Compliance & Ethics

The Wild West Years of AI Are Over

In recent years, the development of artificial intelligence often felt like the Wild West. Companies experimented at lightning speed, pulled massive amounts of data from the internet to train models, and implemented black-box algorithms without giving deep thought to the consequences. With the explosive growth of the technology, social unrest also grew. Bias in algorithms led to discrimination in recruitment and selection or mortgage applications, and deepfakes undermined trust in news media. This unrestrained era is now coming to an end. Governments are intervening to protect citizens’ rights.

For European companies, the European ‘AI Act’ (AI Regulation) is the absolute game changer. This comprehensive legislation introduces a risk-based approach to the development and implementation of AI. For IT departments, this means that compliance, explainability, and AI Governance are no longer peripheral matters, but absolute top priorities when launching every new IT project.

Understanding the Risk Classifications of the AI Act

The European AI Act divides AI systems into four risk categories, each with its own obligations and sanctions. It is essential for software architects and corporate lawyers to determine exactly which category their applications fall into:

  • Unacceptable Risk (Prohibited): AI systems that pose a clear threat to the safety, livelihoods, and rights of people will be completely banned. Examples include ‘social scoring’ systems by governments (such as in China) or indiscriminate facial recognition in public spaces.
  • High Risk: This is the category that most companies will have to deal with. This includes AI systems in critical infrastructure, recruitment and selection (HR software), education, credit assessment, and the justice system. Companies that develop or deploy such systems must meet strict requirements: conduct thorough risk assessments, be able to prove the quality of the training data to prevent bias, maintain detailed logs, and ensure adequate human oversight.
  • Limited Risk (Transparency Obligation): Models such as chatbots (ChatGPT), deepfakes, and generative AI for images. The most important obligation here is transparency. Users must be informed at all times that they are communicating with a machine or that the content (image/audio) is artificially generated.
  • Minimal Risk: Systems such as AI in video games or spam filters fall outside the strict legislation. This includes the vast majority of AI systems currently used in the EU.

Explainable AI (XAI) and the End of the Black Box

One of the biggest technical challenges arising from legislation and the societal call for accountability is the ‘black box’ nature of advanced neural networks. A deep learning model can conclude with 99% certainty that a customer is not eligible for a loan, but often the data scientists themselves do not know *why* the model made that decision, because the logic is hidden in millions of parameters.

This creates the need for Explainable AI (XAI). This is a field within data science that focuses on developing techniques (such as LIME or SHAP) that make the decisions of complex models insightful and understandable to humans. For companies, this means that they sometimes have to consciously choose a slightly less sophisticated but fully transparent model (such as a decision tree or logistic regression) over a non-explainable deep learning network, simply to avoid legal claims and maintain customer trust.

Establishing an Internal AI Governance Structure

To comply with upcoming legislation and prevent ethical blunders, organizations must establish a robust AI Governance policy. This begins with inventorying all AI applications currently used within the company (often in shadow IT). Establish an AI ethics committee, consisting of IT professionals, legal experts, and domain experts, to review every new AI project before it goes into production.

Establish clear guidelines for employees regarding the use of public GenAI tools (such as the ban on entering customer data into ChatGPT) and invest in data quality. By integrating ethics and compliance ‘by design’ into your software development, you transform regulations from an obstacle into a hallmark of reliability and quality.

Discover useful guidelines and tools for entrepreneurs regarding responsible AI implementations via the informative pages of the Chamber of Commerce.

Green AI: The Battle Against the Carbon Footprint of Data Centers

Contents

Verified by MonsterInsights