Skip to main content
Compliance when using AI
Back to all Insights

Insights · Compliance

Compliance when using AI

The EU AI Act creates binding rules for high-risk AI. Companies should classify their systems, clarify responsibilities and prepare the required compliance measures.

Published
18 October 2024
Reading time
4 min read

Share this article

The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024. This initially marks the start of an implementation period. The Regulation will then gradually become directly applicable from February 2025. The provisions on so-called high-risk AI, together with most of the other provisions, are intended to apply from August 2026. During this implementation period, providers in particular, but also deployers of AI systems, must classify their respective software within the regulatory framework.  

An “AI system” means software designed to operate with varying levels of autonomy, which may exhibit adaptiveness after deployment and which, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions.  

Which AI applications are affected?

Article 6(2) of the AI Act in conjunction with Annex III provides a list of high-risk categories. For the time being, this list is exhaustive, although the Commission may amend and expand it.  Apart from the use of AI applications by public authorities in areas such as law enforcement, public security and the administration of justice, the following categories are likely to be relevant for companies: 

  • AI as a “safety component” of products 

  • Biometric identification and categorisation of natural persons 

  • Operation of critical infrastructure using AI 

  • Human resources management (particularly selection decisions) 

  • Assessment of creditworthiness and credit scoring 

Within these categories, an AI system is generally considered high-risk unless an exception under Article 6(3) applies. This is the case, for example, where only narrowly defined procedural tasks are performed or where a fundamentally human assessment remains the basis for the decision-making process. 

 Unlike certain AI practices that are simply prohibited (Article 5, for example “social scoring” and “remote biometric identification in public spaces”), high-risk AI systems are generally permitted but are subject to restrictions and extensive obligations.

The AI Act requires companies to act

Our white paper, “The EU AI Act: A Clarius Guide”, explains the background, objectives and core content of the AI Act, as well as the associated challenges, and provides practical recommendations for companies.

Download the white paper here without obligation!

What obligations apply to providers?

Under the AI Act, a provider is anyone who develops an AI system and places it on the market. It should be noted that, beyond the wording of this definition, distributors, importers, deployers and other third parties may also be covered under the conditions set out in Article 25 of the AI Act. Obligations arise in particular from Article 16 and include: 

  • Ensuring that the AI system complies with the requirements of Articles 9–15 of the AI Act (for example documentation and transparency obligations, the possibility of human oversight, accuracy and cybersecurity).  

  • Operating a quality management system 

  • Carrying out a conformity assessment procedure under Article 43 of the AI Act before placing the system on the market  

What obligations apply to deployers?

A deployer is an entity or body that uses an AI system under its own authority. Under Article 26 of the AI Act, deployers must ensure that: 

  • The technical and organisational measures necessary to ensure proper use are taken. 

  • Human oversight is provided by a qualified person. 

  • Certain deployers carry out a “fundamental rights impact assessment” under Article 27 of the AI Act. 

What obligations apply to distributors and importers?

Under Article 23 of the AI Act, importers must verify that a conformity assessment has been carried out and that the necessary marking and documentation are in place. Similar obligations apply to distributors under Article 24. Article 71 of the AI Act also provides for fines that can be extremely high for companies. Infringements relating to high-risk AI systems can result in fines of up to EUR 15 million or 3 per cent of worldwide annual turnover.  

Conclusion:

Companies, public authorities and other bodies should use the AI Act’s implementation period to review their software applications against the new regulatory requirements. Given the considerable complexity involved in some cases, this should be taken seriously.  

We will be glad to support you in implementing the AI Act and minimising the risk of sanctions in your company. 

Get in touch now

Do you have questions about this topic?

We can assess what the development means for your organisation and advise you directly.

Contact us

Would you like to stay up to date with the latest developments?

Sign up for our newsletter

From EU directives and AI to the industrialisation of different service areas, the market is undergoing significant change, and so is Clarius.

Our newsletter provides regular updates on developments that may be relevant to you.

Form loading …

Your personal contact

Matthias Schulz

Matthias Schulz

Director Sales

Get in touch by email