IA 360
Regulatory Framework

EU Agrees Its AI Act: What Made It In and What Stayed Out

Parliament and Council reached a provisional political agreement on the AI Act on December 8, 2023. It combines bans, risk-based duties, and exceptions that matter as much as the headline rules.

Admin IA360 2 min read AI-generated Leer en español
EU Agrees Its AI Act: What Made It In and What Stayed Out

On December 8, 2023, after negotiations that ran for three days, the European Parliament and Council reached a provisional political agreement on the Artificial Intelligence Act. It was not yet an adopted law or an applicable text: technical drafting, confirmation by member-state representatives, and formal adoption by both institutions still remained. That procedural distinction is the first key to reading a regulatory announcement without turning a milestone into an immediate obligation.

The Council described the agreement on December 9 as a risk-based framework. It does not regulate every form of artificial intelligence alike: it bans certain uses, imposes controls on high-risk systems, and reserves lighter transparency duties for limited risk. The useful question is therefore not merely “does it use AI?” but “which use, deployed by whom, can produce what harm?”

A political agreement, not the end of the procedure

The Council release states the file's status plainly: technical teams would finalize details in the following weeks, and the presidency would submit the compromise text to Coreper, the committee of member-state representatives, for endorsement. Formal votes would follow. The agreement itself envisaged application, with exceptions, two years after entry into force. Agreement, adoption, entry into force, and application date are four different events.

The European Parliament summarized the aim as protecting fundamental rights, democracy, the rule of law, and environmental sustainability from high-risk systems while leaving room for innovation. That language does not mean every detail had been settled. In a provisional negotiation, a release reveals the architecture and political choices; the final articles determine precise legal scope.

Read first where it does not apply

Before the bans, the exclusions matter. Under the scope published by the Council, the regulation would not extend to matters outside EU law or affect national competences in national security. Systems used exclusively for military or defence purposes, solely for research and innovation, and non-professional use by individuals were also outside its scope.

An exclusion does not declare a use safe or ethical. It says this particular instrument does not cover it, or does not cover it in the same way. That prevents a common mistake: reading “out of scope” as “allowed without constraint.” Data-protection law, sector-specific law, and other duties still exist; the agreement expressly clarified how AI Act responsibilities would relate to those existing rules.

The risk ladder

At the top are practices considered unacceptable. The agreement covered cognitive behavioural manipulation, untargeted scraping of facial images from the internet or CCTV to build recognition databases, emotion recognition in workplaces and educational institutions, social scoring, biometric categorization intended to infer sensitive data, and some forms of predictive policing directed at individuals.

Below them are high-risk systems, which are not prohibited. They may enter the market if they meet requirements for risk management, data quality, technical documentation, activity logging, information for deployers, human oversight, accuracy, robustness, and cybersecurity. The agreement also envisaged a fundamental-rights impact assessment before certain deployers put a high-risk system into service.

Limited-risk systems face lighter transparency duties. The Council's example is disclosure that content was AI-generated, allowing recipients to make an informed decision about further use. Classification does not measure how impressive a model is; it connects a function and context to particular duties. The same component can fall into different categories when integrated into different uses.

Biometrics: a ban with exceptions

Real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes was not described as an absolute ban. The Parliament listed narrow exceptions, subject to prior judicial authorization and tied to defined aims: locating victims of certain crimes, preventing genuine and foreseeable threats such as a terrorist attack, or finding suspects in the most serious crimes.

That qualification explains criticism from digital-rights organizations. European Digital Rights (EDRi) acknowledged gains but argued that exceptions opened a path to discriminatory and mass-surveillance uses. It also identified partial boundaries: emotion recognition was banned at work and in education, not everywhere; predictive policing did not disappear in every form; and the technical text still had to be read before the real reach could be assessed.

Both statements can be true: there is a general ban and there are exceptions. Removing either side turns a conditional rule into a slogan. Evaluating a safeguard requires asking who authorizes it, for what purpose, for how long, against which population, and what route remains for an affected person to challenge it.

General-purpose models

The negotiation added rules for general-purpose systems and foundation models, an issue that had grown since the original 2021 proposal. The Council announced transparency obligations before market placement and a stricter regime for high-impact models capable of propagating systemic risk through the value chain. Parliament added evaluations, risk mitigation, incident reporting, cybersecurity, and energy-efficiency duties for the systemic tier.

This layer does not replace classification of the product using the model. A general-purpose provider has its own obligations; an organization integrating it into hiring, credit, education, or critical infrastructure may assume separate duties as provider or deployer of a high-risk system. The agreement sought to allocate responsibility along a chain where the model creator and the organization deciding the final use are not always the same.

What companies said—and did not say

The primary sources reviewed contain no joint acceptance of this agreement by IBM, Meta, AMD, Intel, and Dell. Those organizations appear together because, on December 5, before the legislative deal, IBM and Meta announced the AI Alliance with more than 50 members. Its release discusses open science, evaluation, and responsible tools; it does not present the alliance as an endorsement of the AI Act.

The documented industry response was more qualified. DIGITALEUROPE, a trade association, called the agreement a milestone and said a well-executed rulebook could support uptake and innovation. It also criticized new foundation-model duties and warned that compliance could divert resources, especially at small software companies. That is support for a common framework combined with a dispute over cost and design, not unreserved acceptance.

Governance, complaints, and penalties

The compromise envisaged an AI Office inside the Commission to oversee advanced models, support standards and testing, and enforce common rules. An independent scientific panel would advise on capabilities and risks; an AI Board of national representatives would coordinate implementation; and a stakeholder forum would contribute knowledge from businesses, SMEs, academia, and civil society.

It also recognized that a natural or legal person could complain to a market-surveillance authority. Announced penalties varied by severity: up to €35 million or 7% of worldwide annual turnover for banned practices; €15 million or 3% for other obligations; and €7.5 million or 1.5% for supplying incorrect information, using the higher amount. More proportionate caps were envisaged for SMEs and startups.

Innovation remained part of the design. Regulatory sandboxes were intended to let developers build, test, and validate systems in a controlled environment, including real-world testing under safeguards. Such a tool is useful when a company can learn before launch which category its product occupies, what evidence it must retain, and who will assess conformity.

The skill that survives the headline

To read a new technology regulation, build a timeline and a matrix. The timeline separates proposal, political agreement, final text, adoption, entry into force, and application. The matrix crosses banned practice, high-risk system, limited risk, and general-purpose model with exclusions, responsible actors, and exceptions. Only then does it make sense to discuss the effect on a company or a right.

As of December 10, 2023, Europe had closed a decisive political negotiation; it had not completed the legal work or activated every duty. The agreement demonstrated a durable regulatory method: judge AI not by its label but by use, risk, and the actor making decisions. It also demonstrated a limit: a protection can sound absolute in a summary and become conditional when its exceptions are read. Knowing how to find those conditions is more useful than memorizing a list of bans.

This article was produced with artificial intelligence under human editorial oversight.

Share this article

This website uses cookies to improve the browsing experience. Cookie policy.

↑↓ navigate ↵ open esc close