Jose Felgueroso
Abogado | Attorney

  • Home
  • Blog


AI Legal Developments

info@josefelgueroso.com

Versión en español

2025-06-26

EU AI Act Guidelines: New Prohibitions and Compliance Requirements

The AI Act (Regulation (EU) 2024/1689) entered into force on August 1, 2024, establishing the foundational legal framework but with limited immediate obligations. In February 2025, the first substantive regulatory requirements became applicable, specifically the prohibition of AI systems with unacceptable risks and AI literacy obligations for providers and deployers of AI systems.

The European Commission has issued guidelines clarifying the scope and application of the AI Act. These guidelines detail prohibited artificial intelligence practices and provide comprehensive guidance on AI system definitions.

Prohibited AI Practices

The AI Act adopts a risk-based approach, categorizing AI systems by their potential harm to fundamental rights. Systems posing "unacceptable risks" are outright prohibited, including:

  • Manipulative Systems: AI that uses subliminal techniques or exploits vulnerabilities of specific groups (for example, age or disability) in a manner likely to cause significant harm.
  • Social Scoring:The use of AI to evaluate or classify people based on behavior or personal traits is prohibited when it results in unjustified or harmful treatment in unrelated contexts, whether by public or private entities.
  • Untargeted Facial Scraping: AI that builds facial recognition databases by scraping images from the internet or CCTV without targeting specific individuals.
  • Biometric Categorization: AI that categorizes people by biometric data to infer sensitive characteristics like race, beliefs, or sexual orientation (excluding lawful dataset labeling for law enforcement).
  • Real-Time Biometric ID in Public: Real-time remote biometric identification in public spaces for law enforcement, except in narrowly defined, authorized cases.
  • Emotion Recognition: Systems in workplaces and educational institutions, except for limited medical or safety applications
  • Predictive Policing: Individual criminal risk assessment based solely on profiling or personality traits

Compliance Requirements

Immediate Obligations

AI providers and deployers must ensure compliance from development through deployment. This requires:

  • Case-by-case assessment of each AI system against prohibited practices
  • Fundamental Rights Impact Assessment (FRIA) for high-risk systems, complementing existing data protection impact assessments
  • Prior authorization for any permitted use of real-time biometric identification systems

Legal Framework Integration

The AI Act complements existing EU legislation including the General Data Protection Regulation, consumer protection, and non-discrimination laws. Compliance with the AI Act does not negate obligations under other frameworks—organizations must maintain comprehensive legal compliance across all applicable regulations.

Enforcement and Penalties

Non-compliance with prohibited practices can result in severe penalties: fines up to EUR 35,000,000 or 7% of global annual turnover. The prohibitions apply immediately, but full enforcement mechanisms will become applicable on August 2, 2025.

Key Takeaways

  • Explicit Prohibitions: Certain AI systems are banned outright due to unacceptable risks to fundamental rights
  • Strict Controls: Biometric identification and emotion recognition face heavy restrictions with limited exceptions requiring prior authorization
  • Mandatory Due Diligence: Providers and deployers bear legal responsibility for compliance throughout the AI lifecycle
  • Layered Compliance: The AI Act adds to, rather than replaces, existing EU legal obligations

EU Copyright Framework for Generative AI: Rights and Obligations

The European Union Intellectual Property Office (EUIPO) has released a comprehensive May 2025 study examining the intersection of Generative AI (GenAI) and copyright law. The report, "Development of Generative Artificial Intelligence from a Copyright Perspective," addresses how existing copyright frameworks must adapt to accommodate AI training data usage and output generation.

Legal Framework Overview

The study identifies two key EU regulations governing AI and copyright interactions:

  • Copyright in the Digital Single Market (CDSM) Directive: Provides Text and Data Mining (TDM) exceptions with opt-out mechanisms
  • EU AI Act: Establishes obligations for AI developers to identify and comply with rights reservations

These frameworks create a dual system where rights holders can reserve their content from commercial AI training while AI developers face legal obligations to respect these reservations.

Rights Holder Protections

Opt-Out Mechanisms

Content creators can proactively protect their copyrighted works through various opt-out methods:

  • Legal measures: Unilateral declarations, licensing constraints, website terms and conditions
  • Technical solutions: Robots.txt files, TDMRep protocols, C2PA standards, specialized tools from Spawning.ai, Liccium's TDM.ai, and Valunode's ORDE

These opt-outs enable direct licensing opportunities and create new revenue streams from AI developers seeking legally-cleared training data.

AI Developer Obligations

Compliance Requirements

AI developers and deployers face specific legal obligations:

  • Rights Recognition: Must identify and comply with expressed opt-out declarations using state-of-the-art technologies
  • Transparency: Required to publicly disclose detailed summaries of content used for training general-purpose AI models
  • Legal Compliance: Non-compliance can result in significant liability, driving demand for licensed training data

Market Implications

The regulatory framework is fostering an emerging licensing market for AI training data. Rights holders can monetize their content through direct licensing agreements, while AI developers increasingly seek high-quality, legally cleared datasets to ensure compliance.

However, the absence of a single standardized opt-out system creates complexity for both rights holders and AI developers, who must navigate diverse legal and technical solutions.

Key Takeaways

  • Proactive Rights Management: Content creators must actively implement opt-out mechanisms to protect and monetize their copyrighted works
  • Developer Compliance: AI companies face legal obligations to respect rights reservations and maintain transparency about training data
  • Emerging Markets: New licensing opportunities are developing for legally cleared AI training datasets
  • Standardization Needs: The lack of unified opt-out standards requires stakeholders to adopt multiple technical and legal approaches

US Federal Court Rules AI Training Data Use Constitutes Copyright Infringement

A February 11, 2025, ruling from the U.S. District Court for the District of Delaware in Thomson Reuters Enterprise Centre GmbH and West Publishing Corp. v. Ross Intelligence Inc. has established significant precedent for AI training data copyright protection. The court granted summary judgment for Thomson Reuters, finding Ross Intelligence liable for direct copyright infringement of Westlaw's headnotes and rejecting Ross's fair use defense.

Case Background

Thomson Reuters, owner of the Westlaw legal research platform, sued competitor Ross Intelligence after Ross used Westlaw's copyrighted headnotes to train its AI legal search tool. The court found Ross infringed 2,243 headnotes and determined that Westlaw's headnotes and Key Number System are original works protected by copyright, despite summarizing public domain judicial opinions.

The court established actual copying by LegalEase (Ross's data provider) and found the copied content substantially similar to Westlaw's copyrighted material.

Legal Analysis

Fair Use Rejection

The court rejected Ross's fair use defense, emphasizing several critical factors:

  • Commercial Competition: Ross's AI directly competed with Westlaw in the legal research market
  • Non-Transformative Use: Converting copyrighted text into numerical training data does not automatically constitute transformative use
  • Market Impact: The use affected potential markets for AI training data licensing

The court distinguished this case from precedents allowing intermediate copying of computer code, noting that Ross's "non-generative AI" that "spits back relevant judicial opinions" served the same market function as the original work.

Copyrightability of Editorial Content

The ruling reinforced that editorial judgment and creativity in selecting, arranging, and synthesizing information from public domain sources can create copyrightable works. Westlaw's headnotes qualified for protection due to the "minimal degree of creativity" involved in their creation.

Practical Implications

For AI Developers

This decision creates immediate compliance obligations for AI companies:

  • Training Data Scrutiny: Developers must carefully evaluate copyrighted material used for AI training, especially competitor content
  • Licensing Requirements: Consider obtaining licenses for copyrighted training data to avoid infringement claims
  • Fair Use Limitations: Intermediate copying for AI training does not automatically qualify for fair use protection

For Content Creators

Rights holders gain strengthened protection for their copyrighted works:

  • Editorial Work Protection: Curated content based on public domain sources maintains copyright protection
  • AI Training Market: Potential licensing opportunities for AI training data
  • Enforcement Rights: Stronger position to pursue legal action against unauthorized AI training use

Key Takeaways

  • Editorial Creativity Protected: Synthesized content from public domain sources can qualify for copyright protection through minimal creative expression
  • Competitive Use Matters: AI systems competing directly with the original copyrighted work face heightened scrutiny under fair use analysis
  • Training Data Licensing: AI developers should proactively seek licenses for copyrighted training materials to avoid infringement liability
  • Limited Fair Use: Computer code precedents do not automatically extend to other content types used in AI training

TAKE IT DOWN Act: US Law Criminalizes AI-Generated Intimate Images

The TAKE IT DOWN Act (Public Law No. 119-12) became federal law on May 19, 2025, establishing comprehensive protections against nonconsensual intimate visual depictions. The Act specifically targets "digital forgeries"—AI-generated intimate images that are indistinguishable from authentic content—while creating new criminal penalties and mandatory platform removal processes.

Legal Framework

The Act amends Section 223 of the Communications Act of 1934 to establish federal criminal prohibitions against knowingly publishing nonconsensual intimate visual depictions, including:

  • Digital Forgeries: AI-generated intimate images created using software, machine learning, or artificial intelligence
  • Authentic Images: Real intimate visual depictions published without consent
  • Threats: Criminal liability for threatening to publish this type of content

Criminal liability applies when publication is not a matter of public concern and is intended to cause or actually causes psychological, financial, or reputational harm.

Platform Obligations

Notice-and-Removal Requirements

By May 19, 2026, "covered platforms" must implement comprehensive removal processes:

  • User-Friendly Reporting: Clear, conspicuous process for reporting nonconsensual intimate visual depictions
  • 48-Hour Removal: Content must be removed "as soon as possible, but not later than 48 hours" after valid notice
  • Duplicate Detection: Reasonable efforts to remove known identical copies

Enforcement Mechanisms

Non-compliance with removal obligations constitutes an unfair or deceptive act or practice violation enforceable by the Federal Trade Commission (FTC). The Act expands FTC jurisdiction to cover non-profit organizations for these violations.

Practical Implications

For Individuals

The Act provides victims with immediate legal remedies:

  • Criminal Protection: Federal prosecution available for perpetrators
  • Removal Rights: Direct pathway to request content removal from platforms
  • Threat Protection: Criminal liability extends to threats of publication

For Online Platforms

Covered platforms face significant compliance requirements:

  • Policy Review: Comprehensive evaluation of content moderation policies needed
  • Technical Capabilities: Systems must handle strict 48-hour removal deadlines
  • Legal Uncertainty: Potential conflicts with Section 230 immunity require careful navigation

Implementation Challenges

The Act leaves several key terms open to judicial interpretation, including the definition of "publish" and its interaction with existing legal frameworks. Platforms must prepare for potential legal challenges regarding:

  • Scope of Section 230 immunity protections
  • Coordination with existing civil rights of action under the Violence Against Women Act
  • Technical feasibility of 48-hour removal requirements

Key Takeaways

  • Comprehensive Coverage: Federal criminalization extends to both authentic and AI-generated nonconsensual intimate images
  • Strict Deadlines: Platforms must establish 48-hour notice-and-takedown processes by May 2026
  • FTC Enforcement: Non-compliance triggers federal trade practice violations with significant penalties
  • Legal Ambiguities: Key terms and interactions with existing laws may require judicial clarification

Sources

AI Act (Regulation (EU) 2024/1689)

Commission Guidelines on Prohibited Artificial Intelligence Practices (European Commission, 2025)

General Data Protection Regulation (GDPR)

Development of Generative Artificial Intelligence from a Copyright Perspective (EUIPO, May 2025)

Copyright in the Digital Single Market (CDSM) Directive

Thomson Reuters Enterprise Centre GmbH and West Publishing Corp. v. Ross Intelligence Inc. (U.S. District Court for the District of Delaware, February 11, 2025)

TAKE IT DOWN Act (Public Law No. 119-12) (May 19, 2025)