European Union - AI Strategy and Trust
White Paper on Artificial Intelligence: A European approach to excellence and trust
European Union
RAI-EU-NA-WPAIEXX-2020The European Commission White Paper published on 19 February 2020 sets out policy options to promote AI excellence and trust across the EU. It proposes a twin-track approach of investment to build an ecosystem of excellence and a risk-based regulatory framework to address specific risks to safety and fundamental rights.
Summary
The White Paper on Artificial Intelligence: A European approach to excellence and trust (COM(2020)65 final), published by the European Commission on 19 February 2020, articulates a strategic, values-based approach to AI for the European Union. It sets out policy options and a roadmap for combining significant public and private investment in AI with targeted regulatory measures aimed at building an "ecosystem of excellence and trust". The document frames AI as simultaneously an engine for economic growth, innovation in strategic sectors (healthcare, transport, agriculture, energy, manufacturing, finance), and a source of social benefit, while acknowledging risks including opaque decision-making, discrimination, privacy intrusion and safety hazards.
The White Paper recommends a twin-track strategy: (1) strengthening excellence through funding, coordination, research infrastructures, skills and data access (including pooled European data resources and support for research and industry uptake); and (2) establishing a proportionate, risk-based regulatory framework focused on the uses and impacts of specific AI systems rather than the technology per se. It proposes identifying and regulating high-risk AI applications that could affect safety or fundamental rights, while enabling lighter-touch measures (labels, codes of conduct, voluntary standards) for lower-risk uses. The paper sets out options for conformity assessment mechanisms, market surveillance, registration and documentation requirements, and explores mechanisms such as sandboxes and testing facilities to support innovation.
Importantly, the White Paper links AI policy to existing EU law and values, including the Charter of Fundamental Rights and data protection rules (GDPR). It calls for clarity on liability and safety across AI, IoT and robotics, and published alongside it a Commission report on safety and liability implications. The White Paper launched a public consultation (19 Feb–14 Jun 2020) to collect stakeholder input that later informed the Commission's April 2021 AI regulatory package, including the Proposal for a Regulation laying down harmonised rules on artificial intelligence (AI Act). While the White Paper itself did not create binding obligations or penalties, it outlined the architecture and options that shaped subsequent binding measures, such as a risk-based classification of AI applications, conformity assessment pathways and enhanced enforcement mechanisms to be set in future legislation. The paper emphasises international cooperation and the EU's ambition to become a global standard-setter for trustworthy AI. Primary sources include the Commission publication and the EUR-Lex entry (COM(2020)65 final).
Full article
Read full text ↗Overview
The White Paper on Artificial Intelligence (COM(2020)65 final), published by the European Commission on 19 February 2020, defines a European strategy that pairs investment in research, infrastructure and skills with regulatory options that protect safety and fundamental rights. The document frames AI as a key enabler for competitiveness and societal benefit, while recognising risks such as discrimination, privacy intrusion and unsafe outcomes. The White Paper sets out policy options to build an "ecosystem of excellence and trust" and launched a public consultation to gather stakeholder input. The full text and downloadable PDF are available from the EU's official repositories (see EUR-Lex PDF: COM(2020)65 and the Commission publication page at European Commission - White Paper on AI).
Definitions
The White Paper uses an inclusive, functional approach to AI: systems that combine data, algorithms and computing power to perform tasks normally associated with human intelligence. It distinguishes by use and risk rather than by technical method. Key concepts include "ecosystem of excellence" (research, infrastructure, investment, skills), "ecosystem of trust" (regulatory and governance measures to protect rights and safety), and a "risk-based approach" that classifies AI applications by their potential to harm health, safety or fundamental rights. The document explicitly excludes military AI uses from its scope and foregrounds lifecycle considerations (design, training, deployment, monitoring).
Governance and Institutional Framework
The White Paper proposes governance arrangements that require coordination across the European Commission, Member States and relevant agencies to ensure coherent implementation. It recommended an enhanced role for Commission Directorates-General (including DG CONNECT and DG JUST) and called for strengthened cooperation with national authorities, market surveillance bodies and data protection authorities to supervise compliance with substantive safeguards. The document also suggested establishing interoperability of national AI policies via a coordinated plan and recommended EU-level testing and certification infrastructures and regulatory sandboxes. For further institutional context and later-stages instruments that stemmed from these proposals, see the Commission strategy pages and consultation library (see Digital Strategy — White Paper consultation).
Key Focus Areas
The White Paper emphasises several mutually reinforcing priorities. First, excellence: mobilising research funding (Horizon 2020/Horizon Europe), Digital Europe and private investment to build computing infrastructure, data spaces and critical technologies. Second, trust: ensuring AI complies with EU values and the Charter of Fundamental Rights through a risk-based regulatory approach focused on high-risk applications. Third, safety and liability: clarifying how existing product safety and liability regimes interact with AI, IoT and robotics, and proposing targeted changes. Fourth, market design: enabling SMEs and startups through sandboxes, testing facilities and certification pathways. Fifth, data governance and access: addressing the need for high-quality, representative data pools and secure data sharing mechanisms. Sixth, skills and societal preparedness: investing in upskilling and public-sector AI adoption to ensure inclusive benefits. The White Paper proposes a menu of measures—ranging from voluntary codes and labels to mandatory conformity assessments and registration requirements—depending on the risk profile and public interest dimension of AI applications.
Implementation Framework
The White Paper lays out practical implementation options intended for later translation into binding measures. Central to this is a risk classification of AI uses—unacceptable, high, limited and minimal risk—where high-risk systems would be subject to mandatory obligations (technical documentation, conformity assessment, human oversight, transparency and robustness). Implementation tools included EU-level conformity assessment mechanisms, harmonised standards, coordinated market surveillance, and the possible creation of registries for high-risk systems. To support deployment, the White Paper recommended regulatory sandboxes to test AI systems under real conditions and suggested that the Commission, in cooperation with Member States, foster testing facilities and shared data resources. The Paper also called for alignment with GDPR and sectoral safety regulation and recommended that any future obligations be proportionate and technologically neutral (see the Commission's subsequent AI policy pages for developments derived from these options: Excellence and trust in AI).
Monitoring and Evaluation
The White Paper advocates monitoring mechanisms combining EU-level oversight and Member State enforcement. Monitoring tools proposed include reporting obligations, registries, periodic reviews of risk classifications, impact assessments, data on incidents and harm, and cooperation between market surveillance authorities and data protection bodies. The Commission proposed ongoing consultation with stakeholders and iterative evaluation of policy measures to preserve regulatory agility and ensure proportionality. Periodic reviews and sunset/trigger mechanisms for stricter measures were recommended so rules can evolve with the technology and evidence base.
Penalties, Liability, and Appeals
As a White Paper, the document itself did not set penalties but outlined options for liability and enforcement to be taken forward in subsequent legislation. It identified the need to clarify civil liability rules where AI causes damage and to align sectoral safety legislation with AI-specific risks. Enforcement options considered included conformity assessment failures, market withdrawal, corrective orders and civil remedies. The White Paper also indicated that proportional administrative sanctions and civil liability regimes would be designed in later legal texts, with due process and judicial review preserved.
Relationship to Other Instruments
The White Paper situates itself within the broader EU policy architecture: it complements the 2018 "AI for Europe" strategy, the 2019 European strategy for data and the GDPR, and it recommended coordinated updates to sectoral safety laws (e.g., machinery and product safety). The White Paper's consultation informed the Commission's April 2021 AI regulatory package (including the AI Act proposal) and a revised Coordinated Plan on AI. It therefore acts as a bridge between strategic policy goals and the later binding regulation that operationalised many of the options it presented.
International Alignment
The White Paper emphasises the EU's ambition to foster international dialogue and to promote global standards for trustworthy AI built on human rights, safety and the rule of law. It recommended engaging in multilateral forums, technical standard-setting bodies (ISO/IEC) and bilateral cooperation to ensure interoperability and to reduce fragmentation. The document identified a need to align trade, export controls, and international regulatory cooperation, while preserving EU values and protecting citizens’ rights.
Implementation Timeline
| Event | Date |
|---|---|
| Publication of White Paper | 2020-02-19 |
| Public consultation opened | 2020-02-19 |
| Public consultation closed | 2020-06-14 |
| Consultation results published | 2020-07-17 |
| Commission AI legislative package (informed by White Paper) | 2021-04-21 |
Sources and References
| Source | Type |
|---|---|
| White Paper on Artificial Intelligence: COM(2020)65 final (EUR-Lex PDF) | Primary Source |
| European Commission - White Paper on AI (publication page) | Primary Source |
| Digital Strategy - Consultation Library | Primary Source |
Requirements for a company
What an organisation has to do under European Union - AI Strategy and Trust, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Adopted). These requirements apply once the instrument takes effect and may change before then.
Must do
6- Classify AI use and perform a risk assessment across the lifecycle.Providers of AI systems.
- Maintain technical documentation, logs, and training data provenance.Providers of high-risk AI systems.
- Provide explainability and user information where required.Providers of high-risk AI systems.
- Design human-in-the-loop or human-on-the-loop measures.Providers of high-risk AI systems.
- Undergo conformity assessment for high-risk systems.Providers of high-risk AI systems.
- Report significant incidents to competent authorities as required.Providers of AI systems.
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under European Union - AI Strategy and Trust, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Providers of AI systems. | Classify AI use and perform a risk assessment across the lifecycle. “Central to this is a risk classification of AI uses...” | — | Implementation Framework | Important |
| 2 | Providers of high-risk AI systems. | Maintain technical documentation, logs, and training data provenance. “high-risk systems would be subject to mandatory obligations (technical documentation...)” | — | Implementation Framework | Important |
| 3 | Providers of high-risk AI systems. | Provide explainability and user information where required. “high-risk systems would be subject to mandatory obligations (...transparency...)” | — | Implementation Framework | Important |
| 4 | Providers of high-risk AI systems. | Design human-in-the-loop or human-on-the-loop measures. “high-risk systems would be subject to mandatory obligations (...human oversight...)” | — | Implementation Framework | Important |
| 5 | Providers of high-risk AI systems. | Undergo conformity assessment for high-risk systems. “high-risk systems would be subject to mandatory obligations (...conformity assessment...)” | — | Implementation Framework | Important |
| 6 | Providers of AI systems. | Report significant incidents to competent authorities as required. “Monitoring tools proposed include reporting obligations...” | — | Monitoring and Evaluation | Important |
Related Regulations
Communication: Fostering a European approach to Artificial Intelligence
European Union94% similar
Communication: Artificial Intelligence for Europe
European Union93% similar
Coordinated Plan on Artificial Intelligence — 2021 review
European Union93% similar
Ethics Guidelines for Trustworthy AI (High-Level Expert Group on AI)
European Union92% similar
Cabinet Appreciation / Response to the European White Paper on AI (Kabinetsappreciatie Witboek AI)
Netherlands91% similar
© Regulations.AI · updated on 13-Jun-2026