Model Registry Governance And Gatekeeping Risks .

Modular Legal Frameworks for Emerging Technologies

Detailed Explanation with At Least 6 Case Laws — Without External Links

1. Introduction

Modular legal frameworks for emerging technologies refer to a regulatory approach in which laws, standards, institutional rules and enforcement mechanisms are organised into separate but interconnected modules. Each module addresses a specific legal risk, such as privacy, cybersecurity, artificial intelligence (AI), competition, intellectual property, consumer protection, liability or cross-border data transfers.

Traditional legislation is often designed around established industries and relatively stable technological conditions. Emerging technologies—including generative AI, autonomous systems, blockchain, quantum computing, biotechnology, digital platforms and the Internet of Things (IoT)—develop faster than conventional legislative cycles. A modular framework attempts to bridge this gap by preserving foundational legal principles while allowing technology-specific rules to be updated independently.

For example, an AI-powered medical diagnostic system may simultaneously raise questions of medical-device regulation, data protection, product liability, professional negligence, cybersecurity and competition law. A modular framework allows each legal regime to address its own concerns while establishing rules for resolving overlaps.

The central objective is regulatory adaptability without sacrificing legal certainty, fundamental rights, accountability or democratic oversight.

2. Meaning and characteristics of modular legal frameworks

A modular legal framework is not necessarily a single statute. It may consist of a foundational law, sector-specific legislation, delegated regulations, technical standards, contractual obligations and administrative enforcement procedures.

Its principal characteristics include:

Modularity: Separate rules govern distinct risks or functions.

Interoperability: Different legal modules work together rather than creating contradictory obligations.

Scalability: Requirements can increase with a technology's risk, reach or potential impact.

Adaptability: Technical standards and implementing rules can evolve more quickly than primary legislation, within lawful limits.

Technology neutrality: General principles apply across technologies unless particular risks justify specialised treatment.

Accountability: Developers, deployers, intermediaries and regulators have clearly allocated responsibilities.

Proportionality: Compliance obligations reflect the severity and likelihood of harm.

Legal certainty: Regulated entities can identify the applicable requirements and challenge unlawful decisions.

Modularity must not become regulatory fragmentation. If every regulator creates incompatible definitions, reporting systems or audit requirements, the resulting framework may increase compliance costs without improving safety.

3. Core architecture of a modular framework

Module 1 — Foundational legal principles

Constitutional rights, legality, proportionality, equality and due process

Module 2 — Data and privacy

Consent, lawful processing, security and individual rights

Module 3 — Safety and liability

Testing, risk management, negligence and remedies

Module 4 — Competition and access

Market power, interoperability and discriminatory access

Module 5 — Sector-specific rules

Healthcare, finance, transport and public administration

Cross-cutting coordination and enforcement

Regulatory cooperation, common definitions, audits, appeals, remedies and periodic review

The foundational module supplies principles that cannot be displaced merely because a technology is new. The specialised modules then address distinct operational risks, while the coordination layer resolves conflicts between legal regimes.

4. Legal foundations and regulatory models

A. Horizontal regulation

Horizontal rules apply across industries. Examples include data-protection legislation, cybersecurity duties, competition law, consumer protection and general product-safety principles.

Advantage: They prevent every emerging technology from requiring an entirely new statute.

Limitation: Broad rules may not adequately address specialised risks, such as autonomous medical decisions or safety-critical AI in aviation.

B. Sector-specific regulation

Sectoral modules impose additional obligations in areas such as banking, healthcare, telecommunications and transport.

For example, an AI credit-scoring tool may be subject to general data-protection obligations as well as financial-sector rules concerning lending, discrimination, recordkeeping and risk management.

Advantage: The rules reflect the practical risks of the industry.

Limitation: Different regulators may adopt conflicting definitions, deadlines and testing requirements.

C. Risk-based regulation

Obligations are determined by the nature and severity of the risks rather than merely by the technology's label.

A system that recommends music may warrant limited oversight, while an AI system used in medical diagnosis, employment selection or critical infrastructure may justify stronger testing, documentation, monitoring and human-review safeguards.

D. Experimental regulation and regulatory sandboxes

A regulatory sandbox permits controlled testing of an innovative product or service under defined conditions. It may involve restricted deployment, reporting duties, supervision and exit requirements.

A sandbox does not automatically exempt a company from legislation. Any exemption or relaxation must have a lawful basis, a clear scope and appropriate safeguards.

E. Standards-based regulation

Legislation can establish binding outcomes while technical standards specify methods for achieving them. This permits updates to testing procedures, security controls and documentation without rewriting an entire statute.

However, technical standards must remain subject to appropriate legal oversight, transparency and judicial review where they affect rights or statutory duties.

5. Important case laws

The following cases illustrate judicial principles relevant to modular regulation, technology governance, institutional competence, fundamental rights and coordination between legal regimes. They arise from different jurisdictions; they are not all direct rulings on modular legislation. Their significance lies in the principles they establish for designing and applying adaptable regulatory frameworks.

1. Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) — India

Legal principle: Privacy as a fundamental right.

The Supreme Court of India recognised privacy as a constitutionally protected fundamental right under Article 21 and other freedoms in Part III of the Constitution.

Relevance to modular frameworks:

Technology-specific regulations must remain consistent with constitutional rights.

Data-processing rules should account for legality, legitimate purpose, necessity and proportionality.

Sectoral permissions cannot automatically justify unrestricted surveillance or personal-data collection.

New technologies must be assessed against established constitutional guarantees.

Illustration: A government AI system that combines identity, location and financial records requires a lawful basis and safeguards proportionate to the intrusion involved.

The judgment demonstrates why a foundational rights module should govern every technology-specific module.

2. Shreya Singhal v. Union of India (2015) — India

Legal principle: Freedom of expression and constitutional limits on online regulation.

The Supreme Court struck down Section 66A of the Information Technology Act, 2000, because its vague and overbroad restrictions on online expression violated Article 19(1)(a). The Court also considered intermediary liability and online-content regulation.

Relevance to modular frameworks:

Technology regulations must define prohibited conduct with sufficient precision.

Broad delegated powers can create arbitrary enforcement.

Intermediary obligations must be structured consistently with constitutional freedoms.

Online safety and content regulation cannot be designed without considering freedom of expression.

Illustration: A law requiring an automated content-filtering system to remove vaguely defined “offensive” material could produce excessive removals and suppress lawful speech.

The case illustrates the importance of a common constitutional module that constrains sectoral rules and administrative discretion.

3. Google Spain SL and Google Inc. v. AEPD and Mario Costeja González (2014) — Court of Justice of the European Union

Legal principle: Data protection and search-engine responsibility.

The Court of Justice of the European Union (CJEU) held, in the circumstances before it, that search-engine activity could constitute processing of personal data and recognised a mechanism for requesting the removal of certain search results relating to a person's name, subject to balancing the relevant rights and public interests.

Relevance to modular frameworks:

One technological service can trigger legal duties distinct from those of its underlying content publishers.

The allocation of responsibility should reflect the function performed by each actor.

Privacy, freedom of expression and public access to information may require coordinated assessment.

Remedies should be tailored to the particular processing activity rather than applied indiscriminately.

Illustration: An AI-powered search service may need to distinguish between deleting source material, de-indexing a result and correcting an inaccurate generated summary. Each action presents different legal questions.

This case supports functional allocation of obligations across interconnected digital services.

4. Google LLC v. European Commission (Google Shopping), Case T-612/17 (General Court, 2021), followed by the CJEU judgment in Case C-48/22 P (2024) — European Union

Legal principle: Abuse of dominance through self-preferencing.

The EU courts upheld the Commission's finding that Google had abused its dominant position by favouring its own comparison-shopping service in its general search results to the disadvantage of competing comparison-shopping services.

Relevance to modular frameworks:

Competition law can address new digital-market conduct without requiring a separate statute for every technological feature.

Conduct rules must be applied in light of market structure, effects and the specific facts.

Platform operators may act simultaneously as infrastructure providers and competitors.

Ex ante platform regulation can complement, but does not simply replace, traditional competition enforcement.

Illustration: A dominant AI distribution platform that systematically privileges its own model or application over rival services may raise comparable competition concerns, depending on the market, conduct and evidence.

The analogy is not automatic: self-preferencing by an AI platform is not necessarily unlawful merely because the platform favours its own product.

5. Microsoft Corp. v. Commission, Case T-201/04 (General Court, 2007) — European Union

Legal principle: Interoperability, market foreclosure and dominant-firm obligations.

The General Court largely upheld the European Commission's decision concerning Microsoft's refusal to provide interoperability information to competing workgroup-server operating-system providers and its tying of Windows Media Player to Windows, subject to the specific findings and remedies in the case.

Relevance to modular frameworks:

Competition rules can address exclusion arising from technical incompatibility and control of interfaces.

Interoperability may become legally significant when technical restrictions foreclose competition.

Access remedies require careful attention to necessity, proportionality and incentives to innovate.

A modular regime can combine general competition rules with more specific interface, portability or interoperability duties where justified.

Illustration: If a dominant foundation-model provider prevents rival applications from using necessary interfaces on discriminatory terms, the conduct may warrant competition scrutiny. Whether access must be mandated depends on the applicable legal test and evidence.

The judgment is especially relevant to AI ecosystems built around model APIs, orchestration layers and proprietary software interfaces.

6. Data Protection Commissioner v. Facebook Ireland Ltd and Maximillian Schrems (Schrems II), Case C-311/18 (2020) — European Union

Legal principle: International data transfers and effective protection of fundamental rights.

The CJEU invalidated the EU–US Privacy Shield adequacy decision and retained the validity of standard contractual clauses subject to conditions requiring an assessment of protection in the destination country and, where necessary, supplementary safeguards.

Relevance to modular frameworks:

Cross-border digital services cannot be governed solely by the law of the provider's home jurisdiction.

International-transfer rules must interact with privacy rights, surveillance safeguards and contractual compliance.

A transfer mechanism cannot be treated as sufficient where the actual legal environment undermines effective protection.

Modular systems need procedures for resolving conflicts between international data flows and domestic rights.

Illustration: An AI developer transferring user prompts and sensitive training data to overseas cloud infrastructure must assess applicable transfer rules and the effectiveness of safeguards, rather than relying solely on a contractual clause.

The case demonstrates that regulatory modules must remain effective when technologies and data operate across borders.

7. Internet and Mobile Association of India v. Reserve Bank of India (2020) — India

Legal principle: Proportionality and review of technology-related financial regulation.

The Supreme Court set aside the Reserve Bank of India's 2018 circular that effectively restricted regulated entities from providing banking services to businesses dealing in virtual currencies. The Court found the measure disproportionate in light of the record before it, including the absence of evidence of comparable damage suffered by regulated entities.

Relevance to modular frameworks:

Financial regulation must be supported by an adequate evidential basis.

Regulators may address emerging risks, but the restrictions adopted must be proportionate.

Technology-related uncertainty does not eliminate the need for reasoned decision-making.

A regulator should distinguish between risks to regulated institutions and risks arising from the underlying technology or market.

Illustration: Restrictions on AI-enabled payment services should be linked to identifiable financial, consumer or systemic risks and calibrated to those risks.

The case is relevant to adaptive regulation because it recognises regulatory authority while preserving judicial scrutiny of disproportionate intervention.

8. West Virginia v. Environmental Protection Agency, 597 U.S. 697 (2022) — United States

Legal principle: Limits on expansive interpretations of delegated regulatory authority.

The US Supreme Court applied the major questions doctrine in rejecting the Environmental Protection Agency's asserted authority, under the statutory provision at issue, to implement a generation-shifting scheme for power plants. The Court required clear congressional authorisation for regulatory action of that economic and political significance.

Relevance to modular frameworks:

Legislatures should define the essential policy choices governing transformative technologies.

Delegated rules may implement statutory objectives, but cannot necessarily substitute for legislative authorisation of major policy decisions.

Regulators need clear mandates for imposing extensive obligations on AI, biotechnology or critical digital infrastructure.

Adaptability must not become a justification for unlimited administrative power.

Illustration: An agency introducing economy-wide AI licensing requirements must identify a sufficient legal basis for those requirements rather than relying on general powers unrelated to the measure's scale.

The case highlights the importance of separating legislative decisions about fundamental policy from technical implementation.

9. Loper Bright Enterprises v. Raimondo, 603 U.S. 369 (2024) — United States

Legal principle: Independent judicial interpretation of statutes.

The US Supreme Court overruled Chevron U.S.A. Inc. v. Natural Resources Defense Council (1984), holding that courts must exercise their independent judgment when interpreting statutes and may not defer to an agency merely because a statute is ambiguous.

Relevance to modular frameworks:

Technical expertise does not automatically give a regulator the final word on statutory meaning.

Legislation should clearly specify regulatory objectives, institutional powers and limits.

Standards and guidance must remain consistent with the governing statute.

Courts continue to play a role in maintaining coherence among different regulatory modules.

Illustration: Where a regulator interprets a general statute to impose new obligations on autonomous AI agents, courts must assess the interpretation under the applicable principles of statutory construction rather than automatically accepting the regulator's position.

This case reinforces the importance of legal clarity and judicial oversight in technology regulation.

6. Application to emerging technologies

Modular regulation becomes particularly important where one technological system performs multiple functions or crosses several industries.

TechnologyRelevant legal modulesPrincipal concern
Generative AIData protection, copyright, consumer law, competition, product safetyTraining data, inaccurate outputs, market concentration
Autonomous vehiclesRoad safety, product liability, insurance, cybersecurity, privacyAllocation of responsibility for accidents
Blockchain and DeFiFinancial regulation, consumer protection, AML, data protectionDecentralised control and regulatory accountability
Quantum computingCybersecurity, export controls, intellectual property, privacyCryptographic vulnerability and strategic technology risks
BiotechnologyMedical regulation, bioethics, privacy, product liabilityHuman safety and misuse
Internet of ThingsCybersecurity, product safety, privacy, competitionInsecure devices and ecosystem lock-in
Digital healthcareMedical-device rules, professional standards, privacy, AI governanceUnsafe recommendations and sensitive health data

These modules should operate cumulatively where their requirements are compatible. Where they conflict, the legal framework should establish priority rules, coordination procedures and mechanisms for resolving disputes.

Example: A modular framework for generative AI

Consider a company that develops an AI model, licenses it to third parties and deploys it in a recruitment platform.

Module A — Data governance

Establish lawful data-processing grounds, retention rules, security measures and applicable rights concerning personal information.

Module B — AI risk management

Require suitable testing, documentation, risk assessment and monitoring according to the system's intended use and applicable law.

Module C — Equality and employment law

Address discriminatory outcomes, accessibility, meaningful human review and applicable employee or applicant rights.

Module D — Competition and licensing

Examine restrictive licensing, discriminatory API access, exclusive arrangements and possible foreclosure of competing developers.

Coordination mechanism

Allocate duties among the model developer, system provider and employer; coordinate investigations and preserve effective remedies.

The key principle is that responsibility should be allocated according to the actor's role, actual control, knowledge and applicable statutory obligations. A developer should not automatically be liable for every downstream use, but contractual delegation should not allow actors to evade duties imposed on them by law.

7. Modular regulation in India, the UK and the European Union

India

India's framework combines constitutional safeguards with horizontal and sectoral legislation.

The Information Technology Act, 2000, and associated rules address specified aspects of digital services and intermediary responsibility.

The Digital Personal Data Protection Act, 2023, establishes a statutory framework for digital personal data, subject to its operative provisions and rules.

The Consumer Protection Act, 2019, addresses consumer rights and unfair trade practices.

Sectoral regulators, including the Reserve Bank of India and the Securities and Exchange Board of India, exercise powers within their respective statutory mandates.

Constitutional judicial review provides a constraint on unlawful, arbitrary or disproportionate state action.

The principal design challenge is coordination between these regimes without creating inconsistent duties or weakening fundamental rights.

United Kingdom

The UK combines technology-neutral legislation with sectoral rules and targeted digital regulation.

The UK GDPR and Data Protection Act 2018 govern relevant personal-data processing.

The Digital Markets, Competition and Consumers Act 2024 establishes a regime for designated firms with strategic market status and provides additional competition and consumer-protection powers.

The Online Safety Act 2023 imposes duties on regulated services within its scope.

Product safety, financial services, telecommunications and other sectoral regimes address their respective risks.

A modular approach can help regulators coordinate competition, privacy and online-safety obligations while respecting the boundaries of their statutory powers.

European Union

The EU provides a prominent example of layered digital regulation.

The General Data Protection Regulation addresses personal-data processing.

The Digital Markets Act imposes specified obligations on designated gatekeepers.

The Digital Services Act establishes duties for intermediary services within its scope.

The AI Act introduces a risk-based framework for AI systems and models, with obligations depending on the relevant classification and role.

The EU competition rules under Articles 101 and 102 TFEU continue to apply within their respective legal tests.

These instruments are complementary, not interchangeable. Compliance with one regime does not automatically establish compliance with another. Their interaction requires attention to scope, timing, institutional competence and applicable remedies.

8. Major challenges in modular legal frameworks

A. Regulatory fragmentation

Different regulators may define risk, transparency, explainability or interoperability differently. This creates duplicated reporting and uncertainty.

Solution: Adopt common definitions where feasible, shared reporting mechanisms and formal inter-regulatory coordination procedures.

B. Accountability gaps

A technology's lifecycle may involve developers, cloud providers, model hosts, application developers and end users. Each actor may claim that another controls the relevant risk.

Solution: Define responsibilities by function and control, preserve traceability and establish clear escalation and remediation duties.

C. Regulatory arbitrage

Businesses may relocate activities, divide services across legal entities or structure products to avoid stricter requirements.

Solution: Use coherent jurisdictional rules, anti-circumvention provisions where justified and cooperation between competent authorities.

D. Excessive delegation

Broad powers to issue technical standards or binding directions can raise questions of democratic legitimacy and statutory authority.

Solution: Reserve fundamental policy choices for the legislature, specify the scope of delegated powers and provide transparent consultation and judicial review.

E. Regulatory capture

Dominant firms may influence standards or compliance procedures in ways that favour their proprietary technology.

Solution: Require transparent standard-setting, balanced stakeholder participation, conflict-of-interest safeguards and periodic competition assessments.

F. Technological obsolescence

Detailed legislation can become outdated when technical architectures change.

Solution: Combine durable statutory principles with revisable technical standards, scheduled reviews and evidence-based updates. Material changes in rights or obligations should still receive the legal authorisation required by the applicable system.

G. Conflicting legal objectives

Privacy, competition, cybersecurity, innovation and public safety can point in different directions. For example, interoperability may promote competition but create security or confidentiality risks.

Solution: Require reasoned balancing under the applicable legal tests rather than assuming that one objective automatically overrides all others.

9. A practical model for designing modular technology legislation

A legislature or regulator can use the following sequence.

Identify the technological function. Determine what the system actually does, who operates it and where it is deployed.

Map existing legal obligations. Identify relevant constitutional, horizontal, sectoral and international rules before creating a new regime.

Conduct a risk assessment. Evaluate potential harms, their severity, affected groups, reversibility and likelihood.

Allocate responsibilities. Specify which obligations apply to developers, providers, deployers, intermediaries and public authorities.

Create compatible compliance procedures. Coordinate impact assessments, audits, reporting, recordkeeping and incident notifications where legally permissible.

Provide procedural safeguards. Establish reasons for significant decisions, opportunities to respond, independent review and effective remedies.

Review the framework periodically. Use evidence, enforcement experience, technical developments and public consultation to update rules lawfully.

A well-designed framework should also distinguish between binding legislation, delegated rules, voluntary standards and non-binding guidance. Each has a different legal status, and guidance cannot ordinarily substitute for a statutory power that does not exist.

10. Critical evaluation

Modular frameworks offer three principal benefits.

First, they improve adaptability because one module can be updated without replacing the entire legal structure. Second, they allow specialisation, enabling privacy, competition, safety and financial regulators to apply their respective expertise. Third, they support proportionality by matching obligations to risks rather than imposing identical requirements on every emerging technology.

However, modularity is not inherently superior to comprehensive legislation. Excessive fragmentation can create overlapping compliance duties, inconsistent enforcement and gaps between regulators. Conversely, a single highly detailed statute may become inflexible and fail to accommodate technological diversity.

The strongest approach is therefore a layered, coordinated and rights-based framework: stable foundational principles, specialised sectoral rules, proportionate technical requirements and clear mechanisms for resolving conflicts.

The case law reinforces this approach from different directions. Puttaswamy and Shreya Singhal emphasise constitutional limits; Google Spain and Schrems II illustrate the interaction of digital functions with data-protection rights; Microsoft and Google Shopping demonstrate how established competition principles can address digital-market conduct; and Internet and Mobile Association of India, West Virginia and Loper Bright highlight proportionality, statutory authority and judicial oversight.

11. Conclusion

Modular legal frameworks are a practical response to the rapid evolution of emerging technologies. They enable lawmakers to combine general legal principles with specialised, adaptable rules while maintaining accountability across complex technological systems.

Their success depends not on the number of regulatory modules, but on the quality of their interaction. Effective modular regulation requires clear statutory authority, proportionality, transparent standards, coordinated enforcement, protection of fundamental rights and meaningful access to remedies.

Ultimately, the law should be flexible enough to accommodate innovation, yet sufficiently clear and enforceable to prevent technological change from becoming a justification for arbitrary power, market foreclosure or diminished individual rights.

LEAVE A COMMENT