Ch 17.10 - AI, Art 22, AI Act

Artificial Intelligence and the EU AI Act

AI systems may process personal data during design, training, testing and deployment, so the GDPR can apply throughout the lifecycle. Articles 13 and 14 may require meaningful information about the logic, significance and intended consequences of significant automated decisions. The EDPB says contractual necessity does not generally cover service improvement. It also says whether a trained model is anonymous must be assessed case by case. Solely automated decisions with legal or similarly significant effects engage Article 22. The adopted EU AI Act prohibits defined practices and regulates high-risk systems.

AI Act - risk categories
CategoryExamples / treatment
ProhibitedSubliminal/vulnerability-exploiting manipulation causing harm; public-authority social scoring; real-time remote biometric ID in public for law enforcement (limited exceptions)
High-riskPermitted but strict: training-data quality, documentation, transparency, human oversight, accuracy, security, conformity assessment, public registration, CE marking
Limited / transparencyNotice for systems interacting with people, emotion-recognition, biometric categorisation, and 'deep fakes'
AI Act enforcement

National competent authorities and the European AI Office share enforcement roles. Article 99 sets a top fine of €35 million or 7% of worldwide annual turnover for prohibited practices. Other listed breaches use lower tiers. The Act entered into force on 1 August 2024 and applies in stages.

  • Personal data is used at design, training, testing and deployment - GDPR applies throughout
  • Significant solely-automated AI decisions: provide meaningful info about the logic (Arts 13/14) and engage Article 22
  • Service improvement generally can't rely on Art 6(1)(b) contract (EDPB)
  • After consent is withdrawn, the controller needs another lawful basis or must stop the relevant processing; whether the trained model itself contains personal data requires a case-by-case anonymity assessment
  • Testing for bias may need special category data - an Article 9(2) condition is required; the AI Act would permit this for bias correction in high-risk systems

Key terms - quick answers

What is “AI”?
Software using techniques (e.g. machine learning) that, for human-defined objectives, generate content, predictions, recommendations or decisions.
What is “AI Act”?
Regulation (EU) 2024/1689, a risk-based framework for AI systems that entered into force on 1 August 2024.
What is “High-risk AI system”?
AI permitted but subject to strict requirements (data quality, documentation, human oversight, conformity assessment, CE marking, registration).

Sources and study method

This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.