AI regulation - EU vs UK horizon
24 August 2023
As the global race for developing artificial intelligence (AI) and harnessing its advantages surges on, countries generally agree that regulation is necessary and are actively exploring options to establish a more uniform legal framework for the development, marketing and use of AI to ensure high levels of protection of public interest, whilst ensuring the free movement of AI based goods and services.
At the forefront of AI legislation across the globe is the EU, who are taking a prescriptive legislative framework-based approach in the form of the AI Act, which will impose legislative obligations at all stages of the lifecycle of an AI system. In stark contrast, the UK is adopting, what is referred to as, a ‘pro-innovation’ approach to AI, with flexible regulation and governance that supports scientific research and entrepreneurs, whilst ensuring that the risks of AI are addressed, and consumer confidence and trust remains intact.
In the below table we summarise the similarities and differences across the main aspects of the approaches to regulating AI.
European Commission |
United Kingdom |
|
Definition of AI | A rigid definition which classifies technology based on the level of risk it poses to the health and safety or fundamental rights of a person; unacceptable, high, limited, and minimal. | Flexible definition of AI based on features such as adaptivity and autonomy, rather than the techniques and methods that AI. The intended purpose is to ‘future-proof’ against new and emergent technologies that have unanticipated outcomes. |
Compliance framework | Prescriptive legislative framework-based approach, imposing legislative obligations at all stages of the lifecycle of an AI system. | Principles based approach that UK regulators should consider to best facilitate the safe and innovative use of AI in the industries they monitor. |
Industry/Sector applicability | Horizontal, industry agnostic, application of a single set of rules to govern AIs use. | No intention of assigning rules or risk levels to entire sectors and technologies, rather adopt a ‘context-specific’ approach. Sector specific regulators expected to issue guidance on application of principles in next 6-12 months. |
Regulatory enforcement | Reliance on a coordinated network of new and established regulators, including a central European AI Board and national competent authorities for AI in each Member State. | Adherence to the principles will be on a non-statutory basis and implemented by existing regulators with the key outcome being to drive responsible ‘AI innovation and continue to respond quickly to technological advances’ |
Cost of non-compliance | Penalties of up to EUR 40 million or up to 7% of global annual turnover. | No prescriptive sanctions or monetary fines at this stage. |
What should organisations be doing now?
The regulatory position of the EU and the UK represents two ends of a spectrum. Based on current developments, the EU is set to be the first jurisdiction to enact a comprehensive regulatory framework with countries such as Canada and Brazil following suit with equivalent legislation. Other countries, including the US, will instead follow a broad sectoral approach in line with the UK. As regulations across the globe continue to evolve, a practical first step for companies should be to evaluate their existing compliance frameworks in the realms of data, privacy, security and resilience to determine those areas within existing mandates that cover similar territory.
Regulatory frameworks within the EU and UK are yet to be finalised, however organisations should take early action now to ease the compliance burden further down the line. No regrets activities to consider include:
Launch AI task force and perform horizon scanning |
Establish AI compliance capability, or augment existing compliance capability |
Review AI technologies in-line with relevant third-party and employee expectations |
Define a technology classification catalogue |
|
|
|
|
Our Experts
Related Insights
Your roadmap for DORA day one compliance
With less than six months to go, the race to DORA compliance is on. Our day one roadmap identifies and prioritises critical actions you need to take within four of DORA's main pillars.
Read moreNavigating the FAR: Five priority actions
Australia's financial services industry faces a surge in new regulations and increased oversight. So where do you begin?
Read moreFAR: your questions, answered.
Answers to the most frequently asked questions we receive on the FAR.
Read moreAI risk management: are financial services ready for AI regulation?
Find out how AI is transforming financial services and the crucial need for proactive risk management and compliance in the evolving regulatory environment.
Read moreAre digital and AI delivering what your business needs?
Digital and AI can solve your toughest challenges and elevate your business performance. But success isn’t always straightforward. Where can you unlock opportunity? And what does it take to set the foundation for lasting success?