What is the AI Act – the EU regulation on artificial intelligence?

Regulation (EU) 2024/1689, known as the AI Act, is the first comprehensive legislative framework
in the world governing the use of AI throughout the European Union. It
entered into force on August 1, 2024, and its application will be gradual – between 6
and 36 months, depending on the risk category of the AI system.

The main purpose

  • Ensuring AI that is safe, transparent, and human-centered.
  • Respect fundamental rights and protect EU citizens.
  • Increase trust and accountability in the development and use of AI technologies.

How does the AI Act classify artificial intelligence systems?

The regulation establishes four risk categories, plus a category for general models:

  1. Unacceptable risk – prohibited systems (e.g., real-time facial recognition, social scoring, subliminal manipulation).
  2. High risk – systems used in healthcare, education, critical infrastructure, recruitment, etc. → subject to strict security, transparency, and human oversight requirements.
  3. Limited risk – systems with minimum transparency requirements.
  4. Minimal risk – no special regulations.
  5. Generative AI (GPAI) – models such as ChatGPT → requirements regarding technical documentation,
    transparency, and copyright management.

What are the obligations of companies in Romania?

Romanian companies that develop, distribute, or use AI must:

  • Classify the AI systems used according to their level of risk.
  • Document the design and risk assessment process.
  • For high-risk systems: ensure transparency, cybersecurity, human oversight, quality management, and an EU declaration of conformity.
  • Employers using AI (e.g., in recruitment) → special obligations: qualified oversight, logs, employee information, data impact assessment.
  • Respect complementarity with GDPR – AI Act does not replace, but complements personal data protection rules.
  • Prepare internal audits, training, and compliance procedures.
  • Adopt proactive practices, including voluntary codes of good practice.

Possible sanctions

Non-compliance with regulations may result in:

  • Up to 7% of global turnover or €35 million for prohibited AI.
  • Up to 3% for other violations.
  • Up to 1.5% for providing incorrect information.
  • In certain cases: fines of €40 million or additional restrictions.

How can companies prepare effectively?

  1. Internal audit – identify all AI systems and roles (supplier, distributor, user).
  2. Risk assessment – classify each system.
  3. Complete documentation – design, data sources, logs, monitoring plans.
  4. Training and education – AI teams and management must understand their obligations.
  5. Specialized consulting – tech lawyers and AI experts for compliance.
  6. Proactive alignment – implementation of EU standard practices before deadlines.

Conclusion – why does the AI Act matter for Romania?

The AI Act sets a new global regulatory standard – comparable to the GDPR, but for algorithms and artificial intelligence. For companies, it is not only a legal obligation, but also an opportunity to build trust through the responsible use of AI.

Leave a Reply

Your email address will not be published.

*

Nartea - 2020