techUK
Printable version

Dispatch from Brussels: Updates on EU Tech Policy

Welcome to this edition of the Dispatch from Brussels. The institutions are slowly emerging from their recess and the legislative machinery is preparing for a busy September. Below is a roundup of some of the developments that have taken place over the past two weeks and a quick look ahead at what to expect for September.  

Artificial Intelligence  

EU AI Act Service Desk sets out how the Act applies to AI agents: The Commission's AI Act Service Desk has published guidance addressing a question many have raised repeatedly. It opens by conceding that "AI agent" is used inconsistently in public debate and has no legal definition, while noting broad agreement that an agent must at minimum be able to take in and process input from its environment and then execute actions that interact with or affect that environment. The conclusion is that agents are not a distinct regulatory category. The existing definitions of an AI system in Article 3(1) and of a general-purpose AI model in Article 3(63) are treated as sufficient to capture them, on the basis that an agent will typically contain at least a GPAI model and will constitute an AI system because it usually has an interface, which counts as a system component. The consequences follow from that classification rather than from anything agent specific. 

EU AI Office reports on the fourth Signatory Taskforce meeting under the GPAI Code of Practice: The AI Office has published its account of the Taskforce's 17 July session, which addressed the Safety and Security Chapter and the Copyright Chapter. On safety and security, the Office set out how analysis of model usage can form part of post-market monitoring under Measure 3.5. Its reasoning is that evidence of how a model is actually used, and how it behaves in use, is complementary to pre-deployment evaluation rather than a substitute for it, and feeds into several stages of systemic risk assessment. Participants also discussed so-called marginal-risk clauses, the provisions under which a provider might contemplate matching a competitor that has pushed capability frontiers by releasing an unsafe model. The Office was clear that any such clause could be relied on only in exceptional circumstances, and subject to appropriate evidentiary and procedural safeguards. Members whose organisations are signatories, or who are weighing signature, should read that qualification carefully, as it narrows the clause considerably from how it is sometimes characterised. On copyright, the discussion focused on Measure 1.3(4), under which signatories commit to publishing information allowing affected rightsholders to identify which web crawlers the provider uses and how those crawlers read robots.txt directives, and to notify rightsholders automatically when that information changes. 

Data 

EU Commission publishes overview of Digital Europe Programme data projects: On 20 August, the EU Commission set out how a set of Digital Europe Programme actions are supporting secure and efficient data sharing and reuse by businesses, public authorities and researchers. The page provides a useful overview of projects the EU Commission has funded alongside some open calls.  

Some key developments to look out for in September  

  • The EU’s “Targeted consultation on safeguarding the EU’s data sovereignty” will close on 8 September 
  • As of 11 September, Computer Security Incident Response Teams (CSIRTs) and manufacturers will use the EU’s new Single Reporting Platform (SRP) to report (as per the Cyber Resilience Act), “actively exploited vulnerabilities and severe incidents having an impact on the security of products with digital elements sold in the EU market”.   
  • As per the EU’s Data Act obligations, connected products and related services placed on the market 12 September must be designed so that relevant data are, by default, easily, securely and directly accessible to users, free of charge, where relevant and technically feasible. While the EU is currently reviewing its Data legislation through the Digital Omnibus Proposal, the scope and timeline are yet to be determined. This means that members should continue to follow obligations as set out under existing legislation.  
  • In September, Council work on the data half of the Digital Omnibus resumes under the Irish Presidency, which has set an objective of reaching agreement with the Parliament by the end of the year. 
  • On 16 September, the EU Commission President will deliver her annual State of the Union Speech, which will set key priorities for the year ahead.  
Channel website: http://www.techuk.org/

Original article link: https://www.techuk.org/resource/dispatch-from-brussels-updates-on-eu-tech-policy-august-28.html

Share this article

Latest News from
techUK

LGR Decisions Made, Now the Real Work Begins