
This article examines the legal and regulatory challenges faced by platforms facilitating the primary issuance of tokenized equity in the European Union. Adopting an intermediary-centric perspective, it analyses how platform-based issuance models interact with existing EU financial law frameworks. The article argues that the regulatory classification of issuance platforms is determined primarily by the functional substance of platform activity rather than by the technological features of tokenization, rendering regulatory structuring a strategic design choice with significant compliance implications. It further demonstrates that, while EU law provides a formally comprehensive regulatory framework, persistent uncertainties remain concerning prospectus liability, the interaction with national company law, AML/CTF obligations, and cross-border operations. These doctrinal findings are supported by a quantitative analysis of security token issuance platforms, revealing market concentration, declining platform formation, and limited uptake of innovation-oriented regimes. The article also identifies factors enabling scalable, pan-European platform-mediated equity token issuance.
Encryption is a key building block of digital society protecting the security of the online environment and enabling a meaningful exercise of civil liberties. This technology endows its users with power that does not always sit well with law enforcement and intelligence authorities, which accordingly lose their control over information exchanges within society. The arguments, albeit yet to be substantiated, that this dynamic significantly impacts the fight against crime or other threats have triggered decades-long 'crypto-wars' that endure to this day. These crypto-tensions are compounded by the reality that at present no technological solutions are known that could grant security agencies a so-called 'exceptional access' to communications and data without compromising cybersecurity and fundamental rights. This paper comprehensively explores encryption policy in the EU and how these debates have been playing out in the face of the quantum threat that requires mitigation with new methods of encryption.
The adoption of the Global Digital Compact (GDC) by the United Nations General Assembly in 2024 raises a fundamental question: what do its human rights objectives mean in practice? This article addresses that question through a doctrinal analysis of the GDC's third objective and comparing it against international standards developed at the UN level and regional and national legislation, specifically the EU's Digital Services Act (DSA) and the UK's Online Safety Act (OSA). The article challenges claims of 'technological exceptionalism', which hold that digital technologies require entirely new legal frameworks, and argues instead that regulatory practice at the international, regional and national level consistently applies existing human rights instruments to the digital sphere rather than replacing them. Three areas are examined: human rights due diligence for digital companies, digital trust and safety with respect to women's and children's rights, and information integrity. The analysis of regulations for the digital sector show that the preference of regulators is to create new duties for private actors rather than new rights. The article concludes that the GDC should consolidate, rather than reinvent, international human rights law and that the existing practice of states and regional organisations points in that direction.
This article examines whether the fiduciary architecture of charity law in England and Wales can accommodate decentralised autonomous organisations (DAOs). Although DAOs promise transparency, participation and coordination through blockchain-based governance, which should appeal to charities, uptake within the sector remains limited. The article argues that this reflects a structural incompatibility between decentralised governance and the fiduciary framework through which charity law allocates responsibility. Charity law requires identifiable trustees who bear duties of loyalty, no-conflict, and no-profit and who remain subject to regulatory supervision. DAO governance, by contrast, disperses authority among token holders, relies on automated execution through smart contracts and often operates without legal personality. This mismatch produces what the article describes as a 'fiduciary bottleneck', in which decentralised decisions must ultimately pass through identifiable fiduciaries to acquire legal effect. The analysis conceptualises this tension as regulatory disconnect and considers its implications for integration of decentralised governance within regulatory regimes.
Freedom of expression online is increasingly shaped by intermediary-based regulatory models that profoundly affect end users, yet judicial scrutiny increasingly focuses on intermediaries rather than those whose speech is ultimately restricted. This article develops a complex model-sensitive analytical framework for assessing the intrusiveness of online speech regulation. Building on five criteria of intrusiveness—timing of interference, universal and indiscriminate monitoring, characteristics of the competent authority, risk of collateral damage, and severity of sanctions—the article compares six regulatory models operating in the European legal space. It then analyses the case law of the ECtHR and the CJEU to identify the safeguards and anti-safeguards applied to these models. The analysis reveals a disproportionality between structural intrusiveness and the level of judicial protection afforded both within and across regulatory models. Also, three of the aforementioned criteria were neglected by the courts and the perspective of end users increasingly underemphasised.
This paper offers a comprehensive analysis of French Law No. 2023-451,11LOI n degrees 2023-451 du 9 juin 2023 visant & agrave; encadrer l'influence commerciale et a lutter contre les d & eacute;rives des influenceurs sur les r & eacute;seaux sociaux (1), JORF n degrees 0133 du 10 juin 2023, Texte n degrees 1. . the first integrated European legislation to comprehensively regulate digital influencers. The law fundamentally redefines the influencer's status, shifting from that of a 'free-speech content creator' to a 'responsible economic actor' subject to strict legal obligations in areas such as public health, financial services, advertising transparency, and child protection. The legislation mandates a written contract for all commercial collaborations, explicitly prohibits the promotion of certain high-risk activities, including cosmetic surgery and unlicensed digital assets, and establishes criminal liability for serious violations. It also addresses the legal status of non-resident influencers by requiring them to appoint an EU-based legal representative and to hold professional liability insurance covering activities targeting French audiences. More broadly, this law marks a decisive departure from voluntary self-regulation toward a robust legal framework that carefully balances freedom of expression with consumer protection, with particular attention to child influencers. The paper concludes that the French model offers an advanced and forward-looking reference for regulating the 'influencer economy' in the digital age.
This article examines two key ethical issues surrounding the use of automated facial recognition technology in policing - data protection and discrimination. It investigates how these issues are mobilised and understood in a landmark UK case, Ed Bridges v South Wales Police. By closely analysing legal documents, I show how the court relied on policy as a performative and corrective measure to address ethical issues. I argue that this approach overlooks the broader range of social justice concerns that arise when AI technologies intersect with sociopolitical contexts and institutional practices. These include the intrusiveness of AI in everyday life, racial biases embedded in its design and application, and the institutional racism within which the technology operates. Ultimately, these juridical questions reveal deeper tensions between reformist and abolitionist perspectives.
Transnational data flows are integral to the world economy. Data flows constitute either personal or commercial data, or both. This paper explores data flows across blockchain technology. It examines the current day international and national data flows regulatory frameworks of Australia, India, Singapore, United Kingdom (UK) and the United States (US), including a selection of transnational trade agreements. The paper will demonstrate how the fragmented approach to allocating responsibilities for managing data has resulted in gaps in the law in some jurisdictions, such as requiring a controller or processor to be appointed. This tension continues to remain because blockchain technology is not regulated by governments in the same way as the users of data. Rather, blockchain to date is governed by its own set of self-regulatory protocols and rules. This paper calls for an urgent review of the governance arrangements of the technology to ensure it upholds the public good and is not used by adversaries against governments and society.
Autonomous systems based on artificial intelligence (AI) are increasingly used in automated contracting. Unlike traditional computer programs, autonomous systems are capable of independently formulating and executing contractual decisions based on environmental inputs, without direct human intervention. Their growing use raises important questions regarding the adaptability of existing contract law. This paper examines three key challenges frequently associated with autonomous systems in contracting: their legal status, the validity of AI-formed contracts, and the treatment of unexpected outputs. The analysis demonstrates that none of these challenges necessitates a special legal regime. Existing contract law principles and doctrines are sufficiently flexible to accommodate the involvement of autonomous systems in contracting.
This article examines how responsibility and liability are allocated across the general-purpose AI (GPAI) value chain under EU law. Recognising the fluid and dynamic nature of this value chain, we analyse the obligations imposed on upstream and downstream providers in the AI Act, as well as in complementary instruments such as the GPAI Code of Practice and the European Commission's Guidelines on the scope of the obligations for GPAI models. Our paper identifies gaps in these instruments and explores how they intersect with obligations under the General Product Safety Regulation (GPSR) and the new Product Liability Directive (PLD). The article also considers key aspects of model deployment and distribution under the Digital Services Act (DSA), particularly in relation to GPAI marketplaces and very large online platforms (VLOPs). It highlights the central role of cooperation duties in effective risk mitigation, while emphasising the asymmetries of power and information that may hinder such cooperation. Against this background, the article assesses where responsibility is most appropriately allocated along the GPAI value chain.
Public administrations are steadily digitalizing all their procedures. In particular, computational laws - such as taxes and benefits - are increasingly implemented within computers, enabling scalable, automated computations. These computer implementations have four key specificities: they are critical software at the intersection between law and computer science that will be updated regularly by legal changes and have a long lifespan counted in decades. Thus, great care should be taken to avoid any issue in these specific legal implementations. Building upon years of studying and coding computational laws, both in administrations and as new research products, we propose 20 recommendations to ease the development and maintenance of legal implementations. These recommendations aim at being understandable for lawyers and computer scientists alike.
Ghostbots (griefbots) are technological innovations that are not currently subject to legal regulations (except for regulations limited to ghostbots of public figures, which are in force in the State of New York). Therefore, there is a need to establish a set of legal principles to guide future legal regulations on ghostbots. Undoubtedly, the issue of limitations on ghostbot functioning should be especially considered in relation to survivors' rights and post-mortem rights, as limitations of informational capitalism. The objective of this work is to propose a catalogue of survivors' rights and post-mortem rights that should limit the free functioning of ghostbots. Undoubtedly, this work can be valuable to legal theorists, legal practitioners and policymakers.
Under the GDPR, a valid consent must satisfy a number of requirements to comply with the General Data Protection Regulation (GDPR) and the ePrivacy Directive (ePD). The article evaluates the design of consent banners using a common and popular usability inspection method in human-computer interaction scholarship known as heuristic evaluation, which enables the researcher to identify challenges in technical provision and new generative opportunities for technical systems to better respond to legal requirements. Opportunities, challenges and tensions for a lawful and usable consent are identified through a novel application of usability heuristics to target the intersection of legal requirements and usability in the context of consent banners. These interpretations of the intersection of law and design may aid legal scholars in evaluating the lawfulness and usability of consent design strategies, while acknowledging the tensions and challenges among design and legal perspectives.
This article aims to contribute to the contemporary issue of blockchain's compatibility with data privacy regulations. Existing literature primarily focuses on the potential legal challenges associated with using blockchain technology for processing personal data. This article focuses specifically on the storage limitation principle and shifts from merely identifying problems to proposing a more solution-oriented approach. The underlying rationale is that while the use of blockchain technology in processing personal data is in itself challenging, it is workable with appropriate legal guidance. With broad reference to EU and UK data privacy laws, this article considers the creation of a framework that seeks to balance blockchain's immutability with the storage limitation requirement, which requires that personal data be erased when no longer needed. To do so, this article takes advantage of the broad definition of erasure, which extends to rendering existing personal data unidentifiable where technical considerations make total erasure infeasible. The discussion culminates in the proposal of the functional erasure paradigm, which lays out requirements that could be contained in yet-to-be-determined guidance on the use of blockchain technology. This framework aims to contribute to the eventual regulation of blockchain technology for processing personal data.
The rapid proliferation of smart home technologies transforms the private domestic sphere into a key site of data generation, raising complex regulatory challenges in the European Union. This article examines how EU law - particularly the GDPR, Data Act, and ePrivacy framework - conceptualizes and regulates data produced within smart homes. We highlight tensions between privacy protection and innovation, the treatment of personal versus non-personal data, and the difficulties posed by multi-user household contexts. While current frameworks provide important safeguards, they remain fragmented and insufficiently tailored to the unique social and interpersonal dimensions of domestic data flows. We argue for a more coherent regulatory approach that balances innovation with privacy and recognizes the home not only as a space of intimacy but also as a site of data-driven economic activity.
The recent Artificial Intelligence Act (AI Act) represents a landmark regulatory framework aiming to ensure the trustworthy development and deployment of AI systems across the European Union. For the banking sector - already subject to dense layers of prudential, customer duty and data protection regulations - the AI Act introduces additional compliance challenges that are both novel and complex. This article critically examines the implications of the AI Act for compliance assurance in European banks, with a particular focus on high-risk AI systems and interrelationships with existing regulations such as e.g. the General Data Protection Regulation (GDPR). Special attention is given to the operationalization of AI Act compliance within internal control systems, governance structures, and third-party risk management processes. The article aims at identifying both key assurance scoping factors as well as operational challenges, especially concerning AI system change control, human oversight requirements, awareness and competence building as well as disclosure obligations. Broader implications of AI-based solutions for process controls assurance is also taken into consideration. Drawing on doctrinal and interdisciplinary analysis at the intersection of technology regulation, compliance in the financial sector and assurance-related organizational management conclusions and recommendations potentially relevant to auditors, risk managers and internal controllers are formulated.
As artificial intelligence (AI) systems are increasingly applied in critical domains such as healthcare, finance, and criminal justice, the need for explainability and meaningful human oversight has become a pressing legal and ethical concern. The inherent opacity of complex AI models, often described as the 'black box problem,' raises significant challenges in ensuring accountability, fairness, and due process when automated decisions impact individual rights and opportunities. This paper critically examines the legal frameworks governing AI explainability and human intervention across selected jurisdictions, including the European Union, the United States, the United Kingdom, Singapore, and Malaysia. It analyses the contrasting regulatory approaches, such as the enforceable rights under the EU AI Act and GDPR, compared with the more fragmented and sectoral models in the United States. The paper explores sector-specific instances of algorithmic discrimination in lending, diagnostic errors in healthcare, and wrongful arrests linked to facial recognition to illustrate the regulatory gaps and practical risks of insufficient transparency. It identifies key challenges such as limited enforcement mechanisms, legal ambiguity, the trade-off between accuracy and interpretability, and cross-jurisdictional inconsistencies. The paper concludes with policy recommendations that include strengthening statutory obligations for explainability, establishing algorithmic audit frameworks, developing transparency registries, and promoting greater international coordination in AI governance.
The integration of generative Artificial Intelligence (AI), particularly ChatGPT, into legal practice is reshaping how legal services are delivered, researched, and consumed. While these technologies offer new efficiencies, they also raise profound ethical and legal challenges that the profession is only beginning to confront. This article critically examines the implications of ChatGPT's use within the legal field, focusing on issues such as unauthorised practice of law, algorithmic bias, data privacy, and professional responsibility. Drawing on emerging regulatory responses in the United Kingdom, European Union, and the United States, it explores the extent to which existing legal frameworks can accommodate the unique risks posed by AI. The discussion also considers the evolving role of legal practitioners and educators in ensuring that technological advancement does not undermine core principles of justice, accountability, and public trust. In doing so, the article calls for a recalibration of legal ethics and governance to meet the demands of a rapidly digitising profession.
The EU's Artificial Intelligence Act ('AI Act') delegates key regulatory functions to harmonised socio-technical standards developed by private bodies under the New Legislative Framework ('NLF'). While this promises efficiency and flexibility, it raises legitimacy concerns - especially given the AI Act's fundamental rights objectives. This article critically examines the legal basis and governance structure of the standardisation process, focusing on the roles of CEN, CENELEC, and international cooperation with ISO/IEC. It assesses the inclusiveness, transparency, and accountability of these processes, highlighting risks of over-delegation in areas touching constitutional values. Applying a framework of input, output, and throughput legitimacy, it identifies procedural gaps and analyses the implications of the CJEU's 2024 landmark Public.Resource.Org judgment on access to standards. It concludes with proposals aimed at improving the legal and normative legitimacy of future standardisation in AI, arguing that AI governance depends not only on technical quality but also on democratic accountability and rights-based alignment.
As platforms increasingly shape online dialogue, their role in ensuring access to reliable information poses challenges to free speech and media freedom. The spread of disinformation, algorithm-driven content, and declining trust in institutions have forced platforms to adopt moderation tools, often in partnership with professional fact-checkers. Meta's decision to replace fact-checkers with the crowdsourced tool 'Community Notes' raises significant legal and normative concerns under the EU's DSA. This paper critically examines whether Community Notes qualifies as a lawful and effective alternative under Articles 34-35 of the DSA, which require major platforms to assess and mitigate systemic risks through proportionate, risk-specific measures. It compares the transparency and ethical grounding of professional fact-checking with the opacity of crowdsourced moderation. The paper argues that Meta must show how Community Notes fits within its risk assessments, reporting obligations and demonstrate it reduces disinformation without compromising legal safeguards, journalistic standards, or access to credible information.