The AI Act introduces a framework of rules that differentiates obligations according to the type and the use of an AI system. Some practices are prohibited, while other systems are subject to transparency obligations or, where they are classified as high risk, to stricter requirements on risk management, documentation and human oversight. How a system is classified depends not only on the technology it uses but also on the purpose for which, and the way in which, it is applied. The legal assessment therefore has to start from the system itself and from how it is actually used. An EU AI Act lawyer in Greece looks at what the system is, who develops or uses it, what the business's role as provider or deployer is, and what obligations follow from the applicable regulatory framework. Getting that assessment right at the outset can shape the design of the product, the compliance procedures and the way it is brought to market.
The absence of a specific rule for a new technology is not the absence of legal risk. A business developing robotics, autonomous systems or a new AI application is not outside the law because no specific regulation yet describes its technology exactly. Product liability law, consumer protection, product safety, contract law and, depending on the activity, more specific regulatory requirements all continue to apply. The legal assessment therefore cannot be limited to looking for a rule that names the particular technology.
Where technology moves faster than legislation, the legal assessment has to start from the principles that already apply — liability, safety, data protection, contract and the sector's own rules.
The complexity increases where an AI system processes personal data. The AI Act and the GDPR may then apply in parallel, with different requirements and a different subject matter. Compliance with one framework does not automatically mean compliance with the other. How the system operates, what data is used, the purpose of the processing and the risks created for individuals all have to be examined. The same applies to products and systems that combine artificial intelligence with other technologies. An autonomous vehicle, a robotic system or an AI application may raise questions of product liability, safety, data protection, intellectual property and contractual liability all at once. Assessing those questions before the product is released allows a business to identify the main risks and address them in its design. For businesses developing technology in a regulatory environment that is still evolving, legal advice has to connect to how the product actually works. We examine the system, its use, the data it processes and the markets it is to be placed on, in order to identify the applicable legal framework and the steps needed before launch.
Not optional
Risk classification is the first step
Every AI system placed on the EU market falls into one of the four AI Act risk tiers. The assessment has to be carried out before the system is placed on the market or put into use, so that the compliance requirements are built into its design in good time.
A common mistake
New technology, real legal risk
New technology does not operate in a legal vacuum. Even where there is no specific legislation for a particular AI or robotics application, the general rules on liability, consumer protection and contract continue to apply.
Dual framework
AI Act meets GDPR
Where an AI system processes personal data, the AI Act and the GDPR may apply in parallel. The two frameworks impose different requirements, and compliance with one does not automatically mean compliance with the other.