Definition
- EU AI Act (in force August 2024, roll-out until August 2026): regulates applications by risk. Prohibited: real-time biometric surveillance in public, government social scoring, subliminal manipulation, exploiting vulnerable groups. High risk: medical devices, critical infrastructure, autonomous vehicles, credit scoring, recruitment, education, law enforcement, border control. Limited: chatbots, deepfakes. Minimal: recommenders, spam filters, games.
- GDPR (since May 2018): lawful basis for processing personal data, explicit consent for special categories, data minimization, purpose limitation, right to be forgotten.
- Copyright: training data needs a legal basis; no copyright without human authorship; AI cannot be an inventor.
Formula
High-risk obligations: risk management, data governance, documentation and logging, transparency, human oversight. General-purpose AI with systemic risk: training compute FLOPs.
Law sets principles, not technical specifications; key terms like “transparent” are refined by courts and regulators. Erasing data from trained weights is the research problem of machine unlearning.
Appears in
- Lecture 9.2, why regulate
- Lecture 9.2, EU AI Act, risk category quiz
- Lecture 9.2, GDPR, copyright
- Lecture 7, privacy and copyright of data