EU have created the AI Act, the world's first AI law

EU has created the AI Act, the world's first AI law

The EU and countries all around the world recognise that the introduction and use of AI tools will introduce risks, many of which are ethical. Examples include infringements of privacy of personal data, while bias in AI systems can lead to discriminatory outcomes and increased inequities, such as those that already exist in gender pay gaps.

For example, clerical work is predominantly carried out by women, but AI is expected to take over such roles in the future, which could minimise the job market for women. Generative AI can also be used to mount cyber-attacks, to create “deep–fakes” of people or pretend scenarios (which we are already seeing all over the internet). AI can be used to send perfect phishing and scam call campaigns, and produce child abuse material. AI can contribute to the spread of misinformation or disinformation.

Due to these elevated risks, control is required when developing, deploying, distributing, providing, or using AI.

EU and UK announce legislation

The EU have created the AI Act, which is the worlds first AI law. The law aims to ensure safe use of AI and install trust. The Act is expected to come into force in 2026. Although there is no requirement for the UK to align with the EU, the UK has announced plans to introduce legislation in 2025.

The EU law, which the UK is likely to base their own legislation on, takes a risk-based approach and divides AI tools into risk categories:

  • Unacceptable risk
  • High risk
  • Transparency risk
  • Minimal risk

Risk assessment and control policies for AI

This tells us that risk assessment, control procedures and policies for AI are required, such as acceptable use policies. But most importantly, people need to be informed when AI is used to provide a service or make decisions about them. The use of AI should also be included within public and customer facing privacy notices to ensure transparency. This is already a requirement under the Data Protection Act, so all companies using AI should already be considering such updates.

Strident can help organisations conduct AI risk assessments, create acceptable use and privacy policies. For companies who are looking to achieve AI trust and assurance, ISO42001 can be implemented and certified with a UKAS accredited certification body. The certificate is recognised internationally and is a stamp of externally verified assurance, Strident can provide consultancy to ensure certification to the standard.

To find out more about how Strident can help your business become more secure and compliant, then please get in touch here.

Get the latest news from Strident

6 Steps for Sorted IT

ISO & Data Protection