regulation

AI Laws Across U.S. and Global Practice Areas

AI laws are evolving globally and in the U.S., addressing risks and ensuring public safety as AI adoption increases. The EU AI Act categorizes AI systems into four risk levels, imposing stricter compliance for high-risk applications and banning those with unacceptable risks. In the U.S., federal agencies provide regulatory guidance, but comprehensive federal law is lacking. Notable state laws, like Colorado's and Utah's, are emerging to govern AI use and protect consumer rights. As AI reshapes legal practice, attorneys must balance innovation with ethical considerations and regulatory compliance.

https://legal.thomsonreuters.com/blog/navigating-ai-laws-and-regulations-across-practice-areas/

Using Artificial Intelligence? Prepare Now for the EU AI Act

EU AI Act regulates all AI systems used in the EU, imposing strict compliance for high-risk systems, including those affecting employment. Key requirements include AI literacy training, prohibition checks, technical measures, updated policies, data quality management, human oversight, continuous monitoring, recordkeeping, and informing affected individuals. Non-compliance can result in hefty fines. Organizations should assess current AI systems for regulatory adherence and begin the compliance process immediately.

https://www.staffingindustry.com/editorial/cws-30-contingent-workforce-strategies/using-artificial-intelligence-prepare-now-for-the-eu-ai-act

NIS2: Why Are Firms Struggling to Comply?

Many organizations struggle with compliance to the EU's NIS2 Directive due to complex supply chains, outdated infrastructure, and insufficient cybersecurity investment. ENISA warns that several critical sectors, like ICT and healthcare, face significant challenges. In contrast, industries such as electricity and banking show more cybersecurity maturity. Additionally, inconsistent national regulation and capacity issues hinder compliance efforts across EU member states. Recommendations for improving compliance include conducting risk assessments, establishing clear asset visibility, appointing NIS2 leaders, and implementing strong incident response plans.

https://www.itpro.com/business/policy-and-legislation/nis2-why-are-firms-struggling-to-comply

The EU AI Act: What You Need to Know

EU AI Act Summary: The EU AI Act, adopted by the European Parliament, regulates AI development and use, balancing adoption with individual rights. It categorizes AI risks as unacceptable, high, and low/minimal. Unacceptable risks, like harmful subliminal influences, are banned. High-risk systems must comply with strict standards, while low-risk systems face fewer regulations. The Act will gradually implement over time, with measures including prohibitions on risky systems, establishment of national AI regulatory sandboxes, and guidance on high-risk categories. Organizations must assess and document their AI systems regarding these classifications.

https://kpmg.com/dk/en/ai/the-eu-ai-act-what-you-need-to-know.html

The General-Purpose AI Code of Practice

EU's General-Purpose AI Code of Practice, published July 10, 2025, aids industry compliance with AI Act on safety, transparency, and copyright. It's voluntary for AI model providers, offering legal certainty and reduced administrative burdens. The code includes chapters on Transparency, Copyright, and Safety, applicable to advanced models with systemic risks. Providers can sign the code to demonstrate compliance.

https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai

Europe’s AI Code Urges Companies to Disclose Training Data and Avoid Copyright Violations

EU's AI code mandates companies disclose training data and respect copyright, facing fines up to 7% of revenue for noncompliance. Guidelines aim to help tech giants like OpenAI and Google follow the AI Act, which includes transparency about model development and safety measures.

https://www.techspot.com/news/108644-europe-ai-code-urges-companies-disclose-training-data.html

European Commission Receives Final Version of General-Purpose AI Code of Practice

European Commission publishes final General-Purpose AI Code of Practice, aimed at governing AI operations ahead of the EU AI Act's August rules. Code is voluntary, offering compliance benefits like reduced administrative burden. It addresses safety, transparency, and copyright obligations, developed with input from 1,000+ stakeholders. Debate continues on its effectiveness and regulatory burden, with companies expressing concerns over its prescriptiveness and need for implementation time. Official endorsement from member states is next, allowing organizations to voluntarily comply.

https://iapp.org/news/a/european-commission-receives-final-version-of-general-purpose-ai-code-of-practice

Briefing

TLDR: The EU Artificial Intelligence (AI) Act 2024 establishes a regulatory framework for AI, promoting human-centric use while ensuring safety and ethical standards. It categorizes AI risks into four levels and restricts harmful applications. The Act mandates compliance from August 2026, with interim obligations starting February 2025, emphasizing AI literacy among HR professionals to mitigate risks. The legislation aims to foster trust and encourage responsible AI adoption, while requiring significant efforts in education and guidance for effective implementation.

https://www.cipd.org/ie/views-and-insights/thought-leadership/insight/implications-eu-ai-act/

EU AI Act Unpacked #25: European Commission Releases Critical AI Act Implementation Guidelines (Part 3)

European Commission released guidelines on prohibited AI practices under the EU AI Act on February 4, 2024. These non-binding guidelines clarify interpretations and enforcement of Article 5's prohibitions, impacting developers and deployers of AI systems. Key prohibitions include:

  1. Predictive policing: AI cannot predict criminal behavior based on profiling or personality traits.
  2. Untargeted facial image scraping: Prohibits collecting facial data from the internet without targeting specific individuals.
  3. Emotion recognition in workplaces/education: Bans AI systems recognizing emotions in these contexts to prevent discrimination.

Exceptions exist for certain practices, but companies must ensure compliance to navigate the regulatory landscape.

https://www.lexology.com/library/detail.aspx?g=ef05513f-5e88-4614-86b4-659468de7f05

Scroll to Top