TUM Think Tank
Where today's societal challenges meet tomorrow's technological excellence.
After an intense three-day negotiation marathon, negotiators from the Council presidency and the European Parliament have successfully reached a provisional agreement on the proposal concerning standardized regulations for artificial intelligence (AI), known as the Artificial Intelligence Act. The objective of the draft regulation is to guarantee the safety of AI systems introduced to the European market and employed within the EU, with a commitment to upholding fundamental rights and EU values. This groundbreaking proposal additionally seeks to foster increased investment and innovation in the field of AI within Europe. Following this provisional agreement, efforts will persist at a technical level in the upcoming weeks to conclude the specifics of the new regulation. Once this work is completed, the presidency will present the compromise text to the representatives of the member states for endorsement. The comprehensive text will require confirmation from both institutions and undergo legal-linguistic revision before formal adoption by the co-legislators.
We asked members of our community for their insights on the AI Act. This is what they think:
Samson Esaias: Associate Professor of Law at BI Norwegian Business School, Faculty Associate at the Berkman Klein Center of Internet and Society at Harvard University
"Since the Commission's April 2021 proposal, consensus has emerged within the bloc's legislative bodies on a risk-based approach to AI regulation, along with innovation-supporting measures like sandboxes. Debates have focused on sensitive issues such as biometric identification for law enforcement and regulation of General Purpose AI (GPAI). The Parliament advocated for stronger fundamental rights safeguards, while the Council favoured broader exemptions for the use of biometric identification for law enforcement. The Parliament's GPAI regulatory proposal also encountered resistance from the Council, partly because it focuses on the technology itself instead of the associated risks. Nonetheless, from the press-releases, the Parliament seems to have secured significant wins, including bans on biometric identification using sensitive data, internet photo scraping for facial recognition, restrictions on predictive policing, and mandatory rights impact assessments for high-risk systems. Similarly, despite strong resistance from some member states, the latest draft also includes important obligations on GPAI and systemic foundational models, though criteria for the latter may be overly stringent. This focus on GPAI regulation, initially absent from the Commission's draft, highlights the shift in priorities over the past two years. The question that remains is whether these additions will stay relevant in two years when the legislation comes into effect or if they will highlight the need for a rethink on how to regulate such rapidly evolving technologies."
Urs Gasser: Professor of Public Policy, Governance and Innovative Technology and serves as Rector of the Hochschule für Politik (HfP) and Dean of the TUM School of Social Sciences and Technology, Leader of the TUM Generative AI Taskforce
"The agreement on the AI Act marks an important milestone. Above all, it is a powerful political signal to the global community, showing that the EU lawmaking bodies are functional and can come up with meaningful guardrails in a complex and fast-moving normative field, with human rights and democratic values as lodestars. Whether the AI Act as a complex legal and regulatory intervention – at times resembling a Rorschach test – will live up to the high hopes expressed by its leading proponents remains to be seen. AI governance as a normative field comes with many unknowns. Perhaps the biggest challenge ahead is to learn continuously and manage both legal path dependencies and unintended consequences that often come with such ambitious legislative projects, as the recent history of law, technology, and society teaches us."
Noha Lea Halim: Doctoral Student and Research Assistant at the Professorship for Governance, Public Policy & Innovative Technologies at the TUM School of Governance, Assistant in the TUM Generative AI Taskforce
"The EU via its AI Act agreement brings forward a global benchmark regulatory proposal, representing most ambitious framework to date. By recognizing the need to not only regulate the economic but also the societal impacts of AI, it sets the tone for how AI might unravel in the future and implies far-reaching effects for the research and development of AI systems, in Europe and beyond.
The 12-24 months implementation phase will give a glimpse towards the long-term capability of the regulation to adapt to the technology’s disruptive potential as well as the Union’s ability for capacity building to bring the proposal to life.
The landmark proposal only marks the beginning of addressing AI’s future challenges, moving forward there will be many more to come."
Timo Minssen: Law Professor, CeBIL Director, University of Copenhagen and Global Visiting Professor at TUM in Spring 2024
"While much controversy remains, reaching an agreement on the EU AI Act was crucial since the time to decide where to regulate (or not regulate) is now. AI is evolving so rapidly, and it's already used by millions of citizens in many areas and stages of life on a daily basis. Both the risks and the opportunities are real, and we must address them swiftly if we want to keep control and reap the benefits from this technology in sustainable, safe and fair ways.
Given the complexity of the topic and the need for trade-offs, the delays accompanying the negotiations of the AIA were not surprising. Many of the AIA’s more restrictive provisions, appear to have been slowly watered down. Mostly due to industry interests and competitive concerns, regulatory thresholds have been slowly lowered and more traditional value-based boundaries have been stretched out. For better or worse, we can also see similar developments in the drafting of such guidelines the Chinese interim regulations on generative AI, as well as in Western countries such as in the US and UK.
It is clear that these changing policy perspectives illustrate how AI challenges our traditional values and concepts which signifies the enormous stakes of the task at hand. The impact not only on businesses, welfare, industry, innovation, and the knowledge commons, but also on individuals’ access to - and protection from - powerful technology are massive. Calls for banning or more regulation of specific applications in the EU due to ethical and value-based legal concerns and precautionary approaches, had - and will have - to be balanced against both competitive disadvantages and health risks due to missed opportunities by setting overly high regulatory thresholds. It can therefore be assumed that the significance of so-called regulatory sandboxes will grow, although this is a concept in need of further clarification.
It also seems to me that while rigorously protecting human rights and fundamental values, the AIA has with its risk category-based based aporoach generally taken an regulatory ”as open as possible, and as closed (i.e. regulated) as necessary” position. In particular with regard to lower risk AI systems, this could be good news for many innovators and SMEs developers, though some might have preferred even less rules. On the other hand, those concerned about the risks, or established companies with powerful IP portfolios and regulatory departments, might have preferred an ”as closed as possible, and as open as necessary” approach with high regulatory thresholds, be it to prevent risks - or (!) newcomers and competition.
In that regard it is also important to bear in mind that, essentially, the current debates that we see mostly concern high-level rules. What matters in daily life is how these are implemented where the action happens, as well as if the rules that we set are enforceable, feasible and if compliance can be monitored. If the choice is between having a jungle of extremely detailed rules with insufficient means for enforcement, and having less but very robust and enforceable rule, I definitely prefer the 2nd choice to increase the respect for the rules."
Armando Guio Espanol: Affiliate at the Berkman Klein Center for Internet & Society at Harvard University
"The EU AI Act is a regulation that not only will have an impact in Europe, but around the world. The adoption of this regulation will lead many countries to decide on their own rules regarding the development and implementation of this technology. It will be essential to follow the work that will come in the next months and the implementation process that will emerge in the European Union. In 2024 we will observe several countries join Europe in the official adoption of new regulations for AI systems. For example, several Latin-American countries are discussing now regulatory proposals for AI. The EU AI Act will have a considerable effect in mobilizing and accelerating many of these discussions. It will be also interesting to see how this policy fragmentation will impact the way this technology is being used and deployed, and the response of some of the biggest companies to this process."
Dirk Heckmann: Law Professor at the TUM School of Social Sciences and Technology, Direktor bidt.digital, Generative AI Taskforce
Whether the AI Act will prove to be effective regulation for AI will only be shown in legal practice. Political satisfaction does not replace legal certainty.
TL;DR
After an intense three-day negotiation marathon, negotiators from the Council presidency and the European Parliament have successfully reached a provisional agreement on the proposal concerning standardized regulations for artificial intelligence (AI), known as the Artificial Intelligence Act. The objective of the draft regulation is to guarantee the safety of AI systems introduced to the European market and employed within the EU, with a commitment to upholding fundamental rights and EU values. This groundbreaking proposal additionally seeks to foster increased investment and innovation in the field of AI within Europe.Following this provisional agreement, efforts will persist at a technical level in the upcoming weeks to conclude the specifics of the new regulation. Once this work is completed, the presidency will present the compromise text to the representatives of the member states for endorsement. The comprehensive text will require confirmation from both institutions and undergo legal-linguistic revision before formal adoption by the co-legislators.