The European Parliament voted 499-28, with 93 abstentions, to adopt its negotiating position on the Artificial Intelligence Act, moving the European Union closer to the world’s first broad statutory framework for regulating artificial intelligence and adding new obligations aimed at the fast-growing generation of systems behind ChatGPT and similar tools. The June 14 vote sets Parliament’s position for negotiations with the Council of the European Union, which adopted its own approach in December.

Parliament’s announcement says lawmakers want AI systems operating in Europe to be safe, transparent, traceable, non-discriminatory and environmentally responsible. The adopted amendments retain the Commission’s risk-based architecture but expand prohibitions and create specific transparency requirements for general-purpose and generative systems. The result is not a final law; it opens the interinstitutional bargaining that will determine the text.

A risk-based law expands to meet generative AI

The European Commission first proposed the AI Act in April 2021, before the current wave of public generative-AI systems made large language models a mainstream technology. The Commission’s original proposal was built around categories of risk. Some uses would be prohibited, high-risk systems would face mandatory requirements, and lower-risk applications would receive lighter transparency duties.

Parliament has kept that basic structure while adapting it to a market that changed rapidly during the legislative process. Under the adopted position, providers of foundation models would have to assess and mitigate foreseeable risks, meet design and documentation requirements and register qualifying models in an EU database. Generative systems would need to disclose that content was generated by AI, design the model to prevent unlawful content and publish summaries of copyrighted material used for training.

Those provisions reflect the difficulty of regulating technologies that can be used across many downstream applications. A model trained for general text generation can later be integrated into customer service, education, software development, health administration or other settings with very different risk profiles. Parliament’s approach therefore places some obligations at the model level while retaining stricter rules when a system is deployed in a designated high-risk use.

Biometric surveillance and prohibited practices

Parliament also broadened the list of practices it wants prohibited. The text would restrict remote biometric identification in publicly accessible spaces and ban certain forms of biometric categorization that use sensitive characteristics. It would also prohibit indiscriminate scraping of biometric data from the internet or CCTV footage to create facial-recognition databases, a technique that has raised concerns among privacy and civil-liberties groups.

Lawmakers further targeted systems intended to infer emotions in law enforcement, border management, workplaces and schools, and applications that exploit vulnerabilities or use certain social-scoring techniques. These provisions go beyond the more limited prohibitions in the Commission’s starting proposal and are likely to be among the issues negotiated most intensely with member states.

The Council’s December 2022 general approach also endorsed a risk-based regime but modified definitions and the treatment of general-purpose AI. The Council said its objective was to ensure that systems placed on the EU market are safe and respect fundamental rights while encouraging investment and innovation. The differences between the two institutions now define the negotiating space.

High-risk systems face documentation and oversight

The core of the legislation remains its high-risk category. Systems used in areas such as critical infrastructure, education, employment, essential services, law enforcement, migration and administration of justice can face requirements concerning risk management, data quality, technical documentation, record keeping, human oversight, accuracy and cybersecurity. Parliament also wants users to be able to file complaints and receive explanations in certain cases where high-risk systems materially affect them.

The framework is significant because many of the requirements attach before or when systems enter the European market rather than only after harm occurs. That creates compliance obligations for developers and deployers and gives regulators a basis for examining model documentation, data governance and monitoring. For technology companies, the practical questions include which systems fall into which category, who bears obligations in a supply chain and how rules apply when general-purpose models are adapted by third parties.

Contemporary reporting from The Washington Post noted that the vote came as governments around the world were accelerating efforts to understand and govern rapidly improving AI systems. The EU’s process is unusually advanced because it began years before the current generative-AI boom. That head start has allowed lawmakers to move from general principles toward binding duties while other jurisdictions remain focused on voluntary commitments, agency authorities and exploratory legislation.

Negotiations will decide the final balance

The next stage is the so-called trilogue among Parliament, the Council and the European Commission. Each institution enters with a different text and policy emphasis. The final regulation must reconcile Parliament’s stronger restrictions with the member states’ position and settle technical questions about foundation models, high-risk designations, law-enforcement exceptions and enforcement.

The Council’s December meeting record shows that member states already agreed on a negotiating mandate before Parliament completed its work. That means the legislative process now has two formal positions capable of entering final negotiations. A political agreement could still require months, followed by legal drafting and a transition period before most obligations apply.

The legislation also carries implications beyond Europe. Companies that develop or sell AI systems into the EU market may need to build compliance processes that influence products offered elsewhere. Europe has previously used market access and privacy law to shape global corporate practices; supporters of the AI Act hope a similar effect will produce baseline expectations for documentation, transparency and risk management.

At the same time, the law’s effectiveness will depend on definitions that remain technically difficult. Artificial intelligence covers a broad range of statistical and software systems, while foundation models can evolve quickly and be repurposed after release. Rules that are too narrow can become obsolete; rules that are too broad can sweep ordinary software into expensive compliance structures. Parliament’s text attempts to manage that tension through the risk hierarchy and specific obligations for powerful general-purpose models.

Coverage in TIME described the Parliament vote as a major step toward comprehensive AI regulation, particularly because generative systems had forced lawmakers to revise a proposal drafted before ChatGPT’s public release. The central issue now shifts from whether Europe will regulate AI to the exact boundaries of the final regime.

The 499-28 vote gives Parliament a strong negotiating mandate. It does not settle every technical or political dispute, but it places a concrete regulatory model on the table: prohibit a limited group of unacceptable uses, impose controls on high-risk systems, require transparency from generative models and create an enforcement architecture capable of reaching companies across the AI supply chain. The coming negotiations will determine how much of that structure survives into law.