As artificial intelligence evolves, so do the ethical, technical and legal challenges associated with its implementation.
The debate in the old continent is served. While some see the rules as an obstacle, experts in law and AI technologies argue that a clear framework is the only way to ensure safe and ethical innovation.
Since its inception, the EU Artificial Intelligence Act (or EU AI Act) has been at the center of a global debate: is it an essential regulation to protect European citizens or an obstacle that limits competitiveness and innovation?
How did the EU Artificial Intelligence Law come about?
The road to the EU AI Act began in 2021, when the European Commission presented its initial proposal. Inspired by the General Data Protection Regulation (GDPR), this legislation seeks to establish a risk-based approach to regulating AI applications.
The regulations classify systems into categories according to the level of risk they represent, from low to unacceptable.
Among the main motivations are the prevention of abuses such as algorithmic discrimination, the massive manipulation of opinions or the misuse of technologies such as real-time facial recognition.
These issues, in addition to growing concerns about the impact of AI on fundamental rights, led the EU to prioritize creating a legal framework before the technology overrode existing controls.
The key points of the regulation
Risk-based classification:
· Low risk: Applications such as spam filters or personalized recommendations.
· Limited risk: Includes technologies with transparency requirements, such as chatbots that must inform users that they are not interacting with a human.
· High risk: Systems that affect fundamental rights, such as hiring tools, workplace surveillance or educational evaluation systems. These require a prior risk assessment.
· Unacceptable risk: Applications prohibited for posing a serious danger, such as “social scoring” style mass surveillance or subliminal cognitive manipulation.
Focus on general AI models
General AI models (GPAIs), such as OpenAI’s ChatGPT, Google’s Gemini or Meta’s Llama, are the subject of special attention.
As they are versatile tools with a potential impact on multiple sectors, the regulations establish specific measures to guarantee their security and transparency.
Transparency and copyright
Developers of GPAIs will be required to document the source of the data used to train their models, manage potential copyright infringements, and facilitate prompt complaint mechanisms for rights holders.
Systemic risk management:
GPAIs that are considered “systemic risk”—for example, those with offensive cybersecurity capabilities or prone to generating mass disinformation—will be subject to strict assessments and corrective measures.
Why has Europe lost ground in the AI market?
Although the EU AI Act seeks to protect citizens, its strict regulation has raised concerns about Europe’s ability to compete in the global AI market. A few months ago we told you that Meta AI is not available on WhatsApp in EU countries.
Many technology companies, especially those developing advanced AI tools, have shown reluctance to launch products on the continent due to the cost and complexity of complying with these regulations.
For example, giants like OpenAI, Meta and Google have limited access to their most advanced models in Europe, citing regulatory uncertainties.
This has created a paradox: while the EU seeks to lead in ethical regulation, it runs the risk of falling behind in innovation and technological adoption.
Recent developments and what’s to come
The first draft of the Code of Practice for GPAIs, published on November 12, 2024, is an effort to clarify how the provisions of the AI Act should be implemented.
This document, still in development, seeks to guide developers in adapting their models to European requirements, from detailed data documentation to the identification and mitigation of systemic risks.
Draft highlights include:
- A transparency framework that forces developers to disclose how they train their models and manage copyright claims.
- The introduction of a “Security and Risk Framework”, which requires foresight on the development of capabilities that may generate systemic risks.
- Specific measures for serious incidents, including rapid notification to the competent authorities.
Deadlines for compliance vary depending on the level of risk associated with the models, with stricter requirements coming into effect in 2027 for GPAIs considered high risk.
Can there be a balance between innovation and protection?
As regulations are implemented, Europe will have to find a balance between protecting its citizens and fostering an ecosystem of technological innovation.
For startups and small businesses, the challenge is even greater, as the requirements of the AI Act could be prohibitive without adequate support.
In contrast, other regions such as the United States and China are adopting more flexible approaches, allowing companies to experiment with emerging technologies without immediate restrictions.
This raises a crucial question: can the EU maintain its ethical leadership without compromising its technological competitiveness?
The challenge lies in ensuring that Europe is not only a benchmark in ethical regulation, but also a key player in the global race for leadership in artificial intelligence. And the path for this still doesn’t seem to be clear.
This post is also available in: