Part II applies the philosophical architecture developed in Part I, the Cartesian inheritance of computational design, Kant's distinction between phenomenon and noumenon, Korzybski's map and territory, Bateson's logical levels, and the autopoietic theory of Maturana, Varela, and Luhmann, to the principal instruments of European Union artificial intelligence governance. Its subject is the structural encounter between two autopoietic systems: law, which produces its own distinctions through its own internal operations, and artificial intelligence, which produces its own informational distinctions through self-organisation and structural coupling with its deployment environment. The argument advanced across seven chapters is that the gap between regulatory intent and AI behaviour is not primarily a drafting deficiency or a political compromise but a structural epistemological condition, and that this condition has direct and previously underexamined consequences for legal practice. The Part opens by establishing why AI systems resist the knowability that modern administrative law has historically presupposed of the objects it regulates, and applies that diagnosis to the taxonomic architecture of the EU AI Act, showing that a static, purpose-based classification system cannot track the emergent, self-producing risk profile of systems that continue to develop after deployment. It then turns to the General Data Protection Regulation, arguing that a framework built around the collection of pre-existing personal data struggles to govern a world in which AI systems generate new personal information through inference from data that was never classified as sensitive, and proposes a set of interpretive principles by which existing GDPR provisions can be read to reach this problem without legislative amendment. A chapter on cybersecurity law examines NIS2 and DORA as instruments built for a threat landscape of known unknowns, and argues that AI-enabled offensive and defensive systems generate unknown unknowns that these frameworks are not equipped to enumerate in advance. The second half of the Part addresses liability, human oversight, and constructive reform. A chapter on liability traces the consequences of the withdrawal of the proposed AI Liability Directive and argues that the surviving Product Liability Directive, together with the general law of tort, leaves a structural gap around harms that are emergent rather than designed, proposing a governance-of-emergence model as an alternative to the defect-in-design paradigm. A chapter on human oversight subjects the EU AI Act's Article 14 regime to the empirical literature on automation bias, concluding that the placement of a human reviewer at the point of output does not, without more, deliver the meaningful oversight the provision promises. The Part closes with a constructive chapter proposing a post-Cartesian legal architecture organised around structural coupling rather than direct control, dynamic risk governance rather than point-in-time classification, and the cultivation of the practical judgment on which genuine human oversight ultimately depends. Written from the perspective of a practising lawyer rather than as a work of pure theory, Part II treats the philosophical framework of Part I as an instrument of legal diagnosis and drafting rather than as an end in itself. Its aim is not to argue that European AI law should be abandoned, but to show where its existing categories can be read purposively to reach further than their drafters may have anticipated, and where no amount of purposive reading will substitute for the institutional humility that governing a self-producing technology ultimately requires.
Paper
The full text of this publication is not hosted on 44B due to licensing.
Read it at OpenAlex