The legal framing of high-risk AI: comparative lessons for supranational governance from the EU, South Korea and Colorado
Although substantially different in terms of law-making approach, scope, structure and content, the three AI-related legal acts – EU Regulation 2024/1689 laying down harmonised rules on artificial intelligence (EU AI Act), the South Korean Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust (South Korean Framework AI Act) and Colorado’s Senate Bill concerning consumer protections in interactions with artificial intelligence systems (Colorado SB24-205) – also share certain points of convergence. These three legislative instruments merit comparative analysis because they exemplify three distinct yet influential models for governing high-risk AI. The EU AI Act provides the first comprehensive, binding supranational framework, with a detailed risk-based architecture and substantial duties for providers and deployers. The South Korean Framework AI Act combines an orientation towards competitiveness, trust safeguards and protection of citizens’ rights. Finally, Colorado SB24-205 is a sub-federal, consumer-protection-focused legislation targeting high-risk AI and algorithmic discrimination in consequential decisions, making it an important test case for decentralised AI governance. This article has two overarching objectives. First, it conducts a comprehensive comparative legal analysis of the EU AI Act, South Korean Framework AI Act and Colorado SB24-205, focusing, on the one hand, on the notions of high-risk AI systems and high-impact AI and, on the other, on the principal responsibilities of their developers and operators. Second, it seeks to identify what lessons these three acts offer for the possible introduction of a concept of high-risk AI systems in a supranational regulatory framework. In conclusion, supranational, legally binding and universally accepted minimal common rules dedicated to high-risk AI systems should favour flexibility over precision, while the risk management policy applicable to them must include detailed rules on human oversight, ideally accompanied by the concept of consequential decision-making concerning not only their users but also any other natural person.
Authors
- Uroš Ćemalović (ORCID: https://orcid.org/0000-0002-0760-9703)
Institutions
- Institute for the International Education of Students (US)
Publication Details
- Journal
- The Theory and Practice of Legislation
- Published
- 2026-09-18
- DOI
- https://doi.org/10.1080/20508840.2026.2732684
- Primary Topic
- Ethics and Social Impacts of AI
- Type
- article
- Field-Weighted Citation Impact
- 0.00