Analyzing critical legal trends and developments across data, cyber, AI and digital regulations from around the world and beyond borders

A key step towards adoption of the EU AI Act was reached last Friday as the draft text received unanimous approval from the European Council’s main preparatory body. There are further votes to follow before the Act is adopted, but it’s looking likely that the final vote will take place in April and some substantive provisions of the Act could be in force soon after that, possibly by the end of the year. We set out below how the draft text has developed since political agreement was announced in December 2023, and the remaining steps in the legislative process.

What does the Act say, and what has changed in the latest draft?

The Act has been some time in the making, with hundreds of amendments tabled during the legislative process. There has been intense debate on many aspects of the Act and the balance it strikes between regulating AI and facilitating innovation, recently focused around whether and how the Act should regulate AI foundation models, the advanced generative AI models that are trained on large sets of data with the ability to learn and perform a variety of tasks, as well as over the use of AI in law enforcement.

In December 2023 the EU Parliament, Council and Commission announced political agreement on the Act, and you can find a summary of the key provisions agreed in December 2023 in our post here EU reaches agreement on landmark AI regulation. EU legislators have since been working to reflect that political agreement in a final draft of the Act, ready for votes in the European Council and Parliament. A number of member states including Germany and France have been critical of the resulting agreement, but ultimately all member states voted in favour at a key meeting of the European Councils’ Committee of the Permanent Representatives of the Governments of the Member States to the European Union (COREPER).

The final compromise text has been published following the COREPER vote. The published text reflects the political agreement announced in December, but includes the detailed drafting on critical questions like the definition of an in-scope AI system. Some key developments include the following:

  • A new provision has been added to the main Act, obliging the Commission to develop guidelines on the practical implementation of the Act, including:
    • How the obligations on high risk AI systems should be applied
    • The AI practices prohibited under Article 5 of the Act
    • The practical implementation of provisions relating to “substantial modification” of an AI system, and of the transparency obligations imposed on certain AI systems and on general purpose AI systems
    • The relationship between the AI Act and other relevant EU law, including as regards consistency in their enforcement
    • The application of the definition of an AI system
  • The drafting of the recitals was not discussed in detail during the political negotiations. Recitals provide important guidance on key issues – including the definition of an AI system, what it means for an AI system to “materially influence” decision making, and how prohibited use cases should be interpreted – and have been updated in the published text.

What’s next?

The Act still needs to be formally approved by both the European Council and European Parliament. With political opposition falling away in advance of the COREPER vote, both approvals look more likely, but there is no guarantee until the final votes are in. The final European Parliament vote is likely to take place by April and the approved text will need to go through final checks before its official publication. The first substantive provisions of the Act (requiring phase out of prohibited AI systems) could apply 6 months after official publication.

So there are still a few more hurdles to clear – keep an eye on Connect on Tech for further updates.


Baker McKenzie’s recognized leaders in AI are supporting multinational companies with strategic guidance for responsible and compliant AI development and deployment. Our industry experts with experience in technology, data privacy, intellectual property, cybersecurity, trade compliance and employment can meet you at any stage of your AI journey to unpack the latest trends in legislative and regulatory proposals and the corresponding legal risks and considerations for your organization. Please contact a member of our team to learn more.

Author

Vin leads our London Data Privacy practice and is also a member of our Global Privacy & Security Leadership team bringing his vast experience in this specialist area for over 22 years, advising clients from various data-rich sectors including retail, financial services/fin-tech, life sciences, healthcare, proptech and technology platforms.

Author

Karen Battersby is Director of Knowledge for Industries and Clients and works in Baker McKenzie's London office.

Author

Elisabeth is a partner in Baker McKenzie's Brussels office. She advises clients in all fields of IT, IP and new technology law, with a special focus on data protection and privacy aspects. She regularly works with companies in the healthcare, finance and transport and logistics sectors.

Author

Julia's practice encompasses a range of contentious and non-contentious aspects of IP law including copyright, trade marks, designs and passing off, with a particular focus on contentious IP issues. Julia has extensive experience in IP enforcement and brand protection work, and has acted before the High Court, Court of Appeal, Supreme Court and CJEU.

Author

Dr. Lukas Feiler, SSCP, CIPP/E, heads the Firm’s Commercial, Data, IPTech and Trade practice in Vienna. He is specialized in technology litigations, focusing on regulatory and civil disputes in the areas of data protection, AI, and platform regulation. Building on his litigation expertise, Lukas advises clients on strategic compliance issues in the areas of cyber security, data protection, and AI. Lukas also leads the AI Desk in Vienna and is a member of the Firm’s EMEA Data Privacy & Security leadership team. Lukas regularly represents clients before the Austrian Supreme Court, the Austrian Administrative Supreme Court, the European Commission, and the EU’s General Court and the CJEU.

Author

Francesca Gaudino is the Head of Baker McKenzie’s Information Technology & Communications Group in Milan. She focuses on data protection and security, advising particularly on legal issues that arise in the use of cutting edge technology.

Author

Sue is a Partner in our Technology practice in London. Sue specialises in major technology deals including cloud, outsourcing, digital transformation and development and licensing. She also advises on a range of legal and regulatory issues relating to the development and roll-out of new technologies including AI, blockchain/DLT, metaverse and crypto-assets.

Author

José María Méndez is head of the Intellectual Property, Tech and Media department at Baker McKenzie Madrid and head of the EMEA IPTech practice. Mr. Méndez is recognized as a leader in his field by the most prestigious legal directories. According to Chambers Europe, José María Méndez "was born for copyright law" and “his style is oriented to being pragmatic and offers clear and easy to implement solutions." Jose María is hailed as an “expert in media and production” and considered “the king in audiovisual matters.” Clients describe Jose María as “very specialized and has unsurpassed knowledge of the audio-visual industry.”

Author

Eva-Maria Strobel is a Partner in Baker McKenzie's Zurich office, and chairs the Firm's EMEA Intellectual Property, Data & Cyber, Commercial, Tech & Transactions, Regulatory and Trade Practice Groups. With dual qualifications in Switzerland and Germany, she advises clients across industries on the strategic development, protection, and commercialization of intellectual property assets and legal intersections between emerging technologies, artificial intelligence, and data regulation. Eva-Maria regularly contributes to thought leadership on AI and IP, and is a trusted advisor to multinational clients navigating complex regulatory and innovation-driven landscapes.

Author

Florian Tannen is a partner in the Munich office of Baker McKenzie. He advises on all areas of contentious and non-contentious information technology law, including internet, computer/software and data privacy law.

Author

Anahita Thoms heads Baker McKenzie's International Trade Practice in Germany and is a Member of our EMEA Steering Committee for Compliance & Investigations. Anahita is Global Lead Sustainability Partner for our Industrials, Manufacturing and Transportation Industry Group and a Member of the ABA International Human Rights Steering Committee. She also served for three consecutive term as co-chair of the Export Controls and Economic Sanctions Committee of the ABA. Anahita has won various accolades for her work, including International Trade Lawyer of the Year (Germany) at the 2020 ILO Client Choice Awards, Young Global Leader of the World Economic Forum, Capital 40 under 40, International Trade Lawyer (New York) at the 2016 ILO Client Choice Awards.