MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
The European Union has established a regulatory framework for artificial intelligence (AI) that classifies AI systems according to risk: minimal, limited, high, and unacceptable. The higher the risk to safety or fundamental rights, the stricter the requirements — ranging from transparency obligations to a ban on the most dangerous applications. Anyone who develops AI or deploys it for European citizens will have to deal with this.
In 2021, the European Commission presented a proposal that creates a regulatory framework for AI for the first time. It targets all parties, public or private, both within and outside the EU, that place AI systems on the market or deploy them with an impact on European citizens. (This began as a draft regulation; the European AI Regulation — the “AI Act” — has since been adopted. The main thrust of the risk-based approach outlined below has remained intact; exact details and fine amounts have been modified in certain respects in the final framework.)
AI has long been commonplace
AI — systems that exhibit intelligent behavior — is not new and is found in countless applications. Streaming services use it to recommend titles based on viewing behavior, and accounting software learns from manual entries how invoices should be recorded. Yet producers rarely communicate about it, and it is often unclear which technique (deep learning, machine learning) is being used. This complexity and lack of transparency can erode fundamental rights and make enforcement difficult — a reason for a regulatory framework.
From transparency requirements to a ban
The framework distinguishes AI systems with a minimal, limited, high, and unacceptable risk to safety, livelihoods, or fundamental rights. Different rules apply to each level:
- Minimal/limited risk: primarily transparency requirements. Consider recommendation AI or deepfakes, where it must be disclosed that AI has been used.
- High risk: stricter requirements, for example for AI in personnel management. Strict compliance assessments apply, and human oversight must be possible.
- Unacceptable risk: prohibited. This concerns clear threats to security or fundamental rights, such as systems that identify and track people on a large scale or manipulate behavior. For security purposes (such as counter-terrorism), the framework remains partially open.
Supervision and high fines
Member States designate a national supervisory authority, which participates in a European AI committee. Developers are subject to a reporting obligation for certain defects or incidents, similar to the current reporting obligation for data breaches. Fines can be substantial — in the original proposal up to 30 million euros or 6% of global turnover (in the final AI Act, these maximums have been adjusted in certain areas).
Frequently Asked Questions
To whom do the European AI regulations apply?
For all parties, within and outside the EU, that bring AI systems to market or deploy them with an impact on European citizens — public and private.
How are AI systems classified?
By risk: minimal, limited, high, and unacceptable. The higher the risk, the stricter the requirements, escalating to a ban for the most dangerous applications.
Which AI applications are prohibited?
Applications with an unacceptable risk, such as large-scale identification and tracking of people or the manipulation of behavior, with limited exceptions for security purposes.
Questions about AI and privacy?
If your company implements AI, it is wise to map out the risks and obligations now. The privacy experts at MKB Juristen can assist you. View our expertise in privacy and data protection or schedule an intake meeting .