Addaly is in open beta. Things will change, and AI answers can be wrong — check anything that matters.

AI, Safety and What Goes Wrong

The failure modes of AI, stated plainly, with the numbers.

Lesson 68 of 739 min

Who is writing the rules

Four approaches, not one

There is no global AI law and there will not be one. What exists is four distinct regulatory philosophies, and knowing which one applies to you determines everything about what you must do.

Europe: regulate the product by risk. The AI Act, in force since August 2024, classifies systems by use — prohibited, high risk, limited risk with transparency duties, minimal risk — and imposes obligations accordingly, plus a separate regime for general-purpose models. Prohibitions applied from February 2025, general-purpose model obligations from August 2025, and the bulk of high-risk obligations from 2026 and 2027. Penalties run to tens of millions of euros or a percentage of global turnover. It applies extraterritorially where output is used in the EU.

China: regulate content and require filing. Interim Measures for generative AI services since 2023, algorithm and model filing requirements, and labelling measures effective September 2025 requiring both visible and embedded markers on synthetic content. The emphasis is on information control, provider registration and traceability.

The United States: sectoral, judicial and state-level. No comprehensive federal statute. Existing regulators apply existing law — consumer protection, employment discrimination, financial regulation. States have moved: Colorado enacted an algorithmic discrimination act with implementation dates pushed into 2026, California passed frontier-model transparency legislation in 2025, Texas passed its own framework, and Illinois' biometric statute remains the most litigated instrument in the country. The federal posture has shifted with administrations, and pre-emption of state laws is an active fight.

India: govern the data and the intermediary. No AI statute. The Digital Personal Data Protection Act 2023 covers personal data, the IT Act and IT Rules cover platforms and content including labelling obligations for synthetic media, and government advisories have carried substantial practical weight. The IndiaAI Mission funds compute and capability rather than regulating it. The stated position has favoured enabling adoption over restricting it.

The international layer

Thin, and worth knowing the names.

The Council of Europe Framework Convention on AI, opened for signature in 2024, is the first binding international treaty on AI and human rights, though its obligations are broad and implementation is left to signatories. A network of AI safety and security institutes now runs model evaluations across several countries. Summits at Bletchley in 2023, Seoul in 2024 and Paris in 2025 produced declarations and shifted in emphasis from safety towards adoption. The OECD AI Principles and UNESCO recommendation supply definitions that other instruments borrow, and the OECD's definition of an AI system was adopted almost verbatim into the EU AI Act.

What determines which applies to you

Four questions, in order.

Where are your users? Not where you are. The EU regime follows the output.

What does the system decide? Employment, credit, education, essential services, law enforcement and migration are where obligations concentrate everywhere.

What sector are you in? Health, finance and children's services carry duties that predate and exceed anything AI-specific.

Are you a provider or a deployer? The distinction runs through the EU regime and increasingly elsewhere: the builder and the user of a system have different obligations, and buying a compliant system does not discharge yours.

The state of play, honestly

Three things are true simultaneously.

The rules are real and enforcement is beginning, with the first penalties under data protection law for AI-related processing already issued in several countries.

The rules are also incomplete, inconsistent between jurisdictions, and in several cases written before anyone understood what they were regulating. Definitions of "high risk" and "general-purpose" are being argued over precisely because they determine who is captured.

And compliance is not the same as safety. A system can satisfy every documentation requirement and still harm people, because the requirements govern process rather than outcome. Every practice in this course that is not required by any regulation — measuring override rates, publishing false-accusation counts, guaranteeing a fallback at the gate — is worth more than most of what is required.

The useful posture is to know which regime applies, meet it, and not mistake meeting it for having done the work.

The one thing to keep

Europe regulates the product by risk, China regulates content and requires filing, the US works sectorally through existing regulators and states, and India governs the data and the intermediary — and the EU regime follows where the output is used, not where you sit.

Before you move on

A company based outside the EU sells a CV-screening tool to a customer in Germany, whose HR team uses it on German applicants. Which regime most clearly applies to the tool?

Pick the one you would defend. Nobody sees your answer.

No ads. No data sale. No public scores on people. Ever.

© 2026 Addaly