Search
Contact
Symbolbild zu AI Act
16.07.2024 | KPMG Law Insights

The AI Act is coming: EU wants to get a grip on AI risks

For many people, artificial intelligence (AI) is the great hope for business, healthcare and science. But there are also plenty of critics who fear the risks of AI and call for rules. With the AI Act, the EU Commission now wants to regulate artificial intelligence for the European region and thus get the greatest risks for users under control. The EU Parliament has already approved the Commission’s draft. The law is scheduled to take effect in 2024.

The idea is that the higher the risk of an AI system, the higher the associated requirements and obligations. AI regulation is intended to increase user confidence in AI within the EU and thus also create better conditions for innovation for manufacturers and users of AI applications.

Violations can result in fines of up to 30 million euros or up to six percent of total annual global sales for the previous fiscal year. The sanctions are thus comparable to those of the GDPR.

The AI Act is to be accompanied by an AI liability policy. And the EU Commission also wants to update the Product Liability Directive. The goal: To close liability gaps in the use of AI systems and to address evidentiary difficulties in the event of legal violations in connection with artificial intelligence.

The obligations of the EU AI Act affect manufacturers, suppliers and distributors of AI systems, product manufacturers who incorporate AI systems into their products, and users of AI systems, i.e. virtually every company.

AI with an “unacceptable” level of risk prohibited by the AI Act

The AI Act divides artificial intelligence into three risk classes: “unacceptable,” “high,” and “low/minimal.”

Placing on the market, putting into service, or using AI systems that pose an unacceptable risk is prohibited. These include, in particular, those AI systems that are designed to subliminally adversely influence human behavior. AI that serves to exploit the weaknesses of vulnerable individuals is also unacceptable and thus prohibited. Also prohibited is the use of AI systems by public authorities to assess or classify the trustworthiness of natural persons (“social scoring”). AI systems may likewise not in principle be used for real-time biometric remote identification of natural persons in publicly accessible spaces for law enforcement purposes.

For AI systems with risk class “high”, special requirements apply

AI systems that pose a high risk to the health and safety or fundamental rights of natural persons are referred to as “high-risk AI systems.” These include, for example, human dignity, respect for private and family life, protection of personal data, freedom of expression and information, and freedom of assembly and association.

The AI Act imposes stringent requirements on the design and use of high-risk AI systems, for example, in terms of the quality of the data basis, security, functionality, and also human documentation and oversight, as well as quality and risk management.

Conformity with the AI Act should be made visible with a CE marking.

Lower requirements for systems with “low/minimal” risk class

Unless AI systems are unacceptable and also classified as high-risk AI systems, they fall into the third category. They are then subject to less stringent requirements. However, providers of such systems should still establish codes of conduct and be encouraged to voluntarily apply the regulations for high-risk AI systems. In addition, the EU AI Act requires that even low-risk AI systems must be safe if they are placed on the market or put into service. Security can be ensured in particular by voluntarily observing the regulations for high-risk AI systems.

With AI governance, companies can hedge risks

Organizations should actively evaluate each application and incorporate it into a governance structure.

All AI-based solutions should also be considered. Use cases and the associated risks should be known to companies. Manufacturers of an end product must comply with the vendor obligations set forth in the AI Act and ensure that the AI system embedded in the end product is compliant. Risks also include the liability risk arising from the AI Act.

When building AI governance, the key is who is responsible for grading the risks. To make the assessment as objective as possible, the team should be interdisciplinary.

How AI risk management can succeed

For effective risk management, companies should establish guidelines, processes and monitoring solutions. Various institutions and organizations such as BSI, IDW or DIN are already developing standards for this.

It is advisable not to separate compliance and performance. Management and IT should therefore work closely with the legal and compliance functions. Only if it is ensured that legal regulations are complied with and liability risks are minimized can the potential of artificial intelligence actually be exploited.

Even though the AI Act has not yet been finalized, companies can already start assessing risks and establishing appropriate governance.

Learn more about “AI risks at a glance”: Our whitepaper provides recommendations for AI governance that ensures responsible use of the new technology. Download now.

Authors:
KPMG AG Wirtschaftsprüfungsgesellschaft: Dr. Justus H. Marquardt, Oleg Brodski
KPMG Law Rechtsanwaltsgesellschaft mbH: Francois Heynike

Explore #more

22.01.2025 | KPMG Law Insights

The EU packaging regulation sets strict requirements for packaging

The EU has adopted the Packaging Regulation. After the European Parliament adopted the Commission’s draft on April 24, 2024, the EU member states also approved…

09.01.2025 | In the media

KPMG Law strengthens Legal Transformation Managed Services and Legal Corporate Services with two new senior managers

On January 1, KPMG Law strengthened its Transformation Managed Services practice with Jana Sichelschmidt and its Corporate Services practice with Dr. Michaela Lenk. Both are…

06.01.2025 | Deal Notifications

KPMG Law advises on the sale of Käppler & Pausch GmbH

Gabriel Pausch, the co-founder and main shareholder of Käppler & Pausch GmbH, a system supplier for metal assemblies as well as metal and sheet metal…

03.01.2025 | In the media

Interview in Betrieb on the EU money laundering package and its impact

The EU anti-money laundering package harmonizes anti-money laundering and counter-terrorism rules in Europe and introduces new measures such as cash limits of €10,000, identification requirements…

02.01.2025 | In the media

KPMG Law Statement in eMagazin Immobilienanwälte: Creativity meets law in trademark protection

Four Frankfurt, Elbtower, Vonovia: real estate projects and companies are backed by constructs worth millions or even billions. In order to stand out from the…

20.12.2024 | Deal Notifications

KPMG and KPMG Law supported the sale of circular Informationssysteme to the teccle group

Together with the corporate finance/M&A advisors of KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG), KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) advised the shareholders of circular Informationssysteme GmbH (circular)…

19.12.2024 | Press releases

KPMG Law defends Federal Motor Transport Authority against claim for damages in connection with the emissions scandal

The state is not liable to vehicle purchasers for damages. KPMG Law has defended the Federal Motor Transport Authority (KBA) against a civil plaintiff’s state…

18.12.2024 | KPMG Law Insights, KPMG Law Insights

MiCAR – What the new EU regulation means for crypto service providers and issuers

An EU regulation will soon come into force that will regulate crypto assets uniformly throughout Europe. It contains significant new obligations for issuers and crypto…

16.12.2024 | Deal Notifications

KPMG Law advises CERTANIA Holding GmbH on the acquisition of RASG Holdco Ltd.

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) has provided legal advice to CERTANIA Holding GmbH, a platform of the Munich-based PE firm Greenpeak Partners, on the…

04.12.2024 | Deal Notifications

KPMG Law and KPMG advises Brain Biotech AG on license agreements and monetization of license rights

KPMG Law Rechtsanwaltsgesellschaft mbH and KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG) advised Brain Biotech AG on the monetization of licensing rights with Royalty Pharma and the conclusion…

Contact

Francois Heynike, LL.M. (Stellenbosch)

Partner
Head of Technology Law

THE SQUAIRE Am Flughafen
60549 Frankfurt am Main

Tel.: +49-69-951195770
fheynike@kpmg-law.com

© 2024 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

 KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll