The AI Act is the European Union’s major step to regulating artificial intelligence and reigning in the ineluctable risks its poses to individuals and society. After a convoluted adoption process, which included a strong opposition to regulating GPAI models by France, Germany and Italy, organisations are rightly asking their lawyers what now? Where to start?
I. Setting the stage.
The AI Act comprises of 180 Recitals and 113 Articles, and it’s structured in 13 Chapters, and 13 Annexes.
It is noteworthy that the most extensive chapter of the AI Act is dedicated to the high-risk AI systems which makes a lot of sense given that the Regulation is conspicuously a risk-centred legislative construction. I will come back to it when I analyse the steps an organisation must undertake for complying with the AI Act.
In simple terms, the AI Act applies to operators of AI systems, meaning providers, deployers, importers and distributors of AI systems, of course, if they would make available on the market, put in place on the market or into service an AI system.
At a first read, the definitions in Article 3 of the AI Act seem straight forward nevertheless, watch out for a multitude of interpretations. For example, I ended up discussing with both our product development management and legal associates if an organisation developing an AI system for their internal use only would qualify as a provider, given that the organisation would not put the system on the market.
According to Article 3 paragraph (3) provider means a natural or legal person, public authority, agency, or other body that develops an AI system or a general-purpose AI model or that has an AI system, or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge. Paragraph (11) provides that putting into service means the supply of an AI system by the provider for first use directly to the deployer or for own use in the Union for its intended purpose.
Nevertheless, one of my legal associates dragged my attention that things are getting more complicated for GPAI. In this regard, the Preamble (97) offers relevant context which reads: When the provider of a general-purpose AI model integrates an own model into its own AI system that is made available on the market or put into service, that model should be considered to be placed on the market and, therefore, the obligations in this Regulation for models should continue to apply in addition to those for AI systems. The obligations laid down for models should in any case not apply when an own model is used for purely internal processes that are not essential for providing a product or a service to third parties and the rights of natural persons are not affected. Considering their potential significantly negative effects, the general-purpose AI models with systemic risk should always be subject to the relevant obligations under this Regulation.
My point is that the complexities of the AI Act are complex enough, if I may express myself like this, to the point that organisations would need to delegate its interpretation to their in-house and/or external specialists.
II. Complying with the AI Act in steps.
Pausing for a bit and taking a step back, I must concur with colleagues advising that organisations must maintain an inventory of their IT tools.
Step 1. Is my IT tool an AI system?
Once that accomplished, on the journey to comply with the AI Act, the first step organisations must undertake is to assess if the IT tools they are developing or deploying qualify as AI systems (stand alone or components).
Step 2. Is my AI system a prohibited AI practice?
That being assessed and concluded upon, organisations must check if the AI systems they have in scope are on the list of prohibited AI practices as they are codified in Article 5 of the AI Act. This is an annual assessment since the Commission itself is delegated the right and the responsibility to amend the list once a year. If that is the case, organisations must already know that prohibited AI practices must be decommissioned within six months from the entry into force of the AI Act.
Step 3. Is my AI system a high-risk AI system?
Next step is, of course, to assess if the AI systems qualifies as a high-risk AI system. Article 6 of the AI Act defines what it is supposed to be considered a high-risk AI system. According to Articles 6.1. and 6.2. of the AI Act, there are two relevant criteria for this assessment: first, the AI system is a stand-alone or a component of an AI systems covered by the Union harmonization legislation listed in Annex I required to undergo a third-party conformity assessment; second, the AI system falls into one of the areas listed in Annex III.
In conclusion, in above cases stemming from Article 6.1. and 6.2. of the AI Act the legislator retained a presumption of significant risk of harm to the health, safety, or fundamental rights of natural persons.
Article 6.3. provides for exceptional cases when the above risks might be negated:
An AI system shall not be high-risk if it does not pose a significant risk of harm to the health, safety, or fundamental rights of natural persons, including by not materially influencing the outcome of decision making.
This shall be the case where one or more of the following conditions are fulfilled:
- the AI system is intended to perform a narrow procedural task.
- the AI system is intended to improve the result of a previously completed human activity.
- the AI system is intended to detect decision-making patterns or deviations from prior decision-making patterns and is not meant to replace or influence the previously completed human assessment, without proper human review; or
- the AI system is intended to perform a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III.
Organisations must be aware that if the conclusion of the assessment is that the AI system is not a high-risk this outcome must be documented before the AI system is put on the market or into service. Therefore, either way organisations are not exempt from the registration obligation provided in Article 49 (2):
Before placing on the market or putting into service an AI system for which the provider has concluded that it is not high-risk according to Article 6(3), that provider or, where applicable, the authorised representative shall register themselves and that system in the EU database referred to in Article 71.
Step 4. What is my acting capacity?
If the assessment concludes that the AI system is indeed a high-risk AI, organisations must determine their acting capacity. In other words, is the organisation going to provide, import, distribute or deploy the AI system? Depending on the organisation’s acting capacity different compliance obligations must be accounted for. For instance, more onerous obligations are imposed on providers of the high-risks AI systems.
Step 5. What should I comply with?
In a nutshell, the AI system can be put in place on the market or into service only if a conformity assessment has been undertaken, the Declaration of Conformity (DoC) has been drawn up and the CE marking has been obtained.
According to Article 16 (f): Providers of high-risk AI systems shall ensure that the high-risk AI system undergoes the relevant conformity assessment procedure as referred to in Article 43, prior to its being placed on the market or put into service.
The CE marking indicates that the AI system is safe. It is the reason why lawyers are assimilating the AI Act with a product safety framework.
There are two types of conformity assessments, an internal assessment carried out by the provider itself and an assessment carried out with the involvement of a notified body.
The conformity assessment is part of the quality management system that providers must put in place. The outcome of the conformity assessment is very much dependent on the risk management system and its operation. According to Article 9 of the AI Act: A risk management system shall be established, implemented, documented, and maintained in relation to high-risk AI systems. Basically, the risk management system is nothing else but an assessment of the known and foreseeable risk that the high-risk AI system can pose to health, safety or fundamental rights when used according to its intended purposes, but also in a context of reasonably foreseeable misuse. Other than that, the risk management system must include targeted risk management measures designed to address the risks identified to the point that relevant residual risk associated with each hazard, as well as the overall residual risk of the high-risk AI systems, are judged to be acceptable. In other words, a risk assessment must be conducted to make sure that the AI system is safe or, otherwise, trustworthy. I love the term trustworthy, is very commercial, but I must say that this is more of a safety assessment.
Although the above lines are very much focused on compliance obligations of the providers of high-risk AI systems, the AI Act is imposing compliance obligations along the value chain. And therefore, importers and distributers, are obliged, among other things, to ensure that the system is in conformity with the AI Act by verifying that the relevant conformity assessment procedure has been carried out by the provider of the high-risk AI system. Ultimately, specific deployers must perform an assessment of the impact on fundamental rights that the use of the system may produce.
That being said, depending on the organisation acting capacity, a set of compliance obligations must be followed through. Here is where organisations will have to rely on specialized advice from their lawyers or compliance professionals.
III. Conclusion
I would not end this article without pointing out that the AI Act is a very complex legislation. This article is meant to be a short guidance written with the purpose of putting a structure to the complexity. Nevertheless, this is just a first step I’m undertaking, and I will follow up with more illuminating articles where I will break down the compliance obligations depending on each stakeholder acting capacity. Up until then don’t hesitate to contact my Centre of Excellence at Wrangu for support with the AI Act. Currently my Centre of Excellence provides support in matters relating to privacy and AI Regulations. If you need support in risk management or security regulations I can put in contact with my peers from the other Centres of Excellence.