Author – Mohaned Bahr
The Moment the Pattern Spoke
The Rojas case is invoked here not for its emotional weight but as a single, verifiable event that transformed a contested methodology into an authoritative institutional standard. On 29 June 1892, the people of Necochea, a small town in Buenos Aires, woke to horror. Two murdered children, but their mother, Francisca Rojas, was found injured and alive. Police rushed to the scene and arrested a neighbor based on Rojas’s accusations. At first, the case seemed straightforward, with a suspect and a witness. Yet, the suspect persistently asserted his innocence. Doubts compounded, and the more circumstantial evidence collected, the more the suspect’s ties to the murder became refuted. Until a police officer noticed a tiny bloody thumbprint at the crime scene, and it was sent to Dr. Ivan Vučetić, who had been experimenting with fingerprints as a reliable forensic method for unlocking identities (U.S. National Library of Medicine, n.d.).
Vučetić had always believed a fingerprint could offer forensic science more than it could speak. He noticed that fingerprints consist of a classification of four complex patterns of ridges and furrows, unique to each individual. Vučetić compared the collected bloody thumbprint to Rojas’s fingerprint, and the case was miraculously solved. Rojas was the murderer, and the neighbor’s innocence was confirmed. This was the remarkable moment when a tiny fingerprint became a comprehensive forensic system. It was mandated in Argentina, adopted by Scotland Yard, the New York Police Department (NYPD) and beyond (Datta, 2001).
In today’s world, synthesising the past with the present, we can say that in 1892, fingerprint classification became authoritative because it demonstrated comprehensive reliability and endurance (Buckley, 2024). In 2024, the EU AI Act introduced the most comprehensive AI classification system to date (Boura, 2024). However, where Vučetić’s thumbprints are static, AI evolves faster than law or anything else (Hine & Floridi, 2025; Smuha, 2019). The pace of AI deployment by corporations and states has outrun the regulatory frameworks designed to govern it (Smuha & Yeung, 2024). Hence, we may ponder: Is the EU AI Act the new fingerprint in AI governance? Will it continue to solidify into a global standard? Or will the acceleration of AI innovation, geopolitical competition and alternative regulatory models dilute its influence? This blog post probes this discussion and opens the door to interactive discourse on the future expansion of the EU AI Act to other corners of the world.
From Fingerprints to Algorithms
Prior to Vučetić’s fingerprint classification system, forensic identification in Argentina relied on Bertillonage, a French anthropometric method widely adopted in Europe. The Bertillonage method measured human body dimensions and features to identify suspects. Although imperfect, it was adopted across many European countries (Datta, 2001). Vučetić argued that his fingerprint methodology was more authoritative and reliable, but his work was contested until the Rojas case established fingerprints as key forensic evidence (Datta, 2001). Hitherto, fingerprint identification has remained the reliable standard, having shifted forensic policy, prompted institutions to adopt it and institutionalised scientific fingerprint classification.
The EU AI Act follows the same line. Vučetić’s methodology lacked authority in its early stages, as was probably the case with AI governance before the Act was enacted. AI governance was sporadic across rhetorical recommendations and guidelines, national and institutional frameworks, and subnational-level initiatives, but lacked a consolidated, binding regulatory framework (Smuha & Yeung, 2024). The Rojas case provided authority for Vučetić’s method, proved its validity and conducted its diffusion across the globe. Similarly, the EU AI Act has brought Europe to dominance in AI governance, underpinned by the Brussels Effect and the power of its significant market (Bradford, 2020), consolidating AI principles grounded in the HLEG-AI’s recommendations alongside a market enforcement mechanism (Almada & Radu, 2023; Smuha & Yeung, 2024).
This analogy poses a direct question: is Europe attempting what Vučetić once attempted—turning scattered uncertainty into a consolidated, binding system?
Europe’s Grand Classification Experiment
Vučetić’s methodology did more than just solve the Rojas case. It codified a significant body of scientific research on human anatomy into a single encoded thumbprint that systematically unlocks human identity—a system so authoritative that it became known as vucetichissimo (Datta, 2001). The EU AI Act operates on the same ambition. It is not merely a compliance checklist. It codifies numerous international soft law instruments, for instance, the OECD AI Principles (2019), the UNESCO AI Ethics Recommendations (2024) and HLEG-AI, which carried voluntary weight but lacked binding force (Smuha & Yeung, 2024). Metaphorically, these instruments were akin to a fingerprint voluntarily collected, with no court willing to admit it as uncontested evidence. The EU AI Act is that court.
Given that AI is not a single thing, the EU AI Act adopted the “one size does not fit all” principle and embraced a risk-based approach (Smuha, 2019). Such an approach classifies AI systems into four risk tiers: prohibited risk, high-risk, low-risk and minimal or no risk (Gasiola, 2025), based on proportionality of harm to health, safety and fundamental rights, with a separate regulatory track for general-purpose AI models (Key Issue 3, n.d.). The Act weighs risk and harm, not technology (Justo-Hanani, 2026). That distinction is what makes it a governance philosophy, not just a rulebook.
Just as Vučetić’s system restructured who held authority in criminal forensic investigations, the EU AI Act restructures authority in AI governance, extending binding obligations not only to AI companies but also to public bodies, governments and supranational institutions (Perboli et al., 2025). This is the Act’s regulatory competitive advantage: not a set of scattered provisions, but a whole architectural approach to the AI ecosystem.
Which raises the questions this section was always building toward: will this regulatory power hold? And what would it actually take for the EU AI Act to become a genuine global standard?
The EU AI Act and Rojas’ Case Moment
Before answering the aforementioned question, it is worth noting that authority at inception does not equal authority earned through proof. Vučetić’s methodology gained its decisive legitimacy not from theoretical elegance but from a single, dramatic, publicly verifiable case: the Rojas case. However, the EU AI Act has not yet had its Rojas moment; no enforcement action has yet demonstrated that the Act’s prohibitions carry real consequences. In regulatory practice, authority accumulates gradually, not instantly. For instance, the GDPR followed precisely this trajectory, building its global credibility through landmark enforcement actions: the Schrems II ruling (Cases – InfoCuria – Court of Justice of the European Union, n.d.; Costello, 2020) and the Irish Data Protection Commission’s €1.2 billion fine against Meta (2023) (1.2 Billion Euro Fine for Facebook as a Result of EDPB Binding Decision | European Data Protection Board, n.d.), rather than through a single founding event (Almada & Radu, 2023; Smuha & Yeung, 2024). Perhaps the EU AI Act will likely follow the same path.
In that context, the question worth asking is: “What would the Act’s Rojas moment look like?” Most plausibly, it would take the form of a high-profile prohibited-risk enforcement action under Article 5 (Article 5, n.d.-a), targeting social scoring, subliminal manipulation or real-time biometric surveillance in public spaces, that demonstrates the Act’s prohibitions are not merely declaratory. Until that moment materialises, the analogy holds in architecture but remains incomplete in authority.
The EU AI Act & Brussels Effect Vs Vučetić’s & Bertillon’s Methodology
Speculation about whether the EU AI Act will diffuse as the GDPR did is mixed, with some skeptics and others optimists (Almada & Radu, 2023; Gasser & Almeida, 2017; Smuha & Yeung, 2024). A critical distinction, however, must be drawn between formal diffusion—jurisdictions adopting the Act’s structural architecture—and substantive equivalence—those adoptions actually achieving comparable enforcement outcomes. For instance, Colorado’s AI Act (SB-205) and Brazil’s emerging regulatory framework mirror the Act’s risk-based classification tiers, yet they do not replicate the same enforcement infrastructure that gives the EU its regulatory leverage: a market of over 500 million consumers and institutional capacity built over decades of expertise in technology governance (Bradford, 2020; Almada & Radu, 2023; Shimpo, 2025). This distinction maps directly onto the analogy itself: Bertillonage also spread across jurisdictions—but to those lacking Vučetić’s scientific rigour, it produced unreliable results. Formal adoption without substantive capacity is closer to Bertillonage diffusion than to genuine methodological transfer. Whether the Act’s early adopters will develop the institutional muscle to make the framework work—or whether they will replicate its form without its force—remains an open and consequential question.
Ambivalence and Uncertainty
A recurring objection to this analogy is that fingerprints do not evolve, whereas AI does (Hine & Floridi, 2025). The critique has surface validity but mistakes the analogy’s scope. The fingerprint does not represent the EU AI Act in its entirety; it represents the durability of its risk-based classification logic. Four fingerprint patterns, four risk tiers: just as Vučetić’s taxonomy survived decades of technological change in forensic collection and matching, from ink to digital scanning, a principle-based classification architecture can endure even as the AI-systems it governs accelerate (Hine & Floridi, 2025; Justo-Hanani, 2026; Smuha & Yeung, 2024). Crucially, the Act’s designers anticipated this tension: delegated acts (AI Act Service Desk – Article 97, n.d.), regulatory sandboxes (Article 57, n.d.) and post-market monitoring obligations (Article 72, n.d.) were embedded into the architecture precisely to absorb technological change without dismantling the foundational classification logic (Smuha & Yeung, 2024). Similarly, just as Vučetić’s four-pattern taxonomy survived the transition from ink to digital forensics, the Act’s risk-based core was designed to survive the acceleration it now faces.
The EU AI Act also does not stand alone. It is fiercely competing with the laissez-faire approach championed in parts of the United States and the centralised state model pursued in China (Hine & Floridi, 2025). Both approaches are competing for global hegemony and external projection (CARCHIDI & SOLIMAN, 2024; Smuha, 2019). But this is not the primary challenge. More internally damaging is what comes from within: the EU Commission’s own Digital Omnibus initiative (Digital Omnibus on AI Regulation Proposal | Shaping Europe’s Digital Future, n.d.), which proposes revisions to the Act before it has been fully enforced—something Vučetić never did with his taxonomy before Argentina had finished adopting it. A skeptical reader would treat this as the rock on which the analogy breaks down. But a critical distinction must be drawn. Revision is not inherently fatal—what matters is what is being revised. The Digital Omnibus primarily addresses implementation details: compliance timelines, administrative burdens on SMEs and procedural requirements. It does not, at least in its current form, propose to dismantle the risk-based classification tiers or the prohibited-risk categories under Article 5 (Article 5, n.d.)—the high-risk classification architecture (Article 6, n.d.) that the fingerprint analogy actually represents. If those core elements survive the Omnibus intact, the fingerprint holds. If they do not—for instance, if the Act’s foundational logic is revised before its authority has been earned—then the analogy itself demands a different conclusion: that we may be watching not the fingerprint, but the Bertillonage of our time.
Before concluding, it is worth explicitly naming what would make this analogy fully hold and what would falsify it. The analogy holds if the risk-based classification tiers survive the Digital Omnibus intact, if the Act produces at least one high-profile enforcement action demonstrating that its prohibitions are not merely declaratory and if early adopters develop the institutional capacity to replicate not just the Act’s architecture but its enforcement muscle. Conversely, the Bertillonage conclusion follows if the Omnibus dismantles the foundational classification logic before it has been tested or if a rival regulatory model achieves dominant global projection before the Act’s authority is established. Surfacing and naming these conditions is not a concession to doubt; it is precisely what makes the fingerprint an analytical instrument rather than a rhetorical one.
The Floor Is Now Yours
The fingerprint won. It adapted, spread and remains the gold standard of forensic identification to this day. Whether the EU AI Act can complete that metaphor—surviving the pace of AI innovation, outlasting geopolitical rivalry and proving its reliability before a more agile alternative emerges—is the question this post leaves deliberately open.
So we turn it over to you:
(i) Is the EU AI Act the vucetichissimo of AI governance?
(ii) Are we watching the Bertillonage of our time?
(iii) And who, ultimately, gets to decide the global standard?
References
1.2 billion euro fine for Facebook as a result of EDPB binding decision | European Data Protection Board. (n.d.). Retrieved March 2, 2026, from https://www.edpb.europa.eu/news/news/2023/12-billion-euro-fine-facebook-result-edpb-binding-decision_en.
AI Act Service Desk – Article 97: Exercise of the delegation. (n.d.). Retrieved March 2, 2026, from https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-97.
Almada, M., & Radu, A. (2023). The Brussels Side-Effect: How the AI Act Can Reduce the Global Reach of EU Policy. SSRN Electronic Journal. https://doi.org/10.2139/ssrn.4592006.
Article 5: Prohibited AI Practices | EU Artificial Intelligence Act. (n.d.). Retrieved March 2, 2026, from https://artificialintelligenceact.eu/article/5/.
Article 6: Classification Rules for High-Risk AI Systems | EU Artificial Intelligence Act. (n.d.). Retrieved March 2, 2026, from https://artificialintelligenceact.eu/article/6/.
Article 57: AI Regulatory Sandboxes | EU Artificial Intelligence Act. (n.d.). Retrieved March 2, 2026, from https://artificialintelligenceact.eu/article/57/.
Article 72: Post-Market Monitoring by Providers and Post-Market Monitoring Plan for High-Risk AI Systems | EU Artificial Intelligence Act. (n.d.). Retrieved March 2, 2026, from https://artificialintelligenceact.eu/article/72/.
Boura, M. (2024). The Digital Regulatory Framework through EU AI Act: The Regulatory Sandboxes’ Approach. Athens Journal of Law, 10(3), 385–398. https://doi.org/10.30958/ajl.10-3-8.
Bradford, A. (2020). The Brussels Effect: How the European Union Rules the World (1st ed.). Oxford University PressNew York. https://doi.org/10.1093/oso/9780190088583.001.0001.
Buckley, D. A. (2024, May 3). First murder solved by a fingerprint [Substack newsletter]. The Detective’s Notebook. https://drangelabuckley.substack.com/p/first-murder-solved-by-a-fingerprint.
CARCHIDI, V., & SOLIMAN, M. (2024). THE ROLE OF THE MIDDLE EAST IN THE US-CHINA RACE TO AI SUPREMACY. The Middle East Institute. https://mei.edu/publication/role-middle-east-us-china-race-ai-supremacy/.
Cases—InfoCuria—Court of Justice of the European Union. (n.d.). Retrieved March 2, 2026, from https://infocuria.curia.europa.eu/tabs/affair?sort=AFF_NUM-DESC&searchTerm=%22C-311%2F18.%22&publishedId=C-311%2F18.
Costello, R. Á. (2020). Schrems II: Everything is Illuminated? European Papers – A Journal on Law and Integration, 2020 5(2), 1045–1059. https://doi.org/10.15166/2499-8249/396.
Datta, A. K. (2001). Advances in Fingerprint Technology. CRC Press.
Digital Omnibus on AI Regulation Proposal | Shaping Europe’s digital future. (n.d.). Retrieved February 26, 2026, from https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-ai-regulation-proposal.
Gasiola, G. G. (2025). Rebuilding the pyramid: The AI Act’s risk-based approach using a binary decision diagram. Computer Law & Security Review, 58, 106189. https://doi.org/10.1016/j.clsr.2025.106189.
Gasser, U., & Almeida, V. A. F. (2017). A Layered Model for AI Governance. IEEE Internet Computing, 21(6), 58–62. https://doi.org/10.1109/MIC.2017.4180835.
Hine, E., & Floridi, L. (2025). From No-Win to No-Lose: Journal of AI Law and Regulation, 2(3), 196–211. https://doi.org/10.21552/aire/2025/3/4.
Justo-Hanani, R. (2026). Risk-based approach to EU AI act: Benefits and challenges of co-regulation. Policy Design and Practice, 1–10. https://doi.org/10.1080/25741292.2025.2610869.
Key Issue 3: Risk-Based Approach – EU AI Act. (n.d.). Retrieved February 26, 2026, from https://www.euaiact.com/key-issue/3.
Perboli, G., Simionato, N., & Pratali, S. (2025). Navigating the AI regulatory landscape: Balancing innovation, ethics, and global governance. Economic and Political Studies, 13(4), 367–397. https://doi.org/10.1080/20954816.2025.2569584.
Shimpo, F. (2025). AI Governance and the Future of the Law: International Trends in Developing AI Regulatory Legislation. JAPANESE SOCIETY AND CULTURE, (7). https://doi.org/10.52882/2434-1738-0704.
Smuha, N. A. (2019). From a “Race to AI” to a ’Race to AI Regulation’—Regulatory Competition for Artificial Intelligence. SSRN Electronic Journal. https://doi.org/10.2139/ssrn.3501410.
Smuha, N. A., & Yeung, K. (2024). The European Union’s AI Act: Beyond motherhood and apple pie? SSRN. https://doi.org/10.2139/ssrn.4874852.
U.S. National Library of Medicine. (n.d.). Visible Proofs: Forensic Views of the Body: Galleries: Cases: Juan Vucetich and the origins of forensic fingerprinting [Exhibitions]. Retrieved February 25, 2026, from https://www.nlm.nih.gov/exhibition/visibleproofs/galleries/cases/vucetich.html.
Image Attribution
Generated by: ChatGPT 5.2
Date: 25 February 2026
Prompt: “A dramatic cinematic split composition. On the left half, a close-up of an ink-stained thumbprint pressed onto aged, yellowed parchment paper, lit with warm sepia and amber tones, evoking 1890s forensic science. On the right half, the same fingerprint ridge pattern dissolves and transforms into glowing electric blue neural network nodes and circuit lines against a deep dark navy background. In the centre where both halves meet, the fingerprint ridges flow seamlessly from analog ink into digital data streams. The mood is authoritative, intellectual and cinematic. No text. No people. Photorealistic with subtle cinematic color grading.” -Photo prompt created by Claud Sonnate 4.6