Do Not Protect Us From the Power to Protect Ourselves

The EU AI Act, the Right to Cognitive Assistance and why restoring human agency must not become “high-risk”

Something potentially very important is happening in European AI regulation.

And almost nobody outside the AI policy world appears to be talking about it.

The EU AI Act is no longer a proposal. It is law.

What remains unsettled is how some of its most important provisions will be interpreted.

On 19 May 2026, the European Commission published draft guidelines explaining how it intends to classify “high-risk” AI systems under Article 6 of the Act. The Commission says the guidelines will help providers and deployers determine whether their systems fall within the high-risk regime. Although the guidelines themselves are not legally binding, the Commission explicitly says they reflect its interpretation and will guide enforcement. The latest targeted consultation closed on 23 July 2026, with the final version still to follow.

That sounds technical.

It isn’t.

It could determine something much more fundamental:

How much intelligence ordinary citizens are allowed to have on their side.

And that matters because artificial intelligence may be about to alter one of the oldest power imbalances in modern society.

For generations, institutions have possessed vastly greater analytical capability than the individuals dealing with them.

Banks have lawyers, actuaries, credit models and compliance departments.

Employers have HR departments and recruitment systems.

Insurers have underwriting models.

Government departments have policy teams and administrative machinery.

Financial institutions have product specialists, lawyers, economists and data.

A citizen generally has themselves.

AI changes that.

For the first time, an ordinary person can increasingly place a complicated letter, contract, pension statement, credit decision, employment dispute, insurance rejection, court bundle or investment proposition in front of an intelligent system and say:

Explain this to me.

What assumptions are being made?

What doesn’t add up?

What evidence supports their conclusion?

What rights might I have?

What questions should I ask?

What are my options?

Help me make my own decision.

That isn’t artificial intelligence replacing human agency.

It is artificial intelligence restoring it.

And we need to be extremely careful that regulation designed to protect citizens from AI does not instead protect powerful institutions from citizens using AI.


Read the legislation: EU Artificial Intelligence Act
Read the proposed interpretation: Draft Guidelines on High-Risk AI Systems
Read the consultation: Targeted Consultation on the Draft Guidelines


We’ve tried the alternative

There is an assumption lurking beneath much consumer protection policy:

institutions can be regulated effectively enough that citizens do not need equivalent analytical capability themselves.

British experience should make us very cautious about that assumption.

Payment protection insurance alone ultimately resulted in more than £38.3 billion being returned to customers following complaints about how PPI was sold.

In motor finance, the FCA has now established an industry-wide redress scheme concerning customers it says were treated unfairly between 2007 and 2024, although parts of that scheme are currently subject to legal challenge.

Authorised Push Payment fraud became sufficiently serious that an entirely new mandatory reimbursement regime was required. In the first 18 months of that regime, around £316 million had already been reimbursed to victims.

Investment and pension complaints have likewise generated substantial continuing redress.

These are not arguments for abolishing regulation.

They demonstrate something more important:

regulation is not a substitute for citizen capability.

Regulators act after rules have been designed.

Supervisors act after markets have developed.

Ombudsmen act after disputes arise.

Compensation schemes frequently arrive after harm has occurred.

The person exposed to the decision is there from the beginning.

Why would we not want that person to have the greatest possible lawful capacity to understand what is happening to them?

The AI Act identifies exactly the areas where citizens need more agency

Look at the fields covered by Annex III of the AI Act.

Education.

Employment.

Creditworthiness.

Life and health insurance.

Access to essential public services and benefits.

Law enforcement.

Migration and asylum.

Administration of justice.

These systems can be classified as high-risk because decisions in these areas can profoundly affect people’s lives.

That rationale makes sense.

An employer using AI to determine who gets a job deserves scrutiny.

A bank using AI to determine someone’s creditworthiness deserves scrutiny.

A government department using AI to determine whether someone receives an essential benefit deserves scrutiny.

A judicial authority using AI to assist the application of law to facts deserves scrutiny.

But now reverse the direction.

What if the applicant uses AI to scrutinise the recruitment decision?

What if the borrower uses AI to interrogate the credit assessment?

What if the claimant uses AI to challenge the benefits decision?

What if the Litigant in Person uses AI to understand the law, organise thirty years of evidence and present a coherent case?

The subject matter hasn’t changed.

But the direction of power has.

That distinction is missing from much of the debate.

AI that decides about you is not the same as AI that helps you decide

Consider two systems.

A bank uses AI to evaluate whether Maria is creditworthy.

Maria uses AI to evaluate whether the bank has treated her fairly.

Both involve credit.

Both may analyse financial information.

Both may materially influence what happens next.

But they are not socially equivalent.

The first increases the institution’s capability to make a consequential determination about Maria.

The second increases Maria’s capability to understand, challenge and respond to that determination for herself.

Or take employment.

An employer asks:

Rank these 500 applicants and tell me whom to reject.

An applicant asks:

Compare my qualifications with the published requirements, explain why I may have been rejected and help me decide whether to challenge the decision.

Again, both concern recruitment.

Only one exercises institutional power over somebody else.

This gives us a distinction we are going to need repeatedly in the age of AI:

Decision-making AI

AI used to exercise consequential power over another person.

Decision-enabling AI

AI used to increase a person’s capacity to understand, choose and act for themselves.

The first may diminish human agency.

The second may restore it.

Regulation must know the difference.

The danger of the “general-purpose assistant”

This is where the Commission’s interpretation becomes important.

The Act defines an AI system’s “intended purpose” by reference to the use intended by its provider, including its documentation, instructions and promotional material. It separately defines “reasonably foreseeable misuse” as behaviour outside that intended purpose which can nevertheless reasonably be anticipated.

Those are different concepts for a reason.

Yet general-purpose AI systems create an obvious regulatory dilemma.

ChatGPT, Claude and similar assistants can perform thousands of different tasks.

One user might ask:

Help me understand this rejection letter.

Another might ask:

Rank these applicants so that I can decide whom to employ.

The second deployment could enter Annex III employment territory.

But does that mean the entire general-purpose assistant should effectively be treated as though recruitment selection were its intended purpose?

If the answer drifts towards yes, AI providers face a predictable commercial choice:

comply with the extensive obligations applying to high-risk systems,

or stop the system performing certain categories of task.

That creates what we might call the:

Provider Chilling Effect

Capability → foreseeable regulated use → regulatory exposure → guardrail → lost citizen capability.

The guardrail may successfully prevent an employer from asking a general-purpose AI to rank candidates.

But what happens if it also prevents the candidate asking that same AI to scrutinise how they were treated?

That is not a theoretical concern we should brush aside.

It should be explicitly designed against.

Because otherwise we could create this extraordinary situation:

Your employer may have sophisticated systems analysing you.

Your bank may model you.

Your insurer may price you.

Government may assess you.

Large institutions may retain lawyers, consultants and proprietary technology.

But your personal AI assistant becomes progressively constrained in helping you interrogate them.

That would deepen information asymmetry in the name of reducing AI risk.

What does this mean for Academy OS?

This question isn’t abstract for us.

The Academy of Life Planning is building precisely the kind of technology that challenges traditional information asymmetry.

Academy OS and our wider tool suite are designed to help citizens examine evidence, understand financial propositions, investigate exploitation, organise disputes, identify assumptions and make their own decisions.

They include tools such as BIG Checker, The Leveller, Goliathon, Investigator and Recoverer.

Their purpose is not to make institutional decisions about other citizens.

Their purpose is to give the citizen sitting on the weaker side of the informational relationship greater analytical capability.

But that does not automatically place the Academy outside the AI Act.

The Act defines a “provider” broadly. It includes a person or organisation that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark — whether paid for or provided free. The Regulation can also apply to third-country providers where systems are placed on the Union market or where relevant outputs are used in the Union.

So simply building an Academy app on top of somebody else’s foundation model does not necessarily mean:

“OpenAI is the provider, therefore the Academy has no provider responsibilities.”

There may be an upstream model provider and a separate provider of the downstream AI system.

And Article 25 specifically anticipates circumstances in which someone modifying the intended purpose of an existing AI system — including a general-purpose AI system — can become the provider of a resulting high-risk system.

We therefore need to take this seriously.

We will obtain specialist legal advice as implementation develops.

But we should also challenge the policy itself where necessary.

Because imagine being told that Goliathon must be constrained from helping a Litigant in Person analyse evidence because administration of justice appears in Annex III.

Imagine Investigator being constrained from helping a scam victim reconstruct what happened.

Imagine BIG Checker being prevented from analysing institutional communications because the resulting understanding could materially affect someone’s financial decision.

Imagine an AI system being permitted to help a financial institution formulate its position, while the consumer’s equivalent analytical assistant is disabled from challenging it.

That would be perverse.

The correct response isn’t to weaken safeguards against institutional AI.

It is to recognise an additional human right for the AI age.

The Right to Cognitive Assistance

We should establish a simple principle:

A natural person should be free to use lawful artificial intelligence to understand information, analyse decisions affecting them, evaluate alternatives, exercise legal and contractual rights, challenge institutional decisions and make their own decisions.

AI has reduced the cost of sophisticated cognitive assistance towards zero.

That may prove to be as socially significant as mass literacy, public libraries, universal education or widespread internet access.

For centuries, knowledge asymmetry has been a source of institutional power.

Professionals knew things ordinary people didn’t.

Institutions possessed information citizens couldn’t access.

Complexity itself became a barrier.

AI changes the economics of understanding.

It can give millions of people something previously available primarily to governments, corporations and wealthy individuals:

a capable analytical assistant.

We should be extraordinarily reluctant to take that away.

Six changes Europe should make

The Commission still has an opportunity to make the high-risk interpretation consistent with the Act’s human-centric purpose.

We propose six changes.

1. Create a Personal Agency Safe Harbour

The guidelines should state explicitly that an AI system does not become high-risk merely because it assists a natural person to understand, prepare for, respond to or challenge a consequential decision affecting that person.

A borrower analysing their own credit decision is not a lender determining somebody else’s creditworthiness.

An employee challenging their dismissal is not an employer deciding whom to dismiss.

A Litigant in Person preparing their case is not a court exercising judicial authority.

Same domain. Different direction of power.

2. Introduce a Direction-of-Power Test

High-risk classification should ask not simply:

What subject is this AI dealing with?

but:

Who is exercising consequential power over whom?

Where AI increases an institution’s capacity to evaluate, rank, price, reject, investigate, punish or otherwise determine an outcome about another person, strong safeguards are justified.

Where AI increases a person’s capacity to understand and respond to something being done to them, the presumption should run in favour of access.

This is the missing axis in AI risk classification:

direction of power.

3. Protect the Right to AI-Assisted Contestability

Where institutions use AI in consequential processes, affected citizens should have an explicit right to use AI to interrogate those processes.

Not merely a right to receive an explanation.

A right to analyse the explanation.

Not merely a right to receive documents.

A right to interrogate the documents.

Not merely a right to appeal.

A practical right to acquire the cognitive assistance necessary to exercise that appeal effectively.

The principle should be simple:

If an institution can use computation to make or support a decision about you, you must be free to use computation to challenge it.

4. Keep “intended purpose” separate from “foreseeable misuse”

A general-purpose assistant should not be transformed into an employment-selection system simply because somebody could misuse it to select employees.

The Act itself distinguishes the provider’s intended purpose from reasonably foreseeable misuse.

That distinction must survive implementation.

Regulate the prohibited or high-risk deployment.

Do not automatically eliminate the underlying capability for everybody else.

Otherwise one institutional misuse can become the justification for removing legitimate capability from millions of citizens.

5. Require Agency-Preserving Guardrails

Guardrails should be targeted.

Stopping an AI system making an unlawful discriminatory employment decision does not require stopping a worker analysing whether discrimination occurred.

Stopping automated credit decisions without appropriate safeguards does not require stopping a borrower analysing their mortgage.

Protecting judicial integrity does not require intellectually disarming a Litigant in Person.

The Commission should adopt a principle of minimum agency impairment:

Any restriction imposed to mitigate AI risk should preserve, so far as reasonably possible, the capability of natural persons to understand, question, challenge and decide for themselves.

Guardrails should prevent harmful exercises of power.

They should not prevent lawful resistance to that power.

6. Introduce an Agency Impact Assessment

AI regulation understandably asks:

What harm might occur if this capability exists?

It must also ask:

What harm might occur if citizens are denied this capability?

Every proposed restriction affecting general-purpose AI should therefore consider:

  • whether institutional information advantages will increase;
  • whether affected people will find decisions harder to understand;
  • whether contesting decisions will become more expensive;
  • whether professional dependency will increase;
  • whether access to justice will deteriorate;
  • whether citizens will become less capable of detecting exploitation;
  • and whether regulated institutions retain analytical capability that affected individuals are denied.

There are two kinds of AI risk.

The risk created by capability.

And:

the risk created by capability deprivation.

Responsible regulation must consider both.

This is bigger than AI safety

There is a deeper question here.

Who gets intelligence?

For most of history, sophisticated analytical capability has been scarce.

It belonged disproportionately to governments, corporations, wealthy households and professions.

Artificial intelligence is changing that distribution.

That is why this debate cannot simply be framed around what AI might do wrong.

We must also ask what happens when ordinary people finally possess tools capable of challenging expertise, interrogating authority and understanding systems that have historically been opaque to them.

The institutions being challenged will frequently know more.

Sometimes they will be right.

Sometimes the citizen will be wrong.

AI will make mistakes too.

None of that justifies preserving ignorance.

The answer to imperfect citizen understanding is better cognitive assistance, critical thinking and human agency — not returning ordinary people to informational dependence.

Europe says the AI Act is intended to protect fundamental rights and create human-centric artificial intelligence. High-risk systems include precisely those contexts where enormous power can be exercised over people’s lives.

So let us carry that principle to its logical conclusion.

An AI Act worthy of a human-centric society should regulate artificial intelligence according to the direction in which power flows.

When AI exercises power over a person, demand safeguards.

When AI gives that person greater capacity to understand, choose and act, protect their right to use it.

That is the principle the Academy of Life Planning will campaign for.

The Right to Cognitive Assistance.

Because restoring human agency in the age of AI does not mean replacing one powerful intermediary with an artificial one.

It means giving people enough capability to understand what is happening, enough knowledge to question it, and enough confidence to make their own decisions.

After decades of scandals, redress schemes and retrospective consumer protection, we should have learned something important:

citizens cannot outsource all responsibility for protecting their interests to regulatory architecture.

They need capability of their own.

Artificial intelligence finally gives us the opportunity to provide it at scale.

Do not protect citizens from having the capacity to protect themselves.


Addendum: What Does This Mean for UK Citizens?

The UK has left the European Union. The EU AI Act therefore does not automatically govern every AI system used by a British citizen in Britain.

That does not mean UK citizens can ignore what is happening in Europe.

The EU AI Act has deliberately broad territorial reach. It applies not only to providers established inside the EU, but also to providers outside the EU where they place AI systems on the EU market, and in some circumstances where the output of an AI system operated outside the EU is used inside the Union. (EUR-Lex)

For British citizens, there are therefore two separate issues.

The first is legal.

A UK-only AI service used exclusively in Britain will principally sit within the UK’s own regulatory framework. Britain currently operates a different model from the EU: rather than creating a single horizontal AI classification regime, the UK has largely asked existing regulators to apply principles and existing law within their respective sectors. Government guidance has described this as a pro-innovation, regulator-led approach. (GOV.UK)

But a British company offering AI services into the EU may still come within the EU AI Act.

That matters for UK developers, including organisations such as the Academy of Life Planning. A service does not necessarily escape European regulation simply because its servers, company or developers are in Britain.

The second issue may ultimately be more important.

The Brussels effect does not stop at the border

Large AI companies are unlikely to design every capability independently for every country.

If European regulation makes a particular class of assistance expensive, legally risky or difficult to provide, providers may respond by introducing restrictions at model or platform level.

Those restrictions could then affect British users too.

This is not something the AI Act itself requires. It is a possible commercial consequence of global technology providers designing products around major regulatory markets.

The risk therefore looks like this:

EU classification → provider compliance risk → general-purpose guardrail → capability removed more widely → UK citizen loses cognitive assistance.

A British citizen may never be legally subject to the EU AI Act and still experience its consequences through the AI assistant they use.

That is why this is not merely a Brussels policy debate.

Britain has a choice

The UK should not simply wait to see what European AI regulation produces and then inherit the resulting product architecture.

It can establish its own principle.

We propose that Britain explicitly recognise a:

Right to Cognitive Assistance

A UK citizen should be free to use lawful AI to:

understand information;

analyse contracts and financial products;

interrogate decisions made about them;

identify inconsistencies and missing evidence;

compare options;

prepare complaints and appeals;

understand legal and regulatory material;

organise their evidence;

question professional or institutional assertions;

and ultimately make their own decisions.

The distinction should be based upon the direction of power.

If an employer uses AI to decide whether somebody gets a job, safeguards may be appropriate.

If the applicant uses AI to understand why they were rejected, that capability should be protected.

If a lender uses AI to determine somebody’s creditworthiness, regulate that exercise of power.

If the borrower uses AI to understand and challenge the decision, protect their ability to do so.

If government uses AI to determine someone’s entitlement to a public service, demand accountability.

If the citizen uses AI to understand the rules and appeal the decision, protect that assistance.

If a court or institution uses sophisticated technology to analyse a case, the citizen appearing before it should not be technologically disarmed.

Same technology.
Same subject matter.
Opposite direction of power.

That distinction matters.

The UK should go further than merely regulating AI safely

Government policy repeatedly talks about Britain becoming an AI leader and encouraging adoption and innovation. The existing UK approach gives sector regulators considerable discretion rather than imposing the EU’s single high-risk architecture. (GOV.UK)

That creates an opportunity.

Britain could become the jurisdiction that explicitly protects citizen cognitive sovereignty.

We speak increasingly about sovereign AI: British compute, British infrastructure, British models and Britain’s ability to act independently in a strategically important technology.

But sovereignty should not stop at the state.

A citizen can also be cognitively dependent.

Dependent upon their bank to explain the bank’s product.

Their pension provider to explain their pension.

Their employer to explain the employer’s decision.

Their insurer to explain the insurer’s assessment.

Their regulator to discover misconduct.

Their lawyer to understand the law.

Their adviser to understand their finances.

That dependency has enormous consequences when the institution possesses substantially more knowledge, expertise and resources than the person affected by its decisions.

AI provides the first realistic opportunity to reduce that asymmetry at population scale.

So Britain should establish another form of sovereignty:

Citizen cognitive sovereignty — the practical ability to understand, question and act without being unnecessarily dependent upon the institution on the other side of the decision.

Regulation alone is not enough

The history of British consumer protection should make this obvious.

Citizens cannot outsource all responsibility for protecting their interests to regulatory architecture.

Regulators are necessary.

Rules are necessary.

Professional standards are necessary.

But none of them eliminates information asymmetry, conflicts of interest, institutional failure or human error.

And often the citizen only discovers that something has gone wrong years after the original decision.

The alternative is not deregulation.

It is regulation plus capability.

Protect people from institutions abusing AI.

And simultaneously give people the capability to protect themselves.

That produces a distinctly British policy proposition:

No lawful use of artificial intelligence by a citizen to understand, scrutinise, challenge or respond to a consequential decision affecting them should be prohibited or materially impaired merely because institutional use of AI in the same domain is classified as high-risk.

The European Commission is currently working through exactly how the AI Act’s high-risk classification should operate. Its draft guidelines are intended to influence how providers, deployers and enforcement authorities interpret Article 6 and Annex III, with final guidelines expected by the end of 2026. (Digital Strategy)

Britain should watch that process closely.

But it should not merely copy it.

It should articulate the principle Europe currently risks overlooking:

When AI exercises power over a citizen, regulate the power.

When AI gives the citizen greater power over their own life, protect the capability.

That is what the Right to Cognitive Assistance should mean for UK citizens.

And perhaps the simplest test for British AI policy is this:

Will this rule leave the citizen more capable of understanding, choosing and acting — or less?

Because an AI policy that protects institutions while leaving citizens dependent has misunderstood the problem.

Do not protect us from the power to protect ourselves.

Leave a comment