STARTUPS
AI ACT
Key points of the AI Act:
1. Risk classification: The AI Act establishes a classification of artificial intelligence systems based on their risk. These are divided into four categories:
• Unacceptable risk: Prohibited AI systems, such as those that manipulate human behavior or are used for uncontrolled mass surveillance.
• High risk: Systems that can significantly affect people’s fundamental rights, such as AI used in critical infrastructure, in education, for employee recruitment or for justice.
• Limited risk: AI systems that require transparency, such as chatbots that must inform users that they are interacting with an AI.
• Minimal or zero risk: Most AI applications, such as video games or image filters, that do not require any specific regulation.
2. Obligations for developers: Developers of high-risk AI systems will have to comply with a series of requirements, such as carrying out impact assessments, ensuring the quality of the data used, and guaranteeing the transparency and traceability of the system.
3. Oversight and sanctions: The Act also establishes oversight mechanisms and sanctions for those who fail to comply with the regulation. Penalties can be significant, with fines that can reach up to 6% of the company’s global turnover.
4. Innovation and competition: The AI Act also seeks to balance regulation with the promotion of innovation, providing exemptions for research and development, and supporting small and medium-sized enterprises (SMEs) so that they can compete in the field of AI.
The AI Act and the General Data Protection Regulation (GDPR) are closely related, as both are part of the European Union’s regulatory framework to protect the fundamental rights of individuals in the digital environment, but they focus on different aspects.
Relationship between the AI Act and the GDPR:
1. Complementarity:
• GDPR: The GDPR, in force since 2018, regulates the collection, storage, and processing of personal data within the EU. Its main objective is to protect the privacy of European citizens and ensure that their data is handled in a secure and transparent manner.
• AI Act: The AI Act focuses on regulating the use of artificial intelligence systems, especially those that can have a significant impact on fundamental rights, such as privacy, security, non-discrimination, and others.
Both regulations are complementary in the sense that the AI Act regulates the use of artificial intelligence, while the GDPR regulates how personal data is handled within those AI systems.
2. Data Protection:
• The AI Act imposes additional obligations on high-risk AI systems regarding data processing, which must align with the principles of the GDPR. For example, an AI system that processes personal data must ensure data minimization, anonymity, and informed consent, as required by the GDPR.
• In addition, the AI Act reinforces the transparency and accountability principles of the GDPR, requiring AI systems to be explainable and traceable, especially in contexts where personal data is used.
3. Impact on privacy:
• AI systems that analyse large amounts of personal data can increase the risks of invasion of privacy and discrimination. The AI Act seeks to mitigate these risks by imposing strict requirements on how these systems can operate and how data must be managed, which is directly related to the protections of the GDPR.
• For example, the use of AI for automated decisions, such as in the case of recruitment, must comply not only with the AI Act but also with the GDPR provisions on automated decisions and the right to explanation.
4. Penalties and compliance:
• Both the AI Act and the GDPR provide for significant penalties for non-compliance. Companies operating within the EU must ensure that their AI systems comply with both regulations to avoid fines, which can be very high.
• The AI Act, like the GDPR, reinforces the importance of regulatory compliance at an organisational level, including the need to carry out impact assessments on data protection and AI ethics.
Conclusion:
In summary, the AI Act and the GDPR are designed to work together. While the GDPR ensures that personal data is treated fairly and securely, the AI Act regulates how AI systems can use that data and in what contexts. Both laws are essential to creating a safe and ethical digital framework in the EU, protecting citizens’ rights in the age of artificial intelligence.
ADDRESS
C/ Pau Claris 162, 2º4ª
08037 Barcelona

