Asean Business logo
SPONSORED BYUOB logo

EU’s new AI Act could add to compliance costs for Asean firms: industry players

Legislation is also likely to mark beginning of uneven regulatory approaches to technology that companies have to navigate

Sharanya Pillai
Published Mon, Jul 31, 2023 · 05:00 AM
    • The European Parliament voted overwhelmingly to move forward with the AI Act in June, spurring backlash from tech companies.
    • The European Parliament voted overwhelmingly to move forward with the AI Act in June, spurring backlash from tech companies. PHOTO: REUTERS

    UPCOMING legislation by the European Union (EU) to regulate artificial intelligence (AI) could spell new compliance requirements and costs for companies in South-east Asia, particularly those developing AI-powered services for the global market, industry players told The Business Times.

    First proposed in April 2021, the EU AI Act classifies AI systems into four risk levels: unacceptable, high, limited and minimal or no risk, with different regulations at each level. Generative AI tools, such as ChatGPT, also have disclosure requirements (see table).

    The European Parliament voted overwhelmingly to move forward with the AI Act in June. The new laws are expected to be approved as soon as end-2023, with implementation around 2025.

    Many are watching to see if it will have the same wide-reaching impact as when the EU introduced its landmark General Data Protection Regulation (GDPR). The law, which went into effect in 2018, forced companies all over the world to update their data privacy policies to remain compliant.

    Like the GDPR, the EU’s draft AI Act has an extraterritorial effect. This means it extends to non-EU companies developing AI systems for the EU market.

    The law would also apply where an AI system developed by a non-EU company is used to make a decision about an EU resident, said Lim Chong Kin, head of the telecommunications, media and technology practice at law firm Drew & Napier. “Technology is not constrained by geographical borders,” he noted.

    Goh Ser Yoong, head of compliance at Singapore-based startup Advance.AI, is monitoring the potential ramifications of the new legislation. One of the startup’s businesses is facial recognition technology, and biometric identification is classified as high risk under the EU AI Act.

    Singapore AI companies that operate in the EU or plan to expand there may have to step up investments into legal and compliance processes, obtaining regulatory licences and certification, as well as product research and development, he said.

    The act could also affect how companies do business with EU-headquartered multinational corporations that operate in South-east Asia. “Having to comply with stricter compliance and regulation from their client’s headquarters would result in longer turnaround times and business cycles,” Goh noted.

    Prapanpong Khumon, an adviser to Thailand’s Personal Data Protection Committee (PDPC), suggests that South-east Asian AI companies join industry bodies, such as Thailand’s AI alliance and Singapore’s AI Verify Foundation, to keep up with developments.

    “These regulations are not always easy to read; it takes time to actually digest. So the role of the association would (be to) help in digesting that,” said Khumon.

    Non-uniform regulation

    As more jurisdictions look at how to regulate AI, compliance could get more complicated. Thio Shen Yi, joint managing partner at TSMP Law Corp, noted: “Companies in Singapore and elsewhere will probably have to navigate an overlapping network of non-uniform regulation for years to come.”

    He flagged how the EU’s categorisation of AI risk itself is not “value neutral”, as not all countries agree on what is unacceptable, such as the matter of using AI for social scoring or real-time facial recognition.

    Many other jurisdictions are in the middle of developing their own AI governance frameworks. The Association of Southeast Asian Nations (Asean) is working towards guidelines on responsible AI use, to be released in 2024. Meanwhile, Singapore and Thailand have already introduced voluntary frameworks for the industry.

    Over in the Philippines, the trade and industry department is pushing for an AI ethics and governance framework, Leandro Aguirre, deputy commissioner of the Philippines’ National Privacy Commission, noted at a recent AI and data protection masterclass held at the Singapore Management University.

    A recent Reuters report highlighted that the EU has been lobbying Asian governments to follow the bloc’s lead in regulating AI, but that reception has been lukewarm, with officials from Singapore and the Philippines flagging fears of stifling innovation.

    Aguirre, who was speaking on a panel about the EU AI Act, cited how some observers predict that the current version of the EU’s AI Act could result in billions of dollars potentially being lost.

    “That’s not exactly something that the Philippines would want to lose out on… I think our approach will be different depending on economic and political considerations,” he said.

    While the EU AI Act is a “good starting point for conversations relating to AI governance, I don’t think we can really… just copy and paste it across different jurisdictions”, Aguirre added.

    Khumon of the Thai PDPC pointed out that Thailand may eventually take reference from the EU AI Act, just like how the GDPR became a “gold standard” for the country’s data protection regime. But it still remains to be seen if it will opt to introduce a mandatory model like the EU, or simply expand its voluntary framework or existing regulations.

    Countries ultimately “will take reference from each other” amid the growing global consensus on AI governance and ethics, said Drew and Napier’s Lim.

    New tech, age-old clashes

    Another battlefront for the EU AI Act is with tech companies. One sore point among tech executives is uncertainty over the disclosure requirements for generative AI. For instance, it is not clear to what level of precision generative AI companies would have to disclose copyrighted material in their training data.

    “Practically, how much detail would be necessary in the summary such that it is not too onerous on the developer, and would it lead to an increase in copyright infringement claims against such developers?” questioned Lim, adding that regulators may give more guidance on this in future.

    Many companies are also concerned about the broader economic impact. In June, over 150 executives from European companies, such as Airbus and Siemens, warned in a letter to the European Parliament that the AI Act could “jeopardise Europe’s competitiveness”.

    Before that, the chief executive of ChatGPT maker OpenAI threatened to leave the EU, although he later backtracked his comments.

    The clash between excessive regulation and freedom to innovate is an age-old one, points out TSMP’s Thio. “Bureaucracy is stable, but static. Innovation is progress, but messy, and full of unintended consequences. We’re going to make mistakes in either direction before we get it right,” he added.