The widespread use of artificial intelligence systems capable of generating outputs based on human input and able to influence the external environment and society, has highlighted the need to regulate the production, training, use, and development of such systems. In particular, the European Union has taken a leading role internationally in establishing common regulations for AI, including generative AI such as ChatGPT and others.
The AI Act, which the European Commission aims to finalise by the end of 2023, is intended to apply both to providers from any country placing AI systems on the EU market, and to EU citizens using AI systems, as well as users from other countries who use AI-generated outputs within the EU. This represents a complex set of rules and regulations for lawmakers and indeed, it is.
AI Regulation in Europe
It was in 2018 that the European Commission was first presented with the potential of AI for society, individuals, businesses, and institutions. Generative AI had not yet entered the discussion, but the European Commission had already begun a long process of identifying common standards for the safe and transparent use and development of AI systems.
In 2020, the Commission launched an online consultation involving over 1,200 individuals, associations, and businesses, which recorded almost unanimous agreement on the need to fill legislative gaps regarding artificial intelligence. All feedback pointed towards the need to avoid conflicting obligations across different EU countries or excessive regulation, while also emphasising the importance of a proportionate and technology-neutral regulatory framework that would take into account both the many positive contributions and the potential risks of artificial intelligence.
Indeed, the use of AI was, and is, already bringing significant positive contributions in healthcare, such as more accurate diagnoses of diseases and improved prevention, as well as in industry, where it supports greater efficiency in production systems and predictive maintenance. However, there are also a number of potential risks, such as “opaque decision-making mechanisms, discrimination based on gender or other factors, intrusions into our private lives, or use for criminal purposes [1].”
In 2021, Europe proposed that the first legislation on AI should be based on a risk classification system for users. On 14 June 2023, the European Parliament then issued the AI Act, beginning the legislative process for the first set of EU regulations governing artificial intelligence. The text will now be subject to a trilogue negotiation with the European Council and the European Commission, with the aim of reaching final approval by the end of the year or, in any case, before the 2024 elections.
However, it is expected that the legislation will not come into force until at least 2025, in order to allow economic operators time to adapt to the rules. As a European regulation, it will be binding across all member states, who will only be able to make minimal adjustments.
È importante mettere in luce che l’azione legislativa intrapresa pone l’UE all’avanguardia a livello mondiale per quanto riguarda la normativa sul tema dell’AI, difatti non si sono registrate iniziative analoghe in altri stati, oppure esse sono solo agli albori, come ad esempio negli USA [8].
As mentioned, the AI Act introduces different rules according to the associated levels of risk: unacceptable, high, limited, and finally minimal or none. It establishes obligations for manufacturers, providers, and users according to the level of AI risk involved.
In general, and by way of example, AI systems are considered to present an unacceptable risk and are therefore banned, when they constitute a “clear threat to the safety, livelihoods, and rights of people”.
According to the AI Act, the ban on the use of artificial intelligence extends to all systems used for “cognitive behavioural manipulation of people or specific vulnerable groups, social scoring, and real-time remote biometric identification systems, such as facial recognition.” Regarding real-time and remote biometric identification systems, an exception is provided for those used by law enforcement agencies such as the State Police, for the prosecution of serious crimes and, in any case, subject to prior court authorisation.
AI systems that have a negative impact on health, fundamental rights, and safety are considered high risk. As a result, they are subject to an evaluation process and mitigation of potential negative effects, both before being placed on the market and throughout their entire lifecycle.
A tal proposito, la Commissione europea include un concetto più ampio di sicurezza personale, rispetto a quello già in uso da tempo all’interno del regolamentato europeo in materia di protezione dei dati, privacy, non discriminazione, responsabilità e sicurezza dei prodotti, e altre norme sulla tutela dei consumatori.
The need to broaden the concept of safety arises from the possibility that, in future, risks may emerge which are not covered by current AI regulations, for example, in products such as household appliances, or in services that might be affected by loss of connectivity, software upgrades, or the AI’s own learning during the use of the product or service [2]. Significant examples of high-risk systems include the use of AI in critical infrastructure (such as transport, water, or energy networks), product safety, education, essential services, and recruitment at the workplace [8].
The requirement for transparency and the provision of adequate information to users applies to the category with a limited level of risk, to which belong AI applications designed to create or manipulate images, videos, and audio content [9] and therefore all generative AI tools [10]. Given the importance and relevance of this topic, the next section is dedicated to a more in-depth discussion.
Finally, for the minimal-risk category, which includes, for example, AI-powered video games or spam filters, no limitations on use are foreseen [8].
For an objective assessment of the ongoing regulatory process at European level, it should be noted that, while the version of the AI Act adopted by the Strasbourg Parliament represents a fundamental step forward in terms of legislation, some observers argue that it overlooks or even omits certain key issues related to the use of artificial intelligence.
In this regard, various commentators [8][11][12][13] have pointed out that there is a lack of adequate protection for migrants against possible AI tools aimed at control and profiling based on sensitive characteristics. Such tools could create discriminatory issues, as they are generally prohibited for the rest of the population.
Another criticism that has been raised concerns facial recognition, which is banned in real time but permitted retrospectively, with the resulting risk of judicial errors arising from cases of resemblance or disguise [14].
Further concerns have been raised over the proposal by the European Parliament rapporteur, Brando Benifei, to bring into force the part of the regulation concerning generative AI before the completion of the normal negotiation process [15]. This, it is argued, would set a dangerous precedent in legislative procedure and would also oblige companies to comply, within a much shorter timeframe than normally required—with a set of rules that could be subject to further changes in the near future [16].
Regulation of Generative AI
Since the launch of OpenAI’s ChatGPT, several generative AI providers, including Microsoft, have faced various lawsuits over copyright infringement during the past year.
The allegations mainly concern AI training based on data, images, code, and texts protected by copyright laws. These concerns have led to petitions in various countries, including the United States, calling for a suspension of AI development, including generative AI, at least until there is greater understanding and transparency about how AI makes its decisions and about how sensitive data is protected.
For example, some platforms that work with images and videos, such as Adobe and Shutterstock, have trained and implemented AI systems using only fully licensed or public domain data [3].
Transparency regarding generative AI, its training, and the content it generates in any form is a guiding principle throughout the EU regulation. The aim is to ensure that users are informed when they are interacting with generative AI and can make informed decisions about the content produced by artificial intelligence.
In this regard, the AI Act establishes the requirement to “declare whether content has been generated by artificial intelligence, make available summaries of copyrighted data used for training, and design the model so as to prevent the generation of illegal content.” The aim is to use this as a foundation for reaching an agreement with all EU countries for the final version of the law by the end of 2023 [4].
AI Regulation in Italy
To date, there are no specific laws or decrees in Italy regulating the use of artificial intelligence. However, there are a number of general laws and decrees that can be applied to AI, such as the privacy law (GDPR), the copyright law (Law 22-04-1941 no. 633), and the cybersecurity law (Law 109/2021) [5].
There are, however, several proposed laws on AI—one even written by ChatGPT in response to a “provocative” request from a Lombardy councillor [6], which are still under discussion.
For example, after an initial ban on the most well-known generative AI due to breaches of privacy and data management regulations under current GDPR, the regulatory debate in Italy, aligned with the European approach, aims to promote the responsible and sustainable development and use of AI. This includes a range of measures to ensure security, ethics, and privacy, as well as transparency in AI—that is, the comprehensibility, accessibility, and explainability of how algorithms work [7].
The debate remains open, with the aim of regulation rather than prohibition. Notably, the government has recently established both a commission of thirteen experts, coordinated by Professor Gianluigi Greco, Director of the Department of Mathematics and Computer Science at the University of Reggio Calabria, which is expected to produce a set of national guidelines for artificial intelligence by 31 January 2024, and a committee chaired by Giuliano Amato, tasked with assessing the impact of AI algorithms in the publishing sector [17][18].
References
[1] Libro bianco sull’intelligenza artificiale – un approccio-1_IT_ACT_part1_v2.pdf 2020
[2] https://www.cybersecurity360.it/legal/intelligenza-artificiale-le-nuove-regole-europee-che-disciplinano-luso-della-tecnologia/
[3] https://www.cio.com/article/650713/lincertezza-normativa-mette-in-ombra-lia-generativa-nonostante-gli-elevati-ritmi-di-adozione.html
[4] https://eur-lex.europa.eu/resource.html?uri=cellar:e0649735-a372-11eb-9585-01aa75ed71a1.0006.02/DOC_1&format=PDF 2021
[5] https://www.ildirittoamministrativo.it/Procedimento-amministrativo-evoluzione-digitale-e-suoi-sviluppi-era-Intelligenza-artificiale/stu937
[6] https://www.wired.it/chatgpt-legge-regionale-pd-lombardia-intelligenza-artificiale-astuti/
[7] https://www.milanofinanza.it/news/chatgpt-openai-trova-l-accordo-col-garante-garantira-una-maggiore-tutela-della-privacy-e-dei-dati-202304061043515084
[8] https://www.altalex.com/documents/news/2023/06/23/ai-act-ue-traccia-futuro-intelligenza-artificiale
[9] https://www.europarl.europa.eu/news/it/headlines/society/20230601STO93804/normativa-sull-ia-la-prima-regolamentazione-sull-intelligenza-artificiale
[10] https://ntplusdiritto.ilsole24ore.com/art/ai-act-gli-operatori-obblighi-differenziati-base-livello-rischio-AE8mRlyD?refresh_ce=1
[11] https://unoquattro.it/artificial-intelligence-act-regolamentazione-dellintelligenza-artificiale-tra-limiti-ed-opportunita/#:~:text=Nonostante%20il%20voto%20positivo%2C%20ci,tutti%20i%20sistemi%20di%20IA.
[12] https://www.amnesty.it/ai-act-il-parlamento-europeo-potrebbe-legittimare-luso-di-tecnologie-illecite/
[13] https://altreconomia.it/lai-act-non-si-applica-in-frontiera-un-rischio-per-i-migranti-e-non-solo/
[14] https://www.agendadigitale.eu/cultura-digitale/lai-act-approvato-dal-parlamento-ue-luci-e-ombre-di-un-regolamento-di-portata-storica/
[15] https://www.ansa.it/europa/notizie/rubriche/voceeurodeputati/2023/06/17/benifei-pd-accelerare-lentrata-in-vigore-dellai-act_34894f2d-80ff-4b79-87bb-a266e50112f8.html
[16] https://www.agendadigitale.eu/cultura-digitale/verso-lai-act-i-nodi-da-sciogliere-nel-trilogue/
[17] https://www.wired.it/article/intelligenza-artificiale-comitato-esperti-butti/
[18] https://www.wired.it/article/intelligenza-artificiale-comitato-esperti-butti/