Latest / AI Ethics with Fexingo: Bias, Safety, and Responsible Artificial Intelligence / How the EU AI Act Could Reshape Global Tech Regulation
Transcript
- Lucas: So, the European Union is about to pass what is arguably the world's most ambitious attempt to regulate artificial intelligence — the EU AI Act. It's been in the works since 2021, and if it goes through as expected later this year, it could reshape how every major tech company builds and deploys AI. Luna: I've seen the headlines calling it the 'GDPR for AI.' Is that a fair comparison? Lucas: It's the comparison the EU itself wants you to make. GDPR, the General Data Protection Regulation, passed in 2016 and became the global benchmark for data privacy — the so-called 'Brussels Effect.' Companies like Apple and Microsoft ultimately adopted gdpr style practices worldwide because it was cheaper than maintaining separate standards. The hope is the AI Act does the same thing. Luna: But GDPR has its critics. Compliance costs billions, and a lot of small companies still struggle. Lucas: Absolutely. And that's the tension the AI Act inherits. The Act categorises AI systems into four risk levels: unacceptable, high, limited, and minimal. Unacceptable risk is banned outright — things like social scoring by governments, or real-time biometric surveillance in public spaces. High-risk systems face strict obligations: conformity assessments, human oversight, transparency documentation. Limited risk just requires disclosure — like telling you you're chatting with a bot. Minimal risk, no obligations. Luna: So what counts as high risk? That seems like the crucial line. Lucas: It is. High risk covers AI used in critical infrastructure, education, employment, access to essential services, law enforcement, migration, and the justice system. So if a bank uses AI to decide who gets a loan, or a hospital uses AI to triage patients — those are high risk. The provider has to register the system in an EU database, ensure it's trained on representative data, and enable human review of decisions. Luna: That's a direct hit on a lot of the algorithms we've talked about in previous episodes — hiring tools, medical algorithms, predictive policing. Lucas: Exactly. The COMPAS recidivism algorithm we covered in episode one would almost certainly qualify as high risk. So would the biased hiring tools from episode two. The Act doesn't just set rules; it creates liability. If a high-risk system causes harm, the provider can face fines up to thirty-five million euros or seven percent of global annual revenue — whichever is higher. Luna: That's steeper than GDPR's maximum of four percent of global revenue. That gets a company's attention. Lucas: It is designed to. But here's where it gets interesting: the Act also covers what are called 'general-purpose AI systems' — foundation models like GPT-4, Gemini, or Claude. These were not in the original draft. They were added after ChatGPT exploded in late 2022. And they're subject to a different, lighter set of rules focused on transparency and copyright. Luna: That was a huge lobbying battle. I remember OpenAI and Google pushing hard for that carve-out. Lucas: They did. The final compromise requires foundation models to publish summaries of their training data and respect opt-outs for copyrighted material. But they don't need to undergo a full conformity assessment unless they present 'systemic risk' — a threshold that basically only catches the largest models. Luna: Critics say that leaves a dangerous gap. A foundation model could be misused in a thousand ways that the downstream developer — not the model creator — is responsible for. Lucas: That's the debate in a nutshell. The Act puts most of the compliance burden on the company that deploys the AI, not the company that builds the model. So if a startup fine-tunes GPT-4 to screen job applicants, the startup is on the hook for making sure it's non-discriminatory, not OpenAI. OpenAI just has to hand over a data summary. Luna: Which is a much lighter lift for them. But for a small startup, that compliance cost could be prohibitive. Lucas: Yes, and that's a real concern. The EU estimates compliance costs for a high-risk system between six thousand and fifty thousand euros. For a small company, that's nontrivial. Plus you might need a human-in-the-loop — an actual person reviewing every automated decision — which doesn't scale easily. Luna: Let's talk about the bans. Real-time biometric surveillance in public spaces is banned. But there's a loophole for law enforcement with judicial authorisation, right? Lucas: There is. The original draft had a near-total ban on facial recognition in public. The final version carves out exceptions for 'targeted searches' of victims of crime, prevention of imminent terrorist threats, and prosecution of serious crimes. And even then, it requires a court order. Civil liberties groups say that's still too broad — they'd prefer an outright ban. Luna: It's a compromise that leaves a lot of discretion to national governments. Some countries — like Hungary or Poland — might interpret 'imminent threat' quite loosely. Lucas: Exactly. Enforcement is going to vary wildly across member states. The Act creates a new European Artificial Intelligence Board to coordinate oversight, but day-to-day enforcement falls to national authorities. And some countries have very different attitudes toward surveillance. Luna: Before we go further — I wanted to mention something that keeps this show going. A handful of listeners chip in monthly through buy me a coffee dot com slash fexingo, and that is literally what funds these conversations. Just a sincere thank you if you're one of them. Lucas: Yeah, it makes a real difference. We don't run ads — that's a deliberate choice. If you want to support that, buy me a coffee dot com slash fexingo is the place. And if today was worth a coffee, that's the link. Luna: Absolutely. Okay, back to the Act. One thing I find fascinating is the concept of 'regulatory sandboxes.' Can you explain that? Lucas: Sure. The Act encourages member states to set up controlled testing environments where companies can develop and train AI systems under regulatory supervision — with reduced penalties if something goes wrong. The idea is to foster innovation while still having oversight. Finland and Spain have already piloted similar schemes. Luna: That seems like a smart middle ground. You don't want to stifle AI development entirely, but you want guardrails. Lucas: Right. And the Act includes provisions for small and medium enterprises specifically — reduced fees for conformity assessments, guidance documents, priority access to sandboxes. The EU is aware that overregulation could hand the AI race to the US and China. Luna: Speaking of global competition — will the AI Act actually have a Brussels Effect like GDPR did? Lucas: That's the billion-dollar question. GDPR influenced privacy laws in Brazil, Japan, South Korea, and California. But AI is different. The US and China are moving fast — the US has no comprehensive federal AI law, just executive orders and voluntary frameworks. China passed its own AI regulation in 2023 that focuses on content control and algorithmic transparency, but it's very different in philosophy. Luna: So the EU is essentially saying: if you want to sell to four hundred fifty million wealthy consumers, you play by our rules. That's a strong incentive. Lucas: It is. And we're already seeing it. Microsoft, Google, and OpenAI have all published position papers supporting some form of regulation — they'd rather have one clear standard than a patchwork of fifty state laws in the US or different rules across Europe. So they're likely to adopt AI Act principles globally for consistency. Luna: But there's a flip side. Some argue the Act is so complex that it will primarily benefit big tech, who have the legal teams to navigate it, while locking out European startups. Lucas: That's a legitimate critique. The Act is eight hundred pages long. Understanding it requires hiring lawyers and consultants. A two-person startup in Berlin can't do that easily. And if the compliance burden drives them to the US or Asia, Europe loses its AI talent. Luna: There's also the question of enforcement capacity. The European Commission is hiring about a hundred and fifty AI specialists for a new office. But compared to the scale of AI deployment — it's tiny. Lucas: Yeah, it's a drop in the bucket. GDPR enforcement has been slow and inconsistent — the biggest fines took years. The AI Act could face similar delays. And because AI evolves so fast, by the time a violation is proven, the technology might have moved on. Luna: Do you think the Act is, on balance, a good thing? Lucas: I think it's a necessary first step. It establishes the principle that AI can be regulated, that rights matter, that companies can't just deploy black-box systems without accountability. The specific rules will need refinement — and fast — but having a legal framework is better than the Wild West. The question is whether it can adapt quickly enough. Luna: The Act includes a provision for regular reviews — I think every two years for high-risk classifications. So there is a mechanism for updates. Lucas: That's key. And the EU has shown it can move fast when it wants to — the addition of foundation model rules happened in less than a year. So there's reason for cautious optimism. But ultimately, the success of the AI Act will depend on whether it protects people without strangling innovation. That balance is incredibly hard to strike. Luna: And it will set a precedent for every other country writing AI laws right now. So the world is watching. Lucas: They are. And that's why this moment matters. The AI Act won't be perfect, but it's the most serious attempt yet to answer a question we've been grappling with since episode one: how do we build powerful technology without sacrificing our values? Luna: That's the question that runs through every conversation on this show. Thanks for being here. Lucas: Thanks, Luna. And thanks to everyone listening. We'll be back next week with another angle on responsible AI.