EU Reaches Agreement on AI Act Amid Three-Day Negotiations

The EU reached a provisional deal on the AI Act on December 8, 2023, following record-breaking 36-hour-long 'trilogue' negotiations between the EU Council, the EU Commission and the European Parliament.
The landmark bill will regulate the use of AI systems, including generative AI models like ChatGPT and AI systems used by governments and in law enforcement operations, including for biometric surveillance.
The final draft maintained the tiered approach regarding the measures control foundational models, including categories from 'low and minimal risk' through 'limited risk,' 'high risk' and 'unacceptable risk' AI practices.
The 'high-risk' AI practices will be strictly regulated, with obligations like model evaluation, assessing and keeping track of systemic risks, cybersecurity protections and reporting on the model's energy consumption.
The provisional agreement also provides for a fundamental rights impact assessment before its deployers put a high-risk AI system on the market.
These include manipulative techniques, systems exploiting vulnerabilities, social scoring, and indiscriminate scraping of facial images.
An automatic categorization as 'systemic' for models trained with computing power above 10-25 floating point operations was also added.
A certain number of AI models and practices will be exempted from regulation.
First, free and open source models will not have to comply with any control measures outlined by the law.
Second, the EU Council introduced several exemptions for law enforcement operations, including the exclusion of sensitive operation data from transparency requirements or the use of AI in exceptional circumstances related to public security.
The EU will require a database of general-purpose and high-risk AI systems to explain where, when and how they're being deployed in the EU, even when it's by a public agency.
EU countries, led by France, Germany and Italy, insisted on having a broad exemption for any AI system used for military or defense purposes, even when the system is provided by a private contractor.
In the final draft, systems used exclusively for military or defense purposes will not have to comply with the Act.
The agreement provides that the regulation would not apply to AI systems used for the sole purpose of research and innovation or to people using AI for non-professional reasons.
Its task will be to oversee these most advanced AI models, contribute to fostering standards and testing practices, and enforce the common rules in all member states.
A scientific panel of independent experts will also advise the AI Office about general-purpose AI models.
An AI Board, which will comprise member states' representatives, will serve as a coordination platform and an advisory body to the EU Commission and will give an essential role to EU member states in implementing the regulation, including the design of codes of practice for foundation models.
The provisional agreement provides for more proportionate caps on administrative fines for SMEs and start-ups in case of infringements of the provisions of the AI Act.
The AI models with 'unacceptable risk' will start to be banned six months after the AI Act enters into force.
Requirements for high-risk AI systems, powerful AI models, the conformity assessment bodies, and the governance chapter will start applying one year after the law has been adopted.


This Cyber News was published on www.infosecurity-magazine.com. Publication date: Mon, 11 Dec 2023 12:30:12 +0000


Cyber News related to EU Reaches Agreement on AI Act Amid Three-Day Negotiations

EU Reaches Agreement on AI Act Amid Three-Day Negotiations - The EU reached a provisional deal on the AI Act on December 8, 2023, following record-breaking 36-hour-long 'trilogue' negotiations between the EU Council, the EU Commission and the European Parliament. The landmark bill will regulate the use of AI ...
6 months ago Infosecurity-magazine.com
10 of the biggest zero-day attacks of 2023 - Here are 10 of the biggest zero-day attacks of 2023 in chronological order. Zero-day attacks started strong in 2023 with CVE-2023-0669, a pre-authentication command injection vulnerability in Fortra's GoAnywhere managed file transfer product. ...
6 months ago Techtarget.com
Check Point released hotfix for actively exploited VPN zero-day - MUST READ. Check Point released hotfix for actively exploited VPN zero-day. Microsoft Patch Tuesday security updates for May 2024 fixes 2 actively exploited zero-days. Critical Fortinet's FortiClient EMS flaw actively exploited in the wild. Apple ...
1 month ago Securityaffairs.com
9 Best DDoS Protection Service Providers for 2024 - eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More. One of the most powerful defenses an organization can employ against distributed ...
6 months ago Esecurityplanet.com
Apple fixes Safari WebKit zero-day flaw exploited at Pwn2Own - Apple has released security updates to fix a zero-day vulnerability in the Safari web browser exploited during this year's Pwn2Own Vancouver hacking competition. The company addressed the security flaw on systems running macOS Monterey and macOS ...
1 month ago Bleepingcomputer.com
The SAFE Act to Reauthorize Section 702 is Two Steps Forward, One Step Back - Section 702 of the Foreign Intelligence Surveillance Act is one of the most insidious and secretive mass surveillance authorities still in operation today. The Security and Freedom Enhancement Act would make some much-needed and long fought-for ...
3 months ago Eff.org
Samsung Galaxy S23 hacked two more times at Pwn2Own Toronto - Security researchers hacked the Samsung Galaxy S23 smartphone two more times on the second day of the Pwn2Own 2023 hacking competition in Toronto, Canada. The contestants also demoed zero-day bugs in printers, routers, smart speakers, surveillance ...
7 months ago Bleepingcomputer.com
Days After Google, Apple Reveals Exploited Zero-Day in Browser Engine - Apple has patched an actively exploited zero-day bug in its WebKit browser engine for Safari. Actively Exploited Apple yesterday described the vulnerability as something an attacker could exploit to execute arbitrary code on affected systems. ...
5 months ago Darkreading.com
Samsung Galaxy S23 hacked twice on first day of Pwn2Own Toronto - Security researchers hacked the Samsung Galaxy S23 twice during the first day of the consumer-focused Pwn2Own 2023 hacking contest in Toronto, Canada. They also demoed exploits and vulnerability chains targeting zero-days in Xiaomi's 13 Pro ...
7 months ago Bleepingcomputer.com
US, Britain, other countries ink agreement to make AI 'secure by design' - WASHINGTON, Nov 27 - The United States, Britain and more than a dozen other countries on Sunday unveiled what a senior U.S. official described as the first detailed international agreement on how to keep artificial intelligence safe from rogue ...
7 months ago Reuters.com
Microsoft Cloud Users Store Personal Data In Europe - In effort to resolve privacy worries, Microsoft is to allow its cloud customers to store all personal data within EU. Microsoft has confirmed that it will allow cloud customers to store all their personal data within the European Union, in an effort ...
5 months ago Silicon.co.uk
Cisco discloses new IOS XE zero-day exploited to deploy malware implant - Cisco disclosed a new high-severity zero-day today, actively exploited to deploy malicious implants on IOS XE devices compromised using the CVE-2023-20198 zero-day unveiled earlier this week. The company said it found a fix for both vulnerabilities ...
7 months ago Bleepingcomputer.com
Pwn2Own Automotive: $1.3M for 49 zero-days, Tesla hacked twice - The first edition of Pwn2Own Automotive has ended with competitors earning $1,323,750 for hacking Tesla twice and demoing 49 zero-day bugs in multiple electric car systems between January 24 and January 26. Throughout the contest organized by Trend ...
5 months ago Bleepingcomputer.com
New MOVEit Transfer critical bug is actively exploited - MUST READ. New MOVEit Transfer critical bug is actively exploited. CISA adds Microsoft SharePoint bug disclosed at Pwn2Own to its Known Exploited Vulnerabilities catalog. Critical Fortinet's FortiClient EMS flaw actively exploited in the wild. PoC ...
1 week ago Securityaffairs.com
Europe Reaches a Deal on the World's First Comprehensive AI Rules - European Union negotiators clinched a deal Friday on the world's first comprehensive artificial intelligence rules, paving the way for legal oversight of AI technology that has promised to transform everyday life and spurred warnings of existential ...
6 months ago Securityweek.com
Ivanti confirms 2 zero-day vulnerabilities are under attack - CISA urged enterprises to address two Ivanti zero-day vulnerabilities that remain unpatched amid reports of active exploitation by a Chinese nation-state threat actor. Ivanti published a security advisory Wednesday for an authentication bypass ...
5 months ago Techtarget.com
The Corporate Transparency Act: Striking a Pact Between Fact & Privacy Impact - The Corporate Transparency Act became law in the United States as part of the National Defense Authorization Act for FY2021. While the intention of the act was noble in its creation, the broader implications of the law for the general public are ...
6 months ago Cyberdefensemagazine.com
At a Glance: The Year in Cybersecurity 2023 - From a surge in zero-day attacks to a need to consolidate security stacks for safety, we've seen some notable challenges, trends, and threats. In this post, we'll take a quick, non-comprehensive look at trends and news from 2023, and see what ...
6 months ago Securityboulevard.com
Google Chrome Zero-Day Bug Under Attack, Allows Code Injection - Google has patched a high-severity zero-day bug in its Chrome Web browser that attackers are actively exploiting. The vulnerability, assigned as CVE-2024-0519, is the first Chrome zero-day bug that Google has disclosed in 2024, and the second in the ...
5 months ago Darkreading.com
Europe Sees More Hacktivism, GDPR Echoes, and New Security Laws Ahead for 2024 - An evolving geopolitical landscape has impacted cybersecurity in Europe this year, posing specific challenges for safeguarding critical infrastructure and sensitive data. The Ukraine war and the conflict in Gaza have led to a rise in hacktivism, and ...
6 months ago Darkreading.com
EU Council and Parliament Reach Agreement on Cyber Resilience Act - The Cyber Resilience Act, the EU's upcoming legislation to boost the security of digital products, is now only one step away from being officially adopted. After days of debate within EU institutions, the European Parliament and the EU Council ...
7 months ago Infosecurity-magazine.com
Are the Fears about the EU Cyber Resilience Act Justified? - "The draft cyber resilience act approved by the Industry, Research and Energy Committee aims to ensure that products with digital features, e.g. phones or toys, are secure to use, resilient against cyber threats and provide enough information about ...
7 months ago Securityboulevard.com
Data Power: What the EU Data Act Means for You - On 27 November the European Council adopted the EU Data Act, a first-of-its-kind law that aims to unlock the value of 'industrial data' in the European Union. Laws looking at how data is governed aren't original. It's just that to date they have ...
6 months ago Feedpress.me
Hackers earn over $1 million for 58 zero-days at Pwn2Own Toronto - The Pwn2Own Toronto 2023 hacking competition has ended with security researchers earning $1,038,500 for 58 zero-day exploits targeting consumer products between October 24 and October 27. During the Pwn2Own Toronto 2023 hacking event organized by ...
7 months ago Bleepingcomputer.com
Barracuda fixes new ESG zero-day exploited by Chinese hackers - Network and email security firm Barracuda says it remotely patched all active Email Security Gateway appliances on December 21 against a zero-day bug exploited by UNC4841 Chinese hackers. The company deployed a second wave of security updates a day ...
6 months ago Bleepingcomputer.com

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)