# EU AI Act Proposal 2021

The EU AI Act Proposal 2021 is the European Commission's original draft regulation for artificial intelligence, proposing a risk-based framework to govern AI systems within the European Union. It was introduced on 21 April 2021 and later revised before final adoption.

The EU AI Act Proposal 2021 is the European Commission's initial legislative proposal for regulating artificial intelligence (AI) within the European Union. Introduced on 21 April 2021, it established a risk-based framework to classify AI applications into four levels - unacceptable, high, limited, and minimal - with corresponding obligations for providers and deployers. The proposal was later revised to address the rise of generative AI systems, such as [ChatGPT](https://www.wikiprompt.org/wiki/large-language-model), before being adopted as the final [AI Act](https://www.wikiprompt.org/wiki/artificial-intelligence) in 2024.

The proposal emerged from a broader EU strategy to position the bloc as a leader in trustworthy AI, balancing innovation with fundamental rights protection. It drew on earlier work by the European Parliament and the Commission's High-Level Expert Group on AI, which had called for a regulatory framework that could adapt to rapid technological change. The original text aimed to harmonise national rules, prevent market fragmentation, and ensure that AI systems placed on the EU market were safe and respect existing laws.

## Background and Legislative History

The European Commission had been developing AI policy since 2018, when it published a coordinated plan on AI with member states. In February 2020, the Commission released a White Paper on AI, which outlined policy options and launched a public consultation. The feedback, combined with impact assessments, informed the draft regulation presented on 21 April 2021 by Commissioner for Internal Market Thierry Breton and Vice-President Margrethe Vestager.

The proposal was part of a broader digital package that also included the Digital Services Act and the Digital Markets Act. Unlike those regulations, which focused on online platforms, the AI Act targeted the technology itself, using a product-safety model similar to existing EU legislation on machinery, toys, and medical devices. This approach assigned duties to AI providers (developers) and deployers (users) based on the level of risk their systems posed.

The legislative process took over three years. The European Parliament and the Council of the EU negotiated amendments, with significant changes made in response to the rapid adoption of generative AI tools. The final text was passed by the Parliament on 13 March 2024 and approved by the Council on 21 May 2024, entering into force on 1 August 2024. The 2021 proposal, however, remains historically significant as the foundation for these negotiations.

## Risk-Based Classification

The core of the proposal was a four-tier risk pyramid, which was largely retained in the final Act. The categories were designed to reflect the potential harm an AI system could cause to health, safety, or fundamental rights.

### Unacceptable Risk

Applications deemed to pose an unacceptable risk were to be banned outright. This included AI systems that manipulate human behaviour to circumvent free will, those that exploit vulnerabilities of specific groups (such as children or persons with disabilities), and social scoring systems that ranked individuals based on personal characteristics or behaviour. The proposal also banned real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, with narrow exceptions for specific crimes and with judicial authorisation.

### High Risk

High-risk AI systems were subject to the most extensive obligations. The proposal listed eight specific areas: biometric identification and categorisation of natural persons; management and operation of critical infrastructure; education and vocational training; employment and worker management; access to essential private and public services; law enforcement; migration, asylum, and border control; and administration of justice and democratic processes. Providers of high-risk systems had to implement risk management systems, use high-quality training data, maintain technical documentation, enable automatic logging, ensure transparency, and provide human oversight. They also had to undergo conformity assessments before market placement and throughout the system's lifecycle.

### Limited Risk

Limited-risk AI systems, such as chatbots and deepfake generators, were subject to transparency obligations. Users had to be informed when they were interacting with an AI system, and content generated or manipulated by AI had to be labelled as such. This was intended to allow individuals to make informed choices and to prevent deception.

### Minimal Risk

The majority of AI applications, including video games and spam filters, were considered minimal risk and were not regulated. The proposal encouraged voluntary codes of conduct for these systems, but did not impose binding requirements. Member states were also prevented from adding extra national rules for minimal-risk systems, ensuring a single market for AI.

## General-Purpose AI and Generative Models

The original 2021 proposal did not explicitly address general-purpose AI (GPAI) systems, which can perform a wide range of tasks across different domains. This gap became apparent with the explosive growth of generative AI models like [ChatGPT](https://www.wikiprompt.org/wiki/generative-ai) and [other foundation models](https://www.wikiprompt.org/wiki/openai) in late 2022 and 2023. The draft was revised to include a dedicated category for GPAI, with tiered obligations.

Under the revised framework, all GPAI models had to provide technical documentation, publish training data summaries, and comply with copyright law. Open-source models, where weights and design were made public, faced reduced requirements, such as only needing to publish a training data summary and a copyright policy. Closed-source models had to meet broader transparency duties. High-impact models that required more than 10^25 floating-point operations to train were deemed to pose systemic risks and had to undergo additional evaluations, adversarial testing, and cybersecurity measures.

This revision was a direct response to the challenges posed by [machine learning](https://www.wikiprompt.org/wiki/machine-learning) systems that could be fine-tuned for numerous applications, making it difficult to classify them under the original risk categories. The approach aimed to balance innovation with oversight, particularly for the most powerful models developed by companies like [Google DeepMind](https://www.wikiprompt.org/wiki/google-deepmind) and [Anthropic](https://www.wikiprompt.org/wiki/anthropic).

## Enforcement and Governance

The proposal established a governance structure to ensure consistent application across the EU. It created a European Artificial Intelligence Board, composed of representatives from member states and the Commission, to facilitate cooperation and provide guidance. National supervisory authorities were responsible for enforcing the regulation in their territories, with the power to conduct market surveillance and impose penalties.

Penalties for non-compliance were set at up to 6% of a company's global annual turnover for violations involving prohibited practices, 4% for other infringements, and 2% for supplying incorrect information. These fines were comparable to those under the General Data Protection Regulation, reflecting the EU's commitment to robust enforcement.

The proposal also included provisions for extraterritorial application, meaning that providers from outside the EU would be subject to the regulation if they offered AI systems to users within the EU. This mirrored the GDPR's approach and aimed to create a level playing field for global AI developers.

## Exemptions and Scope

Certain AI systems were excluded from the proposal's scope. These included systems used exclusively for military, defence, or national security purposes, as well as those developed and put into service solely for scientific research and development. The regulation also did not apply to AI used for personal, non-professional activities. These exemptions were intended to respect member states' sovereignty in security matters and to avoid hindering innovation in research settings.

However, the proposal did not exempt AI systems used in law enforcement or migration control, even though these are often state functions. Instead, it subjected them to the high-risk category, with additional safeguards such as human oversight and fundamental rights impact assessments.

## Impact and Legacy

The 2021 proposal was a landmark in AI regulation, being the first comprehensive legal framework for AI proposed by a major jurisdiction. It influenced subsequent regulatory efforts worldwide, including the Council of Europe's AI Convention and various national initiatives. The risk-based approach was widely debated, with some scholars praising its flexibility and others criticising potential gaps or overregulation.

During the legislative process, the proposal was amended to address concerns from industry and civil society. For instance, the list of high-risk applications was refined, and the definition of AI was aligned with the OECD's. The final Act, adopted in 2024, retained the core structure of the 2021 proposal but added the GPAI category and adjusted certain thresholds.

The proposal also sparked academic and policy discussions about the nature of AI regulation. Some argued that the product-safety model was appropriate for AI, while others called for a more human-rights-centred approach. The inclusion of fundamental rights impact assessments was seen as a progressive step, building on earlier work on algorithmic impact assessments.

As of 2025, the AI Act's provisions are being phased in, with the first deadlines for prohibited practices and GPAI obligations already in effect. The 2021 proposal remains a key reference point for understanding the evolution of AI governance in the EU and globally.

---
Source: https://www.wikiprompt.org/wiki/eu-ai-act-2023-proposal
License: CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/)
Last updated: 2026-09-13T03:51:27.665561+00:00
