Europe enforces sweeping new AI law

Image: julien Tromeur @julientromeur via Unsplash

The world’s first comprehensive law regulating artificial intelligence came into effect this month. From 2 August, the European Commission’s AI Office, together with national authorities, began to enforce Europe’s Artificial Intelligence Act. On the same day, new transparency rules came into effect.

The Act outlaws a list of AI actions and flags high-risk practices that must comply with a strict set of conditions prior to public release. It also provides for a complaints mechanism for reporting infringements, and a separate whistleblower tool – a secure, anonymous channel that can be used by industry insiders to expose unlawful or harmful practices.

Nine prohibited practices listed include AI systems that manipulate, deceive or exploit people and their vulnerabilities in harmful ways. Those that unfairly score, profile and monitor people in ways that threaten their rights, and those generating non-consensual sexually explicit content, are outlawed too.  

The legislation also flags high-risk cases that can pose a threat to the health, safety and fundamental rights of citizens. These include the use of AI in transport infrastructure, for exam scoring in educational institutions, for employment screening tools, in regulating access to services, in robotic surgery and for law enforcement. From December 2027, high-risk systems will need to comply with nine strict conditions before being released on the market. These include quality assessments of datasets, human oversight and robust cybersecurity.

The Act requires general purpose AI models to have a copyright policy, provide their documentation to authorities, and publish detailed training-data summaries. Extra obligations involving risk assessment and mitigation apply to the most advanced models that pose systemic risks.

The new transparency rules require AI systems to disclose to users that they are dealing with chatbots rather than humans, and for content that has been generated or altered by AI to contain machine readable watermarks that are easy to detect. Images, videos and audio that has been edited or generated by AI – known as deepfakes – will have to be labelled as such. The commission says these measures are designed to reduce deception and manipulation,  and help people make informed choices.

By the end of July about 190 organisations across a range of sectors, including telecoms, IT, education and retail, had signed a Code of Practice on Transparency of AI-generated Content, which operationalises these transparency rules. Major tech companies including Google, Meta, Anthropic, OpenAI and Microsoft have signed on. About half the signatories are small and newly established companies, which the EC says demonstrates the care that was taken to ensure the code caters to the needs of small and medium sized enterprises too.

Enforcement is shared across three bodies: the AI Office – which can fine offenders up to 3 percent of global turnover – national authorities and the European Data Protection Supervisor, which enforces the rules for AI systems used by EU agencies. EU member states are also expected to ensure competent authorities are properly designated and resourced.

https://artificialintelligenceact.substack.com/p/the-eu-ai-act-newsletter-108-enforcement

Next
Next

Royal commission to look at the impact of AI on society