On 13 March 2024, the European Parliament approved the EU Artificial Intelligence Act (EU AI Act). This marks a historic milestone, as the world’s first comprehensive artificial intelligence (AI) legislation.
By Dalvin Chien, Partner, Ashleigh Fieldus, Senior Associate, and Cheryl Zhang, Associate
The EU AI Act is awaiting formal endorsement by the EU Council. Once endorsed, it will become law and will undergo a staged introduction.
As the first major legislation of its kind, governments and organisations worldwide will be looking to the EU as an example. We will undoubtedly start to see other jurisdictions follow suit.
This article provides a brief overview of the EU Act, the implications for Australia, and what it means for you.
The EU AI Act defines AI systems as machine-based systems that (a) operate with different levels of independence and (b) can adapt over time and uses input data to generate outputs such as predictions, content, recommendations, or decisions that can impact real or virtual environments.
The aim of the EU AI Act is simple. The objective is to protect the safety and fundamental rights of individuals, uphold democracy and the rule of law, and promote environmental sustainability, especially from the potential risks posed by high-risk AI applications.
At its core, the EU AI Act adopts a risk-based approach, regulating AI according to its potential societal harm. The more significant the risk associated with an AI application, the more stringent the regulations imposed..
The EU AI Act breaks down AI applications into three key categories:
1.Prohibited AI. This covers applications including social credit scoring systems, emotion recognition tools in workplaces and schools, and AI that exploits vulnerabilities like age or disability. It would also cover behaviour manipulation and untargeted scraping of facial images for recognition purposes. Additionally, specific predictive policing applications and real-time biometric identification in public spaces fall under this category.
The EU AI Act prohibits the use of such AI applications and systems as they are deemed to present an unacceptable risk to human rights.
2.High Risk AI. These are AI systems that pose significant risks to human health, safety or fundamental rights and is divided into 2 sub-categories:
The EU AI Act says that organisations using high-risk AI systems must assess and mitigate risks, maintain usage records, ensure transparency and accuracy, and include human oversight. European citizens will also be allowed to lodge complaints and receive explanations for decisions made by high-risk AI systems that affect their rights.
3.General Purpose AI. These are machines equipped with human-like cognitive abilities, capable of handling diverse intellectual tasks. They are sometimes referred to as “foundation models”, an example of which is ChatGPT.
The EU AI Act outlines transparency requirements for general-purpose AI systems, including compliance with EU copyright law and publication of detailed summaries of training content. More powerful General Purpose AI models facing systemic risks must undergo additional measures like model evaluations, risk assessments, and incident reporting. Deepfake content must also be clearly labelled.
In addition to regulating the three categories of AI systems discussed, the EU AI Act introduces measures to support innovation and SMEs, including establishing national regulatory sandboxes and real-world testing to assist SMEs and startups in developing and training innovative AI before market placement.
The EU AI Act applies to all companies operating in the EU, regardless of whether they develop or supply AI or not. This includes, for example, AI developers, importers, distributors, and users.
The EU AI Act sets out penalties for breaches concerning AI practices. Member States are tasked with defining these penalties, which must be effective, proportionate, and dissuasive. Breaches can incur substantial fines, with fines capped at lower percentages or amounts for SMEs and startups.
The penalties are as follows:
The decision to impose fines, and their amount, depends on various factors such as the severity of the breach, cooperation with authorities, and financial gains from the infringement. Additionally, there are reporting requirements and procedural safeguards to ensure fair application of penalties. The European Commission may also impose fines on providers of General Purpose AI models for intentional or negligent infringements, with fines not to exceed 3% of the provider’s total worldwide turnover or €15,000,000, whichever is higher.
The EU AI Act has far-reaching extraterritorial application .It will apply to Australian companies in a number of situations.
For example:
Australian companies engaging in AI-related activities that have connections with the EU market or EU citizens should carefully consider their obligations under the EU AI Act to ensure compliance.
The EU AI Act has the potential to establish global norms for AI usage, akin to the GDPR’s impact on privacy regulations, due to the EU’s significant market size, stringent regulations and global economic influence.
Despite this, countries like UK, US, and Canada are prioritising growth and innovation in their AI strategies and are cautious of alienating their AI industries.
Canada, for example, adopted a softer regulatory stance through their proposed Artificial Intelligence and Data Act (AIDA). The AIDA emphasises fostering innovation and responsible AI development while maintaining some flexibility in compliance measures and offering milder enforcement mechanisms compared to the EU AI Act.
As at the date of this article, Australia does not have specific legislation regulating AI. Instead, AI is regulated by a range of existing laws in Australia such as privacy legislation, intellectual property laws, and consumer laws. There are also a range of standards and frameworks that need to be adhered to (e.g., NSW Government agencies are required to take into account the NSW AI Assurance framework for all projects which contain an AI component or utilise AI driven tools).
Whether Australia will follow the path of the EU AI Act or the AIDA is not certain.
Earlier this year, the Australian Government, via the Department of Industry, Science and Resources, expressed its commitment to implementing mandatory safeguards for high-risk AI use cases. The government’s primary goal is to regulate AI development, deployment, and usage, particularly in high-risk contexts, while allowing lower-risk AI to thrive. The regulatory focus encompasses testing and audit, transparency, and accountability, with interim measures like developing an AI safety standard and requirement of watermarking AI-generated content for companies to voluntarily comply.
The government also created an AI Expert Group, established by the Department of Industry, Science and Resources in February 2024, which further underscores the government’s focus on ensuring the safety of AI systems. The group will provide advice to the Department on immediate work on transparency, testing and accountability, including options for AI guardrails in high-risk settings, to help ensure AI systems are safe.
Overall, while Australia does not yet have specific AI legislation in place, it is actively working towards implementing regulatory measures to ensure the safe and responsible development, deployment, and use of AI systems.
Given the dynamic nature of this field, staying informed is key. So, watch this space!
Generative AI is not going anywhere. In addition to Chat GPT, Co-Pilot and Gemini, NVIDIA recently announced the Blackwell Platform that will pioneer six transformative technologies which is set to revolutionise sectors ranging from data processing to generative AI. The Blackwell GPU underpinning the platform are “superchips” that will be four times as fast as the previous generation of chips. It is also continuing to work on Project GR00T. Project GR00T is the foundation model designed for humanoid robots.
The passing of the EU AI Act and the speed and massive scale in which generative AI is being adopted and embraced by the public, will accelerate the take-up of regulation in Australia, or at the very least, an opt-in type framework for AI projects.
In preparation for this, we suggest that organisations do the following:
If you would like further information or have any queries regarding other matters, please do not hesitate to contact: