The EU AI Act
The European Union's risk-based AI law, which entered into force on 1 August 2024 after Parliament's vote that March; it bans some uses outright, regulates high-risk applications, and, after ChatGPT, added duties for the makers of general-purpose models.
What it was
Regulation (EU) 2024/1689, the Artificial Intelligence Act, sorts AI systems by risk. Some practices are banned, including social scoring, untargeted scraping of facial images to build recognition databases, and emotion recognition in workplaces and schools. Systems used in areas such as hiring, education, critical infrastructure and law enforcement are "high-risk" and must meet requirements for risk management, logging, transparency and human oversight. Providers of general-purpose AI models must publish summaries of their training data and comply with EU copyright law, and models trained with more than 10^25 floating-point operations are presumed to pose "systemic risk," which brings evaluation, incident-reporting and cybersecurity duties.
This entry is dated to 1 August 2024, when the regulation entered into force and became law; that is the date from which every later deadline runs. The political landmark came earlier: on 13 March 2024 the European Parliament approved the text by 523 votes to 46, with 49 abstentions; after the Council's approval the regulation was signed on 13 June 2024 and published in the Official Journal on 12 July. The rules apply in stages: the bans from February 2025, the general-purpose model obligations from August 2025, and most other provisions from August 2026.
What it changed
The Commission first proposed the Act in April 2021, organised around how AI systems are used. After ChatGPT, the European Parliament's June 2023 position added obligations for the foundation models underneath, and the final months of negotiation turned on that addition. In November 2023 France, Germany and Italy circulated a joint paper, reported by Reuters, backing "mandatory self-regulation through codes of conduct" for foundation models instead of binding rules. An open letter that week signed by researchers including Geoffrey Hinton warned that self-regulation was "likely to dramatically fall short of the standards required for foundation model safety." The final text kept binding duties for general-purpose models, with the heaviest reserved for those above the compute threshold.
The law's general-purpose provisions were then filled in by a voluntary code of practice, published in July 2025. OpenAI said it would sign. Meta refused; its global affairs chief Joel Kaplan wrote on 18 July 2025 that "this over-reach will throttle the development and deployment of frontier AI models in Europe, and stunt European companies looking to build businesses on top of them."
The arguments it moved
Who should set the rules for AI?
The AI Act applies rules to general-purpose models, not only to harmful applications, and uses a training-compute threshold to decide which models carry the heaviest duties. The November 2023 fight showed the same division that later split California over SB 1047. The French, German and Italian paper argued, in Reuters' summary, that the intrinsic risks lie in how AI is applied rather than in the technology, the position Andrew Ng holds; Hinton and other researchers argued that self-regulation would fall short. Governor Newsom's September 2024 veto of SB 1047 cited the same question the EU had settled the other way, whether a threshold based on training compute is the right trigger for regulation.
Who should have access to powerful models?
Developers of open-weight models opposed parts of the Act both during negotiation and after it became law. Reuters reported in December 2023 that Mistral, which releases open-weight models, and Germany's Aleph Alpha had criticised the tiered approach to foundation models and won support from their governments. In July 2025 Meta, whose Llama models are released with open weights, declined to sign the code of practice that implements the Act's general-purpose model duties.
Positions it bears on
-
Geoffrey Hinton, Regulation of frontier AI
Argues that market incentives will not produce safe AI and that only government regulation can force companies to spend more on safety; supported California's SB 1047 and has pressed the US Congress to act.
Hinton signed the November 2023 open letter urging EU governments to keep binding rules for foundation models rather than self-regulation.
-
Andrew Ng, Regulation
Regulate harmful applications, not general-purpose models. He opposed California's SB 1047, supports rules against specific harms such as non-consensual deepfakes, and argues that licensing or liability at the model level entrenches incumbents and suppresses open source.
Ng's argument that regulators should target applications rather than general-purpose models is the position France, Germany and Italy took in November 2023 and the Act rejected for the largest models.
Sources
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal of the European Union, 12 July 2024 (EUR-Lex)
- AI Act enters into force, European Commission, 1 August 2024
- Artificial Intelligence Act: MEPs adopt landmark law, European Parliament, 13 March 2024 (Internet Archive copy)
- MEPs ready to negotiate first-ever rules for safe and transparent AI, European Parliament, 14 June 2023 (Internet Archive copy)
- Germany, France, and Italy reach consensus on AI Act with mandatory self-regulation, Digital Watch Observatory, November 2023
- Sources, Generative AI a stumbling block in EU legislation talks (Reuters, via Malay Mail), 1 December 2023 (Internet Archive copy)
- Meta says it won't sign Europe AI agreement, calling it an overreach that will stunt growth, CNBC, 18 July 2025
- California Governor's veto message on SB 1047, 29 September 2024