AI Act
AI Act is an EU regulation establishing requirements for artificial intelligence systems. AI Act classifies AI systems by risk (unacceptable, high, limited, minimal) and introduces obligations for providers and users, including transparency, testing, and human oversight requirements.
What is AI Act?
AI Act Definition
AI Act (Artificial Intelligence Act) is a European Union regulation adopted in 2024 that comprehensively regulates the development and use of artificial intelligence systems. AI Act is the first such comprehensive AI regulation in the world, introducing a risk-based approach and specific requirements for AI system providers and users.
AI Risk Categories
Unacceptable risk (prohibited):
- Social credit systems
- Exploiting vulnerable groups
- Real-time biometric identification in public spaces (with exceptions)
- Subliminal manipulation
- Emotion recognition in workplace/education
High risk:
- Critical infrastructure
- Education and employment
- Public services
- Law enforcement
- Migration and asylum
Limited risk:
- Chatbots and virtual assistants
- Emotion recognition systems
- Deepfake generators
- Transparency obligation
Minimal risk:
- Video games
- Spam filters
- Inventory management
- No special requirements
Requirements for High-Risk AI
- Risk management system
- Data quality and governance
- Technical documentation
- Record keeping (logging)
- Transparency for users
- Human oversight
- Accuracy, robustness, security
- CE marking
AI Act Timeline
- 2024: Regulation adoption
- 2025: Ban on prohibited practices
- 2026: Requirements for GPAI
- 2027: Full application
AI Act and Cybersecurity
AI Act includes cybersecurity requirements:
- Robustness against attacks
- Protection against manipulation
- Incident logging
- Security by design
Penalties
- Prohibited practices: Up to €35M or 7% of turnover
- High-risk violations: Up to €15M or 3% of turnover
- False information: Up to €7.5M or 1% of turnover
AI Act vs Other Regulations
| Aspect | AI Act | GDPR | NIS2 |
|---|---|---|---|
| Subject | AI systems | Personal data | Cybersecurity |
| Approach | Risk-based | Rights-based | Security-based |
| Scope | AI providers and users | Data controllers | Essential entities |
AI Act is a groundbreaking regulation that will fundamentally change the AI industry in Europe, imposing obligations on both AI system providers and their users.