The European Parliament voted 523-46 on Wednesday to approve the Artificial Intelligence Act, with 49 members abstaining, moving the European Union to the final stages of adopting what lawmakers describe as the world’s first broad legal framework regulating artificial intelligence by risk. The legislation would impose different obligations depending on how AI systems are used, prohibit selected applications considered unacceptable and create new transparency and safety duties for powerful general-purpose models.
In its March 13 announcement, Parliament said the law is designed to protect fundamental rights, democracy, the rule of law and environmental sustainability while supporting innovation. The vote follows years of negotiation that began before the public explosion of generative AI and was substantially revised after systems such as ChatGPT demonstrated how quickly general-purpose models could spread across sectors.
A risk hierarchy replaces one-size-fits-all AI regulation
The central structure of the AI Act is a risk-based hierarchy. Systems considered to pose unacceptable risks would be prohibited, while those classified as high risk would face demanding requirements before deployment and during operation. High-risk categories include uses in critical infrastructure, education, employment, essential services, law enforcement and other areas where automated decisions can materially affect people’s rights or opportunities.
Reuters reported that high-risk developers will have to address risk management, data quality, technical documentation, record keeping, human oversight and accuracy. The legislation also limits real-time remote biometric identification by law enforcement, with exceptions tied to narrowly defined serious crimes and threats.
Some AI uses would be banned outright. Parliament’s summary includes social scoring, certain forms of manipulative AI, exploitation of vulnerabilities, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and schools, and some forms of predictive policing based solely on profiling or personal characteristics.
Generative AI forced lawmakers to rewrite the framework
The original European Commission proposal was introduced in 2021, before large language models became mass-market products. The rise of ChatGPT, GPT-4, Gemini and similar systems created a regulatory problem because a general-purpose model can be incorporated into thousands of downstream applications rather than fitting neatly into one fixed use case.
The final political compromise creates a separate layer for general-purpose AI. The Associated Press reported that providers of powerful models will face transparency obligations, including documentation about training and compliance with European copyright rules, while models judged to create systemic risk will have additional evaluation and risk-mitigation requirements.
The structure attempts to divide responsibility between the model developer and the company that deploys AI in a specific high-risk setting. A general-purpose model can be low-risk in one application and become part of a high-risk system when used for hiring, medical decisions or critical infrastructure. Regulators therefore need information to move through the supply chain rather than stopping at the original model provider.
Biometrics and fundamental rights remain among the most disputed provisions
The law places strong limits on biometric identification and categorization, but it does not create an absolute prohibition on police use of remote biometric systems. Certain uses remain possible under defined conditions, a compromise that has drawn criticism from civil-liberties groups while governments have argued that serious criminal investigations require limited exceptions.
Euronews reported that Parliament’s two lead negotiators described the vote as a historic step toward “safe and human-centric” AI. The legislation also gives people rights to file complaints and, in some circumstances, receive explanations about decisions made with high-risk systems.
The rulebook is intended to reach beyond companies headquartered in Europe. Providers outside the EU can fall within scope when their systems are placed on the European market or their outputs are used in the Union. That extraterritorial effect is one reason U.S. technology companies are following implementation closely.
Industry supports a common framework but warns about implementation
Technology companies and business groups have broadly accepted the need for AI governance while warning that compliance must not become so complex that European deployment slows relative to the United States and China. Following Wednesday’s vote, BSA | The Software Alliance called the Act an important milestone and urged continued collaboration between policymakers and industry as secondary rules and guidance are developed.
Other industry voices are more cautious. Ars Technica reported concerns from the Computer & Communications Industry Association that some obligations could slow innovation or subject lower-risk systems to burdensome requirements. Much of the practical impact will depend on standards, definitions and enforcement decisions that have not yet been written.
The legislation provides significant financial penalties. Serious violations can result in fines measured in tens of millions of euros or a percentage of worldwide annual revenue, with different ceilings depending on the nature of the breach. That scale is intended to ensure that compliance costs cannot simply be treated as negligible by the largest AI developers.
Copyright rules become part of AI governance
Creators and publishers fought for provisions addressing the relationship between general-purpose AI and copyrighted training material. A coalition of European creative organizations said in a March 13 statement that the law will require providers of general-purpose models to maintain copyright-compliance policies and make available sufficiently detailed summaries of content used to train their systems.
Those provisions do not resolve every copyright dispute. Courts and regulators will still have to determine how existing copyright law applies to model training, licensing and outputs. But the AI Act creates documentation and transparency duties that could make it easier for rightsholders to understand how models were developed and to pursue claims when they believe protected works were used unlawfully.
The decisive work moves from negotiation to implementation
Wednesday’s Parliament vote is not the final procedural step. The Council of the European Union must still formally adopt the agreed text before it is published and enters into force. Once that happens, obligations will phase in over time rather than beginning all at once. Prohibited practices are expected to apply first, followed by rules for general-purpose models and later the full high-risk framework.
The implementation timetable creates a new race between regulators and technology. Standards bodies, national authorities and the European Commission’s new AI Office must define how companies demonstrate compliance while model capabilities continue to evolve rapidly. The challenge is particularly acute for general-purpose AI, where measures of systemic risk, compute, evaluation and downstream use remain technically contested.
By Saturday, however, the political direction is clear. A 523-46 vote has given the AI Act overwhelming parliamentary support, and Europe is preparing to move from voluntary AI principles toward enforceable legal obligations. The question now is whether a risk-based framework can protect users and constrain dangerous applications without freezing technical choices in a field whose capabilities are changing faster than the legislative process that produced the law.