AI regulation: the EU AI Act, data protection law and what to organise now
AI regulation is converging on a risk-based approach: duties scale with the impact of the system, affected people gain rights of information and contestation, and providers and deployers hold distinct obligations. The EU AI Act is the most detailed reference; data protection law already applies to any AI use that processes personal data. Texts differ by jurisdiction, so the stable preparation is the information every version will require.
Common lines across frameworks
This is informational and not legal advice; consult the applicable texts and counsel for your case.
- Classification of systems by level of risk, with proportional duties.
- Prohibited uses at the top of the risk scale.
- Rights for affected people, including information and contestation of automated decisions.
- Governance, documentation and impact assessment duties for high-risk systems.
- Human oversight and allocated responsibility between provider and deployer.
- Supervision, enforcement and penalties.
Extraterritorial reach
The EU AI Act can reach organisations outside the European Union when their systems or the outputs of those systems are placed on the EU market. Sector rules and data protection law often apply in parallel rather than in sequence.
What to organise regardless of the final text
Waiting for certainty risks arriving at the compliance date without knowing where AI is used. Building controls from a draft that may change wastes effort. The stable middle is the record itself.
- Inventory of AI uses, including third-party tools adopted team by team.
- Declared purpose and the people affected by each use.
- Degree of automation and the human oversight point.
- Data involved and its legal basis.
- Risk and impact assessment proportional to the use.
- Decisions recorded, with owner and review date.
Frequently asked questions
Does the EU AI Act apply to a company outside Europe?
It can, when systems or their outputs are offered on the EU market. The specific analysis depends on the role played — provider, deployer, importer or distributor.
What is the difference between a provider and a deployer?
A provider develops or places the system on the market; a deployer uses it under its own authority. Duties differ, but adopting a tool does not transfer all responsibility for how it is used.