The vote

On March 13 the European Parliament adopted the Artificial Intelligence Act with 523 votes in favour, 46 against and 49 abstentions. It enters into force twenty days after publication in the Official Journal. Co-rapporteur Brando Benifei called it the world's first binding law on artificial intelligence. His colleague Dragos Tudorache said the EU had linked the concept of artificial intelligence to the fundamental values that form the basis of its societies. Both statements are true and neither tells you what the law does.

What it does is sort uses of AI into tiers by risk and attach obligations to each tier. That structure was designed years before anyone outside a few labs had used a large language model, and most of the text is about applications rather than models. The parts that touch frontier training runs were added late in the negotiation, and they are the parts we want to spend time on.

The tiers

At the top are practices that are banned outright. Biometric categorisation by sensitive characteristics. Untargeted scraping of faces from the internet or CCTV to build recognition databases. Emotion recognition in workplaces and schools. Social scoring. Predictive policing based solely on profiling. Systems that manipulate behaviour or exploit vulnerabilities. Real time remote biometric identification by police is prohibited in principle, with narrow exceptions that require prior judicial or administrative authorisation and limits on time and place.

Below that are high risk systems, defined by the domains they are used in. Providers and deployers of these must assess and reduce risk, keep logs of use, meet transparency and accuracy standards and ensure human oversight. Citizens gain a right to complain and a right to an explanation of decisions that affect their rights. Most ordinary uses of AI fall below this line and face little beyond transparency duties, such as labelling deepfakes.

The provisions bolted on for general-purpose models

The original proposal had no category for a model that does everything. The final text does. General-purpose AI models must comply with EU copyright law and publish a detailed summary of the content used for training. That second requirement alone is a departure from the current practice of most frontier labs, which disclose little about their data.

Then there is a second tier within the tier. More powerful general-purpose models that could pose what the text calls systemic risk face additional duties: perform model evaluations, assess and mitigate systemic risks, and report serious incidents. The Parliament's summary does not spell out the threshold, and readers will want to check the final text for the compute figure that defines it. The design choice is what matters. A law about biometric scanners and hiring tools now also has a clause that turns on how much compute went into a training run, which makes it, in a small but real way, a law about training runs.

When any of it binds

The timeline is staggered and worth memorising. The bans on prohibited practices apply six months after entry into force. Codes of practice are due at nine months. The general-purpose model obligations apply at twelve months. The law as a whole applies at twenty four months, and the obligations for high risk systems embedded in regulated products come at thirty six. Assuming publication this spring, that puts the general-purpose rules in the first half of 2025 and the bulk of the high risk regime in 2026 and 2027.

The codes of practice deadline is the one we would watch. Much of what the systemic risk obligations mean in practice, what counts as an adequate evaluation, what an incident is, what mitigation is required, will be set in those codes rather than in the Act itself. Whoever is in the room when they are drafted will shape how a frontier lab has to behave in Europe. That is a different kind of process from the parliamentary vote and it will get much less attention.

What it means for a lab, and for us

For a lab, the immediate obligations are disclosure and process. Publish a training data summary, respect copyright, and if your model clears the systemic risk threshold, run evaluations, document risk mitigation and report incidents. None of this dictates what a model may or may not be capable of. It creates a paper trail and a set of duties that can later be enforced. The law also sets up national regulatory sandboxes and real world testing arrangements meant to be accessible to smaller companies, though how usable those are will depend on each member state.

For researchers, the training data summary requirement is the item to care about. If it is implemented with any seriousness, the field will get its first legally required look at what the largest models were trained on, which bears directly on contamination, on provenance and on reproducibility. We would not expect labs to volunteer detail beyond the minimum, and the minimum is not yet defined. That is an argument for paying attention to the codes of practice rather than to the vote, and for treating this week's number, 523 to 46, as the start of the process rather than the end of it.

Sources

  1. European Parliament press release, Artificial Intelligence Act: MEPs adopt landmark law