EU Parliament Passes Major AI Regulation Law

The European Union (EU) Parliament has formally passed the Artificial Intelligence Act, a regulation tackling comprehensive rules for trustworthy AI systems.

The law is seen as the world's first major piece of legislative framework aimed at classifying products and services that use generative AI based on risk and security.

"The AI Act has nudged the future of AI in a human-centric direction, in a direction where humans are in control of the technology, and where it — the technology — helps us leverage new discoveries, economic growth, societal progress and unlock human potential," said Dragos Tudorache, a Romanian lawmaker, before the vote on social media.

The AI Act has been crafted with key objectives at its core. Its primary aim is to protect essential freedoms and ensure the safety of users by setting rigorous standards for AI systems deemed high-risk. This category encompasses use cases in sectors like healthcare, law enforcement, and vital infrastructure, where AI technologies could have a bigger impact.

Products and services deploying AI technologies will be rated one of the following: "low" hazard, "medium" hazard, "high" hazard or "unacceptable." The AI Act will immediately ban those products and services rated unacceptable — like social scoring systems, emotion recognition systems and predictive policing.  

Furthermore, the legislation strives to promote innovation and confidence in AI solutions, positioning European-based organizations as a formidable player in AI development.

For businesses and developers, the AI Act will bring new considerations when using and deploying gen AI. Companies deploying AI systems classified as high risk will need to implement comprehensive risk assessment and mitigation strategies, maintain detailed documentation, and ensure transparency and accountability. These requirements aim to build public trust in AI systems by making their decisions understandable, traceable, and challengeable by individuals

Next, the EU and participating countries will begin integrating the new law and regulations. First up, the AI Act will officially become law in the next two to three months, pending final formalities. Next, products and services deemed unacceptable must be banned by the individual governing countries in the first six months. Finally, agreed-upon rules for public AI products and services will start applying one year after the law has been formally adopted.

For the EU's part, it will establish the AI Office, central governing headquarters in Brussels, with each individual country creating its own watchdog organization aimed at facilitating communication between regulators and the public.

"Thanks to Parliament, unacceptable AI practices will be banned in Europe and the rights of workers and citizens will be protected," said the Internal Market Committee co-rapporteur Brando Benifei. "The AI Office will now be set up to support companies to start complying with the rules before they enter into force. We ensured that human beings and European values are at the very center of AI's development."

Full text of the act is available here on the EU site.

About the Author

Chris Paoli (@ChrisPaoli5) is the associate editor for Converge360.

Featured

  • Abstract futuristic digital network with glowing padlock icons

    Microsoft Intros New Agentic AI Security Multi-Model Defense System

    A new multi-model agentic AI security system built by Microsoft's Autonomous Code Security team helped researchers find 16 new vulnerabilities across the Windows networking and authentication stack, the company anounced in a recent security blog post.

  • Profile silhouette of a person thoughtfully touching their chin, overlaid with transparent data visualizations and digital interface elements suggesting artificial intelligence and analytics.

    The Institutional Knowledge Shift Is Reshaping Higher Ed IT

    Higher education IT leaders are navigating a quiet but consequential transition: Experienced team members are retiring or leaving for private-sector roles, and the teams replacing them are smaller, newer, and often stretched thin. The result is a structural shift in how technology decisions are made, executed, and sustained.

  • laptop displaying a red padlock icon sits on a wooden desk with a digital network interface background

    Malware Turns Microsoft 365 Calendar Into Covert Attack Vector

    Security researchers at Group-IB have uncovered a Windows malware strain that turns Microsoft 365 calendars into covert channels for receiving commands and stealing files from targeted organizations.

  • person typing on a touch screen schedule plan calendar

    DOJ Extends Deadline for ADA Title II Compliance

    Institutions working to meet the Americans with Disabilities Act Title II regulations for digital accessibility have received a temporary reprieve: The United States Department of Justice has published an interim final rule to push back the compliance deadline by one year.