En este modulo
- Regulation structure: overview
- Titles I and II: scope, definitions and prohibitions
- Title III: high-risk AI systems
- Titles IV and V: transparency and general-purpose AI models
- Titles VI and VII: governance and regulatory sandbox
- Titles VIII and IX: post-market surveillance and enforcement
- Delegated and implementing acts
- Harmonised standards and technical specifications
- Sectoral guidance: healthcare, finance, employment, education
- Implementation timeline
- Ejercicio practico
- Puntos clave
Regulation structure: overview
Regulation (EU) 2024/1689, known as the EU AI Act, is the first comprehensive legislation on artificial intelligence in the world. It entered into force on 1 August 2024 and establishes a risk-based legal framework that affects providers, deployers, importers and distributors of AI systems in the European market.
The Regulation contains 113 articles organized in 13 titles, 13 annexes and more than 180 recitals. For a DPO or compliance officer, the key is not to memorize every article, but to understand the regulatory architecture and know where to look when a specific question arises.
Regulatory architecture
The AI Act follows a pattern familiar in European regulation: it establishes general principles in the first titles, develops specific obligations in the central ones, and reserves the final titles for governance, enforcement and transitional provisions. The annexes contain the technical lists that determine the classification of systems.
- Titles I-II: definitions, scope, prohibited practices.
- Title III: the heart of the Regulation. High-risk AI systems: requirements, obligations for providers and deployers.
- Title IV: transparency obligations for limited-risk systems.
- Title V: general-purpose AI models (GPAI), including those with systemic risk.
- Titles VI-VII: governance (AI Office, AI Board, national authorities) and regulatory sandbox.
- Titles VIII-XII: post-market surveillance, enforcement, penalties, delegations.
- Title XIII: final provisions and application timeline.
Difference from the GDPR
The GDPR applies to all processing of personal data. The AI Act applies only to systems that meet the definition of "AI system" in Article 3. Not all automation is an AI system under the Regulation. The first compliance task is to determine whether your system falls within scope.
Titles I and II: scope, definitions and prohibitions
Article 3: key definitions
Article 3 contains 68 definitions. The most relevant for governance:
- AI system (Art. 3(1)): a machine-based system designed to operate with varying levels of autonomy, that may generate outputs such as predictions, content, recommendations or decisions influencing physical or virtual environments. This definition is intentionally broad.
- Provider (Art. 3(3)): a person who develops or has developed an AI system and places it on the market or puts it into service under their own name. This is the party that assumes the greatest regulatory burden.
- Deployer (Art. 3(4)): a person who uses an AI system under their authority. In most organizations, this is your role. Deployer obligations are less extensive but not trivial.
- Intended purpose (Art. 3(12)): the use for which the provider intends the system. Any use outside the intended purpose may reclassify the deployer as a de facto provider.
Article 5: prohibited AI practices
Article 5 establishes 8 absolutely prohibited practices. These prohibitions are applicable since February 2025 and admit no exceptions (except those expressly provided for law enforcement in specifically defined cases):
- Subliminal manipulation: techniques that exploit vulnerabilities of persons or groups to distort their behavior in a manner that causes harm.
- Social scoring: classification of persons based on social behavior for disproportionately unfavorable treatment.
- Individual crime prediction: based solely on profiling or personality traits (without objective evidence).
- Untargeted facial scraping: creation of facial recognition databases through untargeted scraping of images from the internet or CCTV.
- Emotion recognition: in the workplace and educational institutions (with medical/safety exceptions).
- Biometric categorisation: to infer race, political opinions, trade union membership, religious beliefs or sexual orientation.
- Real-time remote biometric identification: in publicly accessible spaces by law enforcement (with specifically defined exceptions and prior judicial authorisation).
- Exploitation of vulnerabilities: by age, disability or specific social or economic situation.
Practical implication
If your organization uses any system that may fall into these categories, the consequence is not "comply with additional requirements". It is to cease the activity. No level of documentation can save a prohibited practice. The penalty can reach 35 million euros or 7% of total worldwide annual turnover.
Title III: high-risk AI systems
Title III (Articles 6 to 49) is the operational core of the Regulation. It defines which systems are high-risk and establishes mandatory requirements for providers, deployers, importers and distributors.
Article 6: high-risk classification
A system is classified as high-risk through two pathways:
- Pathway 1 (Art. 6(1)): the system is a safety component of a product covered by Union harmonisation legislation listed in Annex I (machinery, toys, medical devices, etc.) and requires a third-party conformity assessment.
- Pathway 2 (Art. 6(2)): the system is listed in Annex III. This is the most relevant pathway for most organizations.
Annex III: the 8 high-risk areas
Annex III lists 8 areas with specific sub-areas:
- Biometrics: remote biometric identification (not real-time), biometric categorisation, emotion recognition.
- Critical infrastructure: safety components in the management of traffic, water supply, gas, heating, electricity.
- Education and vocational training: admission, assessment of learning outcomes, proctoring of examinations, detection of prohibited behavior.
- Employment and management of workers: recruitment, filtering of applications, decisions on promotion/termination, task assignment based on profile, performance monitoring.
- Access to essential services: assessment of eligibility for public benefits, credit scoring, risk assessment in life/health insurance, prioritisation in emergency services.
- Law enforcement: risk assessment of victimisation, polygraphs, assessment of reliability of evidence, recidivism prediction.
- Migration, asylum and border control: polygraphs, security/health/irregular immigration risk assessment, document verification.
- Administration of justice and democratic processes: assistance in investigating facts/law, application of law to a specific case, influence on electoral outcomes.
Requirements for high-risk AI systems (Articles 8-15)
Providers of high-risk AI systems must meet these requirements before placing on the market:
- Risk management system (Art. 9): iterative process throughout the entire lifecycle. Identification, analysis, estimation and evaluation of risks. Mitigation measures. Acceptable residual risk.
- Data governance (Art. 10): training, validation and testing datasets must meet quality criteria: representativeness, absence of errors (to a reasonable extent), completeness, adequate statistical properties.
- Technical documentation (Art. 11): before placing on the market, in accordance with Annex IV. Includes general description, system elements, development process, capabilities, limitations, risk management system, changes throughout the lifecycle.
- Record-keeping (Art. 12): automatic logging throughout the operational lifetime. Ability to identify risk situations, facilitate post-market surveillance and enable incident investigation.
- Transparency and provision of information (Art. 13): clear instructions for use: provider identity, characteristics, expected performance, known limitations, human oversight measures, expected lifetime, maintenance specifications.
- Human oversight (Art. 14): designed to enable effective oversight by natural persons. Includes understanding of capabilities and limitations, detection of anomalies, ability to disregard or reverse decisions, stop button.
- Accuracy, robustness and cybersecurity (Art. 15): adequate and documented levels. Resilience against errors, faults, attempts at manipulation by unauthorised third parties.
Deployer obligations (Articles 26-27)
As a deployer, your obligations are distinct from those of the provider but equally binding:
- Use the system in accordance with the provider's instructions for use.
- Assign human oversight to competent persons with the necessary authority and resources.
- Ensure that input data is relevant and representative.
- Monitor the operation and report any risk or serious incident to the provider.
- Carry out a fundamental rights impact assessment (Art. 27) before putting high-risk systems into use in certain contexts.
- Retain the automatic logs generated by the system for at least 6 months.
Titles IV and V: transparency and general-purpose AI models
Transparency obligations (Title IV, Art. 50)
Certain systems that are not high-risk but interact with persons require transparency obligations:
- Chatbots and assistants: inform the user that they are interacting with an AI system (unless obvious from the context).
- Deepfakes: artificially generated or manipulated image, audio or video content must be labelled in a manner detectable both by persons and by automated systems.
- Generated content: text published to inform the public on matters of public interest must indicate that it was artificially generated.
- Emotion recognition and biometric categorisation: inform the persons exposed and comply with the GDPR when processing personal data.
General-purpose AI models (Title V, Arts. 51-56)
GPAI models (GPT, Claude, Gemini, Llama, etc.) have their own regime. This affects foundation model providers, but also has downstream implications:
- All GPAI providers: technical documentation, copyright compliance policy, publication of a summary of the training content.
- GPAI with systemic risk: if the model exceeds 10^25 FLOPS of training compute or is designated by the Commission. Additional obligations: model evaluation, adversarial testing, serious incident traceability, adequate cybersecurity, energy efficiency reporting.
Implication for deployers
If your organization uses a GPAI model as a component of a high-risk system (for example, GPT-4 for candidate screening), the Title III obligations fall on you as the provider of the complete system. You cannot delegate responsibility to the base model provider.
Titles VI and VII: governance and regulatory sandbox
Governance structure (Title VI)
The AI Act creates a three-tier institutional architecture:
- AI Office (European AI Office): within the Commission. Competent for GPAI, general coordination, codes of practice, harmonised standards. It is the de facto regulator for foundation models.
- European AI Board: representatives of national authorities. Advises the Commission, facilitates consistency between Member States, issues opinions.
- National competent authorities: each Member State designates at least one market surveillance authority and one notifying authority. In Spain, AESIA (Spanish Agency for AI Supervision) assumes key functions.
Regulatory sandbox (Title VII, Arts. 57-63)
Member States must establish at least one AI regulatory sandbox before 2 August 2026. These controlled environments allow:
- Developing and testing innovative AI systems under direct regulatory supervision.
- Obtaining guidance on compliance before placing on the market.
- Special conditions for SMEs and startups: priority access, reduced fees.
- Processing of personal data lawfully collected for other purposes, under strict conditions (Art. 59(1)).
The sandbox does not exempt from compliance. It provides a supervised environment where errors have controlled consequences and where the competent authority offers real-time feedback.
Titles VIII and IX: post-market surveillance and enforcement
Post-market surveillance (Arts. 72-75)
Providers of high-risk AI systems must establish a post-market surveillance system proportionate to the nature and risks of the system. This system must:
- Actively collect and analyse performance data throughout the operational lifetime.
- Be documented in a post-market surveillance plan (part of the technical documentation).
- Include a procedure for reporting serious incidents to the competent and market surveillance authorities.
Serious incidents (Art. 73)
A serious incident is defined as any incident that directly or indirectly leads to: death or serious damage to health, serious and irreversible damage to property or the environment, or serious breach of fundamental rights. The provider must notify the market surveillance authority of the Member State where the incident occurred without undue delay and, in any case, within 15 days.
Penalty regime (Arts. 99-101)
The AI Act penalties are significant and tiered:
- Prohibited practices (Art. 5): up to 35 million euros or 7% of total worldwide annual turnover.
- Non-compliance with high-risk requirements: up to 15 million euros or 3% of total worldwide annual turnover.
- Incorrect information to authorities: up to 7.5 million euros or 1% of total worldwide annual turnover.
- SMEs and startups: the lower of the two amounts (fixed amount or percentage).
Delegated and implementing acts
The AI Act delegates to the European Commission the adoption of delegated and implementing acts to develop numerous technical aspects. These acts are essential because they specify the general requirements of the Regulation:
Planned delegated acts
- Update of Annex III: the Commission may add or modify high-risk areas through a delegated act, following the criteria of Article 7.
- GPAI technical documentation: detailed specifications on the content of the technical documentation that GPAI model providers must maintain.
- Systemic risk threshold: revision of the 10^25 FLOPS threshold for designating models with systemic risk.
- Deepfake classification criteria: conditions under which the labelling of artificially generated content is technically and proportionately feasible.
Planned implementing acts
- EU declaration of conformity form.
- Procedures for the notification of serious incidents.
- Detailed conditions for regulatory sandboxes.
- Technical specifications for the CE marking of high-risk AI systems.
- Format and content of the EU public database for high-risk systems.
Mandatory monitoring
Delegated and implementing acts are living law. An AI compliance programme cannot be "set and forget". You need to monitor the Official Journal of the EU, AI Office publications and AESIA documents to stay up to date.
Harmonised standards and technical specifications
The AI Act establishes a presumption of conformity for systems that comply with European harmonised standards or, in their absence, common specifications adopted by the Commission.
Key standards in development
- ISO/IEC 42001: AI management system. Already published. Structure similar to ISO 27001 but focused on AI: policy, risks, controls, continuous improvement.
- ISO/IEC 23894: AI risk management. Complements ISO 31000 with AI-specific risks.
- CEN/CENELEC JTC 21: the European technical committee tasked with developing harmonised standards under a Commission mandate. Working on 10 working groups covering risk management, data governance, transparency, human oversight, accuracy, robustness and cybersecurity.
- NIST AI RMF: although not a European standard, the NIST AI Risk Management Framework is an international reference and can serve as a complementary basis.
Presumption of conformity
When a high-risk system complies with the harmonised standards published in the Official Journal, it is presumed to comply with the requirements of the Regulation covered by those standards. This presumption is rebuttable: the surveillance authority may require additional evidence. But in practice, certifying against harmonised standards is the safest pathway to demonstrate compliance.
Sectoral guidance: healthcare, finance, employment, education
Healthcare
AI systems in medical devices are covered by both the AI Act and the Medical Devices Regulation (MDR 2017/745). The AI Act conformity assessment is integrated into the MDR assessment. Notified bodies under the MDR also act for the AI Act. Note: clinical AI systems that are not medical devices (for example, hospital shift optimization using patient data) may fall under Annex III area 5 (access to essential services).
Finance
Credit scoring is explicitly listed in Annex III. Risk models used in banking and insurance may be high-risk systems. The AI Act applies alongside existing financial regulation (CRD, Solvency II, MiFID II). Financial supervisors (EBA, EIOPA, ESMA) may act as competent authorities within their sectoral remit.
Employment
This is one of the areas with the greatest practical impact. Any AI system used in recruitment (CV screening, automated interviews, candidate evaluation), performance management or decisions about promotion/termination is high-risk. Companies using AI-powered hiring platforms (HireVue, Pymetrics, etc.) are deployers with direct obligations.
Education
Automated admission systems, academic performance assessment, online proctoring and plagiarism/cheating detection are high-risk. Universities and educational institutions must assess all their AI systems against Annex III area 3.
Implementation timeline
The AI Act has a phased application. Not everything is enforceable from day one:
- 2 February 2025: prohibitions under Article 5 and AI literacy obligations (Art. 4).
- 2 August 2025: obligations for GPAI models (Title V), designation of national authorities, codes of practice.
- 2 August 2026: general application of the Regulation. High-risk requirements (Title III), transparency (Title IV), regulatory sandbox. Key date for most organizations.
- 2 August 2027: high-risk AI systems that are safety components of products regulated by Union harmonisation legislation (Annex I, pathway 1 of Art. 6(1)).
Time is limited
If your organization operates systems that may be classified as high-risk under Annex III, you have until August 2026 to meet all Title III requirements. That includes technical documentation, risk management system, data governance, human oversight, fundamental rights impact assessment and registration in the EU database.
Ejercicio practico
- Compile an inventory of all systems using AI components in your organization (include third-party SaaS tools).
- For each system, determine whether it meets the definition of "AI system" in Article 3(1).
- Classify each system: prohibited practice (Art. 5), high-risk (Annex III), transparency obligations (Art. 50), or minimal risk.
- Identify your role in the value chain for each system: provider, deployer, importer or distributor.
- Map the relevant application dates for each system according to the phased timeline.
- For high-risk systems, compile an initial gap list against the requirements of Articles 8-15.
Output: a 2-3 page document that serves as a starting point for your AI Act compliance programme.
Puntos clave
Puntos clave from TG01
- The AI Act is a risk-based regulation with 4 levels: prohibited, high-risk, limited risk (transparency) and minimal risk. Most obligations fall on high-risk systems.
- Annex III lists 8 high-risk areas. The most relevant for most organizations: employment, access to essential services (credit scoring, insurance) and education.
- Deployers (those who use the system) have their own obligations: human oversight, input data quality, monitoring, fundamental rights impact assessment.
- Delegated acts, harmonised standards and codes of practice are living law. AI compliance requires continuous monitoring of regulatory developments.
- The key date for most organizations is 2 August 2026. The prohibitions have already been applicable since February 2025.
Guia de estudio — Conceptos clave de TG01
Estructura del Reglamento: vision general
- Titulos I-II:definiciones, ambito de aplicacion, practicas prohibidas.
- Titulo III:el corazon del Reglamento. Sistemas de alto riesgo: requisitos, obligaciones de proveedores e implementadores.
- Titulo IV:obligaciones de transparencia para sistemas de riesgo limitado.
- Titulo V:modelos de IA de proposito general (GPAI), incluidos los de riesgo sistemico.
- Titulos VI-VII:gobernanza (AI Office, AI Board, autoridades nacionales) y sandbox regulatorio.
- Titulos VIII-XII:vigilancia post-comercializacion, enforcement, sanciones, delegaciones.
Titulos I y II: ambito, definiciones y prohibiciones
- Sistema de IA (art. 3.1):sistema basado en maquina, disenado para operar con niveles variables de autonomia, que puede generar resultados como predicciones, contenido, recomendaciones o decisiones que influyen en entornos fisicos o virtuales. Esta definicion es intencionalmente amplia.
- Proveedor (art. 3.3):persona que desarrolla o hace desarrollar un sistema de IA y lo comercializa o pone en servicio bajo su nombre. Es quien asume la mayor carga regulatoria.
- Implementador (art. 3.4):persona que utiliza un sistema de IA bajo su autoridad. En la mayoria de organizaciones, este es tu rol. Las obligaciones del implementador son menores pero no triviales.
- Uso previsto (art. 3.12):el uso para el que el proveedor destina el sistema. Cualquier uso fuera del uso previsto puede reclasificar al implementador como proveedor de facto.
- Manipulacion subliminal:tecnicas que explotan vulnerabilidades de personas o grupos para distorsionar su comportamiento de manera que cause dano.
- Social scoring:clasificacion de personas basada en comportamiento social para trato desfavorable desproporcionado.
Titulo III: sistemas de alto riesgo
- Via 1 (art. 6.1):el sistema es un componente de seguridad de un producto cubierto por legislacion de armonizacion de la Union listada en el Anexo I (maquinaria, juguetes, dispositivos medicos, productos sanitarios, etc.) y requiere evaluacion de conformidad por tercero.
- Via 2 (art. 6.2):el sistema esta listado en el Anexo III. Esta es la via mas relevante para la mayoria de organizaciones.
- Biometria:identificacion biometrica remota (no en tiempo real), categorizacion biometrica, reconocimiento de emociones.
- Infraestructuras criticas:componentes de seguridad en gestion de trafico, suministro de agua, gas, calefaccion, electricidad.
- Educacion y formacion profesional:admision, evaluacion de resultados de aprendizaje, supervision de examenes, deteccion de comportamiento prohibido.
- Empleo y gestion de trabajadores:seleccion, filtrado de candidaturas, decisiones sobre promocion/despido, asignacion de tareas basada en perfil, monitorizacion del rendimiento.
Titulos IV y V: transparencia y modelos de proposito general
- Chatbots y asistentes:informar al usuario de que esta interactuando con un sistema de IA (salvo que sea evidente por el contexto).
- Deepfakes:contenido de imagen, audio o video generado o manipulado artificialmente debe estar etiquetado de manera detectable tanto para personas como para sistemas automatizados.
- Contenido generado:texto publicado para informar al publico sobre asuntos de interes publico debe indicar que ha sido generado artificialmente.
- Reconocimiento de emociones y categorizacion biometrica:informar a las personas expuestas y cumplir RGPD cuando procese datos personales.
- Todos los proveedores GPAI:documentacion tecnica, politica de cumplimiento de derechos de autor, publicacion de un resumen del contenido de entrenamiento.
- GPAI con riesgo sistemico:si el modelo supera 10^25 FLOPS de entrenamiento o es designado por la Comision. Obligaciones adicionales: evaluacion del modelo, pruebas adversariales, trazabilidad de incidentes graves, ciberseguridad adecuada, reporte de eficiencia energetica.
Titulos VI y VII: gobernanza y sandbox regulatorio
- AI Office (Oficina Europea de IA):dentro de la Comision. Competente para GPAI, coordinacion general, codigos de practicas, normas armonizadas. Es el regulador de facto para los modelos fundacionales.
- European AI Board (Comite Europeo de IA):representantes de autoridades nacionales. Asesora a la Comision, facilita coherencia entre Estados miembros, emite dictamenes.
- Autoridades nacionales competentes:cada Estado miembro designa al menos una autoridad de vigilancia del mercado y una autoridad notificadora. En Espana, la AESIA (Agencia Espanola de Supervision de la IA) asume funciones clave.
- Desarrollar y probar sistemas de IA innovadores bajo supervision regulatoria directa.
- Obtener orientacion sobre cumplimiento antes de la comercializacion.
- Condiciones especiales para PYMEs y startups: acceso prioritario, tasas reducidas.
Titulos VIII y IX: vigilancia post-comercializacion y aplicacion
- Recopilar y analizar datos de rendimiento de forma activa durante toda la vida util.
- Documentarse en un plan de vigilancia post-comercializacion (parte de la documentacion tecnica).
- Incluir un procedimiento de reporte de incidentes graves a las autoridades competentes y de vigilancia del mercado.
- Practicas prohibidas (art. 5):hasta 35 millones de euros o 7% del volumen de negocios mundial anual.
- Incumplimiento de requisitos de alto riesgo:hasta 15 millones de euros o 3% del volumen de negocios mundial.
- Informacion incorrecta a autoridades:hasta 7,5 millones de euros o 1% del volumen de negocios mundial.
Siguiente: TG02 - AI Risk Classification
Now that you know the complete structure of the Regulation, we will dive deeper into the risk classification methodology: decision trees, Annex III analysis and process documentation.
Ir al modulo TG02