Same Technology, Different World
How the absence of an AI classification framework leaves Americans without the protections Europeans take for granted
Facial recognition AI technology is becoming more common for United States federal law enforcement officials to utilize when conducting investigations and identifying suspects. While someone in the United States may think this new depth of surveillance is normal, the reality that exists just across the Atlantic is vastly different. The same technology is explicitly prohibited in the EU. How can such an impactful and potentially invasive utilization of AI be empowered in one jurisdiction but completely prohibited in another?
The difference is not in how each country defines AI, but how each classifies the technology.
Both the EU and the United States (via NIST) draw directly from the OECD baseline definition. This definition was made intentionally broad to empower governments and other regulatory bodies to build upon it. They chose to define AI systems as machine-based systems that generate outputs such as predictions, recommendations, or decisions that influence real or virtual environments.
The fragmentation begins a layer below definition, at classification.
The EU AI Act completely prohibits certain kinds of AI systems from being developed or deployed within EU countries, while no such granular classification lens exists within the United States Federal government. The lack of any classification methods in the United States is empowering the rapid pace of AI development and implementation, sidelining any meaningful guardrails intended to protect citizens, and instead allowing voluntary frameworks with no teeth to be the barrier protecting people from harmful outcomes.
Facial recognition AI is explicitly prohibited due to the classification systems enforced in the EU. The EU AI Act introduces four tiers of classification: Unacceptable Risk, High Risk, Limited Risk, and Minimal Risk. Facial recognition AI falls within the Unacceptable Risk category, is considered a fundamental risk to rights and safety, and is therefore banned. Real-time remote biometric identification systems used by law enforcement in publicly accessible spaces are banned outright, with very few exceptions. These exceptions include searching for missing children, preventing imminent terror threats, and locating suspects of serious crimes; however, those exceptions require prior independent judicial authorization on a case-by-case basis.
The United States has no classification methods for AI systems. Without this, there is no mechanism to distinguish between high-stakes AI systems like facial recognition and low-stakes systems in order to attach appropriate obligations or restrictions to each. When technologies like facial recognition are implemented in the same unregulated manner as benign systems like spellcheckers, this poses a high risk of exacerbating systemic biases such as those present in the application of law enforcement.
Many organizations in the United States are implementing AI systems to automate the recruitment of employees. This, however, is not the case in the EU, where these systems are classified as high-risk and subject to specific mandatory obligations. Providers must build in human oversight, meaning a human must be able to monitor, override, or shut down the system entirely. Providers must also maintain transparency documentation that is comprehensive, kept up to date, and readily available to regulators. High-risk systems must be registered in an EU public database before deployment, creating a public record of what high-risk systems are operating and who is responsible for them.
A job applicant in the EU has legally guaranteed protections against automated job recruitment systems that those in the United States do not. A rejected job application means lost income, lost benefits, and lost career progression impacting long-term quality of life. When consequential decisions about people’s lives, who gets hired, who gets flagged by law enforcement, are made without human oversight, documentation, or accountability structures, humans have effectively given up control over decisions that shape their lives to systems that answer to no one when harmful outcomes occur.
Ordinary people are navigating a world increasingly shaped by AI decisions and are largely unaware of the systems influencing their lives and the motivations and reasoning used to make these decisions. The EU AI Act demonstrates that comprehensive classification frameworks that prioritize human rights are not merely pipe dreams. The demand for rights-respecting regulatory frameworks is real and the EU is taking a leadership role in developing these guidelines for the Western world. On the opposite end of the spectrum, without a federal classification framework, the rapid pace of AI development and implementation in the United States will continue to outrun the guardrails and ordinary people will bear the consequences before regulators treat these risks with the urgency they deserve.
The reason the same consequential AI systems can be empowered in one jurisdiction and prohibited in another is that one jurisdiction built a classification framework that makes that determination systematically, and the other does not. The differences that separate the US and EU approaches are not value-based, they are rooted in the structural approaches taken to address risks posed to people and what each jurisdiction sees as priority: innovation in AI technology or the wellbeing of the people that will be affected.
