This is written to sit beside the EU AI Act, GDPR, U.S. administrative law, or sectoral regulation without pretending to replace them.


ACP as a Legislative Companion (Not a Substitute)

A. What ACP assumes about law

ACP assumes:

  • fragmented authority
  • imperfect enforcement
  • institutional risk aversion
  • political pressure

It does not assume ideal regulators or new statutory categories.


B. How ACP complements existing regimes

EU AI Act

  • The AI Act emphasizes classification, conformity, and documentation.
  • ACP addresses what the Act leaves structurally weak:
    who is authorized to rely on outputs once conformity is achieved.

ACP turns conformity from a terminal state into a precondition.

GDPR

  • GDPR emphasizes transparency, explanation, and rights.
  • ACP addresses the gap between explanation and action.

A right to explanation does not determine who may act. ACP forces that question.

U.S. Administrative Law

  • U.S. governance relies heavily on procedure and recordkeeping.
  • ACP converts records into decision points.

It aligns with administrative due process without expanding statutory scope.


C. Enforcement implications

ACP gives regulators:

  • identifiable ratification events
  • named decision-holders
  • explicit refusal states

This reduces reliance on interpretive audits and increases enforceability without increasing regulatory burden.


D. What ACP refuses legislatively

ACP refuses:

  • capability thresholds as governance proxies
  • disclosure as enforcement
  • best-practice compliance as control

It treats these as necessary but insufficient.


E. Legislative intent clarified

ACP’s intent is not safety maximalism.

Its intent is authority visibility.

Legislatures may regulate outcomes.
ACP ensures someone can be held responsible for deciding.