RegTech4AI sees a gap between AI legislation and practice: “Enact the technology into law”

Published on: August 25, 2026

To ensure ethics, sovereignty, and the responsible use of data and AI, a great deal of European legislation has been developed in recent years. Examples include the GDPR, the Digital Services Act, and the AI Act. While much has been put on paper, how do these laws work in practice? Do they achieve their intended goals? Computer scientist Konrad Kollnigis conducting research on this topic.  


With the support of anAiNed Fellowship Grant, he launched the RegTech4AI research group at Maastricht University. We spoke with Kollnig, an associate professor at Maastricht University and project leader of RegTech4AI, about his research. 

Gorge

Kollnig discovered the existence of this gap in earlier research. For his doctoral dissertation at Oxford, he analyzed millions of mobile apps. It turned out that at least 70 percent were already sharing data with Google and other companies as soon as the user opened the app—even before anything had been clicked. “Fewer than 10 percent gave users any choice in the matter. This didn’t comply with the law, and asking for consent to share data is really the bare minimum. If even the very lowest bar set by the law is met only sporadically, what does that say about the legislation in this area? I was really curious about that.” 

RegTech4AI isa research initiative funded by theNational Growth Fundas part of the Fellowship Grant program. It makes EU regulations for AI work in practice, using regulatory technology.

The initiative develops technical methods to implement the GDPR and the AI Act, thereby bridging the gap between legal requirements and everyday practice. The project will run for five years and funds six full-time researchers.  

To learn more about this, the research group focuses primarily onlegal AI auditing. Thisinvolves systematically evaluating an AI system against what the law actually requires, based on measurable evidence of what the system does in practice. 

Missing the Mark 

The AI Act was primarily drafted for high-risk applications, such as the use of AI in job applications or in healthcare. However, the regulation also requires that AI-generated images be identifiable. Thattransparency requirementtook effect on August 2, 2026, with a transition period until December 2, 2026, for systems that were already on the market. The idea is that people should be able to tell that they are viewing synthetic content. 

To assess how far the market has come in this regard, Kollnig’s group conducted a legal AI audit. The team evaluated fifty AI image generators against that criterion. The results, published in the paper "Missing the Mark", are not very encouraging. Only 38 percent applied a machine-readable watermark, and only nine of the fifty systems displayed a visible label.  

Chinese and English 

So there is a discrepancy between what the legislature intends and what happens in practice. But why exactly is that? To explain this, Kollnig uses a metaphor. “When it comes to legislation in the tech world, it’s as if one side—the legislature—speaks Chinese and the other side—the applications—speaks English, and then we’re surprised that we can’t understand each other. And we just keep doing the same thing over and over.” 

Kollnig does have some ideas on how to break this deadlock. “Enact the technology into law. That means the law should better explain how something should work technically, rather than just determining what the desired outcome is. Specify more precisely what the computer code will look like,” says Kollnig. 

One example of this is a technical standard from California:Global Privacy Control. The idea is that a user specifies once in the browser that they do not want their data shared, after which websites must automatically respect that preference.That could spell the end of the cookie banner. 

It works well because the standard precisely defines how data is exchanged between the browser and the website. The team had already investigated in a legal analysis whether such a signal could also fall under European law. Recently, the team organized a workshop in Brussels with industry representatives, civil society organizations, academics, and the European Commission. The goal was to explore whether such a signal could also work in Europe. Whether that will succeed is uncertain.

RegTech4AI sees a gap between AI legislation and practice: "Enact the technology into law" AIC4NL | AI for the Netherlands
Konrad Kollnig, associate professor
at Maastricht University and project leader
of RegTech4A

Social Media and AI 

Meanwhile, the research continues. Regarding RegTech4AI’s plans for the near future, Kollnig says: “Legal AI auditing will remain our main focus in the coming years. In addition, we’re assessing how social media platforms handle AI. We’re going to investigate whether it’s made sufficiently clear what was created by AI and what wasn’t. The AI Act stipulates that it must be clear for all content whether it is AI-generated or not. In theory, even AI-generated text must be labeled, but for now, no one is doing that yet.”

In addition, the team will conduct research on a challenging standard. The EU Digital Services Act requires very large platforms such as TikTok and Instagram to identify and mitigate “systemic risks” to society. Research into this concept revealed that itis primarily known from the financial sector and that there is no case law on the subject for platforms yet. “Too little is known about this. What exactly are systemic risks? And who determines that? We’re going to dive deep into that,” Kollnig concludes.

Related posts

Share via:

Instrument

Want to contribute to the development of AI in the Netherlands?

Join AIC4NL

Do you have a question or want to get in touch?

Ask your question at info@aic4nl.nl

Follow us on LinkedIn and stay up-to-date with the latest news about AIC4NL

Join AIC4NL

Are you interested in contributing to AI innovation and becoming part of the largest AI community in the Netherlands?

2 persons AI NED