As the European Union’s Artificial Intelligence (AI) Act officially takes effect, the focus now shifts to operationalizing its comprehensive regulatory framework. The AI Act, which stands as one of the most detailed regulations governing artificial intelligence, targets two primary categories: AI systems and General-purpose AI models (GPAI models). These frameworks are designed to oversee AI systems that function with varying degrees of autonomy and can adapt to generate outputs that influence both physical and virtual environments. Meanwhile, GPAI models refer to sophisticated AI models capable of performing across a wide range of tasks and integrating into various applications.
The Act’s scope is expansive, addressing multiple stakeholders within the AI supply chain — from providers and deployers to authorized representatives, importers, and distributors. Importantly, the AI Act applies not only within EU borders but also extends extraterritorially. This means that providers and deployers outside the EU are subject to its stipulations if their AI systems' output is used within the EU.
To comply effectively with the AI Act, stakeholders are recommended to undertake several key steps:
1. Assemble a Cross-functional AI Governance Team:
Organisations should establish a cross-disciplinary AI governance team to manage compliance with the AI Act. This team should include professionals from legal, compliance, HR, data privacy, IT, product engineering, and research and development sectors. Having an AI champion or similar figurehead within the organisation can also be beneficial to address AI-related inquiries and promote ethical AI practices.
2. Evaluate the Current AI Governance Framework:
Understanding the risk categorisation of AI systems is crucial, as the AI Act divides risks into four tiers: prohibited AI practices, high-risk AI systems, transparency risk, and minimal-risk AI systems. Organisations should assess whether their AI-enabled technologies fall under these definitions and the specific obligations that apply. Legal expert Vishnu Shankar underscores the importance of this evaluation in guiding the compliance process.
3. Promote AI Literacy:
By February 2025, the Act mandates ensuring AI literacy among stakeholders, including non-technical staff, to understand AI's impacts and biases. This literacy requirement aims to equip those involved with AI technology with the knowledge needed to engage with AI-related tasks responsibly. Further guidance from the EU Commission is expected to help promote AI literacy throughout the value chain.
4. Implement Compliance Requirements:
Providers of high-risk AI systems should begin aligning with the AI Act's compliance obligations, which include maintaining a risk management system throughout the AI system's lifecycle and ensuring proper data governance. They must also develop technical documentation to facilitate compliance checks, design systems with logging capabilities, human oversight, and the necessary accuracy and cybersecurity.
GPAI model providers have additional compliance requirements, set to take effect in August 2025, which include maintaining up-to-date information and ensuring adequate cybersecurity protection. This encompasses evaluating models using standard protocols and addressing systemic risks from their deployment.
5. Participate in Industry Workshops and Working Groups:
Engagement with ongoing industry discussions remains crucial as the EU develops the Code of Practice for GPAI models. Stakeholders are encouraged to contribute to and follow the establishment of compliance standards. Events such as the "European Forum on AI Law, Safety & Governance" in Brussels in January 2025 provide platforms for stakeholders to stay informed and collaborate on these standards.
The introduction of the AI Act marks a significant milestone in regulatory efforts to address the expanding capabilities of AI technology. As organisations begin to navigate these new requirements, continuous industry dialogue and adherence to emerging standards will be essential in aligning with the EU’s regulatory vision.
Source: Noah Wire Services