European Parliament committees have backed draft changes that would place new safety, transparency and oversight duties on AI providers. The proposed rules reach foundational models behind generative AI, while also expanding restrictions on certain uses of AI and giving people new ways to challenge decisions that affect them.
The vote advances the Parliament’s position, but the legislation is still being negotiated. Civil society groups welcomed stronger protections while raising concerns about enforcement, migration-related uses and the discretion developers could have in classifying risk.
Foundational models would face duties before launch
The amendments would require providers of foundational models to carry out safety checks, adopt data governance measures and reduce risks before making their models available on the market. Providers would also be expected to consider foreseeable risks to health, safety, fundamental rights, the environment, democracy and the rule of law.
The draft adds resource and transparency requirements. Foundational model makers would have to work to reduce energy consumption and resource use, and register their systems in an EU database planned under the AI Act.
Generative AI providers, including services such as ChatGPT, would have to tell users when content is machine generated, apply adequate safeguards to generated content and provide a summary of copyrighted materials used to train their systems. The copyright provision drew criticism from the Irish Council for Civil Liberties’ Kris Shrishak, who argued it did not establish a firm position against companies using protected material without payment.
More uses could be banned or classed as high risk
MEPs backed an expanded list of prohibited AI practices, including restrictions involving facial recognition, predictive policing and emotion recognition. The amendments also broaden the areas that may count as high risk, covering potential harm to people’s health, safety, fundamental rights and the environment.
AI used to influence voters in political campaigns and recommender systems operated by larger social media platforms were also placed on the proposed high-risk list. For people affected by high-risk AI, the text would strengthen the ability to file complaints and seek explanations when decisions significantly affect their rights.
Digital rights group EDRi said the committee text incorporated many of its calls for stronger protections, including accountability and transparency obligations for those deploying high-risk systems. These would include fundamental rights impact assessments and ways for affected people to challenge AI systems.
But the group said the proposed protections still have gaps. It objected to the absence of a prohibition on AI used to facilitate illegal pushbacks or discriminatory profiling in migration control. EDRi also sought broader restrictions on location-based predictive policing and mass biometric surveillance, and questioned an exception for law enforcement in the proposed ban on retrospective public facial recognition.
Enforcement and exemptions remain contested
One contested change would let AI developers assess whether their own systems are significant enough to qualify as high risk. EDRi policy advisor Sarah Chander warned that this could weaken enforcement by giving developers influence over whether obligations apply.
Oversight would also involve a proposed role for an EU AI Office, alongside decentralized supervision by EU member states. Shrishak said amendments would allow regulators to conduct remote inspections, but raised concern that limits on access to AI source code could make investigations harder. He also warned that research exemptions might be exploited, particularly when companies describe their work as research or say they are developing components rather than complete systems.
The amendments include exemptions for research activities and AI components provided under open-source licenses, and support regulatory sandboxes where public authorities can test AI before deployment. The Free Software Foundation Europe argued that limiting the open-source exemption to micro-enterprises would make it difficult for large technology companies to use it as a loophole.
The Parliament’s position is not the final law
The Internal Market Committee and Civil Liberties Committee voted on some 3,000 amendments and adopted a draft negotiating mandate with 84 votes in favour, 7 against and 12 abstentions. A plenary vote to confirm the Parliament’s mandate was expected during the 12-15 June session, after which talks with the Council would begin.
Those negotiations could change the protections. EDRi warned that some member state governments might push to weaken limits on biometric surveillance, while pointing to Austria and Germany as countries that had expressed support for stronger protections. The committee vote sets out the Parliament’s direction; the final balance between AI oversight, fundamental rights and exemptions will depend on the next stage of the process.