AI Policy Wiki
Dashboard

Inside My AI Law & Policy Class 21: Understanding How the EU Regulates AI (Farahany, November 2025)

medium confidence · updated 2026-06-06

EU regulatory architecture deep dive. Anchored on the 'EU healthcare AI startup compliance pop quiz': a single AI diagnostic tool triggers at least 8 EU-level frameworks (AI Act + GDPR + MDR + DSA + Data Act + Cyber Resilience Act + NIS2 + PLD) plus national additions (Italy criminal penalties, France biometric rules, Germany data localization). Walks through the foundation/horizontal-floors/vertical-pillars/national-additions architecture and the 5-different-incident-reports problem.

Author: Nita Farahany Source: https://nitafarahany.substack.com/p/understanding-how-the-eu-regulates Published: November 11, 2025

Class 21 of Nita Farahany's 27-part AI Law & Policy course (published November 11, 2025) describes how the European Union regulates artificial intelligence through overlapping instruments rather than a single statute. The class opens with a classroom exercise Farahany calls a pop quiz: asked how many laws a healthcare AI startup must comply with in the EU, most students guess one comprehensive law, where Farahany's answer is that at least eight major frameworks apply at the EU level alone, before national additions. The class lays out a four-layer model of how those instruments fit together and uses a single high-risk healthcare AI system to trace the compliance and incident-reporting obligations that result.

Three forces shaping European regulation

Farahany frames European technology regulation as shaped by three forces, which she describes as tectonic plates.

The first she calls the Brussels Effect in reverse, arguing that the EU's regulatory model is increasingly associated with weaker domestic AI development rather than global rule-setting. To illustrate the funding disparity she cites Mistral raising $640M at a $6.2B valuation against OpenAI raising $8.3B at a $300B valuation, characterizing the difference not as a gap but as a chasm. She points to the September 2024 Draghi report as warning that Europe is regulating itself into irrelevance.

The second is what she terms the precautionary principle under stress. She summarizes the EU posture as treating technologies as dangerous until proven safe, an approach she says made sense for nuclear power and GMOs, and asks whether it works for AI that evolves faster than regulatory processes can assess.

The third she calls the integration paradox: the more Europe tries to harmonize its rules, the more complex the result becomes. Farahany argues that the EU AI Act was intended to provide a single law but instead produced a complex interplay across GDPR, the DSA, the Data Act, the CRA, the PLD, and NIS2.

The four-layer architecture

The class organizes EU digital regulation into a foundation, horizontal floors, vertical pillars, and national additions.

The foundation is rights-based and described as near-constitutional: the GDPR (2018) together with the EU Charter of Fundamental Rights (in force with the Lisbon Treaty, 2009).

The horizontal floors are cross-cutting instruments. The Data Act (2024) establishes IoT-device data portability and access rights. The Digital Services Act (2024) sets platform rules, including a tier for very large online platforms and search engines (VLOP/VLOSE) with more than 45 million EU users. The NIS2 Directive (2024) imposes cybersecurity obligations on critical sectors, with 24-hour incident reporting.

The vertical pillars are sectoral. The AI Act (2024) provides risk-based AI governance. The Digital Markets Act (adopted 2022, implementing 2023) regulates gatekeepers such as Google, Apple, Meta, and Amazon. The Cyber Resilience Act (2024) requires security-by-default for products with digital elements.

The national additions layer covers member-state rules on top of the EU frameworks: Italy's AI law (October 2025), which carries criminal penalties; France's biometric rules; and Germany's data-localization requirements.

The healthcare AI compliance cascade

Returning to the pop quiz, Farahany traces what a single high-risk healthcare AI system triggers. It requires a Fundamental Rights Impact Assessment (FRIA) under the AI Act and a Data Protection Impact Assessment (DPIA) under the GDPR. If it processes connected-device data, the Data Act imposes data-holder obligations. If deployed via a platform, it falls under the DSA's platform rules, which Farahany compares to Section 230-style rules. It must meet cybersecurity requirements under NIS2 and the CRA, plus any applicable member-state national rules. Each obligation, she notes, comes with different timelines, authorities, and documentation, all requiring different expertise.

Conflicts between frameworks

Farahany argues that the frameworks can pull in opposite directions. The AI Act requires detailed logging for auditing, while the GDPR demands data minimization. She frames an erasure problem around GDPR Article 17, the right to be forgotten: whether training data can be deleted from a neural network without retraining, and if a system is retrained, whether it is still the same system that passed AI Act conformity assessment. She also points to tension among Data Act "data holder" obligations for connected-device data, the AI Act requirement that training data be relevant, representative, and error-free, and GDPR cross-border transfer restrictions.

A related problem she calls the five-different-incident-reports problem: when a serious incident occurs, an organization may face five reports with five deadlines to five authorities. A GDPR personal-data breach must be reported within 72 hours to the data protection authority (DPA); a NIS2 significant incident within 24 hours to the CSIRT; an AI Act serious incident within 15 days to market surveillance; with more depending on circumstances. Farahany asks who writes these at a 30-person startup during the actual crisis.

Closing argument

Farahany ends by suggesting that process may be Europe's strength rather than its weakness. She argues that a system that takes four years to pass a law and four months to realize it needs fixing might reflect a capacity to learn, adapt, and correct, and that the complexity may be the inevitable result of trying to regulate AI democratically. She closes on the idea that the tension between harmonization and complexity is itself the point.

Relationships