The AI Act and the Reversal of Responsibilities: the Silent and Pervasive Impact on Deployers – 2

After exploring in the first part the role of the deployer and the obligations and responsibilities incumbent upon them for the compliant use of high-risk AI systems under the AI Act, in this second installment we complete the picture, which is crucial for ensuring transparency, security, and the protection of the fundamental rights of data subjects.

Incident Management

In the event that a serious incident is identified (for example involving death, serious harm to health or violations of fundamental rights, irreversible damage to critical infrastructures, or serious damage to property or the environment), the deployer must immediately inform the provider (first and foremost), and subsequently the importer or distributor and the market surveillance authorities (Art. 26(5)).

Ordinarily, the reporting of a serious incident to the market surveillance authorities must, in any case, be carried out no later than 15 days after the deployer has become aware of the serious incident (Art. 73(2)). This timeframe must be proportionate to the severity of the serious incident.

More stringent derogations are provided for specific cases:

A. Widespread infringement or serious incident (Art. 3, point 49(b))

If a widespread infringement occurs (e.g. an issue affecting many users) or a serious incident that causes a serious and irreversible disruption to the management or operation of critical infrastructures,

the report must be submitted immediately and no later than 2 days from the moment the deployer becomes aware of it (Art. 73(3)). In a rapidly evolving regulatory context, understanding these aspects is essential for anyone called upon to adopt or integrate artificial intelligence solutions within their organizations.

Following the common thread of the impact of the new rules, we will analyze how compliance with requirements on data relevance and representativeness, together with logging obligations, can make the difference between responsible use of AI and the risk of serious consequences, both legally and ethically.

Condividi

Post Recenti

Workshop – Come realizzare una FRIA

Beyond the Algorithm: Safeguarding the Human in the Age of Artificial Intelligence

Energy Telemarketing: Law 49/2026 Changes the Rules of the Game – 2