William Fry AI Guide: Navigating AI Law
William Fry AI Guide: Navigating AI Law
AI Guide
Insights and Guidance on
the AI Act and other AI
Legal Issues
Introduction to the
William Fry AI Guide
William Fry was founded in 1847 and has always been at the
cutting edge of technology, advising clients on various
technological developments as they arose, and now, artificial
intelligence (AI).
We hope that you enjoy reading this Guide, and that you find it
helpful in addressing the legal issues raised by AI.
THE WILLIAM FRY AI GUIDE
Who Should
This guide is intended for a diverse audience:
Table of
Contents
3. High-Risk AI Systems 14
5. AI Literacy Requirements 26
6. Regulatory Sandboxes 29
9. Extraterritorial Reach 44
3. AI and Cybersecurity 56
4. AI and Contracts 59
1. Prohibited Practices
The AI Act addresses several key areas, starting with the prohibition of certain AI practices due to
their potential to cause significant harm or violate fundamental rights.
The Act bans manipulative or deceptive AI systems that use subliminal techniques to distort
human behaviour and impair decision-making. This prohibition targets AI systems that employ
imperceptible audio or visual stimuli to influence consumer choices unknowingly.
AI systems that exploit vulnerabilities based on age, disability, or socio-economic status are
also prohibited. This includes systems targeting children, elderly individuals, or economically
disadvantaged groups.
Social scoring is another prohibited practice under the AI Act. AI systems that evaluate or classify
individuals based on their social behaviour or personal characteristics, leading to unjustified or
disproportionate treatment, are banned. Such systems can result in discrimination and exclusion,
violating fundamental rights.
The AI Act also prohibits predictive policing systems used solely for predicting criminal offences
based on profiling or assessing personality traits. This prohibition ensures that AI systems do not
unjustly target individuals based on profiling without human assessment of their involvement in an
activity based on objective and verifiable facts.
Untargeted facial recognition databases are restricted under the Act. AI systems that create or
expand facial recognition databases through untargeted scraping of images from the internet or
CCTV footage are prohibited to protect privacy and prevent misuse of biometric data.
|6
Emotion recognition in workplaces and educational institutions is banned unless used for medical
or safety reasons. This regulation prevents the potential misuse of AI systems to infer emotions in
sensitive environments, where power imbalances could lead to exploitation.
AI systems that categorise individuals based on biometric data to infer sensitive characteristics
such as race, political opinions, or sexual orientation are prohibited to avoid discrimination and
privacy violations.
Real-time remote biometric identification systems are heavily restricted for law enforcement
purposes, with strict conditions and safeguards to prevent misuse and protect individual rights.
2. High-Risk AI Systems
In addition to prohibitions, the AI Act classifies certain AI systems as high-risk, subjecting them
to stringent regulatory requirements. High-risk AI systems include certain of those used in
critical infrastructure, education, employment, essential services, law enforcement, migration,
and the administration of justice. Use of these systems requires providers to maintain technical
documentation, implement a quality management system, ensure data governance, and conduct
conformity assessments. Deployers must ensure proper use, monitor performance, maintain
records, and comply with data protection laws.
The AI Act also regulates general-purpose AI models and systems. These models are defined by their
ability to perform various tasks across different applications. If these models possess high-impact
capabilities, they are classified as having systemic risk. Providers of general-purpose AI models
must ensure compliance with documentation, data protection, and transparency obligations.
Deployers are responsible for ensuring proper use and reporting any substantial modifications that
might change the AI system’s risk classification.
4. AI Literacy
AI literacy is another focus of the AI Act. AI literacy involves the skills and knowledge needed
to make informed decisions regarding AI systems. Organisations must ensure their staff possess
adequate AI literacy, supported by initiatives from the European AI Board. Measures to promote
AI literacy include developing training programmes and collaborating with industry groups and
regulatory bodies.
5. Regulatory Sandboxes
Regulatory sandboxes are established to allow providers to test innovative AI systems in real-world
conditions. These frameworks, governed by a sandbox plan, are designed to foster innovation
while ensuring regulatory compliance. Competent authorities provide guidance, supervision, and
support, aiming to mitigate risks and enhance legal certainty. Small and medium-sized enterprises
(SMEs) and start-ups receive priority access and tailored support services within these sandboxes.
|7
THE WILLIAM FRY AI GUIDE
B. Key Dates
• 12 July 2024: The AI Act published in the Official Journal.
• 2 August 2025: Rules on General-Purpose AI Models and Systems come into effect.
• 2 August 2026: Rules on Annex III High-Risk AI systems and establishment of regulatory
sandboxes come into effect.
• For high-risk AI, non-compliance with specific obligations related to operators or notified
bodies can result in administrative fines of up to €15 million or, if the offender is an undertaking,
up to 3% of its total worldwide annual turnover for the preceding financial year, whichever is
higher. This includes obligations of providers (Article 16), authorised representatives (Article
22), importers (Article 23), distributors (Article 24), deployers (Article 26), and requirements
and obligations of notified bodies (Article 31, Article 33(1), (3) and (4), or Article 34), as well
as transparency obligations for providers and deployers (Article 50).
• For SMEs, including start-ups, each fine is capped at the lower of the specified percentages
or amounts.
|8
D. Steps to Compliance
The basic framework suggested for compliance is set out below however different categories of AI
systems will attract different compliance obligations, which are set out in the following sections.
1. Conduct an AI Inventory
2. Assess AI Systems
Review AI systems to determine if they fall under prohibited or high-risk categories. Focus on
customer interaction, marketing, decision-making, and sensitive data processing systems.
Discontinue or modify non-compliant AI systems. Establish policies for ongoing monitoring and
assessment.
|9
THE WILLIAM FRY AI GUIDE
2. Prohibited AI Systems
Compliance
• Examples include AI systems that employ imperceptible audio or visual stimuli to influence
consumer choices unknowingly.
2. Exploitation of Vulnerabilities:
• AI systems that exploit vulnerabilities due to age, disability, or specific social or economic
situations to cause significant harm.
| 10
3. Social Scoring:
• AI systems that evaluate or classify individuals based on their social behaviour or personal
characteristics, leading to unjustified or disproportionate treatment.
• Social scoring by public or private entities can result in discrimination and exclusion,
violating fundamental rights.
• AI systems used solely for predicting criminal offences based on profiling or assessing
personality traits.
• This prohibition does not apply to AI systems that support human assessments based on
objective and verifiable facts.
• AI systems that create or expand facial recognition databases through untargeted scraping
of images from the internet or CCTV footage.
• AI systems designed to infer emotions in workplaces and educational settings, unless used
for medical or safety reasons.
7. Biometric Categorisation:
• AI systems that categorise individuals based on biometric data to infer sensitive characteristics
such as race, political opinions, or sexual orientation.
• While this is not a primary focus for most businesses, it is important to note that real-time
remote biometric identification systems are heavily restricted for law enforcement purposes,
with strict conditions and safeguards.
Key Dates:
• 12 July 2024: The AI Act published in the Official Journal.
| 11
THE WILLIAM FRY AI GUIDE
C. Steps to Compliance:
1. Conduct an AI Inventory:
• Begin by creating a comprehensive inventory of all AI systems currently in use within the
business.
• Categorise these systems based on their purpose, functionality, and the data they process.
• Review each AI system to determine if it falls under any of the prohibited categories outlined
in Article 5.
• Pay particular attention to systems designed for customer interaction, marketing, decision-
making, and those processing sensitive data.
• If any AI systems are identified as potentially prohibited, develop a plan to either discontinue
their use or modify them to ensure compliance.
• Establish internal policies and procedures for ongoing monitoring and assessment of AI
systems to prevent non-compliance.
• Provide specific training on identifying and mitigating risks associated with prohibited AI
practices.
| 12
Conclusion In conclusion, navigating compliance with the AI Act’s
regulations on Prohibited AI systems is crucial for businesses
operating within (and sometimes, outside) the EU. With
significant penalties for non-compliance, including hefty fines
and market restrictions, companies must proactively assess and
modify their AI systems to adhere to legal requirements. This
involves conducting thorough audits, implementing compliance
measures, training staff, and maintaining comprehensive
documentation. By taking these steps, businesses can ensure
ethical AI use while safeguarding fundamental rights, thereby
aligning with both regulatory expectations and societal values.
| 13
THE WILLIAM FRY AI GUIDE
3. High-Risk AI Systems
Articles 16, 22, 23, 24, 26, 31, 33(1, 3, 4), 34, 50 – Obligations
on parties
The AI Act classifies high-risk AI systems based on their use and potential impact on safety and
fundamental rights.
| 14
2. Annex III High-Risk AI:
• AI systems listed in Annex III are considered high-risk. This annex includes AI systems used
in:
• Biometrics:
› AI systems used as polygraphs or risk assessment tools for entry into Member States.
› AI systems evaluating applications for asylum, visas, or residence permits.
› AI systems detecting or identifying individuals in migration contexts.
• Administration of Justice and Democratic Processes:
› AI systems assisting judicial authorities in researching and interpreting facts and the law.
› AI systems influencing election outcomes or voting behaviour.
| 15
THE WILLIAM FRY AI GUIDE
3. Exceptions:
4. Provider Responsibilities:
| 16
• Automatic Logging:
› Ensure high-risk AI systems have the capability to automatically record events (logs)
throughout their lifecycle for traceability and monitoring purposes.
• Conformity Assessment:
› Ensure that the AI system undergoes the appropriate conformity assessment procedure
before being placed on the market or put into service.
• EU Declaration of Conformity and CE Marking:
› Draw up an EU declaration of conformity and affix the CE marking to the AI system or its
packaging to indicate compliance with the AI Act.
• Registration Obligations:
› Comply with registration obligations, including registering the high-risk AI system in the
EU database if required.
• Corrective Actions and Duty of Information:
› Ensure the AI system meets accessibility requirements in line with relevant EU directives.
5. Deployer Responsibilities
The following requirements apply to deployers (users, other than use in the course of a personal,
non-professional activity) of AI systems under the AI Act:
› Use high-risk AI systems in accordance with the provided instructions for use.
› Assign competent personnel for oversight and ensure that they are adequately trained.
• Data Management:
› Ensure that input data is relevant and representative for the AI system’s intended purpose.
• Monitor Operation:
› Maintain logs generated by the AI system for a period appropriate to its purpose, typically
at least six months.
| 17
THE WILLIAM FRY AI GUIDE
› Use information provided under the AI Act to comply with data protection impact
assessments as required by GDPR.
• Annual Reporting:
› Submit annual reports on the use of certain high-risk AI systems, such as post-remote
biometric identification systems, to relevant authorities.
Key Dates:
• For SMEs, including start-ups, each fine is capped at the lower of the specified percentages
or amounts.
| 18
C. Steps to Compliance
Depending on whether the business is a provider or deployer of a high-risk AI system, the following
compliance steps should be implemented (as applicable).
• Identify Applicability:
› Assess if the AI system falls within high-risk categories specified in Annex III.
› Verify if the AI system is a safety component requiring third-party conformity assessments
(Annex 1).
• Document Assessment:
› Develop and implement a risk management system that includes continuous risk
identification, analysis, and mitigation.
› Regularly review and update risk management measures.
• Integrate Human Oversight:
› Ensure that the AI system includes mechanisms for effective human oversight and
intervention.
› Employ relevant, representative, and bias-free datasets for training, validation, and
testing.
› Implement data governance practices to maintain dataset quality.
• Address Data Bias:
› Detect, prevent, and mitigate biases in datasets to avoid discrimination and ensure
fairness.
› SMEs can use simplified technical documentation forms provided by the Commission.
| 19
THE WILLIAM FRY AI GUIDE
| 20
9. Monitor Post-Market Performance
› Implement systems to monitor the AI system’s performance and compliance after it has
been placed on the market.
• Report Serious Incidents:
› Inform competent authorities and relevant parties about any serious incidents or non-
compliance issues.
› Regularly review and update risk management, data governance, and documentation
practices to ensure ongoing compliance.
• Cooperate with Authorities:
| 21
THE WILLIAM FRY AI GUIDE
Article 3 – Definitions
Key AI Act
Articles: Article 51 – GPAI Models with systemic risk
Article 88 – Enforcement
• Their importance lies in their versatility and widespread applicability, which necessitates
robust regulatory oversight to manage risks and ensure ethical deployment.
| 22
2. Classification of General-Purpose AI Models with Systemic Risk:
• Providers, deployers, and other third parties can be considered providers of high-risk
AI systems if they substantially modify a general-purpose AI system’s intended purpose,
leading to it becoming a high-risk AI system (Article 25).
• Draw up and maintain technical documentation of the model’s training and evaluation
(Article 53).
• Put in place a policy to comply with EU copyright law, ensuring all content used for training
respects reserved rights (Article 53(c)).
• Publish a summary of the content used for training the model (Article 53(d)).
• Mitigate systemic risks and ensure cybersecurity protections are in place (Article 55).
• Technical solutions for these markings should be effective, interoperable, robust, and
reliable, considering technical feasibility and costs.
| 23
THE WILLIAM FRY AI GUIDE
7. Deployer Obligations
• Deployers, defined as entities using an AI system under their authority (Article 3(4)), must
ensure that the AI systems they use comply with the AI Act’s requirements.
• Deployers must collaborate with providers to maintain compliance and report any substantial
modifications that might change the AI system’s risk classification.
Key Dates:
• 2 August 2025: Rules on General Purpose AI Models and Systems come into effect.
• The AI Office and national authorities will monitor compliance, with the AI Office having
exclusive powers to enforce obligations related to general-purpose AI models (Article 88).
• This happens if the provider is found to have intentionally or negligently violated the
provisions of the AI Act, failed to comply with a request for documents or information under
Article 91, provided incorrect, incomplete, or misleading information, ignored a measure
requested under Article 93, or did not provide the European Commission with access to the
general-purpose AI model or a model with systemic risk for evaluation under Article 92.
| 24
C. Steps to Compliance
1. Conduct an AI Inventory:
• Begin by creating a comprehensive inventory of all AI systems currently in use within the
organisation.
• Categorise these systems based on their purpose, functionality, and the data they process.
• Establish internal policies and procedures for ongoing monitoring and assessment of AI
systems to prevent non-compliance.
• Educate employees, especially those involved in AI development and deployment, about the
new regulations and the importance of compliance.
• Provide specific training on identifying and mitigating risks associated with general-
purpose AI models or systems.
| 25
THE WILLIAM FRY AI GUIDE
5. AI Literacy Requirements
• AI literacy is defined as the skills, knowledge, and understanding that enable providers,
deployers, and affected persons to make informed decisions regarding AI systems. This
includes awareness of opportunities, risks, and potential harms associated with AI.
• AI literacy is crucial for the ethical deployment of AI, ensuring that all stakeholders understand
the implications of AI use and can manage associated risks effectively.
• Organisations must ensure their staff and other individuals involved in AI operations possess
adequate AI literacy. This includes understanding the technical aspects of AI systems, proper
application during development and deployment, and interpreting AI outputs correctly.
| 26
3. Supporting Structures:
• European Artificial Intelligence Board (AI Board): The AI Board will support the European
Commission in promoting AI literacy, public awareness, and understanding of AI systems’
benefits, risks, safeguards, and related rights and obligations.
• Voluntary Codes of Conduct: The European Commission and Member States will facilitate
the creation of voluntary codes of conduct to enhance AI literacy among developers,
operators, and users of AI systems.
Key Dates:
• 12 July 2024: The EU will publish the AI Act in the Official Journal.
C. Steps to Compliance:
• Design training programmes tailored to different roles within the organisation and to
knowledge gaps identified. These should cover technical aspects of AI, ethical considerations,
risk management, and compliance requirements.
| 27
THE WILLIAM FRY AI GUIDE
• Develop policies that mandate regular AI literacy training for all relevant staff. Include these
policies in the organisational compliance framework.
• Set up procedures for monitoring and assessing the effectiveness of AI literacy initiatives.
• Engage with industry groups, regulatory bodies, and educational institutions to stay informed
about best practices and new developments in AI literacy.
Conclusion Ensuring AI literacy is not just about avoiding penalties but also
about fostering trust and promoting ethical AI practices. By
taking proactive steps to assess, educate, and monitor AI literacy,
businesses can navigate these regulations effectively and
maintain a competitive edge in a rapidly evolving technological
landscape, while ensuring high levels of AI literacy within their
organisation.
| 28
6. Regulatory Sandboxes
Within the AI Act, regulatory sandboxes are defined as frameworks established by competent
authorities. These frameworks allow providers or prospective providers to test innovative AI systems
in real-world conditions for a limited period. The operation of these sandboxes is governed by a
“sandbox plan”, which details the objectives, conditions, timeframe, methodology, and requirements
for the activities conducted within the sandbox. This plan is a mutually agreed document between
the AI provider and the competent authority, ensuring clear guidelines and expectations for the
testing phase. The establishment of AI regulatory sandboxes aims to improve legal certainty,
support the sharing of best practices, foster innovation, facilitate regulatory learning, and enhance
market access for SMEs and start-ups.
| 29
THE WILLIAM FRY AI GUIDE
ESTABLISHMENT
| 30
ROLE OF AI OFFICE
The AI Office is responsible for maintaining a public list of sandboxes to encourage interaction
and cooperation. National authorities must submit annual reports on the progress, incidents, best
practices, and outcomes of their sandboxes to the AI Office and Board. These reports help inform
regulatory practices and may lead to adjustments in the regulatory framework.
ROLE OF COMMISSION
The Commission will develop detailed arrangements for the establishment and operation of
sandboxes through implementing acts. These acts will specify eligibility and selection criteria,
procedures for application and participation, and terms and conditions for participants. Sandboxes
must ensure fair and transparent access, particularly for SMEs and start-ups, and facilitate the
involvement of various stakeholders in the AI ecosystem.
PERSONAL DATA
When personal data processing is involved, data protection authorities must be included in the
sandbox operation. Personal data collected for other purposes may be processed within sandboxes
under specific conditions, primarily when developing AI systems for substantial public interest.
This processing must comply with data protection laws, and data should be handled in a separate,
protected environment with appropriate safeguards.
Providers can also test high-risk AI systems in real-world conditions outside sandboxes, provided
they meet specific conditions and obtain necessary approvals. This testing must ensure informed
consent from participants, and providers must implement measures to protect participants’ rights
and safety.
The AI Act prioritises support for SMEs and start-ups by ensuring they have priority access to
sandboxes and tailored support services. Member States are encouraged to establish communication
channels and provide guidance to SMEs throughout their development. The Commission will
support these efforts by providing standardised templates and maintaining an information platform
for stakeholders.
Key Dates:
• 12 July 2024: The AI Act published in the Official Journal.
• 2 August 2026: Member States’ competent authorities will need to have established at least
one AI regulatory sandbox at national level.
• Annual Reporting: Member States must submit annual reports to the AI Office and the Board
starting one year after the establishment of the sandboxes.
| 31
THE WILLIAM FRY AI GUIDE
• Article 57(12) specifies that providers participating in sandboxes remain liable for any damage
caused to third parties. However, if they adhere to the sandbox plan and act in good faith
following the guidance of the competent authorities, they are shielded from administrative
fines under the AI Act.
C. Steps to Compliance:
1. Understand the AI Act: Familiarise yourself with the AI Act’s requirements and the specific
obligations for the business’s AI system based on its risk classification.
3. Follow Guidelines: Adhere to the guidance and supervision provided by competent authorities.
This includes implementing risk mitigation measures and maintaining detailed records of testing
and validation activities.
5. Exit and Conformity Assessment: Upon successful completion of sandbox activities, utilise the
exit report and written proof provided by competent authorities to streamline the conformity
assessment process for market entry.
| 32
7. Biometric Categorisation
Systems
Article 3 – Definitions
Key AI Act
Articles: Article 5 – Prohibited AI practices
Article 16, 22, 23, 24, 26, 31, 33(1, 3, 4), 34, 50 – Obligations
on parties
| 33
THE WILLIAM FRY AI GUIDE
PROHIBITED APPLICATIONS
HIGH-RISK APPLICATIONS
| 34
PROHIBITED OR HIGH-RISK?
The key difference lies in the nature and sensitivity of the categorisation. Prohibited systems deduce
or infer sensitive attributes from biometric data, while high-risk systems involve categorising
biometric data in ways that could indirectly affect individuals’ rights and outcomes.
The difference seems to be that biometric categorisation will be considered high-risk if sensitive
attributes are readily apparent, but it will be prohibited if such attributes are inferred or deduced
from other data.
Prohibited systems are outright banned due to their inherent risk of severe misuse and discrimination.
In contrast, high-risk systems are regulated to ensure that they are used responsibly and with
necessary safeguards to protect individual rights.
This distinction can lead to confusion, particularly where the line between sensitive inferences
and lawful categorisations is blurred. For instance, while a system categorising images by hair
or eye colour for law enforcement purposes might be high-risk and regulated, a system inferring
someone’s political beliefs from facial recognition data is prohibited. Navigating these nuances
requires careful legal interpretation and compliance with both the AI Act and relevant national laws,
ensuring that biometric technologies are deployed ethically and legally.
Furthermore, the overlap between national laws and the AI Act’s provisions adds another layer of
complexity. For example, Ireland’s specific opt-outs under Recital 40 indicate that certain uses of
biometric categorisation in law enforcement may be permissible under national law, despite the
broader EU prohibition. This necessitates a detailed understanding of both Union and Member
State regulations to navigate compliance effectively.
The regulatory framework’s reliance on the context and purpose of biometric categorisation
systems means that stakeholders must be vigilant in distinguishing between acceptable high-
risk applications and outright prohibited practices. This vigilance is crucial to avoid unintentional
breaches of the AI Act, given the severe implications of using these technologies improperly.
Key Dates:
• 12 July 2024: The AI Act published in the Official Journal.
• 2 August 2026: Rules on Annex III Biometric Categorisation Systems come into effect.
| 35
THE WILLIAM FRY AI GUIDE
• Non-compliance with the rules on Prohibited AI Systems will attract substantial administrative
fines of up to €35 million or, if an undertaking, 7% of the offender’s total worldwide annual
turnover, whichever is higher. Non-compliant AI systems can also be taken off the EU market.
• The AI Act imposes significant fines for non-compliance with its provisions, especially
for high-risk AI systems. Non-compliance with specific obligations related to operators or
notified bodies can result in administrative fines of up to €15 million or, if the offender is
an undertaking, up to 3% of its total worldwide annual turnover for the preceding financial
year, whichever is higher. This includes obligations of providers (Article 16), authorised
representatives (Article 22), importers (Article 23), distributors (Article 24), deployers (Article
26), and requirements and obligations of notified bodies (Article 31, Article 33(1), (3) and (4),
or Article 34), as well as transparency obligations for providers and deployers (Article 50).
• For SMEs, including start-ups, each fine is capped at the lower of the specified percentages
or amounts.
C. Steps to Compliance:
› Identify if the business’s system falls under high-risk categories as defined in Annex III.
› Understand the regulatory requirements for high-risk systems.
| 36
3. Implement Necessary Safeguards for High-Risk Systems
› Ensure all data processing complies with GDPR and relevant EU regulations.
› Implement robust data protection measures.
• Transparency and Notification:
• Risk Analysis:
• Maintain Records:
› Keep detailed records of compliance measures, risk assessments, and mitigation plans.
› Document the decision-making process and any consultations with legal or technical
experts.
• Continuous Monitoring:
› Conduct independent audits to ensure compliance with the AI Act and related regulations.
• Employee Training:
| 37
THE WILLIAM FRY AI GUIDE
| 38
8. Emotion Recognition Systems
Article 3 - Definitions
Key AI Act
Articles: Article 5 – Prohibited AI practices
Article 16, 22, 23, 24, 26, 31, 33, 34, 50 – Obligations on parties
| 39
THE WILLIAM FRY AI GUIDE
The EU AI Act takes a cautious approach towards the deployment of emotion recognition systems
in sensitive environments. Article 5(1)(f) outright prohibits the use of these systems in workplaces
and educational institutions, unless they serve a medical or safety purpose. This prohibition stems
from concerns articulated in Recital 44, which highlights the significant scientific uncertainties and
potential discriminatory outcomes associated with these technologies. The variability in emotional
expressions across different cultures and individuals can lead to unreliable and biased results, thus
justifying their restricted use in contexts where power imbalances are pronounced.
Moreover, Annex III of the AI Act categorises emotion recognition systems as high-risk AI systems,
subject to stringent regulatory requirements. This classification is rooted in Recital 54, which
underscores the potential for biased and discriminatory outcomes, particularly when these systems
are used for critical applications involving biometric data.
Transparency is a cornerstone of the AI Act’s regulatory framework. Article 50(3) mandates that
deployers of emotion recognition systems must inform individuals exposed to these technologies
about their operation. This requirement ensures that individuals are aware of when their biometric
data is being processed to infer emotions. This transparency obligation is complemented by the
GDPR, which governs the processing of personal data, including biometric data, under Regulations
(EU) 2016/679 and (EU) 2018/1725.
The GDPR, particularly through its stipulations on special categories of personal data under Article
9(1), reinforces the stringent protections around biometric data. Any processing of such data must
comply with the GDPR’s requirements, ensuring that the rights and freedoms of individuals are
safeguarded. Recital 132 of the AI Act reiterates that transparency obligations must be fulfilled in a
manner accessible to all, especially considering the needs of vulnerable groups such as individuals
with disabilities.
The EU AI Act’s stringent measures on emotion recognition systems reflect a balanced approach
aimed at fostering innovation while protecting fundamental rights. By categorising these systems
as high-risk and imposing strict transparency and data protection obligations, the Act seeks to
mitigate the potential harms associated with these technologies.
Recital 63 clarifies that the high-risk classification does not inherently legalise the use of emotion
recognition systems under other Union or national laws. Instead, their deployment must always
align with existing legal frameworks, including the Charter of Fundamental Rights of the European
Union and the GDPR. This ensures a comprehensive legal oversight that transcends the AI Act’s
provisions, embedding robust safeguards against the misuse of biometric data.
| 40
Key Dates:
• 2 August 2026: Rules on Annex III Emotion Recognition Systems come into effect.
• The AI Act imposes significant fines for non-compliance with its provisions, especially
for high-risk AI systems. Non-compliance with specific obligations related to operators or
notified bodies can result in administrative fines of up to €15 million or, if the offender is
an undertaking, up to 3% of its total worldwide annual turnover for the preceding financial
year, whichever is higher. This includes obligations of providers (Article 16), authorised
representatives (Article 22), importers (Article 23), distributors (Article 24), deployers (Article
26), and requirements and obligations of notified bodies (Article 31, Article 33(1), (3) and (4),
or Article 34), as well as transparency obligations for providers and deployers (Article 50).
• For SMEs, including start-ups, each fine is capped at the lower of the specified percentages
or amounts.
C. Steps to Compliance:
• Emotion Recognition Systems: Consider whether the business’s system fits the definition
of ‘emotion recognition system’ in Article 3(39), identifying or inferring emotions from
biometric data (as defined in Article 3(34)).
• Prohibitions: Verify that the business’s use case does not fall under prohibited scenarios,
such as use to infer emotions in workplaces or educational institutions, unless for medical
or safety purposes (Article 5(1)(f)).
• High-Risk Systems: Determine if the business’s system is classified as high-risk under Annex
III, which requires stringent regulatory compliance.
| 41
THE WILLIAM FRY AI GUIDE
• Inform Affected Individuals: As mandated by Article 50(3), inform individuals when their
biometric data is being processed to infer emotions. Ensure this information is accessible,
considering the needs of vulnerable groups (Recital 132).
• GDPR Alignment: Align the business’s data processing activities with the GDPR requirements,
particularly regarding special categories of personal data (Article 9(1) GDPR).
• Risk Assessment: Perform a thorough risk assessment to identify potential biases and
discriminatory outcomes, as highlighted in Recitals 44 and 54.
• Mitigation Measures: Implement measures to mitigate identified risks, ensuring the system’s
fairness and reliability.
• Consultation: Engage with relevant regulatory authorities to ensure the business’s compliance
strategy aligns with the latest regulatory expectations and guidelines.
• Updates and Training: Keep the personnel informed about updates in regulations and provide
regular training on compliance requirements.
• Legal Alignment: Ensure the system’s deployment aligns with the Charter of Fundamental
Rights of the European Union and other relevant legal frameworks.
| 42
Conclusion The regulation of emotion recognition AI systems under the EU
AI Act marks a significant advancement in AI governance. By
defining these systems, identifying their risks, and embedding
stringent transparency and data protection measures, the EU
aims to harness the benefits of AI while mitigating its risks.
The interplay with the GDPR further strengthens the regulatory
landscape, ensuring that the deployment of emotion recognition
technologies respects individual rights and maintains public
trust. As AI continues to evolve, such comprehensive regulatory
frameworks will be crucial in balancing innovation with ethical
considerations.
| 43
THE WILLIAM FRY AI GUIDE
9. Extraterritorial Reach
The extraterritorial nature of the AI Act is particularly evident in its application to providers and
deployers of AI systems established in third countries. Article 2(1)(c) specifically addresses this
extraterritorial reach by including providers and deployers of AI systems that have their place of
establishment or are located in a third country, where the output produced by the system is used
in the EU. This output-based jurisdiction is a key aspect of the AI Act’s extraterritorial scope.
| 44
B. Role of Authorised Representatives for Providers Established Outside
the EU
A key mechanism for enforcing the extraterritorial reach of the AI Act is the concept of the
“authorised representative.” An ‘authorised representative’ is defined under Article 3(5) of the AI
Act as a natural or legal person located or established in the EU who has received and accepted
a written mandate from a provider of an AI system or a GPAI model who is established in a third
country to perform and carry out on its behalf the obligations and procedures established by the
AI Act.
The AI Act distinguishes between authorised representatives for high-risk AI systems (Article
22) and those for GPAI models (Article 54). However, the underlying principle remains the same:
ensuring accountability within the EU’s jurisdiction.
• keeping these documents and other relevant information at the disposal of competent
authorities for ten years;
Importantly, Article 22(4) of the AI Act empowers the authorised representative to terminate the
mandate if they believe the provider is acting contrary to the AI Act, and requires them to inform
the relevant market surveillance authority and notified body about such termination.
These provisions ensure that there is always an entity within the EU’s jurisdiction that can be held
accountable for compliance with the AI Act, regardless of where the AI system or model originates.
| 45
THE WILLIAM FRY AI GUIDE
Recital 106 of the AI Act further extends the extraterritorial reach in the context of copyright
compliance, stipulating that providers of GPAI models must comply with EU copyright law,
regardless of where the training of these models takes place. This ensures a level playing field
among providers, preventing competitive advantages based on less onerous legal obligations
applying outside the EU.
However, these provisions may also create challenges for companies operating across multiple
jurisdictions. Non-EU entities will need to carefully assess their AI systems, ensure compliance
with the AI Act, establish a presence in the EU through an authorised representative, and meet the
various obligations if they intend to serve EU customers or process EU-origin data, even if their AI
systems are not directly deployed within the EU.
| 46
PART 2
A Practical Guide to
AI Legal Issues
THE WILLIAM FRY AI GUIDE
A . Over view
Many potential issues arise in relation to IP rights, particularly with regards to IP infringement and
ownership. This section provides an overview of the critical IP considerations for organisations,
focusing on the materials used to train AI systems (Inputs) and the content they generate (Outputs).
B. Issues to Consider
INPUT
Typically, general-purpose AI systems are trained using a substantial dataset, which often contain
IP protected material scraped from the internet via a process known as text and data mining (TDM).
The TDM process may constitute copyright infringement unless authorisation (such as a licence)
has been obtained from the relevant rightsholder or the TDM is carried out on the basis of a lawful
exception.
| 48
OUTPUT
• Infringement:
Whether an organisation is developing or deploying an AI system, the nature of its Output
can result in IP infringement. Where the AI system has been trained on protected works,
Output that reproduces or resembles any of the protected works could attract claims of
infringement. Liability here could exist both for the organisation which developed the AI
system, and for the organisation deploying it, depending on the terms of use between the
parties. Different IP rights other than copyright may also be similarly affected, including
trade marks, patents or even trade secrets.
• Ownership:
Determining the ownership of AI-generated works can be complex. Courts globally are
grappling with the question of ownership of content generated using AI. In some decisions
to date, there has been a requirement for human authorship to enjoy copyright protection,
as seen in recent rulings in the US, UK, and some parts of the EU. The U.S. Copyright Office
and US courts have been explicit in their determination that in the U.S, works created by AI
cannot obtain a copyright registration. In Ireland however, there may be scope for IP rights
to be attributable to AI Output. Under Irish law, the ‘author’ of a work which is computer-
generated is the “person by whom the arrangements necessary for the creation of the work
are undertaken”. Some experts believe this could apply in the context of works generated by
AI. Further questions arise over whether the person who made the necessary arrangements
is the individual who prompted the AI system, or the individual or company who created the
AI system, or perhaps a combination of these. While there is a path by which AI Output may
attract IP protection in Ireland, issues of ownership of such content have yet to be tested in
the Irish courts.
C. Next Steps
• Audit AI Training: review datasets used for AI training and ensure compliance with terms of
use and licensing agreements, and/or reserve the organisation’s rights in relation to the use
of its proprietary information for the training of AI.
• Implement Clear Policies: establish policies regarding the use of third-party IP in AI training,
the use of IP in prompting AI systems, and the ownership of AI-generated output.
• Contractual Protections: ensure that contracts for AI clearly outline IP rights, including
licences, permissions and exceptions. It is important that these contracts also address
potential liabilities and indemnities related to IP infringements.
INPUT
• Dataset Terms of Use: many publicly available datasets can be used for research purposes
only. Organisations must ensure they have the right to use these datasets in a commercial
context.
| 49
THE WILLIAM FRY AI GUIDE
• Rightsholders’ Approval: verify whether IP rights holders have given appropriate permissions
for their work to be used for AI training purposes.
• Exceptions for Use: where there is no explicit permission from an IP rightsholder for the
use of their work, organisations should check whether they could rely on another ground to
use the material. For example, under EU law, there are exceptions which permit the use of
publicly available copyright material for TDM if the owner has not expressly reserved their
rights against TDM.
• Reservation of Rights: organisations which wish to prevent the use of their data for TDM
purposes should ensure that they have expressly and appropriately reserved their rights in
this regard.
• Licences: organisations should ensure that any licence granted over the use of their IP is
sufficiently clear about the use permitted of protected material for AI-training purposes.
OUTPUT
• Human Involvement: it is important to determine whether works created with the help of AI
had sufficient human contribution to secure protection under different IP legislative regimes.
• IP Infringement: establish whether any of the organisation’s IP rights have been infringed by
AI systems. While AI systems are often trained on third party datasets, IP rightsholders must
prove that their works have been actually copied, regardless of potential similarities to the
protected works in the Output.
| 50
2. AI and Data Protection
A . Over view
The GDPR has several key principles that may present challenges for organisations acting as
controllers when using AI systems, namely:
| 51
THE WILLIAM FRY AI GUIDE
A fundamental aspect of the GDPR is that PD must be processed, lawfully, fairly and in a transparent
manner.
1.1.1 To process any PD, a controller must have a legal basis to do so under the GDPR. When it comes
to AI systems, the applicable (and appropriate) legal basis/bases to legitimise the processing
of PD will be hugely context-specific and, in most instances, will be preconditioned by a
“necessity” requirement under the GDPR. For example:
1.1.2 The type of AI system – how was it trained, with what data, how will it be deployed/function,
etc.?
1.1.3 The purposes for which an AI system is being trained and/or deployed by the controller –
what is the AI system seeking to address for the controller (i.e. the use case)?
1.1.4 The controller’s relationship with the individuals whose PD will be processed – is it direct or
indirect?
1.1.5 Is there an existing data protection notice implemented such that the purposes of processing
via an AI system are compatible with the original purposes of processing and within the
reasonable expectations of individuals?
1.1.6 In general, the AI Act does not provide an express legal basis for controllers to process PD
for the purposes of an AI system. As such, a legal basis under the GDPR must be identified
(subject to certain exceptions to this position under the AI Act).
1.1.7 It is best practice to consider the applicable legal basis/bases for each phase of an AI system’s
lifecycle (to the extent applicable for a controller), be that training, development and/or
deployment, along with the data protection role of each actor concerned in the processing.
The applicable legal basis/bases will differ for a provider and deployer because they will
generally have different purposes for processing PD.
1.2 Fairness
1.2.1 The principle of fairness is a crucial aspect of GDPR compliance regarding the interplay
between AI and data protection due to the potential for bias and discrimination. PD must
not be processed in a manner that is unjustifiably detrimental, unlawfully discriminatory,
unexpected or misleading to individuals.
1.2.2 An important aspect of compliance with this principle is that the responsibility for ensuring
compliance with the GDPR should not be transferred from a controller to end users.
Controllers must not include provisions in their terms and conditions of use that data
subjects are responsible for their inputs, as ultimately, it is the controller that is responsible
for complying with the GDPR.
| 52
1.2.3 Transparency
[Link] Informing individuals about how their PD have been obtained, why their PD will be processed
and how they will be used is all part of the GDPR’s transparency obligations. However, this
is challenged when it comes to AI systems because it is not possible, in every use-case, to
identify:
[Link] the source of data which trained an AI system (particularly where data have been scraped
from the internet or taken from user-generated content);
[Link] how an AI system operates and processes PD (e.g. the opacity of how an AI system works
can be a black box and not a glass box);
[Link] whether the use of PD by an AI system is within the reasonable expectations of individuals
(e.g. to whom the PD relates).
2. Accuracy
2.1 AI, particularly public and “out of box” generative AI systems, poses challenges for the
GDPR’s data accuracy principle. These AI systems can be very accomplished at giving output
data that is factually incorrect (e.g. AI hallucinations) but the GDPR requires organisations to
ensure the accuracy of all PD processed and that it is up-to-date.
2.2 In practice, it will be critical to implement policies (including human involvement and human
intervention) to ensure accuracy at each stage of an AI system’s lifecycle in a reasonable
and proportionate manner (e.g. data collection, data analysis, etc.). For example, once an AI
system is operational, organisations should implement a policy to inform end users to verify
the accuracy of any output data and not to presume such accuracy.
2.3 A further dimension to this principle is ensuring that PD remain up-to-date. As such, it will be
necessary to assess whether an AI system remains dynamic once it is in operation, such that
it is continually autonomous, self-learning, adapting and changing, as this means data may
be continually updated and, therefore, processed.
3.1 AI systems must respect and facilitate the exercise of data subject rights under the GDPR,
including access, rectification, and erasure of data. Implementing privacy by design and
default principles, and maintaining accurate records of processing activities are essential for
compliance.
| 53
THE WILLIAM FRY AI GUIDE
B. Issues to Consider
| 54
C. Next Steps
In summary, AI developers and deployers must comply with the GDPR and demonstrate compliance
with their accountability legal framework. This means leveraging existing data protection governance
frameworks to deploy AI systems. To ensure compliance and mitigate risks, organisations should:
1. Review the lawful basis of all processing related to the use and/or training of AI systems within
your organisation.
3. Create an inventory of AI systems deployed or under development, including those from external
vendors and partners.
4. Conduct comprehensive AI impact assessments to identify and mitigate risks, aligning with
GDPR and AI Act requirements, which may include DPIAs/FRIAs.
5. Review, adapt, and revise data protection policies, documents, due diligence questionnaires,
and vendor contracts to incorporate AI-specific requirements and safeguards.
6. Provide ongoing training and awareness initiatives to ensure staff understand the ethical and
legal implications of using AI systems, emphasising data protection and privacy.
| 55
THE WILLIAM FRY AI GUIDE
3. AI and Cybersecurity
Introduction Since the advent of large language models and other forms of
generative AI, organisations have witnessed the transformative
power of this technology. Many businesses (perhaps
unknowingly) already leverage AI to streamline processes and
plan to further capitalise on its potential. Despite their benefits,
such emerging technologies can create vulnerabilities within
organisations, making them more susceptible to cyberattacks.
At the same time, threat actors are incorporating AI into their
arsenal to hack systems.
A . Over view
The emergence of new technologies has altered the threat landscape in the cybersecurity space.
In response to this, and as part of the EU’s Digital Reforms Package, the EU has revised existing
cybersecurity rules and proposed new legislation concerning cybersecurity and AI.
Organisations should consider the legislation coming down the tracks in this space:
NIS 2 is an overarching cybersecurity framework which will replace previous EU cybersecurity laws
under the NIS 1 Directive. NIS 2 aims to protect critical infrastructure and operational resilience
by harmonising cybersecurity standards across Member States. NIS 2 will enter into force on 18
October 2024. It triggers legal obligations for a wider span of critical infrastructure entities in
various sectors, meaning that organisations previously not in scope of EU cybersecurity legislation
may now be caught. In-scope entities must implement technical, operational and organisational
measures to comply with cyber risk management, reporting and information sharing. They must
analyse their business operations, including the use of any machine learning or AI technologies, to
ensure that robust cybersecurity systems are in place.
| 56
2. EU Artificial Intelligence Act (AI Act)
Organisations deploying AI must also take note of the incoming AI Act. The AI Act divides AI systems
into different categories based on their risk categorisation and prescribes rules accordingly.
Organisations deploying ‘high risk’ AI systems should note that, under the AI Act, they must ensure
that such systems meet certain cybersecurity and resilience standards and perform consistently
in those respects throughout their lifecycle. This includes incorporating, where appropriate,
technical solutions to prevent, detect, respond to and control data poisoning, model poisoning,
model evasion, confidentiality attacks or model flaws.
Manufacturers of software or hardware with digital elements will come under the scope of the
impending CRA. This piece of legislation, still in draft form, will require manufacturers to incorporate
cybersecurity into the design, development and distribution of products, test for and remediate
vulnerabilities of products both pre- and post-launch on the market, and undertake conformity
assessments of products to demonstrate compliance with cybersecurity obligations. Where such
products comprise an AI system, this system will need to be taken into account in meeting these
obligations.
B. Issues to Consider
1. Regulatory Compliance
The new cyber laws (such as NIS 2) render cybersecurity a non-negotiable issue for organisations
and a board-level issue. Organisations should assess whether they fall within the scope of
NIS 2, the AI Act and/or the CRA, either due to the nature of their business, the size of their
organisation or their use of AI. Where businesses are caught by these laws, it is imperative that
they prepare to meet the obligations imposed under NIS 2. Significant penalties are attributable
to non-compliance, with organisations facing substantial fines. Notably, board members will
be subject to personal liability for non-compliance with cybersecurity obligations under NIS 2
from October 2024. As such, organisations must focus on whether they are subject to NIS 2’s
baseline standards and implement them into security frameworks accordingly.
2. Strategic Implementation of AI
While organisations should be aware of the potential for AI systems to expose them to greater
vulnerabilities, they should also note that AI can be a valuable tool for increasing cyber-resilience.
AI has multiple applications in cybersecurity, from fraud detection to analysis and prevention.
An increasing number of organisations are already deploying AI to assist their cybersecurity
personnel to defend against cyberattacks. AI can identify and mitigate potential cyber risks by
analysing data and detecting weaknesses in software and networks via penetration testing. The
ability of AI to analyse communication patterns makes it particularly useful in recognising and
intercepting phishing attempts and even in simulating such attacks to help train employees.
Under NIS 2, organisations are encouraged to use machine learning or AI systems to enhance
their cybersecurity capabilities and the security of network and information systems.
| 57
THE WILLIAM FRY AI GUIDE
C. Next Steps
Organisations should take the following steps to address AI and cybersecurity challenges effectively:
3. Integrate AI Thoughtfully
Consider using AI not only as a tool for efficiency but also as a means to bolster cybersecurity.
Ensure that AI systems are designed and implemented with security in mind, addressing potential
vulnerabilities from the outset.
Note: NIS 2 will take effect on 18 October 2024. At the time of publication of this text, the transposing legislation has not
been introduced under Irish law
| 58
4. AI and Contracts
Contracting for AI solutions via SaaS agreements involves addressing unique complexities due to
the dynamic nature of AI, its reliance on large datasets, and its capacity for autonomous decision-
making. Key considerations include clearly defining the scope of AI services, specifying data rights
and usage, determining intellectual property ownership, allocating liability, setting performance
metrics, ensuring regulatory compliance, and establishing clear termination and exit strategies.
These elements are crucial for managing risks and ensuring that both providers and customers
understand their rights and responsibilities, thus fostering a transparent and effective partnership.
B. Issues to Consider
Pre-signing, Customers should conduct a thorough due diligence process, led by legal and
technical experts to evaluate the reliability, capability, and legal compliance of both the AI solution
provider and the solution itself. Key aspects include assessing regulatory compliance, ownership
of intellectual property, data management and security practices, technical proficiency, and the
performance of the product.
| 59
THE WILLIAM FRY AI GUIDE
| 60
6. Modification and Scalability
Anticipating the need for modifications and scalability is crucial. Contracts should outline
processes for updating the AI solution, incorporating new features, and scaling operations to meet
evolving business needs. Flexibility in contractual terms enables adaptation to changing legal and
technological requirements seamlessly.
Comprehensive liability provisions are crucial. However, addressing liability is often complex due to
the autonomous nature of AI. Contracts should consider the allocation of liability, caps on liability,
whether liability should be strict or fault based, and exclusion clauses.
Providers should have in place both an Acceptable Use Policy (AUP) and Terms of Use Policy (ToU)
to mitigate risks associated with customer (and customer’s end users) misuse of the AI solution.
8. Warranties
Warranties should address the unique nature of AI systems while guaranteeing specified
performance, freedom from defects, and compliance with applicable laws.
Customers should seek warranties on data accuracy, non-discriminatory outputs, and where the AI
system is continuously learning and evolving, a warranty that the learning and adaptation processes
will not compromise the systems integrity or its compliance with specified standards.
Providers should ensure their warranties are accurate and that they have warranty and indemnity
insurance in place.
9. Indemnities
Customers should seek indemnities for breaches of data protection legislation, IP infringement,
and failure of the AI system to perform as agreed.
Providers should negotiate these provisions to achieve fair risk allocation, including strict caps on
liability and exclusions for certain damages or claims.
Customers should include provisions to ensure AI systems adhere to ethical principles and comply
with relevant laws and regulations such as the GDPR and the AI Act.
Providers should include provisions guaranteeing that customers use the solution ethically and
responsibly.
Future-proofing AI related SaaS agreements requires proactive measures to anticipate and adapt
to emerging technologies and regulatory frameworks. Clauses enabling renegotiation or automatic
updates based on technological advancements or legal changes ensure that contracts remain
relevant and enforceable over time.
| 61
THE WILLIAM FRY AI GUIDE
C. Next Steps
Customers should prioritise the following steps:
3. Engage Experts: Involve legal and technical experts early in the contracting process to ensure
all relevant aspects are comprehensively addressed.
4. Conduct Thorough Due Diligence: Perform detailed evaluations of potential AI providers and
solutions to ensure reliability, compliance, and suitability for your needs. We recommend
using the AI Act as a benchmark to assess whether the provider has implemented appropriate
technical and organisational measures, similar to how you would assess whether a processor,
under the GDPR, has in place appropriate technical and organisational measures in place using
Article 28(1) of the GDPR as a benchmark.
1. AI Act Compliance: At the outset, Providers must move towards ensuring that it, its products
and services and the contracts governing same are compliant with the AI Act.
2. Identify Objectives and Deliverables: Identify what the customer is looking to achieve in
deploying your AI solution and its intended use case in order to assess the product or service’s
suitability.
3. Supporting Documentation: Ensure that you have all of the supporting documentation in place
for the AI solution, such as an AUP and ToU.
4. Anticipate Questions: Ensure that you are in a position to anticipate any questions that may
arise during the due diligence process to avoid contractual delays. This includes, ensuring that
you are able to provide information on your data management practices and any technical and
organisational measures you have in place to ensure an adequate level of information security
in relation to your products and services.
| 62
5. AI and Corporate Transactions
A Due Diligence Questionnaire (“DDQ”) is sent out at the outset of a due diligence (“DD”) exercise. At
the very least, especially if the target is an AI-based company, we recommend including questions
in relation to the use, development, or otherwise of AI systems in the target company. Doing so at
this early stage will help determine the use of AI by the target company and how it deploys it, in
compliance with laws such as IP or the GDPR.
| 63
THE WILLIAM FRY AI GUIDE
Once you know whether the company uses or develops AI systems or not (as identified in the DDQ
process or otherwise), the next step is to determine the applicability of the AI Act to the AI system
either developed/owned or used by the target company. It is important to note that different types
of AI systems carry varying obligations based on risk categorisation under the AI Act. Additionally,
consideration should be given to evaluating the long-term viability and roadmap of the product
from both a strategic and legal perspective to ascertain if it will be subject to future obligations
including a CE marking and/or AI office registration under the AI Act.
• Training and Data Quality: How has the AI model been trained? What measures are in place
to ensure data quality and data rights?
• Data Sources: Where has the data been obtained that is used to train the data set?
• Intellectual Property Rights: If developing AI, how are the rights in the data and algorithms
of the AI system protected? What measures has the target company taken to protect rights
and know-how in the data, algorithms and software that constitute the AI product(s)? Any
gaps in appropriate measures should also be identified.
• Output Ownership: Who owns the outputs of the AI system? Where do the ownership rights
reside?
If a target company’s main product is an AI product, an extensive review of the customer contracts
and acceptable use policy should be conducted to ensure the following aspects are adequately
addressed:
› IP Ownership: Consider who owns the system’s inputs and outputs and determine
whether this would be considered a red flag in the context of the transaction.
› Data Re-Use Rights: Assess the target company’s rights to reuse customer data and any
associated liability exclusions or limitations.
› Liability and Indemnities: Assess the liability position of the target company and whether
it provides an indemnity for potential damages caused by its tools or not.
› AI Act Compliance: Although not a requirement until the AI Act comes into force, a
review should be conducted of the customer terms of use to ensure compliance with the
AI Act as well as the acceptable use policy of the AI system.
If the target company does not develop or sell AI as its main product or service but is heavily
reliant on the use of AI in delivering its products or services, the same review should be conducted
on the supplier contracts which the target company has with those AI providers. Of course, the
assessment and reporting of these contracts will be substantially different on the customer side
than the vendor side.
| 64
5. Data protection risks of using AI:
| 65
C. Next Steps
Although not entirely reinventing the wheel, it is essential to adjust the due diligence process
in any corporate transaction when AI is involved. It is important to ask the right questions to get
the right answers in the DD process. If the process reveals material risks in relation to the use or
development of AI systems, this can impact the valuation or in more extreme cases, result in pens
down on the deal.
It is therefore imperative that the due diligence process is carried out adequately and ensure that
the risks identified are mirrored in the representations and warranties set out in the SPA or APA. It
is also important to remember that so many legal implications concerning AI are currently unclear,
meaning that such risks may be reduced or changed in the future as laws are developed to address
this new technology.
| 66
THE WILLIAM FRY AI GUIDE
Conclusion
William Fry’s Insights on the
Future of AI and the Law
| 67
Regulator y Governments are drafting comprehensive frameworks like the
Frameworks: AI Act to ensure transparency, accountability, and ethical AI
Balancing Innovation use. These regulations, while potentially costly, build trust and
and Oversight safety, crucial for widespread adoption. Companies that adapt
early can showcase a commitment to ethical practices, gaining
a competitive edge in trust-sensitive markets.
| 68
THE WILLIAM FRY AI GUIDE
Data Governance The reliance on data for AI highlights the importance of robust
and Strategic data governance. Companies must implement comprehensive
Business Impact data protection strategies aligned with global standards,
addressing both legal compliance and consumer trust. This
focus on data protection is strategic, as consumers increasingly
value privacy.
| 69
Work force AI-driven automation is transforming the workforce, potentially
Transformation: displacing jobs while creating new opportunities. The legal
Reskilling and New implications include adapting employment laws to protect
Opportunities workers’ rights, particularly around retraining and job security.
Companies must invest in upskilling and reskilling programmes
to help their workforce transition to new roles created by AI
technologies. This proactive approach mitigates the social
impact of automation and aligns business practices with
emerging legal and ethical standards.
| 70
Conclusion:
A View of AI’s Future
| 71
THE WILLIAM FRY AI GUIDE
Our
Team
Susan Walsh
CONSULTANT
Technology
+353 1 639 5109
[Link]@[Link]
W i l l i a m Fr y L L P | T: + 3 5 3 1 6 3 9 5 0 0 0 | E : i n fo @ w i l l i a m f r y.c o m
w i l l i a m f r [Link]