Why Is Everyone Suddenly Talking About the AI Act?

Why Is Everyone Suddenly Talking About the AI Act?

The AI Act is generating contradictory headlines. Once you understand why the law was created, you can evaluate those claims for yourself.

Hardly any topic surrounding AI is causing as much confusion right now as the AI Act.

In one place, people claim that AI will have to be labeled in the future. Elsewhere, they say the AI Act has been postponed. Others even write that ChatGPT will soon no longer be allowed in Europe at all.

Anyone who tries to compare these statements quickly notices something: they can hardly all be true at the same time. Some are correct. Some are only partially correct. Some are simply wrong.

So where does all this confusion actually come from?

A Law That Began Long Before ChatGPT

The obvious assumption is that the AI Act was created in response to ChatGPT and the current wave of large language models. The timing certainly suggests that.

In reality, however, the European Commission’s preparatory work dates back to a time when language models barely existed in the public consciousness. The original motivation came from different applications: facial recognition in public spaces. Systems used by public authorities to socially score people. Automated hiring filters that systematically disadvantaged certain groups. Scoring systems that evaluated people’s creditworthiness or behavior without allowing those affected to understand how the decision had been made.

These systems all have one thing in common: they make decisions about people, often without those people even knowing or having any practical way to challenge them. A scoring system, for example, might reject a loan application without the applicant ever learning which factors determined the outcome—a wrong ZIP code, a particular spending pattern, or a statistical correlation that has nothing to do with the individual’s actual situation. When a human makes a decision, people can ask for the reasons behind it. With an automated decision that has no disclosure obligation, that possibility simply does not exist. That was precisely the problem the regulation was intended to address—long before any language model was capable of writing text.

ChatGPT therefore did not trigger the AI Act. It merely made the legislation far more visible, because millions of people suddenly came into direct contact with AI and started asking which rules actually apply.

The Technology Is Not What Is Being Regulated

Anyone who wants to understand the AI Act has to let go of one very natural assumption: that a law about “AI” means AI as a technology is being regulated.

That is not what the AI Act does. It regulates the use case, not the tool.

The same language model that powers a chatbot may remain completely unregulated in one context, while in another it may be subject to strict obligations—or even prohibited. A language model that summarizes emails is subject to different rules than exactly the same model when it participates in decisions about granting a loan. Not because the technology is different, but because the consequences for the affected person are different.

For that reason, the AI Act distinguishes between levels of risk rather than between tools. Some applications are prohibited because they are considered incompatible with fundamental rights—for example, systems used by public authorities to socially score people by calculating an overall score from a person’s behavior and attaching advantages or disadvantages to it. Others are classified as high-risk because they influence access to jobs, loans, or education. Software that filters job applications before a human reviewer ever sees them falls into this category and must therefore meet specific assessment and documentation requirements. Some applications are subject only to transparency obligations because people should know that they are interacting with a machine or looking at AI-generated content. A customer service chatbot, for example, must identify itself as such; at that point, the AI Act requires nothing more. Everything else remains unregulated because it does not present a comparable level of risk. A language model that simply helps someone write an email does not fall into any of these categories.

This classification is the actual core of the law.

The AI is not what is being regulated. The use case is.

How strict the rules become also depends on who is acting. The AI Act distinguishes between providers that develop and place an AI system on the market and deployers that use it under their own responsibility. A company that configures a language model for its own applicant screening assumes different obligations than the provider that originally trained and supplied the model—even though both are dealing with exactly the same technology.

Why the Statements From the Beginning Still All Come From Somewhere

With this understanding, the three statements from the beginning become much easier to classify.

“AI must be labeled” is true only for a limited subset of applications: chatbots that must identify themselves as such, and certain AI-generated content. The blanket statement that “every AI” must be labeled is incorrect. The transparency requirement is tied to specific situations, not to the technology itself.

“The AI Act has been postponed” is also only partially true. Certain deadlines have been postponed, primarily for high-risk AI systems. Other parts of the legislation, such as the prohibitions on specific applications and the transparency requirements, continue according to schedule. Anyone concluding from this that the AI Act as a whole has been delayed is confusing one part with the entire framework.

“ChatGPT will be banned” cannot be derived from the risk-based approach at all. What is prohibited are specific use cases—not tools or providers. A language model, by itself, does not fall into any of the prohibited categories.

Three statements. Three different parts of the same layered regulatory framework. That explains why they feel so contradictory, even though none of them is entirely invented.

What Follows From This

Anyone who understands that the AI Act distinguishes between risk levels and use cases can evaluate every new headline about it by asking one simple question: Which part of the law is actually being discussed here—a prohibition, a high-risk classification, a transparency obligation, or none of the three?

Anyone who understands the AI Act as a collection of different rules for different levels of risk will find future headlines on the subject much easier to put into context.

Michael of the Dragons

develops books, software, and open frameworks around technical systems, digital independence, and durable software architectures.
More about Michael →
Why Is Everyone Suddenly Talking About the AI Act?
← Next Article Are We Controlling Software in the Wrong Place?
Why Is Everyone Suddenly Talking About the AI Act?
Previous Article → What Does My Coffee Machine Have in Common with ChatGPT?