forces information out; behaviour stays legal

At the moment of interaction or publication

Art 50 chatbot disclosure; China/California content labeling; SB 53 safety-framework publication

Cheap; preserves choice; enables watchdogs

Only works if someone can act on the information; disclosure fatigue

Certification

A gatekeeper verifies conformity pre-market

Before market access

EU conformity assessment + CE marking; ISO/IEC 42001 certification

Independent scrutiny; portable trust signal

Gatekeeper capacity and competence; checkbox risk

Liability

Harm triggers compensation after the fact

After harm occurs

EU Product Liability Directive (extended to AI); negligence claims

Prices real harm; no method prescription; scales with damage

Victims must prove causation against a black box; slow; uneven

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.