Are we really ready for the European Artificial Intelligence Act?

After all, it is society that determines the rules governing the use of information.
technology, seeking the right balance between innovation and protection.

 

La European Union approved the historic Artificial Intelligence Act and now finished, it is the first
comprehensive regulation on artificial intelligence adopted anywhere in the world. And we have
seen in other areas - especially in matters of privacy - that the legislative approach of the
UE has had a significant influence elsewhere, although it is still early to say
whether policymakers in other regions will view this law as a model. The AI ​​Act of
The EU takes a horizontal approach, regulating AI whether it is a software offering
independent or integrated into hardware, as in the case of an autonomous car.

 

It also follows a life cycle approach regulating aspects of AI from the quality of the
data used
to develop the service, up to the tests of precision and bias, the
human oversight, development or post-market monitoring. All parties
involved in the development, introduction, sale, distribution and use of AI systems
must comply with the obligations established in said law.

 

Since AI systems available on the EU market are often also
will be sold in other parts of the world, and that the EU AI Law will apply wherever they are
use the results of an AI system in the EU, a coherent global approach is recommended
to implement its requirements and ensure compliance.

Key elements of the EU AI Law

The EU AI Law addresses three key areas of risk. First, it bans certain uses of AI
which are considered to be of unacceptable risk, such as, for example, biometric identification in
real-time surveillance carried out by law enforcement in public spaces. Second, it adopts a
regulatory regime for so-called high-risk use cases, those in which the use of
AI could affect significant rights or opportunities available to individuals.
people (for example, in law enforcement, education or employment). And third, for
fundamental models such as large language models, or general purpose AI
(GPAI) imposes transparency obligations for users
have more information about how these models are developed and when they are being used.

AI Risk Management and Governance

Risk management is at the core of the EU AI Act's approach. Companies should therefore
They must identify who has overall responsibility for such management. That person must
work with a multidisciplinary team that includes individuals from the legal,
privacy, security and business to map the AI ​​systems that the company is
developing or using, and to assess the potential risks posed by, such systems.
After that analysis, the team can identify how to address or mitigate them.

There is a strong link between good AI governance and the requirements of the AI ​​Act
of the EU. In any AI development, it is important to have a process to identify, evaluate
and manage risks. In addition, to ensure good results, companies must use
high-quality data. It is essential to monitor the performance of the AI ​​model to avoid
deviations and mitigate potential biases. And any AI that makes recommendations should
be subject to human oversight. Overall, an end-to-end strategy is required
extreme in AI governance.

 

From a perspective of business strategy, companies must think in a way
holistic approach to how to incorporate AI governance into your development processes and
compliance. When developing AI products, they need to assess whether these fall within
the scope of the law and establish processes to ensure compliance with its obligations.
When a company implements AI systems developed by others that are subject to the
law, you must use those systems in accordance with the instructions provided by the
system developer and ensure human oversight in the use of any results
of the System.

In many ways, this is similar to compliance obligations in other areas; however,
However, it will be important for companies to consider the unique aspects of AI, including
new risks not covered by other legal frameworks, and develop the necessary experience
to use them responsibly. And, in implementing the law, there may be provisions
that make sense to apply only to offers on the European market, in the same way
that companies sometimes apply specific provisions of the GDPR only to data
originating in Europe.

In general, building a proSolid AI governance framework will take much of the way.
The specific details of the EU AI Act will still need to be considered, but just as
that with a strong privacy program, it's about making adjustments on a solid foundation.
When will the EU AI Law come into force?

The EU AI Law sets different deadlines for implementing its provisions depending on the
risk category, and these deadlines begin with their publication in the Official Journal after
of final approval:

 

 Unacceptable risk AI: six months from approval – February 2, 2025.

 General purpose AI: 12 months – August 2, 2025.

 High-risk AI: 24 months – August 2, 2026.

 All risk categories, with some exceptions: 36 months – August 2,
2027.

 

Conclusion

 

As with any new law, it will be important to watch how it is applied. With the
AI, much is left to the development of standards, so it will be relevant to see how these
will impact compliance. In addition, there are several regulatory bodies involved in
Member States that will be responsible for enforcing or advising on aspects of
the law. Watching how this advice evolves over time will be informative.
However, these aspects also provide flexibility, so that the law can remain
functional even as AI technology continues to advance in new and exciting ways.
unexpected

 

Jason Albert – ADP Global Chief Privacy Officer

Coexia®

AI in the foreign trade

Hi! I'm Coexia. How can I help you today with your internationalization strategy?
Coexia IA