CDT Europe welcomes the Code of Practice’s inclusion of fundamental rights risks in the systemic risk taxonomy considering that earlier versions of the Code failed to meaningfully integrate consideration of fundamental rights risks, despite extensive rounds of feedback and civil society warnings. This brings the Code into alignment with the AI Act after earlier versions followed a two-tier approach where assessment of most fundamental rights risks remained optional for the riskier general-purpose AI models.
The Code of Practice’s mandatory requirement for providers of general-purpose AI models with systemic risk to consider risks to safety, public security, health, fundamental rights and society at least at a high-level as part of their risk management approach is decidedly a step forward. However, while the exploration of these risks is compulsory, active identification and assessment of these risks is still left to the discretion of providers.
“The reality is that the two-tier approach remains: there is a clear distinction between mandatory and non-mandatory risks to assess, and the open-ended identification of risks still relies on the good faith and good will of providers. For these risks, whether they are assessed or omitted from consideration altogether will be the providers’ decision to make”, said Counsel and Programme Director for Equity and Data Laura Lazaro Cabrera.
“The incentive for providers to robustly identify these risks will only be as strong as the AI Office’s commitment to enforce a comprehensive, good-faith approach”.
The final Code of Practice imposes a significantly lesser burden on providers to meaningfully exchange with external stakeholders: while mandatory external assessments remain, requirements to engage external experts, civil society and downstream actors have been stripped back and replaced with a general principle of cooperation.
“The Code of Practice is a first-of-its-kind, ambitious step forward in the governance of GPAI models, but ultimately is only the beginning of the regulatory conversation, with European standards to follow. The Code’s potential will only be fulfilled in practice through ongoing multistakeholder dialogue, knowledge-sharing and exchange of best practices to ensure meaningful risk assessments and effective mitigations for these complex and evolving societal impacts. We look forward to contributing to such solution-oriented efforts.”
General-purpose AI Code of Practice Implementation: A Rights Blindspot
CDT Europe's analysis of the entry into application of the European Commission’s enforcement powers towards general-purpose AI (GPAI) models, detailed and operationalised in the GPAI Code of Practice.
As Brussels starts emptying for the summer, the risks of frontier AI models continue to capture the attention of policymakers as a key chapter of the AI Act becomes enforceable, and disclosure rules around the use of AI systems and AI-generated content are further clarified.
CDT Europe’s Feedback on the Draft Guidelines for the Classification of High-Risk AI Systems under the AI Act
CDT Europe responded to the European Commission’s consultation on the draft guidelines for the classification of high-risk artificial intelligence systems.
After various months of delays in the AI Act implementation, June saw major milestones in the constitution of oversight bodies and publication of guidance, as well as the publication of the European Union’s long-awaited tech sovereignty strategy.