How Should We View the EU’s AI Principles Code?
If I had to describe the EU’s AI Principles Code in one sentence, I would say it is “an attempt to place the values humans want to protect before introducing AI into society.” The 2019 Trustworthy AI Ethics Guidelines organized elements such as human oversight, safety, privacy, transparency, fairness, consideration for society and the environment, and accountability. After that, the AI Act moved toward risk-based regulation, and now, in the form of something like a code of conduct for general-purpose AI, the EU is trying to apply rules to generative AI and foundation models as well.
I understand the direction. If AI is going to penetrate search, work, education, government administration, and even national security, then “it’s convenient, so anything goes” is obviously dangerous. In particular, issues such as discriminatory decisions, surveillance, handling of personal information, misinformation, copyright, and cybersecurity will cause real harm if left unchecked. I think it is fair to appreciate the fact that the EU brought human rights and safety to the forefront and tried to lead the international discussion.
That said, I do not feel like praising it unconditionally here. What is quite important is the point that “having correct principles” and “creating good governance in practice” are two different things. Human-centeredness, transparency, fairness, accountability — every one of these words is correct. But simply lining up those words does not tell us where, by whom, or to what extent they should actually be implemented within AI services.
Principles Alone Do Not Create AI Governance
AI risks do not arise from AI models alone. They involve training data, external data, prompts, UI, business processes, users’ understanding, administrators’ judgments, changes in operating environments, and even business objectives. So even if regulatory documents or principles say, “Let’s ensure transparency” or “Let’s consider fairness,” unless those ideas are translated into actual use cases, the discussion remains almost entirely abstract.
For example, hiring AI, medical AI, educational AI, emotion-recognition AI, and internal knowledge AI all involve different things that must be protected, different acceptable risks, and different stakeholders. Even within emotion-recognition AI alone, it is highly questionable whether the same prohibitions and permissions should apply equally to monitoring employees in the workplace and to services where children can talk about their worries. If this area is handled carelessly, the discussion collapses into a binary choice of either “it seems dangerous, so ban it” or “it seems useful, so allow it.”
From the Matsumoto perspective, AI governance should always be worked through case by case. Rather than discussing ideals on paper, we should place a concrete service on the table and examine what kind of value it aims to create, what risks interfere with that value, who may be harmed and in what situations, and where responsibility should be placed. Rules that are not built on that accumulation may look impressive, but they are weak in practice.
The Fear of the EU-Style Rules
Another concern is that EU-style regulation ultimately tends to favor large corporations. Documentation, audits, evaluations, legal compliance, certification — in the end, the companies capable of handling all of these properly are usually those with abundant resources. Startups and small developers become exhausted by compliance costs even when they are not doing anything wrong.
This is quite ironic: rules intended to protect users can end up strengthening the position of giant platform companies. I think GDPR had a similar structure. If the same thing happens with AI, then under the banner of “trustworthy AI,” we may in fact simply be reducing the number of challengers.
Of course, this does not mean regulation is unnecessary. The issue is what should be restricted and to what extent. Rather than broadly constraining AI models themselves, it makes more sense to focus specifically on malicious uses and high-risk business applications. After all, the purpose of regulation should not be to make people fear AI, but to properly integrate valuable AI into society.
How Should Japan Respond?
I do not think Japan needs to treat EU rules as something to be accepted wholesale. Japan has its own industrial structure, workplace culture, relationship with government administration, and approach to soft law. Rather, it is probably more suitable for Japan to organize guidelines, case studies, and technical understanding separately while steadily building up concrete use cases.
In particular, companies should not respond simply because “the EU says so.” First, they should clarify what value they themselves want to create with AI. If governance alone is established while the value remains vague, it just turns into governance theater. Companies with no real intention of transforming their operations through AI are often the ones most satisfied with creating impressive-looking rules. That is quite dangerous.
What is necessary, I think, is to use AI routinely while viewing both its risks and benefits with equal seriousness. When people who do not use AI create only AI rules, the discussion inevitably leans toward fear. On the other hand, if people who see AI only as a convenient tool ignore rules altogether, accidents happen. That is why governance built through the habit of using, improving, and evaluating AI is stronger.
Conclusion
The EU’s AI Principles Code is certainly an important starting point for protecting human dignity and safety in the AI era. However, it is wrong to import it wholesale as the correct answer. What matters is not memorizing principles, but thinking within concrete AI services about “what should be protected, what should be realized, and which risks should be borne by whom.”
From my perspective, good AI governance is not a brake meant to stop AI, but something closer to the suspension system that allows AI to run properly. The EU principles can be used as one component of that system. But a car does not run on that alone. Only by connecting real-world use cases, business objectives, user experiences, and the limitations of technology does governance begin to function in practice.
Digital MATSUMOTO
https://medium.com/@digitalmatsumoto/how-should-we-view-the-eus-ai-principles-code-85d82fedc825