欧盟《人工智能法案》正式公布
首套综合性 AI 法律按风险划定义务
欧盟在官方公报发布《人工智能法案》,建立禁止用途、高风险系统、透明度和通用 AI 模型的分层规则。
2024 年 7 月 12 日,《欧盟官方公报》刊出 Regulation (EU) 2024/1689,即常称的《人工智能法案》(AI Act)。它的标题很长,条文更长。法律不试图回答“人工智能究竟是什么”这类适合争论的问题;它必须决定另一批更沉重的事情:谁是提供者,谁在部署,什么用途不得进入市场,什么系统可以使用但必须留下记录,出了问题以后由谁拿出文件。
法案选择风险分层,而不是给所有模型套上同一副枷锁。一部分被认为不可接受的做法受到禁止,例如在特定条件下操纵人的行为、利用脆弱性,或进行某些社会评分和生物识别用途。医疗、就业、教育、关键基础设施、执法等领域中的特定系统可能被列为高风险;它们面对的是风险管理、数据治理、技术文档、日志、透明度、人工监督、准确性与网络安全等成套要求。另一些系统只承担较轻的透明度义务,许多普通用途并不因此成为“高风险 AI”。把整部法律缩成“欧盟禁止 AI”或“所有 AI 都是高风险”,会同时歪曲范围与比例。
立法过程跨越多年,生成式 AI 爆发后文本增补通用 AI 模型(GPAI)义务,说明法律试图追赶的对象在书写期间就已变形。对具有系统性风险的通用模型,法案要求更严格的评估、事故报告和风险缓解;对版权政策、训练内容摘要等,也设置相应义务。法案沿着提供者、部署者、进口商、分销商等角色逐项分配责任,远比一张“可以/不可以”清单复杂。相同技术放进不同用途、由不同主体操作,法律后果可以不同。官方公报日提供清晰的文献锚点,合规日历却要按条款的适用日期逐项排出:禁止性规则、通用模型义务和高风险系统要求各有时间表。所谓“欧盟已经监管 AI”,在现实里是一段持续数年的制度施工,而不是 7 月 12 日的一声号令。
法案的影响也越过欧盟边界。只要系统或其输出进入欧盟市场和使用场景,境外提供者便可能落入适用范围。企业于是不得不把原先留在伦理原则里的词,翻译成产品流程:风险属于哪一类,训练和验证数据从何而来,日志保存多久,人工监督究竟能否中止系统,限制有没有写进用户看得见的说明。合规变成工程与法务的共同项目,而不是公关页脚的一句话。高风险系统的附件定义、标准与指南会决定企业把产品往哪一类靠;游说与解释战争将围绕分类边界展开。
这部法律当然可能过重、过慢,也会在标准制定、执法和技术变化中遭遇解释困难。但它已经让一种含糊变得难以维持:风险要离开发布会结尾那页“安全承诺”,进入档案、职责和可追究的名字。机器仍以毫秒回答,制度只能一条一条写;慢并不天然正确,却是责任被逐项写清时留下的速度。读 AI Act,需要记住的不是口号,而是分层、角色、分阶段生效——以及每一层都可能被未来的修订继续拧紧或放松。
On 12 July 2024, the Official Journal of the European Union published Regulation (EU) 2024/1689—the Artificial Intelligence Act. The title is long; the articles are longer. Law does not try to settle “what AI really is,” a question suited to argument. It must decide heavier things: who is a provider, who deploys, which uses may not enter the market, which systems may be used only with records, and who must produce documents when something goes wrong.
The Act chooses risk tiers rather than one yoke for every model. Some practices judged unacceptable are prohibited—certain forms of behavioral manipulation, exploitation of vulnerabilities, social scoring, and biometric uses under specified conditions. Particular systems in medical care, employment, education, critical infrastructure, and law enforcement may be high-risk and face suites of requirements: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, and cybersecurity. Other systems carry lighter transparency duties; many ordinary uses do not become “high-risk AI.” Compressing the whole law into “the EU bans AI” or “all AI is high-risk” distorts both scope and proportion.
Years of drafting absorbed generative-AI shock by adding general-purpose AI (GPAI) duties—the object deformed while the text was written. GPAI models with systemic risk face stricter evaluation, incident reporting, and mitigation; copyright policies and summaries of training content carry related duties. The Act assigns roles—provider, deployer, importer, distributor—item by item, far more complex than a yes/no list. The same technique in different uses, operated by different actors, can produce different legal consequences. OJ publication is a bibliographic anchor; the real compliance calendar is clause-by-clause application dates. Prohibitions, GPAI duties, and high-risk requirements each have their own schedule. “The EU already regulates AI” is, in practice, years of institutional construction, not a single command on 12 July.
Effects also cross the EU border. Whenever a system or its output enters the EU market and use context, non-EU providers may fall within scope. Companies must translate words that once lived in ethics principles into product process: which risk class applies, where training and validation data come from, how long logs are kept, whether human oversight can actually stop the system, whether limits appear where users truly see them. Compliance becomes a joint project of engineering and legal work, not a sentence in a press-release footer. Annex definitions, standards, and guidance will decide how firms classify products; lobbying will orbit those borders.
The law may prove too heavy or too slow, and it will meet interpretation trouble in standards, enforcement, and technical change. It has already made one vagueness hard to sustain: risk must leave the closing “safety commitment” slide of a launch and enter files, duties, and names that can be held to account. Machines still answer in milliseconds; institutions can only write article by article. Slowness is not automatically right, but it is the speed left when responsibility is itemized. What is worth remembering about the AI Act is not a slogan but tiers, roles, phased application—and the fact that each layer may still be tightened or loosened by later revision.
展开完整事件档案人物、主题、模型与产品
- 人物
- —
- 模型
- —
- 产品
- —