The EU AI Act implements a risk-based regulatory framework that categorizes AI systems into four tiers (unacceptable, high, limited, and minimal risk) with corresponding obligations: prohibited systems face bans, high-risk systems require conformity assessment with notified bodies and must meet seven compliance requirements (risk management, data governance, technical documentation, recordkeeping, transparency, human oversight, and accuracy/robustness/cybersecurity), while limited-risk systems (like deepfakes and chatbots) must disclose AI-generated content, and minimal-risk systems have no mandatory obligations. The Act also establishes specific requirements for general-purpose AI model providers and imposes penalties up to 35 million euros or 7% of annual worldwide turnover for non-compliance.
EU AI Act Explained: Risk Tiers, Compliance & Fines
Added:so welcome everybody thank you very much for joining uh this is our first uh the first of dat IU AI governance web series focusing on the EU AI act uh today I'll be covering unpacking the eua act so this is basically covering the the main interventions that are pushed forward by the ACT um as for who I am my name is Jacob bewick I am the director for AI governance Solutions at dat i coup I lead a team a global team that works with organizations again globally across sectors on helping to refine AI governance processes and translate them into our product uh and specifically govern which you'll learn more about in a later web series but for today we are focusing on the EU AI act um here is our agenda I won't waste precious time on it but if you're a speed reader you will have read it all so let's kick off um first why the EU AI act what is it all about and in the interest of uh not suffering saying EU AI act multiple times over this presentation I will just refer to it as the ACT uh principally the ACT is concerned with protecting EU citizens so it does this by promoting the uptake of human Centric and trustworthy AI while ensuring a high level of protection of health safety fundamental rights all while protecting against harmful effects of AI systems and importantly supporting Innovation so there's a balancing act there uh for the keyy I'm going to be covering these three main interventions today uh the first is the uh risk tearing of uh that is proposed within the ACT uh the risk tiering applies to AI systems and I'm going to use AI systems and AI use cases interchangeably um the next is new obligations Bas during general purpose AI model models uh and model providers now there's a key distinction here already to make um namely that uh the first intervention focuses on AI Systems Second intervention focuses on models uh this is more than an academic point of interest and we'll explain why later on and then finally uh we will discuss the penalty regime uh for non-compliance which goes as high as 35 million euro or up to 7% of uh annual worldwide turnover for the previous fiscal year so who I'm so sorry if you're hearing my background noise we got lots of dings um let's talk about the key stakeholders I've created an artificial kind of buckets uh the first includes Market participants and the second uh is comprised of Market kind of or enforcement actors so let's talk about the market participants very quickly uh I won't talk about all of them because I think there are three critical ones for probably this audience they include deployers so these are organizations that are actually operationalizing AI systems providers these are organizations who are either based within the EU or outside of the EU but selling AI systems into the EU and then GP or general purpose AI model providers now importantly you've got these other actors org entities like authorized representatives distributors and also importers who aren't on the screen it's sort of orbit providers and another important thing to note is that deployers quite quickly become providers so for example a deployer might be consuming third-party AI systems and then might modify one substantively at which point they become the provider of that system even though they're also the deployer within the EU AI act the line share of new obligations fall on these three now if we move over to enforcement um I will not be able to go through all of these uh but if I will focus on these two uh but effectively uh the themes the key themes of what these enforcement actors do uh they enforce the EU act uh they ensure that it's being rolled out well through things like guidance codes of conduct which we'll discuss later on they conduct investigations of the two that are highlighted notified bodies play an important role as an impartial uh thirdparty entity so it's not a public sector entity um that conducts Conformity Assessments in particular for high-risk systems which we'll talk about later um so that basically the um that Regulators can be assured that the uh the deployer of that system is conforming to the law and then we have Market surveillance authorities so these uh exist at the state level so state by state there will be a market surveillance Authority and they act is a single point of contact regarding the AI act uh which will include receiving complaints they have enforcement Powers uh concerning the requirements laid out in the regulation which you'll hear more about uh and they also have supervision responsibilities there's more but I do want to focus on another element of their agreement which is that they can coordinate or they will coordinate uh with the European Commission on things like conducting investigations promoting compliance identifying non-compliance uh raising awareness and so on so we'll move on from the key players and we'll talk about that first Intervention which is the risk cheering uh so the risk Heering is spread out over four levels at the most kind of extreme level is the unex acceptable risk tier this is uh just kind of characterized by having an untenable potential for harm below that the highrisk tier which uh is characterized by posing a serious potential of harm and what's important is this tier is associated with uh the greatest kind of burden of obligations under that is the limited risk here as you might not be surprised there's some potential of harm and then of course there's the minimal risk here with uh no potential for harm so if we move we're going to walk through each level the first is are the prohibited AI systems which are fall within the unacceptable risk tier um I'm not look what I've done is I've looked at uh Act five of the EU act if you want reference uh and I've drawn out kind of a high level of what each AI system or use case uh which is described as falling into this category uh I'll talk about them very quickly just to give you a thematic notion of what's covered here so things that are prohibited include AI systems that are intended to subliminally manipulate people people or exploit protected characteristics to De to distort behavior in a way that's harmful AI systems that evaluate or classify people us using social behavior or actual predicted or inferred characteristics and in a way that ultimately leads to harmful unfavorable or detrimental treatment using personal information to redict criminal Behavior using AI systems to create or expand facial recognition uh databases through scraping web or CCTV data uh inferring emotions at the workplace or an educational institutions biometric categor categorization systems based on protected characteristics and realtime biometric identification systems in public Spaces by law enforcement but there are some exceptions now um if you think your organization is investing in any of these for any particular reason I'd strongly recommend you or you encourage your legal team to review article 5 um because quite simply these are prohibited from being put on the market they cannot be deployed we're going to quickly move now to the high-risk AI systems tier uh which as I mentioned before is kind of the most onerous in terms of uh new obligations uh i' there's two tracks to identifying a high-risk uh AI system uh the first track is quite straightforward it's a list found in Annex 3 what you're seeing on the screen are the are six domains but it's kind of tricky because in fact there are uh more than that and I'll explain why in a minute um a quick run through them and then I'll focus on two which I think have the widest Market relevance so with respect to biometric identification categorization and ocin recognition it is what it says on the tin uh doing these uh conducting using AI in this way would qualify as a high-risk AI system um with respect to the second using AI to operate critical infrastructure such as digital road supply of water gas heating electricity would qualify uh for education and vocational training this is really about evaluating uh using AI to determine access to or evaluating or recommending opportunities for or detecting cheating all in relation to kind of schooling um and I'm going to skip these two for now because I'm going to focus on them in a moment but public authorities is really comprised of three domains this includes uh the administration of justice and Democratic processes law enforcement and managing borders and immigration so if you work at an organization that is installing um facial recognition systems on borders you might want to consider the high-risk system and how uh it might affect you now for these two I'll start with employment worker management and access to self-employment uh I find this interesting because when I talk to organizations kind of no matter where they are and they're looking to leverage AI systems to optimize certain parts of the business HR seems to be like a common denominator uh and fundamentally this domain this domain is preoccupied with things like using AI in the selection or plac placement of targeted ads job ads to analyze or filter job applications and to evaluate candidates uh to make decisions affecting terms of work like promotion termination demotion um allocating tasks based on individual's Behavior personal traits or characteristics or monitoring and evaluating the performance and behavior of persons now with respect to access to essential private and public services and benefits this includes things like uh welfare but it also includes things like using AI to to determine creditworthiness or credit score and we might think that this is the strict sorry strict domain of financial services and you know we're right that it is relevant to that space uh but you know I am thinking about scenarios where an organization might sell a product or a service on a website to an end consumer and I think we're all too familiar with this there's an option to select uh kind of a payment plan that payment plan might be put in place by the organization itself or a third party uh and where that payment plan either today or in future leverages AI to determine basically access to that Finance in order to make that purchase I would wonder whether it would qualify as a high-risk system and if you're this is resonating with you um I'd encourage you to talk to your legal teams now the list here that I've gone through um very quickly is found as I mentioned in the annexes uh one important note is that this is not fixed this is expected to change over time under the penship of um the European Commission whoops so let's go to track two track two is a little bit different and a little bit more interesting and complicated so track two two conditions must be met for an AI system to be deemed high-risk uh the first is that it's intended to be used as a safety component of a product or is itself a product in the context of uh a regulat a regulated space where a third con party Conformity assessment is required and there is a very long list provided in Annex one of all the harmonized legislation relevant to this I will not go through this I am not a specialist in any of this legislation however in the interest of making this material to you I wanted to talk about two hypotheticals um the first is the idea that you might think of uh an organization using Machinery or an AI system um to predict assembly line failures and take mitigating actions whether that's to recommend a human intervene or stop the uh assembly line altogether I would expect that that sort of use case or AI system would qualify as high risk and then in the context of medical devices this one's easy because I am diabetic it's the idea of using AI in insulin pumps so for example we've moved a long way with insulin pump technology Now using uh AI systems to predict hypo and hypoglycemia and either taking automatic or recommended courses of action to mitigate that outcome um in either of those situations I would highly suspect that that would qualifies as high risk but now there's a bit more to this you an organization in this space is already you know complying with existing reg legislative Frameworks they're doing Conformity assessments and the ACT Nots to the fact that organizations will have to navigate multiple Frameworks and in the interest of ensuring consistency and avoiding administrative burden there's an option to give such organizations quote flexibility with regard to operational decisions on how to ensure compliance with multiple regulatory Frameworks which uh seems userfriendly uh and we are we are expecting guid on this and we'll talk about that at the very end now let's talk about the so what of this uh previously I mentioned quite simply here it is not so quite simply this is basically the what must happen if you have a high-risk ey system uh you are looking at a representation of an AI systems life cycle uh where here we're starting and here we're in post deployment um we'll start with what happens upfront so you must comply with requirements which are articulated across articles 8 through 15 um these are the seven requirements they each occupy about a space uh a page or two pages or three pages worth of text i' recommend that if you think you have high-risk AI systems that play in your organization or you plan to you read this for now I'll give you a very high level notion of what's included here starting uh going kind of sequentially so we'll start with Risk Management Systems uh we know that these have to be in place we know that it has to be continuous process and that it has to extend across the entire life cycle um broadly it needs to be able to identify foreseeable risks unex you know unsurprisingly evaluate uh and qualify and manage these risks um these that same function uh it's not just upfront it's just not it's not just before you go pushing towards deployment it's after you've deployed you need to continue monitoring uh monitoring and managing risks next is data and data governance this sets out requirements for train training validation and testing data sets and it speaks to considerations around design choices data collection and preparation processes fundamentally the data sets used need to be relevant to the AI system or and its quote intended purpose that idea of an intended purpose is really crucial all compliance activities because it sets the foundation for basically evidencing that you are um able to deliver on that intended purpose without risk of harm the data sets need to be relevant and the AI system needs to set out some requirements associated with protected data next is technical documentation I'm not going to go into this it's fundamental purpose is to prove that they systems compliant this is the only to my knowledge the only requirement that has its own very own Annex found in Annex 4 which is qu which gives a kind of minimal minimum viable uh technical documentation list um we move to recordkeeping so recordkeeping you effectively have to have the ability to automatically record events over the lifetime of the system and that includes uh every time that high-risk system has actually been operationalized this in turn facilitates things like postmarket monitoring which we'll head which we'll touch on later transparency for high-risk systems is different from transparency which I'll talk later about uh limited risk systems but for now transparency needs to um be designed into the system it needs uh end users need to be able to actually use it they need to be able to interpret outputs uh and they need to use the system appropriately and this includes things like instructions for use contact information of the provider and key characteristics about the system including its capabilities and limitations uh human oversight this is not um Earth shattering but it's useful to know that it's one of the requirements effectively a high-risk system needs to be designed so that humans can oversee it over the course of its development and deployment uh interestingly human oversight is articulated in a way uh respects for proportionality so basically the level of oversight must correspond to or be commerate to the level of risk autonomy context of use and then finally accuracy robustness and cyber security Al Tre love together cyber security this is effectively uh the highis system needs to be secure from external threat robustness it needs to be resilient to any kind of perturbations and data or um the context in which it's been applied and accuracy is interesting um if you're scratching your heads because I've given you a very high level notion of what all these things are um I think you might continue scratching your heads when reading the text there's an expectation that guidance will come come out to facilitate understanding of how these things can actually be delivered upon right now we're I I am of the opinion that we're still in this kind of space of uh both prognostication and hypothesis so if we move on you've you've filled you you know you've set up or established a way to comply with your seven requirements you've done things like conduct a fundamental rights impact assessment which I'm not going to touch on you then get to the space of being thinking your deploy deployment ready uh and at this point you will have to was talking about this earlier uh conduct a Conformity assessment with the notified body and for your reference I got all the Articles if you wish to read the exact text um and once you receive a certificate that you are in fact in Conformity you will articulate you as an organization will write up a declaration of Conformity you will affix a c marking to your high-risk AI system in some way and then you will register it in an EU database at which point you are ready for deployment but it doesn't end there because once you've deployed you have to ensure that you have a postmarket monitoring system in place where you are establishing and documenting um then you know basically ensuring that the risks that you have identified are not kind of coming up and that any risks that do arise you're able to to cope with them or mitigate them all with the view to continuous compliance and should anything go become egregious you have to report any serious incidents to the market surveillance authorities which I mentioned earlier now we'll move down the tier down the uh risk levels to The Limited risks AI systems um look these are generally defined in terms of being AI that generate or manipulate image audio video content with respect to video content constituting a deep fake it also includes text um and in addition to this kind of AI generated content it includes chat bots so you see on the screen what we've all collectively witnessed over the past several years we've got Pope and Co We've Got Deep Tom Cruz this I just saw recently Netflix is apparently used AI um to manipulate images in a true CRI documentary and then of course we have becauseas in the UK King Charles doing a jig all of which are uh generated by artificial intelligence these would qualify as limiting risk AI systems um what do you do about this quite simply you have to disclose the existence of such generated or manipulated content so you can might imagine um in the world we are in in context of using of AI systems distorting the public space so politics Etc um this requirement becomes increasingly important for chatbot whoops for chatbots the require my computer doesn't like me my for chat puts the requirement is that uh the AI system needs to be designed and developed in a way that end users are aware they're interacting with an AI system and you can find this in article 50 we'll move down again to the minimal risk AI systems um according to European Union documentation this is the vast majority of AI systems currently used in the EU the two examples that are given time and again spam filters and AI enabled video games or non-playable characters in video games but if we stretch our imaginations ever so slightly we might think of other scenarios which would qualify as minimal risk I am not a lawyer do not consider this legal advice if you use such systems but in my estimation these require qualified so that might be AI systems that are used in uh optimizing Logistics and Supply chains telling when trucks should drive out when boats should arrive etc etc um and we might extend that to an office environment where AI systems are optimizing scheduling when should Dr a come in when should Dr y leave and so on and then AI systems in the home for example AI systems using uh that are optimizing electricity usage uh we might think of a Ness so long as all it is doing is basing its predictions or optimizations on previous inputs into temperature my expectation is that it would qualify so what do you have to do about this quite simply the minimal risk tier has no new obligations and everything you do is voluntary um providers AA no here's an important caveat article 95 that relates to both the minimal risk tier but also the limited risk tier so AI systems that are not high-risk those providers should be encouraged to create codes of conduct including related governance mechanisms intended to Foster the voluntary application of some or all of the mandatory requirements applicable to highrisk systems from my perspective that's a stretch because those high-risk requirements can be quite extensive um but ultimately this is at the discretion of you your organization your team however you uh can allocate those responsibilities and we in we have the expectation that guidance on this will be forthcoming now what's worth not mentioning mandatory requirements in my understanding refers to the seven requirements I went through earlier and not the laundry list of things that happen after that like getting uh doing Conformity assessments um fixing CD markings Etc so now we're going to Pivot to the second of the uh three interventions note that we are complying with the Trans transparency obligations for The Limited risk tier for general purpose AI uh models there are a number of interventions um the I'll start off I'll start at the start I mentioned earlier that just distinct from the risk tiering and the regulation of AI systems the focus on general purpose AI models which we might call gener of AI um and general purpose AI models get their own kind of specific space because of their uh their their ability to be applied in multiple context they're not single purpose models um the regulation here focuses on the model level not the use case level however the use case level will still be relevant and I'll explain how in a moment um there are two tiers of general purpose AI models uh one just called general purpose AI models there's a little bit of Distinction here between open versus closed models where closed models are facing the line they have more kind of requirements associated with them general purpose models presenting systemic risk is the other tier and this is interesting because it's basically determined by um the volume of compute used I do not have the exact number um and is also defined by the notion that they have high impact capabilities um and that includes having uh the potential to have negative effects in relation to major accidents disruptions of critical sectors serious consequen to public health and safety any actual or reasonably foreseeable negative effects on Democratic processes public or Economic Security um now if we move along independent of the tier both of these kind of model Prov the model providers of both these models will face similar requirements so they have to maintain up-to-date technical documentation including training and testing processes and evaluation results they have to enable providers of AI systems integrating these models to have a good understanding of the Care capabilities limitations they have to make publicly available a sufficiently detailed summary about content used for training and uh they have to comply of course with copyright legal obligations I'm not going to go into the detail for gpay models presenting systemic R risks needless to say they have more work to do before their uh before their models to be are put on the market why does this matter to a group of people who are probably not um model provider gpay model providers quite simply the new requirements that I've just mentioned should set expectations for Market actors so if you're a deployer of an AI system so you've built an AI system and want to integrate this thirdparty general purpose model you should expect this kind of documentation and it should feature into um any uh any compliance activities you have ongoing so if you have a high-risk GU system using Chachi bt4 you need their technical documentation to kind of build up your own uh what's also important to note and I I wasn't going to go into this but I will quickly say it is that uh an organization Downstream user of a of a an open AI model who uses does significant modification and fine-tuning on that model and then puts it into the deployment on the market kind of under their own name becomes a deployer of a general purpose a model and they are hit with the obligations I've just laid out uh importantly um there's a bit of complimentarity here they don't have to do all the work they just have to show their work for what the the changes they've made now we're going to Pivot out of these three interventions and do a little bit of a thought experiment so I've told you about all these requirements hopefully you're still awake um here they are in a very ugly slide if we're at a state where we know what that these requirements are hitting how can we begin to prepare uh especially if we don't have certainty about how to actually deliver on these things or comply with them first I'd encourage you to get a really as deep an understanding as possible of these requirements and think in terms of how will this change how will this impact the organization from a change management perspective which managers will need to be responsible they need to have a detailed enough understanding so that they can think in terms of how different parts of the org maybe your data science and engineering teams will be impacted uh will be hit they might need your data science and Engineering teams might need to do new things they might need to refine things they are doing and finally your administrative impact will hit bringing in probably everybody including your legal and compliance teams who will have to have access to important materials that are produced by those managers and produced by those data science and engineering teams in order to you know demonstrate compliance going forward why bother well if you're an organization in America or anywhere if you're an organization outside of the EU and the EU is one of your main markets and you're selling systems that feature limited or high-risk AI systems into Europe um you need to be compliant you have to demonstrate compliance you have to go through the Conformity assessment process if it's a high-risk system and if you do not um you face pretty steep fines so really compliance is the only option if you are selling within or into Europe first let's talk about the unacceptable risk here I kind of alluded to this earlier this is the highest um highest level kind of penalty up to 35 million or 7% of uh total worldwide annual turnover for the previous Financial year high risk and limited risk non-compliance gets hits with 15 million and 3% 15 million or 3% of annual worldwide turnover and in the case of doing your job doing your compliance activity badly well you also get HD for this so if you supply incorrect incomplete or misleading information you can face fines up to 7.5 million or up to one uh 1% total worldwide annual turnover so we're going to wrap up now the EU act establishes a number of interventions I've really focused on three narrow ones but there's a lot of nuance that I've missed today so I will throw my hands up and confess that um first the risk levels that I mentioned and the focus on AI systems I hope it encourages organizations or you to think through uh understanding well what are the assets I have at play in my organization today what are we planning to have in future can we map them out and we will need to map them out in future and we will need to qualify them this is fundamental because if you don't do this you have you expose yourself to non risk of non-compliance um these new obligations for general purpose model providers again if you're a consumer of these models I strongly think in terms of well uh set expectations that this information will be provided to you and you have to carefully incorporate into your other governance activities and then finally did you non-compliance I hope motivates you to kind of um kind of do what I was hinting at in the last slide which is kind of prepare anticipate think in terms of okay if we're going to be hit by a number of new requirements and obligations how should we be preparing to adapt and let's talk a little bit about logistics so right now we're awaiting what's called official publication in the European Journal once that happens there's a 20-day uh countdown and after that 20-day is complete there's a Cascade of requirements to hit the market um importantly within 6 months there's a ban on unaccept the unacceptable risks here so those prohibited AI systems can no longer be placed in the market uh after 12 months from that 20 days rules for general purpose AI model providers and high-risk AI systems hit and then after two years the whole EU Act is applied and you might think but how still Jacob you've not told us at all how we do it and I'm not the guy to tell you how to do I'm the guy to tell you you should you you need to start thinking about planning for now you should expect this from different European entities right codes of conduct conduct codes of practice standardization activities and guidance that'll help with a lot of the really important things so for example that idea of what I mentioned at the end of the M moris tier that idea of voluntarily applying some of the high-risk requirements to your governance process there should be guidance on that or codes of conduct on that obligations for providers of general purpose models uh Clarity will come through guidance transparency obligations associated with detection and labeling of artificial gener manipul content so that kind of transparency stamp for The Limited risk tier again we should expect we should expect some um guidance and so on and so on most importantly I think is this fundamentally there will be guidance on the Practical implementation of the EU act and in the meantime any organizations including my own will try to figure out ways to prepare for that um what to leave you with well I'd encourage you to ask yourself a your question which I've hinted at earlier um can you say that you know all the a systems currently operationalize in Development Across your org and if you can say that can you are you confident about the risk levels of those are you confident about whether you're a deployer or a um um provider or both are you confident that there's a team or in your organization or maybe teams that are getting ready for the eua ACT and as a sub question of that do you you know the lead person's name and if you don't and if I'd encourage you to explore because hopefully there's some work being done and you don't have to come up with figuring all this out on your own in terms of what next to figure out from us um we'll have another uh webinar in the series that's going to be focused on the key pillars for achieving Readiness which I alluded to uh and then after that we will have a session focusing on um building a system of trust which has kind of wider relevance um Beyond just the and that is the very quick Whistle Stop tour of the unpacking of the U act I hope you found it useful I think we're going to Pivot to a little bit of a Q&A thank you so much Jacob uh for the presentation really insightful uh we did get some audience questions so uh gonna start us off with with a a fairly softball question but uh someone was asking does the EU act impact the UK just I just opened it up and saw that question in fact if you are an organization operating within the UK and selling into Europe then yes it's not that the UK will absorb the eua act at a legal level a legislative level they're discreet so the EU the UK has its own approach to AI regulation which is much more decentralized um its own kind of legal Frameworks so to re to repeat if you're an organization operating in any country outside of Europe but selling into Europe the EU Bears relevance to you it's like gdpr um but if you are an organization operating in another country has nothing to do with Europe uh you just follow domestic legal Frameworks aome and so we had a second question as well when you were speaking about the different risk tiers so someone was asking does the Health Care System belong to a highrisk tier the health risk the Health Care System health healthare system um so as I understand it it relates to there's explicit mention of um it depends it depends on the AI system at play so if you're using AI to as I mentioned earlier that very silly kind of not silly madeup use case of using AI to optimize back office function in a healthcare function then no doesn't really bear relevance if you're using it I would argue again I'm not a lawyer um I would argue that if you are using AI as a safety mechanism in any kind of uh equipment in an office or in a um um a hospital or or AI as a product in equipment in a hospital then I would argue probably does qualify as a high risk because of that second track if you recall but again ask your own legal team that's my view so one of the key theme seems to be ask your your legal team just to conf yeah no I'm uh that's my big cop out I just for transparency with the team with the team I lead we one of the first things we say when we work on legislative topics is that we are not providing you guarantee of compliance we will provide you insight to the best of our abilities and support with Readiness uh and implementation but we do encourage that if it's a legal determination it has to be an internal decision to your company not I wouldn't rely on me fantastic so we have another question uh what measures key players are taking regarding the EU act that's an interesting one um when we say key players I'll just refer to my exposure to different kinds of organizations across the globe um there's increasing interest outside of Europe there's of course increasing interest inside of Europe um there is a pretty good understanding that uh the exactitude the exact kind of approach for compliance is still fuzzy uh but there is an increasing kind of appetite for getting ready like how do we really kind of start thinking and preparing for this um a lot of that relates to wider governance considerations um which starts with topics like um do can I understand all the assets that I have at play in my organization do I have a registry function can I consistently qualify um can I ensure that we have some kind of review and sign off practice that before things go to deployment so there are kind of the the small steps in this direction are starting with how do we get smart about kind of governance practices fantastic uh another question has come in should users be informed if a Content text or image is generated by an AI system yep that's that limited risk tier perfect okay so we have a little bit of a a longer question here so uh we operate a startup we will be implementing several a AI systems amongst other detecting stress amongst users uh in our system in order to be able to detect if we should change our system to help users diminish stress as of what size a company has to abide with the system number of company staff or a number of clients served uh in the financial turnover I just read that Johan and I I'm smiling because it's one of the things I intentionally skipped so there it applies to every organization um I'm going to put my hands up and confess look there are stipulations for smmes and microenterprises so I would recommend there's a lot that the European Commission in their first draft and has and European kind of other entities have supported because it's been maintained over the course of the lifetime of the eua ACT um to ensure that Innovation can still happen in Europe I'm assuming you're based in Europe if you are you will have resources made available to you according to the that will help with compliance um I don't know these in great detail but if you just Google or if you control FindMe um on the eua ACT you will find that there are a lot of Provisions to make sure that the eua ACT basically doesn't kill Innovation um it includes things like sandboxes um it includes things like guidance it includes um there are other things that are kind of outside of the EU act but coming out of the coordinate action plan like access to um other services so there should be a lot Available to You fantastic we're getting great questions from the audience we have uh we have another one coming in here uh what about auditability are there any specific considerations under this act um I wish I knew what a little bit more precise for the question so auditability is kind of implied I think I within the high-risk requirements the the idea of AIT it's not really coming up effectively a compliance a Conformity assessment requires that you articulate a whole lot of information about that a that AI system um which could function like an audit actually I'm going to take a step back um I don't know how many of you are based in the UK hopefully I think a few of you a few years ago maybe a year and a bit ago there's something called the drcf the digital regulator cooperation forum and they published a paper on AI audit in which they were quoted somebody which I love and I will never forget this quote that AI audit on the market globally is currently the wild west um I think as things like the eui act and other regulation become more formalized audit will become more tractable um as for what the AI act itself says about audit no don't you know nothing springing to mind all right so we have another question from Mark um how are traditional data governance practices transferable and applicable to new governance requirements for AI that is a good question um I think I so if we go into look in general or with respect to the ACT sorry can you repeat that with respect to the AI act okay um the data and data governance elements of the AI act have provide a little bit of information about what's expected I don't know basically who owns the data who from a data governance perspective where does it sit who owns it who can access it I think become increasingly relevant in ensuring that uh that's maintained across the course of access rights When developing a system um there's nothing really ex I'm just kind of scrap scratching my head about this one David even might be a better person to answer that but um I might skip that one because I think I'll do it a disservice but it's a good question yeah no worries Jacob we do have a couple more if you're still up for it I'm up I'm up for it give me give me a softball so next question here from Robert uh do you have any recommendations on best practice documentation uh to produce around testing strategies test cases and test results for uh the AI System including any coverage of metrics and defect reports that's a fantastic question and no I don't I wish I did basically we look at the market and um we're kind of waiting on this from standards organizations uh one of the uh kind of outliers in this space from a public sector point of view is Singapore I think the UK might be creeping into the space Maybe um but Singapore has come out with something called AI verify which touches exactly on what you're ref referencing this idea of okay what exactly should we be doing with respect to Benchmark this bench metrics um we're kind of waiting with B breath to hear from ISO maybe even centc but in particular we need that guidance on the full implementation of the AI act which we're kind of promised in the eui ACT uh for Europe itself so it's kind of a I I got happy that I was asked that question because it's kind of amazing that we still don't have best practices out there but give it time all right so I think we'll take just one more question here um so a fairly softer one as well so are a generated uh media free of copyright and Beyond the scope of the ACT AI generated media free of copyright um I would ask what that AI generated media is based on how is it generating I think there's an order of operations question so I'm assuming that the nii system that's generating articles is being fed with something if it's scanning other newspapers to generate summary articles then I think it would probably be hit with that copyright issue um but again ask your lawyer because I think that that's a it's not just creating new media I hope it's not just creating new news stories out of nothing but um there's a there's an order of operations challenge there that you might want to tackle fantastic well I think we're gonna end it here but thank you so much Jacob uh for the great presentation uh and for answering a lot of the audience questions uh to the audience this will this is currently recorded and will be available to you uh after the webinar we're also going to try and follow up with a lot of the questions that did come in through the Q&A uh so not to worry if your question didn't get answered today um and thank you again Jacob thank you everybody for joining hopefully you found it um informative uh if you stayed awake can I just really quickly respond to Alistair Hughes will there be features in data I to help us track compliance the answer yes y thank you aler the answer to that is yes and in fact that's one of the core part of the product that my team works on it's called govern um you're welcome to look at uh our website to find out more about it um future parts of the webinar series will'll show more about govern and what we've been doing in the context of the AI um thei act all right sorry sorry to cut your conclusion off but thank you everybody
Up Next

Understanding Fair Use: The Four Factors in Copyright Law
@USCopyrightOffice
80.2K views•2019-10-30

Young Thug YSL Trial: Legal Arguments on RICO Evidence and Confrontation Clause Issues in Court
@11Alive
13.7K views•2024-05-16

Forensic Phonetics: Speaker Identification in Legal Cases
@nptel-nociitm9240
539 views•2025-03-19

Police Interrogation Tactics: False Confessions & Legal Reform
@LastWeekTonight
7M views•2022-04-18
Related Study Plans & Knowledge Roadmaps
Structured learning paths in Law






![Free CIPP/E European Privacy Training Course [4/5] | Application of GDPR](https://i.ytimg.com/vi/hPIV7R4wYis/maxresdefault.jpg)































