Roundtable #36: Scraping By: Generative AI and the Limits of Cross-Border Governance
Section I: The Reproduction Right—AI Training Under the Berne Convention
When an artificial intelligence (AI) model stores a copyrighted work as part of its training process, a reproduction has occurred under Article 9 of the Berne Convention, to which more than 180 countries are party. Whether that reproduction is permissible depends on national exceptions that vary dramatically across jurisdictions. Article 9 gives authors the exclusive right to authorize reproduction of their works, but Article 9(2) allows countries to create exceptions provided the reproduction “does not conflict with a normal exploitation of the work and does not unreasonably prejudice the legitimate interests of the author.” The legislative frameworks of the United States and Japan, as currently applied, fail to satisfy the Berne Convention’s three-step test, while the European Union’s framework offers the strongest case for compliance, though all three approaches ultimately leave room for greater copyright protections in the context of commercial AI training.
For generative AI models to analyze data, including creative works, they first have to be stored, copied, or processed as part of a training dataset. However, Article 9(1) of the Berne Convention states that “authors of literary and artistic works protected by this Convention shall have the exclusive right of authorizing the reproduction of these works, in any manner or form.” AI developers, such as OpenAI, argue that output generated does not copy what it is trained on. Traditional copyright infringement analysis focuses on substantial similarity between the allegedly infringing work and the original, so by centering the question on output, AI companies shift the analysis to a framework that favors them. However, this approach ignores the legal issues with the training process itself: reproduction also occurs when a copyrighted work is stored, regardless of the final product. The Agreed Statements concerning the WIPO Copyright Treaty maintain that the reproduction right applies in the digital environment and that storage of a protected work in an electronic medium constitutes reproduction. The relevant question under Berne is therefore not whether the output resembles the original work, but whether the input process—including storing copyrighted works to train the AI model—constitutes unauthorized reproduction. Under the Agreed Statements, such storage does constitute reproduction. Despite this, AI training remains widespread across the globe due to the national exceptions permitted by Berne Article 9(2).
Berne Article 9(2) permits member states to create national exceptions to the reproduction right, provided any exception satisfies a three-step test. First, it must constitute a “certain special case,” meaning it must be limited in scope with a specific policy justification. Second, it cannot conflict with the “normal exploitation of the work”—the ability of rightsholders to derive economic value from their reproduction right, including in existing or foreseeable markets such as emerging licensing opportunities. Third, the exception cannot “unreasonably prejudice the legitimate interests of the author.” This does not mean an exception can cause no harm, but the harm to the rightsholder must be proportionate to the public policy purpose the exception serves. All three conditions must be satisfied for an exception to be valid.
In the United States, the fair use doctrine allows certain uses of copyrighted materials without explicit authorization from rightsholders. Although fair use was not created specifically for AI, it has become the standard framework for AI copyright disputes. In Bartz v. Anthropic (2025), authors sued Anthropic for using their copyrighted books without authorization to train models for Claude. The federal court applied the doctrine to AI training and concluded that Anthropic’s use was fair because it was “exceedingly transformative.” Fair use evaluates four factors: the purpose and character of the use, the nature of the copyrighted work, the amount copied, and the effect on the market. Notably, the court did not consider whether its interpretation of fair use satisfies the Berne Convention’s three-step test. Such a gap demonstrates a structural disconnect: the Berne Convention is not self-executing in the United States and was implemented through domestic legislation. Courts apply the domestic statute rather than the treaty directly, meaning that no court is required to guarantee that its fair use analysis complies with the three-step test. An interpretation of fair use that categorically authorizes commercial generative-AI training conflicts with the United States’ obligations under the Berne Convention, as the following analysis demonstrates.
A broad application of fair use to generative AI training permits copying on an enormous scale for commercial development without clear consent or compensation. This conflicts with the first step of the three-step test because AI training is not a limited circumstance when it involves large-scale use of works across an entire industry. The World Trade Organization panel in the United States—Section 110(5) of the U.S. Copyright Act (2000) interprets “certain special cases” to mean that an exception must be clearly defined and narrow in its scope. Fair use can apply to any type of use rather than serving as a specific exception limited to AI training. When applied broadly across multiple industries, it is no longer a “certain special case.” Furthermore, copyrighted works are valuable to the data training process, and using them without consent disregards the financial value that rightsholders could have negotiated with AI companies. Licensing works for AI training is not hypothetical: the Associated Press licensed parts of its news archive to OpenAI in 2023, and the New York Times filed suit against OpenAI in December 2023 arguing that unlicensed training destroys the market for its journalism. Together, these developments demonstrate that the AI training licensing market is a foreseeable market: publishers are both willing to license and prepared to litigate when licensing is bypassed. If AI companies can use copyrighted creations for free under fair use, this undermines an emerging market that constitutes foreseeable normal exploitation, violating step two. Potential prejudice to authors also extends beyond individual licensing losses. AI models trained on copyrighted works can substitute for original works across entire industries, including research, education, and entertainment, reducing the aggregate market value of those works. This systemic harm to both individual authors and entire categories of creative work violates step three. The breadth of the fair use doctrine, as currently interpreted to permit mass commercial AI training, fails to satisfy all three requirements of Berne Article 9(2).
Japan’s framework for AI training comes from Article 30-4 of the Copyright Act, allowing copyrighted works to be used for data analysis and training when the purpose is for “non-enjoyment.” This means that copyrighted works cannot be used to enjoy or allow someone else to enjoy the expression contained in the work; the work must be analyzed purely as data, not read or viewed for its original purpose. The law therefore allows AI developers to store works without the authorization of rightsholders. However, Article 30-4 does not apply to training that analyzes data regarding a specific author or artist. Japan’s legislation attempts to comply with the first step of the test by creating a distinction between enjoyment and non-enjoyment purposes. However, it is still not truly a “special case,” as most AI training can be classified as non-enjoyment. Whether a work is being enjoyed or not does not remove the economic effect on the rightsholder. Similar to the U.S. approach, authors may lose the opportunity to license their work to AI companies, which conflicts with normal exploitation. Japan’s law provides that use is not permitted when it would “unreasonably prejudice” the rightsholder’s interests. However, the law does not guarantee prior consent and does not create a general remuneration right. Individual authors face a structural burden-of-proof problem: the harm from AI training is diffuse and cumulative, spread across millions of works in a single training dataset, making it difficult for any single author to quantify how much market value they lost. The proof requirement is individual, but the harm is systemic. Although Japan’s approach is more specific than U.S. fair use, it still fails the second and third steps of the three-step test.
The European Union’s Digital Single Market (DSM) Directive provides a separate framework for text and data mining. It permits AI developers to perform data mining for any purpose on lawfully accessible works. However, rightsholders can opt out and state that their work cannot be used for data mining. The DSM Directive falls within “certain special cases” because it specifically applies to text and data mining rather than serving as a general-purpose exception. The opt-out mechanism protects normal exploitation by enabling rightsholders to decide whether their works are used for AI training. If they reserve their rights, an AI developer must either avoid using the work or seek authorization, bolstering the AI training licensing market rather than undermining it. This mechanism also protects the author’s legitimate interests by providing control before works are used, rather than requiring proof of prejudice after training has occurred. However, the opt-out system is only effective if authors know where their works are being trained and can meet the technical requirements, such as machine-readable rights reservations. Individual authors, particularly those in developing countries or outside the technology sector, may lack the resources or technical knowledge to implement these reservations. The protection is formally available but practically inaccessible to many of the rightsholders it is designed to protect. The EU framework reasonably satisfies all three steps of the Berne test, but this practical gap means that compliance depends on the capacity of the rightsholder rather than the strength of the right.
Article 9(2) was not written with generative AI training in mind. There is precedent for responding to technological change through new international agreements: the WIPO Copyright Treaty was adopted as a special agreement under Berne to address copyright issues created by the digital environment. AI training creates an analogous situation because it implicates the reproduction right in ways that the existing framework does not account for. In both cases, a new technology made the reproduction right trivially easy to exercise at scale, outpacing the legal frameworks designed to govern it. Participating members of Berne could adopt another WIPO special agreement clarifying how the three-step test applies to AI training. This agreement should recognize AI training licensing markets as part of the normal exploitation of a work and establish minimum standards concerning access, rights reservations, and compensation. It could borrow from the EU’s opt-out framework while addressing its practical weaknesses, particularly ensuring that authors are aware that their works have been used and can exercise their rights without specialized technical capacity.
The most significant obstacle to such an agreement is the United States: the foremost AI companies in the world are located in the United States, and the United States has a history of resisting international copyright obligations that conflict with domestic fair use doctrine. If the United States declined to join a new WIPO special agreement, the agreement would govern the use of copyrighted works everywhere except in the jurisdiction where most AI training occurs. Overcoming this obstacle may require the same market pressure that has driven convergence in other areas: EU adequacy requirements, bilateral trade agreement provisions, or the regulatory gravity that has already led jurisdictions like Brazil to align with EU standards. Without such coordination, the reproduction right that the Berne Convention guarantees will continue to be exercised differently depending on where an AI company is headquartered rather than where the copyrighted work was created.
By Oluwadara Akinsooto
Section II: The Voluntary Standard—Cross-Border Data Under the GDPR and CBPR
Generative artificial intelligence (AI) models are trained on datasets scraped from individuals across jurisdictions; however, no single legal framework governs how that data is collected. Given that the data transcends geographical boundaries, the traditional legal understanding of territorial authority now constrains enforcement, enabling tech actors while limiting the reach of national regulators.
To address this tension, the international community has fractured into various approaches. Major frameworks, including China’s Personal Information Protection Law (PIPL), India’s Digital Personal Data Protection Act (DPDP Act), and Brazil’s General Data Protection Law (LGPD), provide distinct statutory mechanisms. However, while each of these frameworks merits analysis, the European Union’s (EU) legally binding General Data Protection Regulation (GDPR) and the APEC/Global Cross-Border Privacy Rules (CBPR) represent the clearest contrast between binding and voluntary approaches, making them the most productive comparison for evaluating AI governance. While the GDPR framework enforces strict mandates on how data is processed and provides individuals with a comprehensive set of rights, the CBPR system is voluntary and reliant on corporate self-assessment, allowing for easier data transfers across participating economies through consensus-based baselines, verified by independent accountability agents.
The unprecedented scale of AI development and its acquisition of data test the capacity of voluntary systems like CBPR. Since AI developers can train their models on data of individuals across multiple jurisdictions while fully opting out of such frameworks, self-regulatory systems fail to provide protection: non-certified developers remain exempt from certification obligations (barring separate domestic regulations), and accountability agents lack the authority of direct statutory fining. The GDPR model of hard law faces significant challenges regarding extraterritorial enforcement, but these challenges concern the reach of binding law, not its necessity.
The GDPR addresses the problem of varying jurisdictions through the broad scope found in Article 3. Under Article 3(2), the regulation applies to non-EU processors of data if their data processing operations relate to offering goods or services to data subjects within the EU (Article 3(2)(a)) or monitoring their behavior within the EU (Article 3(2)(b)). In relation to generative AI, scraping publicly available data very rarely constitutes directly offering goods or services to individuals. Instead, jurisdiction under Article 3(2)(b) applies when model training consists of monitoring online behavior. The European Data Protection Board (EDPB) clarifies in Guidelines 3/2018 that this criterion requires a non-accidental nexus to the EU, meaning indiscriminate global web scraping triggers GDPR oversight only if an AI developer intentionally tracks the online activity of individuals located within Union territory. Yet the EDPB leaves ambiguous whether harvesting EU languages, regional topics, or EU domain extensions is indicative of intentional tracking without explicit geographic targeting. Since the vast majority of AI developers acquire training data via untargeted and indiscriminate scraping rather than intentional tracking, many foreign AI models may fall beyond the scope of Article 3(2)(b), creating a loophole in the GDPR’s extraterritorial reach. Furthermore, even where Article 3(2)(b) theoretically applies, enforcement requires detection. European supervisory authorities generally lack the technical capacity to trace and attribute specific instances of web scraping to specific overseas developers, meaning the GDPR may have jurisdiction on paper while lacking the practical means to identify violations.
The GDPR’s extraterritorial framework builds on foundational principles from the Court of Justice of the European Union’s (CJEU) landmark Google Spain SL, Google Inc. v. Agencia Española de Protección de Datos (AEPD) (2014) decision, which affirmed that data processed outside the EU is bound by EU law if linked to a local subsidiary. This practically binds major international tech companies with European operations but creates an enforcement gap for offshore AI startups that harvest EU data without any local presence. While Article 27 requires non-EU controllers to designate an EU representative, non-compliant startups frequently fail to appoint one, and even where a representative exists, data protection authorities face difficulties collecting statutory fines from foreign entities lacking EU assets. Importantly, the global reaction to this aggressive extraterritoriality demonstrates that binding regulation does not drive companies away. Rather than exiting the EU market due to increased regulations, many foreign economies have aligned their statutory baselines to maintain data flow compatibility with the EU, engaging in the Brussels Effect. Brazil’s LGPD, for example, explicitly oriented its provisions after the GDPR to preserve broader international commercial ties. This demonstrates how binding laws can stretch beyond the territory in which they are implemented by encouraging global standards through market pressure.
On the other hand, CBPR lacks this gravitational pull primarily due to structural deficiencies in its enforcement mechanisms. Founded upon the APEC Privacy Framework, CBPR relies on corporate self-assessment verified by independent accountability agents. Since this participation is voluntary, AI developers can simply decline to apply for certification, leaving their data harvesting practices entirely outside CBPR oversight, barring separate domestic laws. Even certified companies that violate privacy principles face minimal legal jeopardy, as accountability agents lack independent statutory fining authority or injunctive powers. They are limited to revoking certification or referring non-compliant entities to domestic regulators like the Federal Trade Commission (FTC) in the United States, whose Section 5 enforcement authority is restricted to entities involved in domestic commerce. Foreign AI developers operating without a U.S. presence are therefore beyond the FTC’s reach, exposing a parallel limitation to the GDPR: both frameworks struggle to enforce against offshore actors without a local presence. However, the important difference lies in the remedies available once a violation is identified. The GDPR provides regulators with statutory mechanisms including binding suspension orders via Article 58, representative mandates via Article 27, and statutory fines enforceable through international legal cooperation. When the GDPR identifies a violation by an offshore actor, it has tools to respond even if collection is difficult. The CBPR has no equivalent statutory recourse even when clear violations are identified, leaving individuals whose data has been harvested defenseless outside of the EU or jurisdictions with equivalent hard-law protections.
These gaps are not limited to jurisdictional reach; they extend to operational enforcement as well, where generative AI is inherently resistant to traditional data privacy frameworks. Training models consume large amounts of unstructured web data rather than more discrete, consent-based records, creating a fundamental conflict with data protection principles. Recent enforcement actions, including the Italian Data Protection Authority’s (the Garante) intervention against OpenAI and the EDPB’s 2024 report on AI models and data protection, confirm that mass web scraping frequently conflicts with core GDPR requirements. Under Article 6, data processing requires valid consent or “legitimate interest” under Article 6(1)(f). Mass web scraping is practically blind to informed consent, forcing AI developers to rely on legitimate interest arguments. In 2023, the Garante temporarily blocked ChatGPT, holding that OpenAI lacked an adequate statutory basis to collect personal data for model training under Article 6. After OpenAI implemented age verification, updated its privacy policy, and rolled out a data opt-out mechanism, the Garante restored access. The intervention demonstrates both the power and the limits of hard law: the GDPR created the statutory basis to suspend operations entirely, but enforcement ultimately produced procedural concessions rather than structural changes to OpenAI’s data collection practices—a result that is still beyond what the CBPR framework could achieve, as it lacks the statutory leverage to compel any operational change at all.
A similar tension arises in algorithmic retention under GDPR Articles 16 and 17. While Article 17 establishes a right to erasure, whether “erasure” necessitates purging raw training datasets or undergoing “machine unlearning” to strip the influence of specific data from an already-trained model remains legally contested. If compliance is prevented by technical impossibility, then even hard-law jurisdictions face operational boundaries. Frameworks such as CBPR contain general baselines for eliminating raw source records but lack mechanisms to enforce complex algorithmic unlearning. Although European data protection authorities have not yet ordered an AI company to undertake machine unlearning, the monetary penalties and processing suspensions available under Article 58 represent an advantageous statutory leverage that could theoretically compel AI companies to develop unlearning solutions or face operational shutdown.
Beyond processing and retention, the most significant challenge for AI governance lies in the regulation of international data transfers. The CJEU’s decision in Data Protection Commissioner v. Facebook Ireland Ltd and Maximillian Schrems (Schrems II) (2020) affirmed that personal data cannot be transferred to third countries unless protections essentially equivalent to EU law are guaranteed, even when relying on transfer mechanisms like Standard Contractual Clauses. Generative AI strains this framework because distributed cloud computing fragments training data across global servers, and data incorporated directly into models makes the models themselves a cross-border data issue. This creates an unresolved question under Schrems II: whether each movement of training data across servers in different jurisdictions constitutes a separate “transfer” requiring its own adequacy assessment, or whether distributed model training is treated as a single processing operation. Current case law has not addressed this distinction, but the answer would fundamentally determine the compliance burden for AI developers training models across international infrastructure. If each server-to-server transfer requires independent adequacy verification, compliance at the scale of generative AI training becomes practically impossible; if the entire process is treated as one operation, the adequacy assessment applies once but must account for every jurisdiction the data touches.
The structural difference between the two regulatory systems ultimately rests in the binding enforcement authority. The GDPR provides supervisory authorities with statutory power under Article 58(2)(j) to issue binding orders suspending non-compliant data flows and processing operations. In practice, enforcement faces many challenges. For example, Meta continued transferring EU user data into the United States for years post-Schrems II before authorities issued a €1.2 billion fine and transfer suspension order in 2023. However, this delay is indicative of administrative capacity limits rather than a defect in legal power, as regulators possess the unilateral authority to impose binding penalties regardless of corporate consent. Importantly, this mechanism has been applied directly to AI: European data protection authorities have used Article 58 to compel Meta and X to suspend training their models on EU user data. While the enforcement delay reveals a limitation of hard law, the GDPR’s system remains structurally superior to that of the CBPR, which lacks any statutory mechanism or injunctive authority to block cross-border data transfers or processing into jurisdictions with weak privacy protections.
Generative AI demonstrates that voluntary regulatory frameworks cannot address the data practices of modern AI companies. Binding hard-law regimes are certainly far from perfect, as evidenced by enforcement delays, jurisdictional limits over offshore entities, and the technical difficulties of machine unlearning. However, hard law is indispensable because it creates enforceable obligations that exist regardless of corporate willingness to participate. Since a singular global treaty remains unlikely due to constitutional and legal divides, the future of AI governance depends on actionable hard-law pathways: mutual recognition agreements with strengthened statutory interoperability, expanded GDPR Article 45 adequacy decisions bridging compatible jurisdictions, and statutory backstops including mandatory data privacy provisions in trade agreements. These mechanisms would accomplish what voluntary frameworks cannot: creating enforceable obligations that apply to AI developers regardless of whether they choose to participate. Only through such hard-law baselines can governments around the world prioritize personal data and privacy over corporate control, regardless of the location where AI models are trained or used.
By Ashva Ramesh
Section III: The Precautionary Gap—GenAI Regulation Under the EU AI Act
The precautionary principle, initially emerging out of environmental law under the Rio Declaration (1992), has been an indispensable guiding tool within the European Union (EU) for decades in addressing the human and environmental impacts of emerging technologies. Today, the international community is grappling with the emerging technology of Generative Artificial Intelligence (GenAI), and how to effectively regulate it. In a recent MIT study, experts agreed that potentially catastrophic harms resulting from GenAI—ranging from AI-enabled weapons with mass-harm capabilities and the proliferation of false or misleading information to skyrocketing inequality and unemployment—are possible as soon as the next five years. The EU’s competence to regulate AI is derived from Article 114 of the Treaty on the Functioning of the EU (TFEU), which defines the competence to create harmonized product safety regulations. The EU’s 2024 landmark AI Act has been lauded as the first attempt at a comprehensive regulatory framework for AI technologies, and the Act’s explanatory memorandum outlines its goal of balancing economic interests with the protection of fundamental rights, as defined by the Charter of Fundamental Rights of the European Union. The Act does not meet this goal of robust fundamental rights protections primarily because it fails to properly integrate the precautionary principle, instead assuming regulators can comprehensively identify harmful applications of AI before market rollout and failing to account for the emergent risks of GenAI. This disparity in the application of the precautionary standard is clearly seen when compared with EU regulations of GMO and Genome Editing technologies, and the very fact that the Act is grounded in consumer protection law creates a structural ceiling for fundamental rights protections against AI technology.
The holding of the Court of Justice of the European Union (CJEU) in Artegodan and Others v. Commission (2002) established the precautionary principle as a “general principle of Community law.” It requires “the competent authorities to take appropriate measures to prevent specific potential risks to public health, safety and the environment, by giving precedence to… the protection of those interests over economic interests,” and instructs that action may be taken by governments even if there is inconclusive scientific evidence as to the possibility of that harm. The court elevated the precautionary principle—originally codified in Article 191(2) of the TFEU for environmental policy—to a general principle of EU law, meaning it applies across the entire EU legal order, not only in environmental contexts. This establishes a three-element legal test for the application of the principle: the possibility of serious or irreversible harm, a level of scientific uncertainty, and the duty of the appropriate governing body to take proportionate action to prevent harm.
Experts in the MIT AI risk study reinforced that GenAI is a fundamentally “new paradigm” that could create “society-wide” vulnerabilities, and leaders should not wait for “perfect forecasts” of risk before acting. This is the exact kind of uncertainty the precautionary principle is designed to address, yet the AI Act’s core apparatus of risk management does not meet element three, a proportionate and precautionary response. The risk-classification system consists of four closed risk categories—meaning classification operates on a predetermined list of sectors and intended use cases—and most of the regulations pertain to applications predetermined to be “high-risk.” The risk assessment formula utilized is simple harm probability multiplied by severity, which is firmly rooted in EU consumer safety regulation. This results in highly standardized regulations that cannot be flexible enough to adapt to AI effects emerging across diverse sectors of society. This only assesses known and measurable risks identified in advance, and fails to address the novel and unmeasurable risks of GenAI. It also discounts impacts flagged by experts that may not seem catastrophic as isolated events, but that create cumulative, society-level harms, such as “cognitive atrophy” among younger generations and systemic inequality resulting from bias in AI resume screening. Such issues necessitate a precautionary approach, but because the Act classifies risk based on intended purpose and assumes regulators can correctly identify “high-risk” use cases of AI in advance, systems outside the “unacceptable” or “high-risk” categories receive relatively limited oversight, even though their emergent uses and long-term impacts may be dangerous.
The EU’s regulatory treatment of other technological innovations indicates that there is a significant inconsistency with the application of EU law in AI regulation. Commonly, the precautionary principle is divided into either “strong” or “moderate” applications, but a look at both forms reveals that the AI Act does not conform to either precedent. Arguably, the strongest application of the precautionary standard in the EU is in Heritable Human Genome Editing (HHGE) technology regulation. HHGE is similar to GenAI in that it is an emerging technology with both high risks and rewards, including far-reaching social impacts and difficulty fitting into a rigid regulatory framework given its wide applications. There is currently a blanket moratorium on heritable genome editing per Article 13 of the Oviedo Convention, meaning the technology can only be researched and developed in labs. This gives both scientists and regulators time to collect data and evaluate the costs and benefits of the technology. Yet, even in more “moderate” applications of the precautionary principle, as in GMO regulation, there are more comprehensive precautionary protections than currently exist in the AI Act. In EU GMO regulation, any genetically modified plant that cannot theoretically occur through traditional breeding techniques must obtain explicit permission from a member state before being released into the market, and individual member states are permitted to enact stricter bans on GMO cultivation. In contrast, the AI Act’s compliance approach places the burden on the regulator to classify the system as high-risk, as opposed to the developer to demonstrate actual safety. “Limited” and “minimal” risk systems only require adherence to basic transparency rules, without any formal pre-market sign-offs. This creates a veneer of protection for consumers, instead of substantive rights protections per the EU’s charter obligations. This discrepancy may also be a byproduct of the AI Act’s grounding in Article 114 of the TFEU and its market focus, in which the significant economic incentives of the AI industry color how risk is defined and regulated.
Because the EU has no general competence to harmonize fundamental rights in the Member States, it must “shoehorn” the protection of fundamental rights into the scope of Article 114 as a secondary legal objective. Yet, the AI Act does not execute this secondary goal because it fails to meet the precautionary standard the CJEU has recognized as a general principle of EU law. The AI Act’s compliance framework effectively only manages risk, and there is an inherent tension in attempting to protect human rights through such frameworks because regulatory compliance acts on a sliding scale, while human rights act on a binary (i.e. either a right is upheld or violated). While the AI Act is the current guiding model for most other AI legislation across the world, the regulatory pathway the EU has chosen is not the only one. The Brussels Effect may have a negative impact by “exporting” EU constitutional limitations to other jurisdictions where possibilities may be broader. For example, Brazil has broader constitutional authority to regulate fundamental rights and a direct obligation to protect workers in the face of automation established by the Federal Constitution, yet by taking direct inspiration from the EU’s regulatory framework, it voluntarily restricts itself to a less effective approach. Similarly, South Korea’s AI Framework Act, which took effect in January 2026, adopted a risk-based classification approach directly inspired by the EU model, despite South Korea’s constitutional framework permitting broader protections for fundamental rights in the technology context. Other countries and international governing bodies should pursue explicitly rights-based approaches to AI regulation, such as imposed fundamental rights impact assessments regardless of presumed risk level, as well as additional sector- and issue-specific regulations to target the novel ethical and societal implications posed by particular GenAI applications.
By Zoe Pomeroy
Edited by Isabella Sacca and Owen Wang
This piece was reviewed and finalized by Qizhen (Kiara) Ba.
The views in these articles are those of the individual authors and not of the Columbia Undergraduate Law Review.