AI Regulation: ECRs’ Perspectives is a CREATe blog series featuring the work of early career researchers who are exploring the contemporary challenges of AI regulation. Based on research presented at the AI Regulation ECR Conference, each post provides a concise and accessible insight into emerging legal and policy debates around artificial intelligence.
The series continues with a guest post by Derya Sözen Esen. Derya is an external PhD candidate at Goethe University, where she focuses on the artificial intelligence auditing, compliance and regulations to figure out how we can regulate it without jeopardizing the development of the technology.
The Translation Layer: Why AI Regulation Needs More Than Just Good Intentions
Introduction: Navigating the Compliance Labyrinth
For years, the conversation surrounding Artificial Intelligence was dominated by “vague ethical principles”, lofty ideals that offered moral direction but lacked the technical teeth to drive organisational change. Today, that era is ending. We are in the midst of a high-stakes transition from aspirational guidelines to “binding legal obligations.” However, this shift has birthed a new crisis: the compliance labyrinth. Organisations, such as Information and Communication Technology (ICT) companies, are no longer just facing more rules; they are facing a fragmented regulatory regime of conflicting jurisdictions and heterogeneous standards. Navigating this landscape requires more than a legal team and a developer; it requires “meta-frameworks[1]” to act as the connective tissue between abstract law and technical reality.
Takeaway 1: From “High-Level Ethics” to “Hard Controls”
The landscape of AI governance underwent a tectonic shift in 2023. We have moved decisively beyond the stage of voluntary guidelines and into a world of enforceable mandates. With the emergence of the EU AI Act and formal management system standards like ISO/IEC 42001, “talking” about trust is no longer a viable risk management strategy. In this new era, transparency is being replaced by verifiability. Governance is no longer a matter of intent, but of hard controls that can be tested, measured, and validated. Since 2023, AI governance has shifted from high-level ethical principles toward legally enforceable obligations and formal management system standards.
Takeaway 2: Auditing Frameworks as “Translation Layers”
The most significant hurdle in AI compliance is the epistemic gap between a regulator’s intent and a developer’s code. To bridge this, we must view AI auditing meta-frameworks as “socio-technical translation layers.” Counter-intuitively, audits are not merely mathematical “checks” or binary exercises in box-ticking. According to Esen’s research, they are normative socio-technical instruments. They don’t just record compliance; they actually define what compliance looks like in a technical setting. By providing “epistemic legitimacy,” these frameworks grant organisations the authority to demonstrate that a system is safe and aligned across differing regulatory regimes.
Takeaway 3: The Danger of the “Checklist Exercise”
For C-suite executives and compliance officers, the “checklist” is a trap. There is a significant risk that consolidated auditing frameworks may appear arbitrary or become purely technocratic compliance tools if they are not properly grounded in regulatory theory. The research warns against “descriptive coding”; the practice of simply checking a box without understanding the underlying risk. Because AI risks are inherently context-dependent, effective auditing requires “expert-guided normative synthesis.” A framework cannot be a mindless script; it requires human expertise to interpret regulatory intent and translate it into the specific technical environment of the organisation. There is a risk of frameworks appearing “insufficiently grounded in regulatory theory” or “purely technocratic compliance tools”.
Takeaway 4: The Four Pillars of Auditable AI
To build a meta-framework capable of bridging heterogeneous regulatory regimes, the research identifies four essential design principles:
- Interoperability: The capacity to map a single technical control to multiple, often conflicting, laws; satisfying the EU AI Act, the NIST AI RMF, and ISO standards simultaneously.
- Evidentiary Auditability: Moving beyond simple assertions to a “structured control-derivation schema” where every compliance claim is backed by concrete, traceable evidence.
- Lifecycle Coverage: Ensuring governance isn’t a point-in-time event but an ongoing process spanning from initial development to deployment and eventual retirement.
- Proportionality to Risk: A mechanism to scale compliance efforts based on the system’s impact, especially critical in a fragmented landscape where risk definitions vary by jurisdiction.
Takeaway 5: Meta-Frameworks as Diplomatic Interpreters
It is a common misconception to view these meta-frameworks as “universal regulatory standards” themselves. They are not intended to replace existing laws or rewrite the rules of the road. Instead, think of a meta-framework as an interpreter at a diplomatic summit. It doesn’t write the treaties (the laws), but the way it translates the message determines if the parties (the technical systems) can actually work together. By operationalising existing mandates without undermining regulatory intent, these frameworks allow organisations to function across borders without diluting the safety requirements of any single state.
Conclusion: The Future of Trustworthy AI
As compliance infrastructures mature, they will define the practical boundaries of innovation. We are moving toward a future where “trustworthy AI” is not a marketing slogan, but a verifiable technical state. However, we must ask: Can we ever truly automate trust? While meta-frameworks provide the necessary structure, the “human-in-the-loop” expert synthesis remains the most critical component of the process. In an increasingly complex algorithmic world, the ability to translate legal nuance into technical reality is more of an art than a science, and that expertise will be the ultimate competitive advantage in the future of AI governance.
Publications/Presentations:
- “Toward a Unified Meta-Framework for AI Auditing: A PRISMA Scoping Review of Post-2023 Governance Frameworks and Blind Spots” – IFIP2025, Copenhagen, August 2025, Springer
- “From Principles to Controls: A Design-Science Justification of AI Auditing Meta-Frameworks” – ECR2026, Glasgow, March 2026, CREATe
- “Privacy by Design vs. Engineering Rules in AI Regulation: A Comparative Framework for Auditable Implementation.” – IDS2026, New York, May 2026, IEEE
Later this week, the series continues with the blog post “AI filmmaking and streaming giants” by Panagiotis Lampropoulos, in which he analyses how dominant subscription-based platforms are restructuring the film industry and affecting the creative autonomy by using their market power to influence directors’ artistic decisions.
Endnote
[1] Meta-regulation (meta-framework) is a form of regulation that encourages self-regulation of firms. In contrast to traditional forms of regulation, where decisions concerning rules are decided by the regulator, meta-regulation has firms create their own rules while observing and monitoring those rules. [Cary Coglianese, Evan Mendelson. Meta-Regulation and Self-Regulation. https://ssrn.com/abstract=2002755]