Domain II · Competency II.C

Understand the main elements of AI-specific laws

The architecture of purpose-built AI law, anchored in the EU AI Act (Regulation (EU) 2024/1689): the four risk tiers and what falls in each; core requirements (risk management, data governance, technical documentation, conformity/impact assessment, record keeping); human oversight, transparency and quality management; GPAI model obligations and the systemic-risk threshold; enforcement and penalties; and role-based duties for providers, deployers, importers and distributors — contrasted with the South Korean AI Basic Act and the Colorado AI Act.

Exam weight: 6–8 questions

Quick check not attempted yet — take it below to track your score.

Performance indicators

Key terms

EU AI Act
Regulation (EU) 2024/1689 — the first comprehensive horizontal AI law. Classifies AI systems by risk and imposes obligations by tier and by role, with phased application from 2025–2027.
Risk-tier framework
The AI Act sorts systems into four tiers — prohibited (unacceptable), high, limited (transparency), and minimal risk — with obligations scaling to risk.
Prohibited AI practices (Art. 5)
Unacceptable-risk uses banned outright, e.g. social scoring by public authorities, manipulative/exploitative systems, untargeted facial-image scraping, and (mostly) real-time remote biometric ID in public by law enforcement.
High-risk AI system
Systems posing significant risk to health, safety or fundamental rights (Annex III areas + safety components of regulated products). Subject to the heaviest obligations short of prohibition.
Conformity assessment
The pre-market process by which a high-risk system's compliance is verified (often self-assessment), followed by a CE marking and EU database registration.
Fundamental Rights Impact Assessment (FRIA)
An assessment certain deployers of high-risk AI (e.g., public bodies) must perform on impacts to fundamental rights before use (AI Act Art. 27).
GPAI model
General-purpose AI model — trained on broad data, displaying significant generality, usable across many tasks. Subject to dedicated transparency and copyright obligations.
Systemic-risk GPAI
A GPAI model with high-impact capabilities — presumed where training compute exceeds 10^25 FLOPs — triggering extra obligations (evaluation, adversarial testing, incident reporting, cybersecurity).
Provider
The party that develops an AI system/model (or has it developed) and places it on the market or puts it into service under its own name. Bears the heaviest AI Act obligations.
Deployer
A party using an AI system under its own authority (other than personal, non-professional use). Lighter but real obligations: oversight, monitoring, input data, notice.
South Korean AI Basic Act
Asia's first comprehensive AI law (effective Jan 2026): high-impact AI duties, generative-AI transparency, and a domestic-representative requirement for large foreign providers.
Colorado AI Act (SB 24-205)
Leading U.S. state AI law: a duty of reasonable care on developers and deployers of high-risk AI to avoid algorithmic discrimination — a risk-of-harm model, narrower than the EU AI Act.

At a glance

This is the heaviest-weighted competency in Domain II, and the EU AI Act — Regulation (EU) 2024/1689 — is its centre of gravity. The Act is built on two organising ideas you must hold at once:

Layered on top are the substantive requirements (II.C.2–II.C.3), the separate GPAI model regime (II.C.4), and enforcement/penalties (II.C.5). You should also be able to contrast the EU’s comprehensive risk-based model with the South Korean AI Basic Act and the Colorado AI Act.

II.C.1 — Risk classification framework

TierWhat it isRepresentative examplesObligation
Unacceptable / Prohibited (Art. 5)Uses deemed a clear threat to rightsGovernment social scoring; manipulative or exploitative systems; untargeted scraping of facial images; emotion recognition in workplace/education; most real-time remote biometric ID in public by law enforcementBanned
High-risk (Arts. 6, Annex III)Significant risk to health, safety, fundamental rightsAI in employment/hiring, credit/lending, education, essential services, biometric ID, critical infrastructure, law enforcement, migration; safety components of regulated productsFull requirements + conformity assessment
Limited / Transparency riskInteracts with or generates content for peopleChatbots, deepfakes / synthetic media, AI-generated contentDisclosure/labelling duties only
Minimal riskEverything elseSpam filters, AI in video games, inventory optimisationNo mandatory obligations (voluntary codes)

II.C.2 — Risk management, data governance, documentation, conformity, records

For high-risk systems, providers must establish (Arts. 9–18):

Certain deployers must also perform a Fundamental Rights Impact Assessment (FRIA, Art. 27) before putting a high-risk system into use (notably public bodies and some private actors).

II.C.3 — Human oversight, transparency and quality management

II.C.4 — General-purpose AI (GPAI) models

The Act regulates GPAI models separately from AI systems. All GPAI providers must:

A GPAI model with systemic risk carries extra duties. Systemic risk is presumed where cumulative training compute exceeds 10^25 FLOPs (or by Commission designation). Those providers must additionally: perform model evaluations and adversarial testing (red-teaming), assess and mitigate systemic risks, report serious incidents, and ensure adequate cybersecurity.

II.C.5 — Enforcement and penalties

Enforcement runs through national market-surveillance authorities and, for GPAI, the European AI Office. Fines are tiered to the severity of the breach (whichever is higher of a euro amount or a percentage of global annual turnover):

ViolationMaximum fine
Prohibited practices (Art. 5)€35M or 7% of global turnover
Most other obligations (high-risk, transparency, GPAI duties)€15M or 3%
Supplying incorrect/misleading information to authorities€7.5M or 1%

Phased application (from entry into force, 1 Aug 2024): prohibitions apply from Feb 2025; GPAI obligations from Aug 2025; most high-risk obligations from Aug 2026; high-risk systems that are safety components of regulated products from Aug 2027.

Watch item: the Commission has floated “simplification” / digital-omnibus proposals that could adjust some AI Act timelines and duties. Learn the dates above as enacted, and check for adopted amendments close to your exam date — but expect the exam to test the enacted framework, not pending proposals.

II.C.6 — Role-based obligations

The Act assigns duties by operator role. The same organisation can hold several roles, and a deployer can become a provider (inheriting heavier duties) if it puts its name on a high-risk system or substantially modifies one.

RoleDefinitionCore obligations (high-risk)
ProviderDevelops the system/model and places it on the market under its own nameThe full set: risk management, data governance, documentation, conformity assessment, CE marking, registration, QMS, post-market monitoring
DeployerUses the system under its own authority (professional use)Use per instructions, ensure human oversight, monitor operation, ensure input data relevance, keep logs, inform affected persons, FRIA where required
ImporterPlaces a non-EU provider’s system on the EU marketVerify the provider did conformity assessment, documentation and CE marking before import
DistributorMakes a system available in the chain (not provider/importer)Check CE marking and documentation; do not supply non-conforming systems
Authorized representativeEU-established agent appointed in writing by a non-EU provider (Art. 22)Verify conformity documentation exists, keep it available for authorities, cooperate with regulators — the provider’s mandatory EU point of contact

Territorial scope — who is caught

Like the GDPR, the AI Act reaches beyond the EU’s borders (Art. 2). It applies to:

So a US company with no EU office is still in scope if its AI system’s output is used in the Union. Conversely, an EU company’s system built and used entirely outside the EU (no EU market placement, no EU output use) is not caught.

The wider landscape: US states, China and other regimes

US state laws cluster into four models — recognising which model a statute follows is more useful than memorising every state:

ModelWhat it regulatesExamples
Consequential-decisionAlgorithmic discrimination in high-stakes decisions (employment, credit, housing, healthcare)Colorado AI Act; Illinois’ employment-AI amendments
Frontier-model safetyThe largest foundation models: safety frameworks, incident reporting, whistleblower protectionCalifornia SB 53 (frontier AI transparency)
Transparency / disclosureDocumentation of training data and AI-generated contentCalifornia AB 2013 (training-data transparency)
Interaction / chatbotTelling people they’re dealing with an AIUtah AI Policy Act; chatbot-disclosure laws

China regulates by application, iteratively — three key instruments: algorithm-recommendation provisions (2022), deep-synthesis rules (2023, mandatory labeling of synthetic media), and the Interim Measures for Generative AI Services (2023 — content moderation, training-data legality, labeling duties for public-facing GenAI). Distinctive features: algorithm registration/filing with the regulator and content-alignment requirements.

Other approaches worth one line each: the UK has no horizontal AI statute — existing regulators apply five cross-sector principles (pro-innovation, principles-based). Canada’s federal AIDA bill died with prorogation in early 2025, leaving provincial/privacy law to do the work. Japan follows a light-touch, soft-law-first promotion approach. The spectrum runs: EU (comprehensive, product-safety style) → South Korea (comprehensive but lighter) → China (application-specific, state-led) → UK/Japan (principles/soft law) → US (sectoral + state patchwork).

Contrast: South Korea and Colorado

South Korean AI Basic Act (Asia’s first comprehensive AI law; effective Jan 2026). Like the EU, it is risk-tinged and horizontal, but lighter-touch:

Colorado AI Act (SB 24-205) — the leading U.S. state AI law. It targets “algorithmic discrimination” in consequential decisions (employment, lending, housing, insurance, education, healthcare, legal/government services) by imposing a duty of reasonable care on developers and deployers of high-risk AI (impact assessments, risk-management policy, consumer notice, attorney-general enforcement — no private right of action).

How this shows up later

Sources

Flashcards

1 / 12

Quick check

Quick check1 / 25 · score 0

Under the EU AI Act, a government program that assigns citizens a general "social score" used to grant or deny services falls into which risk tier?

  • AMinimal risk.
  • BLimited / transparency risk.
  • CHigh risk.
  • DProhibited (unacceptable risk).