Everything You Need to Know About the AI Act (European Regulation on Artificial Intelligence)
What is the AI Act?
The AI Act, or European regulation on artificial intelligence, is legislation adopted by the European Union in 2024. It aims to regulate the development, deployment and use of artificial intelligence systems to ensure ethical, secure AI that respects the fundamental rights of European citizens.
Who does the AI Act apply to?
The AI Act applies to:
- All companies based in the European Union that develop or use AI systems;
- All organizations outside the EU whose AI systems are used in the EU;
- All public and private entities, regardless of their size, as soon as they market or operate an AI system.
Which AI systems are covered by the AI Act?
The AI regulation classifies AI systems into four risk levels:
- Unacceptable risk: prohibited AI (e.g.: social scoring, cognitive manipulation…)
- High-risk AI: highly regulated (e.g.: safety, health, education, HR…)
- General-purpose AI: such as GPT or Copilot type models
- Minimal or low risk: light transparency obligations
Who are the main actors concerned by the AI Act?
The regulation defines several roles:
- Provider: the entity that develops or has an AI system developed
- Deployer: the entity that uses AI within its organization
- Importer, distributor, authorized representative: all links in the chain are concerned
Each has different obligations depending on their role and the risk level of the system used.
What are the obligations of the AI Act for high-risk AI?
High-risk AI systems must:
- Be subject to a risk analysis (Art. 9)
- Be technically documented in detail (Art. 11)
- Ensure data quality (Art. 10)
- Allow for human oversight (Art. 14)
- Guarantee security and robustness (Art. 15)
- Affix CE marking and register the system in a European database (Art. 48)
# What is the difference between the AI Act and the GDPR? Both the AI Act and the GDPR are European regulations aimed at protecting individuals, but they focus on different aspects: ## GDPR (General Data Protection Regulation) - **Scope**: Protects personal data and privacy of individuals - **Focus**: Processing of personal data by organizations - **Obligations**: Consent, data subject rights, data protection impact assessments (DPIAs), appointment of a DPO, etc. - **In force since**: May 25, 2018 ## AI Act - **Scope**: Regulates artificial intelligence systems based on their level of risk - **Focus**: Development, deployment, and use of AI systems - **Obligations**: Risk classification, conformity assessments, transparency requirements, human oversight, technical documentation - **Entry into force**: Progressive between 2024 and 2027 ## Key Differences 1. **Subject**: The GDPR regulates **data**, while the AI Act regulates **AI systems** 2. **Approach**: The GDPR is based on protecting fundamental rights to privacy, while the AI Act adopts a **risk-based approach** 3. **Complementarity**: An AI system that processes personal data must comply with **both** the GDPR and the AI Act ## Practical Example A recruitment AI system must: - Comply with the **AI Act** (as a high-risk system) - Comply with the **GDPR** if it processes candidate personal data The two regulations are therefore complementary and often apply simultaneously to AI systems that process personal data.
The GDPR protects personal data while the AI Act regulates artificial intelligence systems.
Both regulations are complementary: an AI system using personal data must comply with both the GDPR and the AI Act.
What are the sanctions in case of non-compliance with the AI Act?
Sanctions can go up to:
- 35 million euros or 7% of global turnover for the most serious violations;
- Warnings, market withdrawals or usage restrictions.
How to achieve compliance with the AI Act?
Here are the recommended steps:
- Raise awareness among teams (e-learning, responsible AI charter)
- Appoint an AI Act lead (often the DPO or an AI officer)
- Map your AI systems
- Classify the risk level of each AI
- Implement the required technical and documentary measures
- Establish AI governance and a quality management system
What ethical principles guide the AI Act?
The AI Act is based on 7 core principles:
- Social and environmental well-being
- Transparency and explainability
- Data protection and privacy
- Technical robustness
- Accountability
- Fairness and equity
- Human autonomy and control
These values must guide every stage of your AI lifecycle.
What tools exist to support companies in their compliance with the AI Act?
You can:
- Use AI Act compliance software (AI register, risk analysis, documentation…)
- Be supported by GDPR/AI experts
- Train your employees with AI Act e-learning
How to know if my organization is concerned by the AI Act?
You are concerned if:
The risk-based approach is at the heart of the regulation: a mapping of your AI systems is essential to determine your obligations.