Go back

Inside the AI Act: Barry Scannell and John O'Connor on the Transparency Obligations

59m 4s

Inside the AI Act: Barry Scannell and John O'Connor on the Transparency Obligations

The webinar, hosted by Barry and featuring John O'Connor of William Fry, discusses upcoming changes under the EU AI Act, particularly those effective August 2, 2026. The speakers outline the phased implementation: prohibitions and AI literacy began in February 2025, GPAI obligations in August 2025, and now transparency rules under Article 50 are arriving, with high-risk rules deferred due to missing harmonized standards. The Digital Omnibus Directive softened AI literacy to an encouraged practice, but the hosts stress proactive compliance. Central to the discussion is transparency: AI systems interacting with people must clearly inform users they are machines, addressing both obvious cases like chatbots and subtle ones like voice assistants in cars. The Turing Test is referenced to illustrate how human-like AI has become, making disclosure essential. John emphasizes that organizations should not delay addressing high-risk requirements, as future-proofing contracts and technical designs now saves time later. They highlight the importance of determining provider versus deployer status, warning that white-labeling AI systems can inadvertently make a company a provider, carrying direct obligations. Early integration of legal, technical, and risk teams in AI procurement is advised to manage risk allocation, warranties, and compliance, ensuring organizations avoid unintended liabilities and align with EU fundamental rights protections.

Transcription

9915 Words, 53884 Characters

English
Hello everybody and welcome to the latest installment of Lodgetime AI with William Fry. And as today, I'm joined by my colleague, John O'Connor, a colleague of mine who's a partner in the Technology Department with William Fry and major experts in all things tech and AI related. And today we're going to be talking about the big changes that are coming in in the AI act under Second of August. And John, I think let's start by introducing yourself. Yeah, as Barry said, I've been working in the tech and data area throughout my career qualifying the big 90s. I practice in London and in Dublin for all of that time in Fry for Practice. I have done a couple of comments, so I've some impression as well as what I like to work in as from a tech and data perspective. And obviously in that context, I'm an author of outsourcing, systems integration, systems implementation type scenarios, a lot of data related stuff as well. So into the weeds on things like capsis, scusas, diversity, including pan-European outsourcing and pan-European tech deals into the whole cloud space. And I've a lot of customer side experience, particularly in financial services, as well as vendor side experience, having asked me for some of the big logis scanner of cloud providers as well over the years. So I think that's the type of practice we have here at Fry's, which is a little boss and obviously in the AI space. All of that is very important in terms of the put the concepts, the abilities, the upstream and downstream warranties and protections, compliance with law and regulation. And just how all of that falls into risk and award and risk allocation in these contracts. And I work alongside Barry, I'm a very big tech and data team here at Fry as well as a separate large IP practice. And we're in fascinating times and we're looking forward to the next hour. We're definitely in fascinating times if the number of people on this webinar are ready to go but with huge numbers. So obviously this is an area where people want to get up to speed on quickly. Hopefully over the next hour we're going to get everyone up to speed. So look for anybody who's new, welcome. We do this every month. This is an informal chat about all things AI, more often than not AI in legal related. The Q&A function is there. So if you do have any questions throughout and we're able to get them, by all means use the Q&A function or we'll try to get your questions or thoughts. But to kick things off, what I'd like to do is just to go through the AI act and how it starts and where we've got to in terms of the various elements that came in. So somebody mentioned to me, why is it the second of all? Well, actually it was, I did a second for Orteeanos. That's going out the weekends and they're asking me then. So I'm just showing that out there. But they're asking why is second of August? Why is it always the second of this month, the second of that month? It only became a certain number of days after it's published in the official journal to EU. So that's why we're now stuck with the second of each month and that's the way it's going to be for the AI act implementation, particularly around the August dates. But the second of February, so the second of August 2024 came into effect. And then in February, the second of February 2025, the rules and prohibitive trapters and AI literacy came into effect. And you'll be familiar with the prohibitive AI rules. There are things like social scoring or subliminal techniques. Interestingly though, the Tintral Ami bus directive, which was finalized and became law on the 27th of July. So this is all very current. That basically has reduced the AI literacy obligation. So it's no longer an obligation. You're just meant to encourage AI literacy. But there's no actual positive obligation and companies anymore. But just because there isn't, doesn't mean you shouldn't do it. So that was the second of February then, and the second of August 2025, the GPAI, so general-purpose AI model obligation. So the models behind likes of Chuck G.P.T. or from the thrupping, and I from Google, those rules came into effect. And then up to now, we were meant to have the high risk rules kicking in. August, but the digital Ami bus is deferred then we can talk about those deferrals. But what's actually going to be kicking in. So first of all, we have the digital Ami bus as I said that came into effect on the 27th of July. But we're going to have the article 50 obligations come in, the market surveillance, the framework for the AI Act is going to come in, and then the general-purpose AI supervisory powers that the AI office will have, they'll kick in as well as power to actually be able to find people. And there are lots of kick in as well, and we can talk about the defines regime. But that's basically where we are right now, and I think what we're going to focus on at the beginning is just talking about the transparency provisions and what that means. So do you have any thoughts on where we are? I think it's, I think it was pragmatic to delay the high-risk assessments that are required because I think at least as far as I can see from my experience with clients in intermediaries and contacts and what I'm hearing is that a lot of organizations are just still jipping their toll on the water that are not necessarily getting a return investment as yet from a lot of this. So hard deploying it as well, but I think there are BHC, what's doable. I think no one's forgotten about the high-risk criteria that it's coming, no one's forgotten about the cyber risk, for example. And that's, I think, front of mind at the CSP level. You know what's interesting, John? You mentioned that we've got a couple of instructions in recently where the clients of specificity said, look, we know the higher schools have been kicked down the road, but forget about that we want to address. We want the advice in this now. I think that's advice, but if you're investing a lot of time, money, management time, see switch, engage into this and you're deploying it at scale across your organization, be it large organization or even a large SME, you're investing a load of hours and money in that. So it makes sense that you future proof of it, particularly knowing that the requirements are still there and they're coming and you're going to be doing probably it. Once you've done your assessments, probably a two to three year deal, so I'd like you to be a 12 month deal. I think some of them are being done, but I think it's going to be longer. So you are looking at having to future proof that contract and to look at those provisions. But I think there we are, it's not a bad place right now. I think it gives a bit more time, but I think Europe has done the right thing to push it down, but even though I think it's the right thing to have regulations on a federalized basis across the EU. So a lot of that's really positive, I think. Yeah, it's interesting. If you look into the weeds of the reasons in rationale behind the delay of the high risk regime, I think one of the key elements was, well, most of the countries were ready for us. Like Ireland is actually far ahead of the pack. So we'll get on to the Irish, the regulation of artificial intelligence. Bill, at the moment, just as the president signed it, so maybe that'll even happen today and become a log. Bush, we're ahead of the pack in terms of having our regime set up, but also how do you know whether or not you're in compliance with the high risk AI systems? We know what's called harmonized standards to be able to benchmark against. And this lack of harmonized standards was one of the big problems with high risk AI coming in. These harmonized standards were meant to be implemented months and months and months ago, but there's been delay after delay. So now they're expected sometime. Maybe the end of this, we'll start the next year and then companies can start working towards it. So I think that was one of the big reasons behind the delay as well. But what hasn't been delayed and what is coming into effect on Sunday, on the second of August, 2026. Are there rules around transparency? So one provides one to draw some transparency. There is a kind of a grace period for legacy generative AI systems. So where AI systems are already on the market, they have up until December to comply. But as the prime sector of August, any of these new systems coming on board, they'll have to comply with the transparency obligations. And of course, I guess I'll frame the conversation like this. In 1950, the famous computer scientist Alan Shoring, most of you, would be familiar with him. So the film, The Imitation Gang is about him. He was the scientist in England, sure, the Second World War, who was able to decode the in the machine. And encryption and used rudimentary computers to do this. And in 1950, there was a very famous article of his in Mind magazine called Han Machines Think. And in that article, he proposed the test and the test was actually called imitation game, but it later became known as the Turing Test and look to simplify what are going into the details, change a bit over time. But the idea was that if you had, let's say, tree terminals showing text and two were written by humans and one was written by a computer, but the person, a human being, wasn't able to tell whether or not they were talking to a computer or talking to a human. Well, then that machine was deemed to have passed Turing Test and it was deemed to be artificial intelligence. And that for decades, he was kind of held up the Turing Test and whether or not would have AI. But the thing is, since the end of 2022 and the introduction of chat, CPT, we just couldn't pass this. There was no, for many people on the call, you probably already, in the last week or two, interacted with AI without realizing that you weren't talking to a human. And the idea behind transparency provisions under one hand is to ensure that people understand when they're talking to a human or talking to a machine and the other thing, all the side of it is that the idea of a virus in magnitude, like then what is real and what is fake? It's become very difficult to identify true synthetic data, true AI generated data and deepfakes and things like that. Yeah, I think that's right. I think sometimes I suppose, it's more obvious to a reasonably circumspect individual that they're talking to a robot, a machine. It's an avatar. It's a slightly robotic voice. It's made plain and obvious. And organizations that deploy that will still need to look at that to make sure that they're not just assuming that people know, but that they take a little bit more steps to ensure that. In the obvious to somebody who is essentially, maybe new to the space, to some extent, hasn't done much of this interaction with a machine and wouldn't ordinarily just pick it up, could be a chat bot on a financial services website around just maneuvering around the website, not necessarily financial data or advice. And the same applies for a lot of retail sites, for example. And I think that's some of the people look at, but on the other hand, the point is that the variety is making, I personally, in terms of using AI on a professional level, and in my personal, what I do notice is that it's natural to forget, particularly when you're interacting with AI on a verbal basis. So it's conversational that you can interact, that it's natural to forget that you're dealing with a machine. So that's why this test is quite rigorous, because particularly when you're interacting, and that's going to become more of the case, or on the less of the case, it's going to be conversational, whether it be in your car, where you have AI, the car is an AI machine, as well as that car, in lots of modern EVs. So you are going to be interacting and speaking with the car, you could bring up history on a way to work. And the whole thing is that I think there's going to have to be genuine transparency on where that data is, how it's used, and just so you know, and you have more controls over that. And obviously, with the chart, I fundamentalize the EU. So these are fundamental rights of the citizens of the EU, which absolutely they need to be protected. These will be that interaction with these AI systems. Yeah, the lay-its, and you know, I use AI in the car all the time. So like a few of Apple CarPlay, and you've got the charging port on your phone, you can just let the car be right. And this morning coming in, I'm just going to say like, such a nerd. So I saw the Odyssey recently. It's a very good movie. And I was brushing up on my mythology, because there's a story for Greek mythology. It's kind of the first time a port trial from where there's so spoilers for the Odyssey. So this person arrestes Kielsen's mother, Klinman Estra, because Klinman Estra Kielsen, I won't say who, because it will actually interfere with the film if anybody hasn't seen it. But he was being pursued by their call to furies, and then to goddess Athena stepped in, she created a trial of the first jury. I was trying to brush up and I tried to remember the different names. And I just this morning coming into work, was talking to the chat TPC, churning away, and who was this person and to remind me what they did again. And like, you know, it's a great substitute for having any friends for a start. But I think what's really interesting is that these voice models now have to even bring in pauses, and they go, "Ah, they do those kind of things." But even breathing noises, they have a breath noise like before they start to sentence. So they're very human-like. Yeah, and I mean, they're made to make you feel like you're having a conversation. And there are certain advantages there, I think. And I can understand why even the phenomenon, which is around the humanoid robots that's coming down the stream at the moment, why that's the case, rather than just robots. Why do they have to be humanoid? But the reality is we're going to be able to do more things, the more they are human-like. And so, but the guardrails, the iterations of that need to be very clear that everybody knows that you're speaking and to a machine. And that's what the AI Act will never say. So it says that providers, so these are the people. It's not used for the systems, but the people who provide the developers, basically, the AI labs of these systems that are intended to interact directly with people are designed and developed in a way that people are informed with the interactivity with an AI system. So this is something that must be done by design. So basically, I guess one way of thinking about it is, when you're familiar with chatbots, you will always see, you were talking to an AI, almost always anyway. And is that enough? And it's queerly ghetto, the times that, how do you actually do that? But it might be just a thing at the start of the chat saying, "Welcome to the William Walk Fry AI chatbots." And that's probably enough. Yeah, I think that's it. And I certainly think it's just, I think so, this is to say, will be obvious in terms of, and then the technical solution would need to be built around that. But I do think there's that we did a recent technology survey when in Fry. And one of the key findings was that the tech piece, which was always done pretty quickly once procurement and the C-3 decided they wanted to deploy it, that was being done sometimes before the legal and regulatory piece was being looked at, propered. But we're seeing now, I think it's fair to say, because cyber-risk is so large, is that organizations are beginning to look at the legal regulation points along with the tech procurement risk and the proof of concept. Now, I think the real benefit of that is that, when you're looking at things like transparency, you're going to actually look for a technical solution and kind of say, how do we try this? Is this going to be transparent to our user base? Be it our employees, if they're going to be exposed to it, or indeed our customers? And then how do we bake warranties and risk allocation into the contract? And by doing that earlier, and it might sound a bit self-serving, lowering it earlier, but it would be in OSLORIS or OSLORIS and console. What you're doing is your G-risk image. And you also know, to the extent you're stepping into risk, what size of risk that is you're able to quantify that, while complying with law and regulation. And maybe ensure you don't step into the provider role by quite labeling a chatbot, when that wasn't your intention. By quite labeling, it means you rebrand it to your own brand and you end up being a provider of that onto the market in the year, which probably not your intention, at all. So getting the contracts right to the B2B level, and ensuring that the technical part matches that, and a good proof of concept, and getting the lawyers involved earlier and risk compliance, as well, because you might have a DPO for GDPR, and in fact, services you may have other risk compliance people, you need to get involved in an outsourcing door of perspective. So it's various. It's getting that, I think, at an agile level, because you don't want to spend two years at a improvement concept and getting the right people in the room with expert fees. And this where it comes along to AI and I think you say, I think it's probably right that it's not an obligation to pass the board, but you're obviously on those teams are going to have to have your best people who are most two dead. And if you don't have the expertise, you're going to have to source it. And it's those types of things. But I think the B2B contract itself needs to be color-braceted to make sure you are not only right, but you understand it. And in order to ensure that your risk allocation is under such a C-speed level, there's a little point, for example, in outsourcing cyber risk, if your capital availability is 1,000 euros. Because one of you really outsourced, you've outsourced on a contractual basis, storage of that data or the solution and the dependency on that set. But you're having to outsource most risk actually because if the worst case scenario happens and there's a breach of contract by the vendor or you're sitting with all that ability as you were before. So that risk allocation, I'd say, I often see that's not dealt with particularly well. What's also what I think is also really important is to decide there around who's the provider in this situation. So Article 51, 50.1 says for this provision around chatbots relating to providers we see the thing is that in John's moment of the white labeling is that the AI access that you're a provider if you're a developer but also if you get someone else to make an AI system for you and you put on the market under your own mark or your own name then you're considered to provide it. So let's say if William Frye got a third party to develop a chatbot for us and then we had that on our website or out in the internet has to William Frye AI chatbosh with our logo then we'd probably be considered to provide her there and that obligation then to inform is actually our obligation. So even if the AI system that we got developed for ourselves doesn't have you're talking to an AI on it. It would be our obligation to ensure that's it. Absolutely. I mean it needs to be realized that it's the whole atmosphere of the AI act as a provider that you're stepping into but only relation to that chatbot and not saying outside of that in relation to that which you're putting on that AI system that you're putting onto the EU market. The other issue is on the vendor side what I've noticed sometimes Barry and we talked about this a few times. Some vendors are very aware of that so they don't want to step into the provider role but they equally want to provide some AI to their customers. So they're basically saying well if you take the AI from us that part of the solution that's likely to be with her party and these are the concerns and we're not quite labeling it. So they're able to kind of pull mingle if you like or bundle this solution. It has to be quite careful how they do that because they don't want to step into the provider role and aim to up that it's murky but it's a way of managing and we obviously act for some of the vendors as well and it's interesting if they get that right how you would get that and get that binary then obviously how that flows into a customer and how the customer analyzes that and not waste some time because the customer then if they accept that and it's a good binary honest you could potentially move away from the AI with the main supplier and just deal with those AI provisions for the AI piece which could speed up your negotiation cycle the concept of an AI addendum to that so companies are using AI addendum to deal with the issue. And your announce left would an negotiation that kind of goes nowhere for a very long time and your waste large time and money in doing that and the team the project you get to Australia to prove for concepts very brief as well I would say for a proof of concept it's hard to comply with all law and regulations so it's better sometimes with guard loads in place so that you're not using that for example so you can avoid a robust data detection analysis with you use synthetic data or dummy data particularly interacting with your data and if you're doing a promise they're not sharing much coffee information for the proof of concept and it's your guard loads because if you're having to do the whole risk of compliance and legal compliance everything on a very robust level for proof of concept when you have no valid proposition you've no use case that you approve that this works and it could be very valuable return investment well then you so what we encourage clients to do is very much contain the guardrails for the proof of concept and have good guardrails and therefore manage it so you're kind of not having to get into the weeds as much on compliance and law and regulation but fairly you need to socialize with the vendor by the way if we're going to do a bigger deal here that's for real money and it's a longer term deal these are the laws and regulations as a bank or as a retailer that we need to comply with and there is no their mandatory law we haven't got a choice and we need you to know at start with proof of concept that we're not seeing from the goals of all of those now because we put guardrails in place if this deals doable it will be doable so that we can comply with manager's law because what you're trying to do is you're making sure you're doing with a vendor who will accommodate to a large extent your compliance with yours of course you and I have worked the things together just on this exact point because when you're doing a POC you don't want to throw the kitchen sinker you don't want to spend this massive legal spend and something so doing it that way allows you identify the risks of legal issues but still be able to perceive with a POC yeah so just just moving on and by the way we did like huge numbers on the webinar which is great to see and the question of flying it until we will try and get them and keep them up we've also been informed that President Kamali signed the regulation of AI Act 2026 in law on 21st July so that's great it's in the law yeah I was checking the ROC this website yesterday and it hasn't been updated from the ROC this website so if anybody from the ROC this is on this call please just note that but moving on to the next part of the transparency provisions and these are the obligations on providers of AI systems which includes general purpose AI systems that generate its Gen AI type AI systems so AI systems generating synthetic audio image video text content there's an obligation now the second of August on those providers to ensure that anything that the AI is producing is basically marked as AI generated so one of the questions we had was how are we expected how are we expected the obligations under the R50 to be enforced when there's no reliable systems text AI generated content well actually one of the things that the AI Act does is that puts an obligation to push in a reliable mechanism to generate AI content so I'll give you an example unlinked in if you if you did an AI generated image and then posted that image on LinkedIn then automatically LinkedIn puts a little badge on it saying C or and the C or mark is a sign that's put on automatically put on images that's an image was AI generators and the reason LinkedIn is able to do that is that because when you download that image in the metadata of the image file is information that tells other systems I am an AI generated image so that is the obligation that now exists now you might be thinking well how does that apply for text if you're talking to chat GPT or Lord and you just copy and face the text well you're right you can't like you mean you it doesn't carry over a copying and pacing text but what we do have in addition to the guidelines what it just commutes are the guidelines and transparency and the court of practice and transparency which are actually two very useful documents and the court of practice in particular and the guidelines talk about container on text so if you've got text in a chat conversation on the AI it can't plug to that obviously but if it's in a PDF if the AI produces a a dark x file or a PDF file well then that file containing the text will have to contain information that this is an AI generated document this is AI generated text but of course the problem is it's so easy to get around these so how do you get around the metadata in an AI generated image yeah well I think I think that's your point well we've always got laws that nefarious actors will seek to evade and we all know that and I don't think that's about to change with anything well we want to make it as difficult as possible so there's not lawful for the vast majority organizations not to be conspicuous about their use of AI and what AI has been put on the market and I think social media comes to mind all a lot of online content call it new media we're talking elections we're talking about news current affairs opinion and then you've legacy media as well so now I don't think everything is going to be so much to this so I think that's a good thing but organizations too that are behind a lot of the technologies that enable all of that and that provide all the AI and it's getting that as joined up as possible for the EU market it's likely the so markets will look distinctly different actually if they don't federalize their laws and that's another thing I think it's worth exploring how that will impact over five years time but I do think as conspicuous as the market can be around AI is a reading positive thing because but you'll still have some element of bad actors and fortunate because I expect even most of the US multinationals that put but content and AI into the the EU market most of them will be materially compliant it might be immediately but I think that's where we leaned up with the vast vast majority of them but I think we'll still have bad actors and unfortunately so some AI won't be clearly marked as you said it's inevitable but at least it would be an offense it's it's how how enforceable will the AI act be against those actors it's a bit like GDPR people who joined the company I think even though it's not even necessarily bad actors, like people of myself, I might get around to the metadata and the IZoundary's image, just take a screenshot of it. Exactly. There's a watermark just drop it out. If you're trying to post in the social media and you don't want to tell tale AIPs, absolutely, and there's going to be lots of that too. But I suppose I'm thinking about from the institutional organizational basis, I'm not sure if they'll do that as much because there will be real consequences this. We're looking at, I think it's 15,3% of inch price. Yeah. Global turnover isn't it? So I mean, that's their huge buys. And on that very point, as you say, John, the transparency provisions of the AI Act actually specifically talked about. So we've been talking about providers up and down there. But like what about just to write your folks like all of us, all the people of the companies on this call, well, we're employers of these generative AI systems. And if you use one of those systems to generate or manipulate an image, audio, or video content with costumes, a deep fake, then you have to give an obligation to say this was AI generated. So let's say William Fry me going forward now. If we have an AI generated image, now what first of all, what's the deep fake? And this is an important version. It's not any AI generated image or text or whatever. It's the only one which constitutes a deep fake. And what constitutes a deep fake is some AI-centratic generated content depicting an existing person, place, object, or event. So at a good example, if you know if there's a celebrity in town, say, if Brad Pitt was in the news, the adult and the pop's down in town of the bar or whatever it might do, an AI generated image of Brad Pitt would have pined in front of all of the posts. Harmless stuff. Although there have been mitigation around things like that like the talks, more litigation, you could play in passing off and everything. But you have been so great because I think there was a famous Hollywood actor who was on Russian television for an AI, for a particular product for more than a year. And to turn out, the whole ad work was a deep fake. And the rest take it down and they did. The thing that produced the other deep fake, which was saying that they shouldn't have to have taken it down. So the deep fake was so powerful that it lasted over 12 months as authentic advertising, which is remarkable. But so I think these things are about to tell which required. There's no absolute, because you could end up passing off into extra property and misuse people's image and destroying personal lives as well as organizational reputation. So I think it absolutely is needed on a federalized basis and a uniform approach. I think the EU is ahead of the rest of the world. In relation to thinking about this the right way. Yeah. And by I think of all of the things to be wary of going forwards, this is the important one in relation to the transparency permissions. So like torture marketing teams and social media teams, but if you use anything and it doesn't even have to be a brand pit, could just be a building. And if you have an AI generated image of, let's say we did one for granted, our doc. Yeah, where our offices are. That would be technically a deep fake and technically we would have to label that as being AI generated. The core of practice has suggested little AI markers that you can place on or near the AI generated image. Just showing those AI generated, but you know, even an event like you could. Yeah, I think the example that Elon Musk can sometimes get a fair press, sometimes innucible and sometimes an unfair press, probably fair. But an unfair example of deep fakes with Tesla, one of his, one of his companies that he's, you know, heavily involved in obviously CEO, was a number of defects of various Tesla cars that apparently had accidents. And this was the consequence of the stage of the car at the end of accident. And all most of those images were deep fakes and they were, they were all over the internet, giving the impression that most other cars wouldn't be destroyed in any way like that and that the cars were unsafe. But you can imagine the level of reputation. So you can start from extrapolation. But that's the type of thing that will be considered because that's an event that happens, an existing event that happens and you're manipulating it to change the reality of it. So that would need to be, but you see, who's good actors and bad actors, like a random internet person may not do it, but an organization after. And even events like, you know, look, Sean and myself are both carry men. So this is a hard example, but let's say I think it's paper wanted and the image of the old Ireland final, the weekend and didn't want to pay a stock photographer. Well, they could just use AI to create it. But they'd have to mark that as an event as AI generated. And somebody's asked a really good question about when does the obligation kick in for edited pictures because they say that they give the example that the whole school is taken by cameras or photographers, they are edited with tools with AI capabilities. This was actually subject to some negotiation actually. And it's a really important point because you need to be able to amend these and it's a lot of AI tools used to amend photos. So it's where, and I think your example is a really good example. Let's say if you've, it's where the level of editing or manipulation substantially offers to what actually happens, say, like, I mean, there isn't any line in the sounds, but it's where you've altered the meaning or whatever. So like, you know, I think they talk about backgrounds a lot actually. I think like after memorable, the guidelines are to code. I think it's to guidelines to talk about backgrounds. But like, if you had a picture of Neil Mark and T-Shook standing at a beach and then you edited the backgrounds so he was standing in front of a jungle, right? It doesn't really make or or ability. It doesn't really make sense. He was never there. Yeah. But what would be considered a deepfake, not necessarily because all he's done is changed the background. It doesn't change the meaning of what was being conveyed or whatever. But like, if you put a standing in front of, I don't know, like a strip club or something, right? Which was an impact? Arguably, it's a pharmacist. Exactly. Something like that. Yeah. Yeah. Just again, then that's like that. And I think there's corporate affirmations individual. I mean, that's another area that would stand anyway. If you could prove who did it and, you know, despite this. But I think that this transparency, I think, is a vital component to where we're going with AI across all sectors, sector, agnostic. And the fact that it's, as Barry said, we're already interacting with this daily and early. The vast majority of us, I think that alone needs a grow. So with that transparency, one would hope that in the vast majority of times, we'll know when it say, I, but there will be some leakage and that organizations will know they have to comply with these because otherwise, it would be, I think, slightly chaotic to say at least. And it would allow for some very unfair things to happen because some of the law, like catch up with defamation, something that could take yours, even if you can, you know, if you meet standard of proof to actually get there. Meanwhile, meanwhile, the consequences reputationally are enormous. So it's really about privacy are by design that the AI transparency by design is so vitally important. And this deep thing, I think, is just part of the overall transparency piece. We've got a couple of really interesting and I think related questions come in. So one question, and it's not something I've told of actually, but they're asking, how does the transparency component of the AI act apply to the kind of enhancements, architects apply to architectural visualizations for building proposals, which can't really be defined as fake. And they're asking, are there specific creative or artistic exemptions in the art? And there was a similar question asking about those artistic exemptions too. So dealing with the architect piece, like if you have a building and then use AI to, you know, go down an extension to everything, that may not necessarily be considered a deep page, but it might be like it's a tricky one. To be honest, say for sites, you're probably safe or are you thinking to just say, look, this is AI generating. And by the way, when people see these images, they know their computer generating, like something like architecture, our systems are familiar with it, so it might be on the same site. But it's a bit like the photograph example, although slightly different, because you don't capture a picture of person in edit, it's slightly the reverse of it. So you AI generate the extension, but then as an architect or even an individual, you begin to kind of fit it better. or change it or sizes. Now you've got something that is probably more defensible, there's not been a deep fate because what you've done is you've adapted it substantially and you say I generated it and I think you kind of move beyond provided you don't also go back to that version. You know what I mean and that becomes the published version. If it were the published version then I think you could then you've questioned Mark, he's very sadist, whether or not if there's a risk or something like that although I don't think there'd be massive risk itself in a design of a house but a design of a commercial building perhaps it's more significant error. Yeah and I think you know on the artistic piece there's there's not an exemption as such but like where the ALI is where you have a deep fate and it's used as part of an evidently artistic creative satirical fictional or ALI is an ALI-GIS worker program so deep things the obligation doesn't go away but to transparency obligations are limited such that you have to explain that it is a deep fate in a way that doesn't hamper the display or the enjoyment of the work. You still have to identify it so like yeah you can imagine something like you know satirical political problems have I got news for you or are satirical in my life you can imagine them. I think there was there's been two or three photography competitions I think in Europe I think I was really about this six months ago and in I think Germany there was definitely one where in the the photographers were asked to disclose whether or not they'd used AI but they were permitted to use AI and someone didn't but won the competition and then they were ruled out for breaching the rules but in another case someone was transparent about that and that was allowed for and they were able to see the version without the chamfering and with the chamfering so they were able to do judges that is so I mean it's just an example and then so the rules of the game were permitting us but obviously within reason because you couldn't completely change essentially was a photograph and so it's interesting the way the world will will the design rules around you know some of that as well as procedures but what was that other question you mentioned? Well another one is actually just come in asking like is dirt disclosure that required for words for for like legal advice so the thing is is that where the words as I mentioned are container rights so where they're contained in a doc expiler PDF of the obligation is there on the providers but in terms of words like the legal advice example no there's just not an obligation there to like to provide some to market as such now where you have a system that generates or manipulates text for the purposes of informing the public on matters of public interest then there's an obligation on users of those systems to notify people to say that oh by the way this text is is AI is AI generators but interestingly that obligation doesn't apply where there's a human in the loop so where it went under human editorial control whatever it makes sense so this would be something like a weather alert in automated AI weather alert that just goes out without a human seeing it or things California it happens a lot earthquake alerts so those would have to be marked as AI generators but if there's an editor or editorial control then you don't have to yeah because it's I think Amazon said that a lot of the books published an Amazon on audible that they know that a lot of them are 67% of them there's there's a huge amount of AI generation and then it edited there after so there's chapters and pieces but it's prompt engineering based on the chapters and then substantial editing going on thereafter to hasten to speed off the the writing process which I think if you're a very good author already you're going to be much better at than someone who's a particularly average the other is the legal service I think it's very interesting is that there's an Irish case that you might be aware of and there's a little bit of the same thread developing in some other jurisdictions but the Irish case was essentially in not tell that the court was saying that if you're coming in with AI generated stuff you need to actually disclose that to court and the other side you know and so that everybody can and you're responsible by the way for the content and indeed the citations so you need to be checking them where are you or private citizens in our alloy a lot of people commented on that in the UK on that Irish case and said does that mean that everything that a law firm does in the background or a prime practice law does in the back home and then obviously changes and reviews we'd like to think in the vast majority of cases do you have to disclose that and that doesn't seem to be where it's going it's more a case that where you said I mean as far as I can see where it's landing is the human in the loop if there's a human in the loop or a lawyer who's interesting what they've engineered through prompt engineering to the prompting and then they're taking that and reviewing it in its entirety and deciding whether or not they're deciding off on that and that's the one then that wouldn't appear to me to be something that you need to actually then go ahead and disclose but I think certainly if you're just deploying AI and you're you're producing a lot of content there in India it looks like you know particularly if there's a public interest issue in relation to the AI act you'd need to you need to disclose that yeah like look I think I think we need to the market reality has shifted and like AI is now just an integral part of the practice of law I would say absolutely and you might as well you know get rocket scientists to go back to using those big tables and slide rules and the way things have gone like this is just the way the practice law has gone but what I would say is that personal accountability is the key elements that whatever you're inputting whatever you're sending to climb whatever you're sending it to court the book stop should you as a lawyer yeah I like to put it like you're supervising the AI as if the AI is an agent to a person that has to be the mindset rather than it's that you're you're writing like you would and like so word or in an email nice about look or some other email or or or we're trusting application or you do it on a in hand-relating you're you're not it's not you that's writing the text it's been prompt engineering so it's being generated and as a result it's as if someone else is generating and you're supervising that person yeah and that has to be the mindset professional services but I'd argue in the the architectural example we're talking about the mindset has to be your supervising the AI yeah the same way that no matter how talented your trainee might be and that we vary in talented training of course that's a good idea but you're never going to just take their work and hand it into compliance without revising it reviewing it and the training equally because they're supervising the AI the trainee does learn just much if that trainee if he or she is checking every sentence all citations and what they've used the AI for is both confirming their own knowledge but confirming it independently themselves and also learning to some extent from it because they can learn and then check those citations and it's hasten you'd like to think the articulation of some of it particularly if they're good at the prompt engineering piece so it's really a skill set for supervising the generation of the content before giving it to the more senior person for maybe signing off or order at a junior level that's not I would say 100% like the introduction of AI and this is what we've been explaining to people like also along an internship program for example it's not about replacing young lawyers if you're doing it right that's not what you're doing at all you're actually enhancing young lawyers and their abilities but it just means changing the way you train these people and I think the organizations that don't catch on to that will be left behind. I've heard described very well a few times and one big consultancy who has a few and a thousand employees said that to your point is exactly what we're saying now would say that what do fear and is then bring what do professionals bring well they bring the judgment they also bring the sometimes the syntax the even the common sense of caught on on how to say certain things particular markets or what kind of how to present something for for marking advertising purposes versus advice and judgment and the length of the content that's produced and then obviously checking all citations and how it's topped and tailed and how the exact summary is written in particular so there's a lot of judgment that goes into it and expertise in terms of supervising that tool and I think I think the other way I heard described as well which is even briefer which I think is so good that there's lots of good lawyers out there and that you know it's hard to French series "One Good Lord from another." And if you can, great. because then you might want to go to that lawyer. But you know that if 90% of a good lawyer is their skill and their ability to advise and their ability to work as a team and so on that, then this 10% for the AI and tech savvy piece called the tech service is becoming a vital 10%, it's not a nice to have 10%. If you don't have this 10% going forward, it's going to mean that you may not be able to fully deploy your professional experience because your competition, et cetera, or if you're in house, your competition there would be doing a better job. So I think the tech savvy piece is a vital component, though. - Absolutely. Although I would say we have to transient good lawyers that they have willing to fly in their outer heads, but that's precisely the point. In the last 10 minutes or so, less than 10 minutes, but it's been a really great conversation and we're getting really good feedback already and big, big audience as well. We were all, got value from some of these insights, but just to talk about what else is coming in there and coming in with second of August. So first of all, what we do have two new prohibited AI provisions after the notification of scandal at the start of the year. For the second December, AI systems that these notification systems and AI systems that produce child sex abuse material, those are going to be prohibits, right and so clearly, but to the extent that obviously elements out there are already illegal, but it's going to be prohibited for them to be on the market. So those are coming in, they come in under the digital omnibus package. But we also have our own piece of AI legislation kicking in as well, which is the regulation of our artificial intelligence act as we learned on this call no longer a bill. So basically, the idea behind this is we're going to have an AI office and there's going to be a CEO of the AI office, but the CEO of the AI office, they're not going to be a regulator and the AI office is not going to be the regulator. AI ought to be responsible for ensuring that the legislation is complied with also for promoting AI in Ireland, but interestingly in Ireland's taking an interest in reports, it's the regulators. The existing regulators are going to be market surveillance authorities, I caught up with authorities under the AI act. They're going to continue to be the regulator. So, you know, the data protection commission, commission, the mad central bank, they're going to be the buddies responsible for enforcing the AI act in Ireland. Now, in order to make us all work, one of the functions of the AI office is a cooperation forum, it's called. So basically, the idea behind the AI office will be to coordinate all of these different regulators because you can imagine there might be something that's what overlap between the commission, the man and the data protection commission as an example. Well, the AI office without the board net would show them figure out who takes on the regulatory responsibilities, but interestingly, in terms of who does the, let's say, the transparency provisions and you mentioned fines there, John, these are massive, massive fines, but it'll be whichever sector is impacted. So, if you're on newspapers, say, and you didn't, you know, complain with transparency provisions, I imagine commission and the man would be the party. There are few financial services and to fail your transparency provisions. Like, and the interesting thing here is that it wouldn't necessarily be, you could be a finance finance insurance company that puts a picture of Brad Pitt standing under your own. Right? And that would be a deep faking, you may not. Like, so it doesn't necessarily have to be an issue with transparency, specifically related to something within the central banks, receiving like, I'm financial services, it sounds like we have yet to see how it would play out, but it sounds like because you are a body already regulated by a central bank, they would be. - Yeah, absolutely. That seems to be the correction to trial. - Unless maybe it was on social media because then maybe it was on social media. - You could have crossed over that. - You could have, yeah. - So, we don't know how this is going to kick in yet, but like, that's the way that these provisions are gonna go, but interestingly, the European AI office has competency for channel purpose AI models. So the opening of the electronics, the Google Gemini, they are going to be kind of governed centrally from the annual P&A office. And one of the things that's digital on the business package change was in so far as these are considered very large online platforms or search engines that those provisions have moved out from the TSA national competency into the EU AI office regime. - Yeah, yeah. So I think we can start wrapping things up. Do you have any parting words, John? - Yeah, I do. - Or inaugural looks down AI. - Yeah, yeah. I just want one thing for the audience because obviously this is where based in Ireland, our head office here at Fries and we'll just share a very, very brief piece that we're involved in a lot of pan-European AI projects that the movement not just wants for late specifically to Ireland. And what's interesting about that is that, on opposite, some of them, most of them are on the kind of the employer side rather than the provider side, although there's some provider mandates as well. But on the employer side, it's interesting that we're contacted by lawyers in an organization in Germany, Spain and Italy. To advise them on proof of concepts and deployment to the AI, banks, insurance companies, big retailers, et cetera. What's interesting about this is that Queen Mary University of London, about six months ago, had a look at about a couple of dozen AI models, mainly come in from the US but there was something showing as well, where some of them were direct from the Irish image models, the general purpose AI. Some of them were more intermediaries of AI systems. And so there's a good spans and of AI provider terms and conditions they were looking at. And they would have lived in the same few years ago for the cloud about a decade ago, Queen Mary did the same thing. Well, very interesting. I was on a webinar recently, and a gentleman that represented on a tour, I know pretty well, he said what's very telling is that about 80% or 70% of the EU AI provider of terms, conditions that are coming into the EU to the various deployments are subject to the laws of Ireland. And pre-Brexit on the cloud side, that would have been about 23% of those countries so much very short. The majority were a combination of English law or Dutch or the laws of Luxembourg sometimes. Now it's flit where by most of these AI models are subject to Irish governing law terms, which is very interesting from a point of view of capsof Susan Bavariancy, compliance with management law, compliance with our new way of our citizens' actions at. But also then our annual pay base, there obviously been management laws in those jurisdictions. But it's very interesting that both negotiating those deals and if there was ever a dispute, they'd be interpreting the courts with Irish law and Irish law principles, as they said on all of the stuff we're talking about risk allocation and things outside capsof institutions and all that stuff will be Irish law interpreted. But it's remarkable to hear so much of that. It's so much Irish law. So that piece I think is going to be fascinating to watch over the next few years. - Yeah, totally agree, John. And look just in terms of my parting words is that, guys, I think the rovers really hit the road. And it's like, I mean, the, we're out of the door with AI work at the moment and people are now at the stage or go into the lawyer is getting advice on things like transparency and particularly your contractual piece. And if you're not doing that, you know, maybe consider why and then of course consider us. And so look everybody, thanks very much. Thanks for joining us and look forward to seeing you in a month's time for the next Loach Time AI. Take care. - Thank you. [BLANK_AUDIO]

Podcast Summary

Key Points:

  1. The EU AI Act is being implemented in phases, with key dates including August 2, 2024 (entry into force), February 2, 2025 (prohibitions and AI literacy), and August 2, 2025 (GPAI obligations).
  2. The high-risk AI rules have been deferred due to delays in harmonized standards, but transparency obligations under Article 50 take effect on August 2, 2026, with a grace period for legacy systems until December.
  3. The Digital Omnibus Directive, finalized on July 27, reduced AI literacy from a mandatory obligation to an encouraged practice, though experts still recommend proactive compliance.
  4. Transparency rules require providers to ensure users know when they interact with AI systems, such as chatbots, by design, not just through disclaimers.
  5. Companies must clarify whether they act as "providers" or "deployers" under the AI Act, especially in white-labeling scenarios where rebranding a third-party AI system can make the company a provider.
  6. Early legal and regulatory involvement in AI procurement, including contract risk allocation and technical solutions, is critical to future-proofing deployments and avoiding unintended provider status.
  7. Ireland is ahead of other EU states in setting up its regulatory framework, with the Regulation of Artificial Intelligence Bill nearing enactment.

Summary:

The webinar, hosted by Barry and featuring John O'Connor of William Fry, discusses upcoming changes under the EU AI Act, particularly those effective August 2, 2026. The speakers outline the phased implementation: prohibitions and AI literacy began in February 2025, GPAI obligations in August 2025, and now transparency rules under Article 50 are arriving, with high-risk rules deferred due to missing harmonized standards. The Digital Omnibus Directive softened AI literacy to an encouraged practice, but the hosts stress proactive compliance.

Central to the discussion is transparency: AI systems interacting with people must clearly inform users they are machines, addressing both obvious cases like chatbots and subtle ones like voice assistants in cars. The Turing Test is referenced to illustrate how human-like AI has become, making disclosure essential. John emphasizes that organizations should not delay addressing high-risk requirements, as future-proofing contracts and technical designs now saves time later.

They highlight the importance of determining provider versus deployer status, warning that white-labeling AI systems can inadvertently make a company a provider, carrying direct obligations. Early integration of legal, technical, and risk teams in AI procurement is advised to manage risk allocation, warranties, and compliance, ensuring organizations avoid unintended liabilities and align with EU fundamental rights protections.

FAQs

The AI Act came into effect on August 2, 2024. Prohibitive rules and AI literacy obligations followed on February 2, 2025, and general-purpose AI model obligations on August 2, 2025. High-risk rules were delayed, with transparency obligations starting August 2, 2026.

The transparency provisions ensure people are informed when interacting with AI systems, such as chatbots, to avoid confusion with humans. They also address the challenge of identifying synthetic or AI-generated content, like deepfakes.

There is a grace period for legacy generative AI systems already on the market, allowing them until December to comply. However, new systems introduced after August 2, 2026, must comply immediately.

The Digital Omnibus Directive, finalized on July 27, 2025, reduced the AI literacy obligation from a positive requirement to merely encouraging AI literacy. Companies are no longer legally required to ensure AI literacy, but it is still recommended.

The high-risk AI regime was delayed because many EU countries were not ready, and harmonized standards needed for compliance benchmarking were not yet implemented. These standards are now expected by late 2025 or early 2026.

A provider is typically the developer of an AI system, but if you have an AI system developed by a third party and put it on the market under your own name or brand, you are also considered a provider. This means you bear the obligation to inform users they are interacting with AI.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.