En este modulo

  1. Regulation structure: overview
  2. Titles I and II: scope, definitions and prohibitions
  3. Title III: high-risk AI systems
  4. Titles IV and V: transparency and general-purpose AI models
  5. Titles VI and VII: governance and regulatory sandbox
  6. Titles VIII and IX: post-market surveillance and enforcement
  7. Delegated and implementing acts
  8. Harmonised standards and technical specifications
  9. Sectoral guidance: healthcare, finance, employment, education
  10. Implementation timeline
  11. Ejercicio practico
  12. Puntos clave

Regulation structure: overview

Regulation (EU) 2024/1689, known as the EU AI Act, is the first comprehensive legislation on artificial intelligence in the world. It entered into force on 1 August 2024 and establishes a risk-based legal framework that affects providers, deployers, importers and distributors of AI systems in the European market.

The Regulation contains 113 articles organized in 13 titles, 13 annexes and more than 180 recitals. For a DPO or compliance officer, the key is not to memorize every article, but to understand the regulatory architecture and know where to look when a specific question arises.

Regulatory architecture

The AI Act follows a pattern familiar in European regulation: it establishes general principles in the first titles, develops specific obligations in the central ones, and reserves the final titles for governance, enforcement and transitional provisions. The annexes contain the technical lists that determine the classification of systems.

Difference from the GDPR

The GDPR applies to all processing of personal data. The AI Act applies only to systems that meet the definition of "AI system" in Article 3. Not all automation is an AI system under the Regulation. The first compliance task is to determine whether your system falls within scope.

Titles I and II: scope, definitions and prohibitions

Article 3: key definitions

Article 3 contains 68 definitions. The most relevant for governance:

Article 5: prohibited AI practices

Article 5 establishes 8 absolutely prohibited practices. These prohibitions are applicable since February 2025 and admit no exceptions (except those expressly provided for law enforcement in specifically defined cases):

  1. Subliminal manipulation: techniques that exploit vulnerabilities of persons or groups to distort their behavior in a manner that causes harm.
  2. Social scoring: classification of persons based on social behavior for disproportionately unfavorable treatment.
  3. Individual crime prediction: based solely on profiling or personality traits (without objective evidence).
  4. Untargeted facial scraping: creation of facial recognition databases through untargeted scraping of images from the internet or CCTV.
  5. Emotion recognition: in the workplace and educational institutions (with medical/safety exceptions).
  6. Biometric categorisation: to infer race, political opinions, trade union membership, religious beliefs or sexual orientation.
  7. Real-time remote biometric identification: in publicly accessible spaces by law enforcement (with specifically defined exceptions and prior judicial authorisation).
  8. Exploitation of vulnerabilities: by age, disability or specific social or economic situation.

Practical implication

If your organization uses any system that may fall into these categories, the consequence is not "comply with additional requirements". It is to cease the activity. No level of documentation can save a prohibited practice. The penalty can reach 35 million euros or 7% of total worldwide annual turnover.

Title III: high-risk AI systems

Title III (Articles 6 to 49) is the operational core of the Regulation. It defines which systems are high-risk and establishes mandatory requirements for providers, deployers, importers and distributors.

Article 6: high-risk classification

A system is classified as high-risk through two pathways:

Annex III: the 8 high-risk areas

Annex III lists 8 areas with specific sub-areas:

  1. Biometrics: remote biometric identification (not real-time), biometric categorisation, emotion recognition.
  2. Critical infrastructure: safety components in the management of traffic, water supply, gas, heating, electricity.
  3. Education and vocational training: admission, assessment of learning outcomes, proctoring of examinations, detection of prohibited behavior.
  4. Employment and management of workers: recruitment, filtering of applications, decisions on promotion/termination, task assignment based on profile, performance monitoring.
  5. Access to essential services: assessment of eligibility for public benefits, credit scoring, risk assessment in life/health insurance, prioritisation in emergency services.
  6. Law enforcement: risk assessment of victimisation, polygraphs, assessment of reliability of evidence, recidivism prediction.
  7. Migration, asylum and border control: polygraphs, security/health/irregular immigration risk assessment, document verification.
  8. Administration of justice and democratic processes: assistance in investigating facts/law, application of law to a specific case, influence on electoral outcomes.

Requirements for high-risk AI systems (Articles 8-15)

Providers of high-risk AI systems must meet these requirements before placing on the market:

Deployer obligations (Articles 26-27)

As a deployer, your obligations are distinct from those of the provider but equally binding:

Titles IV and V: transparency and general-purpose AI models

Transparency obligations (Title IV, Art. 50)

Certain systems that are not high-risk but interact with persons require transparency obligations:

General-purpose AI models (Title V, Arts. 51-56)

GPAI models (GPT, Claude, Gemini, Llama, etc.) have their own regime. This affects foundation model providers, but also has downstream implications:

Implication for deployers

If your organization uses a GPAI model as a component of a high-risk system (for example, GPT-4 for candidate screening), the Title III obligations fall on you as the provider of the complete system. You cannot delegate responsibility to the base model provider.

Titles VI and VII: governance and regulatory sandbox

Governance structure (Title VI)

The AI Act creates a three-tier institutional architecture:

Regulatory sandbox (Title VII, Arts. 57-63)

Member States must establish at least one AI regulatory sandbox before 2 August 2026. These controlled environments allow:

The sandbox does not exempt from compliance. It provides a supervised environment where errors have controlled consequences and where the competent authority offers real-time feedback.

Titles VIII and IX: post-market surveillance and enforcement

Post-market surveillance (Arts. 72-75)

Providers of high-risk AI systems must establish a post-market surveillance system proportionate to the nature and risks of the system. This system must:

Serious incidents (Art. 73)

A serious incident is defined as any incident that directly or indirectly leads to: death or serious damage to health, serious and irreversible damage to property or the environment, or serious breach of fundamental rights. The provider must notify the market surveillance authority of the Member State where the incident occurred without undue delay and, in any case, within 15 days.

Penalty regime (Arts. 99-101)

The AI Act penalties are significant and tiered:

Delegated and implementing acts

The AI Act delegates to the European Commission the adoption of delegated and implementing acts to develop numerous technical aspects. These acts are essential because they specify the general requirements of the Regulation:

Planned delegated acts

Planned implementing acts

Mandatory monitoring

Delegated and implementing acts are living law. An AI compliance programme cannot be "set and forget". You need to monitor the Official Journal of the EU, AI Office publications and AESIA documents to stay up to date.

Harmonised standards and technical specifications

The AI Act establishes a presumption of conformity for systems that comply with European harmonised standards or, in their absence, common specifications adopted by the Commission.

Key standards in development

Presumption of conformity

When a high-risk system complies with the harmonised standards published in the Official Journal, it is presumed to comply with the requirements of the Regulation covered by those standards. This presumption is rebuttable: the surveillance authority may require additional evidence. But in practice, certifying against harmonised standards is the safest pathway to demonstrate compliance.

Sectoral guidance: healthcare, finance, employment, education

Healthcare

AI systems in medical devices are covered by both the AI Act and the Medical Devices Regulation (MDR 2017/745). The AI Act conformity assessment is integrated into the MDR assessment. Notified bodies under the MDR also act for the AI Act. Note: clinical AI systems that are not medical devices (for example, hospital shift optimization using patient data) may fall under Annex III area 5 (access to essential services).

Finance

Credit scoring is explicitly listed in Annex III. Risk models used in banking and insurance may be high-risk systems. The AI Act applies alongside existing financial regulation (CRD, Solvency II, MiFID II). Financial supervisors (EBA, EIOPA, ESMA) may act as competent authorities within their sectoral remit.

Employment

This is one of the areas with the greatest practical impact. Any AI system used in recruitment (CV screening, automated interviews, candidate evaluation), performance management or decisions about promotion/termination is high-risk. Companies using AI-powered hiring platforms (HireVue, Pymetrics, etc.) are deployers with direct obligations.

Education

Automated admission systems, academic performance assessment, online proctoring and plagiarism/cheating detection are high-risk. Universities and educational institutions must assess all their AI systems against Annex III area 3.

Implementation timeline

The AI Act has a phased application. Not everything is enforceable from day one:

Time is limited

If your organization operates systems that may be classified as high-risk under Annex III, you have until August 2026 to meet all Title III requirements. That includes technical documentation, risk management system, data governance, human oversight, fundamental rights impact assessment and registration in the EU database.

Ejercicio practico

Ejercicio TG01: Mapping AI systems in your organization
  1. Compile an inventory of all systems using AI components in your organization (include third-party SaaS tools).
  2. For each system, determine whether it meets the definition of "AI system" in Article 3(1).
  3. Classify each system: prohibited practice (Art. 5), high-risk (Annex III), transparency obligations (Art. 50), or minimal risk.
  4. Identify your role in the value chain for each system: provider, deployer, importer or distributor.
  5. Map the relevant application dates for each system according to the phased timeline.
  6. For high-risk systems, compile an initial gap list against the requirements of Articles 8-15.

Output: a 2-3 page document that serves as a starting point for your AI Act compliance programme.

Puntos clave

Puntos clave from TG01

  1. The AI Act is a risk-based regulation with 4 levels: prohibited, high-risk, limited risk (transparency) and minimal risk. Most obligations fall on high-risk systems.
  2. Annex III lists 8 high-risk areas. The most relevant for most organizations: employment, access to essential services (credit scoring, insurance) and education.
  3. Deployers (those who use the system) have their own obligations: human oversight, input data quality, monitoring, fundamental rights impact assessment.
  4. Delegated acts, harmonised standards and codes of practice are living law. AI compliance requires continuous monitoring of regulatory developments.
  5. The key date for most organizations is 2 August 2026. The prohibitions have already been applicable since February 2025.
Guia de estudio — Conceptos clave de TG01

Estructura del Reglamento: vision general

  • Titulos I-II:definiciones, ambito de aplicacion, practicas prohibidas.
  • Titulo III:el corazon del Reglamento. Sistemas de alto riesgo: requisitos, obligaciones de proveedores e implementadores.
  • Titulo IV:obligaciones de transparencia para sistemas de riesgo limitado.
  • Titulo V:modelos de IA de proposito general (GPAI), incluidos los de riesgo sistemico.
  • Titulos VI-VII:gobernanza (AI Office, AI Board, autoridades nacionales) y sandbox regulatorio.
  • Titulos VIII-XII:vigilancia post-comercializacion, enforcement, sanciones, delegaciones.

Titulos I y II: ambito, definiciones y prohibiciones

  • Sistema de IA (art. 3.1):sistema basado en maquina, disenado para operar con niveles variables de autonomia, que puede generar resultados como predicciones, contenido, recomendaciones o decisiones que influyen en entornos fisicos o virtuales. Esta definicion es intencionalmente amplia.
  • Proveedor (art. 3.3):persona que desarrolla o hace desarrollar un sistema de IA y lo comercializa o pone en servicio bajo su nombre. Es quien asume la mayor carga regulatoria.
  • Implementador (art. 3.4):persona que utiliza un sistema de IA bajo su autoridad. En la mayoria de organizaciones, este es tu rol. Las obligaciones del implementador son menores pero no triviales.
  • Uso previsto (art. 3.12):el uso para el que el proveedor destina el sistema. Cualquier uso fuera del uso previsto puede reclasificar al implementador como proveedor de facto.
  • Manipulacion subliminal:tecnicas que explotan vulnerabilidades de personas o grupos para distorsionar su comportamiento de manera que cause dano.
  • Social scoring:clasificacion de personas basada en comportamiento social para trato desfavorable desproporcionado.

Titulo III: sistemas de alto riesgo

  • Via 1 (art. 6.1):el sistema es un componente de seguridad de un producto cubierto por legislacion de armonizacion de la Union listada en el Anexo I (maquinaria, juguetes, dispositivos medicos, productos sanitarios, etc.) y requiere evaluacion de conformidad por tercero.
  • Via 2 (art. 6.2):el sistema esta listado en el Anexo III. Esta es la via mas relevante para la mayoria de organizaciones.
  • Biometria:identificacion biometrica remota (no en tiempo real), categorizacion biometrica, reconocimiento de emociones.
  • Infraestructuras criticas:componentes de seguridad en gestion de trafico, suministro de agua, gas, calefaccion, electricidad.
  • Educacion y formacion profesional:admision, evaluacion de resultados de aprendizaje, supervision de examenes, deteccion de comportamiento prohibido.
  • Empleo y gestion de trabajadores:seleccion, filtrado de candidaturas, decisiones sobre promocion/despido, asignacion de tareas basada en perfil, monitorizacion del rendimiento.

Titulos IV y V: transparencia y modelos de proposito general

  • Chatbots y asistentes:informar al usuario de que esta interactuando con un sistema de IA (salvo que sea evidente por el contexto).
  • Deepfakes:contenido de imagen, audio o video generado o manipulado artificialmente debe estar etiquetado de manera detectable tanto para personas como para sistemas automatizados.
  • Contenido generado:texto publicado para informar al publico sobre asuntos de interes publico debe indicar que ha sido generado artificialmente.
  • Reconocimiento de emociones y categorizacion biometrica:informar a las personas expuestas y cumplir RGPD cuando procese datos personales.
  • Todos los proveedores GPAI:documentacion tecnica, politica de cumplimiento de derechos de autor, publicacion de un resumen del contenido de entrenamiento.
  • GPAI con riesgo sistemico:si el modelo supera 10^25 FLOPS de entrenamiento o es designado por la Comision. Obligaciones adicionales: evaluacion del modelo, pruebas adversariales, trazabilidad de incidentes graves, ciberseguridad adecuada, reporte de eficiencia energetica.

Titulos VI y VII: gobernanza y sandbox regulatorio

  • AI Office (Oficina Europea de IA):dentro de la Comision. Competente para GPAI, coordinacion general, codigos de practicas, normas armonizadas. Es el regulador de facto para los modelos fundacionales.
  • European AI Board (Comite Europeo de IA):representantes de autoridades nacionales. Asesora a la Comision, facilita coherencia entre Estados miembros, emite dictamenes.
  • Autoridades nacionales competentes:cada Estado miembro designa al menos una autoridad de vigilancia del mercado y una autoridad notificadora. En Espana, la AESIA (Agencia Espanola de Supervision de la IA) asume funciones clave.
  • Desarrollar y probar sistemas de IA innovadores bajo supervision regulatoria directa.
  • Obtener orientacion sobre cumplimiento antes de la comercializacion.
  • Condiciones especiales para PYMEs y startups: acceso prioritario, tasas reducidas.

Titulos VIII y IX: vigilancia post-comercializacion y aplicacion

  • Recopilar y analizar datos de rendimiento de forma activa durante toda la vida util.
  • Documentarse en un plan de vigilancia post-comercializacion (parte de la documentacion tecnica).
  • Incluir un procedimiento de reporte de incidentes graves a las autoridades competentes y de vigilancia del mercado.
  • Practicas prohibidas (art. 5):hasta 35 millones de euros o 7% del volumen de negocios mundial anual.
  • Incumplimiento de requisitos de alto riesgo:hasta 15 millones de euros o 3% del volumen de negocios mundial.
  • Informacion incorrecta a autoridades:hasta 7,5 millones de euros o 1% del volumen de negocios mundial.

Siguiente: TG02 - AI Risk Classification

Now that you know the complete structure of the Regulation, we will dive deeper into the risk classification methodology: decision trees, Annex III analysis and process documentation.

Ir al modulo TG02