
As organizations across the European Union increasingly adopt artificial intelligence, navigating the growing complexity of the EU’s digital regulatory landscape—particularly the interaction of multiple legal instruments and governance layers—has become a central challenge. Beyond direct compliance costs, firms also face significant opportunity costs, as regulatory constraints may limit the development of AI-driven business models. This article undertakes exploratory research to examine how firms navigate this complexity and whether it is reshaping their approaches regarding organizational roles, compliance processes and technological tools. Drawing on qualitative data derived from semi-structured questionnaires and in-depth interviews with professionals from 14 European firms, this exploratory study generates hypotheses indicating that there is a tendency for compliance to evolve from fragmented, monitoring-based approaches toward more coordinated and strategically embedded models. However, this transformation remains partial and uneven. In particular, the analysis identifies indications of an emerging pattern of selective integration in compliance processes, whereby firms seek to align regulatory requirements across instruments where possible, while maintaining separation where legal specificity demands it. The findings further suggest that organizational roles may be becoming more hybrid and strategically embedded, and that technological tools, when adopted, tend to evolve in a path-dependent and only partially integrated manner. Taken together, these dynamics reflect the structural constraints of the EU AI regulatory ecosystem. By conceptualizing compliance as an adaptive governance process shaped by legal complexity, the article contributes to scholarship on AI governance and provides empirical insight into how firms operationalize compliance under the EU AI regulatory framework.
Transparency is a central yet abstract concept in the regulation of artificial intelligence (AI). This article examines how transparency is conceptualised and operationalised in the European Union’s Artificial Intelligence Act (AI Act). It maps the transparency obligations contained in the AI Act according to their scope, orientation, function and legal nature. The analysis shows that these obligations are predominantly concentrated at the upstream level of the AI value chain and primarily address providers of high-risk AI systems; that transparency orientations can be distinguished as regulatory, operational and subject-oriented transparency; and that many obligations serve a traceability function. The article further characterises transparency by design as a distinct type of transparency obligation conceived for high-risk AI systems. Against this background, the article provides a legal-dogmatic analysis of Article 86 AI Act and the newly introduced right to explanation, arguing that Article 86 constitutes an ex post and subsidiary practical safeguard aimed at mitigating information asymmetries in AI-assisted decision-making, rather than establishing a general right to algorithmic transparency.
Rules as Code (‘RaC’) describes the increasing push to digitise legislation that is rapidly emerging around the world. However, despite its growth, there remains no unified definition or approach to RaC. Additionally, there are growing calls for publicly available legal information and materials, which includes RaC, to be more accessible, useable and understandable. The use of legal design patterns is one developing strategy that can be utilised to enhance the communication of legal information to users. This paper argues that augmentation of RaC approaches with legal design patterns could enhance the usability of user-facing outputs. In doing so, we differentiate and conceptualise two prominent understandings of RaC, namely RaC as an output-based approach, and the more innovative definition of RaC as a process-based approach. We believe it is possible to augment both RaC approaches with the addition of legal design patterns to enhance the usability and understandability of RaC outputs. Additionally, this paper reconceptualises RaC itself from a loosely defined movement towards understanding RaC better as repeatable processes or approaches with defined steps. In conclusion, although further exploration of both RaC and legal design patterns is required, our paper provides a much-needed starting point for clarifying RaC as a definition and an approach, as well as for the development of legal design patterns in the context of encoding legislation.
The deepening of China-ASEAN digital trade ties has spawned risks stemming from algorithmic operational mechanisms and the inherent opacity of algorithms, posing major challenges to cross-regional digital cooperation between the two sides. Drawing on digital trade theory and the digital governance frameworks stipulated under the Digital Economy Partnership Agreement (DEPA), the Comprehensive and Progressive Agreement for Trans-Pacific Partnership (CPTPP), as well as relevant consensus reached by the World Trade Organization (WTO), this article analyses the necessity and practical foundation for China and ASEAN to jointly develop algorithmic standards and pursue collaborative governance. It compares the current algorithmic governance frameworks of China and ASEAN member states, identifies their common governance values as well as divergences in regulatory approaches and legal institutional frameworks, and pinpoints the structural defects embedded within each side’s governance regime. This article further pinpoints key obstacles to joint algorithmic governance cooperation: uneven development of regulatory standards across ASEAN jurisdictions, limited institutional capacity and policy room for less developed ASEAN economies, and strategic dilemmas faced by core member states. Accordingly, this article seeks to explore feasible paths to establishing an inclusive regional cooperation mechanism for digital governance, and puts forward preliminary proposals for the coordination of China-ASEAN algorithmic governance, so as to narrow institutional discrepancies and build broader consensus on regional governance.
The EU AI Act introduces risk assessments for AI use cases alongside mandatory mitigation measures, aiming to ensure trustworthy AI systems. However, the ultimate success of establishing trusted AI systems depends on whether public perceptions of risk and mitigation align with these legal classifications. Currently, little is known about whether legal risk classifications and their corresponding safeguards match public risk perceptions. We address this gap by assessing how the public perceives the risks of different AI applications and evaluating how various mitigation measures, such as human oversight or independent certifications, are perceived to reduce those risks. Specifically, participants from an Austrian quota-representative population sample (N=1557) evaluated the perceived risk of three vignettes representing different regulatory risk tiers (workplace emotion detection, driver fatigue detection, and personalized media recommendations). We find that socio-demographic characteristics, such as age and gender, have only small, context-dependent effects on risk perception. Furthermore, mitigation measures decrease risk perception in two of our three use cases. We conclude that public risk perceptions and the efficacy of mitigation measures are highly context-dependent, suggesting that one-size-fits-all safeguards are not a universal solution to perceived AI risk.
Cloud computing, that emerged as an early response to outsourcing by small and mid-sized firms, has over time, emerged as the foundation of the data economy. Cloud computing is no longer merely outsourcing of non-core functions by firms. It is an irreversible trajectory to path dependence and reliance on the digital ecosystem of the global hyperscalers, Amazon, Microsoft and Google. The dependence on cloud will only strengthen further, as AI and quantum computing, that rely on large cloud capabilities, become central to the big data-driven digital economy. What technical (such as complexity of the technology, learning effects and interoperability) and economic considerations (such as ecosystem effects, egress fee and lock-in) can potentially explain the enduring global dominance of the three hyperscalers? Together these economic and technical considerations, also raise non-economic concerns, such as sovereignty and innovation, in cloud computing, that well underline the urgent call by Nation States across the globe for workable competition in the cloud computing industry. This research contribution develops the foregoing considerations, and reasons that in light of the infrastructural and foundational nature of the cloud, it should be seen as part of a digital ecosystem owned and controlled by the hyperscalers, that also qualify as gatekeepers in the EU’s Digital Markets Act (DMA), and other equivalent ex-ante regulatory frameworks across the globe. This ecosystem-driven view offers a normative foundation to consider cloud sovereignty as a non-economic consideration in competition, particularly in light of the irreversible structural impact of cloud on functional autonomy and innovation capabilities of firms. This contribution elucidates how a flexible interpretation and qualitative approach may be more suited to qualify cloud under the DMA, and the relevant obligations therein. It then evaluates the portability and interoperability requirements under the Data Act. The discussion critically evaluates the landscape of cloud computing, and discusses whether together, these legal instruments can effectively promote contestability, fairness and sovereignty in cloud computing, the infrastructure layer of Industry 4.0.
This column provides a country by country analysis of the latest legal developments, cases and issues relevant to the IT, media and telecommunications' industries in key jurisdictions across the Asia Pacific region. The articles appearing in this column are intended to serve as ‘alerts’ and are not submitted as detailed analyses of cases or legal developments.
The global diffusion of European data protection norms is widely regarded as a classic example of the ‘Brussels Effect’. However, upon closer examination, this dominant narrative does not fully capture the nuanced realities of many third countries’ convergence towards EU standards, particularly their adoption of the ‘adequacy’ principle to regulate outbound transfers of personal data. This article provides a different explanation by illuminating key mechanisms of influence that mainstream accounts have tended to underemphasize. These mechanisms include (i) the European Commission’s strategic use of the ‘adequacy’ process (including government-to-government negotiations and ex post periodic reviews) to foster regulatory alignment; (ii) the establishment of institutional synergies between EU data protection law and the Convention 108 framework; and (iii) the normative power of European standards. Independent of the Brussels Effect, these diffusion mechanisms have been indispensable to the worldwide spread of European data protection standards. As such, the EU’s reliance on political negotiations and its normative power to foster legal and regulatory diffusion stands in tension with the prevailing narrative that it exports its data privacy norms primarily through unilateral market regulation. This article thus enriches the existing literature’s explanation of how Brussels shapes global regulatory standards and refines our understanding of the mechanisms driving such regulatory globalization. Turning to the broader international regulatory landscape, this article also examines the challenges facing the diffusion of the European regulatory approach to cross-border transfers of personal data—whether stemming from competing paradigms of other major powers or inherent in the EU’s own standards—and analyzes the EU’s recent trade rulemaking and other developments that may help to counter or alleviate these tensions.
The protection of data intellectual property in China can be analyzed from two dimensions: institutional construction and judicial validation. At the institutional level, pilot regions have established data intellectual property registration mechanisms to confirm relevant rights and interests. This study systematically examines the normative documents governing data intellectual property registration across 17 pilot provinces and municipalities, identifying common elements and divergent requirements regarding subject qualification, data sources, processing requirements, and rights attributes. At the judicial level, courts substantiate and balance registered rights through adjudication. This study examines the nation's first concluded data intellectual property case, analyzing its judicial documents to reveal the logic underlying the recognition of the evidential weight of Data Intellectual Property Registration Certificates and the pathways for rights protection in judicial practice. From the dual perspectives of institutional construction and judicial validation, this study concludes: First, China's data intellectual property protection primarily protects enterprise data when registration conditions are met, protects public data under special circumstances, and generally does not protect personal data. Second, although the institutional framework was initially designed to establish a novel approach to data intellectual property protection, judicial practice demonstrates that China has not recognized data intellectual property as an independent subject matter. Instead, protection remains predominantly reliant on supplementation and extension within the existing intellectual property legal framework.
Artificial intelligence is entering African common-law courts at a moment when those courts remain structured by colonial legal inheritances: reception statutes, stare decisis, adversarial procedure, the repugnancy test, and the subordination of customary law to a facts-not-law evidentiary status. This article asks a single question: Will algorithmic tools disrupt or deepen coloniality in African judiciaries? Drawing on doctrinal analysis, decolonial legal theory, and socio-technical analysis of Legal NLP and judicial decision-support systems and focusing on common-law jurisdictions where the colonial continuum is most legible in contemporary doctrine, I defend a decisive thesis. Algorithmic tools will deepen coloniality where they are deployed as general-purpose adjudicative or predictive systems trained on colonial jurisprudence and embedded within inherited procedural hierarchies, because data, doctrine, and institutional design are co-produced within that legacy. They may disrupt coloniality only where they are narrowly designed as accountable, context-sensitive, procedurally supportive, and decolonial legal infrastructure that elevates customary, Indigenous, and plural legal orders rather than subordinating them. I map algorithmic use-cases across the judicial process, grade their colonial-reproduction risk, correct the Legal NLP literature’s mischaracterisation in earlier African scholarship, and propose seven decolonial design principles. This contribution is threefold: a jurisdiction-specific account of algorithmic accountability in a significant part of the Global South, a diagnostic framework for judicial AI governance beyond Euro-American contexts, and a constructive design agenda for technology law scholars, regulators, and judicial administrators working in the algorithmic courtroom.
Synthetic data constitutes a conceptual disruption that challenges the foundations of data protection law, raising questions about whether it should be classified as personal data, anonymized data, or a sui generis category. This paper examines the inadequacy of the binary framework of the General Data Protection Regulation (GDPR) to address technologies that preserve statistical properties without direct individual correspondence. A strict distinction is made between an analysis of current positive law (lege lata) and proposals for reform (lege ferenda): under current law, synthetic data is evaluated within the existing binary framework by applying the standard set forth in Recital 26; the sui generis category is formulated as a recommendation for future legislation. Through a dogmatic analysis of comparative law, three regulatory models are examined: the permissive approach of the ICO (United Kingdom), the cautious approach of the CNIL (France), and the proactive approach of the Datatilsynet (Norway). The legal status has been partially clarified by CJEU Judgment C-413/23 P (2025) and Opinion 28/2024 of the EDPB. A graduated framework of three risk levels, a voluntary certification system, and an implementation roadmap for the Peruvian legal system from a Latin American perspective are proposed.
Ping Fai Yuen v Fun Yung Li and Lai Yung Li [2026] EWHC 532 (KB) marks the first judicial consideration of the Property (Digital Assets etc.) Act 2025 in the United Kingdom.
The rapid escalation of financial deepfake fraud—driven by the emergence of Fraud-as-a-Service—has outpaced existing regulatory frameworks, creating a critical vulnerability in global digital security. This paper argues that the current legal response remains fragmented, trapped between the European Union’s rights-based architecture (General Data Protection Regulation, AI Act, Digital Services Act) and the United Kingdom’s safety-oriented technology-forcing imperatives (Online Safety Act). Through a doctrinal and functional comparative analysis, this study constructs a three-layered governance paradigm for the digital economy: Layer 1 (Source Control) identifies a compliance black hole in biometric data erasure; Layer 2 (Distribution Control) contrasts systemic risk management with proactive technical detection; and Layer 3 (Accountability) evaluates the shift toward strict corporate criminal liability. Critically, the study evaluates the June 2026 Digital Omnibus updates, identifying a 12-month governance vacuum created by the disparity between the December 2026 functional bans and the delayed December 2027 application timelines for high-risk systems. The paper concludes by advancing six strategic policy recommendations to counter scalable injection attacks, including the enforcement of NIST IAL2 zero-retention biometric standards and obligatory digital provenance (C2PA). Most notably, it proposes a Transatlantic Regulatory and Financial Interoperability Framework, advocating for the integration of biometric integrity protocols directly into ISO 20022 messaging schemas to enforce a real-time financial blockade against non-compliant jurisdictions.
This article explores the impact of the EU's General Data Protection Regulation (GDPR) on Turkish data protection law, illustrating the "Brussels effect" as the Turkish Personal Data Protection Act (PDPA) reaches its tenth year of application. While the GDPR's impact as a global standard is well-documented, its specific influence on T & uuml;rkiye, an EU candidate country, presents a complex case. Modelled after the Data Protection Directive, the PDPA has long exhibited significant normative divergences and implementation challenges compared to the modern European framework. This article examines instances where Turkish national actors, specifically the Data Protection Authority and the Constitutional Court, have attempted to address legislative gaps through interpretive alignment with GDPR standards during this first decade of enforcement. However, these cases also reveal strategic and deliberate deviations from EU practice, illustrating that T & uuml;rkiye's approach to GDPR alignment exhibits selectiveness. Furthermore, the article assesses the significant progress made through the 2024 legislative amendments, which fundamentally reconfigured the regimes for international data transfers, the processing of special categories of personal data, and the system of administrative sanctions to better mirror the GDPR. As the PDPA marks this ten-year milestone, the article concludes that while substantial convergence has been achieved, reaching full alignment remains an ongoing process, including critical objectives such as the signature and ratification of the modernised Convention 108, the establishment of a framework law compliant with the Law Enforcement Directive, and further legislative revisions planned through 2026.
Multilateral development banks (MDBs), as institutions with broad-ranging immunities, have over time developed distinct conceptions and frameworks of accountability as towards those who are negatively impacted by their projects. We argue that MDBs’ understandings of accountability, and the policies, procedures, and mechanisms through which affected groups may seek account and redress, are ill-suited to address the impacts of these institutions’ digitalization projects. As MDBs’ accountability frameworks arose in response to harms from physical infrastructure projects, they are temporally and spatially oriented towards physical, enumerated risks, and those considered “affected” and thus entitled to demand account and redress are delineated by narrow localized geographies. In addition, longstanding limitations of MDBs’ independent accountability mechanisms generate serious obstacles to access. As digital technologies are becoming central to MDBs’ projects, and MDBs are increasingly funding “digital transformation”, critical misalignments are arising between MDBs’ narrow approaches to accountability and the far-ranging impacts of digitalization. Building on pre-existing pathologies of MDBs’ accountability frameworks, and highlighting new challenges posed by digitalization, we argue that a reconceptualization of MDBs’ accountability is required. We offer a series of observations in that direction, beginning from entirely different answers to the questions: accountability for what, to whom, and through which processes?
The 2024 EU Artificial Intelligence Act (AI Act) asserts broad extraterritorial scope: it applies to any AI system whose output is used in the EU, no matter where the company behind the AI is located. The AI Act reflects a wider trend of the EU extending its legislation beyond its borders. But does this mean that companies actually comply with the AI Act? And do compliance levels differ between companies based inside and outside the EU? Empirical evidence on the effectiveness of extraterritorial legislation has so far been limited, focusing mostly on privacy and consumer protection laws.This paper provides such evidence by assessing demonstrated compliance with the AI Act’s prohibitions on certain AI practices under Article 5(1), for which high financial penalties started to apply in August 2025. To this end, this study analysed terms of service and acceptable use policies from 53 AI companies. Results indicate that foreign companies without EU subsidiaries rarely comply, with little improvement following the introduction of penalties. Only around 14% of such companies refer to the AI Act’s prohibitions in their documents, whereas significantly more companies with an EU establishment do so. This may result from limited (extraterritorial) enforcement and uncertainty among non-EU companies about the AI Act’s scope.The findings suggest that EU companies may face a competitive disadvantage compared with foreign firms. This concern is highly relevant to current debates on the competitiveness of EU firms and the potential need for legislative simplification.
Data about people has become a key form of capital in information economies, where its processing is often distributed and multi-party in nature, working through supply chains of interconnected services and actors. Personal data's legal definition - any information relating to an identified or identifiable natural person - divides processing of this data which is subject to data protection law from that which is not. The question of when an individual is in some way 'identifiable' therefore helps determine whether its processing falls within data protection law's framework. I argue that the CJEU's jurisprudence on this question in practice combines with common multi-party processing arrangements to produce a space of effective legal immunity around shadow processing for speculative accumulation of and value extraction from data relating to people, beyond the reach of data protection law. This is because the CJEU's modified relative understanding of identifiability systematically excludes certain supply chain actors from the law's scope. In doing so, this interpretation undermines data protection law's purpose and objectives of protecting people's rights and interests where information about them is being processed, operates retrospectively and produces legal uncertainty for many parties, and leaves governance of shadow processing to unsuitable private law mechanisms. This interpretation should be rejected in favour of a contextual and pluralistic one, which better accounts for the distributed and multi-party nature of data processing today.
This Article analyzes how the growing use of digital technologies in migration management in the European Union (EU) and United States (US) reflects and reinforces the securitization of immigration, and explores the resulting implications for human rights and, more broadly, for core principles enshrined in both systems’ constitutional background.Drawing on securitization theory and critical scholarship on digital governance, the Article argues that both systems are undergoing a process of technosecuritization and identifies three analytical dimensions thereof: risk-by-default, identity consolidation through interoperable data architectures, and automation with legally consequential outputs.The comparative analysis shows that, in the EU, technosecuritization is legalized and codified through broad regulatory frameworks—such as the interoperability regime, the reformed Eurodac system, and the AI Act—within a supranational order formally committed to human rights. In contrast, in the United States, technosecuritization unfolds primarily through executive-driven integration of biometric and targeting systems within the Department of Homeland Security, supported by expansive national security doctrines and by a fragmented framework of judicial and administrative oversight.While both systems experience a relocation of discretion toward infrastructural design, the core constitutional and legal environment surrounding this shift diverges significantly. Consequently, the Article claims that technosecuritization exposes different vulnerabilities of the two systems and concludes by proposing safeguards aimed at extending legal scrutiny upstream—enhancing transparency in system design, strengthening meaningful human oversight, and reinforcing the linkage between digital infrastructure and constitutional guarantees of review and rights protection.
Existing research on Central Bank Digital Currencies (CBDCs) primarily focuses on their payment efficiency and socioeconomic implications, including privacy protection and social welfare enhancement, while also addressing the relationship between financial instruments and human rights. In contrast, this paper addresses a critical issue in the path of CBDCs' development that must be resolved during the technical design phase across states: whether CBDCs shall be designed to compete with cash and other cryptocurrencies for market share or maintain a distinctive, complementary role. Recognizing that CBDCs constitute merit goods as sovereign-issued legal tender that shall advance public value and facilitate human rights, this study employs an analytical public value framework from public administration theory to examine how human rights law is embedded in CBDCs' technologies. Building on a critique of existing payment systems' human rights shortcomings, the article evaluates how CBDCs' technical designs support the protection of five fundamental rights including privacy, non-discrimination, accessibility, social security, and equal access to public services despite inherent tensions. The analysis concludes that while CBDCs' technologies are inherently neutral, their institutional design carries significant human rights implications. Therefore, instead of displacing other currencies, CBDCs shall maintain a distinctive, human-rights-based positioning.