
The EU AI Act is one of the most talked about, and let’s face it, one of the most criticized pieces of legislation in the world right now. Its detractors simultaneously accuse it of being too strict, and, on the other side of the spectrum – not strict enough, which is at least proof that it is genuinely trying to solve a very difficult problem: regulate a rapidly evolving, complex, and globally deployed technology that touches almost every aspect of our lives.
Given the current level of noise, I thought it useful to lean into it and see for myself what this piece of legislation actually says. After combing through its chapters and articles, reading some of its sections carefully, while skipping through others, my selection is inevitably subjective. The Act is a dense and complex piece of legislation, and reasonable people will weigh its provisions differently depending on their background, values and professional perspective.
The top five I outline here are the provisions I considered most important – and I try to explain why each of them made the cut.
If you want to make your own assessment, the full text of the AI Act is available at https://artificialintelligenceact.eu or on EUR-Lex (the EU’s official legal database).
Without further ado, let’s dive in:
#1 EU AI Act Classifies AI Systems Based on Risk
That means not all AI systems are considered equally “dangerous”, if at all. The EU law classifies them into 4 categories: minimal risk (e.g. spam filters), limited risk (e.g. chatbots, deepfakes), high risk (e.g. biometric identification, critical infrastructure AI) and unacceptable risk (e.g. subliminal manipulation, emotion recognition). The higher the risk, the stricter the rules – going from transparency obligations to outright banning. (Chapter II – Prohibited, III – High Risk, IV – Limited Risk)
Why is classifying AI systems by risk important? The AI realm is vast and complex, so you can’t have a “one size fits all” approach. This allows focusing protection where it is most needed, while at the same time leaving space for innovation.
#2 Complete Prohibition of Certain Uses of AI
Some of the AI use cases are completely prohibited in Europe, deemed too dangerous for humans and their rights. For example: real time facial recognition in public spaces, using AI based subliminal techniques intended to manipulate behavior, AI based social scoring, etc. (Article 5)
Why is this chapter important? Manipulation at scale, as opposed to manipulation performed by humans, is not naturally limited. Therefore, a risk that is in human terms “calculated” and contained becomes a mass psychological weapon when inferred by an AI system. These risks can lead to irreversible damage (e.g. a negative social score once granted can deny a person equal access to workforce, health services, or insurance for an indefinite number of years, and can equate to a conviction without trial). These risks create a power asymmetry that is so big that they can lead to severe societal imbalances and are incompatible with the fundamental values of a democratic society.
#3 Strict Rules for High-risk AI Systems
AI systems that are used in sensitive domains – medical, legal, human resources, education or critical infrastructure – must be transparent, rigorously tested and supervised by humans. In short, no machine can take important decisions about human life on its own. (Article 6)
Why is it important? This is where AI systems meet institutional power. The high-risk systems are implemented in banks, hospitals, large employers, police, courts, immigration authorities – that is, exactly in those places where you don’t have the possibility to opt out. These institutions already have enormous power in our lives. Add AI to the mix, and this power becomes even more asymmetrical and difficult to contest.
The supplementary regulations involve documenting and testing before deploying, even more transparency requirements (for example registration in an EU public database), mandatory human supervision, and lifetime risk management.
#4 The Right to Be Informed that You’re Interacting with AI
If you talk with a chatbot or interact with AI generated content (image, video, text), you need to be informed about it. Companies are not allowed to make you believe you are talking to a human when in fact you are interacting with a bot. (Article 50)
Why is it important?
This article establishes a fundamental moral and legal principle: people have the right to know what they are interacting with. It establishes that informed consent is not optional.
#5 Special Regulations for General Purpose AI (GPAI)
Powerful AI models like GPT or Claude are subject to more obligations. The companies that develop these models must respect copyright law, make available information about how the models are trained and allow them to be risk evaluated before they are made available to the public. (Chapter V)
The EU AI Act also defines in quantitative terms what GPAI means. The threshold is set at 10(^25). That means an AI system is designated GPAI if the cumulative amount of computation used for its training measured in floating point operations* is greater than 10 followed by 25 zeros. To put it in perspective, a modern laptop does roughly 10(^12) (one trillion) floating point operations per second. To reach 10(^25) it would need to run for about 300,000 years.
GPT-4 was estimated to have been trained using somewhere around 10(^23) – 10(^24) FLOPs falling just below the threshold.
*A “floating point operation” (FLOP) is one mathematical calculation (adding, multiplying etc.) done by a computer chip.
Note on Natural Person
I couldn’t help but notice that the term “natural person(s)” appears extensively throughout the EU AI Act.
My guess is that the European Commission introduces this term in order to unequivocally designate “real human beings” as opposed to any other type of entity (legal person, company, public body, NGO), but also to distinguish from “AI enhanced person” or “fully autonomous entity”.
The distinction is important precisely because legal rights, protections, and obligations apply differently depending on who or what you are dealing with.
A natural person has a set of unique features that other entities don’t (fundamental rights, empathy, judgement, conscience). A natural person can give or revoke consent, can become victim of fraud or deception, and is also bound by moral and legal accountability, while an AI system has none of those.
At the same time, what can AI do? It can answer with empathy and warmth, it can personalize answers in accordance with your emotional needs, it can simulate a trust-based relationship, and it can make you believe that it understands and cares about your feelings, while in reality, it is not human, it has no rights, and no moral responsibility. In other words, there’s nobody “home”.
The AI Act introduces this term precisely because, for the first time in history, AI is creating an entity that can convincingly mimic a natural person – without actually being one.
The Big Missing Points
However important the 5 provisions previously mentioned, I have noticed the AI ACT doesn’t seriously address some other big societal impact issues. Here are some of them:
- Retraining measures to help employees acquire critical AI skills.
- Protective measures for individuals who will be explicitly laid off due to the implementation of AI.
- Regulations concerning big data centers and their impact on communities (environment, health, utility prices, decline in property values, etc.).
These omissions may not be accidental but rather a conscious political choice to keep the bill focused and passable. Whether this choice is justified or represents a fundamental failure of vision is perhaps the most important debate about the AI Act that has yet to take place in the public sphere.
The Takeaways
I hope this selection steers your curiosity to learn more about what’s being done at a global level to regulate and mitigate AI risks. The EU AI Act is unique in being the first of its kind in terms of complexity, legal binding, and rights-based among all AI frameworks that are being written as we speak, in the entire world.
It exists within a rapidly evolving global landscape where every major economy is wrestling with the same fundamental question: how do you govern a type of technology that is transforming everything, faster than any law can be written?
In my perspective, The AI Act provides clear regulations on how AI interacts with people, but it provides little or no regulation on how AI affects society – jobs, communities, the environment, and the distribution of economic power.
If it’s the beginning of a bigger, more consequential conversation, or merely a paper tiger, we’ll have to live through it to see.