AI regulation in Europe
In April 2021, the European Commission introduced the first EU legislation on artificial intelligence, establishing a risk-based classification system. AI systems that can be used for various applications are analyzed and categorized according to the risk they pose to users. The different risk levels determine whether more or fewer compliance requirements are in effect.

Ambitions
The Parliament's priority was to ensure that AI systems used in the EU are safe, transparent, traceable, non-discriminatory, and environmentally friendly. AI systems should be monitored by humans rather than automation to prevent harmful consequences.
The Parliament also wanted to establish a technology-neutral, uniform definition for AI that can be applied to future AI systems.
Differentiated rules based on risk levels.
These new regulations impose obligations on both providers and users, depending on the risk level assigned to the AI application. While most systems entail only minimal risk, every application must undergo a formal assessment.
Unacceptable risk
Certain AI applications are prohibited in the EU, including
01

Cognitive behavioral manipulation
Cognitive behavioral manipulation of individuals or specific vulnerable groups (e.g., voice-activated toys that encourage dangerous behavior in children).
02

Social scoring
Social scoring via AI—classifying individuals based on behavior, socioeconomic status, or personal characteristics.
03

Biometric identification
Biometric identification and categorization of individuals.
04

Facial recognition
Realtime-identificatiesystemen op afstand, zoals gezichtsherkenning in de publieke ruimte.
Exceptions may be allowed for law enforcement. "Real-time" biometric identification at a distance is only permitted in a limited number of serious cases. "Post" identification (where identification occurs only after a significant delay) may only be used for the prosecution of serious crimes and with the permission of a judge.
High risk
AI systems that negatively impact safety or fundamental rights are classified as 'high risk.' These are divided into two categories:
Systems in products
Systems that fall under existing EU product safety legislation (such as toys, aviation, automotive, medical devices, and elevators).
Systems in specific domains
that must be registered in an EU-wide database.
Management of critical infrastructure.
Education and vocational training.
Employment, workforce management, and access to self-employment.
Access to essential private and public services (e.g., social services).
Law enforcement.
Migration, asylum, and border control.
Support for legal interpretation and the practical application of the law.
All high-risk AI systems are monitored both before being
placed on the market and throughout their entire lifecycle.
Citizens have the right to file complaints about AI systems
with the competent national authorities.
Transparency requirements
Generative AI, such as ChatGPT, is not automatically classified as "high risk," but must comply with transparency requirements and European copyright legislation:
Public
Make it public that the content was generated by AI.
Safe
Design the model so that it cannot create illegal content.
Copyright
Publish summaries of copyrighted data that were used for training.
AI models for general purposes with a significant impact that may pose a system risk (such as more advanced models like GPT-4) must be thoroughly evaluated. Serious incidents must be reported to the European Commission.
Content created or altered with the help of AI—such as images, audio, or video (e.g., deepfakes)—must be clearly labeled as 'AI-generated' to ensure immediate transparency for users.
EPRS – European Parliamentary Research Service. © European Union, 2024.