The EU Bans AI Systems with “Unacceptable Risk”

Starting this Sunday, regulators in the European Union have the authority to ban AI systems deemed to pose an “unacceptable risk” or potential harm.

February 2 marks the first compliance deadline for the EU Artificial Intelligence Act, a comprehensive regulatory framework approved last March after years of development. While the law officially came into effect on August 1, its implementation is now underway.

Article 5 of the law outlines the specifics, but in general terms, the regulation applies to various scenarios in which AI interacts with people, from consumer applications to its presence in physical environments.

Following the EU’s approach, the law classifies AI systems into four risk levels:

  • Minimal risk: Technologies like email spam filters will not be subject to regulation.
  • Limited risk: Applications such as customer service chatbots will face light regulatory oversight.
  • High risk: Systems impacting sensitive areas, such as medical recommendations, will be under strict supervision.
  • Unacceptable risk: These applications, the focus of current compliance requirements, will be completely banned.

The prohibited AI practices include:

  • Social scoring systems that evaluate people based on their behavior.
  • Algorithms that manipulate human decisions in a deceptive or subliminal manner.
  • AI that exploits vulnerabilities such as age, disability, or socioeconomic status.
  • Models attempting to predict criminality based on a person’s appearance.
  • The use of biometrics to infer personal characteristics, such as sexual orientation.
  • Real-time biometric data collection in public spaces for surveillance purposes.
  • Tools that attempt to detect emotions in workplaces or educational settings.
  • Systems that gather images from the internet or security cameras to create facial recognition databases.

Companies using these AI technologies within the EU will face penalties, regardless of their headquarters’ location. Fines could reach up to €35 million (about $36 million) or 7% of their annual revenue, whichever is higher.

However, these sanctions will not be enforced immediately. According to Rob Sumroy, technology director at the law firm Slaughter and May, organizations are expected to comply with the regulations starting February 2, but the next key milestone will be in August. By then, authorities responsible for enforcement will be designated, and fines will start to be applied.


By: Nestor Castillo, ForAllTechNews Director


Discover more from ForAllTechNews

Subscribe now to keep reading and get access to the full archive.

Continue reading