What changes with the new EU AI law: relief for companies and new digital prohibitions

Brussels completes the processing of the new simplification package that reduces administrative burdens for tech SMEs, strengthens control over high-risk systems, and prohibits deepfakes, while the Commission centralizes supervision and accelerates testing spaces for digital innovators.

7 minutes

P 069379 00 13 02 HIGH 922483

P 069379 00 13 02 HIGH 922483

Add DEMÓCRATA to Google

Ask FREN

Published

Last updated

7 minutes

Most read

As dawn broke, negotiators from the European Parliament, the Council, and the Commission managed to close the agreement on the new community simplification package regarding Artificial Intelligence services. The legislators' objective was to streamline the implementation of the new digital legislation so that small businesses do not have to face enormous administrative burdens, without renouncing the framework of guarantees that the European Union considers essential to protect fundamental rights and reinforce legal certainty in the community digital market.

“With simpler and more innovation-friendly regulation, we facilitate innovation without compromising safety,” celebrated the community technology lead, Vice-President Henna Virkkunen. From the Government of Spain, Secretary of State María González Veracruz stated in an interview with Demócrata that “what is being experienced with deepfakes, minors on social media, and content manipulation proves us right in that regulation is essential,” also calling for the development of the entire “democratic shield” that “we have launched in Europe.”

The agreement represents one of the most relevant regulatory advances of recent months within the community strategy to consolidate a European digital ecosystem based on public supervision, algorithmic transparency, and citizen protection against abusive uses of Artificial Intelligence. Brussels thus aims to combine the boost to technological competitiveness with a reduction in bureaucratic barriers that particularly affect startups, SMEs, and mid-cap companies.

Protection against abuse and illicit content

Among the main novelties is the specific prohibition within the AI Law against those practices capable of generating non-consensual intimate sexual content or child sexual abuse material, including applications known as "deepfake" or "nudification" apps. This measure, driven by the Twenty-seven and supported from the outset by the European Parliament, aims to directly protect "dignity and fundamental rights against abuses generated by AI".

European institutions consider that the rise of increasingly accessible generative technologies has increased the risk of fraudulent use of manipulated images and videos, especially against women and minors. The new regulatory framework therefore reinforces the capacity of national and community supervisors to act against platforms or providers that allow such illicit uses.

Likewise, the three institutions have agreed to establish fixed deadlines and progressive calendars to ensure that technical standards and support tools are available before the new obligations become fully enforceable. In this way, Brussels seeks to avoid legal uncertainty or scenarios of unequal application among Member States.

For example, rules related to biometrics, education, or employment —sectors considered high-risk within the European Regulation— will be mandatory starting December 2, next year. The Commission considers it a priority to strengthen supervision in areas where algorithms can directly affect labor rights, educational opportunities, or automated decisions with relevant social impact.

The rules applicable to Artificial Intelligence systems integrated into products such as elevators, toys, or industrial machinery will begin to apply in August 2028. Meanwhile, the obligations for detecting and labeling AI-generated content will come into effect from December of this year. All providers of existing systems on the market will have until next February to adapt to the new transparency requirements.

Less bureaucracy for SMEs and medium-sized companies

One of the main political objectives of the agreement was to prevent business growth from leading to a disproportionate regulatory burden. Therefore, the regulatory privileges initially foreseen for small and medium-sized enterprises will also be extended to small mid-cap companies.

This will involve the introduction of simplified technical documentation, through specific forms drawn up by the European Commission, quality management systems proportional to the size of the company and special consideration of the economic viability of companies when imposing possible administrative sanctions.

The community institutions argue that this reform will allow accelerating European innovation without weakening the supervisory framework. The objective is to prevent only large technology multinationals from having the capacity to comply with regulatory requirements, thus favoring a more competitive and balanced ecosystem within the digital single market.

With the new legal text, the EU executive's AI Office will assume greater supervisory powers, centralizing part of the control to avoid regulatory fragmentation within the European market. It will have exclusive competence over AI systems based on general-purpose models when the model and the system belong to the same provider.

Furthermore, it will supervise Artificial Intelligence integrated into very large online platforms or search engines and will be able to carry out pre-market conformity assessments for certain systems considered high-risk. Brussels thus seeks to strengthen the EU's executive capacity in the face of the sector's growing technological complexity.

Regulatory sandboxes and support for innovation

The European Commission also wants to facilitate access to controlled testing spaces, known as regulatory sandboxes, so that innovative providers can experiment with their solutions under real conditions before their definitive market launch.

On this line, a European Union-scale sandbox will be created, managed directly by the AI Office and operational within two years. The objective is to offer a safe testing environment that allows for the reduction of regulatory adaptation costs and the acceleration of the development of emerging European technologies.

In the same way, the horizontal obligations that imposed on companies the mandatory training of all their personnel in AI have been eliminated. From now on, it will be the responsibility of the Commission and the Member States to promote digital and technological literacy through specific training and awareness programs.

The processing of data intended to detect and correct biases in Artificial Intelligence systems will be permitted, although subject to stricter conditions of supervision and proportionality. Brussels considers this point to be fundamental to guarantee more transparent and less discriminatory algorithms.

Furthermore, those system providers in high-risk areas who consider that their tools should not be classified as such —by being limited to narrow or procedural tasks— will no longer be obliged to register in the European database, although they will still have to document their assessment internally and keep it available to the competent authorities.

Data Treatment and Governance

The European Commission also intended to repeal the Regulation on the Free Flow of Non-Personal Data, the Data Governance Act, and the Open Data Directive with the aim of harmonizing rules and simplifying legal obligations. Regarding data governance and intermediation services, Brussels proposes several far-reaching changes.

Data Brokerage Services

The mandatory notification regime for data intermediation service providers will be transformed into a voluntary registration system aimed at fostering trust. Likewise, the legal separation requirement between activities will be replaced by a functional separation, allowing for more sustainable business models adapted to the reality of the European market.

Re-use of public sector data

Public administrations will be able to establish higher charges or special conditions for the reuse of data by very large companies, especially gatekeepers designated under the DMA. The objective is to protect competition and preserve opportunities for smaller companies within the European digital ecosystem.

“It guarantees legal certainty and a smoother, more harmonized application of the rules across the Union, strengthening digital sovereignty and the overall competitiveness of the EU,” stated after Wednesday’s meeting the Cypriot Deputy Minister of European Affairs, Marilena Raouna, who also highlighted that the agreement “clearly demonstrates the capacity of the European institutions to act quickly and fulfill their commitments.”

According to the presidency of the Council of the European Union, this pact "represents the first achievement of the 'One Europe, One Market' roadmap, agreed by the three institutions last week within the foreseen deadline".

Unification of Incident Notifications

Another of the pillars of the reform involves the introduction of a single European entry point so that entities can comply with their incident notification obligations under multiple Community legal frameworks.

The Commission's philosophy is based on the principle of "notify once, share with many", significantly reducing the administrative burden and avoiding regulatory duplication between different national and European authorities.

In this way, the European Union Agency for Cybersecurity will be in charge of developing and maintaining this centralized notification system. The mechanism will be mandatory for incidents regulated under the NIS2 Directive, the GDPR regarding data breaches, DORA, the eIDAS Regulation on digital identity, and the CER Directive on the resilience of essential services.

Within the Community Executive, estimates are being handled that foresee savings of at least 1 billion euros annually for the affected companies, in addition to another 1 billion in one-time adaptation costs. Brussels calculates that the aggregate impact of these measures could reach at least 4 billion euros in accumulated savings before 2029, while at the same time strengthening European competitiveness in the technological and digital sphere.

More key points, information and questions with FREN

AI-GENERATED CONTENT

¿Cuál es el proceso parlamentario que debe seguir la nueva Ley de Inteligencia Artificial de la UE antes de su entrada en vigor definitiva?

Proceso parlamentario y jurídico del Reglamento de Inteligencia Artificial de la UE antes de su entrada en vigor definitiva

El Reglamento de Inteligencia Artificial de la Unión Europea (AI Act) sigue un proceso legislativo ordinario en las instituciones europeas: primero es aprobado por el Parlamento Europeo y el Consejo de la UE, luego se publica en el Diario Oficial de la Unión Europea (DOUE) y entra en vigor en la fecha establecida. Al ser un reglamento, es de aplicación directa en todos los Estados miembros, pero España debe adoptar medidas internas para su implementación efectiva, como la creación de autoridades de supervisión y la adaptación de normativas nacionales relacionadas.

Fases en las instituciones europeas

El AI Act es propuesto por la Comisión Europea y debe ser aprobado tanto por el Parlamento Europeo como por el Consejo de la UE mediante el procedimiento legislativo ordinario, que incluye debates, enmiendas y votaciones hasta alcanzar un texto común. Una vez aprobado, se publica en el DOUE, lo que le otorga validez jurídica en toda la UE. El reglamento entra en vigor en la fecha que indique el propio texto, normalmente 20 días después de su publicación, salvo disposición contraria.

Aplicación directa y margen para adaptación nacional

Como reglamento, el AI Act no requiere transposición formal a la legislación nacional, pero sí puede necesitar desarrollos normativos complementarios en España. Esto incluye la aprobación de normas técnicas, procedimientos administrativos, sanciones y la designación o creación de autoridades nacionales de supervisión. Además, puede ser necesario modificar leyes sectoriales para armonizarlas con el nuevo marco europeo.

Pasos concretos en España

El Gobierno español debe coordinar la evaluación y planificación de la implementación del AI Act, elaborando normativa de desarrollo y adaptando leyes nacionales cuando sea necesario. Las Cortes Generales participan si se requieren cambios legislativos, y se debe coordinar con las Comunidades Autónomas en materias de su competencia. También es imprescindible crear o designar autoridades de supervisión y establecer mecanismos de formación y control para garantizar el cumplimiento efectivo del reglamento.

Resumen

En síntesis, el AI Act entra en vigor automáticamente tras su publicación en el DOUE, pero su aplicación efectiva en España requiere actuaciones internas: desarrollo normativo, adaptación de leyes, creación de autoridades de supervisión y coordinación institucional, asegurando así una implementación adecuada en el contexto español.

¿Cuáles son las competencias y trayectoria política de Henna Virkkunen dentro de la Comisión Europea?

Competencias y trayectoria política de Henna Virkkunen en la Comisión Europea

Henna Virkkunen es una política finlandesa de referencia en la Unión Europea, actualmente vicepresidenta ejecutiva de la Comisión Europea para la Soberanía Tecnológica, la Seguridad y la Democracia. Su mandato, iniciado en diciembre de 2024, la sitúa al frente de la estrategia europea en innovación digital, ciberseguridad y defensa de los valores democráticos. Antes de su cargo en la Comisión, Virkkunen fue eurodiputada durante una década, con una trayectoria centrada en tecnología, industria y derechos digitales.

Competencias actuales en la Comisión Europea

Como vicepresidenta ejecutiva, Henna Virkkunen lidera áreas clave para el futuro digital y la seguridad de la UE:

  • Soberanía Tecnológica: Impulsa la innovación en inteligencia artificial (IA), coordina el European AI Research Council, supervisa la política única de cloud, y lidera el EU Cloud and AI Development Act. Es responsable del plan a largo plazo para chips cuánticos y de la Digital Networks Act para garantizar redes seguras y la consecución de los objetivos de la Digital Decade 2030 (Comisión Europea).
  • Seguridad: Coordina la protección de infraestructuras críticas (como cables submarinos), refuerza la ciberseguridad en plataformas digitales y comercio electrónico, y combate amenazas híbridas y ciberataques.
  • Democracia: Defiende la justicia y las libertades fundamentales, lucha contra el ciberacoso y la manipulación en redes sociales, y promueve la equidad digital a través de iniciativas como el Digital Fairness Act (Demócrata).

En sus primeros meses, ha anunciado inversiones de 200.000 millones de euros en fábricas de IA, ha visitado centros de referencia como el ICFO en España y ha impulsado la implementación del AI Act y el DSA (ICFO, La Ecuación Digital).

Trayectoria política en la Unión Europea

Virkkunen fue eurodiputada por Finlandia (2014-2024) en el Grupo del Partido Popular Europeo (PPE), participando en comisiones clave:

  • Industria, Investigación y Energía (ITRE): Políticas industriales, I+D y energía.
  • Transporte y Turismo (TRAN): Desde 2021.
  • Comisión PEGA: Investigación sobre el uso de software espía como Pegasus, mostrando su compromiso con la seguridad y la democracia.
  • Participación en la Comisión de Derechos de las Mujeres e Igualdad de Género y en la Delegación para las Relaciones con el Parlamento Panafricano en 2024 (Parlamento Europeo).

En el ámbito nacional, fue ministra de Educación, Administración Pública y Transporte en Finlandia antes de su salto a la política europea (Wikipedia).

Relevancia y posicionamiento

Virkkunen es reconocida por su enfoque estratégico en la autonomía tecnológica europea, la regulación equilibrada y la protección de la democracia digital. Ha sido protagonista en debates sobre la seguridad de las infraestructuras críticas, como la advertencia sobre la participación de Huawei y ZTE en proyectos sensibles, y ha defendido la reducción de la dependencia de proveedores de alto riesgo (Demócrata).

Su liderazgo es clave para la agenda tecnológica de la Comisión Europea bajo la presidencia de Ursula von der Leyen, con un mandato hasta 2029 que será determinante para la soberanía digital y la seguridad europea.

Fuentes adicionales y eventos destacados
¿Qué iniciativas legislativas ha impulsado Henna Virkkunen en materia de inteligencia artificial y ciberseguridad? ¿Cómo ha influido Henna Virkkunen en la regulación europea sobre proveedores tecnológicos de alto riesgo como Huawei? ¿Qué impacto ha tenido la política de soberanía tecnológica liderada por Virkkunen en la industria española?

¿Qué normativa previa regulaba la inteligencia artificial en la Unión Europea antes de la aprobación de esta ley?

Normativa previa sobre inteligencia artificial en la Unión Europea antes de la nueva ley

Antes de la aprobación de la nueva ley específica sobre inteligencia artificial (IA) en la Unión Europea, no existía una normativa única y específica que regulara de manera integral la IA. Sin embargo, la UE contaba con un marco normativo general que afectaba indirectamente al desarrollo y uso de la IA, principalmente a través de regulaciones sobre protección de datos, derechos fundamentales y responsabilidad civil. Estas normativas proporcionaban ciertas garantías y límites, pero no abordaban de forma específica los riesgos y oportunidades asociados a la IA.

Principales normativas aplicables antes de la ley de IA

Las principales normativas que incidían en la regulación de la inteligencia artificial en la UE antes de la nueva ley eran:

  • Reglamento General de Protección de Datos (RGPD): El RGPD (Reglamento (UE) 2016/679) establecía obligaciones sobre el tratamiento de datos personales, transparencia, derecho a la explicación en decisiones automatizadas y protección de los derechos de los ciudadanos frente a sistemas automatizados.
  • Directiva sobre responsabilidad por productos defectuosos: La Directiva 85/374/CEE regulaba la responsabilidad civil por daños causados por productos defectuosos, aplicable también a sistemas de IA en la medida en que se consideraran productos.
  • Directiva sobre comercio electrónico: La Directiva 2000/31/CE regulaba aspectos de los servicios digitales, incluyendo la responsabilidad de los intermediarios y proveedores de servicios en línea.
  • Cartas y tratados sobre derechos fundamentales: La Carta de los Derechos Fundamentales de la UE y el Tratado de Funcionamiento de la UE establecían principios generales de protección de derechos humanos, privacidad y no discriminación, relevantes para el desarrollo y uso de la IA.
Limitaciones del marco previo

Este marco normativo previo no abordaba de manera específica los riesgos éticos, de seguridad y de transparencia propios de la IA, ni establecía obligaciones diferenciadas según el nivel de riesgo de los sistemas. Por ello, la Comisión Europea impulsó la elaboración de una ley específica para la IA, que finalmente fue aprobada para cubrir estos vacíos y establecer un marco armonizado en toda la Unión.

Conclusión

En resumen, antes de la nueva ley de IA, la regulación en la UE se basaba en normativas generales sobre protección de datos, responsabilidad civil y derechos fundamentales, pero carecía de una regulación específica y adaptada a los desafíos de la inteligencia artificial.

¿Cuáles son las principales novedades que introduce la nueva ley de inteligencia artificial de la UE? ¿Cómo afecta la nueva regulación europea de IA a las empresas españolas? ¿Qué posición ha defendido España en las negociaciones sobre la ley europea de inteligencia artificial?

Play

Test your knowledge with FREN!

How much do you know about this topic? Answer the following 3 questions.

¿Qué práctica prohíbe específicamente la nueva Ley de Inteligencia Artificial de la UE?

Question 1 of 3

¿Qué objetivo busca la normativa comunitaria respecto a las pequeñas y medianas empresas?

Question 2 of 3

¿A partir de qué fecha serán obligatorias las normas de la ley de IA para sectores de alto riesgo como biometría, educación y empleo?

Question 3 of 3

Hola, soy Fren. ¿Cómo te ayudo?