EU AI Act
यह क्यों मायने रखता है
गहन अध्ययन
Act अगस्त 2024 में force में आया लेकिन all at once के बजाय phases में apply होता है। General AI-literacy requirement के साथ unacceptable-risk practices के prohibitions फरवरी 2025 से लागू हुए। General-purpose AI models की obligations अगस्त 2025 में आईं और high-risk regime का bulk अगस्त 2026 में लागू होना था, लेकिन जुलाई 2026 से प्रभावी Digital Omnibus ने इसे 2 दिसंबर 2027 तक टाल दिया, जबकि already-regulated products, medical devices, machinery तथा vehicles, में embedded AI को 2 अगस्त 2028 तक का समय मिलता है। Result rolling compliance calendar है जिसे legal तथा engineering teams worldwide broader AI Regulation efforts के साथ track करती हैं, और यह अधिकतर corporate AI शासन programs का anchor document बन गया है।
चार Risk Tiers
Act AI systems को four tiers में sort करता है। Unacceptable-risk uses outright banned हैं: government social scoring, vulnerabilities exploit करने वाली manipulative techniques, recognition databases बनाने के लिए facial images की untargeted scraping, workplaces तथा schools में emotion recognition और public spaces में law enforcement द्वारा अधिकतर real-time remote biometric identification। High-risk uses — hiring तथा promotion screening, credit scoring, education admissions, critical infrastructure, biometric identification और regulated products के safety component के रूप में AI — legal हैं लेकिन heavy obligations रखते हैं: risk-management system, training data में पूर्वाग्रह पकड़ने के data-governance controls, technical documentation, logging, human oversight तथा deployment से पहले EU database में registration। Limited-risk systems के मुख्यतः transparency duties हैं: chatbots को AI होने का disclosure और डीपफ़ेक जैसे synthetic content को label करना होगा। बाकी सब — spam filters, game AI और अधिकतर recommendation tweaks — minimal risk है और किसी new obligation का सामना नहीं करता।
General-Purpose AI के Rules
Dedicated chapter general-purpose AI (GPAI) models — फ़ाउंडेशन मॉडल और frontier बड़ा भाषा मॉडल जिन पर downstream products बनते हैं — cover करता है। Providers को technical documentation maintain करना, training content की sufficiently detailed summary publish करना और EU copyright law respect करने की policy adopt करनी होगी, ताकि model fine-tune या build करने वाली companies के पास खुद comply करने की आवश्यक information हो, legal force वाले standardized मॉडल कार्ड की तरह। 10^25 cumulative FLOPs से अधिक पर trained models को systemic risk carry करने वाला presume किया जाता है और second layer face करते हैं: model मूल्यांकन जिसमें adversarial testing तथा रेड टीमिंग शामिल हैं, EU AI Office को serious-incident reporting और cybersecurity requirements। Free तथा open-source licenses में release models को documentation duties से partial exemptions मिलते हैं — लेकिन systemic-risk threshold cross करने के बाद नहीं, ऐसा carve-out जो ओपन वेट्स ecosystem के लिए मायने रखता है।
यह AI Permit Office नहीं है
एक आम गलतफ़हमी है कि Act Europe में किसी AI system के ship होने से पहले government approval require करता है। ऐसा नहीं है। AI applications की overwhelming majority minimal-risk tier में आती है और कोई new obligations नहीं रखती। High-risk systems के लिए भी compliance मुख्यतः self-assessed है: provider conformity assessment run तथा document करता, CE-style marking लगाता और system register करता है — regulator पर pre-market licensing queue नहीं। केवल prohibited practices की small list flatly banned है और systemic risk वाले general-purpose models ही release से पहले तथा बाद EU AI Office से directly interact करते हैं। Law pure research, personal non-commercial use और बहुत-से open-source development को भी largely scope से बाहर रखता है।
Enforcement और आगे का रास्ता
Enforcement split है: European Commission का AI Office general-purpose तथा systemic-risk models supervise करता है, जबकि हर member state की national market-surveillance authorities बाकी सब police करती हैं। Penalties offense के साथ scale करती हैं — prohibited practices के लिए 35 million euros या global turnover का 7% तक, अधिकतर दूसरे violations के लिए 3% तक — worldwide revenue पर calculated, इसीलिए non-European companies भी ध्यान देती हैं। Remaining milestones अब 2027 तथा 2028 तक चलते हैं जब high-risk regime phase in होती है, harmonized standards finalize होते और GPAI providers के codes of practice day-to-day expectations में settle होते हैं। Per jurisdiction products rewrite करना expensive होने के कारण कई vendors globally Act की requirements standardize कर रहे हैं, जिससे Europe की borders से बहुत आगे influence मिलता है।