Site navigation

EU A Step Closer to Full AI Regulation Legislation

Elizabeth Greenberg

,

EU AI
The law is set to ban the use of AI applications across much of policing, and provide a regulatory framework centred on transparency. 

The European Union (EU) has taken a massive leap toward a comprehensive AI law after its main legislative body ratified a draft of the law.

Now, member countries will debate the final details before the law if fully implemented across the EU.

A hallmark piece of legislation, the law was passed with 499 votes in favour, 28 against and 93 abstentions ahead of further talks with each nation.

“All eyes are on us today,” said Brando Benifei, an Italian member of the EU.

“While Big Tech companies are sounding the alarm over their own creations, Europe has gone ahead and proposed a concrete response to the risks AI is starting to pose.

“We want AI’s positive potential for creativity and productivity to be harnessed but we will also fight to protect our position and counter dangers to our democracies and freedoms during the negotiations with Council.”

What’s in the Law?

While AI technologists warned of potential extinction as a result of the emerging technology, the EU focused on some of the tech’s more pressing issues.

In an exclusive interview with the BBC, the EU’s competition chief Margrethe Vestager said that discrimination is a more pertinent challenge governments must face when regulating AI.

Central to the legislation – and its accompanying debates – was removing certain potential avenues for discrimination and intrusion of privacy.

In Law Enforcement

The law has several bans on the uses of AI, according to the EU Parliament, including:

  • “Real-time” and “post” remote biometric identification systems in publicly accessible spaces.
  • Biometric categorisation systems using sensitive characteristics (e.g. gender, race, ethnicity, citizenship status, religion, political orientation).
  • Predictive policing systems (based on profiling, location or past criminal behaviour);
    emotion recognition systems in law enforcement, border management, the workplace, and educational institutions.
  • Untargeted scraping of facial images from the internet or CCTV footage to create facial recognition databases (violating human rights and right to privacy).

These mostly have to do with law enforcement’s use of AI to identify potential criminals and monitor public spaces, which has come under fire due to the issue of bias in AI systems as well as bias in policing itself.

An audit system by Minderoo Centre for Technology and Democracy found that the UK’s police use of AI was unethical after it invaded privacy and was often guilty of racial profiling and misidentifying people with its facial recognition technology. Police in England currently use AI to monitor crowds and for facial recognition, while Scotland Police have yet to adopt the technology.

While the EU is banning AI’s use in much of policing, AccessNow, a non-profit defending digital rights, slammed the parliament for not extending this ban to immigration systems.

“Without prohibitions in the migration context, the EU is sacrificing the rights of people on the move and will deliberately put marginalized communities at risk, Caterina Rodelli, EU Policy Analyst at Access Now said in a statement.

Border control, however, will be deemed as a high-risk application of AI, and will therefore be required to be transparent and provide risk assessments.

High Risk Applications

Other high-risk applications include in employment recruitment and education, but the law is expanding the the classification for ‘high-risk’ AI applications, which will include AI systems that “pose significant harm to people’s health, safety, fundamental rights or the environment.”

Examples of these include AI algorithms means to influence voters and election outcomes, and in “recommender systems” used by social media platforms with over 45 million users.

Regulations for Developers

Developers and providers of AI foundation models – a fast-evolving field in AI – will have to assess and mitigate for risks and register their models in an EU database prior to releasing them on the EU market.

Generative AI models would have to comply with transparency requirements – like disclosing the content was AI generated, including distinguishing generated images from real ones – and ensuring safeguards against generating illegal content.

These models would also have to provide detailed summaries of the copyrighted data used for their training to the public.

Balancing Innovation with Citizens’ Rights

The EU did make some exemptions on these stipulations for research activities and AI components provided under open-source licenses.

Jonathan Boakes, Managing Director at Infinum, a digital transformation company, commented: “The potential for creativity and innovation through AI is clearly enormous. However, it is crucial to approach AI implementation thoughtfully and the AI Act will play a vital role in ensuring responsible governance, and safeguarding consumer rights and privacy while fostering trust and innovation.

“In fact, rather than stifling innovation, the Act should actually mean tech developers have to get more creative, rather than just jumping on the AI hype train and using it for the sake of it with little thought around what they want it to achieve.”

EU MEPs are promoting ‘regulatory sandboxes,’ or real-life environments, to test AI before it is deployed to the public.


Recommended


To garner more public trust, MEPs want to boost citizens’ right to file complaints about AI systems and receive explanations of decisions based on high-risk AI systems that significantly impact their fundamental rights.

Providing these explanations for AI-made decisions may prove impossible, however, if Generative AI – the model behind ChatGPT – is used. Generative AI is not auditable and can produce different answers to the same question without explanations.

This is something the EU AI Office will have to reckon with, as it will be tasked with monitoring how the AI law is implemented.

Dragos Tudorache, an EU Parliament member from Romania added: “The AI Act will set the tone worldwide in the development and governance of artificial intelligence, ensuring that this technology, set to radically transform our societies through the massive benefits it can offer, evolves and is used in accordance with the European values of democracy, fundamental rights, and the rule of law”.

The law can now progress to the final stage in the EU legislative process, a ‘trilogue’ between the EU Parliament, member states, and the bloc’s executive branch.

After this stage, the law is likely to be fully ratified by 2024.

“Once the AI Act is finalised, the EU will start work on harmonised standards under the Act which will apply across the EU,”  Tim Wright, tech and AI regulation partner at UK law firm Fladgate said.

“Companies should not leave their planning, preparation and implementation too late. When GDPR came in, some businesses struggled to cope with the complexity of the new rules, with Wetherspoons reported to have deleted its entire CRM database when it realised that it would be unable to meet the compliance timetable.”

Boakes added: “At the moment we have barely scratched the surface of AI’s potential and its greatest possibilities. The AI Act serves as a necessary framework to harness AI’s potential while prioritising consumer needs and creating a sustainable AI ecosystem. With great power comes great responsibility, and regulations like the AI Act will ensure businesses do not take that responsibility lightly.”

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data