Last month, the US-EU Trade and Technology Council (TTC) held its inaugural ministerial in Pittsburgh: US Secretary of State Antony Blinken, Commerce Secretary Gina Raimondo, and Trade Representative Katherine Tai met with European Commissioners Margrethe Vestager and Valdis Dombrovskis. Only three months after the TTC process was launched at the US-EU summit, the two sides
On 22 September 2021, the UK Government published its 10-year strategy on artificial intelligence (“AI”; the “UK AI Strategy”).
The UK AI Strategy has three main pillars: (1) investing and planning for the long-term requirements of the UK’s AI ecosystem; (2) supporting the transition to an AI-enabled economy across all sectors and regions…
Three summits last week—G-7, NATO, and U.S.-EU—launched a wide range of transatlantic initiatives to coordinate policy, particularly on trade, technology, and defense. These new formats and dialogues can ensure a much deeper level of regulatory cooperation between the United States and Europe by exchanging perspectives, briefing materials, and in some cases, staff. For companies on both sides of the Atlantic, these emerging policy trends also open up new opportunities to engage decision-makers both in Washington and European capitals.…
Continue Reading Transatlantic Summits: Main Takeaways for Tech and Defense
The Commission’s objectives with the Regulation are twofold: to promote the development of AI technologies and harness their potential benefits, while also protecting individuals against potential threats to their health, safety, and fundamental rights posed by AI systems. To that end, the Commission proposal focuses primarily on AI systems identified as “high-risk,” but also prohibits three AI practices and imposes transparency obligations on providers of certain non-high-risk AI systems as well. Notably, it would impose significant administrative costs on high-risk AI systems of around 10 percent of the underlying value, based on compliance, oversight, and verification costs. This blog highlights several key aspects of the proposal.
Definition of AI systems (Article 3)
The Regulation defines AI systems as software using one or more “techniques and approaches” and which “generate outputs such as content, predictions, recommendations or decisions influencing the environments they interact with.” These techniques and approaches, set out in Annex I of the Regulation, include machine learning approaches; logic- and knowledge- based approaches; and “statistical approaches, Bayesian estimation, [and] search and optimisation methods.” Given the breadth of these terms, a wide range of technologies could fall within scope of the Regulation’s definition of AI.
Territorial scope (Article 2)
The Regulation would apply not only to AI systems placed on the market, put into service, or used in the EU, but also to systems, wherever marketed or used, “where the output produced by the system is used in the Union.” The latter requirement could raise compliance challenges for suppliers of AI systems, who might not always know, or be able to control, where their customers will use the outputs generated by their systems.
Prohibited AI practices (Article 5)
The Regulation prohibits certain AI practices that are deemed to pose an unacceptable level of risk and contravene EU values. These practices include the provision or use of AI systems that either deploy subliminal techniques (beyond a person’s consciousness) to materially distort a person’s behaviour, or exploit the vulnerabilities of specific groups (such as children or persons with disabilities), in both cases where physical or psychological harm is likely to occur. The Regulation also prohibits public authorities from using AI systems for “social scoring”, where this leads to detrimental or unfavourable treatment in social contexts unrelated to the contexts in which the data was generated, or is otherwise unjustified or disproportionate. Finally, the Regulation bans law enforcement from using ‘real-time’ remote biometric identification systems in publicly accessible spaces, subject to certain limited exceptions (such as searching for crime victims, preventing threat to life or safety, or criminal law enforcement for significant offenses).
Classification of high-risk AI systems (Article 6)
The Regulation classifies certain AI systems as inherently high-risk. These systems, enumerated exhaustively in Annexes II and III of the Regulation, include AI systems that are, or are safety components of, products already subject to EU harmonised safety regimes (e.g., machinery; toys; elevators; medical devices, etc.); products covered by other EU legislation (e.g., motor vehicles; civil aviation; marine equipment, etc.); and AI systems that are used in certain specific contexts or for specific purposes (e.g.; for biometric identification; for educational or vocational training, etc.).
- Conditions for reuse of public sector data that is subject to existing protections, such as commercial confidentiality, intellectual property, or data protection;
- Obligations on “providers of data sharing services,” defined as entities that provide various types of data intermediary services;
- Introduction of the concept of “data altruism” and the possibility for organisations to register as a “Data Altruism Organisation recognised in the Union”; and
- Establishment of a “European Data Innovation Board,” a new formal expert group chaired by the Commission.
Conditions for reuse of public sector data (Chapter II, Articles 3-8)
Chapter II of the Data Governance Act would impose conditions on public-sector bodies when they make certain protected data that they hold available for re-use. These provisions apply to data held by public-sector bodies that are protected on grounds of commercial or statistical confidentiality, intellectual property rights, or personal data protection. The Act does not impose new obligations on public-sector bodies to allow re-use of data and does not release them from their existing legal obligations with respect to data. But if public-sector bodies do make protected data available for re-use, they must comply with the conditions set out in Chapter II.
Specifically, the Act prohibits public-sector bodies from granting exclusive rights in data or restricting the availability of data for re-use by entities other than the parties to such exclusive agreements, with limited derogations. In addition, if a public-sector body grants or refuses access for the re-use of data, it must ensure that the conditions for such access (or refusal) are non-discriminatory, proportionate, and objectively justified, and must make those conditions publicly available. The Act also provides that public bodies “shall” impose conditions “that preserve the functioning of the technical systems” used to process such data, and authorizes the Commission to adopt implementing acts declaring that third countries to which such data may be transferred provide IP and trade secret protections that are “essentially equivalent” to those in the EU.
In addition, where specific EU acts establish that certain non-personal data categories held by public-sector bodies are “highly sensitive,” such data may be subject to restrictions on cross-border transfers, as specified by the Commission through delegated acts.
Obligations on “providers of data sharing services” (Chapter III, Articles 9-14)
Chapter III of the Act introduces new rules for the operation of data intermediaries, termed “providers of data sharing services”. Specifically, it would establish a notification and compliance framework for providers of the following data sharing services:
- Intermediation services between data holders and data users, which include platforms or databases enabling the exchange or joint exploitation of data, such as industry data spaces;
- Intermediation services between data subjects that seek to make their personal data available and potential data users; and
- “Data cooperative” services that support individuals or SMEs to negotiate terms and conditions for data processing.
The Act set out several requirements that providers of these data sharing services would need to comply with, including:
- Notifying the relevant EU Member State authority of its intent to provide such services;
- Appointing a legal representative in one of the Member States, if the company is not established within the EU;
- Not using the data collected for other purposes, and using any metadata only for the development of that service;
- Placing its data sharing service in a “separate legal entity” from its other services;
- Having in place adequate security safeguards; and
- Imposing a fiduciary duty towards data subjects to act in their best interests.
Note: This post is the third in a series of posts on the final text of the Trans-Pacific Partnership (TPP) by Covington’s International and Public Policy lawyers. The final TPP text, which was released on November 5, 2015, is available here. TPP is not expected to enter into force until at least 2016, with…
Note: This is the first of a series of posts on the final text of the Trans-Pacific Partnership (TPP) by Covington’s International and Public Policy lawyers. The final TPP text, which was released on November 5, 2015, is available here. TPP is not expected to enter into force until at least 2016, with the…