Skip to content
Regulation

Europe Agrees the World's First AI Rulebook, and It Will Reach Your Projects

Outright bans, transparency duties and fines up to 7% of global turnover, settled in a three-day marathon.

·5 min read ·vev.dev

On Friday 8 December 2023, negotiators for the European Parliament and the Council settled on a provisional agreement covering the Artificial Intelligence Act. Co-rapporteur Brando Benifei called the process "long and intense, but the effort was worth it". His counterpart Dragos Tudorache presented the outcome as the EU getting robust AI regulation on the books ahead of anyone else.

The approach is risk-based. Rather than regulating a technology by name, the text sorts systems by what they are used for and how much harm they could do, then attaches duties to each tier. A short list of uses is banned outright. A larger group is classified as high-risk and carries real paperwork. General-purpose models, the ones sitting behind chat assistants and text generators, get obligations of their own.

The number that will end up in board presentations is the penalty. Breaking the rules can cost between 35 million euro or 7% of global turnover at the top end and 7.5 million or 1.5% of turnover at the bottom, depending on the infringement and on how big the company is.

The tiers, and where an ordinary product lands

Six categories of use are off the table entirely. Social scoring that ranks people by their behaviour or personal traits is out. So is emotion recognition deployed in the workplace or in educational institutions. Building facial recognition databases by scraping images indiscriminately from the internet or from CCTV is prohibited, as is biometric categorisation that sorts people by sensitive traits, race, sexual orientation and political or religious belief among them. The last two cover systems built to steer human behaviour past a person's own free will, and systems that take advantage of someone's age, disability, or social and economic situation. Law enforcement keeps narrow exceptions for biometric identification in publicly accessible spaces, subject to prior judicial authorisation and to defined lists of serious crimes.

High-risk is the tier most commercial software could plausibly touch. It covers systems capable of doing significant harm to health and safety, to fundamental rights, to the environment, and to democracy and the rule of law. Parliament pushed through a mandatory fundamental rights impact assessment that reaches the insurance and banking sectors as well, and systems used to influence election outcomes and voter behaviour sit in this tier too. People on the receiving end gain two things: a route for lodging complaints about an AI system, and the right to an explanation when a high-risk system makes a decision that affects their rights.

General-purpose AI is handled separately. Providers of these systems, and of the models underneath them, have to produce technical documentation, stay within EU copyright law, and publish a detailed summary of the material used in training. Models judged high-impact, and therefore treated as carrying systemic risk, pick up a heavier set: evaluating the model, finding and reducing systemic risks, adversarial testing, telling the Commission about serious incidents, cybersecurity, and disclosure of how much energy the model consumes. Until harmonised EU standards exist, those providers may lean on codes of practice instead.

For smaller companies, the agreement backs regulatory sandboxes and testing in real conditions, run by national authorities, so a system can be built and trained before it goes on the market.

What this means if you are building something

None of it is law yet, and that is not a reason to wait. The agreed text still has to be formally adopted by both Parliament and Council, and Parliament's internal market and civil liberties committees vote on it at a forthcoming meeting. The direction, though, is settled, and almost every duty in it is a documentation duty. Documentation is cheap to keep as you go and expensive to reconstruct two years after the fact.

Write down which AI your product uses, and where. One short register per product is enough: which feature calls which model or third-party service, what data is sent to it, whether any of that data is personal, and who the provider is. Most teams cannot answer this today, because an API key went in one afternoon and was never recorded anywhere.

Check the prohibited list before you build, not after. Emotion recognition inside a workplace tool or a classroom product, or a feature that scores people by their social behaviour, is not a compliance conversation to be had later. Those are uses the co-legislators agreed to ban.

If the product decides something about a person, budget for assessment work. Insurance, banking and anything touching elections are named explicitly. A fundamental rights impact assessment is not a form you fill in at launch week; it needs someone who understands both the system and the people it affects.

Providers pass their duties down the chain. If you build on a general-purpose model, expect the provider's copyright and training-data disclosures to shape what you can promise your own client in a contract. Ask now what your vendor publishes, and keep the answer with the register.

Our reading: for a marketing site or an online shop, this changes little in the near term. For anything that makes a decision about a person, the register you start this month is what will make the later conversation short instead of archaeological.

Sources

Share
Get In Touch

Have a project idea? Write down a quote!

Got a project? Drop us a line if you want to work together on something exciting. Or do you need our help? Feel free to contact us.