At its core, the AI Act proposes a three-tier model of risk classification in order to consider and remediate the impact of AI systems on fundamental rights and user safety:
- Unacceptable risk: Systems with an unacceptable risk rating that are prohibited by the European Commission.
- High risk: Systems with a high-risk rating that must comply with multiple requirements and undergo a conformity assessment.
- Lower risk: Certain AI systems which do not meet the specified criteria for the other two tiers and still present limited risk are recommended to apply the same practices as high-risk AI systems and are subject to transparency obligations.
In a first step, companies should generally identify all AI applications used and rate the respective risks. Depending on the risk classification the AI system is subject to differing regulatory requirements. As the first class (unacceptable risk) is prohibited, and the last (lower risk) only needs to meet light-touch requirements, an AI framework needs to be geared towards the high-risk AI systems that are in use or planned for the future.
EY developed the AI Act Maturity Assessment to:
- Help organizations navigate through the regulation’s requirements
- Assess the use of AI systems and the extent to which the regulation applies
- Support organizations in understanding where they stand regarding the regulation’s requirements and determine to what extent organizations are ready to comply with the regulation
- Assess organizational maturity and determine areas of prioritized focus
- Perform a deep dive on specific AI systems in view of the legal requirements set by the AI Act
As it is often more costly and complex to ensure compliance when AI systems are operating than during the design and implementation phase, we recommend that firms start preparing early. This includes setting up a register for all AI applications used in the organization, risk rating them and putting in place adequate:
- AI governance, policies and design standards
- Resource management
- Risk and control framework
- Data management
- Secure architecture