Skip to main content

The EU AI Act is Now in Effect – Here's Why It Should Matter to You 

Download our EU AI Compliance Pack to learn about everything you need to get certified. The pack is designed to help organizations understand and prepare for this groundbreaking legislation.

EU AI Regulation The European Union’s AI Act is possibly the most consequential regulation passed this year and one of the most impactful of the 2020’s.

As we’ve learned in the decade since the GDPR was first released, the effects of regulations passed in the EU are felt worldwide— there’s simply no way to isolate the nearly 450 million people who live in the eurozone.

Copycat regulations will begin to make their way through governmental bodies across the globe, and, while there will be differences, the core principles of the EU AI Act will remain.

You can read the entire EU AI Act here and we've summarized the key points below. 


Key Elements of the EU AI Act 

Definitions of AI Systems 

The first thing to understand is how the Act defines an “AI System” and how each of those AI systems are categorized. 

AI System 

An AI System is a computer system designed to have some level of autonomy and that uses inputs to infer the correct output. It might be able to adapt on its own after going live. The official definition says,

"A machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments." (Article 3(1)) 

General-Purpose AI (GPAI) Model 

It's important to note the Act doesn’t define an AI Model. The closest term is “General-Purpose AI Model,” referring to any generative AI functions. 

“An AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market.” (Article 3(63)) 

General-Purpose AI System 

This is an AI system based on a General-Purpose AI Model (Article 3(66)). 

Categories of AI Systems 

The Act categorizes all AI Systems, including General Purpose AI Models, as one of the following: 

  • Unacceptable Risk – These are completely prohibited and include systems such as social scoring systems, a compilation of facial recognition databases by scraping the internet, and any AI system designed to manipulate users (Article 5). 
  • High Risk – The vast majority of the regulation covers these high-risk systems. Skip to the end to see how to determine if your system is High-Risk. 
  • Limited Risk – Examples include chatbots and “deepfake” images. These systems have limited obligations, such as ensuring the end user is aware they’re talking with a chatbot, but are not the focus of this regulation. 
  • Minimal/No Risk – The majority of AI applications currently available, such as AI-enabled video games and spam filters, present minimal risk to health, safety, or fundamental rights; these systems face no regulation.  


To Whom Does the EU AI Act Apply? 

Now that we understand the definitions of AI systems and their categories, the next thing to understand are the “Operators” to whom the Act applies.

These Operators include the following categories, and are applicable to both standard AI systems and General-Purpose AI systems: 

  • Provider – Whoever builds and sells their own AI system (in the EU) (Article 3(3)).
  • Deployer – Whoever uses an AI system for professional purposes, so long as the output of the AI system is used in the EU (Article 3(4)). 
  • Importer – An entity that brings someone else’s AI system to market in the EU (Article 3(6)). 
  • Distributor – Anyone in the supply chain between a Provider and Importer (Article 3(7)). 
  • Product Manufacturer – Similar to a Provider, these entities are more broadly defined as anyone who builds any kind of product. In terms of the Act, these entities have the responsibility to safely integrate into their product the AI systems someone else built—such as using OpenAI API calls within your product (Article 2(1)(e)). 
  • Authorized Representative – Another existing EU regulatory concept being applied to the AI space; an Authorized Representative is someone who must be specifically and formally (in writing) appointed by the Provider of a high-risk AI system that was built outside of the Bloc. This person liaises with authorities and consumers within the EU and is ultimately responsible for ensuring the AI system being brought to market complies with all EU regulations (Article 22). 

Understanding the defined players above should help see where your company and your system fits in. 

 

High-Risk AI Systems Explained 

The Act builds upon the style of existing EU regulations in defining the concept of a “high-risk AI system.” There are two ways the Act defines a “High-Risk” system: 

1. Explicitly. Annex III of the Act lists 8 categories of systems that are (almost always) high risk: 

  • Biometrics 
  • Critical Infrastructure 
  • Educational & Vocational Training 
  • Employment 
  • Access to Essential Private Services 
  • Law Enforcement 
  • Migration & Border Control 
  • Administration of Justice & Democratic Processes 


2. In a Roundabout Discovery Manner. This is a little complicated, so bear with me:  

  • With few exceptions, for a product to legally be sold in the Bloc, it must be certified as compliant with EU regulations. 
  • These certifications are known as Conformity Assessments, and after undergoing a Conformity Assessment, a manufacturer is able to affix the CE Mark to their product. 
  • The EU has classified and written regulations on every category of product that’s able to be sold in the Bloc. Each category of product has a prescriptive set of regulations, referred to as “Harmonized Standards,” that apply to products within that category—find the categories and their associated harmonized standards here. You can think of these Harmonized Standards as “the EU AI Act of .” 
  • Each category of products has different standards on how to approach the Conformity Assessment. Once you identify which category your product falls under, you must read the Harmonized Standard for that category to determine if your product is high risk or not. 

Obligations of Providers of High-Risk AI Systems 

Most of the Act’s obligations fall on Providers of high-risk AI systems within the geographical boundaries of the European Union. These obligations include a Conformity Assessment (Annex VII) and some other documentation requirements formally referred to as “technical documentation.” 

As a Provider of a high-risk AI system, you’re required to engage with a third-party known as a Conformity Assessment Body to undergo a specific Conformity Assessment for your AI system.

If you pass, the Conformity Assessment Body will provide you with a “Union technical documentation assessment certificate” (Annex 7(4.6)). The Conformity Assessment Body will review: 

  • The “technical documentation” (Annex IV) of your AI system. 

The technical documentation they will evaluate should contain the records supporting the following requirements: 

  • Establishing a risk management system (Article 9) throughout the lifecycle of the high-risk AI system, to include: 
    • Identifying risks arising both from the proper use and the “reasonably foreseeable misuse” of the AI system 
    • Collecting and evaluating risks that arise after the AI system’s been released (how do people actually use and abuse the tool?) 
    • Implementing risk mitigation measures to address these risks 
  • Conduct data governance (Article 10) to ensure your system is processing quality data and your people are trained on how to use the data. 
  • Draw up technical documentation (Article 11) showing how you’re complying with the Act. 
  • Enable logging and detailed recordkeeping (Article 12) to enable the tracing of the system’s actions and ensure accountability. 
  • Provide clear and transparent instructions (Article 13) to the users of the AI System to enable correct usage. 
  • Design the system to allow for human oversight (Article 14). 
  • Design the system for accuracy and security (Article 15) so the system performs consistently throughout its lifecycle. The Act leaves specifics on this part open ended, stating that the Commission will “work with relevant stakeholders to develop ways to measure these qualities.” 
  • Maintain a Quality Management System (Article 17), as mentioned above. Financial institutions can meet these requirements by complying with existing Union financial services law. 

AI

Obligations of Providers of General-Purpose AI Models 

Unless you offer your GPAI Model as an open-source offering, all providers of GPAI models must (Article 53): 

  • Draw up technical documentation, including training and testing process and evaluation results. 
  • Draw up information and documentation to supply to downstream providers that intend to integrate the GPAI model into their own AI system. This information is provided to enable those downstream providers to understand the capabilities and limitations of your system and to enable their compliance with the Act. 
  • Publish a detailed summary on the content used to train your GPAI model. 

There are some separate considerations if your GPAI is considered to have “systemic risk,” but I won’t detail those here since the applicability of those considerations is so limited. Refer to Annex XIII of the Act if you’re interested in reading further. 


Obligations of Other Operators (Besides Providers) 

While the Act focuses heavily on Providers, it also provides mandates and guidance to the other Operators. Here’s what you need to know if you aren’t a Provider: 

  • Deployer – If you’re simply using somebody else’s AI system, you have a responsibility to: 
    • Follow the instructions the Provider is required to publish, 
    • Ensure an actual human provides oversight of the AI-enabled product, 
    • Monitor the system’s operation and be ready to quickly disable the system if something goes off the rails (Article 26(5)), 
    • Maintain system logs for at least 6 months, and 
      • If applicable, inform your employees they’re using a high-risk AI system (Article 26). 
  • Distributor – The category of Distributor is essentially adding an extra set of eyes to the oversight of an imported AI system. As a Distributor, all the same requirements apply to you as if you were an Importer, even if you aren’t the one selling the system to an end user—the EU wants to extend the responsibility as far as they can to limit the parties who can pass the buck (Article 24). 
  • Product Manufacturer – If you’re building someone else’s AI system into your own product, you essentially become the Provider and are responsible for all requirements and obligations as if you built the system yourself (Article 25(3)). 
  • Authorized Representative – This person is ultimately responsible for ensuring the AI system being brought to market complies with all EU regulations. They must maintain the documentation the Act prescribes and be able to provide the documentation to the authorities upon request. If the Authorized Representative ever has reason to doubt whether the system they’re representing is following the law, they have an obligation to terminate their relationship with the Provider and file a formal report with the European Artificial Intelligence Office (Article 22). 

Timelines for Implementation 

Here are the key dates for compliance (Article 113): 

  • August 1, 2024: Act entered into force 
  • February 2, 2025: Provisions on banned AI systems—those with unacceptable risk—apply 
  • August 2, 2025: Provisions on General Purpose AI Models 
  • August 2, 2026: Most obligations for high-risk AI systems apply 
  • August 2, 2027: Additional obligations for high-risk systems in regulated products apply 


Immediate Actions You Should Take 

Avoid panic. As always, the gears of the regulatory state move slowly—fear not and know that you’ll have time to get your affairs in order. Here’s what you should do now: 

  • Assess Your Role – Are you a Provider? An Importer? Determine where you fall in this newly defined landscape. 
  • Assess Your AI Systems – Identify all AI systems in use and determine which risk category they fall into. 
  • Understand Compliance Obligations – Based on your role and the risk level of your AI systems, determine which of the specific obligations above apply to you and begin drafting the necessary documentation and compliance plans. 


Actions You Should Take Later 

Complete the implementation of your new compliance obligations, based on your role and the risk level of your AI systems. 

  • If you have a general-purpose AI model, do this prior to August 2025
  • If you have a high-risk AI system, do this prior to August 2026
  • Once you’re ready, search this list and engage with a Notifying Body of your choosing to undergo your Conformity Assessment. 
  • Pass, and celebrate! 

Let’s Get Started 

It’s a matter of when, not if, an AI governance framework will apply to you. As such, if you create and sell an AI system, you should begin to gather the documentation required by the EU AI Act.  

If all of this is a bit overwhelming, you’re in the right spot. At risk3sixty, we simplify security and privacy compliance and help you audit, implement, and manage streamlined compliance programs that align with your business objectives. Our team of certified experts is ready to assist you! 

Contact us

Like our content? Subscribe and stay informed.

Tags

See all