Site navigation

The AI Act | Everything You Need to Know

Tom Quinn

,

EU AI Act
The European Union’s AI Act came into force on August 1st, 2024, introducing regulations for the development and use of AI in a world-first.

The European Artificial Intelligence Act (AI Act) has officially entered into force, with provisions coming into effect in stages over the next few years.

European lawmakers have said that the new Act will protect the ‘fundamental rights’ of citizens in the 27-nation bloc while also encouraging investment and innovation. 

Plans for developing AI legislation in the UK were recently announced in the King’s Speech, but British businesses that build or use AI systems within the EU will already need to comply with the EU’s AI Act. With the AI bubble still swelling, almost every global firm will have to grapple with this new regulatory framework.

What are the new rules?

Under the rules, AI developers have been provided with a set of requirements and obligations regarding specific uses of artificial intelligence, with the European Parliament prioritising that AI systems are made to be ‘safe, transparent, traceable, non-discriminatory and environmentally friendly.’ 

The protection of end-users is fundamental, but how that works in practice depends on the level of risk associated with any particular product or service that uses AI. 

Different risk categories have been devised which outline what restrictions every AI developer and operator need to follow. These are categorised as ‘Unacceptable Risk’, ‘High Risk’, and ‘Minimal Risk’.

Under the ‘Unacceptable Risk’ bracket are systems considered a threat to people, which will be banned. That includes AI designed to manipulate people and specific vulnerable groups, for example, voice-activated toys that encourage dangerous behaviour in children.

Other unacceptable uses of AI to be outlawed are social scoring systems that influence how people behave, some types of predictive policing, and emotion recognition systems in schools and workplaces, all of which will face a blanket ban by February 2025.

‘High Risk’ AI systems are those that affect the safety or fundamental rights of individuals. That covers AI used in products falling under the EU’s safety legislation, like toys, cars, medical devices and lifts. 

It also includes AI that manages and operates critical infrastructure, law enforcement practices, the application of the law, as well as migration, asylum and border control management.

Every piece of AI categorised as High Risk will be continually assessed throughout its lifecycle, with people having the right to file complaints about the use of AI systems in these areas with their national authorities.

Generative AI, like ChatGPT, won’t be classified as High Risk, but will have to comply with transparency requirements and EU copyright law. That means disclosing that the content was generated by AI, designing AI models to prevent them generating illegal content, and publishing summaries of the copyrighted data used for training models.

The aim is that by clearly labelling content as AI generated users will be more likely to be aware of and avoid harmful content designed to manipulate, like deepfakes.


Recommended reading


Most AI currently in use is expected to fall under the ‘Minimal Risk’ category, like spam filters, content recommendation systems and AI-based video games. None of these will face any obligation under the AI Act, but companies can voluntarily adopt additional codes of conduct.

By mid-2026, the complete set of regulations will be in force, with other European governmental bodies expected to develop their standards for administering the new laws during the implementation period.

Landmark legislation

Before now, AI regulation within the EU has been limited to specific cases. That includes the Italian Data Protection Authority’s ban on the ReplikaAI chatbot, Google’s temporary suspension of its Bard AI tool rollout in Ireland, and Italian DPA fines for Deliveroo over AI algorithm use but the AI Act is the first comprehensive regulation on AI by a major regulator anywhere.

Brussels has already set up a new AI Office to act as the bloc’s general enforcer for AI rules, with companies facing fines worth as much as 7% of their annual global revenue for non-compliance.

European Commission executive vice president Margrethe Vestager said: “With the AI Act, the EU has taken an important step to ensure that AI technology uptake respects EU rules in Europe.”

The push for widely accepted codes of conduct in AI development between countries was most recently prioritised at the G7 summit hosted by Italy in March. At the time, G7 members acknowledged that although they were pursuing a shared vision for a safe and secure AI framework, the regulatory framework may differ among nations.

These differences have already become apparent with the launch of the UK’s AI and Digital Hub, intended to make it easier for businesses to get the help they need by bringing together the different regulators involved in the oversight of cross-cutting AI and digital technologies. 

With the AI Act coming into effect, these businesses now face the challenge of working within competing frameworks until the UK government sets down its own legislation and tames the wild-west of AI inside its own borders.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data