EU AI Act Overview: Key Insights from Digital Law Expert Alexandre Lazarègue
- European companies are struggling to identify the specific artificial intelligence tools integrated into their operations, creating a compliance gap as the European Union's AI Act takes effect.
- The AI Act establishes a risk-based framework for the regulation of artificial intelligence within the EU, imposing different obligations based on the potential harm a system can cause.
- The primary hurdle for corporate compliance is the proliferation of "shadow AI," where employees utilize third-party AI tools without official IT oversight.
European companies are struggling to identify the specific artificial intelligence tools integrated into their operations, creating a compliance gap as the European Union’s AI Act takes effect. According to Alexandre Lazarègue, a Paris-based lawyer specializing in digital law at Cabinet Lazarègue, many organizations lack a precise inventory of the AI systems they currently employ.
The AI Act establishes a risk-based framework for the regulation of artificial intelligence within the EU, imposing different obligations based on the potential harm a system can cause. For businesses to comply, they must first categorize their tools into the Act’s defined risk levels, a process Lazarègue indicates is currently hindered by a lack of internal visibility.
Compliance Challenges Under the EU AI Act
The primary hurdle for corporate compliance is the proliferation of “shadow AI,” where employees utilize third-party AI tools without official IT oversight. This fragmented adoption means that while a company may have a formal AI strategy, the actual tools in use across different departments often remain undocumented.
Under the AI Act, the legal obligations for a provider or deployer depend on the classification of the AI system. These categories include:
- Unacceptable Risk: Systems that are banned, such as those used for cognitive behavioral manipulation or untargeted scraping of facial images.
- High Risk: Systems used in critical infrastructure, education, or employment, which face stringent requirements regarding data governance, transparency, and human oversight.
- Limited Risk: Systems like chatbots, which primarily require transparency obligations so users know they are interacting with an AI.
- Minimal Risk: The vast majority of AI applications, which face no specific new obligations under the Act.
Lazarègue notes that without a comprehensive audit of existing tools, companies cannot determine which of these categories apply to their operations, leaving them vulnerable to regulatory penalties.
Legal Risks for AI Deployers
The AI Act distinguishes between the “provider” who develops the AI and the “deployer” who uses it under their authority. Many businesses operate as deployers, but they remain responsible for ensuring the tool is used according to the provider’s instructions and that the system does not violate EU law in its specific application.
Failure to maintain a registry of AI tools creates a direct conflict with the transparency and documentation requirements mandated by the EU. For high-risk systems, the lack of documentation can lead to significant fines, which the AI Act scales based on the company’s global annual turnover.
The current state of corporate AI adoption is characterized by a gap between the speed of tool implementation and the speed of legal auditing. This disconnect means that many firms are unknowingly deploying high-risk systems without the required impact assessments or human-in-the-loop safeguards.
Necessary Steps for Corporate AI Auditing
To mitigate these risks, legal experts suggest that companies move beyond simple policy statements and implement active discovery processes. This involves technical audits of software environments and mandatory disclosure from department heads regarding the AI tools used in their workflows.
According to the framework discussed by Cabinet Lazarègue, a compliant AI strategy requires three core components: a complete inventory of tools, a risk classification for each tool based on the AI Act’s criteria, and a documented governance process for the ongoing monitoring of those systems.
