AI Law
Last Updated: July 29, 2026 | By Mihail Sebastian | AI Dictionary
The body of binding legal rules that governs AI: statutes like the EU AI Act, plus existing privacy, liability, and anti-discrimination law applied to AI.
What is AI Law?
AI law is the body of legislation and court decisions that sets binding legal obligations for how artificial intelligence is built, sold, and used. Most of it is not new: privacy, anti-discrimination, product liability, and copyright law already reach AI systems.
What has changed is the arrival of AI-specific statutes, led by the EU AI Act, that regulate the technology directly rather than by analogy.
How AI Law Works
AI law comes from three directions. Legislatures pass statutes: the EU AI Act sets obligations by risk category, and several US states have enacted laws on automated decision-making and deepfakes.
Existing law extends to AI without rewriting: the GDPR gives individuals the right not to be subject to certain decisions based solely on automated processing, and a hiring algorithm that discriminates violates employment law exactly as a human recruiter would.
Courts fill the gaps, deciding who is liable when an autonomous system causes harm and whether training a model on copyrighted works requires a license – questions still moving through litigation.
AI Law vs AI Regulation
The practical difference: AI law is the binding text that legislatures and courts produce, while AI regulation is the detailed rulemaking, guidance, and enforcement through which public authorities put that text into practice. The EU AI Act itself is law; the technical standards, regulator guidance, and market surveillance built around it are regulation.
For an organization, the law defines what obligations exist, and regulators decide what counts as meeting them.
| AI Law | AI Regulation | |
|---|---|---|
| What it is | Binding text from legislatures and courts | Rules, standards, guidance, and enforcement built on that text |
| Who produces it | Parliaments and judges | Public authorities and regulators |
| What it tells you | Which obligations exist | How obligations are interpreted and enforced |
| Example | The EU AI Act’s legal text | Technical standards and market surveillance around the Act |
Example of AI Law
The EU AI Act, which entered into force in August 2024, is the first comprehensive AI statute. It sorts AI systems into risk tiers.
Practices judged unacceptable, such as social scoring by public authorities, are prohibited outright. High-risk systems, including AI used in hiring, credit scoring, and medical devices, must satisfy requirements for data governance, technical documentation, and human oversight before they reach the market.
Lower-risk systems carry lighter transparency duties: a chatbot has to disclose that it is one. The Act applies in phases, with the prohibitions taking effect first in early 2025 and most high-risk obligations following over the next years.
FAQ
Does GDPR apply to AI?
Yes, whenever an AI system processes personal data, which most systems that make decisions about people do. The GDPR governs the legal basis for that processing, and its Article 22 restricts decisions based solely on automated processing that significantly affect a person. It reached AI long before any AI-specific statute existed.
Is there a federal AI law in the United States?
No comprehensive federal AI statute exists. Federal agencies apply existing law to AI within their sectors, and individual states have passed their own statutes; Colorado enacted a broad state AI law in 2024. The result is a patchwork rather than a single rulebook.
Related AI terms: AI Regulation · EU AI Act · Compliance · AI Governance
Did you like the AI Law gist?
Learn about 250+ need-to-know artificial intelligence terms in the AI Dictionary.
Mihail Sebastian — Writes about AI governance, regulation, and the technology behind them. Placeholder bio — replace with a real credential line. About