The European Parliament passed AI act

The EU Regulatory Framework defines 4 levels of risk for AI systems

The EU AI act took years of debate. It will slowly come into force over the next 24 months. It is the world’s first comprehensive regulation governing AI systems.

What it says about it’s goals?
The Act is to protect rights, democracy and the rule of law from high-risk AI.
The act is suggested as a starting point for technology governance.

Supporting businesses
The EU AI Office will be set up to support businesses to start complying with the rules.
EU also makes testing and sandbox capabilities accessible to SMEs and startups.

What will be banned?
AI applications that could violate citizens’ rights will be banned. This includes:

  • Biometric categorization systems based on sensitive characteristics and AI that manipulates human behavior.
  • Emotion recognition in the workplace and schools.
  • Social scoring.
  • Predictive policing based on profiling a person or their characteristics.
  • Untargeted scraping of facial images from the internet or CCTV footage.

Requirements for companies

  • The AI act introduces a rules-based approach to categorize all AI systems based on their potential to impact citizens’ rights. The AI systems more likely to impede civil liberties would be subjected to stricter rules.
  • Citizens have rights to receive explanations about how high-risk AI systems make decisions that affect citizen rights.
  • AI-generated audio, images and video need to be labeled as such.
  • Training Gen AI models for the EU market need to follow machine-readable opt-outs from text and data mining even if their servers are in the U.S.

Requirements for developers

  • General-purpose AI systems, like OpenAI’s GPT-4, need to have detailed summaries on training content.
  • Powerful models need evaluations, assessments and risk mitigating measures in place, and reporting on incidents.

High-risk AI systems need to fulfil obligations including risk assessment.
Businesses will be required to log when the system was used.
Human oversight is required to put in place. High risk applications are such as health, critical infrastructure, border control, education, justice and the everyday services.

Comments
Romanian MEP Dragos Tudorache, one of the co-rapporteurs of the EU AI Act, said “Much work lies ahead that goes beyond the AI Act itself. AI will push us to rethink the social contract at the heart of our democracies, our education models, labor markets and the way we conduct warfare.”

John Buyers, head of AI at law firm Osborne Clarke, said “Businesses need to make good use of the intervening time to understand how the AI Act will bite on their products and services and the supply chains that feed into them, and plan capacity and resources to ensure compliance in good time.”

Alois Reitbauer, chief technology strategist of Dynatrace: “It’s impossible to see how organizations will be able to comply if they aren’t first clear on what constitutes an AI model, so the EU will first need to ensure that has been clearly defined … for example, will the machine learning used in our mobile phones or connected thermostats be classed as an AI system?”

References:
https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
https://aibusiness.com/responsible-ai/eu-parliament-adopts-world-s-first-comprehensive-ai-law#close-modal
https://aibusiness.com/responsible-ai/industry-faces-compliance-hurdles-after-eu-ai-act-passes
https://www.chathamhouse.org/2024/03/eus-new-ai-act-could-have-global-impact