The Blind Spot in Europe's AI Regulation
- GV Vadivan

- Jul 16
- 5 min read
What Herta Security Reveals About Europe's AI Governance and Global Deployments
The European Union has positioned the AI Act as the world's first comprehensive legal framework for regulating artificial intelligence. Built around the principles of trust, transparency and fundamental rights, the Act goes beyond managing technological innovation - it defines what Europe considers acceptable and unacceptable uses of AI.

Certain AI practices are classified as posing an "unacceptable risk" and are prohibited within the Union. Others are subject to stringent obligations before they can be placed on the European market.
At first glance, the framework appears comprehensive.
Yet one important question remains largely unexplored: What happens when the AI leaves Europe? The answer exposes one of the most significant blind spots in Europe's AI governance.
Regulation Ends Where Jurisdiction Ends
The AI Act primarily regulates AI systems placed on the EU market or put into service within the European Union. Its obligations extend to providers, deployers, importers and distributors operating in the European market, and in some cases to providers established outside the EU when their systems affect people in the Union.
But the legislation is far less concerned with a different scenario: A European company develops an AI system in Europe and deploys or sells it entirely outside the European Union.
If the AI is never placed on the EU market and its outputs are not used within the Union, many of the AI Act's restrictions may simply not apply.
From a legal perspective, this reflects the territorial nature of EU legislation. From a governance perspective, however, it raises uncomfortable questions.
If Europe concludes that certain AI applications are incompatible with fundamental rights, should those same technologies become acceptable simply because they are deployed elsewhere?
This question becomes particularly relevant when examining companies such as Herta Security.
Founded in Spain, Herta Security develops AI-powered biometric identification technologies, including facial recognition solutions for applications such as airports, railway stations, smart cities, law enforcement and critical infrastructure. The company's publicly available materials describe deployments and partnerships across multiple regions outside the European Union, including projects in Asia, the Middle East and Latin America.
Herta enables surveillance cameras by deploying its facial-recognition software, and it deployed in more than 4000 cameras in India. At least two of these deployments would be deemed unlawful if they operated inside the European Union.
In its defence, Herta may argue that it has not violated the AI Act or any other law since it has developed the solutions in line with European data-protection principles, regardless of the market in which they are deployed. But it will also argue that it could not "control how public authorities or system integrators implement the technology in specific environments".
Herta provides a useful case study for exploring a broader policy question. Does the Act lead to double standards in implementation?
If the EU considers certain biometric surveillance practices sufficiently harmful to prohibit within Europe, what responsibilities should European developers have when deploying similar technologies abroad?
The Double Standard Question
The AI Act is rooted in the protection of human dignity, privacy and fundamental rights. These principles are universal. They are not intended to apply only to European citizens.
Yet the legislation itself is largely territorial. This creates an apparent contradiction.
Imagine a biometric surveillance system that would be prohibited if deployed in a European railway station. If the identical system is instead installed in a railway station in India by the same European developer, the AI Act may have little or no role to play.
The underlying human rights concerns have not changed. Only the geography has.
This is not necessarily a failure of legislative drafting. Jurisdictional limits are a reality of international law. However, it does expose a gap between Europe's ambitions and implementation of its flagship AI regulation.
The Limits of the "Brussels Effect"
The EU often relies on what scholars call the "Brussels Effect" - the tendency for global companies to adopt European standards worldwide because maintaining different regulatory regimes is expensive.
The AI Act is widely expected to produce a similar effect.
But the Herta example illustrates why this assumption may not always hold. Companies may instead choose to segment their products and markets:
one regulatory standard for Europe,
another for jurisdictions with fewer restrictions.
In such cases, Europe is no longer exporting its regulatory values. It may instead be exporting technologies that Europe itself considers too risky for domestic deployment. This possibility deserves far greater attention than it has received during debates surrounding the AI Act.
AI Leadership or Regulatory Relocation?
European policymakers frequently describe the AI Act as a model for trustworthy AI. The ambition is commendable. But trustworthy AI cannot be measured solely by what happens within Europe's borders.
If European companies continue supplying AI systems to jurisdictions with weaker safeguards, the risks associated with those technologies do not disappear. They are merely relocated. This raises a broader question for AI governance.
Should Europe's responsibility end once the technology crosses its borders? Or should European companies remain accountable for the foreseeable human rights impacts of their AI systems regardless of where they are deployed?
These are not easy questions and there are no easy answers. The debate could extend beyond facial recognition to emotion recognition, predictive policing, biometric categorisation, or other AI applications that present significant risks to fundamental rights.
Towards a More Coherent AI Governance Framework
The AI Act represents an achievement in establishing a horizontal regulatory framework for artificial intelligence. As the Act enters into force, policymakers should begin considering how Europe's broader human rights commitments intersect with the global activities of European AI providers.
Future refinements could include greater transparency around exports of sensitive AI systems, enhanced human rights due diligence obligations for overseas deployments, or mechanisms that better align AI governance with the EU's external human rights policy.
Such measures would not seek to regulate the world.
Rather, they would ensure that the values underpinning European AI regulation are reflected in the conduct of European companies wherever they operate.
Conclusion
The Herta Security example is not ultimately about one company. It is about the limits of territorial regulation in an increasingly global AI economy. The AI Act tells us what Europe is prepared to prohibit within its own borders.
It says far less about what happens when European AI technologies are developed in Europe, commercialised by European companies and deployed elsewhere.
If the European Union truly intends to become the global standard-setter for trustworthy AI, its greatest challenge may not lie in regulating AI inside Europe. It may lie in deciding whether European values should travel with European technology.


Comments