EU AI Act, WCAG 2.2 with a WCAG 3.0 Horizon, and GDPR for Design Leaders
Three regulatory regimes now sit underneath every AI-augmented design decision your team makes, and if you cannot translate them into something a designer can act on by Friday, you will either freeze your team with fear or expose your company to fines neither of you saw coming. The EU AI Act governs what user-facing AI features your team is allowed to build and what they must disclose. WCAG 2.2 governs whether the screens your team ships, including the ones a model generated, are legally usable. GDPR Article 22 governs whether an AI system is allowed to make a decision about a user without a human in the loop. These are not three separate compliance problems handled by three separate teams. They converge on the interface, which is to say they converge on you. This lesson translates each regime into a concrete design-team compliance pattern, separates what is settled law from what is still a working draft, and hands you a one-page compliance reference your team can pin next to the WCAG audit checklist and actually use.
Why a Design Leader Has to Own This, and Cannot Outsource It
The instinct is to treat regulation as legal's problem. That instinct is wrong for a specific structural reason. Legal can tell you that the company has an obligation under the EU AI Act to disclose when a user is interacting with an AI system. Legal cannot tell you whether the disclosure on screen three of your onboarding flow actually communicates that to a human being, or whether it is buried in a footer nobody reads. Legal can tell you that WCAG 2.2 Level AA is the standard. Legal cannot run the audit, because the audit requires reading a generated screen against contrast ratios and focus criteria, which is design work. Legal can tell you GDPR Article 22 restricts solely automated decisions. Legal cannot design the human-in-the-loop interface that satisfies it.
Each of these regimes states an obligation in legal terms and is satisfied or breached in design terms. The translation layer between the two is the design leader's job, and there is no one else positioned to do it. If you wait for legal to hand you compliant designs, you will wait forever, because legal does not produce designs. If you let your team treat compliance as someone else's department, you will ship the violation and find out when the complaint arrives. The compliance one-pager you build in this lesson is the translation layer made durable: it converts three bodies of law into a checklist a designer runs against a screen.
The EU AI Act: What It Actually Governs for Designers
The EU AI Act entered into force in August 2024, and its obligations phase in over several years, with prohibited practices and AI-literacy duties applying first in early 2025, general-purpose-AI obligations from August 2025, and the bulk of the high-risk system requirements applying through 2026 and 2027. The Act is risk-tiered: it sorts AI systems into unacceptable risk (banned), high risk (heavily regulated), limited risk (transparency obligations), and minimal risk (largely unregulated). For a design leader, the two tiers that matter are high risk and limited risk, because those are where the design obligations live.
High-Risk Classification and What It Demands of the Interface
High-risk systems are the ones whose AI makes or materially informs a consequential decision about a person: credit scoring, hiring, access to essential services, certain biometric and safety uses. Most consumer product design will not be building a high-risk system, but the moment your product uses AI to gate access to something that matters in a person's life, you may be inside this tier, and the design obligations are real. High-risk systems require human oversight that is meaningful, not nominal, which is a design problem: the interface has to let a human actually understand, review, and override the AI's output, not just click "approve" on a decision they cannot interrogate. They require transparency about the system's capabilities and limitations, which the interface has to surface. The design pattern here is the meaningful-oversight interface: when AI informs a consequential decision, the screen must give the human reviewer the information, the time, and the genuine ability to disagree.
Limited Risk and the Transparency Obligation Most Designs Hit
This is the tier that touches almost every team building user-facing AI. The Act's transparency obligations require that users be told when they are interacting with an AI system (a chatbot, an AI assistant), and that AI-generated or AI-manipulated content, including synthetic images and deepfakes, be disclosed as such. For a design leader, this is the most common compliance surface you will own, and it is pure interface design. The pattern is the honest-disclosure standard: a user must be able to tell, without effort, that they are talking to a machine and that an image or piece of content was AI-generated. A disclosure that technically exists but is buried, tiny, or worded to be missed satisfies the letter and fails the intent, and increasingly fails the letter too, because regulators are reading "transparency" to mean transparency a real user perceives.
WCAG 2.2: The Settled Floor, and Why the EU Made It Mandatory
WCAG 2.2 became a W3C Recommendation in October 2023, and it is the one regime in this lesson that is fully settled, fully specified, and directly testable. It matters legally because the EU's accessibility law points at it. The Web Accessibility Directive made WCAG-aligned conformance mandatory for EU public-sector websites and apps, and the European Accessibility Act extended accessibility obligations to a broad range of private-sector products and services, with its core requirements applying from June 2025. In practice, WCAG 2.2 Level AA is the conformance target that satisfies these obligations, which means for any product touching EU users, the criteria in WCAG 2.2 are not best practice; they are the law.
You already know how to audit against WCAG 2.2 from the L2 and L3 work. What changes at L5 is that you own it as a compliance obligation, not just a craft standard, and you own it specifically for AI-generated output, which fails these criteria far more often than hand-built work. The criteria a generated screen most reliably violates are worth naming because they belong on the one-pager: 1.4.3 contrast at 4.5:1 for normal text and 3:1 for large text, 2.4.11 focus appearance, 2.5.8 target size at a 24-by-24 CSS pixel minimum, and 2.3.3 animation from interactions for generated motion. The compliance pattern is the mandatory-audit gate: no AI-generated or AI-assisted customer-facing screen ships to EU users without passing a WCAG 2.2 Level AA audit against these criteria, owned by design.
The WCAG 3.0 Horizon, and Why You Must Not Overclaim It
Here is where design leaders get themselves in trouble by sounding more current than the facts support. WCAG 3.0 exists, it is genuinely promising, and it is not law. As of 2026 it remains a W3C Working Draft, not a Recommendation. It proposes a different conformance model, scoring rather than the binary pass/fail of A/AA/AAA, and it is still years from stabilizing, with substantial parts in flux. You should read it as a signal of where accessibility thinking is heading, and you should build nothing on it as if it were settled. The honest framing for your team and your governance committee is precise: WCAG 2.2 Level AA is the conformance target today and the one your compliance obligations point at; WCAG 3.0 is a Working Draft worth watching so you are not surprised, but it is not a standard you conform to and not something to put in a compliance commitment. Overclaiming WCAG 3.0 readiness is the kind of error that destroys your credibility with both legal and engineering, because both can check.
Every one of these regimes states its obligation in the language of law and is satisfied or breached in the language of design. The translation between the two is not legal's job and not engineering's job. It is the design leader's job, and there is no one else positioned to do it.
GDPR Article 22: The One Most Designers Have Never Read
GDPR has been in force since 2018, and most designers know it as the cookie-banner law. Article 22 is the part that matters for AI design, and almost no designer has read it. It gives a person the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects on them. Translated: if your product uses an AI model to make a consequential decision about a user with no meaningful human involvement, the user has a right to object, to obtain human intervention, to express their point of view, and to contest the decision.
The reason this lands on design is that "meaningful human involvement" and "the ability to contest" are interface properties. An AI that auto-rejects a loan application or auto-flags a user account or auto-prioritizes who gets access to a limited resource, with no human in the loop and no way for the user to push back, can violate Article 22. The fix is a design pattern, not a legal memo: the contestability interface. When AI makes a significant decision about a user, the design must surface that an automated decision was made, explain it in terms the user can understand, and provide a genuine, findable path to human review and objection. A "contact support" link buried three levels deep does not satisfy this. A clear "this decision was made automatically; request a human review here" does.
Where Personalized UI Quietly Triggers Article 22
The subtle case, and the one most likely to catch a product design team off guard, is AI-personalized UI. If your product reshapes what a user sees, what offers they get, what content is surfaced, based on an automated profile, you are profiling, and depending on the effect, you may be inside Article 22's scope. Most personalization is low-stakes and outside the "legal or similarly significant effects" threshold; a recommended-articles module is not an Article 22 problem. But a system that decides which users see a better price, or which users are shown a restricted set of options, or which users get gated out of a feature, based on an automated profile, can cross the line. The design pattern is to treat consequential personalization as an Article 22 candidate: ask, for any AI-driven differential treatment, whether it produces a significant effect, and if it might, build the disclosure-and-contest path before it ships, not after the complaint.
The Convergence: Where All Three Meet on One Screen
The reason this lesson treats the three regimes together rather than as separate compliance tracks is that they converge, and the convergence is where design adds value no single-regime specialist can. Consider an AI feature that personalizes a user's account dashboard, makes an automated eligibility decision, and presents it through a generated interface. That one feature touches all three: the EU AI Act's transparency obligation (the user must know AI is involved), GDPR Article 22 (the automated decision must be contestable), and WCAG 2.2 (the generated screen must be accessible). A legal team handling each regime in isolation will miss that the same disclosure surface, the same screen, has to satisfy all three at once, and that the design of that one surface is the single point where compliance succeeds or fails.
This convergence is precisely the design leader's leverage. You are the only person who sees the screen as the user sees it, holds all three obligations in view simultaneously, and can design the one interface that satisfies them together: an honest AI disclosure, a contestability path, and full WCAG 2.2 conformance, integrated rather than bolted on as three separate compliance widgets. Done badly, each obligation becomes a separate banner and the screen becomes a compliance junkyard. Done well, the disclosure, the contest path, and the accessibility are coherent parts of one designed experience. That coherence is craft, and it is craft that legal cannot supply.
Building the Compliance One-Pager
The artifact is a single page your team pins next to the design-review checklist. It is not a legal document and does not try to be; it is a design-team translation of three regimes into questions a designer can answer about a screen. The structure that works has three sections, one per regime, each reduced to a trigger and a pattern.
The EU AI Act section: the trigger is "does this feature use AI to interact with the user or to inform a consequential decision?" If yes, two patterns apply. For interaction or generated content, the honest-disclosure standard: the user can tell without effort that AI is involved. For consequential decisions, the meaningful-oversight standard: a human can genuinely understand, review, and override. The one-pager names the disclosure as a perceivable element, not a buried footnote.
The WCAG 2.2 section: the trigger is "is this a customer-facing screen, especially one AI generated?" If yes, the mandatory-audit gate against the named criteria: 1.4.3 contrast, 2.4.11 focus, 2.5.8 target size, 2.3.3 animation. The one-pager states plainly that WCAG 2.2 Level AA is the conformance target and that WCAG 3.0 is a Working Draft to watch, not to conform to, so nobody on your team overclaims it.
The GDPR Article 22 section: the trigger is "does AI make a significant decision about a user with no meaningful human involvement, including consequential personalization?" If yes, the contestability-interface pattern: disclose that an automated decision was made, explain it understandably, and provide a findable path to human review and objection. The one-pager flags that consequential personalization is a candidate, not an automatic exemption.
How to Make the One-Pager Survive Contact With a Real Team
A one-pager that lists obligations gets ignored. A one-pager built as triggers and patterns gets used, because a designer can run it against a screen in two minutes: does this feature trip the trigger, and if so, is the pattern present? Keep it to the triggers and patterns, push the legal detail into a linked appendix legal owns, and date it, because these regimes are phasing in and the dates move. Review it quarterly against the AI Act's phase-in schedule and any movement in the European Accessibility Act's enforcement, and have legal sign off on the appendix so the one-pager has authority when an engineer or a PM pushes back. The one-pager is the durable form of the translation layer; the discipline of keeping it current is what keeps it from becoming a stale artifact that gives false confidence.
The Failure Modes to Name for Your Team
Two failure modes bracket this work, and a design leader has to steer between them. The first is compliance theater: the disclosure that technically exists but is designed to be missed, the contest link buried where no one finds it, the WCAG audit run once and never again. Theater satisfies a checklist and fails a user and, increasingly, a regulator who reads intent. The second is compliance paralysis: a team so frightened of the AI Act that it refuses to ship AI features at all, or so confused about Article 22 that it treats every recommendation module as a legal landmine. Paralysis is as much a failure as theater, because it forfeits the value AI offers out of an unexamined fear.
The way between them is exactly the one-pager: precise triggers that tell the team when an obligation actually applies, so they neither over-comply on low-stakes features nor under-comply on consequential ones, and clear patterns that tell them what compliance looks like when it does apply. The design leader's job is not to make the team afraid of regulation and not to make them dismissive of it. It is to make them precise about it, which is what turns three intimidating bodies of law into a routine two-minute check on a screen.
Key Takeaways
- Three regimes sit under every AI-augmented design decision and converge on the interface: the EU AI Act (what user-facing AI you can build and must disclose), WCAG 2.2 (whether your screens are legally usable), and GDPR Article 22 (whether AI may decide about a user without a human in the loop). Each states its obligation in legal terms and is satisfied or breached in design terms, so the translation is the design leader's job and cannot be outsourced to legal.
- The EU AI Act is risk-tiered. High-risk systems demand a meaningful-oversight interface where a human can genuinely understand and override the AI. The far more common limited-risk tier demands the honest-disclosure standard: a user can tell without effort that they are interacting with AI or viewing AI-generated content, and a buried disclosure fails both the intent and increasingly the letter.
- WCAG 2.2 Level AA is the settled floor and is law for EU users via the Web Accessibility Directive and the European Accessibility Act (core requirements from June 2025). AI-generated screens fail it constantly; the mandatory-audit gate covers 1.4.3 contrast, 2.4.11 focus, 2.5.8 target size, and 2.3.3 animation.
- WCAG 3.0 is a W3C Working Draft, not a Recommendation, and proposes a scoring model still in flux. Read it as a horizon signal, build nothing on it as settled, and never put WCAG 3.0 readiness in a compliance commitment, because overclaiming it destroys credibility with legal and engineering.
- GDPR Article 22 gives users the right not to be subject to solely automated decisions with significant effects, satisfied by the contestability interface: disclose the automated decision, explain it understandably, and provide a findable human-review path. Consequential AI-personalized UI is an Article 22 candidate, not an automatic exemption.
- The three converge on single screens, which is the design leader's leverage: only design holds all three obligations in view at once and can integrate honest disclosure, a contest path, and WCAG conformance into one coherent experience rather than a compliance junkyard. Build the one-pager as triggers and patterns, date it, review it quarterly, and steer the team between compliance theater and compliance paralysis by making them precise about when each obligation applies.
Skill.re