European regulatory frameworks on AI

The ever-changing European regulatory space around artificial intelligence (AI) systems offers various opportunities for National Human Rights Institutions (NHRIs).  

Key European regulatory frameworks include the recent European Union (EU) AI Act and Council of Europe Framework Convention on AI, Human Rights, Rule of Law and Democracy, as well as the EU’s Digital Services Act.  

Click on a button to learn more

The EU Artificial Intelligence Act

The EU Artificial Intelligence Act (AI Act) is a landmark regulation that aims to establish a harmonised framework for the development, deployment, and use of AI within the EU. It was adopted on 21 May 2024, entered into force on 1 August 2024, and the enforcement of the majority of its provisions will commence on 2 August 2026.

Key features of the Regulation include:

  1. Risk-based approach: The Act categorises AI systems into four risk levels based on their potential impact on safety and fundamental rights. These are:

Unacceptable risk, for example social scoring by governments.

High risk, for instance AI in critical infrastructure or law enforcement.

Limited risk, for example chatbots.

Minimal/no risk, such as AI-enabled recommender systems and spam filters.

  1. Prohibition of certain AI uses: Practices deemed unacceptable are banned, such as social scoring by governments, as are AI systems that manipulate people’s decisions or exploit their vulnerabilities.  
  2. Obligations for high-risk AI: The Act mandates strict requirements for high-risk AI systems, including risk assessments, data quality checks, and human oversight to ensure compliance with safety and rights standards. 
  3. Transparency requirements: Disclosure is required when AI is interacting with users (e.g., chatbots) or producing content. This helps users know they are dealing with AI. 
  4. Governance and oversight: The Act establishes national supervisory authorities and a European Artificial Intelligence Board to oversee and enforce compliance. 
  5. Focus on innovation: Regulatory sandboxes provide support for AI innovation and allow developers to test AI systems in controlled environments. 
  6. Penalties for non-compliance: Stringent fines will be enforced for violations of the Act, with penalties reaching up to 7% of global annual turnover for serious breaches. 

Opportunities for NHRIs

NHRIs can play a key role in supporting the Act’s implementation. They can help ensure that AI systems respect fundamental rights standards and that people affected by AI-driven decisions have protection and recourse.  

NHRIs can engage with the Act through: 

  1. Monitoring compliance: NHRIs can monitor the Act’s implementation within their countries. This helps ensure AI systems adhere to legal requirements, especially ones relating to fundamental rights like non-discrimination, privacy, and freedom of expression.
  2. Engaging in public awareness raising and education: NHRIs can educate the public on the rights covered by and protections available under the EU AI Act. This empowers people to understand how AI impacts their lives and they can challenge unlawful or harmful AI decisions. 
  3. Policy guidance and recommendations: As AI evolves, NHRIs can provide guidance and recommendations to policymakers on aligning AI regulations with fundamental rights standards. They can identify gaps, advise on emerging risks, and advocate for strong protections in line with the EU AI Act. 
  4. Investigating complaints: NHRIs can investigate complaints related to AI systems, helping address grievances from individuals affected by AI-related issues and providing recourse where there are rights violations. 
  5. Collaborating with relevant authorities: NHRIs can work with data protection authorities, regulators, and other relevant bodies to coordinate oversight and enforcement of AI systems, particularly those classified as high risk. 
  6. Supporting groups in vulnerable and marginalised situations: NHRIs are in a strong position to support groups in vulnerable or marginalised situations who may face discrimination or unfair treatment from AI systems. By advocating for inclusive AI policies, NHRIs can help ensure that these groups are protected. 
  7. Fundamental rights impact assessments: NHRIs can use their expertise to support the development and implementation of tools and methodologies for assessing the fundamental rights implications of AI systems and guide compliance with the Act. 

Opportunities for NHRIs under Article 77

If an NHRI has been nominated by their national government as an Article 77(2) body, there are several ways it might be involved in ensuring AI Act compliance. 

  1. Engaging in adverse circumstances: NHRIs can engage when incidents involving, or malfunctions of, high-risk AI systems impact fundamental rights. 
  2. Notification by authorities: According to Article 77(2), market surveillance authorities must inform national public authorities or bodies if a breach of fundamental rights is reported. 
  3. Access to documentation: NHRIs nominated as Article 77(2) bodies can request and access documentation to evaluate the fundamental rights impacts of AI systems. 
  4. Testing of AI systems: If documentation is insufficient, NHRIs can request testing of AI systems through technical means to determine potential breaches of rights. 
  5. Role in fundamental rights protection: These provisions give NHRIs both direct and indirect responsibilities in safeguarding fundamental rights in the use of AI systems.  

Council of Europe Framework Convention on Artificial Intelligence, Human Rights, Democracy and the Rule of Law

The Council of Europe Framework Convention on Artificial Intelligence, Human Rights, Democracy, and the Rule of Law was adopted on 17 May 2024, making it the first legally binding international treaty on AI governance.

The Convention aims to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, while being conducive to technological progress and innovation. It complements existing regulations like the EU AI Act by providing a broader international perspective on responsible AI development and use. 

Key features of the Framework Convention include:

  1. Risk-based approach: Unlike the EU AI Act’s hierarchical risk categorisation, this treaty requires continuous risk assessments tailored to specific AI systems. These assessments should consider factors such as context, stakeholder perspectives, and potential impacts. 
  2. Transparency and oversight: The treaty mandates oversight mechanisms to help prevent risks to human rights, and ensure accountability for adverse outcomes. 
  3. Global scope: Open to non-European countries, it encourages a unified international effort in AI governance, with parties establishing independent oversight mechanisms for compliance. 
  4. Rule of law, democracy and human rights: It safeguards against the misuse of AI in undermining democratic institutions and protects against violations, like discrimination or privacy breaches. 

Opportunities for NHRIs

The numerous ways NHRIs can engage with the Framework Convention include:  

  1. Oversight and accountability: They can play a role in monitoring compliance with the Convention, potentially as part of designated oversight mechanisms.  
  2. Human rights impact assessments: They can contribute expertise in human rights impact assessments to shape responsible AI practices globally.  
  3. Engaging in public awareness raising and education: They can work to raise public awareness of human rights under the Framework Convention.  
  4. Collaboration with stakeholders: NHRIs can engage with national authorities, civil society, and international organisations to shape AI governance in compliance with human rights, democracy and rule of law. 

EU Digital Services Act

The Digital Services Act (DSA) is a regulatory framework designed to enhance user rights and safety in the online environment. It supports free expression while protecting fundamental rights, such as non-discrimination, privacy, and the rights of children. It was adopted on 19 October 2022 and became fully applicable as of 17 February 2024. 

Key features of the DSA include:

  1. Transparency obligations: Platforms must disclose how algorithms work and provide clear reporting on content moderation practices. 
  2. User empowerment: The DSA strengthens user rights, offering appeal mechanisms for content removal decisions. 
  3. Oversight and accountability: Independent national authorities have been tasked with enforcing the DSA, with platforms facing penalties for non-compliance. 
  4. Harm mitigation: Designated “very large online platforms”, such as Facebook and X, and “very large online search engines” must mitigate systemic risks. These include ones that have negative impacts on fundamental rights, threaten civic discourse and electoral processes, and that are linked to AI-driven content moderation and recommendation systems. 
  5. Collaboration opportunities: The DSA enables collaboration with stakeholders – including regional human rights organisations – to develop codes of conduct; create strategies for risk mitigation; and influence digital policies and safeguard digital rights. 
  6. Intermediary responsibilities: The DSA affects intermediary services such as host providers, online marketplaces, and social media networks. These intermediaries must consider the rights and legitimate interests of all parties when implementing content moderation measures. This includes policies, tools, and procedures for moderation (automated or human-reviewed), alongside internal complaint-handling mechanisms to protect users’ fundamental rights. 

Opportunities for NHRIs

NHRIs can engage with the Act by:

  1. Monitoring fundamental rights: NHRIs can monitor platforms’ compliance with ensuring respect of freedom of expression, non-discrimination and privacy rights and implementing measures – such as content moderation – that enable this. 
  2. Promoting transparency: By analysing platform reports and algorithm disclosures, NHRIs can highlight potential risks to human rights and recommend safeguards. 
  3. Engaging with oversight bodies: NHRIs can collaborate with national enforcement authorities to shape the application of the DSA in ways that uphold democratic values and fundamental rights. 
  4. Raising awareness: NHRIs can educate the public about their rights under the DSA and promote responsible online behaviour. 
  5. Addressing concerns of marginalised groups: NHRIs can ensure that the specific needs of groups in vulnerable situations are prioritised under the DSA’s provisions, including children and marginalised groups. This might include protection against online hate speech.Â