The AI Act and the shift in Europe’s regulatory paradigm: towards a normativity based on risk and compliance
The AI Act does more than govern artificial intelligence: it reveals a deep transformation of European regulatory law. By replacing a logic of sanction
The AI Act does more than govern artificial intelligence: it reveals a deep transformation of European regulatory law. By replacing a logic of sanction with a normativity based on anticipation, risk management and compliance, it marks the emergence of a new legal paradigm in the algorithmic age.

At first sight, the adoption of the European regulation on artificial intelligence (the AI Act) is a legal response to the rapid emergence of algorithmic technologies and their economic, social and political implications. Presented as an instrument intended to guarantee safety, the protection of fundamental rights and trust in artificial-intelligence systems, this text is part of a broader dynamic of digital regulation undertaken by the European Union. Yet a strictly functional reading of the regulation, focused on its objectives or on the obligations it imposes on economic operators, does not capture the real significance of this normative innovation.
The AI Act does not merely govern an emerging technological sector. More deeply, it is a marker of a structural transformation of European regulatory law. Through its architecture, its mechanisms and its underlying rationale, it appears to signal the shift from a legal model based on prescription and sanction to a form of normativity centred on anticipation, risk management and organisational compliance. In other words, this regulation invites us to question not only what the law regulates, but the way in which it regulates, and, more fundamentally, what the law itself has become in the algorithmic age.
The classical model of modern law rests on a relatively stable structure: the norm characterises a behaviour, determines its lawfulness or unlawfulness, and then organises, where appropriate, its sanction. This architecture belongs to a reactive temporality, in which legal intervention is conditioned on the occurrence of a violation. It also rests on a vertical conception of normative authority, centred on the State as the principal — or even exclusive — producer of legal norms. This conception has structured most contemporary legal systems, particularly in the continental-law traditions.
The AI Act departs significantly from this scheme. Rather than defining prohibited behaviours coupled with an ex-post liability regime, it organises a regulation based on the classification of risks. Artificial-intelligence systems are categorised according to their level of danger, and the legal obligations applicable to them vary according to this gradation. This structuring rests on a probabilistic logic: the law no longer merely reacts to established facts, it anticipates potential risks and organises their management upstream.
This shift is a major transformation of legal temporality. Where the law traditionally intervened after a harm or an infringement had occurred, it now tends to intervene before the risk even materialises. Normativity is built around uncertainty, probability and anticipation. From now on, the norm no longer primarily seeks to sanction an established violation, but to anticipate, classify and frame potential risks. This evolution is part of a broader dynamic of regulation by risk, already observable in fields such as financial, environmental or health law, but which here finds a particularly accomplished expression.
However, the transformation brought about by the AI Act is not limited to this temporal dimension. It is also accompanied by an institutional and functional shift that affects the very location of normativity. The regulation indeed rests on a complex architecture bringing together public authorities, certification bodies, standardisation structures and private actors. Within this framework, compliance is no longer verified solely after the fact by an administrative or judicial authority; it is internalised within organisations.
Economic operators are required to put in place risk-management systems, technical documentation, traceability and continuous monitoring. Compliance becomes a permanent organisational process, embedded in the very structures of the company. Compliance thus becomes a continuous process integrated into organisations rather than a mere one-off check. This evolution reflects the rise of the logic of compliance, understood not only as a set of obligations imposed on companies, but as a transformation of the way legal norms take root in organisational practices.
This phenomenon leads to a growing hybridisation between the public and private spheres. The effective production of normativity no longer rests exclusively on State institutions, but on a network of heterogeneous actors participating in the implementation and interpretation of norms. Companies become, to a certain extent, co-producers of normativity, insofar as they must themselves organise the conditions of their own compliance. This evolution challenges the classical distinction between public and private law, as well as the location of normative authority.
Beyond these temporal and institutional shifts, the AI Act also seems to bring about a deeper, conceptual transformation, touching on the very nature of legal obligation. In the traditional model, the obligation takes the form of a prescription or a prohibition bearing on a determined behaviour. Within the AI Act, the obligation often appears as an organisational requirement: putting in place a risk-management system, ensuring the traceability of data, documenting processes, guaranteeing post-market monitoring.
Legal constraint no longer lies solely in the prohibition of an act, but in the obligation to structure, over time, a compliant environment. Normativity becomes procedural, continuous and justificatory. It requires actors to demonstrate their compliance permanently, rather than merely avoiding the breach of a rule. Constraint no longer lies exclusively in the sanction, but in the structural obligation to organise and to demonstrate compliance. This shift profoundly modifies the way the law exercises its binding force.
All of these transformations — a temporal shift towards anticipation, institutional hybridisation and a transformation of the structure of obligation — converge towards the idea that the AI Act is much more than an instrument of sectoral regulation. It appears as the symptom of a mutation of the European regulatory paradigm. This mutation does not necessarily mean a complete break with earlier models, but it indicates a shift in the centre of gravity of the law.
In this new paradigm, normativity no longer rests primarily on the sanction of unlawful behaviour, but on the structuring of binding organisational environments oriented towards risk management. The law becomes a device for framing processes rather than a mere system of rules. It organises the conditions under which activities can be carried out, rather than merely judging their conformity after the fact.
This evolution raises fundamental questions for legal theory. How are we to think of normativity in a system where constraint no longer operates mainly through sanction? How are we to grasp responsibility when the law frames potential risks rather than accomplished facts? And how are we to situate normative authority in a context where the production of law is distributed among a plurality of public and private actors?
The AI Act thus offers a privileged vantage point from which to analyse the contemporary transformations of European regulatory law in the algorithmic age. In this sense, it is not only a response to artificial intelligence, but a marker of the broader mutations of the law in societies marked by technological uncertainty, systemic complexity and the hybridisation of forms of governance.
The stake is therefore not simply to assess the effectiveness or the legitimacy of this regulation, but to understand what it heralds. If the hypothesis of a paradigmatic mutation is confirmed, the AI Act may well be the point of entry into a lasting transformation of European law, in which risk management and organisational compliance become the new foundations of normativity.
Bibliography:
Commission européenne. (2021). Proposal for a Regulation laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) (COM(2021) 206 final). https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52021PC0206
European Data Protection Board & European Data Protection Supervisor. (2021). Joint Opinion 5/2021 on the proposal for a Regulation on Artificial Intelligence. https://www.edps.europa.eu/system/files/2021-06/2021-06-18-edpb-edps_joint_opinion_ai_regulation_en.pdf
European Parliament & Council of the European Union. (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). https://eur-lex.europa.eu/eli/reg/2024/1689/oj
European Data Protection Supervisor. (2023). Opinion 44/2023 on the Artificial Intelligence Act. https://www.edps.europa.eu/system/files/2023-10/2023-0137_d3269_opinion_en.pdf
European Parliamentary Research Service. (2021). Artificial intelligence act. https://www.europarl.europa.eu/RegData/etudes/BRIE/2021/698792/EPRS_BRI(2021)698792_EN.pdf
Council of the European Union. (2022). Proposal for a Regulation on artificial intelligence – General approach. https://data.consilium.europa.eu/doc/document/ST-14954-2022-INIT/en/pdf
European Commission. (2025). Standardisation request to CEN and CENELEC in support of Regulation (EU) 2024/1689. https://www.ibf-solutions.com/fileadmin/Dateidownloads/standardisation-request-ai-act-main-document-and-annexes.pdf
Joint Research Centre. (2023). Harmonised standards for the European AI Act. https://publications.jrc.ec.europa.eu/repository/handle/JRC139430
CEN-CENELEC. (2021). Position paper on the Artificial Intelligence Act. https://www.cencenelec.eu/media/CEN-CENELEC/AreasOfWork/Position%20Paper/2021/positionpaper_aia_2021.pdf
National Institute of Standards and Technology. (2023). AI risk management framework (AI RMF 1.0). https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf
National Institute of Standards and Technology. (2024). Generative AI profile. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf
Organisation for Economic Co-operation and Development. (2019). OECD recommendation on artificial intelligence. https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449
Organisation for Economic Co-operation and Development. (2020). What are the OECD principles on AI? https://www.oecd.org/digital/what-are-the-oecd-principles-on-ai.htm
Power, M. (1999). The risk management of everything. Demos. https://demos.co.uk/wp-content/uploads/files/riskmanagementofeverything.pdf
Luhmann, N. (1993). Risk: A sociological theory. (Excerpt available online). https://lchc.ucsd.edu/cogn_150/Readings/luhmann.pdf
Frydman, B., & Lewkowicz, G. (2011). Les codes de conduite: source du droit global? Centre Perelman Working Paper. https://www.centreperelman.be/content/uploads/2022/09/WP_-_Frydman_Lewkowicz_-_codes_de_conduite_-_source_du_droit_global.pdf
Frydman, B. (2017). Les défis du droit global. Larcier. https://www.larcier-intersentia.com/media/wysiwyg/extras/9782802753957/Introduction%20de%20DEDROGLO_20171128_BAT.pdf