Home / Uncategorized / Regulation After the Revolution: The EU’s Artificial Intelligence Actuto Draft
In December 2023, the EU reached final agreement on the Artificial Intelligence Act, the world’s first comprehensive legal framework for regulating AI. Attorney Eyal Brook explains that the law follows a risk-based approach: the greater the potential harm an AI system poses to society, the stricter the obligations imposed on it, up to an outright ban on unacceptable-risk uses. The Act also introduces, for the first time, dedicated rules for powerful general-purpose foundation models. Companies that fail to comply may face fines of up to EUR 35 million or 7% of global annual turnover, whichever is higher.
The accelerated adoption of artificial intelligence has created a need to oversee its development and use, in order to prevent risks in areas such as privacy, copyright, employment, and human rights. This article addresses the European Union’s new and precedent-setting law on artificial intelligence (the EU AI Act), which is designed to tackle these issues and position the EU as the flag-bearer of AI regulation.
Artificial intelligence, which has swept into our lives over the past year, carries far-reaching significance for humanity’s future and has been described as the “fourth industrial revolution.” Achievements once unimaginable are now an evolving, fascinating reality. The field cuts across sectors and continues to develop at an especially rapid pace. Yet despite the clear benefits of this developing technology, these advances have also raised considerable concern over the lack of regulation and the risks inherent in AI – from privacy, through copyright and job losses, to harm to human rights and fundamental freedoms.
In this sense, AI is a disruptive technology that must be met with national strategy and regulatory policy. Around the world, we are witnessing a global legislative race to regulate the development and use of AI technologies. The EU has been a leading force in creating AI regulation, unveiling its bill as early as 2021. In doing so, Europe has positioned itself as a pioneer and regulatory benchmark, recognizing the importance of its role in setting global standards. Other leading players in the field, alongside the EU, include the US, China, and the UK.
In December 2023, a breakthrough occurred in the EU. After extensive discussions and a marathon 36-hour negotiation between the various bodies (the EU Commission, Parliament, and Council), agreement was reached on a revised text of the world’s most comprehensive legal framework for regulating AI: the EU Artificial Intelligence Act. The law was first proposed in April 2021, the European Parliament approved the draft in June 2023, and it is now reaching its final form.
The EU AI Act is a flagship initiative for regulating AI technologies. It follows a risk-based approach, with the core idea being to treat AI according to its potential to cause harm to society – the higher the risk, the stricter the rules. Accordingly, several tiers of AI systems have been defined: from minimal risk, through a strict regime for high-risk uses, to systems deemed to pose an “unacceptable risk,” the use of which will be banned outright.
This development is significant and marks a milestone in the legislative process to regulate AI technology. EU Commissioner Thierry Breton wrote on the social network X that the EU had become the first continent to set clear rules for the use of AI. Carme Artigas, Spain’s Secretary of State for Digitalization and Artificial Intelligence, said the agreement addresses a global challenge in a fast-evolving technological environment and a field that is key to the future of our societies and economies, adding that a delicate balance was struck between strengthening innovation and AI adoption across Europe while fully respecting citizens’ fundamental rights.
The requirements of the EU AI Act vary according to the risk level posed by the AI system. As noted, the basic idea is to regulate AI according to its potential to harm society: the higher the risk, the stricter the rules. Accordingly, the use of AI demonstrating “unacceptable risk” will be banned, including, among others, the following systems or uses:
AI systems classified as “high-risk,” due to their potential to harm health, safety, fundamental rights, the environment, democracy, and the rule of law, will be permitted but subject to stricter requirements and obligations, such as the need to conduct a fundamental-rights impact assessment. Examples include remote biometric identification systems (e.g., for emotion assessment) and AI used in sensitive systems such as critical infrastructure (water, gas, electricity supply), welfare, employment, education, and transport. Citizens will have the right to receive explanations regarding decisions based on high-risk AI systems that affect their rights, and enhanced transparency and registration obligations will apply.
AI systems presenting “limited risk” (such as chatbots or “deepfakes”) will be subject to transparency obligations, such as informing users that the content they are engaging with was generated by AI, so that they can make informed decisions about its use.
The law adds new provisions addressing situations in which AI systems can be used for many different purposes (general-purpose AI), where general-purpose AI technology is subsequently integrated into another high-risk system.
These significant developments required the law to be rewritten repeatedly, in light of the emergence of new AI tools. Specific rules were therefore also established for “foundation models” – an AI model trained on data at such scale that it can be adapted for a wide range of tasks. The law provides that such models must meet specific transparency obligations before entering the market. A stricter regime will apply to foundation models with “high impact” – models trained on an enormous quantity of data and possessing advanced capabilities and performance, which may carry systemic risks. The precise obligations and requirements for these models are expected to be published shortly, alongside the final text issued by EU authorities. Companies developing such models will need to prepare technical documentation, comply with copyright law, and detail the content used to train the model.
It is worth noting that technological developments in AI, which carry far-reaching implications for our lives generally, are integrating not only into fields such as translation, transportation, medicine, investment, and law, but – with the recent rise of generative AI – are also becoming common in various creative and artistic fields, such as music, painting, and writing, which were once considered distinctly human pursuits.
The law does not seek to apply to systems used solely for military or defense purposes. Moreover, the law allows the use of remote biometric identification by law enforcement authorities in public spaces in emergency situations, such as searching for victims (kidnapping, human trafficking, etc.), preventing a specific terrorist attack, and locating persons involved in relevant crimes, subject to certain safeguards (this use was banned under earlier drafts of the law and is now permitted provided law enforcement authorities observe additional safeguards).
The law will not apply to companies developing AI systems intended solely for research purposes. In order to create a more innovation-friendly legal framework, the provisions relating to measures supporting innovation were substantially changed compared to the previous draft.
In this context, the regulatory sandbox should be mentioned. A regulatory sandbox is a controlled environment established by a public authority that enables the safe development and approval of innovative AI systems for a limited, safe period before use, under a specific plan and regulatory supervision. The regulatory sandbox provides a way to connect innovators with regulators and offers them a controlled environment for collaboration. Such collaboration between regulators and innovators is intended to facilitate the development, testing, and validation of innovative AI systems, with the aim of ensuring compliance with the requirements of the AI regulation.
The law provides that use of copyright-protected content requires the rights holder’s consent, unless relevant copyright exceptions and limitations apply. Accordingly, providers of general-purpose AI models may need to obtain consent from rights holders if they wish to carry out text and data mining. It will be interesting to see how this affects companies such as OpenAI and Midjourney.
The law sets out a series of bureaucratic requirements that must be met, including appointing an authorized representative in the EU, who plays a central role in ensuring the system’s regulatory compliance; registering data in the EU database before launching the system; and retaining relevant documentation for ten years after the AI system is placed on the market or put into service.
The law uses the definition of AI systems proposed by the OECD: an AI system is a machine-based system that infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
Non-compliance with the law will result in heavy, significant fines. Fines for violations of the AI Act are set as a percentage of the violating company’s global annual turnover in the preceding financial year, or a predetermined amount, whichever is higher. The fine amounts are:
However, the provisional agreement sets more limited caps / administrative fines for small and medium-sized companies and startups in the event of violations of the law’s provisions.
In the coming weeks, work is expected to continue on the agreement at the technical level, en route to final approval expected in April. The final text of the EU Artificial Intelligence Act will then be published. The provisional agreement provides that the AI Act will apply two years after its entry into force, with certain exceptions for specific provisions that will take effect earlier. As noted, some work still needs to be completed, so it is reasonable to expect that most provisions of the law will take effect in 2026.
That said, the law is unlikely to change substantially. Companies engaged in or developing AI technologies, or investors considering investments in the AI field, may wish to ensure their activity is compliant and would not be considered prohibited under the new law. It is therefore advisable to await publication of the final, official text of the law.