Discussion about this post

User's avatar
Bhan's avatar

One thing I’ve been wondering about as enforcement begins is whether the AI Act’s capacity to observe risk can eventually match its regulatory reach.

The Act can reach certain providers and deployers outside the EU when their AI output is used inside the Union. Article 85 also gives natural and legal persons a complaint route, while enforcement is handled through the AI Office and national authorities. So there is clearly machinery here. (Eur-Lex)

The part I’m less certain about is what happens at the outer edges of EU-linked supply chains.

Europe is heavily dependent on third countries for a number of critical inputs, and African economies are an important part of several of those relationships, alongside major agricultural and other supply chains. The EU itself is actively trying to strengthen and diversify those external dependencies. (European Commission)

That creates a fairly significant asymmetry: the regulatory and surveillance institutions are predominantly inside a highly developed European market, while some of the earliest real-world effects of an AI system could appear much farther upstream, among producers, contractors, smaller businesses or communities with considerably less institutional leverage.

That may have been easier to overlook in older regulatory environments. With AI, I’m not sure that is a safe assumption.

Imagine the same AI system produces small but correlated errors across several thousand suppliers. Individually, the resulting incidents might look trivial, local or unrelated. They may occur in different countries, languages and commercial relationships. Yet economically they could be manifestations of the same underlying model behavior.

If only a small fraction become complaints, or if those complaints reach different authorities without being connected, the regulator could end up with data that is perfectly accurate about what it saw, while still being materially incomplete about what was actually happening.

That is where I see a potential Black-Swan-style economic problem. Not a pure Black Swan in the technical sense, because the vulnerability can be imagined beforehand, but a tail event whose scale appears unexpectedly large because its precursor signals were dispersed outside the regulator’s strongest field of observation.

A risk-based law ultimately depends on the quality of the information feeding its understanding of risk.

So perhaps extraterritorial reach eventually requires something analogous to decentralized observational capacity as well, not necessarily EU field offices, but trusted regional mechanisms capable of receiving, validating and aggregating signals where important EU supply chains actually originate: cooperation with local regulators, producer associations, universities, trade bodies, civil society or other credible intermediaries.

Otherwise there is a possibility that jurisdiction becomes geographically broader than situational awareness.

I don’t take that as an argument against the AI Act. It may actually be an argument for strengthening its credibility as implementation matures. If the EU intends to regulate AI effects that cross borders, ensuring that weak signals from the less powerful side of those borders remain visible may become as important as the enforcement powers themselves.

I’m curious whether this is already being addressed somewhere in the implementation architecture that I’ve missed.😊

Marius Laurusevicius's avatar

Two reporting channels opening at once changes the practical risk picture for small firms. Complaints and whistleblower reports do not require a regulator to notice you first, so exposure now starts with a customer or an employee rather than an inspection. I run a finishing business in Lithuania, and the response that scales at my size is narrow scope: AI goes to measurements and estimates, nothing customer-facing, so the labelling duties largely do not bite. The Commission has not published how it will triage incoming reports, so volumes and response times remain unknown.

10 more comments...

No posts

Ready for more?