ARTICLE
2 August 2024

EU AI Act Enters Into Force – But Not Everything Is Effective Yet

FL
Foley & Lardner

Contributor

Foley & Lardner LLP looks beyond the law to focus on the constantly evolving demands facing our clients and their industries. With over 1,100 lawyers in 24 offices across the United States, Mexico, Europe and Asia, Foley approaches client service by first understanding our clients’ priorities, objectives and challenges. We work hard to understand our clients’ issues and forge long-term relationships with them to help achieve successful outcomes and solve their legal issues through practical business advice and cutting-edge legal insight. Our clients view us as trusted business advisors because we understand that great legal service is only valuable if it is relevant, practical and beneficial to their businesses.
August 1, 2024 marks another milestone in EU privacy and cybersecurity regulation as the day that the EU AI Act first becomes effective.
European Union Technology
To print this article, all you need is to be registered or login on Mondaq.com.

August 1, 2024 marks another milestone in EU privacy and cybersecurity regulation as the day that the EU AI Act first becomes effective. However, like the General Data Protection Regulation (GDPR) before it, the EU AI Act provides for a transition period and many provisions will not become effective for some time, with the last set of obligations scheduled to go into effect in 2030.

The earliest milestone for businesses to be mindful of is the prohibition on unacceptably risky AI, which goes into effect February 2, 2025 – just 6 months from now. Businesses that are subject to the EU AI Act must discontinue any use of AI deemed an unacceptable risk.

The next key date is a year away. On August 2, 2025, providers of general purpose AI models must comply with their obligations under the EU AI Act. Some of these obligations include developing detailed technical documentation of the AI model, documentation that enables downstream users to understand the AI model's capabilities and limitations, and public-facing documentation about the training data. They must also have adequate cybersecurity protection for the model (which has a whole new set of risks compared to other SaaS products, including prompt stuffing and similar "front door" attacks), conduct model evaluations, and assess and mitigate potential risks.

The EU AI Office is supposed to draft "codes of practice" regarding obligations for providers of general purpose AI models before May 2, 2025 and provide at least 3 months before taking effect. However, developers of these models may need to expend significant resources to create this documentation and assess risks and should begin efforts sooner rather than later, while still remaining nimble to adjust for any such codes of practice.

The EU AI Act was proposed in April 2021, politically agreed in December 2023 and published in the Official Journal of the EU 12 July 2024. It will be a keystone regulation for the development and deployment of AI in the EU and around the world.

View referenced article

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More