

On February 2, 2025, the first set of rules under the Artificial Intelligence Act (‘AI Act’), which came into force on August 1, 2024, came into force. Some notable implications of these rules include a prohibition on the use of AI programmes that evaluate social behaviour, and a partial restriction on facial recognition in public spaces. With the AI Act, the European Union has set yet another example regarding how liberal democracies could be cognizant regarding their responsibility towards providing citizens certain implicit reservations of digital rights and their enforceability without demand. Previously, the General Data Protection Regulation (‘GDPR’) had stood ground as a model in this regard, in a changing, highly connected world.
“Data is a new currency,” “Data is a new corporate raw material,” and “Data is the most valuable thing on earth” – these are no longer prognoses. Data is a new war. It is not unlikely that in the near future, political parties across electoral constituencies would pitch data protection as a crucial agenda within their manifestos. This will be guided by two core objectives - self-preservation, and the positioning of data protection as ‘national interest’, even as the latter will likely be guided by the standing of corporate lobbies on the issue.