1. Developing and implementing compliance measures
If you wish to start using AI, you should first ask yourself: What requirements does the EU’s AI Act set out for the use of AI? What are the associated objectives and implications? And what does this mean for your own organisation? The compliance requirements of the AI Act should be understood as product safety regulations. The EU aims to promote the use of trustworthy AI systems and protect society from risks. AI applications must meet a whole range of criteria derived from the EU Charter of Fundamental Rights. What this means specifically for your organisation depends on many factors, particularly the type of application and the associated risks.
The AI Act distinguishes between four risk classes for AI systems:
- Minimal risk
- Low risk
- High risk
- Unacceptable risk (prohibited AI practices)
The specific requirements for an organisation arise from its roles in relation to the use of AI, as well as the nature of the data processed during the training and application of AI.
2. Developing technical competence
The AI Act stipulates that organisations using AI must equip their staff with an adequate level of AI competence. Rapid technological progress makes this a real challenge for those involved – whether they are developing, testing or integrating applications into existing IT landscapes. Trustworthy partners who are familiar not only with AI but also with existing specialist processes or business applications can help build these skills.
3. Developing subject-matter expertise
In addition to technical expertise, subject-matter expertise is also crucial for the successful deployment of AI. Companies and public authorities should communicate openly on the topic of ‘AI and ethics’ and teach the fundamentals of AI so that staff can use it in a legally compliant manner. A key challenge for staff development will be to establish an appropriate understanding of AI compliance requirements across the entire workforce. The aim is to allay fears, build trust and achieve more together with AI. Furthermore, by conducting and documenting training programmes, organisations fulfil their duty to provide evidence.
4. Adapting organisational structure and processes
The integration of Microsoft Copilot into Office applications reflects a general trend: AI is becoming present throughout the organisation. This raises numerous questions regarding the organisation’s processes and structure: Where is personal data processed using AI? Who reviews the results of AI applications? Is the dual-control principle sufficient? To assess which specific regulations must be observed and how they can be implemented efficiently, a combination of legal, technological, technical and organisational expertise is required. Only in this way can organisations identify at an early stage where AI is affecting existing processes. In addition, arrangements must be made to determine who will document and communicate the new procedures. It must be established which roles and organisational units are to take on the new compliance tasks.
5. Testing and practising under real-world conditions
When it comes to implementing ethically responsible AI solutions, knowledge alone is not enough. Practice is also required. At the decision-maker level, this means, amongst other things, scrutinising how day-to-day operations in businesses and public authorities align with AI compliance requirements. In public authorities, for example, draft legislation and final legislative texts can be compared at the touch of a button. The integration of AI will transform the practical use of software across the board. And all staff must know, in their day-to-day work, which data they are permitted to use in AI applications – and which they are not.
6. Carry out a conformity assessment
The AI Act defines a ‘conformity assessment’ as ‘the procedure by which it is demonstrated that the specified requirements for a high-risk AI system are met’. These requirements include, for example, that providers of high-risk AI systems must establish and document a risk management system throughout the entire lifecycle. They must also test high-risk AI systems before placing them on the market or putting them into service, implement specific data governance measures and set up a quality management system to ensure compliance with the provisions of the AI Act.
7. Ensuring the legal compliance of tenders
The AI Act presents particular challenges for public authorities: they must take the requirements of the legislation into account as early as the tendering stage for AI projects. Furthermore, there may be interactions with other EU regulations, such as the Data Act, particularly where internal security or critical infrastructure is concerned.
8. Strengthening data management
The AI Act imposes specific requirements on data governance. On the one hand, this means that AI systems must meet the high standards of the GDPR when processing personal data. Secondly, the requirements for data quality are increasing across the entire organisation: this applies both to checking training data to ensure it is suitable for non-discriminatory AI recommendations, and to labelling AI-generated text and images. The focus is on the entire lifecycle of AI and the data used for AI – from development through to implementation and operation, right through to automated deletion.
How you can utilise AI: Generative AI (materna.de)
Download white paper: Request the AI white paper now (materna.de)