· Alexander Lewisch

The Convergence of AI Ethics and the AI Act: From Abstraction to Application

How virtue ethics, deontology and utilitarianism became the legal foundation of the EU AI Act — and where the law falls short of the ethics

A tree split into a warm half and a cool half, labelled ‘Ethik’ and ‘Recht’, with ‘AI ACT’ below, against a skyline.
AI-generated image

The EU AI Act can be seen as a deliberate attempt to translate classical philosophical-ethical aspects into binding law, in order to regulate AI through principles such as autonomy, responsibility and the prevention of harm. Although this approach gives the law a strong normative foundation, its implementation remains incomplete owing to legal gaps and conflicts with existing legal frameworks.

Codifying Ethics and Regulating Technology – A Twofold Challenge

Introduction – The Tension Between Philosophical Ethics and Law

The rapid development and implementation of artificial intelligence (AI) has led society to a normative crossroads. Fundamentally, ethics and law operate in different, if connected, spheres. While ethics provides a guide for what a society considers “desirable” or “right”, the law defines what is binding and enforceable, backed by sanctions. The most recent wave of technological innovation, especially in the field of generative AI, has dramatically underlined the urgency of a convergence of these spheres. In this, demonstrated risks have made the need for strict regulation and ethical practices obvious.

The European Union has responded to this challenge with a regulation, the so-called “AI Act”, thereby creating the world’s first comprehensive legal instrument for regulating AI. This instrument, however, did not emerge ex nihilo; it is the result of a deliberate political path that contains a deeply philosophical-ethical component. The stated aim of the regulation is to promote the “uptake of human-centric and trustworthy artificial intelligence” while at the same time ensuring a “high level of protection of health, safety and fundamental rights”.

The Italian philosopher and professor of philosophy and information ethics at the University of Oxford, Luciano Floridi, analyses this regulatory approach as inherently European. In his analysis of the legislation, he notes that the AI Act “inherits” the “fundamental approach” of EU values. The vision underlying this approach is unmistakable: technology, including AI, must serve humanity, its values and its needs. While Floridi criticises the term “human-centric” as potentially “outdated terminology” that might carry anthropocentric tendencies, he recognises the ambitious attempt behind it, namely the AI Act’s effort to cast a normative, value-based vision into binding, operational law.

The AI Act can thus be understood as the legal end product of a process that was not only years-long and organised politically, but also philosophical. This process began formally with the establishment of an independent High-Level Expert Group on AI, HLEG for short, by the European Commission in 2018. In 2019 the HLEG presented its ethics guidelines, which served as a direct blueprint for the Commission’s 2021 legislative proposal and the final 2024 regulation. This path dependency from ethics to law is at once the greatest strength and the greatest weakness of the AI Act. It is a strength, because it gives the law a coherent normative foundation anchored in European core values. But it is also a potential weakness, because the AI Act is now measured by whether its legal mechanisms, such as Article 14 “on human oversight”, can actually achieve the high ethical goals, or whether they degenerate into bureaucratic insignificance in regulatory enforcement.

Philosophical Ethics and Its Relevance for AI

At its core, the debate on AI ethics can be understood as an application of classical philosophical theories to new technological circumstances. The AI Act and the ethics guidelines that preceded it are deeply rooted in the classical theories of philosophical traditions (virtue ethics, deontology and utilitarianism).

Virtue Ethics and Responsibility

Aristotelian virtue ethics argues that ethics is a matter of the character and practical wisdom of the actor. AI development along these lines requires structured ethical reflection. The AI Act enforces such virtue-ethical processes, for example by prescribing risk management and quality management that must be maintained over the entire life cycle of the AI system. On this point, the well-known writer Hannah Arendt, in her work “Eichmann in Jerusalem: A Report on the Banality of Evil” (1964), provided an urgent warning as to why an institutionalised ethics of responsibility is necessary. Her analysis of the “banality of evil” shows the irresponsibility that arises when individuals delegate their moral judgement to bureaucratic processes and fail to exercise their personal responsibility. Arendt sees individual responsibility as the central criterion for preserving the capacity for judgement.

The greatest “banal” danger in the application of AI is “automation bias”, the uncritical acceptance of algorithmic recommendations. Here Arendt provides the philosophical justification for why “human oversight” under Article 14 of the AI Act is so decisive. Article 14 is the legal defence mechanism against the “banality of the algorithm”, in that it explicitly assigns to the human the ability and the duty to ignore, alter or reverse the system’s output, and thus functions as an instrument for reclaiming personal responsibility.

Deontology and Autonomy

The European tradition of fundamental rights, which plays a central role in the AI Act, is hardly conceivable without the deontological ethics of Immanuel Kant. At the centre of Kantian deontology is not the utility of an action but the duty that arises from reason. The highest principle of this ethics is the autonomy of the will. Kant calls this “the sole principle of morality”.

From this autonomy Kant derives the “end-in-itself formula” of the categorical imperative, which commands us to treat humanity, both in our own person and in the person of everyone else, “always at the same time as an end, never merely as a means”. The HLEG guidelines directly reflect this idea when they stress that “respect for human dignity” requires that people “never be merely (…) sorted, scored, (…) or manipulated” as objects.

The prohibitions in Article 5 of the AI Act are a direct legal image of this Kantian ethics. The prohibition of AI systems that use subliminal or manipulative techniques, or the prohibition of “social scoring”, is not primarily justified in utilitarian terms. These systems are prohibited not because they do more harm than good, but because, in Kant’s sense, they per se violate autonomy and human dignity and see people merely as a means to an end, i.e. for achieving an external goal, such as steering behaviour or social conformity.

Consequentialism and the Prevention of Harm

While Kantian deontology explains the absolute prohibitions of the AI Act, consequentialism, especially the utilitarianism of Jeremy Bentham or John Stuart Mill, provides the philosophical blueprint for the regulatory part of the law, i.e. the risk-based approach. Consequentialism evaluates the morality of an action by its consequences. John Stuart Mill’s “harm principle”, set out in his work “On Liberty”, states: “That principle is, that the sole end for which mankind are warranted, individually or collectively, in interfering with the liberty of action of any of their number, is self-protection. That the only purpose for which power can be rightfully exercised over any member of a civilised community, against his will, is to prevent harm to others. His own good, either physical or moral, is not a sufficient warrant.”

This harm principle is precisely operationalised by the AI Act’s four-tier, risk-based approach:

  • Mill’s libertarianism (no intervention): The last part of the quotation above shows that one’s own good is not a sufficient ground for a restriction. This corresponds to the categories for AI systems that, under the AI Act, present only minimal or no risk and are largely unregulated. Here the freedom to innovate prevails.
  • Mill’s harm principle (intervention): The quotation also contains the right of a society, a state or, as Mill puts it, a civilised community, to intervene in order to prevent harm to others. This corresponds to the regulated categories of the AI Act. As soon as an AI system poses “serious risks to the health, safety or fundamental rights” of third parties, it is classified as a “high-risk system” and subjected to strict obligations. In this sense, the AI Act is a regulation that ensures AI safeguards safety, health and fundamental rights.

The Development of European AI Ethics Guidelines

The AI Act is, as set out in the introduction, the end product of a process that began with ethical considerations. The High-Level Expert Group on AI (HLEG), set up by the European Commission in 2018, had the task of defining an ethical framework for AI development in Europe. In April 2019 the HLEG presented its ethics guidelines for trustworthy AI. These define trustworthy AI as a system that must have three components which ideally work together in harmony. The three pillars of the HLEG are:

  1. Lawful: respecting all applicable laws and regulations.
  2. Ethical: respecting ethical principles and values.
  3. Robust: from both a technical and a social perspective.

The AI Act is the codification of the first pillar (lawful), which, however, draws massively on the second pillar (ethical) in its substance in order to ensure the third (robust).

As a normative foundation, the HLEG additionally identified four ethical principles, grounded in the philosophical traditions discussed:

  1. Respect for human autonomy
  2. Prevention of harm
  3. Fairness
  4. Explicability

The decisive step of the HLEG was the translation of these four abstract principles into seven concrete, operational key requirements. These seven HLEG requirements form the blueprint for the heart of the AI Act, i.e. the obligations for high-risk systems in Chapter III. They were operationalised in the “Assessment List for Trustworthy AI (ALTAI)”, a practical checklist for developers and users. The convergence of ethics and law becomes clearest when the seven HLEG requirements are compared directly with the specific articles of the AI Act for high-risk systems (in brackets). The HLEG requirements include:

  1. Human agency and oversight (Article 14: human oversight)
  2. Technical robustness and safety (Article 15: accuracy, robustness and cybersecurity)
  3. Privacy and data governance (Article 10: data and data governance)
  4. Transparency (Article 13: transparency and provision of information)
  5. Diversity, non-discrimination and fairness (Article 10: data and data governance)
  6. Societal well-being and environmental sustainability (Article 95: codes of conduct for the voluntary application of specific requirements)
  7. Accountability (Article 11: technical documentation and Article 12: record-keeping)

Where the Law Falls Short of the Ethics

The AI Act is not a perfect translation, because the transformation from “soft” ethics to “hard” law inevitably gives rise to tensions, gaps and conflicting objectives.

Tension 1: AI Act vs. GDPR (General Data Protection Regulation)

A primary area of tension and a fundamental conflict of objectives lies in the relationship to the General Data Protection Regulation (GDPR). The ethical goal of “fairness” calls for the legal obligation under Art. 10 AI Act to detect and correct bias. Yet to detect bias effectively (e.g. on the grounds of sex or ethnic origin), models often have to be trained or tested on sensitive data (under Art. 9 GDPR) that describe precisely these characteristics.

Here the ethical goal of fairness (AI Act) collides head-on with the ethical goal of data protection (GDPR), which in principle prohibits the processing of such data. The AI Act attempts to resolve this conflict in Art. 10(5). It creates a strictly purpose-bound exception that allows the processing of sensitive data only for the purpose of bias detection and bias correction, and only where this is strictly necessary and is protected by strict technical and organisational measures (e.g. pseudonymisation, access controls). This solution, however, reveals a critical gap, because this exception in Art. 10(5) applies exclusively to providers of high-risk AI systems. It does not apply to providers of General-Purpose AI (GPAI) models or systems with lower risk, even though these too carry a potential for discrimination. Here the legal solution (AI Act) falls significantly short of the ethical demand (fairness in all systems).

Tension 2: AI Act vs. DSA (Digital Services Act)

A further conflict arises in the interplay with the Digital Services Act (DSA), particularly in the regulation of AI systems used by very large online platforms. The ethical principle of accountability requires auditability. To examine AI systems for systemic risks, independent researchers and civil society need access to relevant data. The DSA recognises this necessity and, in Article 40, explicitly grants vetted researchers such data access for the analysis of systemic risks. The AI Act, by contrast, which also addresses systemic risks, especially through GPAI, contains no comparable provision. This constitutes a serious deficiency in the coherence of EU digital legislation. Here the AI Act potentially hinders the achievement of its own ethical goals by denying researchers the access that another EU law (the DSA) has already deemed fundamental to oversight.

Tension 3: The Operationalisation of “Accountability”

“Accountability” is a central ethical principle. In the AI Act it is operationalised primarily through procedural obligations via Article 11 (technical documentation) and Article 12 (record-keeping). Providers must document ex ante how their system is designed and ensure ex post that its operation is traceable through “logs”. Critics argue, however, that this reduces “accountability” to mere procedural documentation.

This decisive liability gap was meant to be closed by the “AI Liability Directive”. This draft directive, which aimed to ease the burden of proof for victims of AI-related harm, was, however, withdrawn by the European Commission in February 2025. This leaves the largest gap in the system. Without a clear liability regime, accountability remains an ethical postulate without the legal power necessary to ensure justice in the event of harm.

Conclusion: A Responsible Future Through the Symbiosis of Ethics and Law

The AI Act is not merely another act of digital regulation; through its ethical aspiration it is also a codified philosophy, because it attempts to translate the normative foundations of European ethics into binding, technical and procedural obligations for high-risk systems. Ethics and law go hand in hand in the AI Act insofar as the HLEG’s ethical guidelines provided the direct template for the core legal requirements in Articles 10–15. While ethics supplies the “why” (e.g. protecting autonomy), the law contributes the “how” (e.g. human oversight in Article 14). For all this confidence, however, the symbiosis is incomplete and marked by frictions. Significant tensions remain in coherence with existing law (GDPR, DSA). The most serious gap, however, gapes in the area of liability, since the withdrawal of the AI Liability Directive leaves the operationalisation of “accountability” confined to procedural documentation.

Originally published at SEQIS Blog