Published on 16 Jun 2026

The AI Rulebook Is Being Written; And Nobody Has All the Answers Yet

Why It Matters 

As artificial intelligence moves into healthcare, finance, transport and public services, governments are racing to regulate systems they do not fully understand. The stakes are high: weak oversight could expose people to harm, while inappropriate regulation could slow innovation. 

Key Takeaways 

  • AI systems are difficult to regulate because even developers may not fully understand how their own complex models function, which can also indicate abdication of duties.  
  • Most governments are still relying on voluntary ethics frameworks rather than binding laws.  
  • Data quality, not just algorithms, may become the biggest  challenge for companies deploying AI.  

 

AI’s Biggest Problem May Not Be the Algorithm 

Public debate around AI often centres on powerful algorithms, but the bigger issue is the data behind them. 

Unlike traditional software, AI systems are trained using vast datasets rather than fixed instructions. This makes them near impossible to audit, especially when developers themselves may not fully understand how decisions are made. 

The chapter analyses how flawed or biased training data can lead AI systems to produce harmful outcomes at scale, from unsafe self-driving systems to discriminatory decisions in hiring or lending. Poorly labelled or narrow datasets can undermine reliability, fairness and safety. 

For regulators, verifying whether AI developers used sufficient or high-quality data may prove extremely difficult. 

Governments Are Moving Fast — But Mostly With Guidelines, Not Laws 

Most governments are still relying on voluntary AI ethics guidelines rather than binding laws. Australia, the United States, the European Union and the Organisation for Economic Co-operation and Development have all introduced frameworks focused on fairness, transparency, accountability and safety. 

But the chapter argues these principles often remain vague in practice, creating uncertainty for businesses. 

The European Union has taken the strongest regulatory stance so far, proposing a risk-based framework with stricter rules for high-risk AI systems such as those used in healthcare or policing. Meanwhile, countries such as Canada are introducing practical compliance measures, including mandatory impact assessments and bias testing for automated systems. 

 Data Protection Could Become the Front Line of AI Regulation 

As AI systems rely heavily on data, data protection laws are becoming a key tool for regulating AI. 

In the United Kingdom, the Information Commissioner's Office has issued guidance requiring organisations to assess risks, test for bias and ensure human oversight when deploying AI systems. Responsibility for compliance now extends beyond technical teams to senior management. 

The chapter also analyses unresolved questions around liability and intellectual property, including who is responsible when AI systems cause harm, and who owns AI-generated content. While Europe has proposed new liability frameworks, global rules remain unsettled. 

Business Implications 

Companies adopting or deploying AI will soon face legal oversight similar to those already seen in heavily regulated industries such as banking, healthcare and transport. 

The research urges businesses to focus on AI governance within their organisation as an urgent business and legal liability strategy, and should get their house in order. This includes documenting datasets, fine-tuning use-cases, testing for bias, and ensuring senior leadership oversight, including at board level. 

The message for business leaders is increasingly clear: claimants, courts and regulators will not accept “the algorithm made the decision” as a defence. 

Firms that can demonstrate trustworthy AI practices early will have a competitive advantage as security and other threats will be minimised, even as governments tighten oversight and public scrutiny intensifies. 

Authors and sources 

Authors: Hannah Yee-Fen Lim (Nanyang Technological University) 

Original chapter: Regulatory Compliance, published in Artificial Intelligence (Edward Elgar Publishing) 

 ---

For more research, click here to return to NBS Knowledge Lab.