THE EUROPEAN UNION’S ARTIFICIAL INTELLIGENCE LAW AND ARTIFICIAL INTELLIGENCE GOVERNANCE

1.     The Age of Artificial Intelligence and Regulation

“Artificial intelligence is the new electricity.” Andrew Ng’s apt observation sums up the fact that artificial intelligence is not merely a technological trend, but a revolutionary force that permeates every aspect of life, much like the invention of electricity. Today, no sector—from manufacturing to finance, from healthcare to human resources—can remain untouched by this transformation. Artificial intelligence systems are fundamentally altering not just the way companies operate, but their very corporate DNA, by analysing vast amounts of data in seconds, automating decision-making processes, and enhancing our ability to predict the future.

Whilst this change brings significant opportunities, it also raises serious risks regarding fundamental rights and freedoms, such as discrimination, lack of transparency and accountability. In particular, the impact of automated decision-making systems on individuals’ rights, the potential for systematic biases in data sets to produce outcomes detrimental to the AI user, and the ‘black box’ nature of AI systems have made regulatory intervention inevitable.

In this context, the European Union (“the Union”) has extended the risk-based and preventive regulatory approach it has long adopted in the field of digital technologies to the field of artificial intelligence, and the Artificial Intelligence Act (“AI Act”) has been adopted accordingly. The AI Act sets out rules governing the development and placing on the market of AI systems, whilst aiming to establish a safe, human-centred and rights-respecting AI ecosystem.

Under the AI Act:

  • AI systems have been classified according to their risk levels,
  • Certain AI applications have been completely banned,
  • Comprehensive technical, organisational and governance obligations have been introduced for “high-risk” systems,
  • Transparency obligations for individuals interacting with artificial intelligence have been established.

In this respect, the AI Act is not merely a technical regulation; it mandates corporate compliance and governance across a wide range of areas, from product development processes to human resources practices, and from customer interactions to data governance structures. In this study, the obligations introduced by the AI Act—particularly regarding high-risk artificial intelligence systems—will be examined from a GRC LEGAL perspective; the study will explore how companies should classify risks associated with these systems, define roles, and establish appropriate control mechanisms.

2.     Concepts and Actors

Although the AI Act contains numerous definitions, it is particularly important to clarify certain fundamental concepts to ensure that roles and obligations are properly understood. Indeed, these definitions are set out in Article 3 of the AI Act and encompass the key elements that determine the regulation’s structure and scope of application. In this context, the most critical definitions in practice are addressed below in simplified terms.

Artificial Intelligence System (“AI System”)

According to the AI Act, an artificial intelligence system is a machine-based system capable of operating at different levels of autonomy, capable of adapting to a certain extent after deployment, and which determines the form of output it produces based on the inputs it receives, in accordance with specific objectives, through ‘inference’. Within this definition, artificial intelligence systems produce outputs such as predictions, content generation or recommendations.

In practice, this definition means that, unlike traditional software, the system does not merely apply predefined rules but is capable of making inferences from data and possesses a certain degree of “learning” capacity.

Provider

Under the AI Act, a provider refers to a natural or legal person who develops an artificial intelligence system, or commissions its development and markets or makes it available for use under their own name or brand. This definition covers not only technical development activities but also the marketing of a system under one’s own brand; consequently, in certain circumstances, the relevant actor may be classified as a “provider” even if they have not directly carried out the development.

User (Deployer)

A deployer refers to a natural or legal person who uses an artificial intelligence system under their own authority. However, this use must not fall within the scope of personal (non-professional) activities. In this context, companies that integrate an artificial intelligence system into their business processes and use it in decision-making mechanisms are, as a rule, considered to be “deployers”. End-users who use the system personally in their daily lives, however, do not fall within this scope.

Importer

Importer: A natural or legal person established within the Union who places an artificial intelligence system, developed and made available on the market by a person or organisation established outside the Union, on the Union market.

Distributor

A distributor refers to a natural or legal person, other than a supplier or importer, who, by being part of the supply chain, makes an artificial intelligence system available on the Union market.

3.     Risk-Based Approach and Classification

The AI Act is founded on a risk-based approach, which provides for different obligations depending on the level of risk that artificial intelligence systems may pose. Under this approach, not all artificial intelligence systems are subject to the same level of regulation; rather, they are categorised into different groups based on their potential impact on individuals’ fundamental rights and freedoms and on security.

Within this framework, the AI Act classifies artificial intelligence systems into four main risk categories:

  • Unacceptable risk
  • High-risk
  • Limited risk
  • Minimal risk

Risk-based classification is the first and most critical step in determining obligations under the AI Act. This is because the category into which an AI system falls:

  • the scope of the obligations to be applied,
  • the level of liability the company will assume,
  • and the necessary technical and organisational measures.

Therefore, one of the first steps companies must take is to correctly identify the risk class of the AI systems they are using or developing.

 

3.1. Minimal Risk

For artificial intelligence systems falling within the minimal risk category, no binding obligations are envisaged under the AI Act, and the use of these systems is largely unrestricted. Systems in this category encompass artificial intelligence applications commonly encountered in everyday use that do not pose a significant risk to individuals.

3.2. Limited Risk

For AI systems falling under the limited risk category, the AI Act adopts a lighter regulatory approach, primarily imposing transparency obligations. In this context, it must be clearly indicated that users are interacting with an AI system. Currently, it is stated that the vast majority of AI systems within the European Union fall under the limited or minimal risk categories.[1]

3.3. High-Risk AI Systems

High-risk AI systems are those with the potential to have significant impacts on individuals’ safety or fundamental rights. For such systems, the AI Act envisages a comprehensive compliance regime, imposing numerous technical, organisational and managerial obligations, particularly on providers and users.

‘Providers’ who develop and place a high-risk AI system on the market under their own name are the actors subject to the most stringent obligations under this regulation. These obligations begin at the design stage of the system and continue throughout its entire lifecycle, encompassing development, testing, placing on the market, and post-market monitoring.[2]

In this context, providers must not merely ensure the technical functioning of the system; they must also establish a comprehensive compliance mechanism aimed at the prior identification, mitigation and monitoring of risks. In this regard, the existing obligations for high-risk artificial intelligence systems are scheduled to come into force on 2 August 2026.[3]

The criteria for determining which AI systems are classified as ‘high-risk’ under the AI Act are set out in Article 6 of the Act and Annex III. Within this framework, high-risk systems have been categorised based on specific sectors and areas of use. The main high-risk areas can be summarised as follows:

Area

Examples of High-Risk Applications

Biometric Identification

Remote biometric identification and biometric categorisation systems.

Critical Infrastructure

Management and operation of critical infrastructure such as road traffic, water, gas, electricity and heating.

Education and Vocational Training

Admission of students to educational institutions, assessment of examination results and analysis of learning outcomes.

Employment and HR

Decisions regarding CV screening, performance appraisal and the termination of employment relationships during recruitment processes.

Essential Public and Private Services

Credit score assessment (excluding fraud detection), eligibility checks for public benefits, and prioritisation of emergency calls.

Law Enforcement

Assessment of the reliability of evidence, crime scene analysis, use of lie detectors.

Immigration and Border Control

Assessment of visa applications, analysis of irregular migration risks, verification of travel documents.

Justice and Democracy

Systems assisting judicial authorities in decision-making processes, algorithms that could influence election results.

 

3.3.1. Obligations Regarding High-Risk Artificial Intelligence Systems

With regard to high-risk AI systems, the AI Act provides for a comprehensive compliance regime, particularly for providers. In this context, obligations cover the entire lifecycle of the system, from the design phase through to post-use monitoring. Within this framework, the main obligations regarding high-risk AI systems can be summarised as follows:[4]

  • Establishment of a risk management and quality system: A continuous framework must be established for the identification, assessment and mitigation of risks throughout the system.
  • Data governance and data quality: The quality, representativeness and absence of bias in the data sets used must be ensured.
  • Testing and validation processes: The system must be tested in accordance with defined criteria prior to being placed on the market.
  • Record-keeping and traceability: Records of system activities must be maintained to ensure auditability.
  • Transparency and user information: Clear information regarding the system’s operation, capacity and limitations must be provided to users.
  • Technical documentation and retention: Technical documents relating to the system must be prepared and retained for specified periods.
  • Conformity assessment and CE marking: The system must undergo a conformity assessment before being placed on the market, and the CE marking must be affixed to a visible part of the system.
  • Human supervision: Human intervention and control must be ensured during the use of the system.
  • Cybersecurity and accuracy: It must be ensured that systems are secure, robust and produce accurate results.
3.3.2. Obligations of Deployers

The obligations of actors classified as “deployers” under the AI Act focus on managing the risks arising during the use of systems and protecting individuals’ fundamental rights. In this context, the main obligations for deployers are summarised below:

·         AI Literacy:

Deployers are obliged to ensure that staff involved in the use of AI systems possess sufficient knowledge and awareness regarding the system’s operation, risks and limitations.

·         Transparency Obligations:

Users are obliged to provide the necessary information to relevant individuals in specific AI usage scenarios. In this context:

  • It must be clearly stated that interaction with artificial intelligence is taking place,
  • Content generated or manipulated by artificial intelligence (e.g. deepfakes) must be appropriately labelled,
  • Where emotion recognition or biometric categorisation systems are used, relevant individuals must be informed.

·         Compliance with and Oversight of Usage Instructions:

Where high-risk systems are used, users are obliged to ensure that the system is operated in accordance with the usage instructions specified by the provider. Furthermore, system outputs must be monitored and human intervention provided where necessary.

·         Monitoring of Data and System Performance:

Users must verify the suitability of the data sets used to ensure the system operates correctly and in accordance with its intended purpose, and must regularly monitor system performance.

·         Incident Reporting and Response:

Should it be determined that the system poses a risk to fundamental rights or has caused a serious error, users must suspend use of the system and report the situation to the provider and the relevant authorities.

·         Record Keeping:

In the context of the use of high-risk systems, records relating to system activities must be kept and retained for specified periods.

·         Fundamental Rights Impact Assessment:

In certain circumstances (particularly for public bodies or organisations providing public services), an assessment of the impact on fundamental rights must be carried out prior to the use of an AI system.

As can be seen, the obligations under the AI Act vary not only depending on whether the system is ‘high-risk’ but also according to the organisation’s role as a deployer or provider of the system. Therefore, it is of critical importance to carry out a role and scope determination in the following order:

1.    System inventory and use case identification: An inventory of all AI solutions used or developed within the organisation must be compiled; the purpose, area of use and affected groups of individuals must be clarified for each system.

2.    Risk classification: It must be determined which of the following categories the relevant system falls into: unacceptable risk, high risk, limited risk, or minimal risk. With regard to high risk, Article 6 and Annex III of the AI Act should be checked in particular.

3.    Role identification (Provider or Deployer?): Within the same system, an organisation may assume different roles in different scenarios. Therefore, each scenario must be modelled separately.

4.    Identification of the set of obligations and action plan: Once the role and risk class have been clarified, the technical, organisational and governance measures to be implemented for the relevant system (e.g. risk management, data governance, logging, transparency, human oversight, incident reporting, compliance assessment, etc.) should be translated into a system-specific “compliance checklist”; and the responsible units and timetable must be determined.

 

3.4. Unacceptable Risk

Artificial intelligence systems falling within the category of unacceptable risk are completely prohibited under the AI Act on the grounds that they pose a clear and serious threat to individuals’ fundamental rights and freedoms. Within this scope, the development, placing on the market or use of the artificial intelligence systems listed below is not permitted:[5]

Subliminal manipulation:

These are systems that could cause harm by influencing individuals’ behaviour without their awareness. For example, directing individuals towards a specific political preference without their knowledge or consent could fall within this scope.

Exploitation of vulnerabilities:

Systems that exploit individuals’ vulnerabilities arising from their age, economic status, or physical/psychological characteristics to steer them towards harmful behaviour. For example, AI-enabled toys that encourage children to engage in dangerous behaviour fall within this scope.

Biometric categorisation based on sensitive characteristics:

Systems designed to classify individuals based on sensitive characteristics such as gender, ethnic origin, political views, religious beliefs or sexual orientation.

General-purpose social scoring:

Systems that involve scoring individuals based on their social behaviour, personal characteristics or activities (such as shopping habits or social media interactions). Such systems can lead to the arbitrary restriction of individuals’ access to employment, credit or other opportunities.

Real-time remote biometric identification:

Biometric identification systems used in public spaces are generally prohibited. However, in limited circumstances—such as locating missing persons, preventing terrorist attacks, or identifying suspects of serious crimes—they may be used exceptionally with the approval of a judicial authority.

Emotion recognition systems:

Systems designed to detect individuals’ emotional states, particularly in workplaces and educational institutions, are prohibited. However, limited uses for security purposes (such as detecting a driver’s drowsiness) may be assessed as high-risk.

Predictive policing:

These are systems that assess an individual’s future risk of committing a crime based on their personal characteristics.

Scraping of facial images:

These are systems aimed at creating or expanding biometric databases by indiscriminately collecting facial images obtained from the internet or video surveillance systems.

4.     Artificial Intelligence Governance from a GRC LEGAL Perspective

The obligations introduced by the AI Act should not be viewed merely as technical and legal requirements; they also necessitate the establishment of a comprehensive governance structure for companies. In this context, AI governance aims to define roles and responsibilities during the development and use of AI systems, to strengthen the human factor, and to manage risks effectively.

4.1. Identification of Roles and Responsibilities

In order for the obligations introduced under the AI Act to be properly implemented, it is first necessary to correctly identify the relevant actor’s position in relation to the system. At this point, the distinction between the ‘provider’ and the ‘deployer’ is decisive.

Providers, as actors who develop the artificial intelligence system or place it on the market under their own name, are responsible for the entire lifecycle of the system, starting from its design. In contrast, deployers are actors who use the system within their own business processes; their obligations are primarily focused on managing risks during the system’s usage phase.

However, this distinction of roles under the AI Act does not directly determine the status of “data controller” or “data processor” under data protection legislation. Indeed, under the General Data Protection Regulation (“GDPR”), a data controller is defined as a natural or legal person who determines the purposes and means of the processing of personal data (GDPR, Art. 4(7)), whilst a data processor is considered to be a person who processes data on the instructions of the data controller (GDPR, Art. 4(8)).

In this context, an actor acting as a provider in an artificial intelligence system may be regarded as both a data controller and a data processor, depending on the specific circumstances. For example, if the provider processes personal data for the purpose of developing or improving its own model, the status of data controller may arise; conversely, where the provider processes data solely in accordance with the customer’s instructions, it may be regarded as a data processor. Similarly, users who integrate an AI system into their own business processes are generally regarded as data controllers, as they determine the purposes and means of the data processing activities.[6]

 

For this reason, it is of critical importance for companies to conduct a separate role analysis for each specific AI use case, in order to correctly identify both the obligations under the AI Act and those under the GDPR.

 

4.2. AI Literacy

The AI Act mandates that individuals interacting with AI systems must possess sufficient knowledge and awareness to ensure these systems are used safely and effectively. In this context, companies must conduct regular training and awareness-raising activities for employees using AI systems to foster an understanding of the system’s operational logic, capabilities, limitations and potential risks.

Accordingly, it is crucial that not only technical teams but all departments that come into contact with AI systems (such as human resources, marketing, and operations teams) are informed about the risks and responsibilities these systems may entail.

AI literacy is regarded not merely as an educational obligation, but also as a critical governance tool for the effective operation of the human oversight mechanism—one of the obligations mentioned above—and for fostering an AI culture across the organisation.

4.3. Integration of DPIA and FRIA Processes

The use of artificial intelligence systems is not merely a technical matter; it creates a multi-layered risk area that directly impacts the processing of personal data and the fundamental rights of individuals. Consequently, there is a direct link between the Fundamental Rights Impact Assessment (“FRIA”) regulated under the AI Act and the Data Protection Impact Assessment (“DPIA”) envisaged under the GDPR.

Under the AI Act, the FRIA is mandatory for certain users, particularly in the use of high-risk artificial intelligence systems (AI Act, Art. 27). However, this obligation does not apply to all users; it is limited to public authorities, private organisations providing public services, and specific high-impact use cases.

Whilst the DPIA focuses on risks arising from personal data processing activities (GDPR, Art. 35), the FRIA assesses the impacts on fundamental rights from a broader perspective. In this respect, the two mechanisms are complementary.

Within this framework, the FRIA obligation does not require a separate and independent assessment to be carried out in every instance. Indeed, where DPIA processes carried out under the GDPR already cover a significant portion of the risks that artificial intelligence systems may pose, the FRIA assessment can be built upon this existing framework. Consequently, the key for companies is not to create duplicate processes, but to adopt a holistic assessment approach by expanding existing DPIA mechanisms to include the dimension of fundamental rights.

 

5.     Expected Changes to the AI Act Under the Digital Omnibus Package

The “AI Digital Omnibus” proposal, which has been put forward to the European Union with the aim of enhancing the enforceability of the AI Act and reducing administrative burdens, seeks to simplify existing obligations to a certain extent. However, Joint Opinion No. 1/2026, published by the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS), indicates that certain aspects of this simplification approach may pose risks in terms of the protection of fundamental rights and legal certainty.[7]

In particular, under the proposal, the legal basis for processing special categories of personal data for the purposes of bias detection and mitigation is being extended; this is being extended to a broader artificial intelligence ecosystem, not limited solely to high-risk systems. Although this approach could technically support the fair operation of systems, the EDPB and EDPS emphasise that, unless the boundaries of this exception are clearly defined, it could be open to abuse.

Furthermore, proposals to ease record-keeping and documentation obligations for high-risk systems risk weakening the level of accountability for providers ; in particular, they raise the possibility of the ‘not high-risk’ assessment being misused. Similarly, the extension of certain privileges granted to SMEs to broader groups of companies is viewed as a factor that could undermine the risk-proportionate regulatory approach.

Furthermore, the proposal suggests that the obligation regarding AI literacy should be removed from the direct responsibility of companies and transformed into an incentive-based framework. However, this approach is also criticised on the grounds that it could carry the risk of weakening internal organisational awareness and human oversight mechanisms.

Proposals to delay the timeline are similarly noteworthy. Whilst postponing the effective date of obligations regarding high-risk systems may provide short-term compliance relief for companies, it could lead to a temporary reduction in the level of protection of fundamental rights due to ‘legacy systems’ that may fall outside the scope of the regulation.

In this context, the AI Digital Omnibus proposal highlights the need to strike a delicate balance between simplifying regulation and safeguarding fundamental rights. For companies, however, this process signifies not an area where action should be taken on the expectation that obligations will be eased, but rather a dynamic regulatory environment where existing governance and compliance mechanisms must be strengthened and made adaptable to changes.

 

CONCLUSION

The European Union’s AI Act removes obligations relating to artificial intelligence from being merely a technical compliance issue, placing them directly at the heart of corporate governance. Within this framework, the management of risks associated with AI systems is no longer solely the responsibility of IT or legal departments, but has become a holistic governance issue that must be embraced across the entire organisation.

The risk-based approach introduced by the AI Act moves companies away from a passive compliance mindset, compelling them to proactively classify the technologies they use and develop, clarify roles and responsibilities, and establish appropriate control mechanisms. This transformation is not merely a regulatory requirement; it also presents a strategic opportunity for companies to develop trustworthy, transparent and sustainable artificial intelligence systems.

At this point, the real issue is not merely ‘complying with the AI Act’; it is about integrating artificial intelligence as a natural part of corporate risk management, data governance and decision-making processes. Indeed, this transformation must be addressed in conjunction with compliance processes conducted under data protection legislation (particularly the GDPR/KVKK); existing mechanisms such as the DPIA should be expanded to cover AI risks, thereby establishing an integrated compliance and governance framework. For in the near future, competitive advantage will be shaped not merely among companies that use artificial intelligence, but among those that can embed artificial intelligence within a responsible, auditable and governance framework.

On the other hand, the AI Digital Omnibus proposal has brought to the fore the simplification of obligations to a certain extent and the restructuring of implementation processes; however, it has been emphasised that this process must be managed with care, particularly regarding the protection of fundamental rights and legal certainty. This situation demonstrates that AI regulation is not a static but a dynamic field; for companies, compliance must therefore be approached not as a one-off project, but as a continuously updated governance capability.

Consequently, the step companies must take goes beyond merely following legislation; it involves positioning artificial intelligence not as a ‘compliance burden’ but as a tool that strengthens corporate governance. This approach will not only reduce regulatory risks but will also enable organisations to establish a more reliable, accountable and sustainable structure within their digital transformation processes.

[1] European Commission, AI Act

[2] https://artificialintelligenceact.eu/high-level-summary/

[3] Guide to the EU AI Act for businesses outside the EU

[4] EU AI Act: 10 Things High-Risk Companies Need to Know

[5] EU AI Act: How Risk is Classified

[6] Cranium, AI Act and GDPR: How These Regulations Work Together to Safeguard AI and Privacy

[7] Matheson, EDPB-EDPS publishes opinion on the AI Digital Omnibus proposal