This is written to sit beside the EU AI Act, GDPR, U.S. administrative law, or sectoral regulation without pretending to replace them.
ACP as a Legislative Companion (Not a Substitute)
A. What ACP assumes about law
ACP assumes:
- fragmented authority
- imperfect enforcement
- institutional risk aversion
- political pressure
It does not assume ideal regulators or new statutory categories.
B. How ACP complements existing regimes
EU AI Act
- The AI Act emphasizes classification, conformity, and documentation.
- ACP addresses what the Act leaves structurally weak:
who is authorized to rely on outputs once conformity is achieved.
ACP turns conformity from a terminal state into a precondition.
GDPR
- GDPR emphasizes transparency, explanation, and rights.
- ACP addresses the gap between explanation and action.
A right to explanation does not determine who may act. ACP forces that question.
U.S. Administrative Law
- U.S. governance relies heavily on procedure and recordkeeping.
- ACP converts records into decision points.
It aligns with administrative due process without expanding statutory scope.
C. Enforcement implications
ACP gives regulators:
- identifiable ratification events
- named decision-holders
- explicit refusal states
This reduces reliance on interpretive audits and increases enforceability without increasing regulatory burden.
D. What ACP refuses legislatively
ACP refuses:
- capability thresholds as governance proxies
- disclosure as enforcement
- best-practice compliance as control
It treats these as necessary but insufficient.
E. Legislative intent clarified
ACP’s intent is not safety maximalism.
Its intent is authority visibility.
Legislatures may regulate outcomes.
ACP ensures someone can be held responsible for deciding.
Member discussion: