Changes between two versions
What changed between the plenary report and the adopted text
From · plenary report· 22 May 2023
on the proposal for a regulation of the European Parliament and of the Council on laying down harmonised rules on Artificial Intelligence (Artificial Intelligence Act) and amending certain Union Legislative Acts
+5 added · −28 removed · 105 changed paragraphs, packaging included.
Part 4 of 15: Paragraphs 181–240
Change 71
Changed:Article 2 – paragraph 5 b (new): 5 b.5b. This Regulation is without prejudice to the rules laid down by other Union legal acts related to consumer protection and product safety;
Change 72
Changed:Article 2 – paragraph 5 c (new): 5 c.5c. This regulation shall not preclude Member States or the Union from maintaining or introducing laws, regulations or administrative provisions which are more favourable to workers in terms of protecting their rights in respect of the use of AI systems by employers, or to encourage or allow the application of collective agreements which are more favourable to workers.
Change 73
Changed:Article 2 – paragraph 5 d (new): 5 d.5d. This Regulation shall not apply to research, testing and development activities regarding an AI system prior to this system being placed on the market or put into service, provided that these activities are conducted respecting fundamental rights and the applicable Union law. The testing in real world conditions shall not be covered by this exemption.The Commission is empowered to may adopt delegated acts in accordance with Article 73 that clarify the application of this paragraph to specify this exemption to prevent its existing and potential abuse. The AI Office shall provide guidance on the governance of research and development pursuant to Article 56, also aiming to coordinate its application by the national supervisory authorities;
Change 74
Changed:Article 2 – paragraph 5 e (new): 5 e.5e. This Regulation shall not apply to AI components provided under free and open-source licences except to the extent they are placed on the market or put into service by a provider as part of a high-risk AI system or of an AI system that falls under Title II or IV. This exemption shall not apply to foundation models as defined in Art 3.
Article 3 – paragraph 1 – point 1: (1) ‘‘artificial intelligence system’ (AI system) means a machine-based system that is designed to operate with varying levels of autonomy and that can, for explicit or implicit objectives, generate outputs such as predictions, recommendations, or decisions, that influence physical or virtual environments;
Change 75
Changed:Article 3 – paragraph 1 – point 1 a (new): (1 a)(1a) ‘risk’ means the combination of the probability of an occurrence of harm and the severity of that harm;
Change 76
Changed:Article 3 – paragraph 1 – point 1 b (new): (1 b)(1b) ‘significant risk’ means a risk that is significant as a result of the combination of its severity, intensity, probability of occurrence, and duration of its effects, and its the ability to affect an individual, a plurality of persons or to affect a particular group of persons;
Change 77
Changed:Article 3 – paragraph 1 – point 1 c (new): (1 c)(1c) ‘foundation model’ means an AI system model that is trained on broad data at scale, is designed for generality of output, and can be adapted to a wide range of distinctive tasks;
Change 78
Changed:Article 3 – paragraph 1 – point 1 d (new): (1 d)(1d) ‘general purpose AI system’ means an AI system that can be used in and adapted to a wide range of applications for which it was not intentionally and specifically designed;
Change 79
Changed:Article 3 – paragraph 1 – point 1 e (new): (1 e)(1e) ‘large training runs’ means the production process of a powerful AI model that require computing resources above a very high threshold;
Article 3 – paragraph 1 – point 3: deleted / (deleted)
Article 3 – paragraph 1 – point 4: (4) ‘deployer means any natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity;
Article 3 – paragraph 1 – point 8: (8) ‘operator’ means the provider, the deployer, the authorised representative, the importer and the distributor;
Change 80
Changed:Article 3 – paragraph 1 – point 8 a (new): (8 a)(8a) ‘affected person’ means any natural person or group of persons who are subject to or otherwise affected by an AI system;
Article 3 – paragraph 1 – point 11: (11) ‘putting into service’ means the supply of an AI system for first use directly to the deployer or for own use on the Union market for its intended purpose;
Article 3 – paragraph 1 – point 13: (13) ‘reasonably foreseeable misuse’ means the use of an AI system in a way that is not in accordance with its intended purpose as indicated in instructions for use established by the provider, but which may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems;
Change 81
Changed:Article 3 – paragraph 1 – point 14: (14) ‘‘safety‘safety component of a product or system’ means, in line with Union harmonisation law listed in Annex II, a component of a product or of a system which fulfils a safety function for that product or system, or the failure or malfunctioning of which endangers the health and safety of persons;
9 unchanged paragraphs
Article 3 – paragraph 1 – point 15: (15) ‘instructions for use’ means the information provided by the provider to inform the deployer of in particular an AI system’s intended purpose and proper use, as well as information on any precautions to be taken; inclusive of the specific geographical, behavioural or functional setting within which the high-risk AI system is intended to be used;
Article 3 – paragraph 1 – point 16: (16) ‘recall of an AI system’ means any measure aimed at achieving the return to the provider of an AI system that has been made available to deployers;
Article 3 – paragraph 1 – point 20: (20) ‘conformity assessment’ means the process of demonstrating whether the requirements set out in Title III, Chapter 2 of this Regulation relating to an AI system have been fulfilled;
Article 3 – paragraph 1 – point 22: (22) ‘notified body’ means a conformity assessment body notified in accordance with this Regulation and other relevant Union harmonisation legislation;
Article 3 – paragraph 1 – point 23: (23) ‘substantial modification’ means a modification or a series of modifications of the AI system after its placing on the market or putting into service which is not foreseen or planned in the initial risk assessment by the provider and as a result of which the compliance of the AI system with the requirements set out in Title III, Chapter 2 of this Regulation is affected or results in a modification to the intended purpose for which the AI system has been assessed;
Article 3 – paragraph 1 – point 24: (24) ‘CE marking of conformity’ (CE marking) means a physical or digital marking by which a provider indicates that an AI system or a product with an embedded AI system is in conformity with the requirements set out in Title III, Chapter 2 of this Regulation and other applicable Union legislation harmonising the conditions for the marketing of products (‘Union harmonisation legislation’) providing for its affixing;
Article 3 – paragraph 1 – point 29: (29) ‘training data’ means data used for training an AI system through fitting its learnable parameters;
Article 3 – paragraph 1 – point 30: (30) ‘validation data’ means data used for providing an evaluation of the trained AI system and for tuning its non-learnable parameters and its learning process, among other things, in order to prevent underfitting or overfitting; whereas the validation dataset is a separate dataset or part of the training dataset, either as a fixed or variable split;
Article 3 – paragraph 1 – point 33: (33) ‘biometric data’ means biometric data as defined in Article 4, point (14) of Regulation (EU) 2016/679;
Change 82
Changed:Article 3 – paragraph 1 – point 33 a (new): (33 a)(33a) ‘biometric-based data’ means data resulting from specific technical processing relating to physical, physiological or behavioural signals of a natural person;
Change 83
Changed:Article 3 – paragraph 1 – point 33 b (new): (33 b)(33b) ‘biometric identification’ means the automated recognition of physical, physiological, behavioural, and psychological human features for the purpose of establishing an individual’s identity by comparing biometric data of that individual to stored biometric data of individuals in a database (one-to-many identification);
Change 84
Changed:Article 3 – paragraph 1 – point 33 c (new): (33 c)(33c) ‘biometric verification’ means the automated verification of the identity of natural persons by comparing biometric data of an individual to previously provided biometric data (one-to-one verification, including authentication);
Change 85
Changed:Article 3 – paragraph 1 – point 33 d (new): (33 d)(33d) ‘special categories of personal data’ means the categories of personal data referred to in Article 9(1) of Regulation (EU)2016/679;
8 unchanged paragraphs
Article 3 – paragraph 1 – point 34: (34) ‘emotion recognition system’ means an AI system for the purpose of identifying or inferring emotions, thoughts, states of mind or intentions of individuals or groups on the basis of their biometric and biometric-based data;
Article 3 – paragraph 1 – point 35: (35) ‘biometric categorisation means assigning natural persons to specific categories, or inferring their characteristics and attributes on the basis of their biometric or biometric-based data, or which can be inferred from such data;
Article 3 – paragraph 1 – point 36: (36) ‘remote biometric identification system’ means an AI system for the purpose of identifying natural persons at a distance through the comparison of a person’s biometric data with the biometric data contained in a reference database, and without prior knowledge of the deployer of the AI system whether the person will be present and can be identified, excluding verification systems;
Article 3 – paragraph 1 – point 37: (37) ‘‘real-time’ remote biometric identification system’ means a remote biometric identification system whereby the capturing of biometric data, the comparison and the identification all occur without a significant delay. This comprises not only instant identification, but also limited delays in order to avoid circumvention;
Article 3 – paragraph 1 – point 39: (39) ‘publicly accessible space’ means any publicly or privately owned physical place accessible to the public, regardless of whether certain conditions for access may apply, and regardless of the potential capacity restrictions;
Article 3 – paragraph 1 – point 41: (41) ‘law enforcement’ means activities carried out by law enforcement authorities or on their behalf for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security;
Article 3 – paragraph 1 – point 42: (42) ‘national supervisory authority’ means a public (AM 69) authority to which a Member State assigns the responsibility for the implementation and application of this Regulation, for coordinating the activities entrusted to that Member State, for acting as the single contact point for the Commission, and for representing the Member State in the management Board of the AI Office;
Article 3 – paragraph 1 – point 43: (43) ‘national competent authority’ means any of the national authorities which are responsible for the enforcement of this Regulation;
Change 86
Changed:Article 3 – paragraph 1 – point 44 – introductory part: (44) ‘serious incident’ means any incident or malfunctioning of an AI system that directly or indirectly leads, might have led or might lead to any of the following: / (a) the death of a person or serious damage to a person’s health, / (b) a serious disruption of the management and operation of critical infrastructure;infrastructure, / (b a)(ba) a breach of fundamental rights protected under Union law;law, / (b b)(bb) serious damage to property or the environment;environment.
Change 87
Changed:Article 3 – paragraph 1 – point 44 a (new): (44 a)(44a) 'personal data' means personal data as defined in Article 4, point (1) of Regulation (EU)2016/679;
Change 88
Changed:Article 3 – paragraph 1 – point 44 b (new): (44 b)(44b) ‘non-personal data’ means data other than personal data;
Change 89
Changed:Article 3 – paragraph 1 – point 44 c (new): (44 c)(44c) ‘profiling’ means any form of automated processing of personal data as defined in point (4) of Article 4 of Regulation (EU) 2016/679; or in the case of law enforcement authorities – in point 4 of Article 3 of Directive (EU) 2016/680 or, in the case of Union institutions, bodies, offices or agencies, in point 5 Article 3 of Regulation (EU) 2018/1725;
Change 90
Changed:Article 3 – paragraph 1 – point 44 d (new): (44 d)(44d) "deep fake" means manipulated or synthetic audio, image or video content that would falsely appear to be authentic or truthful, and which features depictions of persons appearing to say or do things they did not say or do, produced using AI techniques, including machine learning and deep learning;
Change 91
Changed:Article 3 – paragraph 1 – point 44 e (new): (44 e)(44e) ‘widespread infringement’ means any act or omission contrary to Union law that protects the interest of individuals: / (a) which has harmed or is likely to harm the collective interests of individuals residing in at least two Member States other than the Member State, in which: / (i) the act or omission originated or took place; / (ii) the provider concerned, or, where applicable, its authorised representative is established; or, / (iii) the deployer is established, when the infringement is committed by the deployer; / (b) which protects the interests of individuals, that have caused, cause or are likely to cause harm to the collective interests of individuals and that have common features, including the same unlawful practice, the same interest being infringed and that are occurring concurrently, committed by the same operator, in at least three Member States;
Change 92
Changed:Article 3 – paragraph 1 – point 44 f (new): (44 f)(44f) ‘widespread infringement with a Union dimension’ means a widespread infringement that has harmed or is likely to harm the collective interests of individuals in at least two-thirds of the Member States, accounting, together, for at least two-thirds of the population of the Union;
Change 93
Changed:Article 3 – paragraph 1 – point 44 g (new): (44 g)(44g) ‘regulatory sandbox’ means a controlled environment established by a public authority that facilitates the safe development, testing and validation of innovative AI systems for a limited time before their placement on the market or putting into service pursuant to a specific plan under regulatory supervision;
Change 94
Changed:Article 3 – paragraph 1 – point 44 h (new): (44 h)(44h) ‘critical infrastructure’ means an asset, a facility, equipment, a network or a system, or a part of an asset, a facility, equipment, a network or a system, which is necessary for the provision of an essential service within the meaning of Article 2(4) of Directive (EU) 2022/2557;
Change 95
Changed:Article 3 – paragraph 1 – point 44 k (new): (44 k)(44k) ‘social scoring’ means evaluating or classifying natural persons based on their social behaviour, socio-economic status or known or predicted personal or personality characteristics;
Change 96
Changed:Article 3 – paragraph 1 – point 44 l (new): (44 l)(44l) ‘social behaviour’ means the way a natural person interacts with and influences other natural persons or society;
Change 97
Changed:Article 3 – paragraph 1 – point 44 m (new): (44 m)(44m) ‘state of the art’ means the developed stage of technical capability at a given time as regards products, processes and services, based on the relevant consolidated findings of science, technology and experience;
Change 98
Changed:Article 3 – paragraph 1 – point 44 n (new): (44 n)(44n) ‘testing in real world conditions’ means the temporary testing of an AI system for its intended purpose in real world conditions outside of a laboratory or otherwise simulated environment;
9 unchanged paragraphs
Article 4: deleted / (deleted) / (deleted)
Article 4 a (new): Article 4 a / General principles applicable to all AI systems / 1. All operators falling under this Regulation shall make their best efforts to develop and use AI systems or foundation models in accordance with the following general principles establishing a high-level framework that promotes a coherent human-centric European approach to ethical and trustworthy Artificial Intelligence, which is fully in line with the Charter as well as the values on which the Union is founded: / a) ‘human agency and oversight’ means that AI systems shall be developed and used as a tool that serves people, respects human dignity and personal autonomy, and that is functioning in a way that can be appropriately controlled and overseen by humans; / b) ‘technical robustness and safety’ means that AI systems shall be developed and used in a way to minimize unintended and unexpected harm as well as being robust in case of unintended problems and being resilient against attempts to alter the use or performance of the AI system so as to allow unlawful use by malicious third parties; / c) ‘privacy and data governance’ means that AI systems shall be developed and used in compliance with existing privacy and data protection rules, while processing data that meets high standards in terms of quality and integrity; / d) ‘transparency’ means that AI systems shall be developed and used in a way that allows appropriate traceability and explainability, while making humans aware that they communicate or interact…
Article 4 b (new): Article 4 b / AI literacy / 1. When implementing this Regulation, the Union and the Member States shall promote measures for the development of a sufficient level of AI literacy, across sectors and taking into account the different needs of groups of providers, deployers and affected persons concerned, including through education and training, skilling and reskilling programmes and while ensuring proper gender and age balance, in view of allowing a democratic control of AI systems / 2. Providers and deployers of AI systems shall take measures to ensure a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on which the AI systems are to be used. / 3. Such literacy measures shall consist, in particular, of the teaching of basic notions and skills about AI systems and their functioning, including the different types of products and uses, their risks and benefits. / 4. A sufficient level of AI literacy is one that contributes, as necessary, to the ability of providers and deployers to ensure compliance and enforcement of this Regulation.
Article 5 – paragraph 1 – point a: (a) the placing on the market, putting into service or use of an AI system that deploys subliminal techniques beyond a person’s consciousness or purposefully manipulative or deceptive techniques, with the objective to or the effect of materially distorting a person’s or a group of persons’ behaviour by appreciably impairing the person’s ability to make an informed decision, thereby causing the person to take a decision that that person would not have otherwise taken in a manner that causes or is likely to cause that person, another person or group of persons significant harm; / The prohibition of AI system that deploys subliminal techniques referred to in the first sub-paragraph shall not apply to AI systems intended to be used for approved therapeutical purposes on the basis of specific informed consent of the individuals that are exposed to them or, where applicable, of their legal guardian;
Article 5 – paragraph 1 – point b: (b) the placing on the market, putting into service or use of an AI system that exploits any of the vulnerabilities of a person or a specific group of persons, including characteristics of such person’s or a such group’s known or predicted personality traits or social or economic situation age, physical or mental ability with the objective or to the effect of materially distorting the behaviour of that person or a person pertaining to that group in a manner that causes or is likely to cause that person or another person significant harm;;
Article 5 – paragraph 1 – point b a (new): (b a) the placing on the market, putting into service or use of biometric categorisation systems that categorise natural persons according to sensitive or protected attributes or characteristics or based on the inference of those attributes or characteristics. This prohibition shall not apply to AI systems intended to be used for approved therapeutical purposes on the basis of specific informed consent of the individuals that are exposed to them or, where applicable, of their legal guardian.
Article 5 – paragraph 1 – point c – introductory part: (c) the placing on the market, putting into service or use of AI systems for the social scoring evaluation or classification of natural persons or groups thereof over a certain period of time based on their social behaviour or known, inferred or predicted personal or personality characteristics, with the social score leading to either or both of the following:
Article 5 – paragraph 1 – point c – point i: (i) detrimental or unfavourable treatment of certain natural persons or whole groups thereof in social contexts that are unrelated to the contexts in which the data was originally generated or collected;
Article 5 – paragraph 1 – point d – introductory part: (d) the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces;