IA Regulations (AI Act)

The Artificial Intelligence Regulation (or AI Act) establishes a framework for the placing on the market, putting into service, and use of artificial intelligence systems based on the level of risk they pose.

Getting Off to a Good Start

The European Artificial Intelligence Regulation (AI Act) is the first piece of legislation specifically dedicated to artificial intelligence. It aims to regulate the development, marketing, and use of artificial intelligence (AI) systems that may pose risks to health, safety, or fundamental rights.

Objectives of the European AI Regulation: 

  • To ensure that AI systems made available within the European Union are safe and respect fundamental rights, as well as the health and safety of individuals;
  • To encourage innovation by creating a uniform legal framework tailored to SMEs and by establishing testing and support mechanisms;
  • Grant competent authorities market surveillance powers to verify compliance with the obligations of the AI Regulation; (to be placed below) Create a common legal framework for the entire internal market and prevent fragmentation.
     

In practice

The regulation classifies AI systems based on the risks they pose. It prohibits certain uses of AI and imposes specific requirements on high-risk AI systems.

A risk-based approach classifies AI systems into four levels:
 

  1. Unacceptable risk:
    Definition: These systems are strictly prohibited because they pose too great a risk to the health, safety, or fundamental rights of individuals.
    Decision: Total prohibition on placing on the market, putting into service, or using the system.
    Examples: Subliminal manipulation, social scoring, real-time biometric surveillance in public spaces, etc.
     
  2. High risk:
    Definition: AI systems with a significant impact on health, safety, or fundamental rights.
    Decision: Enhanced requirements for compliance with rigorous standards for risk management, data governance, and human oversight.
    Examples: AI used in critical infrastructure (healthcare, transportation, energy), education and training systems, automated recruitment tools, AI for essential public services (healthcare, justice), etc. and AI used in certain products already subject to regulation (e.g., medical devices, in vitro diagnostic devices, toys, etc.)
     
  3. Limited Risk:
    Definition: These systems are subject to specific transparency requirements, particularly in cases of a clear risk of manipulation.
    Decision: Users must be informed that they are interacting with an AI system.
    Examples: Chatbots, content generation, deepfakes, emotion recognition systems, etc.
     
  4. Minimal risk:
    Definition: All other AI systems are not subject to any specific obligations under the AI Regulation.
    Decision: No specific regulatory requirements.
    Examples: Spam filters, AI-based video games, etc.
     
  5. Parallel category: General-purpose AI models

The AI Regulation also governs general-purpose AI models, i.e., models capable of performing a wide range of tasks (such as generative AI models). Providers of these models will be required to comply with various obligations, ranging from publishing a summary of training data to conducting a thorough assessment and implementing measures to mitigate systemic risks.

When?

The AI Omnibus Act has modified the timeline for the AI Regulation’s entry into force.

It is being implemented gradually:

  • February 2, 2025: Ban on AI systems posing unacceptable risks
  • August 2, 2025: Rules for general-purpose AI models take effect
  • August 2, 2026: Transparency and labeling requirements take effect (Article 50)
  • December 2, 2027: Entry into force of obligations for sector-specific high-risk AI systems (Annex III, including biometric AI systems used for access to essential public and private services, etc.)
  • August 2, 2028: Entry into force of obligations for high-risk AI systems integrated into regulated products (Annex I, including medical devices and in vitro diagnostic devices).
     

Frequently Asked Questions

Who is affected by the AI Act?

The European Artificial Intelligence Regulation (AI Act) applies to any organization that supplies, imports, distributes, or deploys artificial intelligence systems covered by the regulation.¹ This includes companies, associations, and government agencies.

Does the AI RIA Act replace the GDPR?

No, the RIA does not replace the GDPR; rather, it complements it. The GDPR applies to all processing of personal data. Therefore, complying with the RIA’s requirements helps ensure compliance with the GDPR’s requirements.
For more information, see the CNIL’s FAQs. 

How can I find out which regulations apply to my project?

  • The AI Act applies on its own: if my solution uses a high-risk AI system without requiring personal data. In practice, this is very rarely the case.;
  • The GDPR applies on its own: if I process personal data without using an AI system subject to the AI Act;
  • Both apply: if my high-risk AI system requires personal data for its development or deployment;
  • Neither applies: if my low-risk AI system does not process personal data. In practice, this is very rarely the case.

For more information, see the CNIL’s
FAQs. 

What are the supervisory authorities and governance structures provided for in the IA Regulation?

The AI Regulation provides for several levels of oversight and governance:

  • European AI Office: established within the European Commission, it is responsible for market oversight of general-purpose AI models
  • National Market Surveillance Authorities: Each Member State must designate authorities responsible for monitoring and enforcing the rules on AI systems, including prohibitions and requirements for high-risk systems

In France, oversight of the proper implementation of the AI Regulation will be carried out by several authorities. Thus, oversight of AI systems covered by the regulation after they are placed on the market or put into service will be carried out by the competent or relevant sector-specific administrations, agencies, and authorities.

More information on the competent authorities is available on the website of the Directorate General for Enterprises
 

What are the penalties for noncompliance?

The penalties provided for under the AI Act range from 1% to 7% of the company’s global annual revenue, or fines ranging from 7.5 to 35 million euros. The amount depends on the nature of the noncompliance (prohibited uses, requirements for high-risk applications, or transparency requirements for limited risks). This amount is reduced for small and medium-sized enterprises.

Our experts on the subject

Line Farah,

Digital Health Delegation (DNS)

Hélène Guimiot,

CNIL