T

The EU Artificial Intelligence Act: What Ukrainians Need to Know? - the article by Volodymyr Misechko for Ekonomichna Pravda

On May 21, 2024, the European Council gave its final approval to the Artificial Intelligence Act (AIA), following a vote in favour by the European Parliament on March 13, 2024.
 
The Artificial Intelligence Act (AI Act) hailed by experts as a groundbreaking piece of legislation and the Intelligence Act establishes a comprehensive framework for regulating artificial intelligence technologies and systems and it is heralded as a benchmark for global AI governance, the Act is anticipated to serve as a model for policymakers worldwide. Its scope encompasses all economic sectors (excluding the military) and encompasses all types of AI.
 
Ukrainians should familiarise themselves with the provisions of the Artificial Intelligence Act for several compelling reasons:
  • as Ukraine steadfastly progresses towards the EU membership, the AI Act's norms will be incorporated into the Ukrainian legislation within the coming years.
  • compliance with the AI Act is mandatory for all AI systems seeking access to the EU's internal market, consequently Ukrainian developers and providers shall adhere to these standards when offering AI-related services and products across borders.
Establishing Comprehensive Rules for Artificial Intelligence Technology
The Artificial Intelligence Act stands as the world's first comprehensive law regulating artificial intelligence, while attempts to restrict this technology are being undertaken by government institutions worldwide. The EU Commission will hold the authority to impose fines of up to 35 million euros or 7% of a company's global annual revenue for violations of the Act. However, the AIA allows for a lower penalty scale for small and medium-sized enterprises, including startups, and mandates that their interests and economic viability be considered.
 
Therefore, the new regulations will have significant implications for any individual or legal entity that develops, uses, or sells artificial intelligence systems within the EU.
 
Some AI applications are outright prohibited, while the Act imposes stringent restrictions on “general-purpose” AI (General purpose AI, GPAI) systems. These restrictions include compliance with the EU copyright law, disclosure of information regarding model training, regular testing, and adequate cybersecurity measures.
 
However, the restrictions on general-purpose AI systems will not come into effect immediately but only 12 months after the Act enters into force. Even then, currently commercially available general-purpose AI systems, such as ChatGPT from OpenAI, Gemini from Google, and Copilot from Microsoft, will be granted a "transition period" of 36 months from the date of entry into force of the Act to bring their technology into compliance with the legislation.
 
Article 113 of the AI Act outlines the phased implementation of its provisions is the following:
  • The AI Act will enter into force in the nearest future - 20 days after its publication (in the Official Journal of the European Union);
  • 6 months after entry into force (the end of 2024 /beginning of 2025), a ban will be imposed on certain AI systems that do not meet the risk assessment criteria;
  • 12 months after entry into force (from June/July 2025), the rules for GPAI models will become applicable;
  • 24 months after entry into force (from June/July 2026) all provisions of the Act will come into full effect, including those for high-risk AI systems;
  • The transition period for GPAI models will end 36 months (the middle of 2027) after entry into force.
Key Principles
In the preamble of the AI Act, it is stated that artificial intelligence (AI) is a family of rapidly evolving technologies capable of delivering a broad range of economic and social benefits. However, the same elements and methods that enable the socio-economic advantages of artificial intelligence may also give rise to new risks or negative consequences for individuals or society.
 
The enactment of the law serves dual purpose: 1) to foster the widespread adoption, investment, and innovation in the field of artificial intelligence; 2) to address and minimise the potential risks associated with the deployment of such technologies. Additionally, the EU is positioned to influence the development of global norms and standards concerning AI.
 
The core principle of the law lies in regulating AI based on its potential risks and societal impact: the higher the risk of harm to society is, the stricter the rules are. AI risk mitigation should be implemented without unduly hindering technological advancement or disproportionately increasing the cost of AI solutions in the market.
 
Article 1 of the AI Act establishes:
  • harmonised rules across the EU for the market entry, deployment, and use of AI systems;
  • prohibitions on Certain AI Practices;
  • special requirements for high-risk AI systems and obligations for operators of such systems;
  • harmonised rules for artificial intelligence systems intended for interaction with individuals, emotion recognition and biometric categorisation systems, as well as artificial intelligence systems used for creation or processing of images, audio, or video content;
  • market monitoring and oversight rules.
Risk-based approach
The Artificial Intelligence Act categorises AI systems based on the likelihood of harm and the potential severity of that harm:
 
Prohibited AI systems are those with an unacceptable level of risk to safety, rights, or fundamental freedoms of individuals. For instance, real-time facial recognition and biometric identification systems based on cameras installed in public places (with certain exceptions).
 
As outlined in Chapter II of the Act, prohibitions apply to systems that have significant potential to manipulate individuals through subconscious methods or exploit vulnerabilities of specific groups, such as children or persons with disabilities. Social scoring based on AI, conducted by governmental bodies (ranking individuals based on their personal characteristics, socioeconomic status, or behaviour), is also prohibited.
 
High-Risk Artificial Intelligence Systems – these are the systems with a high potential to cause significant harm or violate human rights (Chapter III of the Act). They require rigorous regulation and supervision throughout their lifecycle to mitigate risks. For example, systems used in critical infrastructure, education, recruitment, public services, law enforcement, border control, and judiciary.
 
High-risk AI systems include autonomous vehicles or medical devices. They also encompass AI systems used in financial services and education, where there is a risk of bias. Providers of high-risk AI systems must, among other obligations, ensure compliance with the Artificial Intelligence Act, maintain specific documentation, keep logs, and address issues related to automated AI systems.
 
General-purpose Artificial Intelligence Systems (GPAI) – These include systems like ChatGPT, Gemini, and Copilot. They can pose systemic risks and must undergo thorough assessment processes.
 
Low-risk AI Systems – These are systems that pose fewer risks. They still require certain security measures, but regulatory requirements for these systems are less stringent. For example, AI-driven chatbots used for customer service to provide automated responses to inquiries.
 
Additionally, according to Chapter IV of the Act, this category includes AI systems that interact with humans, are used for emotion detection, or create deep fake content. When individuals interact with an AI system or their emotions are detected using automated means, they must be informed of this fact.
 
If an AI system is used to create or process images, audio, or video content resembling authentic material, it should disclose that the content was generated using automated means, with exceptions for lawful purposes (law enforcement activities). This enables individuals to make informed choices.
 
Minimal-risk Artificial Intelligence Systems fall under the least regulatory burden. For instance, basic email filters that classify messages as spam.
 
The Act establishes several exceptions. For instance, it pertains to AI systems used exclusively for military, defence, or national security purposes, or AI systems and models specifically developed and deployed solely for scientific research and development.
 
New Regulators
Implementation and enforcement of the Act will be overseen by the newly established Artificial Intelligence Office (AI Office) at the EU level. The Office, among its responsibilities, may assess General-Purpose AI models and assist national authorities in monitoring the market for high-risk AI systems.
 
Another institution created under the Act is the European AI Council (Chapter VI of the Act), composed of representatives from EU member states, responsible for advisory tasks such as issuing opinions and recommendations. Additionally, a scientific panel (The Scientific Panel) comprising independent experts will support the implementation and enforcement of the Act, including monitoring activities of the AI Office concerning GPAI. Member states will also receive support from the Panel in their enforcement activities.
 
Conclusions
The comprehensive Act, spanning over 420 pages, represents the EU's attempt to establish a "global standard for AI regulation." Its success will be judged over time. Experts already foresee potential challenges in interpreting and implementing various provisions of the Act into national legislations and in their direct application.
 
Therefore, Ukrainian lawyers, lawmakers, and AI developers should begin detailed study of the Act now. Moreover, shortly after its publication in the EU Official Journal, there will likely be numerous commentaries and explanations from European experts. All of this will contribute to accumulating the necessary groundwork for applying the provisions of the Act as they are phased into effect.