Video summary

海野敦史講義94「AI政策に関する国際的な動向」

Main summary

Key takeaways

News and Commentary

Overview

This lecture surveys international policy developments for AI, centering on the EU’s AI Act (EU AI law) while briefly comparing approaches in the United States and the United Nations.


1) Why the EU AI Act is highlighted

  • The EU is presented as taking a proactive, regulation-focused stance toward AI—especially around controlling how AI is used.
  • The lecturer outlines the enactment process:
    1. A draft proposed by the European Commission (April 2021)
    2. Negotiation with the EU Council and European Parliament
    3. Adoption in May 2024
  • The Act is described as a “risk-based” framework aiming for:
    • Human-centered, trustworthy AI
    • Protection of fundamental rights, including health/safety, democracy, rule of law, and the environment
    • Support for innovation
  • A key design/enforcement feature:
    • The Act is a regulation (not a directive), so it applies directly across EU member states.
    • Day-to-day enforcement is largely left to national authorities, with some roles for the European Commission.

2) Core structure of the EU AI Act

Scope / who is covered

  • Applies not only to EU-based providers, but also to providers outside the EU if they:
    • place or operate AI systems within the EU
  • This includes actors such as:
    • importers/distributors
    • certain representatives

Exemptions

Carve-outs include:

  • military / national security uses
  • certain public institutions/international organizations (with exceptions)
  • AI for scientific R&D
  • pre-market testing
  • personal non-professional use
  • (generally) AI released under open-source licenses, with some caveats for high-risk systems

Definitions (role clarification)

Definitions clarify overlapping responsibilities, including:

  • AI system
  • general-purpose AI model, emphasizing:
    • self-training / self-supervision
    • broad task versatility
  • provider, deployer/implementer, and downstream provider
  • intended use (based on what the provider specifies in manuals and documentation)

3) Risk-based categories: what is prohibited vs. regulated

The Act organizes AI into four risk levels:

1. Unacceptable risk (in principle prohibited)

Examples include:

  • subliminal techniques or manipulation impairing informed decision-making
  • exploiting human vulnerabilities
  • social scoring
  • crime prediction based on personality profiling
  • scraping facial images to build facial recognition databases
  • emotion recognition in education/workplaces (with medical/safety exceptions)
  • ecological classification systems inferring sensitive traits
  • real-time remote biometric identification by law enforcement in public spaces (generally prohibited, with narrowly defined exceptions), such as:
    • kidnapping / human trafficking / missing persons
    • serious threats
    • terrorism
    • certain serious-crime contexts

2. High-risk AI (allowed only under strict requirements)

  • High-risk is tied to specific application areas (Annex 3), including:
    • biometric authentication
    • critical infrastructure
    • education / vocational training
    • employment / worker management
    • access to essential public services
    • law enforcement
    • immigration & border control
    • operations affecting judicial/democratic processes
  • The lecture stresses particularly important domains:
    • infrastructure, education, employment, law enforcement, and the judiciary
  • Even where exceptions might reduce risk classification, “natural profiling” is stated to remain high-risk.

3. Limited risk

  • Generative and certain interactive systems require limited transparency obligations, such as:
    • marking that content is AI-generated
    • disclosures so users understand AI involvement

4. Minimal risk

  • Generally permitted
  • Mainly voluntary codes of conduct may be recommended.

4) Obligations for high-risk AI providers & compliance mechanisms

The lecture outlines extensive provider duties for high-risk systems, including:

  • Risk management processes
  • Quality management and technical documentation
  • Maintaining logs (at least six months) and relevant recordkeeping
  • Conformity assessment procedures:
    • self-assessment, or
    • third-party certification depending on standards/common specifications
  • Human oversight:
    • systems must be designed for effective monitoring commensurate with risk/autonomy
  • Cybersecurity and robustness:
    • resistance to attempts to manipulate systems
  • Post-market monitoring:
    • includes a post-market monitoring plan within technical documentation
  • Reporting serious incidents to market surveillance authorities within short deadlines, including:
    • “within 15 days” generally
    • faster timelines for certain incidents (with very rapid reporting described for late-stage/critical cases and some death-related scenarios)
  • Establishment of an authorized representative (agent) with authority to:
    • ensure conformity documentation
    • support authority requests

5) Importers/distributors’ duties

Importers and distributors are regulated actors:

  • Verify:
    • CE mark
    • EU declaration of conformity
    • instructions for use
    • technical documentation status
    • authorized representative designation
  • Do not place non-compliant or improperly documented high-risk AI systems on the market
  • Ensure corrective actions (e.g., recall/withdrawal) if noncompliance is suspected or discovered
  • Share responsibilities related to compliance checks and information retention

6) User/deployer obligations & workplace impacts

For implementers/users (excluding personal non-professional use), duties include:

  • ensure technical/organizational use consistent with the manual
  • provide training and capability, with minimum human supervision appropriate to risk
  • ensure input data is relevant/representative relative to intended use
  • monitor operation and follow transparency/user manual requirements
  • notify provider/distributor and authorities if risks to health/safety/fundamental rights are suspected, and stop use when necessary
  • store generated logs and comply with workplace rules, including informing:
    • employee representatives
    • affected employees before deployment

7) Transparency obligations for limited-risk / general-purpose AI

Key transparency requirements include:

  • marking and ensuring detectable identification (machine-independent) of AI-generated or manipulated content, such as:
    • synthesized images/videos/audio/text
  • disclosures for deepfakes, with exceptions for clearly artistic/fictional contexts
  • disclosures when AI-generated text is published for public interest (training-related contexts are mentioned)
  • additional requirements for general-purpose AI models with systemic risks, such as:
    • technical documentation
    • policies for copyright compliance
    • detailed summaries of training data/content
    • systemic risk evaluations and mitigation
    • reporting to the EU AI Office

8) Regulatory sandboxes (testing before market)

  • The Act includes an AI regulatory sandbox for supervised testing and verification of innovative AI.
  • Participants may use certain personal data for development/testing if legal conditions are met.
  • Authorities provide guidance, and participants must manage:
    • rights-related risks
    • third-party damages arising from experiments

9) Enforcement and penalties

  • Enforcement is split:
    • national authorities enforce much of the Act
    • the European Commission’s AI Office handles parts related to general-purpose AI
  • Penalties are described as potentially severe:
    • up to €35 million or 7% of global annual turnover (for prohibitions/unacceptable risk violations)
    • up to €15 million or 3% (for other violations)
    • smaller amounts for providing incorrect/misleading information to conformity bodies
    • additional penalties for general-purpose AI model providers under certain conditions
  • The lecture also mentions promoting codes of conduct to encourage non-high-risk AI systems to voluntarily adopt governance mechanisms similar to high-risk requirements.

10) Comparison: United States approach

  • The lecturer contrasts the EU with the US by noting the absence of a single federal AI law equivalent to the EU AI Act.
  • US policy is described as more focused on:
    • technology development
    • de-regulation
  • Instruments include presidential directives/executive actions to review or reduce “excessive regulation.”
  • Regulatory authority is portrayed as largely state-based, though some states (e.g., Texas and California) have comprehensive AI-related rules.
  • Example themes mentioned:
    • deepfake-focused measures
    • AI chatbot regulation under healthcare rules
    • constraints on AI use in public institutions
  • A US-to-UN perspective is implied: policy direction is dynamic and depends on jurisdiction.

11) United Nations / global perspective

  • The lecture notes the UN establishing an expert panel on AI in 2025 and publishing a major preliminary report in July 2026.
  • Key UN framing points emphasized:
    • AI capability growth is outpacing governance speed
    • AI benefits areas like healthcare, education, agriculture, and climate-related efforts
    • human supervision and accountability become harder as AI agents take on more tasks
    • the importance of “AI sovereignty” (computing resources, governance capacity, technical talent)
    • risks from concentration of AI capabilities/profits undermining democracy
    • increasing misinformation/false information risks and social division
    • language disparities potentially excluding many Global South countries
    • governance/regulation framed not only as protecting individual rights, but also as building institutional/structural governance capacity

Overall conclusion of the lecture

The lecture argues that international AI policy is converging around structured governance—especially the EU’s risk-based, institutionally enforced model—while the US remains more deregulation/innovation-driven and the UN emphasizes structural governance capacity. The EU AI Act is presented as a detailed reference for designing legislation that manages AI risks while still enabling innovation.


Presenters / contributors

  • 海野敦史(Umi)

Original video