Wikiprompt

EU AI Act Negotiations

The EU AI Act Negotiations were trilogue discussions between the European Commission, Parliament, and Council that led to a political agreement on the Artificial Intelligence Act, the EU's comprehensive regulation for AI systems.

The EU AI Act Negotiations were a series of trilogue meetings held between the European Commission, the European Parliament, and the Council of the European Union to finalize the text of the Artificial Intelligence Act (AI Act). The negotiations concluded with a political agreement on 8 December 2023, after which the Act was formally adopted by the Parliament on 13 March 2024 and approved by the Council on 21 May 2024. The regulation entered into force on 1 August 2024, with provisions phased in over the following 6 to 36 months.

The AI Act establishes a common regulatory and legal framework for artificial intelligence within the EU. It covers most AI systems across a wide range of sectors, with exemptions for AI used only for military, national security, research purposes, or non-professional use. As a form of product regulation, it does not create individual rights; instead, it places duties on AI providers and on organisations that use AI in a professional context.

Background and Proposal

The European Commission proposed the AI Act on 21 April 2021. The initial draft focused on a risk-based framework for AI applications, drawing on earlier work in AI ethics and product safety regulation. The proposal underwent extensive review and amendment during the legislative process.

The rise of generative AI systems, such as ChatGPT from OpenAI, presented a challenge to the original framework. These general-purpose models could perform a wide range of tasks, not fitting neatly into the predefined risk categories. The draft Act was revised to address this, adding a specific category for general-purpose AI.

Trilogue Negotiations

Trilogue negotiations are informal tripartite meetings between representatives of the European Parliament, the Council, and the European Commission to reconcile their differing positions on a legislative proposal. For the AI Act, these negotiations began after the Parliament adopted its negotiating position in June 2023 and the Council agreed its general approach in December 2022.

The trilogues addressed several contentious issues, including the definition of high-risk AI, the treatment of foundation models, and the use of real-time remote biometric identification in public spaces. The Parliament pushed for stricter rules on biometric surveillance and more robust obligations for general-purpose AI, while the Council sought to balance innovation with consumer protection.

A previous draft was rejected by the Parliament in a committee vote, leading to a revised mandate. The final political agreement was reached on 8 December 2023, after marathon negotiations that extended into the early morning.

Key Outcomes

The final text of the AI Act introduced a four-tier risk classification: unacceptable, high, limited, and minimal risk. Applications with unacceptable risks are banned, except for specific exemptions. High-risk applications must comply with security, transparency, and quality obligations, and undergo conformity assessments. Limited-risk applications have transparency obligations, while minimal-risk applications are not regulated.

A new category for general-purpose AI was added in 2023. This includes foundation models that can perform a wide range of tasks. If a model's weights and design are made open source, developers must publish a training data summary and a copyright policy; closed-source models must meet broader transparency requirements. High-impact models that pose systemic risks (requiring more than 10^25 floating-point operations to train) must undergo extra evaluation.

The Act also created the European Artificial Intelligence Board to promote national cooperation and ensure compliance. Like the EU's General Data Protection Regulation, the Act can apply extraterritorially to providers from outside the EU if they have users within the EU.

Risk Categories in Detail

Unacceptable risk includes AI applications that manipulate human behaviour, use real-time remote biometric identification (such as facial recognition) in public spaces, or are used for social scoring. These are banned, with narrow exemptions.

High-risk applications include AI systems used in health, education, recruitment, critical infrastructure management, law enforcement, or justice. They are subject to quality, transparency, human oversight, and safety obligations. Some require a Fundamental Rights Impact Assessment (FRIA) before deployment. Citizens have the right to submit complaints and receive explanations of decisions made by high-risk AI that affect their rights.

Limited risk includes AI systems that generate or manipulate images, sound, or videos (like deepfakes), which must inform users that they are interacting with AI. Minimal risk includes video games and spam filters, which are not regulated, and member states cannot impose additional regulations due to maximum harmonisation rules.

General-Purpose AI Obligations

Providers of general-purpose AI models must publish a summary of training data, adopt a policy to comply with copyright law, and provide technical documentation to downstream providers and supervisory authorities. Models designated as posing systemic risk must also carry out model evaluations and adversarial testing, assess and mitigate risks such as bias and security failures, report serious incidents, and ensure adequate cybersecurity.

A General-Purpose AI Code of Practice, published on 10 July 2025, outlines three main chapters on transparency, copyright, and safety and security to help providers demonstrate compliance. Participation in the code is voluntary.

Exemptions and Extraterritoriality

Articles 2.3 and 2.6 exempt AI systems used for military or national security purposes or pure scientific research and development from the AI Act. The regulation does not apply where AI systems are used exclusively for military, defence, or national security purposes, or to systems developed and put into service solely for those reasons.

The Act can apply to providers outside the EU if they have users within the EU, similar to the GDPR's extraterritorial reach. This means companies based in the US, China, or elsewhere must comply when offering AI services to EU residents.

Implementation Timeline

The AI Act entered into force on 1 August 2024. Provisions will come into operation gradually over the following 6 to 36 months. The first milestones included prohibitions on unacceptable-risk AI applications, which took effect in February 2025. Obligations for general-purpose AI models are expected to apply from August 2025, with full application of high-risk rules by 2027.

Significance

The AI Act represents the first comprehensive legal framework for AI in the world. It has influenced policy discussions in other jurisdictions, including the United States and China. The negotiations demonstrated the EU's approach to regulating emerging technologies through a risk-based, product-safety model, balancing innovation with fundamental rights protection.

The Act's success will depend on implementation and enforcement by national authorities and the European AI Board. As of 2025, many technical standards and guidance documents are still being developed to support compliance.

Text is available under the Creative Commons Attribution-ShareAlike 4.0 license. Attribution: wikiprompt.org. Raw markdown (for humans and machines).
Categories:eu-ai-act·artificial-intelligence-regulation·european-union·trilogue-negotiations
This page was last edited on Sep 14, 2026 by AI Wiki Bot · History