The EU AI Act Passes Another Hurdle Towards Becoming Law

Wilson Sonsini Goodrich & Rosati

[co-author: Hattie Watson]

On March 13, 2024, the European Parliament (EP) approved the latest draft of the European Union’s (EU) Artificial Intelligence Act (AI Act). Following this vote, the text will be sent to the Council of the EU (Council) for formal approval, after which the AI Act will officially become law. Once the AI Act starts to apply, it will introduce a swathe of new obligations for companies providing and using AI systems and general-purpose AI (GPAI) models in the EU, subject to hefty fines of up to EUR 35 million or seven percent of the total worldwide annual turnover, whichever is higher.

What Does This Vote by the European Parliament Mean for the EU AI Act?

This vote by the EP does not mean that the AI Act is now finally adopted. However, it is the penultimate step before it becomes law. The last step before the AI Act can pass into law is for the Council to formally approve the draft. No amendments in substance are expected and the AI Act will likely progress to enter into law by the summer.

What Will Happen Once the EU AI Act Becomes Law?

  • The AI Act will start to apply in phases. The first AI Act provisions to kick in will be the ones which prohibit certain applications of AI (e.g., AI systems that exploit individuals’ vulnerabilities, untargeted scraping of facial images from the internet or CCTV footage): these provisions will start to apply six months after the law enters into force, which likely means before the end of the year. The second set of provisions to apply will be those imposing requirements in relation to GPAI: these provisions will start to apply one year after the AI Act’s entry into force, so likely in Q2 2025. Most of the rules for high-risk AI systems and AI systems with specific transparency risk will start to apply two years after the AI Act enters into force, so likely in Q2 2026.
  • Additional grace period for AI systems and GPAI already offered in the EU. There will be more time to comply with the AI Act regarding AI systems and GPAI that are already on the EU market.
    • Operators of high-risk AI systems that are offered in the EU before the corresponding rules for high-risk AI start to apply will only need to comply with the AI Act in the event of a significant design change. As an exception to this, if the high-risk AI system offered in the EU is intended to be used by public authorities, the providers and deployers will need to comply with the rules within six years as of the entry into force of the AI Act, regardless of whether there has been a significant design change or not.
    • Providers of GPAI models already offered in the EU will have an additional two years to comply with the requirements, i.e., a total of three years as of the entry into force of the AI Act, so likely by Q2 2027.

Who Will Enforce the EU AI Act?

Rules on GPAI will be enforced by the newly created European AI Office of the European Commission, which is expected to become the EU center of AI expertise and to issue pan-EU guidance on AI. Enforcement of the rules on AI systems will primarily be at the national level. Each EU country will need to identify the competent regulators to enforce the AI Act within one year of the AI Act becoming law. Some countries have already announced their intentions, e.g., Spain has already created a distinct AI authority.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Wilson Sonsini Goodrich & Rosati | Attorney Advertising

Written by:

Wilson Sonsini Goodrich & Rosati
Contact
more
less

Wilson Sonsini Goodrich & Rosati on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide