We mentioned it in a previous Digital Trends update, that AI regulation is near, but we have now seen the world’s first AI law! The full details are yet to be published, but having followed the new we know the significant details.

The AI Act, although agreed with the European Union, will apply to organisations worldwide. It puts extensive requirements on the development and use of ‘high-risk’ AI systems, as well as the AI models that are more general use. The AI Act gives organisations around 2 years to become compliant, and from there significant penalties will be enforced. Much like GDPR fines, these penalties are significant! With prohibited AI violations receiving €35million or 7% of the global annual turnover in fines. Most other violations will receive a €15million fine or 3% of the global annual turnover. Supplying incorrect information can also result in a fine, this being a significant €7.5million or 1.5% fine. SMEs and startups will have their fines capped, but these are still likely to be significant as the AI law is hoping to really deter organisations from violating it.

So what are the basics of the AI law?

The definition of AI will align with the OECD definition – “An AI system is a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that [can] influence physical or virtual environments”. There are then specific requirements and levels of transparency for different risk levels of AI; for example, High-Risk AI such as vehicles and medical devices have key requirements relating to data governance and transparency, and general AI such as generative AI will require individuals to be informed when they are interacting with AI.

High-risk AI relates to the AI tools that interact with medical devices, vehicles, education, and has access to services in finance, law, justice, and migration. The requirements for AI organisations operating in these sectors are high, with transparency and human oversight being key requirements, along with robust cyber security, risk and quality management, fundamental rights and conformity assessments, and also the requirement to register in a public EU database of high-risk AI systems.

More general AI will still be held to high standards, but these requirements are more focused around technical documentation, IP safeguards, copyright, and training data summaries. There will also be requirements for incident reporting, risk assessments, and for generative AI to be labelled and detectable.

What AI is prohibited?

There are a few AI uses that are prohibited under the AI law. The focus around prohibiting certain AI uses is to protect vulnerable people and protect people’s biometric data. Any AI used to exploit people’s vulnerabilities, biometric and sensitive characteristics, or AI used to recognise emotion will be prohibited. Law enforcement will also be prohibited from using real-time biometric identification in public.

What does the EU’s AI Act mean for the development of AI?

There are many people, including Emmanuel Macron, that believe the AI Act could hamper the development of AI in Europe. There was a battle to be the first to set out AI regulations, but there’s also a competition to become world leaders in tech and AI. You could argue that those that have regulated AI can develop the safest and therefore the most advanced AI, but then there’s also the counter arguments for not limited the growth of a technology that has so quickly developed. Setting these global standards does put the EU in the driving seat, but also allows other nations to build around the law and potentially avoid investment in the EU tech scene where it doesn’t suite them. Either way, AI will continue to develop, both safely and unregulated. The EU setting such high standards shows that AI technology has the potential to be damaging to society and it’s a good thing that protections are now in place. With the development of AI still in its infancy, could these standards have come too soon? AI has yet to reach its peak, so should there be such strict measures to prevent that? Well, we can only wait and see.

With the regulations still to fully be set, and many more laws to follow, the next few years of AI development are really looking to be defined. So be sure to keep up with all the key advancements and developments within the tech world and AI by subscribing to Digital Trends.

If you’re working within AI, or any other regulated sector, then we have written up a blog on navigating marketing within these sectors. We are always happy to help develop a marketing strategy to navigate through highly regulated sectors, having done plenty of research around the communications in these spaces.