One example of this is the EU Regulation on Artificial Intelligence, also known as the AI Act. It takes a risk-based approach, imposes obligations on providers and deployers of AI systems, among others, and prohibits certain AI practices. Depending on the type and area of application of an AI system, requirements regarding transparency, risk management, documentation and human oversight, among other things, may apply.
In addition to the AI Act, other requirements related to AI may be relevant for companies. These include, for example:
- Data protection requirements such as the General Data Protection Regulation
- Cybersecurity requirements such as the Cyber Resilience Act
- Product liability and product safety requirements such as the Product Liability Directive or the Machinery Regulation
- Industry-specific requirements such as the Medical Device Regulation
Companies should therefore assess which requirements apply to them and document their compliance accordingly. In addition, they should establish the conditions under which they and their workforce use AI. Such an internal set of rules can, for example, govern permissible tools, the handling of confidential data or verification requirements for AI-generated results.