AI Policy Wiki
Dashboard

Inside My AI Law & Policy Class 20: The EU AI Act's Reality Check (Farahany, November 2025)

medium confidence · updated 2026-06-06

EU AI Act introduction class. Anchored on the November 19 2025 Digital Omnibus 'simplification' package — a regulatory mulligan announced just months after the EU AI Act took effect. Walks through the EU AI Act's risk pyramid (unacceptable/high-risk/limited risk/minimal risk + GPAI), the 3 paths to high-risk classification (Article 6(1) safety-critical / Annex III categories / 10^25 FLOP threshold), the Article 6 self-exemption escape hatch, and the child-abuse-detection deployment dilemma.

Author: Nita Farahany Source: https://nitafarahany.substack.com/p/the-eu-ai-acts-reality-check-inside Published: November 9, 2025

Class 20 of Nita Farahany's 27-part AI Law and Policy course is the course's introduction to the EU AI Act. It walks students through the Act's structure — a four-tier risk pyramid plus a separate systemic-risk category for general-purpose AI (GPAI) — and the three paths by which a system becomes "high-risk," then anchors the discussion on the November 19, 2025 Digital Omnibus "simplification" package, which Farahany frames as the EU revisiting the Act only months after it took effect. The class uses a child-abuse-detection scenario as a teaching device for the Act's high-risk obligations and closes on the question of how durable the EU's regulatory approach will prove.

The Digital Omnibus framing

The class is built around the November 19, 2025 Digital Omnibus announcement, which Farahany describes as Brussels acknowledging that the 113-article, 13-title, 180-recital AI Act needed simplification months after taking effect (August 1, 2024). She characterizes the announcement as a "four-month confession" that, in her reading, reveals what Europe prioritizes when the regulation is tested in practice.

The risk pyramid

Farahany presents the EU AI Act's risk framework as a four-category pyramid: unacceptable risk (banned under Article 5), high-risk (heavily regulated), limited risk (transparency obligations), and minimal risk (no rules). She treats GPAI models above 10^25 FLOPs as a separate systemic-risk category outside the four tiers.

To illustrate that the same technology can fall at different levels depending on deployment, she uses facial-recognition examples: an iPhone unlock as the base with no rules, airport security as a compliance-heavy use, and social-credit scoring as the banned peak — the same underlying technology, different deployments, and different rules.

Three paths to high-risk classification

Farahany identifies three routes by which a system becomes high-risk:

  1. Safety-critical (Article 6(1)) — AI that is part of a product such as a medical device, car, or airplane already subject to Annex I conformity assessment. She characterizes such systems as "born into regulatory royalty, except backwards."
  2. Annex III (Article 6(2)) — eight categories: biometrics, critical infrastructure, education, employment, essential public and private services, law enforcement, migration/asylum/border control, and administration of justice and democratic processes.
  3. GPAI systemic-risk threshold — 10^25 FLOPs. Per Epoch AI (June 2025), more than 30 models had crossed this threshold.

The Article 6 self-exemption

The class describes a self-exemption mechanism under Article 6: even a system that meets a high-risk category can exempt itself if it does not pose "significant risk." Farahany describes the process as a developer realizing it is high-risk, deciding it is nonetheless fine, claiming the exemption (which is publicly registered), and hoping it is not audited.

Section 2 high-risk obligations

For systems that remain high-risk, the class walks through the Section 2 obligations, which Farahany characterizes as the list "going to slow down a startup":

  • Article 9: risk management system (continuous)
  • Article 10: data governance (representative, unbiased, error-free)
  • Article 11: technical documentation (50+ elements)
  • Article 12: automatic logging
  • Article 13: user instructions
  • Article 14: human oversight
  • Article 15: accuracy and robustness

The child-abuse-detection scenario

The class applies the Article 9 obligations to a hypothetical AI system that analyzes hospital records, school behavioral reports, and social-services data to detect child abuse. Under Article 9, the deployer must identify all foreseeable risks, which Farahany enumerates as bias against poor communities, differences in cultural parenting norms, false positives that destroy families, and false negatives that miss abuse. The live class split 50/50 on whether to deploy. Farahany raises two questions the scenario poses: whether Article 9 actually permits risk-benefit weighing, and whether it focuses on the right values.

The Brussels Effect in reverse

Farahany argues the EU may exert only a limited "Brussels Effect" for AI, citing Alex Engler (Brookings, 2024). The reasons offered are that the EU invests 4% of US AI spending and lags in compute and open-source, and that — unlike privacy regulation — AI systems are easily geo-fenced, so companies can refuse EU service. She notes that leading companies have already delayed product launches in the EU.

The values pyramid and three lenses on simplification

Farahany describes a values pyramid she attributes to the EU's stated priorities: human dignity, then fundamental rights, then democratic governance, then market innovation. Her argument is that each simplification moves something down that pyramid — removing transparency requirements weakens accountability, and extending grace periods favors innovation over protection.

She offers three lenses for interpreting the Digital Omnibus simplification:

  1. Necessary regulatory learning — GDPR-style growing pains.
  2. Structural impossibility — the claim that the Act cannot be simplified because general-purpose technology resists categorization.
  3. Capitulation — the reading that 46 CEOs forced changes to a democratically enacted law, with American companies shaping European regulatory possibilities.

Relationships