Skip to Content

AI regulation in Europe

 

In April 2021, the European Commission introduced the first EU legislation on artificial intelligence, establishing a risk-based classification system. AI systems that can be used for various applications are analyzed and categorized according to the risk they pose to users. The different risk levels determine whether more or fewer compliance requirements are in effect.

Ambitions 


The Parliament's priority was to ensure that AI systems used in the EU are safe, transparent, traceable, non-discriminatory, and environmentally friendly. AI systems should be monitored by humans rather than automation to prevent harmful consequences.

The Parliament also wanted to establish a technology-neutral, uniform definition for AI that can be applied to future AI systems.


Differentiated rules based on risk levels.

These new regulations impose obligations on both providers and users, depending on the risk level assigned to the AI application. While most systems entail only minimal risk, every application must undergo a formal assessment.

Unacceptable risk

Certain AI applications are prohibited in the EU, including

01

Cognitive behavioral manipulation

Cognitive behavioral manipulation of individuals or specific vulnerable groups (e.g., voice-activated toys that encourage dangerous behavior in children).

02

person holding white printer paper

Social scoring

Social scoring via AI—classifying individuals based on behavior, socioeconomic status, or personal characteristics.

03

Biometric identification

Biometric identification and categorization of individuals.

04

Facial recognition

Realtime-identificatiesystemen op afstand, zoals gezichtsherkenning in de publieke ruimte.

 

Exceptions may be allowed for law enforcement. "Real-time" biometric identification at a distance is only permitted in a limited number of serious cases. "Post" identification (where identification occurs only after a significant delay) may only be used for the prosecution of serious crimes and with the permission of a judge.

High risk


AI systems that negatively impact safety or fundamental rights are classified as 'high risk.' These are divided into two categories:

Systems in products

Systems that fall under existing EU product safety legislation (such as toys, aviation, automotive, medical devices, and elevators).


Systems in specific domains

that must be registered in an EU-wide database.

  • Management of critical infrastructure.

  • Education and vocational training.

  • Employment, workforce management, and access to self-employment.

  • Access to essential private and public services (e.g., social services).

  • Law enforcement.

  • Migration, asylum, and border control.

  • Support for legal interpretation and the practical application of the law.

All high-risk AI systems are monitored both before being 
placed on the market and throughout their entire lifecycle. 
Citizens have the right to file complaints about AI systems
with the competent national authorities.

 

Transparency requirements

Generative AI, such as ChatGPT, is not automatically classified as "high risk," but must comply with transparency requirements and European copyright legislation:

1

Public 

Make it public that the content was generated by AI. 

2

Safe 

Design the model so that it cannot create illegal content. 

3

Copyright 

Publish summaries of copyrighted data that were used for training.

 

AI models for general purposes with a significant impact that may pose a system risk (such as more advanced models like GPT-4) must be thoroughly evaluated. Serious incidents must be reported to the European Commission.

Content created or altered with the help of AI—such as images, audio, or video (e.g., deepfakes)—must be clearly labeled as 'AI-generated' to ensure immediate transparency for users.

EPRS – European Parliamentary Research Service. © European Union, 2024.