What does the European Union aim to achieve?
A revolution in the field of artificial intelligence (AI) is happening before our eyes. EU institutions recognize the potential benefits that AI brings, but they also see the threats. Artificial intelligence supports human work. It analyzes vast amounts of data, selects information, and draws conclusions. It recognizes and creates images. The interference of AI in human life is increasing, which may affect our private interests, such as participation in recruitment, the course of education, or access to healthcare.

An intelligent camera system can, for example, identify individuals who pose a threat at the airport. This increases the safety of all passengers. The system may be 99% effective, but should we accept that 1% of tens of thousands of travelers will face serious inconveniences?
AI did not emerge "from nowhere." It was trained on a vast amount of data. EU institutions have noted the lack of transparency in the creation of AI systems. This means, for example, a lack of control over what data was used to train the system. What will happen if AI is trained on content that contains discriminatory opinions against certain social groups based on their gender, age, race, or sexual orientation? There is a risk that a poorly trained AI model will incorporate learned biases, unfairly treating and even harming many individuals.
Progress and the free market often go hand in hand, but they do not align well with new regulations, obligations, and penalties. Nevertheless, the Union is convinced that the new Regulation will not stifle the development of AI in Europe. On the contrary, the new legal framework is intended to support this development by increasing citizens' trust in safe and regulated AI. Entrepreneurs are also expected to benefit. The introduction of the new regulation in the form of a Regulation aims to ensure the common and uniform application of rules regarding AI across all EU member states. This is intended to facilitate entrepreneurs' simultaneous entry into multiple markets. Legal uncertainty is to be eliminated through clear rules.
What AI will be prohibited?
Some uses of AI are completely prohibited. For example, there is no consent from the Union for obtaining the images of individuals from surveillance cameras for the purpose of expanding databases. Law enforcement agencies will be able to use AI systems integrated with cameras to identify dangerous individuals in public places in real-time, but only to a limited extent. This applies, for instance, to combating the most serious crimes and threats to public safety. Each such system must be approved by an authorized body, such as a court.
Systems that recognize human emotions in the workplace or in educational institutions will be illegal. Permissible exceptions must be dictated by safety or medical considerations. For example, it will be possible to monitor a pilot's level of fatigue in the workplace.
AI systems must not intentionally mislead or exploit particularly vulnerable individuals. The use of AI for social scoring of individuals will also be unacceptable if such scoring leads to harmful or unfavorable treatment of certain individuals or groups of individuals.
Who do the new regulations apply to?
The regulation will apply to both public and private entities in the EU and beyond, as long as the AI system is deployed in the EU market or its use affects individuals located in the EU.
The obligations set forth in the regulation apply to both providers and importers and distributors of AI solutions. Some obligations also rest on entities using high-risk AI systems, for example, a bank deciding to purchase such a dedicated tool.
What are high-risk AI systems?
AI systems that may adversely affect the safety and fundamental rights of citizens are considered high-risk systems. An annex to the regulation contains a list of such systems. For example, a system used in recruitment that analyzes CVs submitted by job candidates is regarded as a high-risk system. The application of AI in education may pose high risks if AI assesses learning outcomes. AI used in access to healthcare services or in creditworthiness assessments may also be highly risky. Another example of such a system is AI that evaluates and classifies received emergency calls.
What are the new obligations related to high-risk AI systems?
Before putting a high-risk AI system into operation, providers should conduct a compliance assessment in light of the adopted requirements regarding AI. These requirements include, among others, data quality, documentation, traceability, transparency, human oversight, accuracy, cybersecurity, and reliability. Providers of high-risk AI systems will need to implement quality and risk management systems to minimize threats to users.
Entities using such systems should take appropriate technical and organizational measures to ensure that the systems are used in accordance with the operating instructions, and that the individuals overseeing them possess the necessary competencies. Additional informational obligations regarding the use of AI have emerged.
High-risk AI systems that will be implemented by public authorities will be registered in a public EU database. An exception applies to systems used for law enforcement and immigration purposes, which will also be registered in the database, but only in its non-public part.
Specific Approach to General-Purpose AI
The regulation imposes additional requirements on providers of general-purpose AI. Such AI is defined as AI that has been trained using a total computational power exceeding 10^25 FLOP. This threshold includes the two most advanced models of this type, such as OpenAI's GPT-4 and Google's Gemini.
According to EU authorities, general-purpose AI systems are powerful enough to pose systemic risks. Consequently, providers of such systems will be required to assess and mitigate risks, report serious incidents, conduct state-of-the-art testing and evaluations of models, ensure cybersecurity, and provide information regarding the energy consumption of their systems.
Financial Administrative Penalties

PROMOTIONAL OFFER
Compliance with the AI Act and Cybersecurity
Do you need support in the secure implementation of AI solutions? During the conversation, you will learn about the requirements of the AI Act and receive a special offer for a security audit of the systems.
Potential penalties can be very high. For example, continued use of prohibited AI may result in a fine of up to €35 million or 7% of the total annual global turnover from the previous financial year (whichever of these amounts is higher).
The Commission announces that it will develop guidelines regarding the provisions and practices related to the imposition of penalties.
Do you want to know more?
The EU regulation on artificial intelligence is a comprehensive and complex legal act. In December 2023, the EU Commission published a document containing a set of questions and answers, which further explains the purpose of the introduction and the fundamental principles of the new regulation. We invite you to read the Polish translation of this publication.
AI Act: Translation
Why are regulations on the use of artificial intelligence necessary?
The potential benefits to society from artificial intelligence (AI) are diverse – from improving healthcare to streamlining education. In the face of the rapid technological development of artificial intelligence, the EU has decided to act unanimously to seize existing opportunities.
The AI Act represents the world's first comprehensive legal regulation on this subject. Its aim is to counteract threats to security, health, and fundamental rights. The regulation also seeks to protect democracy, the rule of law, and the environment.
Although most AI systems pose little or even zero risk, some of them generate threats that need to be addressed to avoid undesirable outcomes.
For example, the lack of transparency in many algorithms can create uncertainty and hinder the effective enforcement of existing regulations regarding safety and the protection of fundamental rights. In response to these challenges, legislative action was necessary to ensure the smooth functioning of the internal market for AI systems, taking into account both benefits and risks.
This applies to applications in biometric identification systems or when AI is used to make decisions regarding important personal interests, such as recruitment, education, healthcare, or law enforcement.
With the latest advancements in artificial intelligence, increasingly powerful generative AI is emerging. So-called general-purpose AI models, which are integrated into many AI systems, are becoming too important for the economy and society to remain unregulated. In light of potential systemic risks, the EU is implementing effective regulations and efficient oversight.
What threats will be considered in the new regulations regarding artificial intelligence?
The implementation of artificial intelligence systems has significant potential. It can bring social benefits, economic growth, increase innovation, and enhance the global competitiveness of the EU. However, in certain cases, the specific characteristics of some AI systems may pose new threats related to user safety and the protection of fundamental rights. Some powerful and widely used AI models may carry systemic risks.
This creates legal uncertainty among companies and potentially leads to slower adoption of AI technologies by businesses and citizens due to a lack of trust. A varied regulatory approach by national authorities to this issue could threaten the fragmentation of the internal market.
Who is affected by the act on artificial intelligence?
The legal framework will apply to both public and private entities within the EU and beyond, provided that the artificial intelligence system is deployed in the EU market or its use affects individuals located in the EU.
The regulations may concern both providers (e.g., creators of tools for CV verification) and entities using high-risk AI systems (e.g., a bank deciding to purchase such a tool). Importers of AI systems will also need to ensure that the foreign provider has conducted the appropriate conformity assessment procedure and obtained European Conformity (CE) marking, as well as that the required documentation and user instructions are included with the system.
Furthermore, the EU act provides for specific obligations for providers of general-purpose AI models, including large generative AI models.
Providers of free and open models will be exempt from most of the above obligations. This exemption does not apply to providers of general-purpose AI models that are associated with systemic risks.
The discussed obligations do not apply to research, development, and prototypes preceding market introduction. Moreover, the regulation does not apply to AI systems intended solely for military, defense, or national security purposes – regardless of the type of entity conducting these activities.
What are the categories of risk?
The Commission proposes a risk-based approach, with four levels of risk for artificial intelligence systems, as well as the identification of risks specific to general-purpose models:
- Minimal risk: All AI systems that do not fall into the other levels may be developed and used in accordance with applicable regulations without additional legal obligations. This category includes the vast majority of AI systems currently in use or likely to be used in the EU. Providers of such systems may voluntarily decide to apply requirements for trustworthy AI and adhere to voluntary codes of conduct.
- High risk: A limited number of AI systems specified in the proposal, which could potentially have an adverse impact on the safety of individuals or their fundamental rights (protected by the Charter of Fundamental Rights of the EU), are considered high-risk systems. An annex to the regulation contains a list of high-risk AI systems, which may be reviewed to adapt to the development of AI applications.
- This level also applies to product safety elements covered by EU sectoral legislation. Such elements will always be considered to carry high risk if they are subject to compliance assessment conducted by a third party under sectoral regulations.
- Unacceptable risk: This category includes a specific set of particularly harmful AI applications that are contrary to EU values, as they violate fundamental rights, and therefore will be prohibited. These include:
- social scoring for public and private purposes;
- exploitation of vulnerable individuals, use of subliminal techniques;
- real-time biometric remote identification in publicly accessible places carried out by law enforcement authorities, with a few exceptions (see below);
- biometric categorization of individuals based on biometric data to determine or establish the race of those individuals, political opinions, membership in trade unions, religious or philosophical beliefs, or sexual orientation. Filtering of data sets based on biometric data in the area of law enforcement will still be possible;
- individual predictive surveillance system;
- emotion recognition in the workplace and in educational institutions, except in cases where it is dictated by medical or safety considerations (e.g., monitoring a pilot's fatigue level);
- non-targeted acquisition of facial images from the Internet or surveillance cameras for the purpose of creating or expanding databases.
- Specific risk regarding transparency: For certain AI systems, it is necessary to meet specific requirements regarding transparency, for example, when there is a clear risk of manipulation (as in the case of using chatbots). Users should be aware that they are interacting with a machine.
Furthermore, the Artificial Intelligence Act takes into account the systemic risk that may arise from the use of general-purpose AI models, including large generative AI models. Such models can be used for various tasks and become the basis for many AI systems in the EU. Some of these models may pose systemic risks if they are highly functional or widely used. For example, powerful models could lead to serious incidents or could be misused to conduct large-scale cyberattacks. Many individuals could suffer if a model disseminates harmful biases against them across multiple applications.
How to determine if an artificial intelligence system is high-risk?
Along with a clear definition of “high risk,” the regulation also establishes a reliable methodology that will assist in identifying high-risk AI systems in accordance with the established legal frameworks. This aims to provide legal certainty to businesses and other entities.
The risk classification is based on the criterion of the intended purpose of the AI system while ensuring compliance with applicable EU product safety regulations. This means that the risk classification depends on the function performed by the AI system and the specific purpose and conditions under which the system is used.
Attached to the regulation is a list of cases of AI systems deemed to be high-risk. The Commission will ensure that this list is continuously updated and adjusted. Systems listed as high-risk applications that perform limited procedural tasks, improve the outcomes of previous human actions, do not influence human decisions, or perform purely preparatory tasks are not considered to pose high risk. However, an AI system will always be regarded as a high-risk system if it engages in the profiling of natural persons.
What are the obligations of providers of high-risk AI systems?

PROMOTIONAL OFFER
Prepare for AI regulations in your company
Are you wondering how to adapt the use of AI to new legal requirements? During the consultation, we will assess your compliance with the AI Act and you will receive a discount on a comprehensive risk analysis.
Before placing a high-risk AI system on the EU market or making it available for use in any other way, providers must subject the system to a compliance assessment. This will enable them to demonstrate that their system meets the mandatory requirements for AI reliability (such as data quality, documentation, traceability, transparency, human oversight, accuracy, cybersecurity, and reliability). The assessment should be repeated if the system or its purpose undergoes significant modification.
AI systems that are components of product safety, which are covered by sectoral EU law, will always be considered high-risk if they are subject to compliance assessment conducted by a third party based on that sectoral law. Similarly, for biometric systems, compliance assessment by a third party is always required.
Providers of high-risk AI systems will also need to implement quality and risk management systems to ensure compliance with the new requirements and minimize risks to users and affected individuals, even if the product has already been placed on the market.
High-risk AI systems that are implemented by public authorities or entities acting on their behalf will need to be registered in the EU public database, unless they are used for law enforcement purposes and for immigration-related needs. In such cases, the systems will need to be registered in a non-public part of the database, which will be accessible only to the relevant supervisory authorities.
Market surveillance authorities will support the monitoring process of the AI system after its market introduction through audits and by enabling providers to report serious incidents or breaches of obligations regarding the protection of fundamental rights when they obtain information about such events. Each market surveillance authority may, in exceptional cases, allow the marketing of a specific high-risk AI system.
Thanks to the introduced regulations, national authorities will have access to information necessary to verify whether the use of the AI system was lawful in the event of a breach.
What are examples of high-risk AI system applications defined in Annex III?
- Some elements of critical infrastructure, e.g., in the areas of traffic management and the supply of water, gas, heating, and electricity.
- Education and vocational training, e.g., for assessing learning outcomes and controlling the educational process and prevention.
- Employment, employee management, and access to self-employment, e.g., posting targeted job advertisements, analyzing and filtering job applications, and assessing candidates.
- Access to key private and public services and benefits (e.g., healthcare), creditworthiness assessment of individuals, and risk assessment and valuation concerning life and health insurance.
- Some systems used in the area of law enforcement, border control, justice, and in democratic processes.
- Assessment and classification of emergency calls.
- Biometric identification systems, categorization, and emotion recognition (outside of prohibited categories).
- Recommendation systems used by very large online platforms have not been included, as they are already covered by other regulations (Digital Markets Act [DMA]/Digital Services Act [DSA]).
How are general-purpose AI models regulated? General-purpose AI models, including large generative AI models (GPAI), can be used for various tasks. Individual models may be integrated with a large number of AI systems. It is essential for a provider planning to utilize a general-purpose AI model to have all the necessary information. This ensures that their system is secure and compliant with the Artificial Intelligence Act. For this reason, the Artificial Intelligence Act requires providers of such models to disclose certain information to further AI system providers. Such transparency enables a better understanding of these models. AI model providers should also implement principles during their training to ensure compliance with copyright regulations. Some of these models may pose systemic risks due to their immense capabilities or wide applicability. Currently, general-purpose AI models that have been trained using a total computational power exceeding 10^25 FLOP are considered to carry systemic risk, assuming that models trained with greater computational power are generally more efficient. The European Artificial Intelligence Authority (established within the Commission) will be able to update this threshold in light of technological advancements. Furthermore, it may, in specific cases, designate other models as carrying such risks based on additional criteria (e.g., the number of users or the degree of autonomy of the model). Therefore, providers of models that pose systemic risks will be required to assess and mitigate risks, report serious incidents, conduct state-of-the-art testing and evaluations of models, ensure cybersecurity, and provide information regarding the energy consumption of their models. Consequently, they will be asked to collaborate with the European Artificial Intelligence Authority to develop codes of conduct. These will be treated as a primary tool for detailing the principles of cooperation with other experts. A scientific team will play a key role in overseeing general-purpose AI models.
Why is 10^25 FLOP an appropriate threshold for GPAI models deemed to pose systemic risk?
The 10^25 FLOP threshold currently takes into account the most advanced GPAI models, namely OpenAI's GPT-4 and likely Google's DeepMind Gemini. The capabilities of models exceeding this threshold are not yet sufficiently understood. They may pose systemic risks, thus it is justified to impose an additional set of obligations on the providers of these models. The FLOP threshold is intended to serve as an initial indicator of a model's capabilities. It may be raised or lowered by the European Artificial Intelligence Authority, for instance, in light of advancements in objectively measuring model capabilities and the development of computational power required to achieve a certain level of performance. The Artificial Intelligence Act may be updated to change the FLOP threshold (via a delegated act).
Is the Artificial Intelligence Act a forward-looking solution?
The regulation indicates various levels of risk and contains clear definitions, including those related to GPAI. The provisions set outcome-oriented requirements for high-risk AI systems. However, specific technical solutions and operational arrangements are left to be regulated in industry standards. These will provide the flexibility of the legal framework, allowing it to be adapted to various use cases and enabling the introduction of new technological solutions. Furthermore, the Artificial Intelligence Act may be amended by delegated and implementing acts, including to update the FLOP threshold (delegated act), add criteria for classifying GPAI models as posing systemic risks (delegated act), and change the conditions for establishing regulatory sandboxes and elements of real-world testing plans (implementing acts).
How does the Artificial Intelligence Act regulate biometric identification?
The use of remote biometric identification in real-time in publicly accessible places for law enforcement purposes (e.g., facial recognition using CCTV) is prohibited, unless it occurs in one of the following cases:
- law enforcement actions related to 16 specified crimes;
- targeted searches for specific victims, abduction situations, human trafficking and sexual exploitation, and disappearances; or
- preventing threats to life or physical safety of individuals or responding to current or foreseeable threats of a terrorist attack.
The list of 16 crimes includes:
- terrorism;
- human trafficking;
- sexual exploitation of children and the creation of materials depicting the sexual exploitation of children;
- illegal trafficking in narcotic drugs and psychotropic substances;
- illegal trafficking in weapons, ammunition, and explosives;
- murder;
- serious bodily harm;
- illegal trafficking in human organs and tissues;
- illegal trafficking in nuclear or radioactive materials;
- kidnapping, illegal deprivation of liberty, and taking hostages;
- crimes under the jurisdiction of the International Criminal Court;
- unlawful seizure of an aircraft/ship;
- rape;
- environmental crimes;
- organized robbery or armed robbery;
- saboteur activities, participation in a criminal organization involved in at least one of the crimes listed above.
Remote biometric identification in real-time used by law enforcement agencies will require prior approval by a judicial authority or an independent administrative body. This decision will be binding. In emergencies, approval may be granted within 24 hours. If the request for approval is denied, all data and results must be deleted.
The above procedure must be preceded by an assessment of the impact on fundamental rights and should be reported to the relevant market supervisory authority and the data protection supervisory authority. In emergencies, the system may be implemented without formal registration.
The use of AI systems for subsequent remote biometric identification of individuals subject to investigation (i.e., identifying individuals visible in the collected video material) will require prior approval by a judicial authority or an independent administrative body, as well as notification to the data protection authority and the market supervisory authority.
Why must remote biometric identification be subject to special rules?
Biometric identification can take various forms. It can be used to identify a user, for example, to unlock a smartphone, or for verification and checking activities at border crossings to confirm a person's identity based on their travel documents (“one-to-one matching”).
Biometric identification can also be used remotely to identify individuals in a crowd when a person's image is checked against a database (“one-to-many matching”).
The accuracy of facial recognition systems can vary significantly depending on a number of factors, such as camera quality, lighting, distance, database, algorithm, as well as the ethnic origin, age, or gender of the individual. This also applies to gait and voice recognition, as well as other biometric systems. Highly advanced systems continuously reduce false identification rates.
Although an accuracy rate of 99% may seem high, it can still be very risky if it results in suspicion being cast on an innocent person. Even an error rate of 0.1% is substantial when it concerns tens of thousands of individuals.
How do regulations protect fundamental rights?
Working with good GDPR tools is not work!
A human-centered approach to AI requires ensuring that AI applications comply with regulations concerning the protection of fundamental rights. Requirements for accountability and transparency regarding the use of high-risk AI systems, combined with improved law enforcement capabilities, will ensure that legal compliance is considered at the design stage.
In the event of violations, the regulations will enable national authorities to access the information necessary to clarify whether the use of AI was in accordance with EU law.
Furthermore, the Artificial Intelligence Act requires implementing entities, which are public authorities, private entities providing public services, or providers of high-risk systems, to conduct a Data Protection Impact Assessment regarding the protection of fundamental rights.
What is a Data Protection Impact Assessment regarding the protection of fundamental rights? Who and when must conduct such an assessment?
The use of high-risk AI systems may impact fundamental rights. Consequently, implementing entities that are public authorities, private entities providing public services, or suppliers of high-risk systems conduct a Data Protection Impact Assessment (DPIA) regarding the impact on fundamental rights and notify the national authority of its results.
The assessment consists of a description of the processes of the implementing entity in which the high-risk AI system will be used, an indication of the time and frequency with which the high-risk AI system is to be utilized, the categories of natural persons and groups that may be affected by the use of the AI system in a specific context, the identification of specific risks of harm that may concern these categories of persons or groups, as well as a description of the implementation of human oversight measures and the actions to be taken in the event of a threat arising.
If the supplier has already fulfilled this obligation through a Data Protection Impact Assessment (DPIA), the assessment of the impact on fundamental rights should be conducted in conjunction with the DPIA.
How do the new regulations address issues of racial and gender bias in AI?
It is very important that AI systems do not create or perpetuate biases. Properly designed and utilized AI systems can rather contribute to reducing biases and existing structural discrimination, thereby leading to fairer and non-discriminatory decisions (e.g., in recruitment).
The new requirements for all high-risk AI systems will serve this purpose. Artificial intelligence systems must be technically reliable to ensure that the technology is suitable for the intended purpose, and that false positive or negative results do not disproportionately affect protected groups (e.g., based on racial or ethnic origin, gender, age, etc.)
High-risk systems will also need to be trained and tested using sufficiently representative datasets to minimize the risk of discriminatory biases embedded in the model and to ensure counteraction through appropriate bias detection, correction, and the application of other remedial measures.
Models must also be traceable and auditable, ensuring the retention of appropriate documentation, including data used to train the algorithm. This will be crucial in ex post investigations.
The compliance management system both before and after the introduction of AI systems to the market will need to ensure their regular monitoring and swift response to potential threats.
When will the Artificial Intelligence Act fully come into force?
The Artificial Intelligence Act will come into effect on the twentieth day after its publication in the Official Journal of the European Union, following its adoption by the European Parliament and the Council. Its full application will begin 24 months after it comes into force, with the following timelines:
- 6 months – after coming into force, member states will gradually withdraw prohibited systems;
- 12 months – requirements for managing general-purpose artificial intelligence will begin to apply;
- 24 months all provisions of the Artificial Intelligence Act will apply, including obligations regarding high-risk systems specified in Annex III (list of high-risk cases);
- 36 months – obligations regarding high-risk systems specified in Annex II (list of EU harmonization legislation) will apply (in the current text of the Regulation, this is Annex I – note from the DPO 24).
How will the Artificial Intelligence Act be enforced?
At the national level, member states will be required to designate at least one competent national authority, among which there will be a national supervisory authority that will oversee the application and implementation of the regulation, as well as conduct market surveillance activities.
To enhance effectiveness and establish an official point of contact with society and other partners, each member state should designate one national supervisory authority that will also represent the country in the European Artificial Intelligence Board.
The source of additional technical knowledge will be a consultative forum, representing a balanced selection of stakeholders, including industry representatives, start-ups, SMEs, civil society, and academic communities.
Additionally, a European Artificial Intelligence Office will be established within the Commission. It will oversee general-purpose AI models and collaborate with the European Artificial Intelligence Board. It will be supported by a scientific panel consisting of independent experts.
Why is the European Artificial Intelligence Board needed and what will it focus on?
The European Artificial Intelligence Board will consist of high-level representatives from the relevant national supervisory authorities, the European Data Protection Supervisor, and the Commission. Its task is to facilitate the efficient, effective, and harmonized implementation of new regulations concerning artificial intelligence.
The Board will issue recommendations and opinions for the Commission regarding high-risk AI systems and other aspects essential for the effective and uniform implementation of the new regulations. It will also support standardization efforts in this area.
What tasks will the European Artificial Intelligence Agency have?
The European Artificial Intelligence Agency will develop EU expertise and capabilities in the field of artificial intelligence and will contribute to the implementation of EU regulations concerning AI through a centralized structure.
The task of the European Artificial Intelligence Agency will particularly involve enforcing and supervising new regulations concerning general-purpose AI models. This includes preparing codes of conduct to detail the principles, the Agency's role in classifying AI models as posing systemic risk, and monitoring the effective implementation and compliance with the provisions of the regulation. The execution of the latter task will be facilitated by the powers to request documentation, conduct assessments of models, carry out investigations in case of alerts, and call on providers to take corrective actions.
The Artificial Intelligence Agency will ensure coordination of policies in the field of AI and cooperation among the involved institutions, bodies, and agencies of the Union, as well as with experts and stakeholders. The Agency will particularly focus on establishing a strong connection with the scientific community to support law enforcement. It will also act as an international reference point for independent experts and expert organizations and facilitate the exchange of information and cooperation with similar institutions worldwide.
What are the differences between the European Artificial Intelligence Board, the European Artificial Intelligence Agency, the advisory forum, and the scientific panel of independent experts?
The European Artificial Intelligence Board will carry out expanded tasks involving advising and supporting the Commission and member states.
European Office for Artificial Intelligence, established within the Commission, is to work towards the development of EU expertise and capabilities in the field of AI and contribute to the implementation of EU regulations concerning AI. In particular, the European Office for Artificial Intelligence will enforce and supervise new regulations regarding general-purpose AI models.
The Advisory Forum will consist of a balanced group of stakeholders, including representatives from industry, start-ups, SMEs, civil society, and academic circles. The forum's task will be to advise the Council and the Commission, as well as to provide technical expertise. Its members will be appointed by the Council from among the stakeholders.
The Scientific Panel of Independent Experts will support the implementation and enforcement of the regulation concerning GPAI models and systems, providing member states with access to a pool of experts.
What penalties are imposed for violations of the regulations?
GDPR Compliance Diagnosis.
Do it yourself
The provisions of the regulation specify the thresholds to be considered:
- up to €35 million or 7% of the total annual global turnover from the previous financial year (whichever amount is higher) for violations of prohibited practices or non-compliance with data requirements;
- up to €15 million or 3% of the total annual global turnover from the previous financial year for non-compliance with any other requirements or obligations arising from the regulation, including violations of the provisions concerning general-purpose AI models;
- up to 7.5 million euros or 1.5% (in the current text of the Regulation it is “1%” – note by the DPA 24) of the total annual global turnover from the previous financial year for providing to notified entities and competent national authorities incorrect, incomplete, or misleading information in response to an inquiry;
- for each category of violation – the lower of the two specified amounts in the case of SMEs and the higher amount in the case of other enterprises.
In order to harmonize national regulations and practices regarding the imposition of administrative fines, the Commission, based on the opinion of the Council, will develop guidelines.
As institutions, agencies, and bodies of the EU should set an example, they will also be subject to the regulations and potential penalties. The European Data Protection Supervisor will be authorized to impose monetary fines on them.
What can individuals affected by violations of the regulations do?
The Artificial Intelligence Act grants the right to file a complaint with the national authority. On this basis, national authorities may take action regarding market supervision, in accordance with the applicable regulations concerning such supervision.
Additionally, a directive on liability for artificial intelligence is planned to be introduced. It aims to provide individuals seeking redress for damage caused by high-risk AI systems with effective means of identifying potentially responsible parties and the ability to obtain relevant evidence for compensation claims. To this end, the proposed directive provides for the obligation to disclose evidence concerning specific high-risk AI systems suspected of causing harm.
Furthermore, the proposed amendment to the Product Liability Directive will ensure the right to compensation for individuals who have suffered due to death, bodily injury, or property damage caused by a defective product in the Union. The directive will also clarify that AI systems and products that integrate AI systems are also covered by the applicable regulations.
How will voluntary codes of conduct for high-risk AI systems operate?
Providers of low-risk applications can ensure that their AI system is trustworthy by developing their own voluntary codes of conduct or adhering to codes of conduct adopted by other representative associations.
These codes will apply simultaneously with the obligations regarding transparency concerning certain AI systems.
The Commission will encourage industry associations and other representative organizations to adopt voluntary codes of conduct.
How will the codes of conduct for general-purpose AI models operate?
The Commission invites providers of general-purpose AI models and other experts to collaborate on the codes of conduct.
The codes developed and approved for this process may be used by providers of general-purpose AI models to demonstrate compliance with the obligations arising from the Artificial Intelligence Act, similar to how it operates under the GDPR.
The codes are essential for clarifying the rules applicable to providers of general-purpose AI models, which may be associated with systemic risks. Specifying the rules will allow for the creation of forward-looking and effective principles for assessing and mitigating risks, as well as fulfilling other obligations.
Does the Artificial Intelligence Act contain provisions regarding environmental protection and sustainable development?
The aim of the proposed regulation is to ensure safety and protect fundamental rights, including the fundamental right to a high level of environmental protection. One of the explicitly mentioned and protected legal interests is indeed environmental protection.
The Commission will address European standardization organizations to develop a standardization document regarding reporting and documentation processes to improve the efficiency of AI systems in terms of resources. This includes reducing energy consumption and other resources by high-risk AI systems during their operation, as well as energy-efficient development of general-purpose AI models.
Furthermore, the Commission will be required to submit a report on the review of progress in developing standardization outcomes for energy-efficient development of general-purpose models within two years from the date of application of the regulation, and subsequently every four years, assessing whether there is a need to take further measures or actions, including binding measures or actions.
Additionally, providers of general-purpose AI models that are trained on large amounts of data, and thus characterized by high energy consumption, will be required to disclose energy consumption.
The Commission has been called upon to develop an appropriate methodology for this assessment.
In the case of general-purpose AI models that pose systemic risks, energy efficiency must also be assessed.
How can the new regulations support innovation?
The regulatory framework can enhance the popularity of AI in two ways. On one hand, increased user trust will boost demand for AI utilized by businesses and public authorities. On the other hand, by enhancing legal certainty and harmonizing regulations, AI providers will gain access to larger markets with product offerings that users and consumers will appreciate and purchase. The regulations will apply only where absolutely necessary, thereby minimizing the burden on economic entities.
The Artificial Intelligence Act will also enable the creation of regulatory sandboxes and the conduct of real-world testing. These will provide a controlled environment for testing innovative technologies for a limited time, thereby supporting innovation among businesses, SMEs, and start-ups while respecting the provisions of the regulation. Both the mentioned measures and others: additional networks of AI excellence centers and public-private partnerships for AI, data, and robotics, as well as access to digital innovation hubs (EDIH) and testing and experimentation facilities (TEF), will help create the appropriate framework conditions for companies in the development and implementation of AI.
Real-world testing of high-risk AI systems may be conducted for a maximum of 6 months (with the possibility of extending for another 6 months). Before commencing the tests, a plan must be prepared and submitted to the market supervisory authority. This plan and the detailed conditions of the tests must be approved by the authority. If the authority does not respond within 30 days, the matter may be resolved by means of tacit consent. However, the tests may be subject to unannounced inspections by the authority.
Real-world tests may only be conducted using specific safeguards, e.g., users of the systems undergoing such tests must provide informed consent, the tests must not have any negative impact on them, the results must be reversible or negligible, and the collected data must be deleted after the tests are completed. Special protection must be provided to particularly vulnerable groups, i.e., due to age, physical or mental disability.
How will the EU facilitate and support innovation in AI beyond the Artificial Intelligence Act?
The EU's approach to artificial intelligence is based on the pursuit of ensuring the highest quality and building trust. This aims to enhance research and industrial potential while ensuring safety and the protection of fundamental rights. Citizens and businesses should be able to benefit from AI while feeling secure and adequately protected. The European strategy for artificial intelligence aims to make the EU a world-class AI hub. It also strives for AI to be human-centric and trustworthy. In April 2021, the Commission presented a package on AI, including (1) a review of the coordinated plan on artificial intelligence and (2) a proposal for a regulation establishing harmonized rules governing AI.
As part of the coordinated plan, the Commission adopted a comprehensive strategy to promote the development and implementation of AI in Europe. This strategy focuses on creating conditions conducive to the development and dissemination of AI, ensuring the highest quality from the laboratory stage to the market, increasing the reliability of AI, and building strategic leadership in high-impact sectors.
The Commission seeks to support the actions of member states by coordinating and harmonizing their efforts to promote a coherent and synergistic approach to the development and implementation of AI. The Commission launched the European AI Alliance platform, which brings together stakeholders representing academia, industry, and civil society to exchange knowledge and insights on AI policy.
Furthermore, the coordinated plan provides for various measures to unlock data resources, support critical computing capabilities, enhance research potential, assist European testing and experimentation facilities (TEF), and SMEs through European Digital Innovation Hubs (EDIH).
What is the international aspect of the EU's approach?
The Artificial Intelligence Act and the coordinated plan are part of the EU's efforts to achieve the status of a global leader in promoting trustworthy AI at the international level. Artificial intelligence has become an area of strategic importance at the intersection of geopolitics, trade interests, and security issues.
Countries around the world are opting to utilize AI as a tool to fulfill their aspirations for technological advancement. This is due to its utility and potential. Regulations concerning AI are still emerging, and the EU aims to take action to support the establishment of global AI standards in close cooperation with international partners, in accordance with a multilateral system based on the principles and values it upholds. The EU intends to deepen partnership relations, coalitions, and alliances with its partners (e.g., Japan, the USA, India, Canada, South Korea, Singapore, and the Latin American and Caribbean region), as well as with international organizations (e.g., OECD, G7, and G20) and regional organizations (e.g., the Council of Europe).






