
RIA and GDPR: a new era for data protection and Artificial Intelligence in Europe

Reading time: 5 min
The European Regulation on Artificial Intelligence (RIA), which entered into force on 1st August 2024.
It marks a crucial step in the regulation of AI in Europe. This regulation aims to ensure that the development, marketing, and use of AI systems respect fundamental rights and ensure user safety. In addition to the GDPRThe RIA introduces specific requirements for AI systems, based on a risk assessment.
Let's take a quick look at the main implications for innovative companies.
Context and objectives of the RIA
The adoption of the AI Regulation (RIA) addresses a growing need to regulate AI technologies to prevent misuse and protect individual rights . This regulation reflects the European Union's ambition to become a global leader in AI while establishing high ethical standards. The RIA's main objectives include protecting fundamental rights, ensuring user safety, and promoting transparency in AI practices. Unlike the GDPR, which focuses on protecting personal data, the RIA covers a broader range of AI-related concerns.
Risk classification and requirements
The RIA proposes a classification of AI systems into four risk levels: unacceptable, high, specific to transparency, and minimal.
Unacceptably risky practices, such as social scoring and the misuse of biometric recognition, are strictly prohibited. High-risk systems, which may compromise security or fundamental rights, are subject to rigorous compliance assessments and detailed technical documentation. Systems requiring specific transparency, such as chatbots, must meet clear transparency obligations. Finally, minimal-risk systems are not subject to specific requirements imposed by the RIA.
| Level of risk | Description |
|---|---|
| Unacceptable | Prohibits practices contrary to EU values and fundamental rights, such as social scoring, exploitation of people's vulnerability and real-time biometric identification by law enforcement services. |
| High | This concerns systems that could compromise security or fundamental rights. It includes biometric, recruitment, and law enforcement systems. These systems are subject to rigorous compliance assessments. |
| Specific to transparency | Demands transparency obligations for AI systems that present a risk of manipulation, such as chatbots and artificial content generation. |
| Minimal | No specific obligation. Applies to the majority of AI systems currently used in the EU or likely to be used in the future. |
Implications for businesses and society
The RIA has major implications for innovative companies that develop and use AI systems. Developers must now ensure their products comply with new compliance and transparency requirements. Users of these systems, meanwhile, must be clearly and transparently informed about how the AI technologies they use work and the potential risks involved.
The CNIL , as the national supervisory authority, will play a crucial role in enforcing these rules and supporting companies to ensure their compliance. While the RIA imposes new constraints, it also offers opportunities for innovative companies to distinguish themselves by adopting ethical and secure practices.
Conclusion
The European AI Regulation is a significant step forward in ensuring the responsible and ethical use of artificial intelligence in Europe. By establishing clear standards and strengthening the protection of fundamental rights, the RIA helps create a trustworthy environment for the development and adoption of AI technologies. As AI continues to transform various sectors, this regulatory framework offers promising prospects for safe innovation that respects European values.
Some references
- « Entry into force of the European regulation on AI: the CNIL's first questions and answers – Article from the CNIL, CNIL website. – July 12, 2024
- « Artificial intelligence — Questions and answers – Article from the European Commission, European Commission website – August 1, 2024
- « EU AI Act: First Regulation on Artificial Intelligence – Article from the European Parliament, European Parliament website. – June 1, 2023
- « EU AI Act: Navigating a Brave New World – Latham & Watkins Report, Latham & Watkins website. – August 2, 2024
- « EU Sets Global Standards with First Major AI Regulations – Article from the World Economic Forum, World Economic Forum website. – August 2, 2024
- « Robust Governance for the AI Act: Insights and Highlights from Novelli et al. – Article by Novelli et al., Artificial Intelligence Act website. – 2024















