Doble Lectura #4

Not everything called 'AI regulation' regulates the same thing

A team from Stanford and Harvard builds a taxonomy to compare the artificial intelligence laws of five jurisdictions, including Brazil. The finding: using the same word for voluntary guidelines and for binding laws creates a false sense of protection and opens the door to regulatory capture.

Generated automatically · sources linked · no prior human review

At a glance

  • What it is: Comparing Apples to Oranges: A Taxonomy for Navigating the Global Landscape of AI Regulation
  • Who: Sacha Alanoca and Kevin Klyman (Stanford University), with Shira Gur-Arieh and Tom Zick (Harvard University).
  • Where: FAccT ‘25, the ACM conference on fairness, accountability and transparency, Athens, June 2025. doi.org/10.1145/3715275.3732059
  • Type: comparative analysis. They build a taxonomy of eleven criteria and apply it to five legal frameworks, with interviews with regulators and legal experts as input.

First reading: what it does and what it finds

It helps to start with what the study is not. It is not an experiment or an evaluation of which law works best. It is a conceptual work: the authors build a taxonomy, a grid of eleven criteria, to compare in an orderly way artificial intelligence laws that are currently discussed as if they were the same thing. They apply it to five jurisdictions they call early movers: the European Union, the United States, Canada, China and Brazil. The source material is the legal texts and interviews with regulators and experts from each place, plus an interactive visualization to make all of it accessible.

The thesis is in the title. Comparing these laws is comparing apples to oranges. The underlying problem, they argue, is semantic: the label “AI regulation” is used equally for voluntary guidelines (what they call soft law) and for binding laws with penalties (hard law), and that ambiguity is not innocent. When a recommendation with no obligation is presented as if it were a law with teeth, it produces what the paper describes as a false sense of security: citizens believe they are protected by strict rules that do not actually exist. That confusion, they warn, also leaves the country more exposed to regulatory capture, when industry ends up writing the rules it is supposed to follow.

The concrete contribution is that grid. Instead of analyzing each law separately, the taxonomy reveals the axes along which the five frameworks diverge. Some regulate horizontally, classifying all uses by risk level, like the European Union and Brazil; others do so vertically, stretching sectoral laws that already existed, like the United States. Some act ex ante, requiring testing before the system is deployed; others ex post, leaving redress until after the harm. Some target the technology (generative models, dual-use foundation models); others, the specific use (biometric identification, social scoring). And enforcement ranges from centralized models, such as the European AI Office or China’s CAC agency, to models spread across sectoral regulators, as in the United States and Brazil.

Of the eleven criteria, the one the authors flag as the most opaque is stakeholder participation in the design of the law. That is where their most uncomfortable finding appears: a systematic asymmetry between the private and the public. In Canada, of 253 stakeholders consulted for its AI law, 216 came from the business sector, with minimal presence of marginalized groups. In Brazil, during the passage of an earlier digital law, a big tech company was accused of promoting entries against the bill in its search engine. For the authors, those imbalances are the raw material of regulatory capture: for example, setting the compute threshold that triggers obligations just above the models that exist today, so that in practice nothing ends up regulated.

A nuance that runs against common sense: the paper dismantles the idea that regulating and innovating are mutually exclusive. China, with strict regulation, remains a leader in AI development. The coexistence of the two, they say, shows that they are not opposites.

Second reading: from Latin America

Here the reading is direct, because Brazil is one of the five cases and not an appendix. Its bill 2338/2023, modeled on the European Union’s risk-based approach, would be the first comprehensive artificial intelligence law in Latin America if it is passed. The paper describes it with its own architecture: a decentralized enforcement system, coordinated by the data protection authority and supported by sectoral regulators. The authors also point out that they looked beyond the US-Europe axis by including Brazil and China, in a field that tends to ignore these countries.

What the taxonomy offers the region is a tool to avoid confusion. And this is my reading, not the paper’s: most Latin American countries, outside Brazil, are still in soft law territory, that is, national strategies and voluntary principles. The study’s central warning lands right there. If a statement of good intentions is communicated as if it were a binding law, the risk is not just rhetorical: it is that citizens let their guard down believing they are protected. The grid is useful precisely for asking each regional framework what is real and what is facade: whether there are penalties, who enforces, who was consulted.

Where the study connects with the present is in the era of models. The authors themselves note that technology-focused regulation targets frontier models through compute thresholds, and that those thresholds can be set conveniently, just above the models already available. I add something that is my own extrapolation: several of those thresholds were written in 2023 and 2024, and at the speed at which models are advancing they age quickly, which makes the warning about capture even more concrete for anyone legislating in the region today.

The question it leaves works for any Latin American congress about to debate its law. Before celebrating that a country “already regulates AI,” it is worth opening the grid and checking what type of regulation it is. Because, as the paper shows, not everything that carries that name obliges anyone to do anything.

The fine print

  • It is a snapshot of a fast-moving landscape. The authors themselves accept this: the US executive order was revoked almost at the same time the paper was published. The taxonomy is designed to withstand those swings, but the data for each case expire.
  • There are five frameworks, chosen because they are binding, state-led and of global weight. That leaves out jurisdictions that only have voluntary guidelines, that is, much of Latin America beyond Brazil.
  • The stakeholder participation criterion is, by the authors’ own admission, the hardest to measure, due to a lack of public data. The work describes and organizes; it does not grade or rule on which law protects best.

Paper keywords: AI governance, AI regulation, AI ethics, responsible AI, participatory AI, risks of regulatory capture

Automated reading. This text was generated by Claude, an Anthropic model, from the original source, without line-by-line human review. It may contain errors or debatable interpretations; to check any point, see the original source.
Spotted an error? Report it

Tell us what's wrong, quoting the sentence if you can and, if you have it, the source that corrects it. An automated process reviews reports every night: if the error is verified, the page is corrected and a correction note is added at the bottom.

Your email is optional: we only use it if we need more context about the report. It doesn't subscribe you to the newsletter.