The Regulatory Wave That’s Actually Happening
The decade of tech industry self-governance — the implicit arrangement where technology companies operated with minimal regulatory oversight on the premise that they were creating economic value and that regulators didn’t understand the technology — has been drawing to a close since approximately 2018 and is now in active transition. Significant legislation has passed in the EU, is passing in various US states, and is being considered at the federal level in the US and by governments globally. The ‘move fast and break things’ era of tech regulation is over; the regulatory constraint era is beginning.
This matters to individual technology users in specific ways: privacy rights and data deletion capabilities are expanding in jurisdictions with strong consumer protection legislation, platform moderation is being affected by platform liability legislation, and AI-specific regulation is creating the first mandates for transparency and risk assessment in AI systems. Understanding what’s changed and what’s changing provides context for evaluating both specific tech products and the industry’s direction.
EU Digital Markets Act and Platform Competition
The EU’s Digital Markets Act (DMA), in effect since 2024, designates the largest digital platforms as ‘gatekeepers’ and imposes interoperability and anti-self-preferencing requirements. Practically: Apple was required to allow alternative app stores on iOS in EU markets (implemented in iOS 17.4), messaging platforms were required to begin interoperability work (WhatsApp, Messenger, and iMessage are required to accept messages from third-party clients), and dominant platforms cannot preference their own services in search results or require bundled service adoption.
The DMA’s impact on EU users has been most visible in the alternative app store options for iPhone users in EU markets — an option that allows installing apps outside Apple’s App Store review process, which Apple has implemented in a constrained way that regulators are reviewing for full DMA compliance. The interoperability requirements for messaging will take years to fully implement but represent a structural change to how messaging platform network effects work.
AI-Specific Regulation: The EU AI Act and What It Requires
The EU AI Act (adopted 2024, phasing in through 2026-2027) is the first comprehensive AI regulation framework enacted by any major jurisdiction. It categorizes AI systems by risk level (unacceptable risk, high risk, limited risk, minimal risk) and applies different requirements to each tier. High-risk AI systems (those used in critical infrastructure, education, employment, essential services, law enforcement, and migration) require transparency documentation, human oversight mechanisms, and conformity assessments before deployment.
The practical implications for AI product users: AI systems used for consequential decisions — hiring screening, credit assessment, benefits determination — must disclose when AI is involved, must be auditable for accuracy and bias, and must provide human review options. The ‘we used an algorithm’ explanation for consequential decisions without transparency or appeal mechanism is specifically addressed by the Act’s requirements for high-risk systems.
US State Privacy Laws and Their Practical Effects
In the absence of comprehensive federal privacy legislation in the US, a patchwork of state laws has created enforceable privacy rights in several states (California CPRA, Virginia CDPA, Colorado CPA, Texas TDPSA, and others). California’s privacy law remains the most influential: it gives California residents the right to know what data is collected, the right to delete it, the right to opt out of data sales, and the right to non-discrimination for exercising these rights.
Practically: the ‘Do Not Sell or Share My Personal Information’ links now present on most major US websites are direct products of California privacy law. The data deletion requests that users can submit to tech companies are legal rights, not discretionary accommodations. For users in states with privacy laws, these rights are enforceable; for users in states without them, the same rights often exist as a practical matter because companies have extended their compliance broadly rather than implementing state-specific versions.
Platform Liability and Content Moderation Pressure
Section 230 of the Communications Decency Act (the US law that protects platforms from liability for user-generated content) has been a recurring target of proposed reform from both parties — for different reasons. The legal protection it provides has been central to the platform economy’s development; its potential modification would significantly change the incentive structure for how platforms handle content moderation.
The EU’s Digital Services Act (DSA, enforceable since 2024 for the largest platforms) imposes content moderation obligations on large platforms regardless of US law: risk assessments for societal harms, algorithmic transparency, advertising transparency, researcher data access, and the ability for users to see content in non-algorithm-sorted order. These requirements apply to platforms serving EU users regardless of the platform’s home jurisdiction.
