Superficially this sounds great...but as with the "legitimate interest" clause in GDPR, the law actually gives its blessing to a lot of repugnant practices (eg using AI to evaluate asylum seekers' applications) as long as a vague quality standard is maintained when inspectors are looking

European Commission

🔹 AI-generated media, ‘deepfakes’ must be clearly labelled as such 🔸Chatbots and virtual agents must explicitly state they aren't human 🔹You must be told when AI is actively analysing you, like biometrics, emotion tracking → link.europa.eu/gTvhRX