The EU AI Act — the European Union's AI Regulation for Governing Artificial Intelligence
The world's first comprehensive framework for artificial intelligence — and its risk-based approach
Digitalisation and, above all, the use of new systems with Artificial Intelligence (AI) are advancing rapidly and are confronting society as a whole with new challenges. Alongside the far-reaching possibilities that new AI technologies offer, the associated technological change also harbours considerable risks and some uncertainties. For this reason, the European Commission published a proposal on 21 April 2021 for laying down harmonised rules for Artificial Intelligence in the European Union.
The EU AI Act — 3 years between proposal and agreement
Three years after the publication of the Commission’s proposal, the European Parliament and the European Council were able to reach an agreement on 21 May 2024 on the EU AI Act (AI is the abbreviation for “Artificial Intelligence”), a regulation governing artificial intelligence in the European Union. The EU AI Act is thus the world’s first comprehensive framework (113 articles) for artificial intelligence. With it, the EU wants to create a legal basis for the development and use of AI, in order to minimise possible risks and avert the resulting harm. The legal framework, however, does not only aim at a harmonisation of the legal provisions, but is also intended to be the foundation for the unfolding of the new technology, in order to promote investment, innovation and creative solutions in the field of AI.
Structure of the EU AI Act
- Chapter I: General provisions
- Chapter II: Prohibited artificial intelligence practices
- Chapter III: High-risk AI system
- Chapter IV: Transparency obligations for providers and operators of certain AI systems and GPAI models
- Chapter V: General-purpose AI models
- Chapter VI: Measures in support of innovation
- Chapter VII: Governance
- Chapter VIII: EU database for high-risk AI systems
- Chapter IX: Post-market monitoring, information sharing, market surveillance
- Chapter X: Codes of conduct and guidelines
- Chapter XI: Delegation of power and committee procedure
- Chapter XII: Confidentiality and penalties
- Chapter XIII: Final provisions
- Annex I: List of Union harmonisation legislation
- Annex II: List of criminal offences
- Annex III: High-risk AI systems
- Annex IV: Technical documentation
- Annex V: EU declaration of conformity
- Annex VI: Conformity assessment procedure based on internal control
- Annex VII: Conformity based on the assessment of the quality management system and the assessment of the technical documentation
- Annex VIII: Information to be submitted upon the registration of high-risk AI systems (Article 49)
- Annex IX: Information to be submitted upon the registration of high-risk AI systems (Annex III / Article 60)
- Annex X: Union legislation on large-scale IT systems in the area of freedom, security and justice
- Annex XI: Technical documentation pursuant to Article 53(1a)
- Annex XII: Transparency information pursuant to Article 53(1b)
- Annex XIII: Criteria for the designation of general-purpose AI models with systemic risk
What is a regulation?
In the EU, a regulation is a legal act that has direct application in the member states and does not first have to be transposed by national laws, as a directive does.
In the AI Act, the EU attempts to take into account and reconcile both the interests of companies and state authorities that offer and use AI systems within the EU, and the fundamental rights and interests of the EU citizens who come into contact with AI-based applications.
According to Article 2 of the AI Act, the rules apply to everyone within the EU, regardless of the seat of the operator or the place where the AI-based systems are manufactured or operated. Moreover, the rules do not apply to systems that were developed in the EU but are used outside the EU. The regulation has no validity for:
- AI systems that do not fall within the scope of Union law, such as the competences of the individual member states in the field of national security
- AI systems, if these are used, operated or (modified or unmodified) applied exclusively for military, defence-policy or national security purposes
- AI systems used by foreign authorities or international organisations for law enforcement and judicial cooperation, provided they do not violate the rights of the individual
- AI systems used for scientific research and development
- AI systems that are not yet on the market at all
- individuals who use AI systems for personal, non-professional activities
- as well as AI systems that are released under open-source licences, unless they are high-risk or therefore fall under certain restrictions or protective provisions of the regulation.
A risk-based approach to assessing AI systems
The core of the AI Regulation is formed by the classification of AI systems according to risk classes. This risk-based approach assesses AI systems according to their risk to the safety, health and fundamental rights of people. In doing so, the AI Act defines and delineates four risk levels from one another.
Level 1: AI prohibitions — unacceptable risk
Article 5 of the second chapter lists AI systems that, according to the regulation, represent an unacceptable risk and are therefore prohibited. These include AI systems that
- use subliminal, manipulative or deceptive techniques to deliberately manipulate decisions, or the behaviour, of persons, whereby considerable harm to those affected can arise with a high probability.
- exploit weaknesses of persons or entire groups of persons (e.g. age, disabilities, socio-economic circumstances) in order to bring about a certain behaviour, and knowingly accept the resulting harm.
- contain biometric categorisation systems that allow inferences to be drawn about sensitive characteristics such as race, political opinions, trade union membership, religious/philosophical convictions or sexual orientation. Excepted are lawfully acquired biometric datasets such as images, or the categorisation of biometric data by law enforcement authorities.
- are used for the adverse assessment or classification of persons or groups of persons according to social behaviour or personal characteristics.
- serve for risk assessment in order to create profiles of whether and how likely natural persons are to commit criminal offences.
- create or expand facial recognition databases from the internet or from video surveillance footage.
- are set up for the purpose of being able to infer emotions in the workplace or in educational institutions, except where they are deliberately used for medical or safety reasons.
- use real-time remote biometric identification in publicly accessible spaces for the purpose of law enforcement. This does not apply to certain circumstances, such as the search for missing persons, abduction victims, victims of human trafficking or sexual exploitation, the prevention of a substantial and imminent threat to life or of a foreseeable terrorist attack, as well as the identification of suspects in serious criminal offences.
Level 2: AI systems with high risk
The classification of AI systems with high risk takes up a considerable part of the regulation. Apart from Articles 6 to 27 in Sections 1 to 3 of the third chapter, Annex I refers to the Union harmonisation legislation, which in Article 6 lays down under which conditions an AI system is classified as high-risk. Annex III lists high-risk AI systems within the meaning of Article 6(2). Accordingly, they are high-risk AI systems if they fall within the areas of biometrics, critical infrastructure, general and vocational education, employment, worker management, access to self-employment, services, law enforcement, migration and justice. Cases of biometric identity verification, for the detection of financial fraud or for the organisation of political campaigns, are also mentioned as an exception.
For AI systems classified as high-risk, the providers and operators must, pursuant to Articles 8 to 17, fulfil extensive obligations with regard to risk management, data and data governance, technical documentation, transparency, logging, human oversight, conformity assessment and cybersecurity. As a consequence, in connection with AI systems, an assessment of the effects on fundamental rights must additionally always be carried out.
Level 3: AI systems with specific risk and particular transparency obligations
A further risk classification concerns providers of certain AI systems and GPAI models (GPAI stands for General Purpose AI), which in Article 50 are obliged to ensure transparency and must inform their users about interactions with AI systems, such as with chatbots or deepfakes. This also includes biometric systems, provided they do not fall under the prohibited systems.
In Article 53, the AI Act contains special rules for the development and use of GPAI models. The providers and developers of these AI models are obliged to keep detailed records of the development and testing of their AI. This information must be shared with other companies that want to use it. Excepted from this rule are AI models that are open-source, unless they represent a systemic risk. The providers of GPAI models also commit themselves to cooperation with the Commission and the competent national authorities.
General Purpose AI (GPAI)
A GPAI model is an AI model — even if it was trained with a large amount of data using self-supervision at scale — that displays significant generality and is capable of competently performing a broad range of different tasks, regardless of how the model is brought to market, and that can be integrated into a variety of downstream systems or applications.
A GPAI system is an AI system that is based on a general AI model that can be used for a variety of purposes, both for direct use and for integration into other AI systems.
Level 4: AI systems with minimal risk
The vast majority of AI systems fall into the fourth level, with the lowest risk. These AI applications are so far almost unregulated. These include, for example, AI-supported video games or spam filters. Providers of these systems can voluntarily commit to codes of conduct.
Deadlines for the entry into force of the AI Act provisions pursuant to Article 113(7)
- June–July 2024: the EU AI Act is published in the Official Journal of the EU
- 20 days later, after publication, the regulation enters into force
- 6 months later, Chapter I and Chapter II (prohibitions of AI) apply
- 12 months later, Chapter III, Chapter V, Chapter VII, Chapter XII apply
- 24 months later, most of the remaining provisions come into effect
- 36 months later, Article 6(1) and the corresponding obligations apply
In the event of violations, companies face substantial fines:
- The fines would range between EUR 35 million or 7% of the worldwide annual turnover (whichever amount is higher) for violations against prohibited AI applications, EUR 15 million or 3% for violations against other obligations, and EUR 7.5 million or 1.5% for the supply of incorrect information.
- For SMEs and start-ups, proportionate upper limits for fines are to be provided for in the event of violations against the regulation.
Quo Vadis — Artificial Intelligence in the EU?
Similar to the GDPR (General Data Protection Regulation), the European Union has once again created a comprehensive framework with the EU AI Act in order to regulate the use of artificial intelligence. With it, the EU wants to take account of the rapid development in the field of AI and forestall the possible disadvantages and risks and counter dangers decisively. The decisions taken, however, are only the beginning of many further measures that will have to be put in place on account of future developments and the associated challenges. While some are relieved and satisfied about the EU’s initiative to regulate AI while simultaneously protecting fundamental rights, others see in the regulation an already outdated framework that could develop to their disadvantage in global competition, above all with the USA and China. Nevertheless, for data protectionists and fundamental rights experts, as well as for representatives of the economy, the provisions do not go far enough, or rather too far, from their point of view. Both sides doubt the future viability of the existing regulation. The deadlines in particular are seen critically, because most of the rules will only enter into force in 2026. This will lead to a large number of the rules already being outdated again on account of the rapid developments in the field of AI.
Practice will show where possible loopholes in the provisions lie, whether the risks with regard to the safeguarding of fundamental rights can really be minimised, what effects the regulation will have for providers and operators of AI systems, and how the role of Europe in global competition will develop.
Originally published at SEQIS Blog