《解读欧盟人工智能法案(英)-毕马威.docx》由会员分享,可在线阅读,更多相关《解读欧盟人工智能法案(英)-毕马威.docx(27页珍藏版)》请在课桌文档上搜索。
1、umfrJrfWDecodingtheEUAlActUnderstandingtheAlAct,simpactandhowyoucanrespondKPMG.MaketheDifference.KPMGInternationalContents07ExecutivesummaryExaminingtheAlAcfsimpactandscopeUnravellingtheAlAcfskeycomponentsNextstepsIntroductionArtificial Intelligence (AI) is offering new benefits to society and busin
2、esses, aiming to transform the workplace and major industries along the way.Simply put, the race is on to embrace the remarkable and evolving power of Al and automation.AsKPMGsGlobalTeChReDOrt2023reveals,mostglobalexecutives(62percent)reportanincreaseinperformanceorprofitabilityfromdigitaltransforma
3、tioninitiativesrelatedtoAlandmachinelearningoverthepast24months.And68percentsaythesetechnologieswillplaya*vital,roleinhelpingthemachievetheirbusinessobjectivesoverthenextthreeyears,while57percentbelieveAlandmachinelearningwillbeimportant*inmeetingshort-termobjectives.ButastheworldwideAlproliferation
4、inbusinessandoreverydaylivesunfolds,thereisacriticalneedforguardrailsandlegislationtodealwithsignificantnewrisksregardingtheappropriateandethicaluse,developmentanddistributionofAl.AccordingtoTnJStinartificialintellience,aglobalsurveyconductedbyKPMGAustraliaandtheUniversityofQueensland,threeinfivepeo
5、plearewaryabouttrustingAlsystems,and71percentexpectAltoberegulated.Morerecently,CEOsfromglobaltechgiantscalledforgreaterAlregulationatameetingonCapitolHilltoprotectpeoplefromtheworsteffectsofAl.Inresponse,theEuropeanUnion(EU)hasreachedaground-breakingprovisionalagreementonacomprehensiveArtificialInt
6、elligenceAct(AlAct)thattakesarisk-basedapproachtoprotectingfundamentalrights,democracy,theruleoflawandenvironmentalsustainability.iThoughitsexpectedtobecomelawin2024,withcomplianceexpectedby2025,thislegislationthefirstofitskindisanticipatedtoemergeasthede-factonewglobalstandardforAlregulation.Withth
7、eintroductionoftheAlAct,theEUaimstostrikeabalancebetweenfosteringAladoptionandensuringindividualsrighttoresponsible,ethicalandtrustworthyuseofAl.Inthispaper,weexplorewhattheAlActmaymeantoyourorganizationandexaminethestructureoftheAlAct,theobligationsitimposes,thetimelinesforcomplianceandtheactionpla
8、nthatorganizationsshouldconsider.OrganizationalleadershipshoulddriveinitiativesinlinewiththeAlAct,companybrand,valuesandrisktolerancetopromoteresponsibleuseofAl.Thiscanhelppromoteethicaldevelopment,regulatorycompliance,riskmitigationandstakeholdertrust.,DavidRowlandsGlobalAlLeaderKPMGInternationalAl
9、shouldbedevelopedandusedwithafocusonsafetyandethics,turningtechnologicaladvancementintoapositiveforceforsociety.TheEUAlActwillhelpfosterinnovationwhileprotectingend-users.,1.aurentGobbiGlobalTrustedAlLeaderKPMGInternationaliEuropeanParliament.(December9,2023).ArtificialIntelligenceAct:dealoncomprehe
10、nsiverulesfortrustworthyAlPressrelease.ExecutivesummaryTheAlActaimstoregulatetheethicaluseofAlAlholdsimmensepromisetoexpandthehorizonofwhatisachievableandtoimpacttheworldforourbenefit-butmanagingAsrisksandpotentialknownandunknownnegativeconsequenceswillbecritical.TheAlActissettobefinalizedin2024anda
11、imstoensurethatAlsystemsaresafe,respectfundamentalrights,fosterAlinvestment,improvegovernance,andencourageaharmonizedsingleEUmarketforAl.MostAlsystemsneedtocomplywiththeAlActbythefirsthalfof2026TheAlActsdefinitionofAlisanticipatedtobebroadandincludevarioustechnologiesandsystems.Asaresult,organizatio
12、nsarelikelytobesignificantlyimpactedbytheAlAct.Mostoftheobligationsareexpectedtotakeeffectinearly2026.However,prohibitedAlsystemswillhavetobephasedoutsixmonthsaftertheAlActcomesintoforce.Therulesforgoverninggeneral-purposeAlareexpectedtoapplyinearly2025.2Providersandusersofhigh-riskAlsystemsfacestri
13、ngentobligationsTheAlActappliesarisk-basedapproach,dividingAlsystemsintodifferentrisklevels:unacceptable,high,limitedandminimalrisk.3High-riskAlsystemsarepermittedbutsubjecttothemoststringentobligations.Theseobligationswillaffectnotonlyusersbutalsoso-calledprovidersofAlsystems.Theterm,provider,inthe
14、AlActcoversdevelopingbodiesofAlsystems,includingorganizationsthatdevelopAlsystemsforstrictlyinternaluse.Itisimportanttoknowthatanorganizationcanbebothauserandaprovider.Providerswilllikelyneedtoensurecompliancewithstrictstandardsconcerningriskmanagement,dataquality,transparency,humanoversight,androbu
15、stness.UsersareresponsibleforoperatingtheseAlsystemswithintheAlActslegalboundariesandaccordingtotheprovidersspecificinstructions.Thisincludesobligationsontheintendedpurposeandusecases,datahandling,humanoversightandmonitoring.GuardrailsforgeneralAlsystemsNewprovisionshavebeenaddedtoaddresstherecentad
16、vancementsingeneral-purposeAl(GPAI)models,includinglargegenerativeAlmodels.”ThesemodelscanbeusedforavarietyoftasksandcanbeintegratedintoalargenumberofAlsystems,includinghigh-risksystems,andareincreasinglybecomingthebasisformanyAlsystemsintheEU.ToaccountforthewiderangeoftasksAlsystemscanaccomplishand
17、therapidexpansionoftheircapabilities,itwasagreedthatGPAIsystems,andthemodelstheyarebasedon,mayhavetoadheretotransparencyrequirements.Additionally,high-impactGPAImodels,whichpossessadvancedcomplexity,capabilities,andperformance,willfacemorestringentobligations.Thisapproachwillhelpmitigatesystemicrisk
18、sthatmayariseduetothesemodelswidespreaduse.5TheAlActdoesnotaffectexistingUnionlawExistingUnionlaws,forexample,onpersonaldata,productsafety,consumerprotection,socialpolicy,andnationallaborlawandpractice,continuetoapply,aswellasUnionsectorallegislativeactsrelatingtoproductsafety.CompliancewiththeAlAct
19、willnotrelieveorganizationsfromtheirpre-existinglegalobligationsintheseareas.UnderstandingtheAlAcfsimpactonyourorganizationwillbepivotaltosuccessOrganizationsshouldtakethetimetocreateamapoftheAlsystemstheydevelopanduseandcategorizetheirrisklevelsasdefinedintheAlAct.IfanyoftheirAlsystemsfallintotheli
20、mited,highorunacceptableriskcategory,theywillneedtoassesstheAlActsimpactontheirorganization.Itisimperativetounderstandthisimpactandhowtorespondassoonaspossible.2EuropeanCommission.(December12.2023).ArtificialIntelligenceQuestionsandAnswersPressrelease.3EuropeanCouncil.(December9,202).ArtificialIntel
21、ligenceActTrilogue:PressconferencePart4.Video.4EuropeanParliament.(March2023).General-purposeartificialintelligenceBackgroundmaterial.5EuropeanCommission.(December12,2023).ArtificialIntelligenceQuestionsandAnswersPressrelease.ExaminingtheAlAcfsimpactandscopeKPMQ ImemaiionalDecoding the EU Al Act 7-T
22、heEuropeanCommission(EC)proposedtheAlActinApril2021.AsofDecember2023,theEuropeanParliament,theEuropeanCouncilandtheEuropeanCommissionhavereachedaprovisionalagreementtomaketheAlActlaw.Through our lens: The potential impact of the Al ActTheproposedAlActisexpectedtoreshapehowwethinkaboutandmanageAlsimi
23、larlytowhathashappenedindataprivacyoverthelastcoupleofyears.Expectedtobecomelawin2024,theAlActwilllikelyhaveanimmediatewide-rangingimpactonanybusinessoperatingintheEUthatoffersAlproducts,servicesorsystems.ThelawintroducesadefinitionforAlintheEU,categorizesAlsystemsbyrisk,laysoutextensiverequirements
24、andnecessarysafeguardingmechanismsforAlsystems,andestablishestransparencyobligations.Whatitaimstodo?TheECaimstobalancepromotingAldevelopmentandboostinginnovationwithmanagingemergingriskseffectively.Thisisreflectedintheobjectivesoftheproposals EnsuringthatAlsystemsontheEUmarketaresafeandrespectpublic
25、rightsandvalues. ProvidinglegalcertaintytofacilitateinvestmentandinnovationinAlsystems. Enhancinggovernanceandeffectiveenforcementofethicsandsafetyrequirements. FacilitatingthedevelopmentofasingleEUmarketforlawful,safe,trustworthyAlapplicationswhilepreventingmarketfragmentation.Stimulatethepositive
26、Stimulateinnovationthroughregulatorysandboxeswheresmallandmedium-sizedenterprisescantesttheirAlsystemswithoutimminentregulatoryscrutiny. Promoteharmonizationofstandards,codesofconductandcertification. OffergreatertransparencyregardingAlsystems. Createalevelplayingfieldforthoseinvolved. Safeguardfund
27、amentalrightsandprovidelegalcertaintyforindividualsresidingintheEU.Adoptbestpractices CategorizeyourAlsystemsandunderstandtheassociatedrisks. Imposemorestringentrequirementsforhigh-riskAlsystems(obligatoryriskmanagement,datagovernance,technicaldocumentation,etc.). Carryoutconformityassessmentsandpos
28、tmarketmonitoringforhigh-riskAlsystems. Establisheffectiveoversightandenforcementmechanisms.Manageandreducerisks ProhibitunacceptablerisksinAlsystems. Avoidfundamentalrightsviolations. Preventtheuseofsubliminalorunethicaltechniquesthatmightinfluenceordistortapersonsbehaviorinsuchawaythatitcausesharm
29、tothatpersonoranotherperson. Minimizebiasthatcouldresultinunfairorinadequateoutcomes. Restricttheexploitationofvulnerablepeopleorgroupsduetotheirage,disability,politicalopinionorotherfactors.EuropeanCommission.(April21,2021).ProposalforaRegulationoftheEuropeanParliamentandoftheCouncil,LayingDownHarm
30、onisedRulesonArtificialIntelligence(ArtificialIntelligenceAct)andAmendingCertainUnionLegislativeAct.Toachievetheseobjectives,theAlActappliesarisk-basedapproach.ThisallowsforestablishingspecificminimumrequirementstoaddresstherisksandproblemslinkedtoAlsystemswithoutundulyconstrainingorhinderingtechnol
31、ogicaldevelopmentordisproportionatelyincreasingcostsrelatingtoplacingAlsystemsonthemarket.Whowillbeaffected?Mostorganizations,bothinsideandoutsidetheEU,aredevelopingorusingAlsystemsthatwilllikelyqualifyasAlunderthescopeoftheAlAct.Giventheshortimplementationperiod,however,organizationsshouldgainaprof
32、oundunderstandingoftheAlsystemstheyaredevelopingand/ordeployingandhowtheymeasureuptotheAlAcfsrequirements.Whatpartiesarecovered? AnyproviderplacingAlsystemsonthemarketorputtingthemintoservicewithintheEU,regardlessoflocation. AnyproviderofAlsystemslocatedoutsidetheEU,whosesystemoutputcanorisintendedf
33、oruseintheEU. AnyproviderofAlsystemslocatedintheEU. AnyimporterordistributorplacingAlsystemsonthemarketormakingthemavailablewithintheEU. ProductmanufacturersplacingproductswithAlsystemsonthemarketorputtingthemintoservicewithintheEUundertheirnameortrademark. UsersofAlproductsandserviceswithintheEU.Wh
34、atisnotcovered? Alsystemsdevelopedorusedexclusivelyformilitarypurposes. Alsystemsusedbypublicauthoritiesorinternationalorganizationsinnon-UnioncountrieswhenusedforlawenforcementorjudicialcooperationwiththeEUunderaframeworkofinternationalagreements. Alsystemsdevelopedandusedforthesolepurposeofscienti
35、ficresearchanddiscovery.Alsystemsintheresearch,testing,anddevelopmentphasebeforebeingplacedonthemarketorputintoservice(thisincludesfreeandopen-sourceAlcomponents).PeopleusingAlforpersonaluse.InthesamewaytheGeneralDataProtectionRegulation(GDPR)isenforced,theECunderstandsthatnon-Eropeanentitiesselling
36、theirproductsinEuropeanmarketsshouldberegulatedsimilarlytothememberstates.TheEUisexpectedtobethecentergroundforglobalAlstandards,withdivergenceintheUSandpossiblytheUK.LiketheGDPR,theAlActwillhaveandextra-territorialeffect.Whoisaffectedinyourorganization?Executiveswhomanagecompliance,datagovernancean
37、dthedevelopment,deploymentanduseofAltechnologieswilllikelyseetheirrolesandresponsibilitiesimpactedbytheAlAct.Beyondseniorrolesintheorganization,theBoardofDirectorsandvariousGovernanceCommitteesmayalsobeaffected,andtheyshoulddevelopawarenessandknowledge.GiventhebroaddefinitionofAlandthecurrentpaceofp
38、roliferation,organizationsshouldtakeaholisticapproach.Seniorexecutivesshouldcollaborateonpurposefulinnovationanddevelopment,riskmanagement,andgovernanceofAlsystemstoachievecompliancewiththeAlAct.HowitwillbeenforcedandwhatarethepenaltiesTheEChasproposedastructureforenforcingAlproviderrequirementsbyes
39、tablishinganArtificialIntelligenceBoardandExpertGroup.BothpartiessitattheEUlevelandareresponsiblefor: Contributingtoeffectivecollaborationwithnationalsupervisoryauthorities. Providingrecommendationsforbestpractices. Ensuringconsistentapplicationoftheregulation.Eachmemberstatewillbeexpectedtocreateor
40、designateaNationalCompetentAuthoritytoensuretheimplementationoftheregulationandtosafeguardtheobjectivityandimpartialityoftheiractivities.TheEUsproposedregulationwilllikelyhaveafar-reachingimpactonallorganizationsleveragingthevastpowerofAl5andtheconsequencesofnoncompliancecouldrangefromrestrictingmar
41、ketaccesstosignificantfinesdependingonthelevelofnoncompliance.Finesmayrangefrom35millioneurosor7percentofglobalturnoverto7.5millionor1.5percentofturnover,dependingontheinfringementandsizeofthecompany.77EuropeanParliament.(December9,2023).ArtificialIntelligenceAct:dealoncomprehensiverulesfortrustwort
42、hyAlPressrelease.TrackingtheEU,slegislativeSpring026ThefinalAlActtakeseffectinitserirety.journey1.ate2024Prohibitionson,unacceptableriskAlsystemswillapply.Mid2025Severalobligationstogeneral-purposeAlwillapply.Whenwillitapply?MostoftheobligationsoutlinedintheAlActareexpectedtobecomeeffectivebythefirs
43、thalfof2026.Prohibitionsareanticipatedtotakeeffectbytheendof2024,andobligationsregardinggeneral-purposeAl(GPAI)areexpectedtotakeeffectasearlyas2025.GPAIreferstoAlsystemsthatperformgenerallyapplicablefunctions,suchasimageandspeechrecognition,audioandvideogeneration,pattern/detection,questionanswering
44、,translationandot*rs,butcanhaveawiderangeofpossibleuses,Mfiintendedandunintended.Thesesystemsutilizedashigh-riskAlsystemsorincorpgtedascomponentsofotherhigh-riskAlJune2023-December2023FinalAlActnegotiationsoccurbetweentheCouncil,Commission,andParliament.Aprovisionalagreementtofinalizetheproposedrule
45、sisreachedinDecember2023.WearehereThefinaltextisexpectedinthefirsthalfof2024.December2022TheCouncilhasadopteditscommonposition(generalapproach*)ontheAlAct.April2021TheEuropeanCommissionunveilsaproposalforanewArtificialIntelligenceAct.June2023TheParliamentadoptstheirnegotiationpositionforthedraftAlAc
46、t.UnravellingtheAlAcfskeycomponents2024CopyrightownedbyonOCmoreofthKPMGInternationalnlits.KPMGIntemationaJentitiesprovidenoservicestoclients.Alrightsreserved.DCdi9thEUAlAct11-TheAlActisacomprehensivedocumentdesignedtohelpprovideacleardefinitionofartificialintelligence,enablingEU-widealignmentandcons
47、istencywithotherUnionlawsandregulations.TheAlAcfsprimarygoalistoestablishauniformandhorizontallegalframeworktopromotetheuptakeofAlsystemswhileprovidingahighlevelofprotectionagainsttheirharmfuleffects.ThisframeworkcanhelptobuildtrustinAltechnologyandgiveindividualsandorganizationsgreaterconfidenceinu
48、singit.Defining artificial intelligenceThe Al Act applies a broad definition of an Al system derived from the recently updated Organisation for Economic Co-operation and Development (OECD) definition. While the Al Acts text is not yet publicly available, the OECD definition is as follows:uAn Al system is a machine-based system that, for explicit or implicit