En este modulo

  1. Regulation structure: article map
  2. Annex III: high-risk systems in detail
  3. Provider obligations for high-risk AI
  4. Deployer obligations (professional user)
  5. Conformity assessment: step-by-step process
  6. Required technical documentation
  7. GPAI models: specific obligations
  8. Enforcement: authorities, penalties, timeline
  9. Compliance checklist for legal teams
  10. Ejercicio practico
  11. Puntos clave

Regulation structure: article map

The AI Act (Regulation (EU) 2024/1689) has 113 articles and 13 annexes. You do not need to read them all. These are the key blocks for a legal team:

Title I (Art. 1-4): Scope and definitions

Title II (Art. 5): Prohibited practices

Title III (Art. 6-49): High-risk systems

The most extensive block. Defines what is high-risk, what obligations providers and deployers have, and how conformity is assessed.

Title IV (Art. 50): Transparency

Obligations for systems that interact with persons (chatbots), generate content (deepfakes, AI-generated text), or detect emotions.

Title V (Art. 51-56): GPAI models

Obligations for providers of general-purpose AI models (OpenAI, Anthropic, Google, Meta). Documentation, copyright, systemic risk.

Titles VIII-XII (Art. 64-99): Enforcement

National authorities, European AI Office, regulatory sandboxes, penalties.

Annex III: high-risk systems in detail

Annex III is the reference for determining whether a system is high-risk. It lists 8 areas:

1. Biometrics

Remote biometric identification (not real-time), biometric categorization by sensitive attributes, emotion recognition.

2. Critical infrastructure

Safety components in management of traffic, water, gas, heating, electricity, internet.

3. Education and vocational training

Determining access to educational institutions, assessment of learning outcomes, assessment of the appropriate level of education, proctoring of examinations.

4. Employment and worker management

The most relevant for companies: recruitment (CV screening, candidate filtering), promotion/dismissal decisions, task assignment based on behavior, performance evaluation.

5. Access to essential services

Eligibility assessment for public benefits, credit scoring, insurance risk assessment, emergency call classification.

6. Law enforcement

Individual risk assessment (recidivism), polygraphs, illegal content detection, evidence reliability assessment.

7. Migration and asylum

Immigrant risk assessment, travel documents, asylum/visa applications.

8. Administration of justice

Fact-finding, interpretation of law, alternative dispute resolution.

High-risk criteria (Art. 6)

A system is high-risk if: (a) it falls within Annex III AND (b) it poses a significant risk of harm to health, safety, or fundamental rights. Being on the list alone is not enough: there must be real significant risk. The provider may argue their system does not meet (b), but must document it.

Provider obligations for high-risk AI

The "provider" is whoever develops or commissions the development of an AI system and places it on the market under their name. Main obligations (Art. 8-15):

  1. Risk management system (Art. 9): continuous and iterative process throughout the entire lifecycle. Identify, assess, and mitigate risks. Document.
  2. Data governance (Art. 10): training, validation, and test data must be relevant, representative, free from errors to the extent possible, and complete. Examine biases.
  3. Technical documentation (Art. 11): before placing on the market. Minimum content in Annex IV.
  4. Record-keeping (Art. 12): automatic logging during operation. Decision traceability. Minimum retention per applicable law.
  5. Transparency (Art. 13): clear instructions of use for the deployer. Information on capabilities, limitations, residual risks.
  6. Human oversight (Art. 14): designed to be overseen by humans. Ability to intervene, correct, deactivate.
  7. Accuracy, robustness, and cybersecurity (Art. 15): appropriate levels. Resilient to errors, failures, adversarial manipulation.
  8. Quality management system (Art. 17): documented QMS.
  9. Conformity assessment (Art. 43): before placing on the market.
  10. Registration in the EU database (Art. 49): public database managed by the Commission.

Deployer obligations (professional user)

The "deployer" is whoever uses a high-risk AI system in a professional context (not end consumer). Most companies are deployers, not providers. Obligations (Art. 26):

  1. Use according to instructions: follow the provider's instructions.
  2. Human oversight: assign competent natural persons for oversight. With adequate training.
  3. Input data: ensure that input data is relevant and representative.
  4. Monitor operation: monitor that the system functions correctly. Report incidents to the provider and authorities.
  5. DPIA (if GDPR applies): conduct a data protection impact assessment before using the system.
  6. Inform affected persons: Art. 26.7: inform workers and their representatives that high-risk AI is used in the workplace.
  7. Registration (if public sector): register the use in the EU database.

Provider vs deployer distinction

If you purchase HubSpot AI for lead scoring, you are a deployer. HubSpot is the provider. If you develop your own scoring system with LangChain, you are a provider (and deployer). Provider obligations are significantly more extensive.

Conformity assessment: step-by-step process

Art. 43 defines two pathways:

Pathway 1: Self-assessment (most cases)

The provider internally evaluates that it meets all requirements. No external body needed. Applies to most high-risk systems EXCEPT biometrics.

  1. Verify compliance with Art. 8-15 (technical requirements)
  2. Complete technical documentation (Annex IV)
  3. Implement QMS (Art. 17)
  4. EU declaration of conformity (Annex V)
  5. CE marking
  6. Registration in the database

Pathway 2: Third-party assessment (biometrics)

For biometric identification systems: a notified body must validate. Longer and more costly process.

Required technical documentation

Annex IV defines the minimum content. For legal teams, these are the documents you must prepare or request from the technical team:

Block 1: General description

Block 2: Development

Block 3: Performance

Block 4: Post-market

GPAI models: specific obligations

Title V regulates general-purpose AI models (GPT, Claude, Gemini, Llama). This affects model providers, not directly the companies that use them. But as a legal team, you need to know:

Obligations for all GPAI (Art. 53)

Additional obligations for GPAI with systemic risk (Art. 55)

Models with high-impact capabilities (threshold: >10^25 FLOP of training). Currently: GPT-4, Gemini Ultra, Claude Opus.

Practical implication for your company

If you use ChatGPT, Claude, or Gemini via API: GPAI obligations fall on OpenAI/Anthropic/Google, not you. But if you build a high-risk system ON TOP of these models (e.g., CV screening with the Claude API), YOU are the provider of that high-risk system and have Title III obligations.

Enforcement: authorities, penalties, timeline

Authorities

Penalties (Art. 99)

InfringementMaximum penalty
Prohibited practices (Art. 5)35M EUR or 7% global turnover
High-risk non-compliance (Title III)15M EUR or 3% global turnover
Incorrect information to authorities7.5M EUR or 1% global turnover
SMEs and startupsProportional (lower amounts)

Application timeline

DateWhat applies
Feb 2025Prohibited practices + AI Literacy (Art. 4 and 5)
Aug 2025GPAI obligations (Title V)
Aug 2026High-risk (Title III) + transparency (Art. 50)
Aug 2027Full application. Legacy systems must comply

Compliance checklist for legal teams

AI Act Checklist for Legal
  1. [ ] Complete inventory of AI systems in the organization
  2. [ ] Classification of each system: prohibited / high-risk / limited risk / minimal risk
  3. [ ] For high-risk: identify whether we are provider or deployer
  4. [ ] Provider: technical documentation (Annex IV), QMS, conformity assessment
  5. [ ] Deployer: human oversight assigned, DPIA if GDPR applies, inform workers
  6. [ ] Art. 50 transparency: chatbots labeled, AI-generated content marked
  7. [ ] AI Literacy: evidence of staff training
  8. [ ] Registration in the EU database (if high-risk or public sector)
  9. [ ] Post-market monitoring plan
  10. [ ] Incident reporting procedure
  11. [ ] Review of contracts with AI providers (AI Act clauses)
  12. [ ] Professional liability insurance reviewed

Ejercicio practico

Ejercicio LG04: AI Act analysis of your organization
  1. Take your company's AI system inventory (or create one if it does not exist)
  2. For each system, determine if it is high-risk using Annex III and Art. 6
  3. For the high-risk ones, identify: provider or deployer?
  4. List the specific obligations that apply based on the role
  5. Create a compliance timeline with milestones through August 2026
  6. Identify the 3 most critical gaps (what you do not comply with today)
  7. Draft a memo for leadership with findings and recommendations

Puntos clave

Puntos clave from LG04

  1. 113 articles, 13 annexes. Key blocks: Art. 5 (prohibited), Title III (high-risk), Art. 50 (transparency), Title V (GPAI).
  2. Annex III defines 8 high-risk areas. Employment (area 4) is the most relevant for companies.
  3. Provider vs deployer: most companies are deployers. Different obligations.
  4. Conformity assessment: self-assessment for most. Third-party only for biometrics.
  5. If you build a high-risk system on GPT/Claude, YOU are the provider of that system.
  6. Critical deadline: August 2026 for high-risk. February 2025 already in force (prohibitions + literacy).
  7. Penalties: up to 35M EUR or 7% global turnover. Proportional for SMEs.
Guia de estudio — Conceptos clave de LG04

Estructura del Reglamento: mapa de articulos

  • Art. 2:Ambito territorial. Aplica a proveedores que comercialicen o pongan en servicio sistemas IA en la UE, independientemente de donde esten establecidos. Tambien a deployers establecidos en la UE.
  • Art. 3:68 definiciones. Las criticas: "sistema de IA" (Art. 3.1), "proveedor" (Art. 3.3), "deployer" (Art. 3.4), "puesta en servicio" (Art. 3.11), "datos biometricos" (Art. 3.34).
  • Art. 4:AI Literacy. Obligacion transversal ya en vigor desde febrero 2025.
  • Scoring social, manipulacion subliminal, explotacion de vulnerabilidades, identificacion biometrica remota en tiempo real (con excepciones policiales), inferencia de emociones en trabajo/educacion (con excepciones de seguridad), scraping facial masivo, clasificacion biometrica por raza/orientacion/creencias.
  • En vigor desde febrero 2025.

Anexo III: sistemas de alto riesgo en detalle

  • El mas relevante para empresas: reclutamiento (screening CVs, filtrado candidatos), decisiones de promocion/despido, asignacion de tareas basada en comportamiento, evaluacion del rendimiento.
  • Criterio de alto riesgo (Art. 6): Un sistema es alto riesgo si: (a) esta en el Anexo III Y (b) supone un riesgo significativo de perjuicio para la salud, seguridad o derechos fundamentales. No basta estar en la lista: debe haber riesgo real significativo. El proveedor puede argumentar que su sistema no cumple (b), pero debe documentarlo.

Obligaciones del proveedor de IA de alto riesgo

  • Sistema de gestion de riesgos (Art. 9):proceso continuo e iterativo durante todo el ciclo de vida. Identificar, evaluar y mitigar riesgos. Documentar.
  • Gobernanza de datos (Art. 10):datos de entrenamiento, validacion y test deben ser relevantes, representativos, libres de errores en la medida posible, y completos. Examinar sesgos.
  • Documentacion tecnica (Art. 11):antes de puesta en mercado. Contenido minimo en Anexo IV.
  • Registro de actividad (Art. 12):logging automatico durante operacion. Trazabilidad de decisiones. Retencion minima segun legislacion aplicable.
  • Transparencia (Art. 13):instrucciones de uso claras para el deployer. Informacion sobre capacidades, limitaciones, riesgos residuales.
  • Supervision humana (Art. 14):disenado para ser supervisado por personas. Capacidad de intervenir, corregir, desactivar.

Obligaciones del deployer (usuario profesional)

  • Usar conforme a instrucciones:seguir las instrucciones del proveedor.
  • Supervision humana:asignar personas fisicas competentes para supervisar. Con formacion adecuada.
  • Datos de entrada:asegurar que los datos de entrada son relevantes y representativos.
  • Monitorizar funcionamiento:vigilar que el sistema funciona correctamente. Reportar incidentes al proveedor y autoridades.
  • DPIA (si aplica RGPD):realizar evaluacion de impacto antes de usar el sistema.
  • Informar a personas afectadas:Art. 26.7: informar a trabajadores y sus representantes de que se usa IA de alto riesgo en el lugar de trabajo.

Evaluacion de conformidad: proceso paso a paso

  • Verificar cumplimiento de Art. 8-15 (requisitos tecnicos)
  • Completar documentacion tecnica (Anexo IV)
  • Implementar QMS (Art. 17)
  • Declaracion de conformidad UE (Anexo V)
  • Marcado CE
  • Registro en base de datos

Documentacion tecnica requerida

  • Nombre y version del sistema
  • Proposito previsto y usos previsibles
  • Interaccion con hardware/software
  • Versiones de software relevantes
  • Descripcion del proceso de desarrollo
  • Decisiones de diseno y trade-offs

Siguiente: LG05 - GDPR and Privacy with AI

The AI Act and the GDPR are complementary. DPIAs, legal basis, Art. 22, international transfers. What your legal team needs to know.

Ir al modulo LG05