On 14 June 2023, the European Parliament (the ”EP”) approved with 499 votes in favour, 28 against, and 93 abstentions, several significant amendments to the proposal for a Regulation laying down harmonized rules on artificial intelligence (the "AI Regulation" or ”AI Act”). The initial form of the proposal is that launched by the European Commission in 2021[1], and the final version of the AI Act is expected before the end of 2023.
The European Parliament focuses in particular on the monitoring and surveillance of individuals, especially on the processing of biometric data. In a nutshell, the amendments proposed by the EP address the following sections of the proposed AI Regulation: Defining some concepts The EP has brought some significant changes to the definitions of the terms used in the proposed AI Regulation (Article 3), as follows: ▸the EP has aligned the definition of artificial intelligence systems (AI system) with that provided by the OECD[2] according to which, an AI system means "a machine-based system that is designed to operate with varying levels of autonomy and that can, for explicit or implicit objectives, generate outputs such as predictions, recommendations, or decisions, that influence physical or virtual environments”; ▸ the EP introduces new definitions such as "risk", "significant risk", "general purpose AI system", "large training runs", "deep fake", "widespread infringement”, “biometric-based data", "biometric identification", "biometric verification", " social scoring"; ▸ the EP renames "users" of AI systems to "deployers"; ▸ the EP also defines the term "affected person" as ”any natural person or group of persons who are subject to or otherwise affected by an AI system". Introduction of six new general principles applicable to all AI systems (Article 4) (a) human agency and oversight, (b) technical robustness and safety, (c) privacy and data governance, (d) transparency, (e) diversity, non-discrimination and fairness, and (f) social and environmental well-being. Major changes concerning prohibited artificial intelligence practices (Article 5) The EP significantly amends the list of prohibited practices in the field of AI, such as: ▸ AI systems that use subliminal techniques that individuals cannot perceive or exploit vulnerabilities with the purpose or effect of materially distorting human behaviour; ▸AI systems based on predictive analytics (based on profiling, assessment of personality traits, location, or previous criminal behaviour); ▸AI systems for inferring emotions, thoughts, states of mind, or intentions of a person in workplace or educational institutions; ▸AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage, etc. On top of that, specific requirements are also imposed on generative AI systems, such as obligations to disclose that content has been generated by artificial intelligence, to design the AI system to prevent the generating of illegal content, and to publish summaries of copyrighted data used for training. Introduction of more stringent obligations for providers and operators (e.g., the provider, the deployer, the authorized representative, the importer, and the distributor) of high-risk AI systems (Article 16) The most important obligations imposed on these providers and operators include the following: ▸ensures transparency and information to users as provided for in Article 13 of the proposed AI Regulation (g., the identification data and the contact details of the provider are offered in the AI system’s instructions for use or in an appropriate digital format or made otherwise available in a durable medium; information on type or quality of input data, or any other relevant information in terms of the training, validation, and testing data sets used; information on the characteristics, capabilities, and limitations of performance of the high-risk AI system, such as the level of accuracy, robustness, and cybersecurity, the degree to which the AI system can explain decisions it takes, etc.; ▸the deployers of high-risk AI systems shall carry out a Fundamental rights impact assessment on fundamental rights. Exclusion of unfair contractual terms in AI agreements concluded with SMEs or start-ups – (Article 28) As a novelty compared to the Commission's initial proposal, the EP introduces the concept of unfair contractual terms in AI agreements unilaterally imposed by a company on an SME or a newly established company and provides that such terms are not binding on the latter if they are unfair. A contractual term is considered unfair if its object or effect is to: ▸exclude or limit the liability of the party that unilaterally imposed the term for intentional acts or gross negligence; ▸exclude the remedies available to the party upon whom the term has been unilaterally imposed in the case of non-performance of contractual obligations or the liability of the party that unilaterally imposed the term in the case of a breach of those obligations; ▸give the party that unilaterally imposed the term the exclusive right to determine whether the technical documentation and information supplied are in conformity with the contract or to interpret any term of the contract. Right to lodge a complaint with a national supervisory authority (Article 68) Similar to the GDPR’s provisions, the proposed AI Act has been amended by the provision that affected persons (i.e., every natural person or group of natural persons) have the right to lodge a complaint with a national supervisory authority if they consider that the AI system relating to him or she infringes the AI Regulation. Affected persons also have the right to an effective judicial remedy where the national competent supervisory authority does not handle a complaint or does not inform the data subject within three months of the progress or outcome of the complaint lodged. Amendments to the level of fines and introduction of new penalties for non-compliance with the provisions of the AI Regulation (Article 71): ▸ the non-compliance with the prohibition of the artificial intelligence practices - administrative fines of up to EUR 40.000.000 or, if the offender is a company, up to 7% of its total worldwide annual turnover for the preceding financial year, whichever is higher; ▸ the non-compliance of the AI system with the requirements laid down in Article 10 (data and data governance) and 13 (transparency and provision of information) - administrative fines of up to EUR 20.000.000 or, if the offender is a company, up to 4% of its total worldwide annual turnover for the preceding financial year, whichever is the higher (this is a new penalty imposed by the EP); ▸ the non-compliance of the AI system or foundation modelwith any requirements or obligations under the regulation, other than those laid down in Articles 5, 10, and 13 - administrative fines of up to EUR 10.000.000 or, if the offender is a company, up to 2% of its total worldwide annual turnover for the preceding financial year, whichever is higher; ▸the supply of incorrect, incomplete, or misleading information to notified bodies and national competent authorities in reply to a request - administrative fines of up to 5.000.000 EUR or, if the offender is a company, up to 1% of its total worldwide annual turnover for the preceding financial year, whichever is higher.[1] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52021PC0206 [2] https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449