1 of 29

Understanding the EU AI Act: �What It Means for Research & Education

Magdalena Rzaca – HEANET Conference

2 of 29

  • Act I: The Spark
  • Act II: Structure & Impact 
  • Act III: Governance and readiness
  • Act IV: Discussion

The RevolutionAIry�Road Ahead:

3 of 29

Why the AI Act is RevolutionAIry?

Global standard targeting AI and GPAI

Regulates the whole AI lifecycle

Based on risk – tightens where needed

Heavy penalties

4 of 29

FROM DATA TO RISK

Input → AI → Risk

5 of 29

Why the AI Act is so different?

LEGAL DEFINITION OF AI SYSTEMS

FULL LIFECYCLE GOVERNANCE

RISK-BASED STRUCTURE

GLOBAL REACH WITH FAST INTRODUCTION

6 of 29

GDPR VS AI ACT

Aspect

GDPR (evolution)

AI Act (revolution)

Focus

Personal data

AI systems & impact

Scope

Processing

Design → Deployment (risk)

Oversight

SA’s + EDPB

National AI Authorities + AI Office

Principle

Data protection by design

Trustworthy AI by design

7 of 29

AI Act vs GDPR – Penalties

Category

AI Act

GDPR

Highest Fine

€35 million or 7% of annual global turnover

€20 million or 4% of annual global turnover

Standard High-Risk Breach

€15 million or 3% of turnover

€10 million or 2% of turnover

Administrative Failures

€7.5 million or 1% of turnover

€10 million or 2% of turnover

8 of 29

Act II: Structure & Impact 

9 of 29

AI System definition – key elements

Machine-based system: wide range of technologies

Varying levels of autonomy

Human involvement – needs human input

Affects environments: whether digital (e.g., search rankings) or physical (e.g., robotics)

10 of 29

FOUR TIER RISK CLASSIFICATION

Risk Level

Regulatory Response

Unacceptable (e.g. social scoring, dark patterns)

Banned outright

High-Risk (e.g. recruitment, education, critical infrastructure)

Strict obligations on safety, transparency, human oversight

Low Risk (e.g. chatbots)

Transparency requirements only

Minimal Risk (e.g. spam filters)

No obligations; encouraged voluntary codes

11 of 29

UNACCEPTABLE AI MODELS

These are prohibited outright, regardless of safeguards, due to their conflict with EU fundamental rights.

�A university using facial recognition on campus in real-time to identify students for entry into buildings or events.

  • Why is it banned? Considered as mass surveillance

Campus networks must avoid deploying or enabling RBI tools in public spaces unless strict legal exceptions apply.

12 of 29

High risk defitinition

An AI system is considered high-risk if it is:

Intended to be used as a safety component of a product, or subject to third-party conformity assessment under EU product safety legislation

Or

Listed in Annex III, which outlines specific use cases where AI presents systemic risks

13 of 29

Game-changer: Annex III

Eight specific areas where AI systems are presumed to be high-risk, based on their INTENDED use including:

Biometric identification and categorization

Critical infrastructure (also intended to be used as safety components in the management and operation of critical digital infrastructure)

Education and vocational training

Employment, workers management

Access to essential services

Law enforcement

Migration, asylum, and border control

Administration of justice

14 of 29

High risk examples

🎓 Student admission scoring;

🧠 Behavioural monitoring;

🎯 Automated grant decisions

Transparency, human oversight, fairness, documentation.

15 of 29

GEANT E-academy chatbot: low risk example

What was necessary for AI Act Compliance?

Transparency Notice; Ethical Use Terms, Risk Assessment, Human Oversight, IP-only logging, Internal system inventory

From GDPR perspective: Privacy Statement

Low Risk ≠ No Risk

16 of 29

What Role Does Your Organisation Play in the AI Lifecycle?

ROLE

As NRENs, you may be:

🧪 Provider – develops AI

🌍 Importer – brings AI into EU

🖥️ Deployer – uses AI in production

�🖥️ Deployer (e.g. Copilot use)

�🧪 Provider (custom tools, models)�

17 of 29

Risk evaluation & obligations

High-risk designation under Annex III isn’t based on the tech itself—it’s based on how and where it is intended to be used.

For example: an AI model used to assess student performance in a university is high-risk if it influences access to education.

But the same model used in a research sandbox with no real-world impact may not be high-risk.

NRENs must understand what AI systems are hosted, how they're used and by whom. All this must comply with the relevant AI Act obligations.

18 of 29

Research Exemption

As seen in art. 2 (5) and recital 72 of the AI Act

Applies to AI systems used exclusively for research & development

Applies to non-commercial R&D activities

As soon as AI is put into service or affects real users, full obligations apply

19 of 29

Open source exemption

Open-source AI models are partially exempt if not placed on the market for a commercial purpose

They must respect transparency obligations under Article 52, especially for GPAI models

No exemption for deployment in high-risk use cases

20 of 29

AI Sandboxes: Safe Spaces for Innovation

Why Use a Sandbox?

Test in real conditions

Access regulatory guidance

De-risk at early stages

Enable collaboration

Idea → Sandbox → Supervised Test → Deploy

21 of 29

ACT III: Governance and readiness

AI Act governance requires cooperation between Legal, Technical, Security, Risk and Ethical teams

22 of 29

GDPR vs AI act –� governance

Governance

GDPR

AI Act

Role

DPO

AIO / AI Gov Committee

Expertise

Privacy

Legal • Ethics • Technical

• Security • Risk

Focus

Data processing

AI lifecycle

23 of 29

AI Office

Interpretation and application of the Act.

A central role in monitoring GPAI models (like ChatGPT).

It may coordinate with NRENs and research institutions, especially those involved in AI testing, development, or deployment.

It promotes trustworthy AI and supports innovation -AI sandboxes.

24 of 29

Act IV: Discussion

25 of 29

The countdown is on!

✔️ June 2024 — Act approved

⚙️ Feb 2025— Part of the obligations became applicable

🛠️ August 2026 — Core rules fully applicable

26 of 29

WHAT CAN YOU DO TODAY?

🧠 Raise AI Awareness – across staff

🗂️ Audit AI Tools – even low-risk systems

🔍 Assess Risk Level – is it high? minimal?

📃 Draft Transparency Notice – even for Copilot

👥 Build Governance Team –cross-functional

27 of 29

GDPR & AI Act alignment

Integrate AIIA in your DPIA stream

Even if you’re using Copilot, GPT, or open-source GPAI & their use is connected with the processing of personal data 🡪 then AI Act obligations and GDPR apply

28 of 29

We are working on creating SIG LEGAL – join!

29 of 29

Let’s connect: https://www.linkedin.com/in/magdalena-rzaca-fip/

Let’s shape governance that works for education and research!

LEGAL HUB