Understanding the EU AI Act: �What It Means for Research & Education
Magdalena Rzaca – HEANET Conference
The RevolutionAIry�Road Ahead:
Why the AI Act is RevolutionAIry?
Global standard targeting AI and GPAI
Regulates the whole AI lifecycle
Based on risk – tightens where needed
Heavy penalties
FROM DATA TO RISK
Input → AI → Risk
Why the AI Act is so different?
LEGAL DEFINITION OF AI SYSTEMS
FULL LIFECYCLE GOVERNANCE
RISK-BASED STRUCTURE
GLOBAL REACH WITH FAST INTRODUCTION
GDPR VS AI ACT
Aspect | GDPR (evolution) | AI Act (revolution) |
Focus | Personal data | AI systems & impact |
Scope | Processing | Design → Deployment (risk) |
Oversight | SA’s + EDPB | National AI Authorities + AI Office |
Principle | Data protection by design | Trustworthy AI by design |
AI Act vs GDPR – Penalties�
Category | AI Act | GDPR |
Highest Fine | €35 million or 7% of annual global turnover | €20 million or 4% of annual global turnover |
Standard High-Risk Breach | €15 million or 3% of turnover | €10 million or 2% of turnover |
Administrative Failures | €7.5 million or 1% of turnover | €10 million or 2% of turnover |
Act II: Structure & Impact
AI System definition – key elements
Machine-based system: wide range of technologies
Varying levels of autonomy
Human involvement – needs human input
Affects environments: whether digital (e.g., search rankings) or physical (e.g., robotics)
FOUR TIER RISK CLASSIFICATION
Risk Level | Regulatory Response |
Unacceptable (e.g. social scoring, dark patterns) | Banned outright |
High-Risk (e.g. recruitment, education, critical infrastructure) | Strict obligations on safety, transparency, human oversight |
Low Risk (e.g. chatbots) | Transparency requirements only |
Minimal Risk (e.g. spam filters) | No obligations; encouraged voluntary codes |
UNACCEPTABLE AI MODELS
These are prohibited outright, regardless of safeguards, due to their conflict with EU fundamental rights.
�A university using facial recognition on campus in real-time to identify students for entry into buildings or events.
Campus networks must avoid deploying or enabling RBI tools in public spaces unless strict legal exceptions apply.
High risk defitinition
An AI system is considered high-risk if it is:
Intended to be used as a safety component of a product, or subject to third-party conformity assessment under EU product safety legislation
Or
Listed in Annex III, which outlines specific use cases where AI presents systemic risks
Game-changer: Annex III
Eight specific areas where AI systems are presumed to be high-risk, based on their INTENDED use including:
Biometric identification and categorization
Critical infrastructure (also intended to be used as safety components in the management and operation of critical digital infrastructure)
Education and vocational training
Employment, workers management
Access to essential services
Law enforcement
Migration, asylum, and border control
Administration of justice
High risk examples
🎓 Student admission scoring;
🧠 Behavioural monitoring;
🎯 Automated grant decisions
Transparency, human oversight, fairness, documentation.
GEANT E-academy chatbot: low risk example
What was necessary for AI Act Compliance?
Transparency Notice; Ethical Use Terms, Risk Assessment, Human Oversight, IP-only logging, Internal system inventory
From GDPR perspective: Privacy Statement
Low Risk ≠ No Risk
What Role Does Your Organisation Play in the AI Lifecycle?
ROLE | As NRENs, you may be: |
🧪 Provider – develops AI 🌍 Importer – brings AI into EU 🖥️ Deployer – uses AI in production | �🖥️ Deployer (e.g. Copilot use) �🧪 Provider (custom tools, models)� |
Risk evaluation & obligations
High-risk designation under Annex III isn’t based on the tech itself—it’s based on how and where it is intended to be used.
For example: an AI model used to assess student performance in a university is high-risk if it influences access to education.
But the same model used in a research sandbox with no real-world impact may not be high-risk.
NRENs must understand what AI systems are hosted, how they're used and by whom. All this must comply with the relevant AI Act obligations.
Research Exemption
As seen in art. 2 (5) and recital 72 of the AI Act
Applies to AI systems used exclusively for research & development
Applies to non-commercial R&D activities
As soon as AI is put into service or affects real users, full obligations apply
Open source exemption
Open-source AI models are partially exempt if not placed on the market for a commercial purpose
They must respect transparency obligations under Article 52, especially for GPAI models
No exemption for deployment in high-risk use cases
AI Sandboxes: Safe Spaces for Innovation
Why Use a Sandbox?
Test in real conditions
Access regulatory guidance
De-risk at early stages
Enable collaboration
Idea → Sandbox → Supervised Test → Deploy
ACT III: Governance and readiness
AI Act governance requires cooperation between Legal, Technical, Security, Risk and Ethical teams
GDPR vs AI act –� governance
Governance | GDPR | AI Act |
Role | DPO | AIO / AI Gov Committee |
Expertise | Privacy | Legal • Ethics • Technical • Security • Risk |
Focus | Data processing | AI lifecycle |
| | |
AI Office
Interpretation and application of the Act.
A central role in monitoring GPAI models (like ChatGPT).
It may coordinate with NRENs and research institutions, especially those involved in AI testing, development, or deployment.
It promotes trustworthy AI and supports innovation -AI sandboxes.
Act IV: Discussion
The countdown is on!
✔️ June 2024 — Act approved
⚙️ Feb 2025— Part of the obligations became applicable
🛠️ August 2026 — Core rules fully applicable
WHAT CAN YOU DO TODAY?
🧠 Raise AI Awareness – across staff
🗂️ Audit AI Tools – even low-risk systems
🔍 Assess Risk Level – is it high? minimal?
📃 Draft Transparency Notice – even for Copilot
👥 Build Governance Team –cross-functional
GDPR & AI Act alignment
Integrate AIIA in your DPIA stream
Even if you’re using Copilot, GPT, or open-source GPAI & their use is connected with the processing of personal data 🡪 then AI Act obligations and GDPR apply
We are working on creating SIG LEGAL – join!
Let’s connect: https://www.linkedin.com/in/magdalena-rzaca-fip/
Let’s shape governance that works for education and research!
LEGAL HUB