EU AI Act – Overview

Date of publication: July 10th, 2024
With the rapid growth of AI as a tool to assist users in being more efficient and productive, countries are rolling out new regulations to address potential risks posed by AI while providing AI systems and users with governance guidance to eliminate and/or mitigate risks.
The European Union's new Artificial Intelligence (AI) Act, (final Act signed on June 13, 2024), establishes a comprehensive regulatory framework for AI systems within the EU. This landmark legislation categorizes AI systems based on the level of risk they pose, ranging from minimal to unacceptable, and tailors the requirements accordingly. The legislation has been adopted by Council and Parliament. It is expected to be published in the Official Journal later in July and will come into force 20 days thereafter. It will be effective after 24 months.
The following provides an overview of the new law and considerations for companies as they embrace innovative technology systems that incorporate the use of AI.

A. Applicability of the law

To whom does this law apply?
  1. Providers placing on the market or putting into service AI systems or placing on the market general-purpose AI models in the Union, irrespective of whether those providers are established or located within the Union or in a third country.
  2. Deployers of AI systems that have their place of establishment or are located within the Union.
  3. Providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union.
  4. Importers and distributors of AI systems.
  5. Product manufacturers placing on the market or putting into service an AI system together with their product and under their own name or trademark.
  6. Authorized representatives of providers, which are not established in the Union.
  7. Affected persons that are located in the Union.
  8. The EU AI Act is not sector specific. It applies to all sectors.
When does it not apply?
  1. Does not apply to AI systems used for military, defense or national security purposes or international organizations for law enforcement and judicial cooperation (provided they protect individual rights).
  2. Does not apply to AI systems used for scientific research & development, or AI systems not yet on the market.
  3. Does not apply to individuals using AI systems for personal, non-professional activities, or AI systems released under free and open-source licenses, unless they are high risk or fall under certain articles.
  4. Does not affect existing EU laws on data protection, privacy, and confidentiality.

B. Implementation timeline

The majority of the obligations for most businesses will take effect after two years. The various provisions will be phased over time as follows:
  • 6 months:
    bans concerning prohibited AI systems will become applicable.
  • 9 months:
    AI Office codes of practice should become available.
  • 12 months:
    requirements concerning general purpose AI will become applicable.
  • 24 months:
    most of the rules in the Act will take effect.
  • 36 months:
    obligations relating to AI systems that are “high-risk” because they are subject to specified EU product safety legislation (such as regulations governing vehicles, machinery, and toys) will become applicable.

C. Key provisions of the AI Act include:

  1. Prohibited Practices:
    The Act bans certain AI applications deemed to pose unacceptable risks. These include manipulative AI that exploits vulnerabilities, real-time biometric identification in public spaces for law enforcement (with limited exceptions), and AI systems that assess personal traits for criminal prediction.
  2. High-Risk AI Systems:
    This category includes AI systems integral to safety in products (like medical devices) or those used in critical areas such as employment, law enforcement, and essential public services. These systems must meet stringent requirements concerning risk management, data handling, transparency, and cybersecurity before they can enter the EU market.
  3. Transparency Requirements:
    AI systems that interact directly with users or manipulate media (like deepfakes) must disclose their nature and limitations to users to prevent deception.
  4. General AI Systems:
    The Act sets specific rules for general-purpose AI models, especially those with significant capabilities that could impact the internal market or society. These models require rigorous documentation, risk assessment, and compliance with robust standards to ensure safety and respect for fundamental rights.
  5. Enforcement and Penalties:
    The Act mandates strict penalties for non-compliance, which can reach up to €35 million or 7% of the total worldwide annual turnover, depending on the severity of the infringement. But for many infringements, the maximum fines are the higher of €15 million or 3% of total worldwide annual turnover.
  6. Support for Innovation:
    The Act encourages innovation through regulatory sandboxes, which allow developers to test and refine AI systems in controlled environments before broader deployment.
This regulation aims to ensure that AI systems are developed and deployed in a way that respects EU standards and values, promoting trust and safety in technology while fostering innovation and economic growth.

D. AI defined

AI is defined in the EU AI Act using the following terms:
  • "AI system" means "a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments."
  • "General-purpose AI model" means "an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
  • "General-purpose AI system" means "an AI system which is based on a general-purpose AI model, and which has the capability to serve a variety of purposes, both for direct use as well as for integration in other AI systems."

E. Other regulations to consider

There are numerous other laws applicable in the EU that may affect the development or use of AI in the EU. A non-exhaustive list of common examples includes:
  • The EU General Data Protection Regulation (EU) 2016/679 - GDPR
  • The Product Liability Directive, which, if adopted, will allow people harmed by software (including AI software) to receive compensation from the software manufacturer (replacing Directive 85/374/EEC) – this is in draft form. Timing unknown
  • The General Product Safety Regulation 2023/988/EU, replacing Directive 2001/95/EC
  • Various intellectual property laws under the national laws of EU Member States
The AI Act will likely be supplemented by the proposed EU AI Liability Directive (AILD) and the new Product Liability Directive (PLD).
  • AILD. The AI Act contains no provisions addressing liability for damage claims, but the AILD gives more certainty around liability, creating a rebuttable presumption that any fault in an AI system is the fault of the developer. Critics have questioned, however, how it will be established that an AI system has malfunctioned and is at fault.
  • PLD. The new PLD, which is intended to be adopted by the Council of the EU later this year, aims to modernize the existing rules on the strict liability of manufacturers for defective products. It gives individuals the right, on the basis of strict liability, to claim compensation from manufacturers for damage they have suffered as a result of a product defect. The new PLD thus creates a framework that makes it easier for individuals to assert and enforce such claims.
It should be noted that the AI Act is one of numerous global laws, pending regulations and executive orders on the subject of AI. It will be important to monitor and understand the other regulations as they move forward to ensure compliance. Other examples of where AI legislation is moving forward or exists today include (but are not limited to) UK, Switzerland, Canada, Brazil, China, Japan, India, Australia, and numerous US state-level laws such as NY, CO, OH, PA, TX, etc. Although many of these pending laws are currently focused on the higher risk areas (e.g., individual profiling) that may not have application in the GTM environment, this is a rapidly evolving area so monitoring will be important.

F. Definitions of stakeholders

The AI Act affects various stakeholders. It applies to providers, deployers, importers and distributors of AI systems or general-purpose AI models (GPAI), as well as product manufacturers that offer AI as part of their product offering.
  • Providers:
    Primary focus of the AI Act is on “providers” of AI systems and models. Broadly, providers are organizations supplying AI under their own brand. Providers will be subject to the Act if: (a) they put their AI on the market in the EU, or (b) the output of their AI system is used in the EU.
  • Deployers:
    In essence they are the users of the AI systems. Deployers are subject to the Act if (a) they are located or established in the EU, or (b) the output of the AI system is used in the EU.
  • Importers:
    Organizations that are located or established in the EU that offer in the EU AI systems under the brand of a non-EU organization.
  • Distributors:
    Anyone in the supply chain that makes an AI system available on the EU market (that is not a provider or an importer).
A critical aspect of the Act is the distinction between 'Providers' and 'Deployers' of AI systems. This carries significant legal implications, and in practice, the line between the two is sometimes hard to define. Given that the Act heavily focuses on Providers' obligations, correct classification is important for managing risk exposure in the event of regulatory challenges.
To help better define these stakeholders, the below grid can be used as guidance.
ASPECT
AI PROVIDER
AI DEPLOYER
Definition
Entity that develops or has an AI system developed and places it on the market or puts it into service under its own name or trademark.
Entity using an AI system under its authority, except for non-professional personal use.
Development
Direct involvement in or commissioning the creation and design of AI systems.
Integrates and manages AI systems created by others.
Market Placement
Responsible for introducing AI systems to the market.
Uses AI systems within their operations without introducing them to the market.
Compliance Obligations
Ensures AI systems meet safety, transparency, and accountability standards before market introduction.
Ensures AI systems are used in compliance with the Act during operations and monitors performance and outcomes.
Risk Exposure
Bears significant responsibilities and risks, including compliance with the full scope of the Act's requirements.
Bears responsibility for verifying the Provider's compliance and the AI system's performance.
(Mishcon de Reya LLP; 2024)
Providers of General Purpose AI (GPAI) will be subject to obligations like those of high-risk AI systems, including model registration, risk management, data governance and documentation practices, implementing a quality management system and meeting standards pertaining to performance, safety, and resource efficiency.
The AI Act defines a GPAI as “an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications.”

G. Risk categorization

The EU AI Act also classifies AI systems according to various levels of risk, as the law takes a risk-based approach. Requirements are based on the level of risk posed:
  • Unacceptable risk:
    AI systems that present an “unacceptable” risk are prohibited. This includes (among others) AI systems used for social scoring and AI systems that use deceptive or exploitative techniques to materially distort a person’s behavior in a manner that can cause harm.
  • High risk:
    AI systems that present a “high” risk include AI systems. These fall within two categories: (i) AI systems used as a safety component of a product (or otherwise subject to EU health and safety harmonization legislation); or (ii) AI systems deployed in eight specific areas, including (among others) education, employment, access to essential public and private services, law enforcement, migration, and the administration of justice.
  • Limited risk:
    AI systems that present “limited” risk include those that directly interact with natural persons (e.g., chatbots), emotion recognition systems, biometric categorization systems, and AI systems that generate "deep fakes" (i.e., audio or visual content that appears genuine, even though it is created by an AI system) are required to disclose the fact that the content has been artificially generated or manipulated. The transparency obligations imposed on deployers of these AI systems do not apply where the use is authorized by law to detect, prevent, investigate, and prosecute criminal offenses. If the content is "evidently" an artistic, creative, satirical, fictional analogous work or program, these obligations are limited to the disclosure of existence of "deep fakes" in an appropriate manner that does not hamper the display or environment of the work.
  • Low or minimal risk:
    Any AI system not caught by the above are of low or minimal risk.
The limited risk category covers systems with limited potential for manipulation, which are subject primarily to transparency obligations. This includes informing a person of their interaction with an AI system and flagging artificially generated or manipulated content.

H. How to prepare

  • Identify AI systems:
    Catalog the software and hardware products being used by your company (both internally and externally) and assess which could fall under the definition of “AI systems.”
  • Assess whether the Act applies:
    For identified AI systems, determine if they are covered by the broad scope outlined in the AI Act, e.g., if the system is offered to users in member states.
  • Classify the systems:
    Classify AI systems according to their regulatory tier/risk under the law, recognizing that only a subset may be categorized as prohibited or high-risk.
  • Determine organizational role:
    Understand the specific requirements to which the software / hardware must comply in relation to these AI systems. Identify the organizational role — whether provider, deployer or other — to determine obligations under the law.
  • Review Requirements:
    Once proper categorizations are determined, review the specific requirements for those categories to identify compliance obligations.
  • Develop a compliance plan:
    This is needed to ensure compliance with the obligations and seamlessly integrate them into your broader compliance framework.
While the AI Act does not encompass all AI systems, it is important to remember that those outside its scope remain regulated under other frameworks, such as the GDPR, as well as by consumer protection and intellectual property laws. These laws also apply to AI systems that fall within the scope of the AI Act.

I. Sample of possible requirements

As the requirements can vary depending on proper categorization of roles and risk level, it is best to determine those items before reviewing the relevant requirements. However, the below provides a sample of what some requirements could be once determination is made.
  • Create and maintain comprehensive documentation, including detailed information about model architecture, training methodologies and data, testing processes, and energy consumption. This documentation must be provided to the EU AI Office and competent national authorities upon request.
  • Provide downstream providers who integrate their systems with certain information, including information and documentation required to enable such downstream providers to have a “good understanding” of the capabilities and limitations of the GPAI, and to comply with their obligations under the AI Act.
  • Put in place a policy for complying with EU copyright law.
  • Make publicly available a “sufficiently detailed summary” of the training data used, in a format to be determined by the EU AI Office.
  • Appoint an authorized representative in the EU (if the provider is established outside the EU)
  • Providers of AI systems that interact directly with individuals (such as chatbots) must ensure that it is reasonably clear to individuals that they are interacting with AI.
  • Providers of systems that create AI-generated content must ensure that the content is marked in a machine-readable manner to indicate that it is AI-generated.
  • Deployers of AI systems that generate “deep fakes” must disclose that the content is artificially generated or manipulated.
  • Deployers of AI systems that generate or manipulate text for informing the public on matters of public interest (e.g., current affairs, journalism) must disclose that the content is artificially generated or manipulated (unless there is sufficient human review/control).
Understanding requirements under the EU AI Act will position companies to have meaningful conversations with their technology providers (both internal and external) that are incorporating AI into their solutions. The new world of AI is a rapidly changing one and the EU AI Act is just the beginning of additional regulations that will come into force as stakeholders better comprehend this new tool and how to use it in a productive, safe, and secure manner.
ONESOURCE™ Global Trade is currently working on ways to incorporate AI into its solutions to allow for greater efficiencies, productivity and streamlined work processes for users. Be on the lookout for news on our HS Assistant in the coming months! More information will follow as it becomes available.
For additional information on AI, visit Thomson Reuters Institute, Technology and Innovation Resource Center and explore how technology and innovation will influence the evolution of future legal, tax, trade, accounting, risk & fraud and ESG services. You can also download our new Future of Professionals 2024 report which discusses AI-powered technology and the forces shaping professional work in the future.