1/12
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
The EU AI Act applies different obligations depending on the level of risk. Unacceptable-risk uses are prohibited, high-risk systems face specific requirements, limited-risk systems mainly face transparency obligations, and minimal-risk systems generally remain under the status quo.
An AI system is a machine-based system designed to operate with varying levels of autonomy and possibly adapt after deployment. For explicit or implicit objectives, it infers from its inputs how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
A provider develops an AI system or GPAI model, has it developed, or places it on the market under its own name or trademark; a deployer uses an AI system under its authority. Providers or deployers outside the EU can also be covered when their system's output is used in the EU.
(?) Which important AI uses are prohibited as unacceptable risk?
Prohibited uses include harmful manipulation, exploitation of vulnerable groups, certain biometric categorisation, social scoring, predictive policing based on profiling, untargeted scraping to build facial-recognition databases, and emotion recognition at work or in education except for certain medical or safety reasons.
High-risk status can arise because AI is a safety component in a regulated product or because its intended use is listed in Annex III. An Annex III system may not be high-risk if it poses no significant risk and only performs a narrow procedural task, improves a completed human activity, detects decision-making patterns without replacing human review, or performs a preparatory task; profiling of natural persons remains high-risk.
AI used as a safety component in transport systems such as cars, trucks, trains, aircraft, and boats is governed through sector-specific transport legislation. The AI Act's high-risk requirements are incorporated through targeted amendments and secondary legislation while respecting sector-specific regulatory features.
High-risk AI systems require risk management, data governance, technical documentation, record keeping, transparency, human oversight, and appropriate robustness, accuracy, and cybersecurity. These requirements apply throughout the AI-system lifecycle.
Risk management is a continuous and iterative lifecycle process. It identifies and analyses known and reasonably foreseeable risks, considers intended use, foreseeable misuse, and deployment context, applies suitable mitigation measures, and reduces the overall relevant residual risk to an acceptable level.
The datasets must be relevant and sufficiently representative and, as far as possible, free of errors and complete for the intended purpose. Data governance must also consider the deployment context, including the detection and correction of bias.
(?) Why are technical documentation and record keeping required for high-risk AI systems?
Technical documentation must clearly and comprehensively describe the system and provide the information needed to demonstrate compliance. Automatic event logging provides traceability and supports operational monitoring, post-market monitoring, and identification of situations involving risks or substantial modifications.
Transparency requires enough information for deployers to interpret and appropriately use AI outputs, including the system's characteristics, capabilities, limitations, and oversight measures. Human oversight must be proportionate to risk, autonomy, and context and may require the ability to disregard, override, reverse, or stop the AI system.
Robustness includes measures such as technical redundancy, backups, fail-safe plans, and mitigation of harmful feedback loops. Accuracy levels and relevant metrics must be communicated, while cybersecurity requires resilience against attacks that manipulate inputs, use, outputs, or performance.
(?) What does the compliance lifecycle of a high-risk AI system look like?
Before market placement, the system undergoes a conformity assessment and compliance steps such as a declaration of conformity, CE marking, and registration where applicable. After deployment, continuous monitoring and market surveillance continue, and a substantial modification can trigger reassessment.