The AI Act: A Lawyer's Paradise

The AI Act is the first broad piece of legislation in the world dealing specifically with artificial intelligence. It applies in phases: the prohibited practices and the AI literacy requirement already apply, the rules for general-purpose AI models followed, and the bulk of the obligations, including those for high-risk AI, take effect in the years after that. The exact dates are under pressure from ongoing European discussions about simplification, so anyone preparing would do well to keep track of the current state of play.

For organisations, this mainly raises practical questions. Who is responsible when an AI system is actually deployed? The Act draws a sharp distinction between the provider, who develops a system or places it on the market under its own name, and the deployer, who uses the system under its own authority. That distinction determines which obligations rest on you, and it shifts. Anyone who substantially modifies a purchased system, puts their own brand on it or uses it for a different purpose can unwittingly become a provider, with all the documentation, conformity and oversight obligations that come with it.

Precisely because AI is rarely built entirely in-house, the compliance question moves into the supply chain. Supplier, integrator and end user all depend on each other's information: without technical documentation, instructions for use and arrangements on data, logging, incident reporting and human oversight, none of the parties can demonstrate compliance. The contract therefore becomes the instrument in which responsibilities, information flows, warranties, liability and risk are genuinely allocated. Those who fail to address this explicitly only discover where the gaps are when an incident or audit occurs, with fines that can run into millions of euros or a percentage of worldwide annual turnover.

In this session, Bram Hoovers uses real-world examples to guide you through the legal and practical impact of the AI Act. Not a theoretical treatise, but a translation into what compliance actually means: which choices you need to make now, which arrangements to record with suppliers and clients, and where organisations stumble in practice.

What you will take away

  • The distinction between provider and deployer, and when you switch roles without realising it
  • The key obligations under the AI Act and who bears them
  • Contractual allocation of responsibilities and risk across the AI supply chain
  • Common pitfalls in compliance projects
  • The role of lawyers in AI governance and implementation

Who should attend
In-house counsel, compliance and privacy professionals, procurement, and anyone within the organisation who decides on the development or use of AI.