The European Parliament will endorse the regulatory brake on AI: "Leaving it to free will is not the solution"

The Eurochamber will ratify this Tuesday the Artificial Intelligence Act simplification package, which reduces administrative burdens for innovative companies, expands access to regulatory testing environments, and strengthens prohibitions against sexual deepfakes and AI-generated child abuse material.

7 minutes

20260318 EP 201724A LD2 0347 MEDIUM

20260318 EP 201724A LD2 0347 MEDIUM

Add DEMÓCRATA to Google

Ask FREN

Published

Last updated

7 minutes

Most read

Brussels wants to run over the simplification as well through the legislation that turned the European Union into a pioneering power in the regulation of Artificial Intelligence. The objective is to harmonize the application of the rules and correct what the institutions call “practical challenges” detected during the implementation of the regulatory framework. The European Parliament plans the definitive approval of this omnibus package this Tuesday, after negotiators reached a political agreement with the Twenty-Seven.

What the co-legislators are pursuing with this reform is, mainly, to reduce administrative burdens for companies, facilitate priority access to controlled testing environments, and adapt certain obligations to the operational reality of European companies. In parallel, the text reinforces some specific prohibitions, especially those related to the generation of non-consensual sexual content through Artificial Intelligence systems.

We have over-regulated Europe. We have prevented European companies from being able to pick up the gauntlet thrown by the United States and China regarding the latest AI models. For this reason, we depend on their infrastructure,” defended the rapporteur of the text, the Swedish popular MEP Arba Kokalari, during the debate held this Monday in the Plenary of the European Parliament. According to the parliamentarian, the reform will allow correcting some of the requirements she considers “exaggerated” of the first European regulation on Artificial Intelligence and offer a more favorable environment for entrepreneurship and technological innovation.

For his part, the Irish liberal MEP who spoke on behalf of his group appealed to address the issue from a transversal perspective and recalled that European legislators have both the obligation to regulate and the responsibility to “allow technology to flourish in Europe.” “Leaving AI to free will is not the solution,” he stated during the parliamentary debate.

More time for high-risk systems

One of the main points of friction during the negotiations was the implementation schedule for certain technical provisions. The European Parliament even proposed the elimination of what it considered excessive discretion by the European Commission, setting specific dates for the entry into force of several annexes to the regulation.

Finally, the Council accepted a good part of this position, establishing that certain obligations linked to high-risk systems will not begin to apply until December 2027 and August 2028, depending on the corresponding regulatory block. According to negotiators, this temporal margin will allow for the development of harmonized standards and offer greater legal certainty to both companies and supervisory authorities.

The decision also responds to the repeated demands of the technology sector, which had been requesting more time to adapt products, processes, and internal systems to requirements that, in many cases, still lack fully defined technical standards.

Reinforced prohibition of sexual deepfakes

The agreement, which will predictably be ratified this Tuesday, significantly expands the prohibitions related to systems designed to generate artificial explicit sexual images, commonly known as deepfakes.

The new wording prohibits not only systems specifically designed to produce this type of content, but also those capable of generating or manipulating realistic intimate material of identifiable individuals without their consent. Furthermore, the prohibition of tools intended to produce child sexual abuse material through Artificial Intelligence is explicitly incorporated.

However, the text includes a limited exemption for providers who can demonstrate that they have implemented effective security measures, such as specific filters, blocking mechanisms, or training systems aimed at rejecting requests that could reproducibly lead to this type of illicit content.

Negotiators believe that this approach will allow for the maintenance of technological innovation without sacrificing the protection of fundamental rights, especially in areas related to human dignity, privacy, and the protection of minors.

Advantages for mid-cap companies

One of the most relevant novelties affects so-called mid-cap companies, that is, those companies that have already surpassed the legal definition of SMEs but cannot yet be equated with large multinational corporations.

Once the new text enters into force, these companies will have priority access to the so-called regulatory sandboxes, in addition to being able to benefit from simplified technical documentation models.

Lawmakers argue that this measure will facilitate the growth of innovative companies, preventing the leap between the obligations applicable to SMEs and the requirements imposed on large companies from causing a "regulatory shock" that is difficult to bear in terms of administrative and bureaucratic costs.

The intention is to prevent business growth from becoming a regulatory penalty that ends up discouraging the expansion of European technological projects in advanced stages of development.

More flexible training for workers and users

The agreement also modifies the obligations relating to Artificial Intelligence literacy.

Providers and professional users will no longer have to limit themselves to "guaranteeing" a certain level of knowledge about these technologies. Instead, they will be obliged to take reasonable measures to promote the training and qualification of their staff.

These actions must be adapted to the technical and educational context of the affected workers and will be supported by practical examples that the European Commission will publish with the aim of facilitating compliance, especially among small and medium-sized enterprises.

In this way, the colegislators implicitly recognize that a uniform and rigid obligation could be ineffective or disproportionate for certain organizations. The new approach opts for a more flexible model, although it maintains the requirement for responsible and adequate training of personnel involved in the development or use of Artificial Intelligence systems.

Sensitive data to combat algorithmic bias

The interinstitutional negotiations also incorporated a provision that is particularly relevant from a technical and legal point of view.

The new article will allow, exceptionally, the processing of certain special categories of personal data—such as information relating to ethnic origin or religious beliefs—for the sole purpose of detecting, assessing, and correcting possible discriminatory biases present in Artificial Intelligence systems.

The novelty is that this legal basis will be extended to all AI models and systems, and not only to those classified as high-risk.

The processing of these data will be subject to strict guarantees. The information may only be used for this specific purpose and must be deleted once the identified bias mitigation process is concluded. Likewise, the regulations will expressly restrict the use of minors' data for these activities.

With this, Brussels seeks to strengthen the fight against algorithmic discrimination by providing developers with technical tools that allow them to verify that their models are sufficiently representative and do not generate unfair or biased results.

More power for the European AI Office

Another of the most significant structural changes affects the distribution of supervisory powers.

The European Commission's Artificial Intelligence Office will assume exclusive competence to supervise systems based on general-purpose models when the model provider and the system provider are the same entity or belong to the same business group.

This body will have expanded powers to conduct on-site inspections, request information under threat of financial penalty, and impose binding commitments on companies subject to supervision.

Brussels intends to concentrate the oversight of the most advanced and powerful models on a community-wide scale to ensure uniform application of the legislation and avoid divergent interpretations among the different national competent authorities.

According to community sources, this centralization will improve regulatory coherence and offer greater predictability to economic operators developing pan-European technologies.

"Ah, here we go again"

Tuesday's vote also takes place in a particularly sensitive context for European technological autonomy.

The recent suspension of the Fable 5 and Mythos 5 models by the company Anthropic, following a national security directive adopted by the United States, has revived the debate about the structural dependence that Europe maintains on the North American technological ecosystem.

The decision, which temporarily restricted international access to certain advanced Artificial Intelligence capabilities, caused numerous European companies, developers, and research centers to suddenly have their access to tools they had already integrated into their work processes interrupted.

For numerous observers, the episode demonstrates the extent to which European access to the most advanced technologies continues to be conditioned by decisions made outside the continent and subject to geopolitical considerations unrelated to the interests of the European Union.

Likewise, this move has opened a new front for reflection on the nature of technological power in the digital economy. While Brussels has concentrated much of its efforts on building a regulatory framework based on security, transparency, and fundamental rights, Washington has shown that effective control capacity also involves dominance over the infrastructure, foundational models, and commercial services that underpin the global Artificial Intelligence ecosystem.

Fearing that the United States will normalize similar restrictions on strategic technologies under increasingly broad national security criteria, the European Union faces growing pressure to accelerate its technological sovereignty strategy. The development of its own models, European advanced computing infrastructures, and open-source alternatives increasingly appears as a matter not only of economics but also of geopolitics.

In this context, the simplification of the Artificial Intelligence Act is presented as an attempt to balance two objectives that Brussels considers inseparable: maintaining European regulatory leadership in rights and security, while creating more favorable conditions for the development of a competitive technological ecosystem capable of reducing the community bloc's external dependence.

More key points, information and questions with FREN

AI-GENERATED CONTENT

What are the next steps in the parliamentary processing of the new European regulation on Artificial Intelligence after its approval in the European Parliament?

Next steps of the European AI Regulation after the European Parliament

Brief answer

After the approval of the European Artificial Intelligence Regulation (AI Act) in the European Parliament, the text enters its final phase of formal adoption and application. The key next steps are: the definitive and unchanged approval by the Council of the EU, its publication in the Official Journal of the EU, and entry into force 20 days later. From there, a staggered schedule opens: some obligations (such as prohibitions on high-risk uses) will begin to apply earlier, while the bulk of the regime for high-risk systems will have a transitional period of several months or years. Although it is a European regulation, its implementation will require Spain and the other Member States to adapt their administrative and regulatory organization to supervise and sanction its compliance.

1. Closing the European legislative process

1.1. Formal approval by the Council of the EU

The European Parliament has already adopted its final position on the AI Regulation, within the ordinary legislative procedure. The next institutional step is the formal approval by the Council of the European Union (the governments of the 27 Member States). At this stage, the content is no longer reopened if the text is the one agreed in the trilogue; the Council limits itself to confirming the political agreement. Once the Council formally adopts the Regulation, the legislative act will be considered definitively approved at the EU level.

1.2. Signature and publication in the Official Journal

After adoption by the Parliament and the Council, the regulation must be signed by the presidents of both institutions. Then, the Regulation is published in the Official Journal of the European Union (OJEU). That publication is the milestone that sets the date for the entry into force, which usually occurs 20 days after publication, unless a specific provision in the text states otherwise.

2. Entry into force and application schedule

2.1. Entry into force

A European Regulation like the AI one is directly applicable in all Member States once it has entered into force, without the need for transposition as with directives. However, the AI Act itself foresees a staggered schedule for the application of different obligations, to allow companies, administrations, and authorities to prepare.

2.2. Gradual application of obligations

Although the specific deadlines depend on the final text, the usual scheme in this type of regulation is that:

Absolute prohibitions (for example, certain uses of mass surveillance or behavioral manipulation, if included in the Regulation) apply relatively soon after entry into force.
• Obligations for high-risk AI systems (conformity assessments, data requirements, transparency, risk management, etc.) come into force after a longer transitional period, so that developers and users can adapt systems and internal processes.
• There may be specific deadlines for certain categories (general-purpose systems, foundational models, transparency obligations towards users, etc.).

In practice, this means that although the Regulation is legally valid shortly after its publication, the full regime will be rolled out progressively over the following years.

3. Implications and steps in Spain

3.1. Internal institutional and regulatory adjustments

Although the AI Act does not require a classic “transposition,” Spain will need to adopt a series of internal measures to apply it effectively. Among them, it is foreseeable:

• The designation or strengthening of competent authorities to supervise compliance with the Regulation, coordinate with the future European AI governance structure, and exercise sanctioning power.
• Possible adjustments in sectoral legislation (consumer protection, data protection, product safety, financial services, health, etc.) to ensure coherence with the new European framework and avoid overlaps or regulatory gaps.
• The development of guidelines, codes of conduct, and regulatory sandbox mechanisms to facilitate the adaptation of companies, administrations, and social organizations.

3.2. Space for Spanish parliamentary initiatives

From the point of view of parliamentary processing in Spain, once the European framework is closed, the following may be proposed:

Private members' bills from groups in the Congress or Senate seeking to complement the European Regulation (for example, regarding public procurement of AI systems, user rights, or promotion of responsible innovation).
• Possible government bills to organize the national regulatory architecture (authorities, interministerial coordination, additional sanctioning regime in areas left open by the Regulation).
Parliamentary oversight initiatives (hearings, questions, motions) to monitor Spain's position in the Council of the EU, the preparedness of our administrations, and the impact on strategic sectors.

These initiatives do not alter the content of the AI Act, which is decided at the European level, but they do condition how it is applied in Spain and what additional supports or safeguards are introduced nationally.

4. Monitoring and future review

Once in force, the European Commission must carry out monitoring of the impact of the AI Regulation and, likely, periodic evaluation reports. Based on those results, it could propose legislative reforms or adjustments in the future. In parallel, the European Parliament and national parliaments, including the Spanish Congress of Deputies, may promote debates and political resolutions on implementation, protection of fundamental rights, and the balance between innovation and regulation.

What are the competences and functions of the European Parliament in technological regulation according to EU legislation?

Competences of the European Parliament in technological regulation

Competences of the European Parliament in technological regulation

The European Parliament is, together with the Council of the EU, the central co-legislator in almost all technological regulation of the Union. Its competences derive from the EU Treaties and are embodied in the ability to approve, amend, or reject rules on the digital market, data protection, artificial intelligence, or cybersecurity. Additionally, it politically controls the European Commission, influencing the direction of legislative proposals in technological matters. However, it does not act alone but within an institutional system where it shares functions with the Commission and the Council.

Legal basis and role as co-legislator

The functions of the European Parliament in technology are mainly supported by the Treaty on the Functioning of the EU (TFEU). Most digital legislation is adopted through the ordinary legislative procedure (Article 294 TFEU), in which Parliament and the Council legislate on an equal footing. This includes key areas such as the functioning of the internal market (Article 114 TFEU), information society services, telecommunications, free movement of non-personal data, cybersecurity, or competition rules applied to digital platforms.

In practice, this means that no major technological regulation (such as rules on platforms, data, AI, or cybersecurity) can be approved without the agreement of the European Parliament. Parliament can introduce substantial amendments to Commission proposals and, in case of disagreement with the Council, activate conciliation committees. If no compromise is reached, the legislative act is not adopted.

Driving and shaping technological regulation

Although the formal legislative initiative corresponds to the European Commission, Parliament has several tools to influence the technological agenda:

First, it can approve own-initiative reports in which it calls on the Commission to present concrete proposals in areas such as artificial intelligence, data economy, cyber resilience, or platform governance. These reports, although not legally binding, carry strong political weight and usually precede legislative proposals. Second, in the legislative procedure itself, it can completely redirect the content of a draft regulation through amendments, introducing new rights, additional obligations for tech companies, or safeguards for users.

Additionally, through its specialized committees (for example, Industry, Research and Energy; Internal Market; Civil Liberties), Parliament holds public hearings with experts, companies, and civil society, which help shape standards on topics such as content moderation, algorithm use, biometric systems, or data governance.

Protection of fundamental rights and technological ethics

A distinctive function of Parliament in technological matters is as a guarantor of fundamental rights. Based on the EU Charter of Fundamental Rights, Parliament pushes to integrate guarantees of privacy, freedom of expression, algorithmic non-discrimination, and transparency into all digital rules. Thus, in the processing of technological regulations, it usually insists on:

Safeguards against mass surveillance or intrusive processing of personal data; obligations of explainability and human oversight in high-risk AI systems; transparency in content moderation and recommendation algorithms; and effective appeal and redress mechanisms for users affected by automated decisions.

Parliament also promotes ethical frameworks and principles for technology, requesting impact assessments on fundamental rights and democratic values, especially in the use of AI in security, justice, employment, or public services.

Control of the European Commission and regulatory enforcement

Beyond legislating, Parliament exercises political and democratic control over how the Commission designs and applies technological regulation. It can:

Submit oral and written questions to the Commission and the Council about the application of digital rules, preparation of new delegated or implementing acts, and the actions of European agencies linked to technology. Approve resolutions criticizing or supporting certain regulatory directions, for example, on international data transfer agreements or cybersecurity rules for critical infrastructures. And hold hearings and oversight of commissioners responsible for the digital agenda, conditioning their appointment or continuity.

In the area of delegated and implementing acts, which develop technical aspects of technological laws, Parliament can oppose delegated acts if it considers they exceed the mandate given by the legislator or violate the balance reached in the base text.

Budget, programs, and digital industrial policy

Parliament also participates in defining and approving the EU budget and major funding programs linked to digital transformation, under co-decision with the Council. This allows it to direct resources towards research in emerging technologies, deployment of digital infrastructures, support for innovative SMEs, or development of cybersecurity capabilities.

Through the approval of multiannual financial frameworks and specific programs, Parliament influences European technological industrial policy, promoting objectives such as digital sovereignty, boosting semiconductors, European cloud computing, or digital training of citizens.

Limits and coordination with Member States

Despite its central role, Parliament's competences are limited by the general distribution of EU powers. Areas such as education, health, or national security remain largely the competence of the States, so the European Parliament's capacity in technology is channeled mainly through the internal market, data protection, consumer protection, competition, and trade policy. The detailed implementation of technological regulation is largely carried out at the national level, where state parliaments and governments (such as the Spanish Congress and Government) adapt and apply European rules, within a framework where the European Parliament sets the common legislative bases.

What legal requirements must companies meet to access regulatory sandboxes in the European Union?

Legal requirements to access regulatory sandboxes in the EU

Summary answer

The European Union's regulatory sandboxes are not harmonized by a single law but share common legal requirements: the company must be duly incorporated, comply with basic regulations (commercial, tax, labor, and data protection), demonstrate that its project is innovative, and provide a controlled testing plan that minimizes risks for consumers and the financial system. Additionally, a viable business model, appropriate governance and internal controls, and the capacity to exit the sandbox (exit plan) are required.

Many sandboxes focus on financial and digital services (fintech, insurtech, crypto-assets, AI, data), so it is also usually required to identify the applicable sectoral regulation and possible breaches to be tested under supervision (for example, financial license requirements, PSD2, MiFID, DORA, etc.). Finally, authorities require transparency: the company must accept intensive supervision, report incidents, and generally comply with the selection criteria, deadlines, and conditions that each national or European supervisor publishes in its calls.

1. General framework of sandboxes in the EU

In the European Union, sandboxes have mainly developed in regulated sectors (especially financial and digital) as a response to rapid technological innovation. The European Commission has promoted this approach in several communications and sectoral frameworks, but the concrete structure is usually in the hands of national authorities (central banks, securities supervisors, data authorities, etc.).

This means there is no “single European sandbox license”: each country or authority defines its criteria, although they converge on a central idea: allowing innovative projects to be tested in a controlled environment, with partial derogations or flexible interpretations of regulations, in exchange for enhanced guarantees for participating users and close monitoring by regulators.

2. Basic legal requirements of the company

In almost all sandboxes, the entity is required to:

a) Be legally incorporated and up to date with its basic obligations. Proof of registration in the relevant Member State's commercial register is usually requested, identification of directors and, if applicable, significant shareholders. Additionally, it is verified that the company is current on tax and social security obligations and is not disqualified from operating in the sector.

b) Comply with horizontal EU regulations. Although the sandbox allows flexibility in sectoral rules, structural norms are not suspended such as:

• Data protection regulations (General Data Protection Regulation – GDPR).
• Basic consumer protection rules (Consumer Directives, unfair terms, information rights).
• Anti-money laundering regulations, where applicable.
• Competition rules and prohibition of collusive practices.

c) Demonstrate good repute and minimum solvency. In financial areas, authorities usually request information on the background of directors, absence of serious sanctions, and sufficient financial resources to support the test without risking participants.

3. Requirements related to the innovative project

The central piece of access to the sandbox is the specific project to be tested:

a) Innovative character and value proposition. The company must demonstrate that the solution introduces relevant innovation (technological, business model, or process) and generates potential benefits for consumers, competition, financial inclusion, regulatory efficiency, sustainability, etc. Purely commercial projects without substantive novelty are usually excluded.

b) Regulatory need for the sandbox. One of the most important criteria is to justify that the initiative faces regulatory barriers or uncertainties that prevent its deployment under ordinary rules. The regulator wants to clearly see which articles or requirements of sectoral regulation generate doubt or obstacle, and how the sandbox can help clarify or adjust that regulation.

c) Concrete testing plan and risk control. A detailed plan is required where the following are defined:

• Test objectives and regulatory questions to resolve.
• Limited scope (number of users, volume of operations, duration).
• Risk mitigation measures for participants (prior information, loss limits, complaint mechanisms).
• Success or failure indicators and action scenarios in case of incidents.

4. Governance, compliance, and user protection

Beyond the business idea, authorities value the company's capacity to manage regulatory compliance:

a) Governance and compliance structure. It is usually required that the company identifies a project manager, a compliance contact, and, if applicable, a data protection officer. There must be a minimum system of internal control, operation recording, and incident management.

b) Consumer protection and transparency. It is mandatory to explain how users will be informed that they participate in a pilot, what risks they assume, what compensation mechanisms exist, and how their rights are guaranteed (data, complaints, withdrawal, etc.).

c) Technological security. In digital sandboxes, aspects such as information security, cybersecurity, business continuity, and, where applicable, compliance with frameworks like DORA (digital operational resilience) are reviewed when appropriate. Although the sandbox may soften some formal requirements, a level of technological risk incompatible with the minimum protection required by EU law is not allowed.

5. Commitments during and after the sandbox

Finally, to be admitted, the company must accept a series of commitments:

a) Cooperation and continuous reporting. The entity commits to sharing data, results, and lessons learned with the authority. This includes rapid incident notification, periodic reports, and access to technical documentation.

b) Exit plan. There must be a clear scenario for when the pilot ends: continuity under an ordinary license, adaptation of the model to fully comply with regulation, or orderly closure of the project guaranteeing users' rights.

c) Acceptance of limits and possibility of early termination. The authority usually reserves the right to interrupt the experiment if it detects disproportionate risks or breaches. The company must accept these conditions as part of the sandbox's legal framework.

Since I am not an assistant specialized in all European regulations but in political and regulatory context (mainly Spanish), for specific requirements of a particular sandbox (for example, that of a financial or data supervisor of an EU country), it is necessary to consult the regulatory bases and calls published by each national or European authority.

Play

Test your knowledge with FREN!

How much do you know about this topic? Answer the following 3 questions.

What is one of the main objectives of the European regulatory reform on Artificial Intelligence?

Question 1 of 3

What prohibition is reinforced in the new European regulatory framework on AI?

Question 2 of 3

What measure is introduced to combat biases in Artificial Intelligence systems?

Question 3 of 3

Hola, soy Fren. ¿Cómo te ayudo?