MCF horizons Podcast Series Ep.2: AI Act Summer: Guidelines, Deadlines and What’s Next

In this episode of MCF horizons, Doug McMahon and Isobel Murphy take stock of a pivotal summer for the EU AI Act.

Their discussion ranges from the Digital Omnibus amendments and the Article 50 transparency deadline to Ireland's new domestic AI oversight framework. They break down what's changed, what's now in force, and where enforcement is heading, offering practical insights for organisations navigating this fast-moving regulatory landscape.

 

Audio Transcript

Transcript available to view here, or in full below.

[00:00 – 00:28]

Welcome to MCF horizons, McCann FitzGerald’s podcast series where we explore the legal and market developments, trends and policy milestones that are shaping today's landscape.  Through conversations with our lawyers, we share practical, forward-looking insights to help organisations navigate change and make informed decisions. Now let's turn to today's episode.

Hi everyone. My name is Isobel Murphy and I'm an Associate in the Technology and Innovation Group in McCann FitzGerald.

[00:28 – 00:53]

I'm joined here today by my colleague Doug McMahon, who's a Partner in the Technology and Innovation Group.

Welcome, Doug.

Thanks, Isobel.

So today we're taking stock of where the AI Act stands because it has moved very quickly from law on paper to law in practice over the past couple of weeks. We have a lot to cover, but we might start with the Digital Omnibus on AI, which is the EU legislative package which amended the AI Act.

[00:53 – 01:15]

Doug, noting that the Omnibus came into effect at the end of July, what are the key changes that organisations should be paying most attention to?

There's a few things in the Omnibus that that are worth noting. It's interesting that the Omnibus was set out to be as part of the overall Digital Omnibus, and so they passed away the AI Act side of things because they needed to very quickly move the compliance dates out for high-risk AI systems.

[01:15 – 01:40]

So the most significant impact of the Digital Omnibus from an AI perspective is probably the moving from the deadline of 2nd of August for high-risk systems to be compliant to the 2nd of December 2027. So it's interesting that actually that hasn't really simplified anything, hasn't changed or just changed the compliance timelines, but that is kind of a really big impact for companies that are trying to grapple with how do we comply with high-risk AI systems’ compliance activities?

[01:40 – 02:05]

They did a few other things as well, which are kind of interesting. One of the ones it did was introduce a new prohibited practice. And this was really driven by the events around Grok and the kind of the rise of these nudification apps, and that has now been banned as a prohibited practice. And I think that's interesting in one sense, because we always knew that the high-risk systems and the prohibited practices which are embedded in the AI Act, were always going to need to be updated over time.

[02:05 – 02:24]

But we have very quickly seen a very quick move to that new change. And then finally, I think the one of the other changes I'd mention would be in relation to AI literacy. So this is one of the obligations that we've known has been in force for a while. And there was a bit of back and forth in the legislative discussions about what changes would be made to this AI literacy requirement.

[02:24– 02:41]

That's the requirement for companies to ensure their staff have sufficient, well was to have sufficient, AI literacy to be able to use AI systems. What's happened there is that originally that was going to be moved so it would actually be an obligation just on Member States. But now it's actually what's done is slightly back to say you must have AI literacy training, but there's no particular standard it has to meet.

[02:41 – 03:09]

So that's one that's I think people hopefully organisations already have AI literacy programmes in place, but they might have to look at them again and think, you know, do we want to make tweaks to this in light of the fact that the obligation has changed slightly?

Very interesting. We might move now to discussing transparency. The 2nd of August deadline for compliance with the Article 50 transparency obligations has now passed, and we've recently seen the European Commission publish final guidelines on Article 50 and also a Code of Practice relating to Article 50.

[03:09 – 03:30]

So Doug, what are the key requirements for operators of AI systems that organisations should be aware of?

So I think with the transparency framework, as with all things with the AI Act, we have to think about the obligations that apply to a provider of an AI system and a deployer. So a provider, the company that creates the AI system and places it on the market, and then the deployer, effectively the company that uses that system.

[03:30 – 03:47]

So if you're a provider of an AI system, the kind of the obligations that have come into place there, the first obligation that comes into force that we need to think about would be interactions with AI systems. So when you have an AI system, most likely a chatbot, but it can be other forms of interaction with AI systems between a natural person and that system.

[03:48 – 04:04]

The provider has to make sure that the person is aware they’re interacting with an AI system, unless it's obvious. So what we have seen is that there's going to be a move from a situation where you may well interact with a chatbot online, and you have a good suspicion this might be an AI chatbot, but actually it's never told you.

[04:04 – 04:24]

Whereas now we're in a world where we should be being told this is an AI chatbot. The other obligation, which hasn't quite come into force yet, it relates to a provider, relates to the generation of synthetic materials. So synthetic audio, video, images.  And there's an obligation there to make it so that you can detect whether or not something is a synthetic AI material via a machine-readable system.

[04:24 – 04:42]

That means that within the file there will be probably metadata which says this was generated by this AI product. And then normally aswell there would be a watermarking system so imperceptible to us as humans, but a machine can see ‘that audio was generated by AI’, or ‘that video was generated by AI’, and the enforcement framework for that isn't quite in place yet.

[04:42 – 05:01]

So that's been delayed for a little bit more until I think it's the 2nd December this year. But that's the key things for providers. And then we move on to deployers, which is providers are a small subset of the AI ecosystem, whereas deployers - people who use these systems - they’re kind of the broader base. They have two obligations that arise in relation to transparency.

[05:01 – 05:21]

The first one is one that doesn't arise that often, but it relates to transparency when you have AI systems doing emotion recognition or then processing biometric data. So there's an obligation to be transparent with natural persons whose personal data is being processed for those purposes. And so we haven't seen exactly how that's going to work in practice, but you have to make sure to make them available, to make them aware of that.

[05:21 – 05:36]

So if you are using those systems that has to be notified. An area where that might come into play sometimes would be if you have a system which is maybe trying to look in a contact centre, and it's trying to assess whether or not a customer is happy with the service or what their emotions are on that call.

[05:36 – 05:53]

That might be an emotion recognition system that might have to be notified. And then finally, there's the obligation if you're a deployer and you're using an AI system that creates synthetic media, which is a deepfake - so effectively that means an AI system is being used to create an image or audio or video, which replicates a real-world scenario -

[05:53 – 06:16]

you have to make sure you are notifying people that's happening, and that's normally going to be with, say, an AI button, but it can be an AI logo, but it could be other ways. And we're kind of waiting to see how people interact with that requirement. And then finally there's the requirement for if you're publishing text and it's for a public interest purpose, if you don't have an editorial step between that text being generated and it being published, then you have to make sure you put that -

[06:16 – 06:36]

- you make sure that people are aware that it was AI-generated text.

Okay. So lots to take in there for both the providers and deployers of AI systems. And we might turn now to Ireland, more specifically the Regulation of AI Act, which has now been signed into law giving Ireland its own domestic framework for AI oversight alongside the EU level rules.

[06:36 – 06:58]

Doug, for organisations that are already grappling with the AI Act, what does the Irish legislation add and where should organisations turn their focus to first?

I think it's interesting to think about what the Regulation of AI Act is trying to do. So it is effectively an implementing piece of legislation. And I think the Irish government was very clear that they weren't looking to gold-plate the AI Act.

[06:58 – 07:19]

They were just trying to make it so that obligations in the Act could then be enforced in the Irish context. So the way it kind of operates and which organisations should be aware of, I suppose, would be it creates a National AI Office, which is this kind of coordinating body, and that acts as the kind of contact point between Ireland and the EU-level AI Office.

[07:19 – 07:38]

And so that's the contact point. And the reason why we have that AI Office is because Ireland's gone for this distributed model of enforcement for the AI Act, which is very unusual, something we haven't seen something before like this. So there's a large number of bodies, sectoral-specific bodies, that have given powers to enforce the AI Act. So if it's relates to processing of personal data, it's the Data Protection Commission.

[07:38 – 07:59]

If you're a broadcaster, it would be Coimisiún na Meán, if you're medicines it might be the Health Product Regulation Authority - that kind of thing. And so what's happened now is that they've all been given powers under the under the AI Act, under the Regulation of AI Act, and they've been given I mean, I suppose if you were thinking an organisation, they've been given the full suite of powers that you would expect a modern regulator to have.

[07:59 – 08:25]

And so they have all the powers they need to be able to go from – and it's kind of a tiered set of powers that go from - compliance notices, investigations, requests for information all the way up to be able to issue the significant fines that the AI Act puts in place. I think for an organisation, one of the things that's going to be interesting, or interesting maybe to practitioners, maybe it'll be more painful for organisations, will be that we're going to have this distributed model so that you might well have, say, if you're a financial services company, the Central Bank of Ireland can be your regulator.

[08:25 – 08:43]

They have a particular way of doing business, and they also have their own administrative sanctions framework, which they're allowed to use in this context. But you may also be processing data, say, of staff, and you may then have as your regulator the Data Protection Commission, because it's processing personal data, and you may have very different experiences of those two regulators and the way they undertake enforcement.

[08:43 – 09:04]

And even when you get into the sanctions regimes, the way they apply them. And historically, we've seen in Ireland, regulators have very different ways of bringing about compliance and different attitudes towards that. So I think we can have a kind of a bit of a bumpy road ahead to see when you have organisations need to identify who their regulator is, then those interactions may have to be tailored to the regulator they're talking to.

[09:04 – 09:17]

The AI Office is meant to try and bring about that coordination of that and trying to smooth out those wrinkles. But I do think there'll be a period of time when we are dealing with different regulators and we have to be kind of light-footed in the sense of, well, this regulator likes to interact in this way, this one another way.

[09:17 – 09:42]

If there’s a joint investigation, what’s that going to be like? It's going to be interesting for practitioners.

That's all very interesting. Thanks, Doug. And we might now move a bit closer to the topic of enforcement. Specifically, general purpose AI model providers have had their obligations enforced for some time, and the European Commission's grace period for enforcement for signatories of the GPAI Code of Practice recently came to an end on the 2nd of August.

[09:42 – 10:08]

How do you envisage GPAI model enforcement and AI Act enforcement more generally will develop from here?

It's interesting. So this is kind of a follow on from the DSA. So we have to maybe take a step back. We had, for the GDPR, this model where you had national regulators in charge of regulating anyone who's in their jurisdiction – this lead supervisory authority concept - which meant that Ireland's Data Protection Commission is the regulator for the big social media companies.

[10:08 – 10:27]

And that's the model for GDPR, but for digital regulation now, we've generally moved away from that. And the Commission has taken a role in enforcement when it's dealing with the very large, significant players. And that's exactly what's happened in the AI Act. So for the GPAI enforcement, that is primarily going to be a European Commission-level AI Office enforcement activity.

[10:27 – 10:48]

And I think if we're thinking about how enforcement is going to pan out at that kind of level, we could probably look a little bit towards the DSA and how that enforcement kind of developed in relation to kind of VLOPs and VLOSEs. And what we saw there was a very quick move towards the issuance of RFIs. I think with the DSA, it was within a couple of months of the coming into force of the DSA

[10:48 – 11:04]

we had the first RFIs only I think it was four months or so before we had the first enforcement proceedings initiated.  That I think was by EU standards, very quick to get to that level. And you often expect to have more of a bedding-in period. In this case, we have had this pause for a year. I think the Commission has had time.

[11:04 – 11:38]

It's been very busy on AI generally and lots of different guidelines and things being developed, but it has had time to decide what its enforcement strategy would be. If I was to take a bet, I think there would be probably a series of RFIs issued relatively quickly in the next couple of months. I think then the investigations might take longer, and it might be that they need to take more time before they decide to move into enforcement activity, just because I think the AI Act is even more complex, and it will be driven by the types of issues that they have and don't think we’ve necessarily seen what their priorities will be there.

[11:38 – 12:01]

But yeah, AI enforcement, I think, will happen in terms of requests for information relatively quickly, maybe a longer period before we see enforcement. And that will contrast, I think, with the domestic regime, where I mentioned previously we have this large number of regulators. They all have different levels of resources, but I think they are all having this additional requirement to regulate AI.

[12:01 – 12:16]

I think it will take them longer, maybe to get to grips with it. And the only thing that will really change that would be if we have some kind of event, which then prompts a requirement. So if there's an egregious breach we might then see that. So when we saw what happened with Grok, now we have this ban.

[12:16 – 12:35]

If something similar happened, I imagine we would see regulators very quickly moving to enforce against that, that kind of thing. But absent an external event prompting enforcement, I think there'll be, I would imagine there'll be, a period of time where we won't really see, you know, huge activity at the domestic level, but maybe the EU level, there will be RFIs, but maybe not enforcement for a little while.

[12:35 – 13:07]

So finally, earlier in the summer the European Commission published guidelines on the classification of high-risk AI systems under Article 6 of the AI Act. And these guidelines aren’t yet finalised, and they're not legally binding, but they are the most authoritative indication of how the Commission and other regulators will approach AI classification under the Act. So Doug what's your read on the direction these Guidelines are taking, and are there any key insights which might be particularly useful for organisations to note?

[13:07 – 13:26]

I mean, maybe the first thing to say is I think they have at least tried to grapple with some of the harder issues that the high-risk classification framework raises in a way that guidelines in other contexts, say the EDPB guidelines are a little bit famous for giving the most softball examples and then leaving the kind of the hard stuff to you to figure out, whereas I think they have tried to engage a bit more substantially with that.

[13:26 – 13:56]

And these are very long guidelines. There are 150 pages. So there's a lot to digest, and there's a lot of useful stuff there.  In terms of the two areas which have been somewhat controversial, or at least the ones where they've commented, the first one will be we have this question of - if you have a general purpose AI model, or even just a capable model which can undertake a broad set of tasks, even if it's not a GPAI in terms of classification, there's been this question of, well, if that could be used for a high-risk activity, does that mean automatically that that AI system is high-risk?

[13:56 – 14:16]

And then the provider of that system has to comply with all the high-risk requirements.  And there had been a kind of, certainly from an industry perspective, there had been a hope that we would have a move where there would be some kind of way, a get-out way, to say actually, as long as you take certain very relatively straightforward steps, you shouldn't be regarded as a provider of a high-risk AI system, even if it could be used by a deployer in certain ways.

[14:16 – 14:42]

And the justification for that was there are provisions under the AI Act, which means you can move from being a deployer to a provider if you use a system for a new purpose, and therefore the idea would be, well, if you're using it for high-risk and it wasn't designed for that specifically, well, then you take those obligations. But actually the Guidelines have taken quite a narrow view on that, and they've said that it wouldn't be sufficient for a provider simply to say, please don't use my model for high-risk purposes, that as a contractual requirement, that wouldn't be enough.

[14:42 – 14:58]

And they've kind of looked at it and said, you know, you have to look at things like, how is the model presented to the market? So even in terms of advertising capabilities. And I think the steps you'd have to take if you have a general-purpose AI model or a very capable AI system that has broad application to try and move yourself away from being a high-risk system,

[14:58 – 15:12]

it looks like those steps can be quite complicated and may not be successful. And I think it's an example of maybe we're going to go back to think about the way the AI Act came about. It was the AI Act high-risk classification framework – the idea for it came about before we had the rise of the LLM models.

[15:12 – 15:32]

So that was in a world where AI systems generally did have a single purpose, or they had relatively limited purposes. And during the course of the legislation being negotiated, LLM, the ChatGPT came out, LLMs rose. And I think this is a fundamental tension in the legislation, which I think maybe we were being overly hopeful to think the Commission could somehow resolve that in the Guidance.

[15:32 – 15:47]

But I think it's going to be an area that's going to continue to be kind of difficult, and it's going to be one there’s going to be kind of developments on to see how is that going to work in practice. And then the other point, which I think is worth highlighting from the Guidelines, is the approach that's taken to what's known as the filter mechanism.

[15:47 – 16:08]

So this is under Article 6(3) where we have this provision where even if you meet the requirements for an AI system to be classified as high-risk under Annex III, if it doesn't create high-risk to natural persons, you can then avail of basically an exception - your only real obligation is to register that system and you don't have to comply with the rest of the obligations.

[16:09 – 16:25]

The thing that came about there is that the way that provision is drafted, it has the kind of general principle that there should be an exception if it doesn't create high risks. And then there are what you could either read as being four examples of times in which those systems might be able to be classified as not being high-risk.

[16:25 – 16:42]

So, for example, the first one is if it performs a narrow procedural task.  There are those four what I think a lot of people reading these examples, but actually the Commission's interpretation of the provision is difficult - it’s not brilliantly drafted and it's difficult to say what the correct interpretation is, but they've said that, you know, those are the only four examples you can possibly rely on.

[16:42 – 16:59]

So it isn't a general question: could you say this isn't creating high risk? You actually have to say do I fall within one of these four examples. The only thing that it maybe helpfully clarifies, which I think was already fairly clear, is they're not cumulative. So if you fall in one or the other, then you get there. So that's again an area where there could be push back.

[16:59 – 17:17]

It will be interesting to see if there's movement in the draft Guidelines. Historically, we haven't generally seen kind of large shifts in position under guidelines from consultation to finalisation. But maybe there'll be more there you might see.

We'll have to wait and see. So as we wrap up, Doug, if we had to leave our listeners with one key takeaway from everything we've discussed today, what would that be?

[17:18 – 17:36]

Well, I think people probably have started to notice they're interacting with more AI chatbots than they were perhaps realised they were. And that's because these obligations around transparency about interacting with AI systems have come into force. So I think in terms of a takeaway, if I was an organisation, I'd be looking at that and thinking, well, if my users are going to be told I'm using an AI chatbot, how might I present that to them?

[17:36 – 17:48]

How does that fit with my corporate tone of voice? What options do I have in terms of how that's presented? I think that's going to be a real kind of key part of this, that people are going to interact with AI systems, they're going to know about it. So making sure you manage that journey and making sure you own that journey is going to be really important.

[17:48 – 18:08]

That's a great point. So I think we're going to finish up there. I just want to say thank you very much, Doug, for joining us here today and for sharing all of those very interesting insights. Thanks.

Thank you for listening to MCF horizons. For more insights and updates, visit mccannfitzgerald.com. And don't forget to subscribe to stay up-to-date with future episodes.

This content has been prepared by McCann FitzGerald LLP for general guidance only and should not be regarded as a substitute for professional advice. Such advice should always be taken before acting on any of the matters discussed.