How to navigate the AI Act: Back to the Basics

Does your organisation work with AI systems, or technologies that function like them? If so, you may be navigating a web of compliance obligations under the AI Act. These obligations can vary depending on your role and the type of risk classification your AI system falls under.

This blog mainly focuses on the first step towards AI compliance, defining your system. AI is used to describe various levels of automation, but not all cases of automation qualify as AI under the AI Act. After defining your system, this blog will introduce the next steps: risk classification, role determination and compliance obligations.

 Step 1: Defining your System

Article 3(1) of the AI Act contains seven elements that must be present at some point of the AI’s lifecycle for it to be seen as an AI system under the Act.

An AI system is understood as the following in article 3(1) of the AI Act:

  • A machine-based system: refers to the hardware and software of the AI system (e.g. storage devices, memory, operating system, computer code, etc.).
  • That is designed with varying levels of autonomy: means that it can act with independence of actions without human intervention (e.g. self-driving cars, traffic control systems, robotics, etc.).
  • And that may exhibit adaptiveness after deployment: which refers to self-learning capabilities (e.g. smart devices or chatbots which use user feedback).
  • And that, for explicit or implicit objectives: by which ‘implicit’ means goals not explicitly stated, and ‘explicit’ refers to directly encoded goals (social media recommendation models (implicit) or language translation (explicit) etc.).
  • Infers from the input it receives: uses different inferencing techniques, such as machine learning (spam detection systems, pre-training language models, image classification) and logic- and knowledge-based (sorting, matching, searching).
  • How to generate outputs such as predictions, content recommendations, or decisions: such as estimating unknown values, new content, suggestions or fully automated conclusions.
  • That can influence physical or virtual environments: meaning the AI shall not be passive, but actively impact their environment physically or digitally (robotic arm or digital spaces).

When talking about what counts as an AI system under the AI Act, the definition spans two stages: the pre-deployment (building) phase and the post-deployment (use) phase of the system. Some parts of the definition only need to be in place during the build phase, while others might only appear once the system is in operation. This makes a periodic evaluation of the AI system as a whole a necessary step.

Further steps:

Step 2: Risk Classification:

The second step to AI Act compliance is to determine what risk classification your AI system falls under. The AI act prescribes a tiered classification of prohibited (e.g. credit scoring), high-risk (e.g. product/sectoral or certain use-case categories), low risk (e.g. some chatbots) or minimal risk (e.g. some spam filters). To be able to classify each AI correctly, companies need to have a thorough understanding of their AI and its application.

Step 3: Role Designation

The third step to AI Act compliance is knowing your role in relation to the AI system, as this determines which obligations apply. You will need to identify whether you are a provider, deployer, importer, distributor or manufacturer and be aware that your role can change over time. One example is a company that buys an AI system (deployer) and becomes the provider if it places its own trademark on it. The AI Act allows for importers, distributors and manufacturers to become providers in certain cases.

Step 4: Compliance Obligations

After establishing that your system is an AI system, which risk classification it falls under and which role you have, then comes the fourth step, compliance obligations. The AI Act is complex in the sense that different obligations apply to different risk classification and different roles. Most obligations pertain to providers of high-risk AI systems. These can be found in Section 2 of the Act and vary from simple record-keeping obligations to more intricate quality management systems and post-market monitoring.

Conclusion

This blog details four steps in order to be on the road towards AI Act compliance. However, there are more steps in the pipeline of compliance. Implementing, monitoring, evaluating are just some of them.

Reem Mohammed Legal Manager

Do you want to know more?

 If you are doubtful about whether your system might be an AI system or already know that you have an AI system but need guidance for the other steps, Considerati is equipped with the knowledge to advise and guide you towards AI Act compliance!

Our services orContact