The regulatory toolbox: bans, obligations, disclosure, certification, liability
Lesson 3 of 5 in How AI Governance Works: Laws, Standards, and Everything Between.
Strip the philosophy away and every AI law is assembled from the same handful of tools. Regulators have been using them for a century — on drugs, cars, food, aircraft — and AI law recycles them all. Five dominate.
Bans simply prohibit a practice. The EU AI Act’s Article 5 bans social scoring by public authorities, untargeted scraping of facial images for recognition databases, and emotion recognition in workplaces and schools. Bans are the bluntest tool: maximal protection, zero flexibility — which is why they are reserved for practices judged incompatible with fundamental values at any benefit.
Obligations (ex ante requirements) let a practice proceed if conditions are met: risk management, data-quality controls, documentation, human oversight, accuracy testing. This is the workhorse of risk-based regulation — the EU AI Act’s Articles 8–15 for high-risk systems are one long obligation list. The trade: strong protection, heavy compliance cost, and rules that must be written before all the evidence is in.
Disclosure doesn’t restrict the practice at all; it forces information into the open and lets people and markets react. Tell users they are talking to a machine (EU AI Act Article 50). Label AI-generated content (China’s 2025 labeling measures; California’s AI Transparency Act). Publish safety frameworks (California SB 53; New York’s RAISE Act). Cheap, innovation-friendly — and only as strong as the audience’s ability to act on the information.
Certification interposes a gatekeeper: someone must verify conformity before the product reaches the market. The EU’s conformity assessment regime — self-assessment for most high-risk AI, notified-body review for some — is certification machinery inherited directly from EU product-safety law, CE mark and all. Audited ISO/IEC 42001 certification is its private-sector cousin.
Liability works after the fact: no gate, no checklist — but if your system injures someone, you pay. Product-liability rules (the EU’s updated Product Liability Directive extends to software and AI), negligence, and contract law all apply to AI today. Liability’s elegance is that it prices harm without prescribing methods; its weakness is that opaque systems make causation brutally hard for victims to prove — which is exactly why the EU updated its directive to ease the evidentiary burden.
Around the big five sit supporting tools: regulatory sandboxes (supervised spaces to test innovative systems — EU AI Act Articles 57–63 require every member state to run one), registration (the EU’s public database of high-risk systems), and procurement rules (governments using their buying power to impose standards contract by contract).
| Instrument | How it works | When it bites | AI example | Strength | Weakness |
|---|---|---|---|---|---|
Ban | Prohibits the practice outright | Before anything happens | EU AI Act Art 5 — social scoring, untargeted face-scraping | Absolute protection; no case-by-case fights | Blunt; hard to amend; boundary disputes migrate into definitions |
Obligation | Permits the practice subject to requirements | Before and during deployment | EU AI Act Arts 8–15 for high-risk systems | Calibrated protection; creates audit trails | Compliance cost; rules ossify; favours large players |
Disclosure | Forces information out; behaviour stays legal | At the moment of interaction or publication | Art 50 chatbot disclosure; China/California content labeling; SB 53 safety-framework publication | Cheap; preserves choice; enables watchdogs | Only works if someone can act on the information; disclosure fatigue |
Certification | A gatekeeper verifies conformity pre-market | Before market access | EU conformity assessment + CE marking; ISO/IEC 42001 certification | Independent scrutiny; portable trust signal | Gatekeeper capacity and competence; checkbox risk |
Liability | Harm triggers compensation after the fact | After harm occurs | EU Product Liability Directive (extended to AI); negligence claims | Prices real harm; no method prescription; scales with damage | Victims must prove causation against a black box; slow; uneven |
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.