Key Takeaways
- The EU is pursuing a risk‑based, human‑centric AI framework that aims to become a global standard, much like the GDPR.
- The proposed Artificial Intelligence Act classifies AI systems into four risk tiers (unacceptable, high, limited, minimal) and imposes stricter obligations on high‑risk applications.
- Accountability, transparency, and protection of fundamental rights are core pillars; the EU has already issued ethical guidelines (Ethics Guidelines for Trustworthy AI) and an Assessment List for Trustworthy AI (ALTAI).
- While the EU focuses on regulation and standards, it has not yet established binding EU‑wide rules for training personnel who supervise AI, leaving this to Member States or allied initiatives such as NATO.
- International cooperation—particularly through the EU‑US Trade and Technology Council and NATO’s AI Strategy—seeks to align democratic values with security needs in the AI domain.
EU Strategy and Foundations
The European Commission launched the European Strategy on Artificial Intelligence in April 2018, asserting that the EU “can lead the way in developing and using AI for good and for all, building on its values and its strengths.” The strategy highlighted three commitments: increasing investment to match the EU’s economic weight, ensuring no one is left behind in education and the workplace, and making new technologies reflect European values such as those enshrined in the GDPR and Article 2 of the Treaty on European Union (“respect for human dignity, freedom, democracy, equality, the rule of law and respect for human rights”). To operationalise this vision, the Commission created the European AI Alliance and the High‑Level Expert Group on AI (AI HLEG), which delivered the Ethics Guidelines for Trustworthy AI (April 2019) and the Policy and Investment Recommendations for Trustworthy AI (June 2019). These documents laid the groundwork for a “human‑centred approach to artificial intelligence” that the Commission later reaffirmed in the Communication “Building Trust in Human‑Centred Artificial Intelligence” (April 2019) and the Assessment List for Trustworthy Artificial Intelligence (ALTAI) (July 2020), identifying seven key requirements for trustworthy AI.
From White Paper to the AI Act
Building on the strategy, the White Paper on Artificial Intelligence (February 2020) proposed twin goals: an “ecosystem of excellence” for AI development and an “ecosystem of trust” rooted in a human‑centric approach. The White Paper was accompanied by a report on safety and liability that flagged gaps in existing product safety legislation, notably the Machinery Directive (2006/42/EC). In December 2020, ENISA warned that AI introduces new cyber‑security challenges, reinforcing the need for a coherent regulatory response.
On 21 April 2021 the Commission unveiled COM (2021)205, proposing the Artificial Intelligence Act—a harmonised regulation on AI applications described as “shaped by European values and risk‑based, ensuring both safety and fundamental rights protection.” The proposal stresses that AI can “support socially and environmentally beneficial outcomes” while also creating risks, and therefore the EU intends to “lay the necessary legal bases so that artificial intelligence has rules and specific guidelines within the common European space.” If adopted, the Act would be the world’s first comprehensive legal framework for AI.
Risk‑Based Classification and Core Obligations
The AI Act adopts a risk‑based approach, sorting AI systems into four categories:
- Unacceptable risk – e.g., real‑time biometric identification in public spaces for law‑enforcement purposes (the Commission cites the Chinese social‑credit scoring model as an example).
- High risk – AI that controls critical infrastructure, endangers life or health, or is used for CV sorting in recruitment. These systems must undergo pre‑market conformity assessments, meet transparency obligations, and be monitored throughout their life cycle.
- Limited risk – systems that interact with users (e.g., chatbots) and must provide clear information that they are AI‑driven.
- Minimal risk – the vast majority of AI applications, which would remain largely unaffected by the new rules.
The Commission argues that this structure guarantees that “Europeans can trust the artificial intelligence they are using.” Notably, the Act also obliges biometric surveillance, highlighting concerns about discrimination and privacy violations when facial recognition is used indiscriminately.
Human‑Centric AI and Oversight Gaps
Central to the EU’s vision is human‑centric AI, which the Commission insists must remain “under human control.” The Ethics Guidelines for Trustworthy AI list “human agency and oversight” as a key requirement, advocating human‑in‑the‑loop, human‑on‑the‑loop, or human‑in‑command mechanisms. Article 14 of the AI Act reiterates that high‑risk AI must be designed so that natural persons can effectively oversee its functioning, requiring providers to identify appropriate oversight measures and ensure that those assigned have the “necessary competence, training and authority.”
Nevertheless, the proposal stops short of mandating specific EU‑wide training standards for AI supervisors. It merely states that training must be “adequate for the task,” leaving the detail to Member States. This omission contrasts sharply with initiatives such as the US National Artificial Intelligence Initiative, which funds apprenticeships, STEM education, and skills programs to build an AI‑ready workforce. The EU’s current support—through the Digital Europe Programme, Horizon Europe, and the Digital Education Action Plan—focuses on creating AI experts but does not yet address the training of personnel who supervise AI in critical or defence settings.
AI in Law Enforcement and the AP4AI Initiative
Recognising the particular sensitivities of AI use by police and security agencies, Europol launched the Accountability Principles for Artificial Intelligence (AP4AI) in February 2022. Developed with the Centre of Excellence in Terrorism, Resilience, Intelligence, and Organized Crime Research (CENTRIC), AP4AI offers a practical toolkit for internal security practitioners. It defines accountability as “the acknowledgement of an organisation’s responsibility to act in accordance with the legitimate expectations of stakeholders and the acceptance of the consequences.”
The framework introduces twelve principles—legality, universality, transparency, pluralism, independence, commitment to robust evidence, enforceability and redress, compellability, explainability, constructiveness, conduct, and learning organisation—to guide accountable AI deployment across design, development, and application stages. AP4AI stresses the need for a regulatory assurance body that can identify risks and advise stakeholders and governments, echoing the EU’s broader call for oversight mechanisms while acknowledging that current legislation lacks specific accountability rules for AI in policing.
NATO’s Parallel Approach
While the EU concentrates on civil regulation, NATO has turned its attention to emerging and disruptive technologies (EDTs), prioritising artificial intelligence as a cross‑cutting enabler for modernisation. At the October 2021 Defence Ministers’ meeting, NATO adopted its Artificial Intelligence Strategy, establishing six principles for safe and responsible AI use in defence: lawfulness, responsibility and accountability, explainability and traceability, reliability, governability, and bias mitigation. These mirror the EU’s ethical guidelines but include a verification component to ensure compliance.
NATO’s upcoming 2022 Strategic Concept—set to be adopted at the Madrid Summit—aims to shift focus from merely adopting new technologies to how military and civilian personnel use them, emphasizing education, training, and instruction on AI and other EDTs. Initiatives like the Defence Innovation Accelerator for the North Atlantic (DIANA) and the NATO Innovation Fund are intended to deepen cooperation with industry, academia, and NGOs, thereby building the digital capacity needed to supervise AI systems in hybrid and conventional operations.
Conclusions and Outlook
The EU’s overarching goal is to strategically position itself amid the global AI race led by the United States and China. By proposing the Artificial Intelligence Act, the Commission hopes to create a regulatory benchmark that, like the GDPR, becomes an international reference point. The Act’s balanced approach—pairing fundamental‑rights protection with public‑security considerations—is intended to foster trustworthy AI while preserving competitiveness.
However, the analysis reveals a notable gap: the absence of binding EU‑wide standards for training those who monitor and oversee AI, especially in high‑stakes domains such as law‑enforcement, defence, and critical infrastructure. While the EU invests heavily in AI research, innovation, and skills development through programmes like Digital Europe and Horizon Education, the practical preparation of AI supervisors remains largely delegated to national initiatives or allied frameworks such as NATO.
For the EU to truly become the global standard‑setter it aspires to be, future iterations of the AI framework will need to integrate clear, enforceable training requirements alongside its risk‑based regulations. Only then can the union guarantee that AI systems are not only ethically designed and legally compliant but also competently overseen by a skilled workforce capable of safeguarding both security and fundamental rights in an increasingly AI‑driven world.

