Why does AI regulation keep swinging? The core tension between protection and progress
The fundamental reason AI regulation swings is that it tries to do two things at once: protect people from harm and avoid slowing down innovation. These goals pull in opposite directions. The EU AI Act, the first comprehensive AI law in a major jurisdiction, tries to navigate this by using a risk-based framework—meaning the level of regulation depends on how risky an AI system is judged to be [1]. But this creates a built-in tension: if you set the bar too high, you block useful technology; if you set it too low, you expose people to harm. One study analyzing the EU AI Act's risk management provisions notes that the law requires providers of high-risk systems to follow detailed risk management steps, but enforcing those steps is itself a challenge [7]. The swing happens because regulators are constantly recalibrating where that bar sits, and different stakeholders—companies, civil rights groups, governments—pull it in different directions.
The swing is not random; it reflects a real, unresolved debate about how much risk is acceptable. A 2021 study argues that a strict liability regime (where companies are fully responsible for harms) by itself creates a 'chilling effect' on AI innovation, especially for small and medium-sized enterprises that cannot afford the legal risk [3]. To counter that, the authors propose a 'sandbox' approach—a regulatory safe space where AI products can be tested under safeguards before full deployment [3]. This is a concrete example of the pendulum: strict rules protect people but slow innovation, so regulators introduce flexibility (sandboxes) to speed things up, which then raises new concerns about insufficient protection, and the cycle continues.
The swing looks different depending on the sector: finance, labor, and civil rights
The tension between innovation and risk is not uniform—it plays out very differently depending on where AI is used. In financial services, for example, a 2025 study notes that the EU AI Act's provisions aim to foster 'responsible AI use' while safeguarding consumer data privacy, but it also highlights that US state laws on AI are inconsistent, creating a patchwork that makes compliance difficult for companies [4]. This inconsistency means the regulatory swing is amplified by jurisdictional differences: what is allowed in one state may be banned in another, forcing companies to either slow down or take risks. A separate 2023 study proposes a framework of Key AI Risk Indicators (KAIRI) specifically for finance, measuring things like accuracy, fairness, and explainability, to help institutions manage AI risks without waiting for regulators to act [6]. That study applies its framework to case studies identified as highly relevant by European financial institutions, showing that the industry itself is trying to self-regulate to avoid a heavy-handed swing from regulators [6].
In the workplace, the stakes are even higher and the swing more pronounced. A 2023 comparative study of EU and North American regulations found that the widely adopted 'risk-based approach' is not well-suited for enforcing fundamental labor rights like privacy, human dignity, and equality [5]. The authors argue that a scalable, decentralized framework—which is what most current regulations use—is 'not appropriate' for protecting workers, because it allows companies to interpret risks in ways that favor efficiency over rights [5]. This means that in labor contexts, the regulatory pendulum can swing toward innovation (allowing algorithmic management of workers) until a scandal or abuse forces a swing back toward protection. The same study warns that the 'frenzied race to regulate' could actually increase legal uncertainty and allow companies to shop for the weakest regulations (regulatory arbitrage), which would both slow innovation and undermine labor rights [5].
Civil rights and data protection add another layer. A 2026 study comparing the Cambridge Analytica scandal (which revealed structural limits in privacy protection) with algorithmic censorship in India (where AI was used for state surveillance) shows that the same technology can be regulated very differently depending on political context [2]. The EU treats privacy as a fundamental right and has created a 'pioneering global regulatory benchmark' with the GDPR and AI Act, while other jurisdictions use AI to control information under the guise of national security [2]. This means the swing between innovation and risk is not just about speed versus safety—it is also about whose rights are being protected and whose are being sacrificed. The study argues that only 'egalitarian, comprehensive and adaptable legal systems' can ensure AI development aligns with democratic principles [2].
About These Sources
This answer is built on 8 peer-reviewed studies — published from 2021 to 2026, 3 from 2024 or later, 5 in Q1 journals, collectively cited 328 times — selected as the most relevant from 8 studies that passed quality screening, drawn from 42 papers retrieved from a database of over 500 million.
Sources used in this answer
The science and practice of proportionality in AI risk evaluations
The EU AI Act requires providers of advanced general-purpose AI models to evaluate systemic risks, but applying the principle of proportionality—calibrating regulation to actual risk—requires new scientific methods that are still being developed.
The challenges of AI regulation: data protection, civil rights, and landmark cases
Comparing the Cambridge Analytica scandal and algorithmic censorship in India shows that the same AI technology can be regulated very differently depending on political context, with the EU treating privacy as a fundamental right while other jurisdictions use AI for state surveillance.
A Sandbox Approach to Regulating High-Risk Artificial Intelligence Applications
Strict liability alone creates a chilling effect on AI innovation, especially for small and medium-sized enterprises, so a sandbox approach—a regulatory safe space with safeguards—is proposed as a complement to balance protection and progress.
Bridging the gap: Policymakers, innovation and privacy in financial services AI
In financial services, the EU AI Act aims to foster responsible AI use while protecting consumer data privacy, but US state laws are inconsistent, creating a patchwork that complicates compliance and amplifies the regulatory swing.
Between risk mitigation and labour rights enforcement: Assessing the transatlantic race to govern AI-driven decision-making through a comparative lens
The risk-based approach common in EU and North American AI regulations is not well-suited for enforcing fundamental labor rights like privacy and equality; a decentralized framework can lead to regulatory arbitrage that both slows innovation and undermines worker protections.
Artificial Intelligence risk measurement
A proposed Key AI Risk Indicators (KAIRI) framework for finance measures AI trustworthiness through four principles (Sustainability, Accuracy, Fairness, Explainability) and was tested on case studies identified as highly relevant by European financial institutions.
Risk Management in the Artificial Intelligence Act
The EU AI Act's key risk management provision (Article 9) requires providers of high-risk systems to follow detailed risk management steps, but enforcement of these requirements remains a challenge.
Artificial Intelligence Risks and Algorithmic Regulation
Algorithmic regulation could benefit from a 'prudential test' to determine whether automated decision-making systems are suitable for legal decision-making, but this is still an evolving concept.
