The EU AI Act: the known knowns

Now that a political agreement has been reached on the EU AI Act, we preview the known knowns of the law, before looking into the known unknowns of its technical details and implementation.
AI box representing the AI Act on an EU flag

Following the political agreement on the EU AI Act from last Friday evening, the fragile agreement was sold to Member States. Meanwhile, daily technical meetings kicked off to lock in the details and develop the final text.

This process yielded a set of known knowns on generative AI, high-risk systems on prohibited use cases, and an understanding of what the known unknowns of technical details and enforcement are. The new roles of the Commission are significant.

The EU AI Act has been celebrated as a historic global precedent by EU policymakers, while the industry’s first reactions range from sceptical to ambivalent.

Our first take is that the cost of the rules on generative AI is acceptable, while the scope will very much depend on the Commission. The focus of any assessment should be the rules on high-risk uses by corporates. These will give some legal certainty at first but stand to be replaced by sector-specific rules.

From here onwards, the EU will seek to retrofit any international governance developments into its framework, diluting international efforts. Any matters of EU national security and many matters of law enforcement will be exempt from the AI Act.

After 38 hours of final negotiations, two years since the proposal, and over 600 hours of negotiations overall, the EU reached a political consensus over its AI Act (AIA) late Friday evening. This is a world first in terms of horizontal AI legislation.

The hard-fought outcomes of the political agreement have more impact on future civil liberties in the EU than on commercial uses of AI. Most matters of industry impact have been known in the lead-up to last Friday.

There are also a group of known unknowns – to be resolved in technical talks over the next two weeks or so, technical standards which will follow the principle legislative text, and national-level implementation decisions. Member States will not stand still in this process. A number are exploring preparedness and market development strategies.

There is a national security exemption to the AI Act. This is a reminder that, as we have been writing, defence risks, or in our language, US-style concerns, are real regarding AI, but they are a Member State and, in some cases, a NATO competence.

From here onward, the EU will seek to align international standards to this framework or, if necessary, dilute them sufficiently so that frameworks fit with them. This applies to expected G7, G20 and UN initiatives on AI.

Finally, the world’s largest AI markets have not yet indicated intent to develop similar horizontal AI legislation, notably the US, China and the UK. In the EU, we expect 2024 to kick off further vertical rule-making, including financial services and labour rights.

The requirements of the AI Act should be grouped around generative AI, prohibited use cases, and high-risk systems. The rules on the latter are most extensive.

High-risk AI falls into two categories: systems that are a product or safety component, such as toys and medical devices, and systems used for designated ‘high-risk’ purposes, such as employment, credit scoring, and critical infrastructure. There are eight such categories, and the Commission will be given the power to amend this list.

Ultimately, it was agreed that the use of AI to influence the outcome of elections and voter behaviour would be classified under the high-risk framework.

The key debate here was who is on and off the list. A high-risk system can be self-exempt if it meets one or more of four criteria – if the system performs a narrow procedural task; if the system reviews or confirms human-made decisions (rather than being the sole basis for decision-making itself); if the system is an accessory to human work; and if the system only performs a preparatory task to the decision-making process.

Systems on this list will be subject to rules on risk mitigation, data governance, transparency and documentation, accuracy, robustness and cybersecurity and ought to undergo internal conformity assessment

Explainability and redress have also been prioritised, meaning that individuals can initiate complaints and receive explanations about decisions made using high-risk AI if their rights have been impacted.

At the final trilogue, MEPs successfully argued for including a mandatory Fundamental Rights Impact Assessment (FRIA) for high-risk AI systems before they are put onto the market, on top of other conformity assessments. Member States had originally opposed this.

We ought to be cognisant that after this horizontal legislative effort is over, the sector-specific Directorate Generals of the Commission will want to create specialised rules. This has always been, and is likely to be, the case in financial services. Therefore, the high-risk use cases of credit and insurance will likely be even more impacted by those rules in the mid-term.

As we expected, consensus landed on a two-tier regulatory system.

The upper tier will comprise models with 10~25 FLOPS – unfortunately, this was just the mid-point of Parliament’s 10~24 ask and Council’s 10~26 proposal.

Crucially, the Commission can also designate models as having systemic risk based on factors, such as known or estimated cost of training the model, performance benchmarks, and the number of business users in the EU (set at 10,000).

Models in the general tier will have basic documentation and information-sharing obligations for all general-purpose AI (GPAI) models. An important compromise is that these basic obligations will be subject to stronger enforcement than just voluntary codes of practice – i.e. codes of conduct can be introduced as an interim measure while the benchmarks are being drawn up, but these will supplement rather than replace the final rulebook.

For models in the “systemic risk” tier, there will be advanced model assessment criteria and transparency requirements.

Contrary to the Council’s final compromise proposal ahead of the final trilogue, GPAI systems – i.e. the downstream applications of GPAI models – will not face additional regulations. It seems the centre and centre-right of Parliament felt that these were unnecessary. As a result, providers of downstream GPAI systems will only need to comply with additional technical requirements if their systems are deployed in high-risk use cases.Prohibited usesThe controversial real-time remote biometric identification by law enforcement authorities will be subject to prior authorisation, done within 24 hours if necessary. It will also be limited to 16 specific crimes. In response to civil rights advocates, any use will be preceded by prior fundamental rights impact assessment. Member States may introduce even more restrictions here.

Use of AI for biometric categorisation is prohibited for those systems that categorise persons individually, based on their biometric data, to infer their race, political opinions, trade union membership, religious or philosophical beliefs or sexual orientation. This does not mean searching databases (e.g. images). Law enforcement is exempt from these prohibitions.

It is also prohibited to use Minority Report-style systems for predictive policing, as well as systems for the recognition of emotions.

The controversial real-time remote biometric identification by law enforcement authorities will be subject to prior authorisation, done within 24 hours if necessary. In response to rights advocates, any use will be preceded by prior fundamental rights impact assessment. Member States may introduce even more restrictions here.

Systems offering post-remote biometric identification would be considered as high risk.

As anticipated, and in light of the new GPAI model rulebook, an AI Office has been set up within the Commission to oversee the regulation of the Act. The Office will help to set standards and benchmarks, particularly around testing and evaluation practices, and to ensure that the Act’s rules are enforced equally across Member States. This had been a priority after the difficulties arising from GDPR, which has sometimes been applied unevenly across Member States.

The AI Office will be advised by a scientific panel of independent experts, to help with setting and adjusting benchmarks and designation criteria for fGPAI models with systemic risk, as well as to advise on the emergence of next-generation foundation models and their associated risks.

Adjacent to the AI Office will be an AI Board made up of Member State representatives.  The Board will function as a coordination platform and advisory body to the Commission, as well as allowing Member States a say in how the foundation model regulations are implemented (including, e.g., creating codes of practice).

Finally, industry representatives, SMEs, start-ups, civil society, and academia will be able to provide technical expertise to the AI Board through a new ‘advisory forum’.

This week, at least, and possibly next, technical trilogues will continue daily to iron out the details of the political agreement. There is still tension among the co-legislators on some of the details of the tedious consensus reached.

Recitals will likely be the only part of the text left to the incoming Belgian Presidency of the Council of the EU, i.e. to be concluded in Q1. Then, between Q1 and the entry force of the AIA there will be procedural votes, legal and language review – so earliest end H1.

Most of the requirements will apply two years after the Act enters into force, i.e. around mid-2026. However, a few provisions will apply earlier: notably, prohibited AI systems bans will apply from six months after the Act enters into force, while the requirements for GPAI models, high-risk conformity assessment bodies and the AI Office will start applying within one year from entry into force.

Level two requirements will be developed before then: some have exact deadlines (such as the development of codes of practice, which must happen within nine months after the entry into force), but the deadlines for most are open-ended.

Some provisions in the AI Act – like sandboxes and SME relief – aim to foster innovation. However, the key contribution the law can make is to offer a playbook for the division of responsibilities along an AI supply chain, particularly for the developers and deployers of high-risk uses.

The heated European debate on the use of AI in law enforcement points to a strong value system, which may come at odds with other jurisdictions where the civil liberates debate is more secondary.

Finally, on generative AI, the rules seem to mostly allow the Commission a close oversight of the developing market.

More Posts

Starmer’s UK-EU reset: rhetoric rises, reality lags 

Managing Director James Nation outlines how Starmer and Reeves are advancing a more openly pro-EU stance to reset UK–EU relations, while highlighting the persistent gap between political rhetoric and practical constraints, and what this means for domestic politics, negotiations with Brussels, and the risks facing Labour ahead of the next election.

Forefront Advisers Limited, 20 St Thomas St, London SE1 9RS, registered in England and Wales, no. 13248974

Scroll to Top

Discover more from Forefront

Subscribe now to keep reading and get access to the full archive.

Continue reading

Joseph Steward

Director

Joseph works across Forefront’s digital assets and UK political teams. He joined Forefront from the FCA, where he worked on developing the UK’s crypto policy, with a particular focus on stablecoins. During his time at the FCA he also covered UK strategy and engagement in the Asia-Pacific region and was seconded to HM Treasury ahead of the 2024 general election to support the government transition and cover US and Canada financial services policy. He holds a degree in politics from University College London, which included a year at the Higher School of Economics in Saint Petersburg.

Jessica Hazel

Senior Analyst

Jess works on coverage of Energy and Sustainability policy, typically focusing on activities in the UK market.

She previously worked as a Hydrogen Policy Official for the Scottish Government, covering a range of different policy areas in her time there. 

Jess completed her MSc in Environment and Development at the University of Edinburgh.

Manon Quénel

Associate Director

Manon works on the coverage of the EU sustainability policy focusing on the sustainable finance agenda and corporate accountability rules.

Before joining Forefront, Manon worked for a Brussels-based public affairs consultancy where she was supporting corporate clients navigate the EU political and regulatory landscape, focusing on the Green Deal and the financial services’ agenda. Previously, she worked in the policy department of the French Economic and Social Council in Paris and interned in the European Parliament in Brussels.

Manon holds a dual degree of master’s in public administration from SciencesPo Strabourg and York University and a specialized master in EU studies from Universite Libre de Bruxelles.

James Nation

Managing Director

James is a Managing Director of UK Politics. He previously worked as the Deputy Head of the Number 10 Policy Unit from 2022 until May 2024 and before that was a Special Adviser to the Chancellor of the Exchequer. Recently, he led the team responsible for the Conservative Party Manifesto in the 2024 General Election campaign. Earlier in his career, James worked as a civil servant in MHCLG and the Treasury, following on from a role in tax and fiscal policy at the CBI. 

Ksenia Duxfield-Karyakina

Managing Director

Ksenia is the Managing Director of Emerging Technology at Forefront. She has spent most of her career in technology policy, working across the UK, Europe, Asia-Pacific, and Emerging Markets. Her expertise spans AI, data governance, cloud, content, and fintech policy areas.

Before joining Forefront, Ksenia led public policy and regulatory affairs for Google Cloud in Europe, and was responsible for YouTube Policy in APAC and Eurasia, based out of Hong Kong. Prior to entering the big tech industry, Ksenia worked in financial services, focusing on anti-fraud and policies addressing financial crime within the OECD ecosystem. She is a journalist by training and holds a PhD in new media economics. Ksenia is a parent to two daughters, an art lover, and an avid reader (of paper books).

Dustin Benton

Managing Director

Dustin is the MD of sustainability at Forefront. Previously, he was policy director at Green Alliance, leading its work across energy, resources, and the natural environment. He previously worked at Defra, where he was chief analytical advisor to Henry Dimbleby’s National Food Strategy and led the department’s analysis of food vulnerability. Earlier in his career, Dustin led on climate and renewables at the Campaign to Protect Rural England. He holds an MA in Political Thought and Theory from the University of Birmingham and an MA in International Relations and French from the University of St Andrews.

Max Kemp

Associate Director

Max works in the EU team on energy & net zero, with a focus on industrial policy. He joins Forefront with several years’ experience in industry associations, first advising local energy companies on EU policy and then representing the glass sector on energy issues. He has also worked in legal and policy consulting for the EU institutions. 

Joseph Steward

Director

Joseph works across Forefront’s digital assets and UK political teams. He joined Forefront from the FCA, where he worked on developing the UK’s crypto policy, with a particular focus on stablecoins. During his time at the FCA he also covered UK strategy and engagement in the Asia-Pacific region and was seconded to HM Treasury ahead of the 2024 general election to support the government transition and cover US and Canada financial services policy. He holds a degree in politics from University College London, which included a year at the Higher School of Economics in Saint Petersburg.

Ramona Visenescu

Associate Director

Ramona is an Associate Director focusing on sustainable finance and circular economy. Ramona previously worked in Brussels at Teneo, where she also covered ESG legislative priorities and interned at the European Commission in DG Economy and Finance. She earned her Bachelor degree in International Relations and European Studies from the University of Bucharest and completed an Advanced Master in Financial Markets at the Solvay Brussels School of Economics & Management.

Pietro Candia

Associate Director

Pietro works across EU Politics and is based in Brussels. Before joining Forefront, he interned in other political risk advisory firms and worked in the government relations division of a major oil corporation. He holds a Bachelor’s degree in International Politics from Georgetown University and a Master’s degree in European and International Public Policy from LSE.

Imogen Stead

Senior Analyst

Imogen works across the Emerging Tech service, covering EU, UK and multilateral policy and regulatory developments in AI and critical technologies. She previously worked on Forefront’s UK Politics note, with a focus on post-Brexit trading relations and foreign policy, and has prior experience of policy and stakeholder management in two UK Civil Service departments. She holds a BA, MPhil and DPhil in Classics from the University of Oxford. 

Michele Grassi

Analyst

Michele works on EU digital assets policy and Italian politics. He previously interned as MEP assistant at the European Parliament and as a Policy analyst at the Lombardy Regional Council. Michele holds a double degree MSc in European Public Policy from LSE and Bocconi University.

Pascal LeTendre-Hanns

Director

Pascal leads on Forefront’s Energy & Net Zero and Sustainability insights. Pascal previously worked in the Paris-based pro-European think tank, EuropaNova. He is leading sustainability policy coverage and following political developments in France and Spain. He graduated from UCL with a First Class Honours degree in European Social and Political Studies, specialising in international relations and French, which included a year at Sciences Po Paris. 

Charles d’Arcy-Irvine

Director

Charles works on political and policy insight advising businesses across different industries. He previously worked in investment banking at Goldman Sachs and Deutsche Bank, as an official at HM Treasury, as a political adviser to George Osborne, and in real estate. He holds a master’s degree in public administration from the John F. Kennedy School of Government at Harvard University and is a Trustee of the Epping Forest Schools Partnership Trust. 

Christopher Glück

Managing Director

Chris leads Forefront’s EU political analysis and insights team. He previously led Hanbury’s EU Public Affairs work. Previously, Chris worked on EU financial services policy in HM Treasury and as policy advisor for Jakob von Weizsäcker in the European Parliament. Chris holds a master’s degree from the College of Europe and read history at the University of Munich. 

Matt Gravelle

Managing Director

Matt leads on the Financial Services and Digital Assets team.  He joined in late 2024 from Kraken, a leading cryptoasset exchange, where he was Head of Policy and Government Relations for the UK and APAC.

Matt has worked in financial services policy since moving to London in 2013. Before his time at Kraken, he spent more than 5 years as a Director in Standard Chartered’s regulatory affairs team, where he focused on crypto and broader markets regulation across the bank’s global footprint. He previously held policy roles at Deutsche Bank and CME Group.  

Matt is originally from Ottawa, Canada, where he worked for the Canadian government and a policy think tank before moving to the UK. Matt studied at Queen’s University (BA) and McMaster (MA) in Ontario and the University of British Columbia (PhD) in Vancouver.

Gergely Polner

Managing Director

Gergely heads Forefront’s EU team. He was previously Head of EU Affairs at Standard Chartered Bank and at the British Bankers Association. Before his City career, he spent eight years at the EU institutions, including as a spokesperson for the EU Council Presidency and Head of UK Public Affairs for the European Parliament. While at the EU Institutions, Gergely worked on the EU’s sanctions regime and the regulatory reform in financial services. He started his career as a lawyer and built a successful legal translation business.

Get in touch

Fill out the form below, and we will be in touch shortly.

James Bergeron

Senior Adviser

James Bergeron leads Forefront’s defence analysis and advice. He is a former US Navy submarine officer and law professor, he has served as the political advisor to ten senior US and NATO commanders.