Degree 5 · Unit 5.4
The regulatory landscape
Artificial intelligence is not regulated as a technology. It is regulated as a use. The very same model may be entirely unproblematic for summarising an article and tightly restricted for screening job applications. Once you understand that logic, you can read any new regulation that appears.
Risk is not abolished; it is managed by a conscious, written decision for each risk — the same logic the four regulatory tiers above rest on.
Every risk needs one documented choice in the treatment plan, with an owner and a date. "Accept" is a legitimate decision, but an unwritten acceptance is negligence.
The Gulf and the Arab world
The Gulf states have taken a different approach in method: guidance, national strategies and ethics frameworks issued by the competent authorities, with tighter sectoral regulation in banking, health and personal data. The general direction there is an enabling one — encouraging adoption while putting barriers around sensitive sectors — which is unlike the European direction, built as it is on graduated prior prohibition.
Build to the strictest
Frameworks change faster than any book's print cycle, so the working rule matters a great deal more than the list: build to the strictest. If you design your system to the standards that apply to high-risk use — an impact assessment, human oversight, documentation and logs — then you are ready for any regulation that appears, in any jurisdiction.
And do not overlook effect across borders. If you have clients or employees in a jurisdiction that regulates strictly, its obligations follow you even when you are established somewhere else entirely. Check the scope of application before you assume you fall outside it.
There is a third thing worth knowing: regulation does not punish the use, it punishes the absence of proof. An organisation that holds a record of what it did and who reviewed it comes out of an audit intact, even where it got something wrong. An organisation with no record is asked about everything and can prove nothing at all.
Governance is not a document written once but a cycle that turns — and every turn leaves the organisation firmer than the last.
One turn every twelve months at least: watch, assess, set policy, control, test, improve — and then watching begins again with better knowledge than it had.
Do this
1 — In your field. Classify every system in your register across the four levels. How many fell into "high risk" while you do not treat them as such?
2 — In writing. Write down where your disclosure appears telling the user that a system took part in the service. If it is not visible, add it today.
How to walk through a new regulation in twenty minutes
New regulations will appear long after this programme is printed, and you will not need to read any of them in full. Read four things, in this order: the scope of application, which tells you whom it applies to; then the classification, which tells you how it grades different uses; then the documentary obligations, which tell you what you have to be able to prove; and then the dates it takes effect.
Everything else — the definitions and the technical exceptions — you read when you need it. Master those four and you will know where you stand in any regulatory text in a single sitting, without waiting for anyone else's interpretation of it.
Where to after this unit? You know what is imposed on you. The next unit gives you your own instrument for measuring your maturity: UCSMM.
