This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.
The Lens

Digital developments in focus

| 3 minute read

AI momentum shows no sign of slowing: recent regulatory developments in the EU and UK

We know the AI regulatory landscape is evolving, but the last few weeks have seen policymakers and regulators in both the EU and UK announce a range of developments which illustrate the pace of this change. 

In the EU, the staged implementation of the AI Act continues, albeit with an amended version of the Act now that the AI Omnibus has entered into force:

  • AI Omnibus package entered into force on 27 July: As part of the EU’s digital simplification package, the AI Omnibus makes a number of changes to the AI Act – these include:
    • Grace period for marking rules:  The omnibus delays certain transparency rules, granting providers with AI systems on the market before 2 August 2026 a four month transitional period to comply with their marking obligations - effectively delaying their application to those systems until 2 December 2026.
       
    • Delays and scope reduction for high-risk rules: The high-risk rules have also been delayed, with Annex 3 high-risk rules (AI use in employment, credit scoring etc.) now applying from 2 December 2027 and Annex 1 rules (AI embedded in physical products like toys and lifts) from 2 August 2028. The grandfathering rules, which take high-risk AI systems out of scope if they are already on the market, unless significant changes are made in their designs, remain - the omnibus changes just clarify that the new application dates will apply here too. 
      Changes to the high-risk rules also limit the scope of those rules, for example by taking the AI Systems in products governed by the Machine Regulations out of direct scope of many of the Act's substantive obligations, and clarify how the AI Act works with relevant sector rules (for example when it comes to the procedures for conformity assessment bodies). 
       
    • Strengthening safety and fundamental rights: Following public and political concerns around nudification apps (systems that generate non-consensual sexually explicit and intimate content or CSAM) these have been banned.
      The omnibus changes also allow certain processing of sensitive personal data for bias detection and correction.
       
    • Simplification: The AI literacy requirements have been simplified and changed to a process rather than output obligation, with organisations now only having to “take measures to support the development of AI literacy” and the Commission and Member States having to support and facilitate these efforts.
      The rules relating to registering exempted AI systems in the EU central database have also been streamlined, and certain of the simplified legal obligations SMEs had benefited from under the Act have been extended to small and mid-cap companies.
       
    • Extended enforcement powers for the AI Office: The AI Office will now oversee enforcement for a larger number of AI systems, subject to some exemptions. These include those systems built on general-purpose AI models where the model and system provider come from the same undertaking. It also includes those systems embedded in large online platforms and search engines (VLOPs and VLOSs under the DSA). 
      See our blog and this Commission article on the Omnibus for more information.
       
  • AI Act generally applicable from 2 August: While the Omnibus may have delayed some rules, others take effect this Sunday. The Act applies generally from 2 August, meaning key provisions including the enforcement rules and transparency rules (subject to the above) will apply from this date. To help compliance with these new transparency rules, the EU also finally published guidelines on the Transparency of AI generated content (see our blog) to accompany the Transparency Code of Practice they published back in June.
     
  • EDPB guidelines: The Act is, however, not the only noteworthy EU development. The European Data Protection Board recently published new draft guidelines on web scraping - one of the most contentious data collection practices underpinning generative AI - confirming that it does fall within the GDPR's scope whenever personal data is collected. See our blog for more information on the guidelines.  

 The UK has been equally busy, with both political and regulatory developments announced. In particular, changes to government leadership and departmental responsibilities have raised questions about the future direction of UK AI policy and regulation. New prime minister Andy Burnham has appointed a Minister for AI, set up an AI Taskforce and signalled an intention to place AI at the centre of economic and public service agenda.  However, concerns have been voiced from some in the tech sector that his dismantling of the Government’s tech department DSIT could lead to a loss of focus and governmental expertise in this space. From a legal perspective, we will be watching closely to understand how these political changes impact UK AI regulation, and in particular whether proposals previously discussed under the former government, including the possibility of some kind of UK AI-specific legislation, remain on the agenda.

Sign up to receive the latest insights. Click here to subscribe to The Lens Blog.

Tags

ai, digital regulation