On 21 May, the European Council adopted the first European Regulation aimed at ensuring respect for human rights, the rule of law and democratic legal standards in the use of artificial intelligence systems (hereinafter “the AI Regulation”). It has just been published in the European Parliament and the Council, the OJEU on 12 July.
What does it regulate?
The AI Regulation aims to regulate the provision and deployment of artificial intelligence systems in order to minimise the associated risks, applying to providers of artificial intelligence systems that are implemented or marketed within the European Union, or whose results (“output”) are used in this territory, regardless of their place of origin. Furthermore, it extends to the users of these systems, considering as users those who deploy or operate these systems for third parties, and not the end users (citizens, consumers, etc.) who are affected by them.
This risk-based approach to regulating the use of artificial intelligence means that the different obligations relating to these technologies differ according to the threats they may pose to society.
Thus, the AI Regulation establishes a classification according to the degree of risk, imposing light transparency obligations for those presenting a limited risk and stricter requirements for both the development and implementation of artificial intelligence systems that present a high risk, up to the prohibition of AI systems that are considered to present unacceptable risks. Thus, AI systems that use biometric data for certain purposes, such as the creation of facial recognition databases by extracting images from the internet or the assessment and classification of people based on their social behaviour or personal characteristics, will be banned.
It also addresses general purpose artificial intelligence models, which will be subject to certain requirements, for example on transparency.
Who is affected?
Although it mainly affects companies that develop artificial intelligence systems and launch them on the market, it also affects any company or professional that implements artificial intelligence solutions, as well as States in their use of artificial intelligence for the provision of public services.
What does it consist of?
The Regulation prohibits certain AI systems and establishes transparency and oversight requirements tailored to specific contexts and risks for others, including for example the identification of content generated by AI systems, as well as imposing obligations to ensure that AI systems respect equality, the prohibition of discrimination and the right to privacy.
What will be the applicable penalties for non-compliance with the regulation?
The European Commission will have the power to impose fines on companies that violate the AI Regulation of up to €38 million or 7% of their global annual revenue, whichever is higher.
When does it come into force?
After being approved by the Presidents of the European Parliament and the Council, the OJEU published the “European Regulation 2024/1689 laying down harmonised rules in the field of artificial intelligence” last Friday 12 July. This Regulation will enter into force 20 days after its publication in the OJEU, on 1 August 2024. However, it will not be until 2 August 2026 that the measures will start to apply, with the exception of:
– Provisions on the subject matter, scope, definitions and prohibited practices (Chapters I and II) that will apply from 2 February 2025;
– Provisions on notifying authorities and notified bodies, Chapter V on general purpose AI models (classification, obligations, etc.), provisions on governance and penalties (except fines for providers of general purpose AI models) and Article 78 on confidentiality obligations, applicable as of 2 August 2025;
– Article 6.1 on classification rules for high-risk AI systems and corresponding obligations, applicable from 2 August 2027.
– Obligations for certain IA systems that are components of large-scale IT systems established by EU legislation, such as the Schengen Information System, which will not be applicable until the end of 2030.
Across Legal provides our clients with advice in relation to the development and/or use of AI systems through the analysis of the AI Regulation, as well as the subsequent preparation of a personal and individualised report on the specific case, addressing aspects such as the legal implications arising from the use of artificial intelligence and our recommendations to comply with the requirements of the AI Regulation.
We also offer our clients the subsequent implementation of the obligations set out in the report and any other legal queries that may arise during the process.
If you want to know more, contact Across Legal and our IPIT team will provide you with detailed guidance on how the AI Regulation could affect you and help you develop strategies to comply with the requirements of the new applicable regulation.




