The EU AI Act
The EU AI Act is the most significant AI regulatory development globally. Understanding it matters even for NZ and AU organisations — it affects any organisation with EU customers or operations.
Risk-based approach
The EU AI Act classifies AI systems by risk level and applies proportionate requirements. Unacceptable risk applications are prohibited (social credit scoring, real-time biometric surveillance in public spaces). High risk applications (AI in education assessment, employment, credit, healthcare, law enforcement) face the most extensive requirements.
High-risk requirements
High-risk AI systems must: maintain technical documentation, implement risk management systems, use high-quality training data, enable human oversight, be accurate and robust, include automatic logging, and provide transparency to users. Providers of high-risk systems must register with a central EU database.
General-purpose AI models
The Act includes specific provisions for GPAI models (like GPT-4 and Claude) — requiring transparency about training data, compliance with copyright law, and — for the most capable models — additional evaluation, adversarial testing, and incident reporting obligations.
Relevance for NZ organisations
The EU AI Act has extraterritorial reach — organisations placing AI systems on the EU market or whose AI systems affect EU users must comply regardless of where they are headquartered. NZ and AU regulators are watching the EU approach closely and are likely to develop similar frameworks.
The EU AI Act is imperfect, contested, and still being implemented. But it establishes a template for risk-based AI regulation that will influence frameworks globally — including New Zealand over the next five years.