The EU Tightens AI Scrutiny as Rules on General-Purpose Models Take Effect
In Focus
- The rules under the E.U. AI Act took effect on August 2
- They give EU regulators powers to inspect AI models and restrict access in the region
- AI firms like OpenAI, Anthropic, and Google will be targeted under the new rules
The provisions governing general-purpose AI models under the E.U. AI Act took effect on August 2. The rules expand the powers of the European Commission to inspect AI models, restrict their access to the EU market and enforce compliance. Under the new rules, regulators can impose EU AI model fines of up to 3% of a company’s annual turnover or €15 million, whichever is higher, for violations.
Why the General-Purpose AI Model Rules?
The new rules are designed to regulate providers of general-purpose AI models. The AI Act prohibits certain high-risk AI practices, including systems that manipulate individuals, exploit vulnerabilities, or engage in harmful social scoring. The AI Office, which is domiciled at the European Commission, will be responsible for administering the new rules.
The new enforcement powers will affect every tech company that offers general-purpose AI models in the EU, irrespective of its physical location. This means that American AI firms like OpenAI, Anthropic, and Google will be targeted under the new rules. The EU is already holding talks with OpenAI and Anthropic following recent hacking attacks by their AI models.
“Harms can occur if AI is not properly designed and used and the most advanced models create risks on an entirely new scale.” Executive VP for tech tech sovereignty, security and democracy Henna Virkkunen said as cited by Quartz.
Tech companies have expressed commitment to continue working with EU regulators on compliance with the AI rules.
“We’ve collaborated closely with the European Commission and the wider ecosystem on implementing the AI Act, including its Codes of Practice, and will continue working together to help Europe realise the benefits of the Intelligence Age,” OpenAI’s VP of EMEA Policy Tom Gordon noted.
What Obligations Do Tech Companies Have Under the New Rules?
Under the EU AI Act rules, companies like OpenAI and Anthropic must document specific information. Such entities must share the information with relevant authorities or downstream providers. AI firms are also expected to develop a copyright policy and publish the data they use to train their models in summarized form.
Companies that run interactive AI systems like chatbots must inform users that they’re engaging with AI and not humans. Additionally, altered or AI-generated content must feature machine-readable marks.
The Act imposes additional requirements for frontier AI model providers like Anthropic and OpenAI. According to the new rules, these are models that have the potential to pose systemic risks. The extra compliance requirements relate to large-scale disruptions like cybersecurity threats. The new rules took effect months after Anthropic gave the EU’s cyber agency, ENISA, access to Claude Mythos.
How Will EU’s New Rules Shape the AI Race?
The new AI rules could make regulatory compliance an important competitive factor. Companies that can meet Europe’s transparency, copyright, and safety requirements without slowing product development might gain an advantage in one of the largest AI markets.
Although the new rules could increase compliance costs and delay AI rollouts, they could result in higher industry standards. As other governments consider similar regulations, the approach taken by the EU might become a global standard for AI governance.