On August 2nd, the European Union (EU)'s Artificial Intelligence (AI) Act came into force, with powers reaching far beyond the EU's borders. Companies in countries outside the EU, such as the US and the UK, which offer their services to users inside the EU will find themselves bound by the new ruling. Meta and Google, for example, have already signed the voluntary code, signalling their intent to align with the framework.

While the new act will not come into force in its entirety until 2030, its most significant provisions are now already law. The act covers most sectors, with exemptions for military, national security, research, or non-professional AI use. Most of the obligations under the EU AI Act concern AI systems. However, its definition of an AI system is very broad.

The act defines an AI system as: "A machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments".

High-risk AI systems face the most onerous obligations

While the act covers most sectors, the most onerous regulatory obligations relate to high-risk AI systems (HRAIS). High-risk categories include AI systems used in the insurance and banking sectors and those used in recruitment and employment for placing job advertisements, scoring candidates or reviewing job applications, promotion or termination decisions or in reviewing work.

Banned AI applications

Banned AI applications in the EU include cognitive behavioural manipulation of people or specific vulnerable groups. This includes, for example, voice-activated toys that encourage dangerous behaviour in children. Using AI for classifying people based on behaviour, socio-economic status or personal characteristics is also banned, together with biometric identification and categorisation of people. This includes real-time and remote biometric identification systems, such as facial recognition in public spaces.

Some exceptions may, however, be allowed for law enforcement purposes. "Real-time" remote biometric identification systems will be allowed in a limited number of serious cases, while "post" remote biometric identification systems, where identification occurs after a significant delay, will be allowed to prosecute serious crimes and only after court approval.