Notes · updated 2026-07-19
Research Trends in AI Law and Governance: Regulation, Accountability, and AI Governance (2024–2026)
Between 2024 and 2026, the law governing AI moved from “principles” to “binding rules.”
The ethics declarations and soft law that nations had lined up in parallel are now being replaced by statutory text printed in official journals and by judgments handed down in court.
This note organizes the research trends of this transitional period from a corpus of 33 primary legal sources and peer-reviewed law articles (source/review/ai-law-governance-research-trends/papers.md).
Writing the text of a regulation, translating that text into accountability machinery, and having scholarship fill the gaps in liability and rights that the machinery cannot capture: these are three distinct tasks, and the research thickened in that order. The analysis specific to design practice under Article 50 is left to eu-ai-act-design-impact; here we address the general trends in law and governance.
Two legislative peaks rose: the EU’s staged application and the U.S. reversal
In 2024 the EU enacted Regulation (EU) 2024/1689 (the AI Act). It is the first comprehensive horizontal regulation in the world, sorting AI systems into prohibited, high-risk, limited-risk, and minimal-risk tiers and imposing conformity assessment and obligations on general-purpose AI models (GPAI) (L01). The text entered into force on 1 August 2024, but the obligations do not take effect all at once. The prohibitions apply from 2 February 2025, the GPAI obligations from 2 August 2025, and the core obligations for high-risk systems from 2 August 2026.
What bridged this staged application was the General-Purpose AI Code of Practice, finalized in July 2025. It is a voluntary tool for demonstrating compliance with Articles 53 and 55 of the AI Act, structured in three chapters: transparency, copyright, and safety and security (L02). The European Commission and the AI Board approved its adequacy on 1 August 2025. Gstrein and colleagues diagnose the arrival of GPAI regulation as marking a shift in AI governance from ex-post remedy to ex-ante control (L20). They caution, however, that three questions remain unresolved: enforceability, democratic legitimacy, and future-proofing against technology.
The United States traced the opposite arc. In October 2023 the Biden administration issued Executive Order 14110 (Safe, Secure, and Trustworthy AI), directing more than 100 actions across over 50 federal agencies (L03). Yet on 20 January 2025 this order was revoked by Executive Order 14148. The subsequent Executive Order 14179 (Removing Barriers to American Leadership in AI) ordered the withdrawal of all measures taken under 14110 and championed AI development free of ideological bias (L04). On the operational side for federal agencies, the 2025 OMB memorandum M-25-21 retained Chief AI Officers and pre-deployment testing and impact assessment for high-impact AI systems, while shifting the center of gravity from control toward accelerating use (L05). The EU piling rules up, the U.S. stripping rules away. The contrast between these two peaks is the starting point for the comparative regulation research that followed from 2024 onward.
A staircase of binding force: from standards to treaties
While regulation research tends to cluster around the EU–U.S. dichotomy, actual governance was built as a staircase of documents with differing binding force. Zaidan and Ibrahim name the state in which law cannot keep pace with AI’s advance regulatory inertia and discuss frameworks for international coordination (L21). Climbing this staircase from bottom to top reveals what the research has taken as its object.
The softest step consists of non-binding standards and principles. In July 2024 NIST published NIST AI 600-1 (Generative AI Profile), mapping 12 categories of risk that are specific to, or exacerbated by, generative AI onto the Govern, Map, Measure, and Manage functions (L06). In the same year, OECD revised the AI Principles it had first adopted intergovernmentally in 2019, updating them in response to the rise of generative AI (L07). This revised version forms the definitional foundation shared by the EU AI Act, the NIST framework, and the UNESCO recommendation.
One step up, intergovernmental agreement documents line up. In September 2024 the UN Secretary-General’s High-Level Advisory Body issued its final report Governing AI for Humanity, noting that 118 countries are excluded from major governance initiatives and presenting seven recommendations (L08). The International AI Safety Report (January 2025), with the UK government as secretariat and Yoshua Bengio as chair, is the first international scientific report on the capabilities, risks, and mitigations of general-purpose AI, produced by 96 experts from 30 countries (L10).
At the top step sits a legally binding treaty. The Council of Europe’s Framework Convention on AI (CETS No. 225) was opened for signature in September 2024, the first in the world to require, with binding force, that the entire AI lifecycle be aligned with human rights, democracy, and the rule of law (L09). From soft standards to binding treaties, research divides into domains according to which step of this staircase it analyzes.
Accountability moved from “explanation” to “audit”
Transparency research long centered on the “right to explanation.” But from 2024 onward, the center of gravity moves from explaining individual decisions to auditing systems as a whole. This shift accelerated once laws mandating audits actually came into effect and their operational data became available.
Gerchick and colleagues analyzed the 116 published bias audits that New York City’s Local Law 144 mandated for hiring AI tools (L14). They confront readers with a reality in which the definitions are ambiguous and only about 2% of the Fortune 500 published an audit; the paper earned an Honorable Mention at FAccT 2025. Even when an audit institution begins to operate, if the discretion to release an audit remains with the firm, accountability is hollowed out.
Skepticism about institutional efficacy also turns on the actors performing the audits. Terzis and colleagues analyze, through political economy, the process by which algorithmic audits are institutionalized as regulatory obligations under the Digital Services Act and the Online Safety Act, and point to the risk that the incumbent audit industry (the so-called Big Four) will occupy the new audit space (L13). Chappidi and colleagues name accountability capture the process by which the record-keeping practices meant to support transparency and accountability instead absorb systems into existing frameworks, and depict the tension between internal and external accountability from a survey of 100 practitioners (L15).
In the EU context, Söderlund analyzes the AI Act’s qualified transparency machinery (L12). This design, which grants access to oversight bodies rather than the general public, protects trade secrets while enabling supervision, but she points out that the goal of accountability toward the public leaves residual challenges. If accountability research has moved toward “audit,” the next question is on what basis such audits can verify decisions. Stewart addresses this question head-on, proposing procedural safeguards he calls evidentiary rights that verify decisions through counterfactual interrogation rather than relying on model disclosure (L16, 2026).
Who fills the gap in liability?
When AI behaves autonomously and harm arises through the hands of developers, deployers, and users, who bears responsibility? This question leapt to the center of scholarship precisely because the EU’s AI Liability Directive (AILD) stalled. Noto La Diega and Bezerra criticize the AILD’s scope as confined to disclosure rules and causal presumptions, arguing that securing the safety of generative AI requires a comprehensive ex-post tort liability regime that includes strict liability (L17).
Two contrasting prescriptions stand side by side over where responsibility lies. Herbosch argues that harm caused by autonomous AI agents can be handled by existing tort law through the adaptive revision of precedents in product liability and medical malpractice, and that no new liability regime specific to AI is needed (L18). Custers and colleagues, by contrast, take as their starting point the many hands problem, in which the involvement of multiple actors obscures the locus of responsibility, and seek to resolve the liability gap through a combination of liability overlap and fiduciary duty (L19). Whether adapting existing law suffices, or a new allocation principle is required: on this single point, AI liability research since 2024 is split.
Copyright: reports and rulings moved at once
Copyright over training data is one of the few areas in which policy documents and litigation moved simultaneously during this period. The U.S. Copyright Office issued its serial report “Copyright and Artificial Intelligence,” examining the copyrightability of AI-generated works in Part 2 (January 2025) and the application of copyright law to generative AI training in the pre-publication Part 3 (May 2025) (L23, L24). Part 2 reaffirms the position that AI-generated works lacking substantial human selection or arrangement fall outside protection. Part 3 presents the four-factor fair use analysis, a comparison of text-and-data-mining exceptions, and an outlook on licensing markets.
The rulings piled up faster than the reports could organize them. In February 2025, in Thomson Reuters v. Ross Intelligence, a federal district court for the first time rejected a fair use defense for using copyrighted material for AI training (L25). In June, in Bartz v. Anthropic, Judge Alsup found the reproduction of books for training “spectacularly transformative” and thus fair use, while carving out reproductions derived from pirated shadow libraries as infringement (L26). Days later, in Kadrey v. Meta, Judge Chhabria likewise found fair use for Llama’s training, but stated explicitly that the plaintiffs could have prevailed had the “market dilution” argument been properly presented, emphasizing that this was not a universal endorsement (L27). Training may be fair use, but its grounds and the room for rebuttal vary from case to case.
The memorization problem symbolizes how scholarship grasps this variation. Cooper and Grimmelmann define memorization as a state in which a substantial portion of the training data can be approximately reproduced, bridging the technical concept in machine learning with the judgments of copyright law (L30). Ginsburg, responding to the Copyright Office’s Part 3, organizes a case-law landscape in which the fair use status of feeding training data remains unsettled (L31). From a comparative-law perspective, Wu contrasts industry-oriented U.S. law with rights-oriented EU law and sketches a scheme for creating a right to fair remuneration for training under UN international governance (L32).
Developments in Europe illuminate an axis distinct from the U.S. In November 2025 the Munich Regional Court held in GEMA v. OpenAI that the text-and-data-mining exception of the EU DSM Directive (Article 4) does not apply to AI training that gives rise to memorization (L29). Since song lyrics were reproduced through simple prompts, the court reasoned, this amounts to copyright infringement. In March 2026 the UK government withdrew an opt-out TDM exception from its preferred policy and reported a “wait and see” stance choosing the status quo and industry-led licensing-market development (L33). To the single question of the legality of training, the U.S. answers with the four fair use factors, the EU with the scope of the TDM exception, and the UK with a policy of waiting.
Unverified items
- The Council of Europe Framework Convention (CETS No. 225, L09): the treaty PDF returned 403 and the body text was not retrieved. Only the signature date and CETS number confirmed.
[primary verification needed] - The Colorado AI Act (SB24-205, L11): amendment pending via SB26-189 (May 2026), with the effective date postponed.
[latest version to be confirmed] - Maclure & Morin-Martel (L22): the issue number of Digital Society.
[primary verification needed] - Thomson Reuters v. Ross (L25) / Bartz v. Anthropic (L26) / GEMA v. OpenAI (L29): the primary judgment text was binary or non-public; holdings were cross-checked against multiple law-firm analyses.
[primary verification needed] - The pending New York Times v. OpenAI (L28) and Getty Images v. Stability AI have not reached judgment. Fair use precedents may change on appeal.
References
33 items in total: primary legal sources (regulations, executive orders, standards, reports, rulings) and peer-reviewed law articles. URLs confirmed reachable via WebFetch. The internal working ledger is source/review/ai-law-governance-research-trends/papers.md. For related economic trends see ai-economics-research-trends; for social-science trends see ai-social-science-research-trends.
A. Primary legal sources and policy documents on AI regulation
- L01 European Parliament & Council of the EU (2024). Regulation (EU) 2024/1689 (Artificial Intelligence Act). Official Journal of the EU / EUR-Lex. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
- L02 European Commission AI Office (2025). General-Purpose AI Code of Practice (Final Version). European Commission. https://digital-strategy.ec.europa.eu/en/news/general-purpose-ai-code-practice-now-available
- L03 The White House (2023). Executive Order 14110: Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence. Federal Register. https://www.govinfo.gov/app/details/CFR-2024-title3-vol1/CFR-2024-title3-vol1-eo14110/summary
- L04 The White House (2025). Executive Order 14179: Removing Barriers to American Leadership in Artificial Intelligence. Federal Register. https://www.govinfo.gov/app/details/DCPD-202500170
- L05 U.S. Office of Management and Budget (2025). OMB Memorandum M-25-21: Accelerating Federal Use of AI through Innovation, Governance, and Public Trust. https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-21-Accelerating-Federal-Use-of-AI-through-Innovation-Governance-and-Public-Trust.pdf
- L06 National Institute of Standards and Technology (2024). NIST AI 600-1: Artificial Intelligence Risk Management Framework — Generative AI Profile. https://doi.org/10.6028/NIST.AI.600-1
- L07 OECD (2024). Recommendation of the Council on Artificial Intelligence (updated). C/MIN(2024)16/FINAL. https://oecd.ai/en/ai-principles
- L08 UN Secretary-General’s High-Level Advisory Body on AI (2024). Governing AI for Humanity — Final Report. United Nations. https://www.un.org/en/ai-advisory-body
- L09 Council of Europe (2024). Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225). https://www.coe.int/en/web/portal/-/council-of-europe-opens-first-ever-global-treaty-on-ai-for-signature
- L10 International AI Safety Report (2025). International Scientific Report on the Safety of Advanced AI (chaired by Y. Bengio). https://internationalaisafetyreport.org/publication/international-ai-safety-report-2025
- L11 Colorado General Assembly (2024). SB24-205: Consumer Protections for Artificial Intelligence (Colorado AI Act). https://leg.colorado.gov/bills/sb24-205
B. Accountability, auditing, and transparency / liability / governance / ethics institutionalization
- L12 Söderlund, K. (2025). High-risk AI transparency? On qualified transparency mandates for oversight bodies under the EU AI Act. Technology and Regulation 2025, 97–113. https://doi.org/10.71265/6bedar76
- L13 Terzis, P., Veale, M., & Gaumann, N. (2024). Law and the Emerging Political Economy of Algorithmic Audits. FAccT ‘24. https://doi.org/10.1145/3630106.3658970
- L14 Gerchick, M.K., Encarnación, R., Tanigawa-Lau, C., Armstrong, L., Gutiérrez, A., & Metaxa, D. (2025). Auditing the Audits: Lessons for Algorithmic Accountability from Local Law 144’s Bias Audits. FAccT ‘25. https://doi.org/10.1145/3715275.3732004
- L15 Chappidi, S., Cobbe, J., Norval, C., Mazumder, A., & Singh, J. (2025). Accountability Capture: How Record-Keeping to Support AI Transparency and Accountability (Re)shapes Algorithmic Oversight. AIES 2025. https://arxiv.org/abs/2510.04609
- L16 Stewart, M. (2026). Beyond Explanation: Evidentiary Rights for Algorithmic Accountability. FAccT ‘26. https://arxiv.org/abs/2603.22716
- L17 Noto La Diega, G., & Bezerra, L.C.T. (2024). Can there be responsible AI without AI liability? International Journal of Law and Information Technology 32(1). https://doi.org/10.1093/ijlit/eaae021
- L18 Herbosch, M. (2025). Liability for AI Agents. North Carolina Journal of Law & Technology 26(3), 391–458. https://journals.law.unc.edu/ncjolt/articles/liability-for-ai-agents/
- L19 Custers, B., Lahmann, H., & Scott, B.I. (2025). From liability gaps to liability overlaps: shared responsibilities and fiduciary duties in AI and other complex technologies. AI and Society 40(5), 4035–4050. https://doi.org/10.1007/s00146-024-02137-1
- L20 Gstrein, O.J., Haleem, N., & Zwitter, A. (2024). General-purpose AI regulation and the European Union AI Act. Internet Policy Review 13(3). https://doi.org/10.14763/2024.3.1790
- L21 Zaidan, E., & Ibrahim, I.A. (2024). AI Governance in a Complex and Rapidly Changing Regulatory Landscape: A Global Perspective. Humanities and Social Sciences Communications 11(1), 1121. https://doi.org/10.1057/s41599-024-03560-x
- L22 Maclure, J., & Morin-Martel, A. (2025). AI Ethics’ Institutional Turn. Digital Society 4. https://doi.org/10.1007/s44206-025-00174-x
C. Copyright/IP and LLM training (scholarship, primary sources, rulings)
- L23 U.S. Copyright Office (2025). Copyright and Artificial Intelligence — Part 2: Copyrightability. https://www.copyright.gov/ai/Copyright-and-Artificial-Intelligence-Part-2-Copyrightability-Report.pdf
- L24 U.S. Copyright Office (2025). Copyright and Artificial Intelligence — Part 3: Generative AI Training (Pre-publication Version). https://www.copyright.gov/ai/Copyright-and-Artificial-Intelligence-Part-3-Generative-AI-Training-Report-Pre-Publication-Version.pdf
- L25 Thomson Reuters Enterprise Centre GmbH v. Ross Intelligence Inc., No. 1:20-cv-613-SB (D. Del. Feb. 11, 2025). https://www.courtlistener.com/docket/17131648/thomson-reuters-enterprise-centre-gmbh-v-ross-intelligence-inc/
- L26 Bartz et al. v. Anthropic PBC, No. 3:24-cv-05417 (N.D. Cal. June 23, 2025). https://www.afslaw.com/perspectives/alerts/landmark-ruling-ai-copyright-fair-use-vs-infringement-bartz-v-anthropic
- L27 Kadrey v. Meta Platforms, Inc., No. 23-cv-03417-VC (N.D. Cal. June 25, 2025). https://caselaw.findlaw.com/court/us-dis-crt-n-d-cal/117422847.html
- L28 The New York Times Company v. Microsoft Corp. et al., No. 1:23-cv-11195 (S.D.N.Y., filed Dec. 27, 2023, pending). https://ailawsuittracker.com/cases/new-york-times-v-openai/
- L29 GEMA v. OpenAI, Inc., Case No. 42 O 14139/24 (Landgericht München I, Nov. 11, 2025). https://www.twobirds.com/en/insights/2025/landmark-ruling-of-the-munich-regional-court-(gema-v-openai)-on-copyright-and-ai-training
- L30 Cooper, A.F., & Grimmelmann, J. (2025). The Files Are in the Computer: On Copyright, Memorization, and Generative AI. Chicago-Kent Law Review 100(1), 141–. https://scholarship.kentlaw.iit.edu/cklawreview/vol100/iss1/9/
- L31 Ginsburg, J.C. (2025). AI Inputs, Fair Use and the U.S. Copyright Office Report. Journal of Intellectual Property Law & Practice 20(8), 521–522. https://doi.org/10.1093/jiplp/jpaf046
- L32 Wu, H. (2024). Copyright Protection During the Training Stage of Generative AI. Computer Law & Security Review 55, 106056. https://doi.org/10.1016/j.clsr.2024.106056
- L33 UK Government (DSIT/DCMS/IPO) (2026). Report on Copyright and Artificial Intelligence. https://www.gov.uk/government/publications/report-and-impact-assessment-on-copyright-and-artificial-intelligence/report-on-copyright-and-artificial-intelligence