By Victoria Castro
Antiquity was no a stranger to myths and legends about endowing artificial beings with reason and consciousness. The oldest known automata date back to Ancient Greece and Egypt, the Middle Ages combined folklore with the endowment of consciousness to artificial beings, and the first computer programmer, Ada Lovelace, speculated about the possibility of “a thinking […] or reasoning machine” as early as the 19th century. The first programmable digital computer was built in the 1940s. These are the origins of AI as we know it.
In and of itself, AI research did not appear until 1956. From then, growth was steep and fast. It became a multibillion-dollar business by the end of the 1980s. Machine learning reached its peak in the 2000s; soon after, deep learning followed. Generative AI was popularised as a result of the 2020s’ AI boom, with the appearance of large language models (LLMs), like ChatGPT, and models of Artificial General Intelligence (AGI), like OpenAI or DeepMind.
Parallel to these developments was the growth of social media. Early board-style platform precursors were popularised throughout the 80s and 90s; the social media boom arrived in the 2000s. As of today, 62.6% of the world uses social media. While both AI and social platforms are epiphenomena of technological development and globalisation, one single difference makes the approach taken to digital platforms and AI strikingly different: while the former is closely regulated, the latter is largely not. In the EU, the first policy relating to data privacy and social media regulation was adopted in 2002 with the e-Privacy Directive. The General Data Protection Regulation (GDPR) followed closely, being passed in 2016, and was complemented with the 2022 Code of Practice and Disinformation and the 2023 Digital Services and Digital Markets Acts (DSA and DMA respectively). Altogether, an ongoing effort is being made to address concerns over online safety, transparency, and privacy – worries not yet curtailed in the use of AI, despite these two sectors being so closely related.
Currently, hardly a day goes by in which AI is not the focus of at least one conversation. It has become the backbone of a great deal of larger systems, and an irremediably important source of assistance for its users. Ever since 2016, when the New York Times reported that the industry was in a “frenzy”, AI has seeped into day-to-day happenings. ChatGPT alone has an estimated 180 million monthly active users, sees over 122 million daily users, and processes over 1 billion queries per day; the EU estimates that in 2024, over 40% of large enterprises used AI. As it stands, it is an irremediable part of any system, from acting as email spam filters to diagnosing health-threatening disorders.
More troublingly, the COMPAS system controversy and Donald Trump’s election in 2016 proved that the mismatch between the capabilities of AI and technological infrastructure was concerning. The former, an AI case management and decision support software for criminal justice, was proved to make biassed and erring racial judgements, violating the US’ Fourteenth Amendment; in the latter, AI was used to deter Black Americans from voting. In neither of these examples has regulation been passed to avoid a future repetition. Most recently, Trump’s penchant for AI has taken the shape of posting deepfake videos of his political rivals; if a president being an intentional source of misinformation is not worrying enough, perhaps that he partakes in public slandering is. Ultimately, these cases demonstrate the risk of large-scale misinformation spurring from the misuse of AI, and the large gap between the capabilities of these softwares and their managing agencies. While these examples of misinformation and disorder are localised issues, they demonstrate the danger of AI and its potential to have international consequences. In being fed social media content, AI learned from and worked in systems solely meant to maximise engagement, leading to misinformation, misuse of data, and untrustworthy models. It is alarming to know that the EU’s communications and information sector is the most frequent user of AI despite these shortcomings, employed for R&D and innovation. Even more alarming was the suicide of a teen following his conversation with an AI chatbot earlier this year due to the unrestricted nature of AI usage.
Thus, while advantages seem numerous, concerns about potential risks and ethical implications seem equally various. International economics, security, politics, and credibility will be shaken by the implications of AI. It will exacerbate income inequality, AI-borne economic disparities, and threats to democracies due to the potential of AI disrupting electoral processes. These have pushed the EU to create the first ever legal horizontal framework on AI to address its risks, providing developers and deployers with clear requirements and obligations. Although it came into action in the summer of 2024, rules concerning high-risk systems will only be enforced from 2026, when the Act will achieve full legislative compliance, and provisions are expected to phase until 2027.
The EU Artificial Intelligence Act has many impacts. Firstly, it determines that employers dealing with AI must ensure all employees dealing with these systems have a sufficient level of AI literacy. Secondly, it forces AI products to have over a certain quality, promoting trust. Thirdly, it prohibits those AI systems threatening people’s rights or requiring unethical use. These include systems using subliminal manipulation, exploiting vulnerabilities, scraping biometric data, using biometric categorisation for sensitive traits, inferring emotions in sensitive contexts, and those used for social scoring, or for predicting criminal behaviour. Finally, it establishes the requirement for high-risk systems to be closely monitored, following EU standards and an independent third-party check, as they might affect safety and rights. These are AI systems in which the AI is meant to be a key safety feature, or if the AI itself is the product.
Although simple, the proposal has both European and extraterritorial finance bracing for impact. All companies providing or using AI (including its associated products) in the EU will be affected, independent of where they are headquartered; noncompliance will lead to fines of up to 7% of global annual turnover or of €35 million – whichever is higher.
The first obstacle for corporations is adhering to the rules set out by the Act. Companies must carry out risk-assessments, develop AI inventories, ensure compliance with the new regulation, offer clear and concise technical documentation and user information, develop and maintain risk management systems, ensure traceability, perform post-deployment monitoring, and establish a system of reporting with the national competent authorities (NCAs). This essentially forces companies offering AI-related services to create and streamline new systems whose only purpose is to fulfil the requirements the Act sets out. As a result, financial institutions are expected to increase outsourcing to ICT providers with greater frequency. Similarly, this will result in greater overhead on all AI spending. However, integrating of the Act’s monitoring requirements with the preexisting supervisory framework will help the market surveillance activities to remain unaffected.
Subsequently, all employees must be trained to use the company’s AI system appropriately. Staff training will become a new focus, both for those directly responsible for these systems and for employees indirectly affected. The EIOPA recommends the use of initiatives such as the ESA’s Digital Finance Supervisory Academy to use economies of scale and support more agile up-skilling to this end. This can eventually lead to an increase in efficiency and greater AI literacy. The candidate and customer-appraising systems will also require an update. Tasks usually relegated to the human resources department – such as recruitment and terminations – will also be affected.
More particularly, the financial sector, which is heavily reliant on AI, will experience a change in their compliance regulation systems. All financial institutions will have to assess, modify, and potentially create new systems, even when using third-party systems. The Act also labels AI-based creditworthiness, pricing, and risk assessments in life and health insurance as high-risk AI use cases, and thus will be subjected to stringent measures. In contrast, the rest of the services offered by the finance sector are likely to remain regulated by existing legislation; supervisors will address cases in which extra guidance must be applied.
One of the greatest impacts the AI Act will have is on the job market. Despite fears of AI substituting workers, new roles are set to become available as companies seek out workers with the skills to both satisfy and supervise the enforcement of the new legal requirements. At the macro level, the European Artificial Intelligence Office will be founded. At the company level, these processes of monitoring and security will require human oversight. However, much like many newspapers predicted, the use of AI to automate and innovate procedures will affect employees – especially those holding multiple jobs. Data suggests that clerical, secretarial, and para-professional roles will be the most affected, as automation will replace their tasks, putting at risk vulnerable workers. Altogether, the AI Act fails to fully address labour concerns, as certain roles and vulnerable positions are likely to be permanently lost. This results in a paradoxical policy that neglects employment security, particularly that of vulnerable groups, while remaining human-centric by placing the full control and supervision of AI on the hands of new government authorities. New boards, panels, and forums have been created to this end.
The quality and monitoring requirements are also accompanied by transparency obligations: users must be informed of the use of AI unless its use is obvious or for legal purposes. Businesses must appropriately label all AI content, notify users when AI is being used for emotion or biometric analysis, disclose manipulated content, and provide clear and accessible information about their AI system where applicable. By enhancing confidence and trust in AI solutions, consumers and employees alike will show a greater predisposition towards systems using AI to automate, thus easing pressure on companies.
The introduction of the EU AI Act also entails a leveling of the playing field amongst the EU countries. All companies will be subjected to the same regulation, promoting cross-border trade and innovation within the EU. Nevertheless, it might become a challenge for these same companies to compete against industry rivals with unrestricted AI access. It is for this reason that the EU recently paused and simplified the Act. Imposing stringent measures on a rapidly-changing industry may dampen growth by blocking the adoption of cutting-edge services. While the US and China (the EU’s greatest competitors) choose innovation, the EU has prioritised tackling legislation; while the international equity market faces a boom in the AI industry large enough to provoke a slowdown in other sectors, the EU has taken a step back. Although the Act is intended to boost competitiveness by making the EU the market leader in a ‘trust-worthy’ brand of AI, its shortcomings at an international scope are many. As a result, it is likely that the European AI sector will suffer from early stagnation and future regulatory inconsistencies.
In humanities-related industries, the impact of the Act is much more positive than what could be anticipated. Greater control over AI will return to artists their voices, while establishing harsh controls and measures over intellectual property. Data protection regulators will be accompanied by new measures to protect copyright and patents. It is possible that this will galvanise a boom in art industries as the act of creating is revaluated, or that, conversely, higher costs might hinder them. In the broader economy, this new emphasis on data protection is expected to become a thorny topic: while increased transparency and security are expected to facilitate the licensing process and award data-owners AI revenue, no existing managerial frameworks currently address all the caveats the Act requires them to, and the regulatory landscape will most likely fragment further as each EU country sets its own pricing and rules. In addition, these increased costs might be prohibitive for small agents. Although they can be excluded from the strictest aspects of the regulation, this omission will lead to its own obstacles, such as biassed AI datasets borne from a lack of information on smaller or marginal communities or languages. Altogether, this price increase might be recessive for certain products and lead to a drop in competition, although the creation of natural monopolies is unlikely.
Nonetheless, AI-supporters argue these consequences would have taken shape regardless of the timing of the Act. Ultimately, the use of AI in and consequent legislation would have spurred changes to the very structure of the corporate and financial systems. The greatest obstacle the Act will generate for European markets is the possibility that this stance will become a competitive setback for the EU. Whether this will pay off in the long term, when the US and China have to tackle the structural caveats the unrestricted use of AI provokes remains to be seen, but what is for sure is that the EU is joining the race late.
The views expressed in this article are the author’s own, and may not reflect the opinions of The St Andrews Economist.
Image Source: Sprout Media Lab

