Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act/ the AI Act) and amending certain European Union legislative acts was published in the Official Journal of the EU on 13 July 2024. The Act on Artificial Intelligence will enter into force on 1 August 2024 and will apply from 2 August 2026, i.e. 24 months after its announcement.
According to the written justification of the Regulation, Artificial Intelligence (AI/SI) is a rapidly developing technology group that can bring many different socio-economic benefits in all sectors and areas of social activity.
However, the use of AI with its specific features (e.g. black box effect, complexity, data dependence, autonomous behaviour) may have a negative impact on a number of fundamental rights enshrined in the Charter of Fundamental Rights of the European Union. The Artificial Intelligence Act aims to ensure a high level of protection of these fundamental rights and aims to take account of different sources of risk through a clearly defined risk-based approach.
The regulation is intended to build on EU values and fundamental rights and to help citizens and other users to trust and accept solutions based on Artificial Intelligence, and businesses are more willing to develop such solutions.
The Artificial Intelligence Act regulates:
- rules on the placing on the market, putting into service and use of Artificial Intelligence Systems in the Union;
- prohibitions on specific practices in Artificial Intelligence;
- specific requirements for high-risk artificial intelligence systems and the obligations incumbents of such systems;
- harmonised rules on transparency for artificial intelligence systems intended to interact with or manipulate images, audio content or video content.
The Act on Artificial Intelligence divides AI into 4 groups:
- 1) high-risk software,
- 2) technologies of limited impact
- 3) minimum impact technologies and
- 4) Non-acceptable schemes which will be banned in the EU.
High-risk programmes include those that use biometric data, i.e. data on physical, physiological or behavioural characteristics of a natural person, or that clearly identifies them – face image or fingerprint data, critical infrastructure management and operation systems, vocational education and training systems, criminal prosecution systems.
High-risk artificial intelligence systems will have to meet the specific requirements set out in the Artificial Intelligence Act, including, inter alia, having a function enabling the automatic recording of events (‘event registers’) during the operation of those systems, or ensuring the effective supervision of such a system by man, and obtaining the required CE marking.
Non-acceptable systems, i.e. prohibited systems, will include so-called social scoring systems to assess citizens on the basis of their social behaviour, subliminal techniques beyond the individual's awareness, artificial intelligence systems that exploit any weaknesses of a particular group of people due to their age, mobility disability or mental disorder in order to significantly distort the behaviour of a person belonging to that group.
Artificial intelligence systems used by or on behalf of public authorities for the assessment or classification of the reliability of individuals conducted for a limited period of time on the basis of their social behaviour or known or anticipated personal characteristics or personality characteristics shall also be prohibited. Subject to such a prohibition, such a point-based social evaluation shall, inter alia, lead to unfair or unfavourable treatment of certain persons or their entire groups with the purposes for which their data were originally generated or collected.
The use of AI for the so-called remote identification of biometric "in real time" in public space for law enforcement purposes is also to be unacceptable, following narrow exceptions, including where this is absolutely necessary to prevent a specific, serious and direct threat to the life or physical security of individuals or to a terrorist attack. So a specific control will be exercised by the public sector, including the police, the electoral process or courts.
The so-called "regulatory sandboxes" for the AI are also intended to form a controlled environment that facilitates the development, testing and validation of innovative artificial intelligence systems for a limited time before they are placed on the market or put into service in accordance with the specified plan. Such activities must be carried out under the direct supervision of the competent authorities and in accordance with their guidelines in order to ensure compliance with the requirements of this Regulation and, where appropriate, with other provisions of Union law and the law of the Member States under surveillance in the sandbox.
The European Council on Artificial Intelligence is also set up to contribute, inter alia, to ensuring fruitful cooperation between national supervisory authorities and the European Commission on matters falling within the scope of this Regulation. Each Member State must also establish or designate competent national authorities to ensure the application and implementation of the Artificial Intelligence Act.
For breach of the obligations to comply with the prohibition of AI practices set by the Artificial Intelligence Act, as well as for failing to comply with the relevant conditions by training, validation and testing data used to train Artificial Intelligence models, there are serious financial penalties - up to EUR 30 million or, if the perpetrator is an entrepreneur up to 6% of his total annual world turnover for the previous financial year, with a higher amount applicable.
In the event of a breach of the remaining obligations under the Artificial Intelligence Act, a financial penalty of up to EUR 20 million or if the perpetrator is an entrepreneur of up to 4% of its total annual global turnover for the previous financial year, with a higher amount applicable.