Universiteit Leiden

nl en

Six myths about the EU AI Act debunked

The EU AI Act has been in force since August 2024, but much remains unclear for citizens, businesses and legal professionals. Anne Meuwese, Professor of Public Law & Governance of AI, addresses six common myths about this complex piece of legislation.

The European Union's AI Act is the world’s first law to establish specific rules for the development and use of artificial intelligence. Its aim is to ensure that AI is safe and respects citizens’ fundamental rights, while also leaving room for innovation. Not all provisions of the Act are in force yet. For example, the rules governing so-called high-risk AI systems have recently been postponed. These are specific AI applications that can have a significant impact on people’s health, safety, or fundamental rights.

The postponement was a stopgap measure by the European legislature, prompted by the fact that many Member States, including the Netherlands, are lagging behind in designating the authorities responsible for oversight. That alone has fuelled considerable confusion, but a number of myths and misconceptions about the Act have been circulating for some time too.

Myth 1: Without a supervisory authority, the Act is useless for citizens

‘There are already avenues available,’ says Meuwese, ‘even if you can’t yet file a complaint with the national supervisory authority.’ Citizens can take legal action in two ways. If a public authority makes a decision about you in which AI plays a role, you can ask a court to assess whether that decision is lawful, including whether it complies with the AI Act. If a company causes harm through the use of AI, you can bring a claim before the courts and seek compensation for damages.

‘Lawyers are already citing the AI Act,’ says Meuwese. ‘They’re just not yet doing so with much precision, which is why courts have so far made only limited use of it.’ The legislation recently played a role in a court ruling for the first time. In that case, the court held that Case Matcher, a search tool used by the Dutch Immigration and Naturalisation Service (IND), does not qualify as an AI system under the definition set out in the AI Act.

Myth 2: Without a supervisory authority, organisations can flout the rules without consequences

That, too, is more nuanced, says Meuwese. ‘The idea is that organisations themselves are responsible for ensuring their compliance with the rules. The prospect of substantial fines provides a strong incentive to do so, even in the absence of a supervisory authority. After all, the prohibition of certain AI applications is already in force. The same applies to the transparency requirements for chatbots, deepfakes and automatically generated news content, although the latter is subject to a transitional period. The rules for high-risk AI systems have been postponed until December 2027, but organisations are already preparing for them.’

Myth 3: The AI Act will prevent another childcare benefits scandal

During the childcare benefits scandal, the Dutch Tax Administration used an algorithm to assess parents’ risk profiles, precisely the type of system that is now subject to regulation under the AI Act. ‘When a government fails so profoundly, there are usually multiple causes,’ Meuwese explains. ‘That was certainly true in the childcare benefits scandal as well. A single law can never prevent something like that on its own. The more relevant question is whether the AI Act could have made a significant difference in that case.’

Meuwese says that this very question has inspired many students to write their thesis on the legislation. One of them is Bodine Kornman, who showed in her bachelor's thesis that the Act primarily helps to provide greater insight into how high-risk AI systems operate. However, as Kornman also demonstrated, greater insight does not necessarily mean that decisions are made more carefully. ‘For that, additional Dutch legislation is needed, and at present such rules are only partly in place,' says Kornman. 'There’s also a risk that increased regulation could actually make flawed decisions more readily accepted, because people may place greater trust in the system.’

Getty Images via Unsplash

Myth 4: The AI Act already prohibits the profiling of citizens

According to Meuwese, this is the most persistent myth. The AI Act does indeed prohibit both social scoring, whereby citizens are assigned a form of social score, and predictive policing, whereby authorities attempt to predict who is likely to commit a crime. However, these prohibitions are far more narrowly defined than is often assumed. In the case of social scoring, for example, the prohibition would apply to situations where someone is denied a permit because they were caught travelling on a train without a valid ticket.

‘Most profiling algorithms will at most be classified as high-risk AI systems, and these will remain permissible after December 2027, provided they comply with the applicable requirements. Profiling may nevertheless be prohibited under other legislation, as was already the case before the AI Act. For example, if it results in discrimination or is used in violation of the GDPR’s prohibition on fully automated decision-making.’

Myth 5: Government authorities have to self-regulate. How can that be independent?

‘It can,’ says Meuwese, ‘because government authorities are not monolithic entities: regulators operate within a system of checks and balances in which different branches and bodies oversee one another. The AI Act requires national supervisory authorities to be independent, and the European Commission is responsible for ensuring compliance with that requirement.’

Moreover, many of the regulators likely to play a role in AI oversight, such as the Dutch Data Protection Authority, already supervise legislation that applies to government bodies themselves. One example is the General Data Protection Regulation (GDPR).

Myth 6: The AI Act is now ‘finished’

‘Legislation is never really “finished”,’ says Meuwese, ‘and that’s especially true of the AI Act.’ She gives agentic AI as an example. This refers to AI systems that can pursue goals autonomously and perform complex tasks without a human having to prescribe every step of the process. ‘The big question is how the AI Act will influence the development and use of AI. What I am particularly curious about is whether lawmakers and regulators will be able to keep pace with developments in agentic AI.’

Anne Meuwese and Francien Dechesne received an NWO grant (Open Competitie M) to study how professionals in the Netherlands are working with the new AI Act. The publication of a book that Meuwese has written on the topic of Generative AI in government authorities and the law is scheduled for early 2027.

This website uses cookies.  More information.