ChatGPT Didn't Break the AI Act. It Showed Why Adaptive Regulation Matters
Summary
The EU AI Act's legislative history demonstrates adaptive regulation, countering the narrative that ChatGPT blindsided regulators. Initially proposed in April 2021, the Act focused on regulating AI based on use-case risks, not the technology itself. However, it did not fully anticipate general-purpose AI (GPAI) models, a gap identified by stakeholders in August 2021. ChatGPT's emergence in late 2022 made this issue politically undeniable, prompting significant legislative adaptation. The process, spanning from November 2021 to December 2023, introduced a tiered regime for foundation models, including baseline duties for all GPAI providers, a lighter touch for open-source models, and stricter rules for those with systemic risk. Key obligations include technical documentation, copyright compliance, and training data summaries. Enforcement powers, including fines up to 3% of global annual turnover, became active on August 2, 2026, with models on the market before August 2025 having until August 2, 2027, to comply. The AI Office, operational with over 125 staff, and a Scientific Panel of 60 experts support implementation and ongoing adaptation.
Key takeaway
For legal professionals advising technology companies on EU compliance, you must recognize the AI Act's dynamic nature. Your clients, especially general-purpose AI providers, face immediate enforcement of obligations, including potential fines up to 3% of global annual turnover starting August 2, 2026. Ensure your compliance strategies account for the tiered GPAI architecture and engagement with the AI Office and Code of Practice to mitigate risks and adapt to evolving regulatory expectations.
Key insights
Adaptive regulation, exemplified by the EU AI Act, is crucial for governing rapidly evolving technologies like AI.
Principles
- Regulate AI based on use-case risks, not technology alone.
- General-purpose AI requires dedicated regulatory frameworks.
- Legislative processes can adapt to technological shifts.
Method
The EU AI Act adapted by introducing a tiered GPAI architecture: baseline duties for all, lighter rules for open-source, and stricter obligations for systemic risk models, supported by a Code of Practice and an AI Office.
In practice
- Providers must supply technical documentation and training data summaries.
- Implement cybersecurity protections for high-capability models.
- Engage with the AI Office and Code of Practice for compliance.
Topics
- EU AI Act
- General-Purpose AI
- AI Regulation
- Regulatory Adaptation
- AI Office
- Compliance
Best for: CTO, VP of Engineering/Data, Director of AI/ML, Policy Maker, Legal Professional, Consultant
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by Tech Policy Press.