FCC Robot Import Ban, ChatGPT's DSA Designation, and the CMA's Microsoft 365 Probe
Three regulatory actions landed inside twenty-four hours, in three jurisdictions, aimed at three different problems. What they have in common is that none of them used a statute written for the technology in question.
The FCC’s ban on foreign advanced robotic devices covers any new ground-based, software-controlled wireless robot weighing more than 4.4 pounds. Because the threshold is defined by mass and locomotion rather than by capability, the rule reaches warehouse automation platforms, inspection robots, delivery machines, and consumer robot vacuums alike. The authority being exercised is equipment authorization, the same mechanism that governs whether a radio transmitter may be sold in the United States, now carrying a supply-chain security objective.
The European Commission is preparing to designate OpenAI’s ChatGPT and Roblox as very large online platforms under the Digital Services Act, possibly as soon as August. The DSA was drafted with recommendation feeds, content moderation at scale, and systemic risk assessments in mind. Applying it to a conversational assistant raises immediate definitional questions about what constitutes disseminated content, what an audience metric means for a one-to-one interface, and how a risk assessment is conducted on generated output rather than on user-uploaded material. Designation brings audit obligations, researcher data access requirements, and transparency reporting.
The UK’s Competition and Markets Authority has opened an investigation into Microsoft over a potential consumer law breach, concerning users paying more to renew Microsoft 365 after Copilot functionality was added to the product. This is the most conventional of the three: a question about whether customers received adequate notice and genuine choice when a subscription price changed on renewal. Consumer contract law was built for exactly this.
Why the instruments are borrowed
No jurisdiction currently has a general-purpose statute covering AI products or autonomous physical systems at the point of sale. The EU AI Act applies to specified risk categories and is phasing in. US federal AI legislation does not exist. What regulators do have is decades of accumulated authority over spectrum, platforms, competition, and consumer contracts, all of which can be pointed at new products by reinterpretation rather than by legislation.
That produces two predictable outcomes. Rules get drawn against proxies that the enabling statute already understands, which is how a security concern about connected devices becomes a weight threshold. And the resulting obligations land unevenly, because the instrument determines the remedy: the FCC can block imports but cannot regulate data handling, the DSA can compel audits but not product design, and the CMA can address pricing conduct but nothing about the underlying capability.
Compliance teams should expect more of this rather than less. Purpose-built regimes take years, and the actions taken in the interim will be shaped by whichever existing authority happens to reach the conduct in question.