After years of drafting and negotiations, on March 13, the European Parliament approved the EU's Artificial Intelligence Act (AI Act), making it the world's first comprehensive AI legislation. The AI Act is positioned as a core part of a “broader package of policy measures to support the development of trustworthy AI,” which also includes the AI Innovation Package and the Coordination Plan on AI. The AI Act aims to strike a balance between promoting AI innovation and ensuring the protection of people's health, safety and fundamental rights.
The AI Act is 459 pages in its latest edition (including instructions and annexes) and can be difficult to read, so we have provided references to the relevant provisions of the AI Act throughout as a guide.
timing and implementation
The AI Law will come into force 20 days after publication in the Official Journal of the European Union, with key elements being implemented gradually until it is fully applied in two years. Publication in the official journal is scheduled for April this year. Within six months of the effective date, you must cease using any AI system that poses an unacceptable risk. Obligations for providers of general purpose AI begin 12 months after the effective date. Most high-risk AI system requirements will come into force 24 months after the effective date, but some types of high-risk AI systems (mainly those regulated by EU product safety legislation) will not be required until 36 months after the effective date. It is not within the scope of the AI Act. moon mark.
Scope and enforcement
Similar to the EU's General Data Protection Regulation, the AI Act has extensive extraterritorial provisions that can bring organizations not established in the EU into the scope of the law (Article 2). The AI Law applies to developers (“providers”) and users (“adopters”) of AI systems and general purpose AI models (including the use of their outputs) sold or used in the European Union and other AI supply companies. will be done. chain. In AI law, an “AI system” refers to a machine-based system that operates with some degree of autonomy and is capable of inferring from input how to produce an output that affects a physical or virtual environment for some purpose.
The new European AI Authority will primarily enforce AI legislation and provide for fines of up to €35 million, or 7% of global annual turnover, for violations related to prohibited AI uses (€15 million; or 3% of global annual sales). , for most other violations). The AI Directorate also works with the European Commission, the European Commission for Artificial Intelligence and the national authorities of EU Member States to manage and supervise compliance with regulatory obligations under the AI Act.
Take a risk-based approach
The AI Act develops obligations and requirements based on a risk-based approach, and the majority of restrictions and requirements apply not only to general-purpose AI models, but also to AI systems used for unacceptable or high-risk purposes. Also applies. The list of types of AI use that are unacceptable or pose a high risk is regularly reviewed and amended to take into account changes in technology. Additionally, while AI developers (“providers”) will have more obligations under the AI Act than others, there are also many requirements for companies deploying AI systems in the EU. .
Prohibited AI systems. AI systems that pose an unacceptable risk are prohibited (Article 5) and, if currently in use, must be phased out within six months of the effective date of the AI Act. Some of these AI systems are considered to be a clear threat to the security, livelihood and fundamental rights of people in the EU. These include those used by AI, with some exceptions.
- It aims to manipulate behavior in ways that can cause serious harm.
- Predict emotions in workplaces and educational settings.
- Exploiting vulnerable people.
- It evaluates or categorizes people based on their behavior, creating social scores that result in unfavorable treatment and other harmful effects.
- The facial recognition database uses untargeted mass scraping of facial images.
- Predict the likelihood of committing a crime based solely on profiling.
- Allows remote “real-time” biometric authentication in publicly accessible spaces for law enforcement purposes.
High-risk AI systems. High-risk AI systems can pose significant risks to people but can be developed and used in accordance with the requirements of the AI Act. Uses of AI that may pose a high risk (Article 6) include:
- Product safety, particularly the safety of regulated products such as vehicles, toys, and medical devices.
- Critical infrastructure such as digital infrastructure, traffic flow, and utilities.
- Educational or vocational training, including access to education, scoring of exams, and monitoring of prohibited exam activities.
- Employment and workforce management, including hiring, applicant screening, promotion, and termination.
- Important services and benefits such as eligibility determination, insurance pricing, and emergency service dispatch.
- Law enforcement and border control, including assessing the reliability of evidence and making immigration and asylum decisions.
- legal justice and democracy. It is used for research, the application of law, and to influence elections and voting behavior.
Developing and delivering high-risk AI systems comes with a list of requirements, including:
- Establish, implement, document and maintain AI risk management protocol Identify, minimize and manage reasonably foreseeable risks throughout the lifecycle of high-risk AI systems (Article 9).
- documented data governance For high-risk AI systems involving training of AI models, including information about relevant design choices, data provenance, data quality, assumptions, and potential biases (Article 10).
- Thorough and up-to-date information technical documentation (Article 11 and Annex IV).
- automatic activity logging To evaluate operations, identify risks and facilitate post-market monitoring (Article 12).
- Transparency and clearness Information for adopters Management of high-risk AI systems, including accurate instructions for use (Article 13).
- human surveillance Measures to minimize risks (Article 14).
- precision and resilience This ensures that high-risk AI systems behave as expected and are resistant to abuse (Article 15).
- a Conformity assessment Procedures for demonstrating compliance (varies depending on the type of high-risk AI system) (Articles 43 to 47), etc. test (Article 60).
- database Registration (Articles 49 and 71).
- Post-market monitoring (Article 72).
- notification Major incidents and widespread violations and investigation of incidents (Article 73).
Additional requirements for developers of high-risk AI systems (“Providers”) are set out in Articles 16 to 22, including quality management systems, further documentation requirements, corrective actions for non-conforming high-risk AI systems, and This includes cooperating with the competent authorities. . Specific obligations for other organizations involved in the supply chain of high-risk AI systems follow from Articles 23 to 27. For example, implementers of high-risk AI systems must take appropriate technical and organizational measures to ensure compliance with instructions regarding the use of AI systems. Assign competent individuals to monitor AI systems and provide human oversight to monitor high-risk AI system behavior.
Generic AI models and generative AI. Early drafts of the AI Act did not initially mention “general purpose” AI models. However, given the rapid growth of generative AI, the drafters added provisions to address the risks of general-purpose AI models. A general-purpose AI model is defined as an AI model that is versatile enough to perform many different tasks or to integrate AI models. Various downstream applications or systems. Large-scale generative AI models are a common example of general-purpose AI models.
Providers of general-purpose AI models must publish a detailed overview of the content used to train their models, including text, images, videos, and other internet data, and have policies in place to comply with EU copyright law. (Articles 53 to 55). . High-impact general-purpose AI models that have the potential to pose systemic risks are subject to additional obligations such as risk assessment, model evaluation, testing, and critical incident reporting.
Transparency is a core obligation regarding generative AI and other AI systems that interact directly with people (Article 50). People should use caution when interacting with generative AI, especially if they could be influenced by it in any way. For example, if you use an AI-powered chatbot, you need to educate people so they can make informed decisions about interacting with the chatbot. You should also be careful when you come across AI-generated content, or “deep fakes,” such as images, audio, text, and video content that can be misleading. As an example, AI-generated news articles must be labeled as artificially generated unless they go through a human-controlled editing process before publication.
What's next?
The first step for many is to determine whether their organization uses AI or outputs from AI in the EU. In that case, the AI Act is likely to apply. Next, evaluate the AI systems used in your organization to assess whether there are any prohibited or high-risk AI uses. Where such uses are identified, we will prioritize phasing out the use of prohibited AI systems and develop a plan to bring risky uses of AI into compliance with AI law. Developers of general-purpose AI models must also prioritize these compliance obligations. Even organizations that do not plan or use prohibited or high-risk AI systems should still consider the AI Act's transparency requirements. Transparency is expected as a best practice for using AI, even if it is not specifically required.
[View source.]
