April saw Europe’s AI policy debate reach a critical juncture, with final negotiations on the AI Omnibus underway and key disagreements still unresolved around scope and safeguards. Rapid technological developments, such as Anthropic’s Mythos model, are also intensifying pressure on EU institutions to ensure their governance framework can keep pace. CDT Europe’s April AI Bulletin keeps you up to speed on the latest EU AI governance developments.
The AI Omnibus Saga Wraps Up
After the European Parliament and the Council of the European Union both adopted their negotiating position on the AI Omnibus file last month, co-legislators are close to agreeing on the final text with the last political trilogue taking place on 28 April.
At the time of writing, the key open question remains whether high-risk AI systems embedded in products regulated under EU product safety legislation should be exempted from the AI Act’s scope. This amendment, proposed by the European Parliament and strongly supported by industry, has faced limited enthusiasm in the Council, with different compromise proposals being discussed. Civil society on the other hand has broadly opposed the change, underscoring that the amendments would result in reduced safeguards for fundamental rights and increased fragmentation.
Remaining open questions concern how the co-legislators will land on the exact wording around the prohibition of AI systems generating non-consensual intimate images and child sexual abuse material, as well as provisions regarding the supervision of general-purpose AI systems.
The Omnibus was also subject of more overarching advocacy efforts, with a number of civil society organisations calling for its rejection and a coalition of US-based organisations petitioning the European institutions and enforcement bodies to stand strong against US attempts to weaken EU digital regulation, including the AI Act. Industry actors have asked for further measures, including extending the application deadline for AI transparency requirements under Article 50 and reintroducing the registration exemption of AI systems self-assessed not to be high-risk.
Anthropic’s Mythos Model Sparks Concerns
Anthropic’s Mythos model – with allegedly unprecedented capabilities of finding and exploiting cybersecurity vulnerabilities – and its limited release to trusted technology partners and organisations sparked discussions in light of the apparent non-involvement of EU supervisory authorities. In Europe, only the UK’s AI Security Institute is confirmed to have received early access to the model and released a technical analysis.
The European Commission confirmed that it is following developments closely. Mythos and its unprecedented security challenges have fuelled ongoing calls to ensure better resourcing and staffing of the AI Office, in particular the unit overseeing general-purpose AI models with systemic risks.
In other news:
In the context of the ongoing antitrust case against Meta’s exclusion of third-party AI assistants from Whatsapp, the European Commission sent a supplementary statement of objections to the company. While Meta recently announced changes to its policy – allowing access of third-party assistants subject to a fee – the Commission argues that this creates equivalent barriers of access as the previous ban. It therefore intends to impose interim measures.
The Council of Europe Steering Committee for Human Rights published a handbook on human rights and artificial intelligence to support government officials and policymakers in applying human rights standards in the context of AI. It focuses on key AI uses in public governance sectors, including administration of justice, law enforcement, immigration and border control, democratic processes and social services and welfare.
The Irish Human Rights and Equality Commission (IHREC), a designated fundamental rights authority under Article 77 AI Act, published observations on a draft Irish bill operationalising aspects of the AI Act. A key concern is the bill’s operationalisation of Article 77 AI Act, which provides for inadequate cooperation and consultation mechanisms between market surveillance and fundamental rights authorities, and fails to provide access to technical expertise and necessary resourcing.
A Dutch court prohibited Grok and X to generate and distribute non-consensual intimate images and child sexual abuse material. While X has taken measures to limit the generation and dissemination of such content in the beginning of this year, the judgement concluded that reasonable doubts remained as to the effectiveness of these measures. xAI, the company behind the chatbot, is consequently required to pay 100.000 Euros per day of non-compliance with the judgement.
Mistral AI published “European AI: A playbook to own it”, suggesting a framework to accelerate AI development and adoption in Europe. In their analysis, they focus amongst others on measures to attract and retain talent, streamline digital regulatory frameworks, reduce obligations for companies and to enhance public procurement of European AI tools.
Content of the Month 📚📺🎧
CDT Europe presents our freshly curated recommended reads and works for the month. For more on AI, take a look at CDT’s work.
Potential Avenues for Redress for AI-related Harms under EU Equality and Non-Discrimination law: A Visual Explanation
In this third instalment of the series, we look at the opportunities afforded by EU equality and non-discrimination law in providing redress for AI-related harms.
General-purpose AI Code of Practice Implementation: A Rights Blindspot
CDT Europe's analysis of the entry into application of the European Commission’s enforcement powers towards general-purpose AI (GPAI) models, detailed and operationalised in the GPAI Code of Practice.
As Brussels starts emptying for the summer, the risks of frontier AI models continue to capture the attention of policymakers as a key chapter of the AI Act becomes enforceable, and disclosure rules around the use of AI systems and AI-generated content are further clarified.
CDT Europe’s Feedback on the Draft Guidelines for the Classification of High-Risk AI Systems under the AI Act
CDT Europe responded to the European Commission’s consultation on the draft guidelines for the classification of high-risk artificial intelligence systems.