The Upcoming EU AI Act


On June 14, 2023, the European Parliament adopted its position on the draft AI Act, bringing an EU regulation for generative AI and other AI systems one step closer.

A (draft) AI Act?

In April 2021, the EU legislator published a first draft of the so-called “AI Act”, whose objective is to create a set of harmonized rules for the development, marketing and use of AI in the European Union to ensure that AI systems are used in a safe, ethical and trustworthy manner while protecting people’s rights.

Since then, the text has been amended and extensively debated. In particular, the recent widespread introduction of ChatGPT and the attention paid to such “generative-purpose AI systems” has been a trigger for inserting considerable clarifications and obligations for providers of such AI systems.

As the AI Act is a Regulation, it will be binding in its entirety and directly applicable in all Member States.

What are the main components of the draft AI Act?

A central aspect of the AI Act is a risk-based approach . It rests on 6 quality principles:
-human agency and oversight
-technical robustness and safety
-privacy and data governance
-transparency
-diversity, non-discrimination and fairness
-social and environmental well-being

These principles are then turned into specific obligations. The obligations an entity must comply with will depend (a) on the nature of the entity and (b) on the AI system in question.
a.To whom does the draft AI Act apply?

The AI Act will apply first and foremost to providers placing AI systems on the EU market . As with the GDPR, being established in the EU is not a requirement to fall within the scope of the AI Act. Therefore, American or Chinese companies may also be subject to this legislation. In addition, manufacturers, authorized representatives, distributors and importers will also have to comply with certain obligations.

b.What are the different AI systems and obligations?

The following is a brief summary of the most important points for the different AI systems set out in the draft:
• AI systems with unacceptable risks

There is a general prohibition on placing such AI systems on the EU market, as they are considered to contradict the Union’s values of respect for human dignity and fundamental rights.
-Social scoring (classification of people based on their social behavior or personal characteristics);
-emotion recognition systems in law enforcement, the workplace or educational institutions;
-“Real-time” remote biometric identification systems in publicly accessible spaces.

• High-risk AI systems
This is the most strictly regulated category. These are AI systems that pose significant harm to people’s health, safety, fundamental rights or the environment.

The AI Act imposes very broad requirements that AI systems must meet, as well as far-reaching obligations for providers if they wish to market such AI systems. This includes implementing a quality management system, carrying out a conformity assessment (CE marking), conducting a “fundamental rights impact assessment”, training and data governance, and cybersecurity.

-AI systems used for the operation of critical infrastructure (for example, the electricity supply);
-Automated recruitment tools;
-Credit scores;
-AI recommender systems used by social media platforms that are designated as very large online platforms under the Digital Services Act.

• General-purpose AI systems
These are AI systems designed to perform a wide range of tasks that are broadly applied across different domains. They are capable of performing functions such as recognizing and understanding images and speech, generating audio and video content, detecting patterns, answering questions, translating languages and more.

This category has been introduced recently and also covers generative AI (e.g., ChatGPT) and ” foundation models ” (e.g., GPT 3.5). A tiered approach is proposed for these models, with a stricter regime for foundation models.

The obligations include: carrying out risk assessments, obligations related to the design of the foundation model (including from an environmental impact perspective), registration of the foundation model in an EU database, notifying people that they are interacting with an AI system, and providing a summary of the available training data that is protected by copyright law.

-Chatbots;
-Translation tools;
-Virtual assistants.

All other AI systems

All AI systems are required, in principle, to provide certain information to users to ensure transparency.

What about enforcement?

National supervisory authorities will be primarily responsible for enforcement. They will have broad powers, including the imposition of fines (with amounts at stake similar to those of the GDPR). However, the placing on the market of unacceptable AI systems may be sanctioned with administrative fines of up to EUR 40 000 000 or, if the offender is a company, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.

When do companies have to comply with the AI Act?

A final text is expected by the end of the year and it will then apply two years later.
This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.