Skip to content
Samraj Matharu

Europe's Moral Compass for AI: From Regulation to Realisation

Europe has written the most complete rulebook for artificial intelligence in the world. The harder question is what has to change inside organisations for any of it to hold.

Originally published by the World Academy of Art and Science in EXTRA. Hosted here because the publisher's article URL has since rolled over.

The EU AI Act is an achievement of drafting. It classifies systems by risk, imposes obligations proportionate to that risk, and puts a legal spine behind ideas that had previously circulated as voluntary principles. Whatever one thinks of the detail, it establishes that some uses of these systems are not a matter of private preference.

But regulation lands on organisations, not on models. And organisations absorb regulation the way they absorb everything else: through process, incentives and ownership. A rule that has no owner inside a company is not a rule, it is a sentiment. This is the gap between regulation and realisation, and it is where the next several years of work actually sits.

In advertising, which is the industry I know best, the point is easy to see. Automated buying systems make millions of decisions a day. Every one of those decisions carries a value judgment about what is worth optimising towards — and in almost every case, that judgment was made implicitly by whoever chose the optimisation metric. Nobody experiences that as an ethical decision. It is simply what the platform defaults to.

So the operative question is not whether a company agrees with the principles. Almost everyone agrees with the principles. The question is whether the principles have been encoded anywhere that spends money or takes an action. If a commitment to attention quality, or to lower-carbon delivery, or to fair treatment of an audience segment, exists only in a policy document, the system will continue optimising for whatever it was already optimising for, and the policy will be true and irrelevant at the same time.

Realisation therefore has three practical requirements. First, named ownership: a person, not a committee, accountable for the behaviour of a given automated system. Second, encoded constraints: the values expressed as parameters the system acts within, rather than as guidance surrounding it. Third, inspectability: the ability for the accountable person to see what the system did and why, in terms they can reason about.

This is what I have come to call bounded agency. Hard-coding every rule produces something brittle, where the real judgment was made months earlier by whoever wrote the logic and is now invisible to everyone executing it. Full autonomy produces something flexible and unaccountable. The useful design is an agent that decides freely, but only inside parameters that are explicit, owned and visible.

Europe's regulation, read charitably, is an attempt to make bounded agency the default rather than the exception. Whether it succeeds will not be decided in Brussels. It will be decided in operating models, in procurement documents, in whoever ends up named on the internal wiki page next to a system that spends money on someone's behalf.

Have a question, a project or an idea worth exploring?

I read every enquiry myself. Tell me what you are trying to decide or change, and I will tell you honestly whether I can help.