AESIA Guidelines on the AI Act – Guide No. 2
How can the AI Act be applied in practice? The Spanish Agency for the Supervision of Artificial Intelligence (AESIA) has published its second guideline, Practical guide and examples to understand the AI Act. While Guide No. 1 provides a general introduction to the European Regulation on Artificial Intelligence,Guide No. 2 focuses on the practical application of the AI Act through concrete examples and use cases. Its purpose is to illustrate how the provisions of the Regulation can be applied to specific AI systems and how the obligations arising from the AI Act depend on the characteristics, intended purpose and context of each system.
The Guide is structured around two practical use cases: an AI system used to assess applications for financial assistance for families in situations of economic vulnerability and a smart insulin pump used for the management of chronic diseases. These examples are used to illustrate the application of the AI Act at different stages of the lifecycle of an AI system and in different regulatory and technological contexts.
The first use case concerns an AI system deployed by a public authority to support the assessment of applications for financial assistance. The system processes information concerning applicants and is intended to assist the public administration in determining eligibility for financial support. The example illustrates the importance of identifying the intended purpose of the system and determining the role of the different actors involved in its development, provision and deployment.
The example also shows how an AI system used in the context of access to essential public services or benefits must be assessed under the risk-based approach of the AI Act. The classification of the system determines the requirements that must be fulfilled by the provider and deployer. The Guide considers, in particular, the risks associated with inaccurate or discriminatory outcomes and the need to ensure appropriate human involvement in decisions affecting individuals.
The second use case concerns a smart insulin pump for chronic disease management. The pump incorporates AI functionalities intended to support the management of a patient's condition. The example illustrates the application of the AI Act to an AI system operating in the healthcare sector, where failures or incorrect outputs may have direct consequences for the health and safety of individuals.
In this case, the Guide examines the different actors involved in the AI system and the relationship between the AI Act and the regulatory framework applicable to medical devices. It considers the intended purpose of the system and the risks associated with its operation, including the possibility of incorrect predictions, errors, failures or inappropriate functioning.
The two examples demonstrate the importance of determining the intended purpose of an AI system. The intended purpose is relevant for establishing whether a system falls within the scope of the AI Act, determining its risk classification and identifying the obligations applicable to the actors involved. The same technological capability may therefore be subject to different requirements depending on the context in which it is deployed and the consequences that its use may have.
The Guide then applies the AI Act's risk-based approach to the two cases. The classification of an AI system determines the level of regulatory requirements applicable to it. Where a system qualifies as high-risk, the provider and other relevant operators must comply with a comprehensive set of requirements concerning the design, development, documentation, deployment and monitoring of the system.
Among the requirements illustrated through the examples is the establishment of a risk management system. Risks must be identified, analysed and evaluated throughout the lifecycle of the AI system. Appropriate measures must then be adopted to eliminate or reduce identified risks and to address risks arising both from the intended use of the system and from reasonably foreseeable misuse.
The Guide also addresses data and data governance. The quality of the data used to train, validate and test an AI system is particularly important. Data should be relevant to the intended purpose of the system and sufficiently representative of the context in which the system will operate. The examples demonstrate how inadequate or biased data can contribute to inaccurate or discriminatory results.
Technical documentation and record-keeping are also examined. Providers of high-risk AI systems must document relevant information concerning the system, including its design, development, functioning and performance. Records generated during the operation of the system contribute to its traceability and allow relevant events and decisions to be reconstructed.
The Guide further considers transparency and information requirements. Individuals and users must receive appropriate information concerning the AI system and its operation. Depending on the specific use case, this includes information necessary to understand the role played by the AI system and to enable appropriate interaction with it.
Another central requirement illustrated by the examples is human oversight. High-risk AI systems must be designed so that natural persons can effectively oversee their operation. Human oversight should allow operators to understand the relevant outputs, identify potentially problematic results and intervene where necessary. The level and form of oversight depend on the characteristics and risks of the particular AI system.
The Guide also applies the requirements concerning accuracy, robustness and cybersecurity. AI systems must achieve an appropriate level of accuracy in relation to their intended purpose and should be sufficiently robust to operate reliably under the conditions for which they were designed. They must also be protected against vulnerabilities and other forms of interference that could affect their functioning or produce harmful outcomes.
Quality management is considered as an organisational framework supporting compliance with the AI Act. It encompasses, among other elements, compliance procedures,risk management, design and development controls, testing, documentation, post-market monitoring and incident reporting.
The Guide also illustrates the role of conformity assessment for high-risk AI systems. Depending on the characteristics of the system and the applicable regulatory framework, conformity may be assessed through internal controls or through the involvement of third parties. The purpose is to verify that the AI system satisfies the requirements established by the AI Act before it is placed on the market or put into service.
The lifecycle approach is further reflected in the requirements concerning post-market monitoring. Providers must establish processes for systematically collecting and analysing information about the performance of AI systems after they have been placed on the market or put into service. Monitoring makes it possible to identify previously unknown risks, failures or changes in the performance of the system and to take appropriate corrective measures.
The Guide also considers serious incident reporting. Where a serious incident occurs in connection with a high-risk AI system, the relevant provider must follow the reporting obligations established by the AI Act and provide the competent authorities with the information necessary to assess the incident and take appropriate measures.
The two practical cases also illustrate the importance of distinguishing between the different actors in the AI value chain. Depending on their role, providers, deployers and other operators may have different responsibilities under the AI Act. The identification of these roles is therefore an essential part of determining which obligations apply to each actor.
In the case of the financial assistance system, particular attention is given to the interaction between AI and decisions affecting individuals' access to public services and benefits. The example shows how the use of AI in such contexts requires attention to the risks of discrimination, inaccurate assessments and inappropriate reliance on automated outputs, as well as to the need for human intervention.
In the case of the smart insulin pump, the focus is on an AI system whose operation may directly affect health and safety. The example demonstrates how the regulatory requirements concerning risk management, data quality, accuracy, robustness, human oversight and monitoring operate together where an AI system performs functions in a safety-sensitive environment.
Overall, Guide No. 2 illustrates the application of the AI Act by following the entire regulatory pathway of a concrete AI system: identifying its intended purpose, determining the actors involved, assessing whether and how the AI Act applies, establishing the relevant risk classification, identifying the applicable requirements and considering the measures necessary throughout the system's lifecycle.
The Guide therefore moves from the general principles described in Guide No. 1 to their practical application in specific AI scenarios, showing how the requirements of the AI Act operate in different sectors and according to the risks associated with each particular system.
Sei pronto a trasformare i dati in valore per il tuo business?

