Risks and rulesGuide 8 of 9

The Limits, Risks and Regulation of Artificial Intelligence

11 min readUpdated on By the CheblAI editorial team
Read inFrançaisEnglish中文

In brief

  • AI is powerful but imperfect: it can make mistakes (hallucinations), reproduce discrimination (bias), consume a lot of energy and raise questions about privacy and copyright.
  • The European Union has adopted the first major legal framework for AI, the AI Act, which entered into force on August 1, 2024 and applies in stages through 2028.
  • As a user, a few simple habits greatly reduce the risks: verify, protect your data, and disclose your use of AI.
On this page
1. Errors and Hallucinations2. Bias and Discrimination3. Privacy and Personal Data4. Copyright and Intellectual Property5. Energy and the Environment6. Disinformation, Jobs and Concentration of PowerRegulation: The EU AI ActGood Habits for UsersFrequently asked questionsSources and references

1. Errors and Hallucinations

A language model produces plausible text, not necessarily accurate text (see how ChatGPT works). Real cases illustrate this:

  • Mata v. Avianca (United States, 2023): lawyers submitted court decisions invented by ChatGPT to a federal court in New York. Judge P. Kevin Castel dismissed the case and imposed a $5,000 fine.
  • Air Canada (Canada, February 2024): a tribunal ordered the airline to compensate a customer who had been misled by its chatbot about the terms of a bereavement fare. The airline cannot shift the blame onto its bot.
  • Consulting reports (2025): a report commissioned by the Australian government and billed at $440,000 contained nonexistent references, and the firm refunded part of the contract.

According to Stanford University’s 2026 AI Index, the number of documented AI-related incidents rose from 233 in 2024 to 362 in 2025.

2. Bias and Discrimination

An AI learns from data produced by humans, along with their inequalities. It can therefore reproduce them, or even amplify them.

  • Hiring: in 2018, Reuters revealed that Amazon had abandoned an experimental résumé-screening tool that penalized female applicants, because it had learned from résumés that came mostly from men.
  • Facial recognition: the “Gender Shades” study (Joy Buolamwini and Timnit Gebru, 2018) showed markedly higher error rates for darker-skinned women in several commercial systems.
  • Justice: in 2016, a ProPublica investigation challenged COMPAS, a tool used in the United States to assess the risk of reoffending, for making errors that differed depending on the person’s race.

3. Privacy and Personal Data

What you write to an assistant may be stored, reviewed by moderation teams, or used to train future models, depending on the provider’s policy. In Europe, the GDPR applies to personal data, and the CNIL (the French data protection authority) publishes recommendations on AI and data protection.

  • Don’t enter passwords, banking details, medical records, your company’s confidential documents or information about identifiable third parties.
  • Check in the settings whether your conversations are used for training, and turn that option off if you wish.
  • For professional use, favor “business” plans, which generally offer contractual guarantees.

4. Copyright and Intellectual Property

Models are trained on huge datasets that include protected works. Authors, artists, publishers and photo agencies are challenging this use in court (for example Getty Images against Stability AI in 2023, or The New York Times against OpenAI and Microsoft in December 2023). Courts and lawmakers in several countries have not yet settled every question: the state of the law is evolving fast and differs from one country to another.

For users, the prudent approach is to read the tool’s terms of use, avoid asking it to reproduce protected works or characters, and review and rework the text it generates.

5. Energy and the Environment

According to the International Energy Agency, data centers consumed about 415 TWh in 2024 (nearly 1.5% of the world’s electricity), and their consumption could reach about 945 TWh in 2030. AI is one of the main drivers of this increase (see how an AI is built).

6. Disinformation, Jobs and Concentration of Power

  • Disinformation: synthetic content (text, images, voices, videos) can be produced in bulk and at low cost, which makes scams, identity theft and manipulation easier.
  • Jobs: AI automates tasks more than entire occupations; the net effect on employment is still debated and varies by sector. Skills in using AI are becoming an asset.
  • Concentration: developing the largest models takes enormous resources. According to the 2026 AI Index, more than 90% of notable models come from industry; this concentration fuels debates about digital sovereignty and transparency.

Regulation: The EU AI Act

The European Union has adopted the first major general legal framework for artificial intelligence. The European Parliament voted for it on March 13, 2024, the Council approved it on May 21, 2024, and it entered into force on August 1, 2024. Its central principle: the riskier an AI use is, the stricter the rules.

Four-level pyramid of the EU AI Act: unacceptable risk (prohibited), high risk (strict requirements), limited risk (transparency), minimal risk (unrestricted)
Diagram 1 — The four risk levels of the EU AI Act.
LevelRuleExamples
Unacceptable riskProhibitedSocial scoring of citizens, manipulation that exploits vulnerabilities, certain real-time biometric identification in public spaces (with limited exceptions)
High riskAllowed under strict conditions: conformity assessment, data quality, human oversight, documentationAI used for hiring, access to education, credit or essential services, certain medical devices
Limited riskTransparency obligations: telling people they are interacting with an AI, flagging synthetic contentChatbots, deepfakes
Minimal riskNo specific obligationsSpam filters, video game AI

General-purpose AI models, such as those powering ChatGPT, Claude or Gemini, are subject to specific transparency obligations, and to stronger evaluations for the most powerful models.

The Application Timeline

  1. August 1, 2024Entry into force

    The regulation is in force, but its obligations apply in stages.

  2. February 2, 2025Prohibitions and training

    The prohibited practices and the obligation to train staff on AI (“AI literacy”) become applicable.

  3. August 2, 2025General-purpose models

    The governance rules and the obligations for general-purpose AI models apply.

  4. August 2, 2026General application

    The regulation becomes generally applicable, including the transparency obligations (Article 50).

  5. December 2, 2027High-risk systems

    After a delay adopted in 2026 (the “Digital Omnibus”), the rules for the high-risk systems listed in Annex III (biometrics, employment, education…) apply on this date instead of August 2026.

  6. August 2, 2028AI built into products

    The rules for AI built into products that are already regulated (toys, elevators, medical devices…) apply.

Other countries have their own rules. China, for example, regulates generative AI services through interim measures in force since August 2023.

Good Habits for Users

  1. Verify

    Check important facts, figures, quotes and references against a reliable source.

  2. Protect

    Don’t share sensitive data, and check your privacy settings.

  3. Stay in control

    Use AI as an assistant, not as a decision-maker, especially for health, law or finance.

  4. Be transparent

    Disclose your use of AI when it is expected or required.

  5. Keep learning

    Understanding how AI works helps you better see its limits. See the beginner’s guide.

Frequently asked questions

What are the main risks of artificial intelligence?

Errors and hallucinations, bias and discrimination, privacy violations, copyright issues, disinformation (deepfakes), energy impact and effects on jobs.

What is the EU AI Act?

It is the European Union’s regulation on artificial intelligence, which entered into force on August 1, 2024. It classifies AI uses by level of risk (unacceptable, high, limited, minimal) and imposes stricter rules the greater the risk.

When does the EU AI Act apply?

In stages: prohibitions on February 2, 2025, general-purpose models on August 2, 2025, general application on August 2, 2026, Annex III high-risk systems on December 2, 2027 after a delay, and AI built into products on August 2, 2028.

Can you trust ChatGPT?

For writing, rephrasing or brainstorming ideas, it is very useful. For facts, figures, or legal or medical questions, you need to verify the information, because it can be confidently wrong.

Are my conversations with an AI confidential?

Not necessarily. Depending on the provider, they may be stored and sometimes used to improve the models. Check the privacy policy, turn off training if possible, and don’t enter sensitive information.

Sources and references

  1. European Commission — AI Act
  2. Gibson Dunn — EU AI Act Omnibus Agreement: postponed high-risk deadlines
  3. IEA — Energy and AI (2025)
  4. Stanford HAI — AI Index Report 2026
  5. Wikipedia — Mata v. Avianca, Inc.
  6. CNIL (French data protection authority) — Artificial intelligence
  7. Reuters — Amazon scraps secret AI recruiting tool that showed bias against women (2018)
  8. Buolamwini & Gebru, “Gender Shades,” 2018
  9. ProPublica — Machine Bias (2016)

Independent editorial content. The facts, dates and figures cited rely on the sources listed at the end of the page; this content is for information only and does not constitute professional advice.