Matthew Sag

The Illusory Normativity of Rights-Based AI Regulation

Citation: Yiyang Mei and Matthew Sag, The Illusory Normativity of Rights-Based AI Regulation, 21(2) Indian Journal of Law and Technology (2025)

In a nutshell:

In The Illusory Normativity of Rights-Based AI Regulation, Yiyang Mei and Matthew Sag argue that the rights language pervading EU AI regulation functions as a tool of administrative ordering and risk containment rather than a principled commitment to fundamental rights, and that the EU model is a historically contingent arrangement with no claim to universal application.

Summary

The Illusory Normativity of Rights-Based AI Regulation takes aim at the assumption, most prominently associated with Anu Bradford’s Digital Empires, that the European Union’s regulatory framework for AI, anchored in the GDPR, the Digital Services and Markets Acts, and the AI Act, reflects a principled rights-based model that other nations should emulate. We do not deny that rights like the right to explanation or the right to contest automated decisions are legally real. Our claim is about how they function: in practice, these provisions operate less as constitutional guarantees than as administrative protocols for managing technological disruption and preserving systemic balance within a fragmented political order.

The argument proceeds through comparative institutional analysis. The article traces the European legal order’s orientation toward equilibrium from the Peace of Westphalia through the Maastricht Treaty and the Stability and Growth Pact, showing how rights emerged in European history as tactical mechanisms for restoring order in divided societies. Against that background, we compare EU and U.S. regulation in five domains: data privacy, cybersecurity, healthcare, labor and employment, and disinformation. In each, EU regulation prioritizes centralized risk mitigation and administrative control, while the American approach reflects decentralized authority, sectoral pluralism, and a constitutional preference for innovation and individual autonomy. The disinformation case study reverses the standard narrative: in the United States, a rights-centric framework built on the First Amendment sharply limits content regulation, while EU policymakers impose systematic controls on digital falsehoods.

The article does not endorse the American model; both systems are contingent and both carry trade-offs. The conclusion draws out the implications: the EU model should not serve as a default global template for AI governance, and debates over AI regulation should focus on the details of institutional design rather than competing values in the abstract. Rights without political foundation, we conclude, are merely aspirations.

Why read this article?

The Illusory Normativity of Rights-Based AI Regulation offers a compact comparative survey of EU and U.S. law bearing on AI across five regulatory domains. On the EU side, it works through the GDPR’s enforcement apparatus of data protection authorities, impact assessments, and substantial fines, along with the DSA, DMA, and AI Act. On the U.S. side, it covers the sectoral patchwork of privacy statutes such as HIPAA and COPPA, Section 230, and state-level deepfake and right of publicity laws, including Tennessee’s ELVIS Act.

The article also provides useful intellectual history. It reconstructs the rights-ethics-design framing that dominates contemporary AI governance scholarship, from Bradford’s Brussels Effect account through the EU High Level Expert Group’s Ethics Guidelines for Trustworthy AI, and situates the EU’s regulatory style in a longer European tradition of balance-of-power thinking. Readers will also find a summary of the empirical literature on the GDPR’s costs to website traffic, app development, and algorithmic bias auditing.

Further Reading

Anu Bradford, Digital Empires: The Global Battle to Regulate Technology (Oxford University Press, 2023) – The principal target of the article’s critique, this book presents the EU’s rights-driven regulatory model as one of three competing visions for governing the digital economy, alongside the American market-driven and Chinese state-driven models.

Paul M. Schwartz, Global Data Privacy: The EU Way, 94 N.Y.U. L. Rev. 771 (2019) – This article explains how EU data protection law spread globally through adequacy decisions, bilateral agreements, and other institutional pathways, offering an account of EU influence that goes beyond unilateral market power.

Woodrow Hartzog & Neil M. Richards, Privacy’s Constitutional Moment and the Limits of Data Protection, 61 B.C. L. Rev. 1687 (2020) – Hartzog and Richards argue that the United States is at a constitutional moment for privacy and warn against importing a watered-down version of the European data protection model.

Margot E. Kaminski, Regulating the Risks of AI, 103 B.U. L. Rev. 1347 (2023) – This article documents the convergence of lawmakers on both sides of the Atlantic on risk regulation as the dominant tool of AI governance, and analyzes what is gained and lost when AI harms are framed as risks to be managed.