Skip to content
VibeFormer
44 min

The AI Act

Regulation 2024/1689, the fairness strand's main instrument, and the chapter where your own research becomes the strongest card you hold. Includes the Annex III gap for public enforcement authorities.

Listen

0. Read this alongside his own paper

He teaches a course called The Law of Artificial Intelligence, so this is his taught subject, and he has published on it twice in ways that matter to you. Both are summarised below so you do not need to chase them.

1. The basics, and the timeline that moved

Regulation (EU) 2024/1689, adopted 13 June 2024, in force 1 August 2024. The first comprehensive horizontal AI regulation anywhere.

Its architecture is product safety law — conformity assessment, CE marking, notified bodies, market surveillance — with a fundamental rights layer added on top. That hybrid origin explains most of its awkwardness, and it is a fair criticism to voice: a framework designed for certifying lifts and toys is being asked to police fundamental rights.

DateWhat applies
1 Aug 2024Entry into force
2 Feb 2025Prohibitions under Article 5, and the AI literacy duty under Article 4
2 Aug 2025General-purpose AI obligations, governance structures, penalties
2 Aug 2026Article 50 transparency obligations, GPAI penalty powers, national market surveillance activated
2 Dec 2027Annex III high-risk obligations — deferred from 2 Aug 2026
2 Aug 2028Annex I high-risk, embedded in products — deferred from 2027

The Omnibus also added a prohibition on generating non-consensual intimate imagery and child sexual abuse material, and moved the regulatory sandbox deadline to December 2027.

2. The architecture

  1. Unacceptable risk — prohibited outright, Article 5
  2. High risk — permitted but heavily regulated, Article 6 with Annexes I and III
  3. Limited risk — transparency obligations only, Article 50
  4. Minimal risk — unregulated

Running alongside all four: a separate regime for general-purpose AI models, Articles 51 to 56, with additional duties above a systemic-risk threshold.

3. Provider versus deployer, and the classification that decides everything

ActorDefinition
Provider, Article 3(3)Develops an AI system and places it on the market or puts it into service under its own name. Carries most of the obligations
Deployer, Article 3(4)Uses an AI system under its own authority. A competition agency using a screening tool is a deployer
Importer and distributorArticles 23 and 24
Affected personNot a full role, but holds rights under Articles 85 and 86
AI OfficeInside the Commission. Supervises general-purpose AI
AI BoardMember State representatives
Scientific PanelIndependent experts, able to raise qualified alerts
Market surveillance authoritiesNational enforcement. For the Annex III law enforcement, migration and justice categories, this is meant to be the data protection authority

4. Scope

Caught: providers placing systems on the EU market wherever they are established; deployers established or located in the EU; and providers or deployers in third countries where the output is used in the EU.

Excluded: military, defence and national security purposes; scientific research and development as the sole purpose; pre-market research and development, though not real-world testing; purely personal non-professional use; and free and open-source AI, except where it is prohibited, high-risk, or caught by Article 50.

5. Definitions, and the word that does the work

AI system, Article 3(1): a machine-based system, operating with varying levels of autonomy, possibly adaptive after deployment, that infers from input how to generate outputs such as predictions, content, recommendations or decisions influencing physical or virtual environments. Aligned with the OECD definition.

General-purpose AI model, Article 3(63): displays significant generality and competently performs a wide range of distinct tasks. Systemic risk is presumed under Article 51 where cumulative training compute exceeds ten to the power of twenty-five floating point operations.

6. Article 5 prohibitions, and two instructive near-misses

  • Subliminal, manipulative or deceptive techniques materially distorting behaviour and causing significant harm
  • Exploiting vulnerabilities based on age, disability, or social and economic situation
  • Social scoring by public or private actors leading to detrimental treatment that is unjustified or disproportionate
  • Individual criminal risk assessment based solely on profiling or personality traits, that is, predictive policing
  • Untargeted scraping of facial images to build recognition databases
  • Emotion recognition in workplaces and education
  • Biometric categorisation inferring race, political opinions, trade union membership, religion, sex life or sexual orientation
  • Real-time remote biometric identification in public spaces for law enforcement, with narrow exceptions

Two of these nearly catch competition screening, and the near-miss is the interesting part.

7. Article 6, Annex III, and the gap at the centre of your pitch

Article 6(1): high-risk where the system is a safety component of, or is itself, a product under Annex I legislation requiring third-party conformity assessment.

Article 6(2): the Annex III use cases are high-risk.

Article 6(3) derogation: an Annex III system is not high-risk where it poses no significant risk — because it performs a narrow procedural task, improves a previously completed human activity, detects decision patterns without replacing or influencing human assessment, or performs preparatory work. But it is always high-risk if it profiles natural persons.

The eight Annex III areas: biometrics; critical infrastructure; education; employment and worker management; access to essential public and private services, which is where credit scoring sits; law enforcement; migration, asylum and border control; and administration of justice and democratic processes.

And an agency wanting to stay outside would reach for Article 6(3): our screen merely detects patterns without influencing human assessment. After SCHUFA, that is a factual claim a court will test — and if the agency opens an investigation because the screen flagged it, the claim looks thin.

8. High-risk requirements, and the two articles that are yours

ArticleRequirement
9Risk management system, iterative across the lifecycle
10Data and data governance. Training, validation and test data must be relevant and sufficiently representative, and to the best extent possible free of errors and complete, and must be examined for possible biases affecting fundamental rights or causing discrimination. Article 10(5) permits processing special category data where strictly necessary for bias detection and correction
11 with Annex IVTechnical documentation
12Logging. Automatic recording of events over the system's lifetime
13Transparency to deployers: instructions for use, capabilities and limitations, declared accuracy
14Human oversight. Designed so natural persons can understand its capacities and limits, remain aware of automation bias, correctly interpret the output, decide not to use it, override it, or stop the system
15Accuracy, robustness and cybersecurity

9. Obligations by actor, and the FRIA

  • Article 16 — provider obligations: quality management, documentation, conformity assessment, CE marking, registration, corrective action
  • Article 25 — the value chain, and when a deployer becomes a provider
  • Article 26 — deployer obligations: use per instructions, assign human oversight to competent and trained people, ensure input data relevance, monitor, retain logs, cooperate with authorities. Article 26(11) requires deployers of Annex III high-risk systems making or assisting decisions about natural persons to inform those persons
  • Article 27 — the fundamental rights impact assessment, required of deployers that are bodies governed by public law or private entities providing public services. It must describe the deployment process, the period of use, the categories of persons affected, the specific risks of harm, the human oversight measures, and the governance and complaint arrangements, and be notified to the market surveillance authority

A competition agency is a body governed by public law, so Article 27 would bite — except that it only triggers for Annex III high-risk systems. The gap from section 7 switches it off.

10. Article 50 transparency, in force since August

Systems interacting with humans must disclose that they are AI. Synthetic content must be marked in machine-readable form. Deep fakes must be disclosed. Text published to inform the public on matters of public interest must be labelled as AI-generated unless a human took editorial responsibility for it.

11. General-purpose AI, and the clause written for your job

  • Article 51 — systemic risk classification, presumed above ten to the twenty-fifth floating point operations of cumulative training compute
  • Article 53 — provider duties: technical documentation, information to downstream providers, a copyright policy, and a public summary of training content
  • Article 55 — systemic risk duties: model evaluation including adversarial testing, systemic risk assessment and mitigation, serious incident reporting, cybersecurity
  • Article 56 — codes of practice
  • Partial open-source exemption under Article 53(2), unless the model carries systemic risk

12. Rights and penalties

  • Article 85 — the right to lodge a complaint with a market surveillance authority
  • Article 86 — the right to explanation of individual decision-making. A person subject to a decision taken by a deployer on the basis of output from an Annex III high-risk system, producing legal effects or adversely affecting health, safety or fundamental rights, may obtain clear and meaningful explanations of the role of the AI system in the decision procedure and the main elements of the decision taken
  • Article 87 — whistleblower protection
BreachMaximum
Prohibited practices, Article 535 million euro or 7 percent of worldwide annual turnover
Most other obligations15 million euro or 3 percent
Misleading information to authorities7.5 million euro or 1 percent

Small and medium enterprises pay the lower of the two figures rather than the higher.

13. Neighbouring instruments

  • GDPR and Regulation 2018/1725 apply in parallel, under Article 2(7)
  • Product Liability Directive (EU) 2024/2853 now treats software and AI as products
  • The AI Liability Directive proposal was withdrawn in 2025, so there is no harmonised fault-based AI liability regime. Worth knowing: it is a visible hole in the EU's framework

14. Criticisms

  • Product-safety architecture poorly suited to fundamental rights harms
  • Annex III is a closed list and already dated. Your gap is an instance of this
  • Article 6(3) hands providers substantial self-assessment discretion
  • Heavy dependence on harmonised standards that are not finished
  • Public-sector deployment gaps, and a weak penalty regime for public bodies
  • Thin national enforcement capacity
  • The Digital Omnibus deferral widely read as deregulation under industry pressure

15. The ATLANTIS tensions

The AI Act requiresThe reality for a competition agency
Annex III categories tied to criminal law enforcement and judicial authoritiesA competition agency is neither, so its screen may sit outside the regime entirely despite imposing fines of ten percent of turnover
Article 10 representative training data, examined for biasRequires retaining data on firms never pursued, colliding with GDPR minimisation and Article 28 purpose limitation
Article 14 oversight sufficient to interpret output correctly while resisting automation biasYour finding: a system's account of its own reasoning can be true and incomplete, so the reviewer cannot interpret it correctly even when trying
Article 86 explanation of the system's role and the main elements of the decisionArticle 296 TFEU demands reasons and Article 27 of Regulation 1/2003 demands access to the file. Nobody has reconciled the three
Article 27 fundamental rights impact assessment for public bodiesOnly triggers for Annex III high-risk, so the gap switches it off
Article 3(1) covers only systems that inferA rules-based screen with identical legal effect falls outside the Act altogether
Article 100 caps EU institutions at roughly 1.5 million euroFirms face 7 percent of worldwide turnover. Asymmetric accountability

16. How this connects to ATLANTIS

Of the project's three strands — accuracy, fairness, and institutional arrangements — the AI Act is the main instrument for the second, and it is where the legal-track PhD on the fairness problem will spend four years.

Schrepel's own framing of that strand is worth quoting from memory: AI systems inherit the biases of their training data, the computer science literature on that point is now vast, and competition enforcement has barely engaged with it. When a screening model flags one market rather than another, the selection reflects choices about data and design that nobody outside the agency can examine. When machine-generated analysis informs a decision, the duty to give reasons meets an explainability problem the case law never anticipated. The AI Act adds obligations, but its application to enforcement agencies using AI against private parties raises questions the text does not settle.

17. What the panel brings to this chapter

Panel memberWhy the AI Act is their territory
SchrepelWrote Decoding the AI Act for the Journal of Competition Law and Economics, and teaches a course titled The Law of Artificial Intelligence. Also co-authored on foundation model competition with Alex Pentland at MIT and on measuring the openness of foundation models with Pott, which is the closest existing example of what your position is supposed to produce: a measurement methodology applied across real models, with policy conclusions drawn from it
Tijmen WismanFundamental rights and proportionality, and the SyRI case in particular, where a state algorithm failed an Article 8 ECHR test partly for insufficient transparency and verifiability. SyRI is the closest European precedent for the Article 27 impact assessment actually having teeth, and it is a Dutch case he worked on. Know it
Catalina GoantaThe DSA's Article 37 independent audits and Article 40 researcher data access are the EU's first attempts to make algorithmic auditing a legal obligation and to force data out of an unwilling holder. Both are templates ATLANTIS needs. Her legal compliance API proposal is in the same family
Georgiana MirzaDigital ecosystems and data spaces, where fundamental rights, competition and innovation meet. The governance-fragmentation question — who supervises what — runs through her territory

18. What is unexplored, and six projects you could run

19. Your CV, mapped onto this chapter

What you haveWhere it landsThe provision
LLM behavioural evaluation and the Mens Rea harness — three conditions, clean control, interrogation ladder, persona-shift probes, enforced measurement invariantsProjects 2 and 5. This is the single most directly transferable asset you ownArticle 14 human oversight; Article 15 robustness
Adversarial prompting and red teaming, professionally at Outlier and in a published harnessProject 2, and auditing any deployed toolArticle 55, where adversarial testing is now a statutory duty
RAG pipeline engineering in two production systems, including guardrails and edge cases found in live logsProject 5, retrieval integrity for agency systemsArticle 15 accuracy and robustness
Model evaluation methodology — Wilson intervals at small n, McNemar on paired designs, judge-reliability reporting, deterministic parsing where no model is neededProject 3, explanation stability; and the statistical backbone of any auditArticle 10 bias examination; Article 296 reasons
First-order logic, knowledge representation, Prolog, and the VU summer school Logic as a Tool for Modelling at grade 9.0An auditable symbolic layer that produces a derivation rather than a score — the only explanation form that satisfies reason-giving by constructionArticle 86 explanation; Article 296 reasons
Causal inference — DAGs, Bayesian belief networks, do-calculus, Bayesian structural time seriesProject 6, quantifying what minimisation costs an audit; and separating a model's effect on a decision from correlation with itArticle 10 representativeness; GDPR Article 22 after SCHUFA
Fine-tuning and open-weight model work — TinyLlama, Hugging Face, Gemma, Llama 3, NVIDIA NIMCredibility on the GPAI chapter, and the open-source exemption debate Schrepel writes aboutArticles 51 to 55
Legal training in evidence and procedureWhy you can see that Article 86 and Article 27 of Regulation 1/2003 are asking different questions about the same fileThe whole fairness strand

20. If you remember ten things

  1. Regulation (EU) 2024/1689, in force August 2024, product-safety architecture with a fundamental rights layer.
  2. Annex III high-risk obligations now apply from 2 December 2027, deferred by the Digital Omnibus in July 2026. Most summaries are wrong about this.
  3. Four tiers — prohibited, high-risk, transparency-only, minimal — plus a separate general-purpose AI regime.
  4. Provider versus deployer decides your obligations, and Article 25 means a deployer can become a provider.
  5. Article 5 prohibitions nearly catch competition screening through social scoring and predictive policing, but miss, because firms are not natural persons and competition enforcement is not criminal.
  6. The Annex III gap: point 6 is criminal law enforcement, point 8 is judicial authorities, a competition agency is neither, and the gap cascades through Articles 10, 14, 27 and 86.
  7. Article 10 requires representative data examined for bias; Article 14 requires meaningful oversight and names automation bias explicitly.
  8. Article 86 gives a right to the system's role and the main elements of the decision — narrower than people assume, and only for Annex III high-risk.
  9. Article 55 makes adversarial testing a legal obligation.
  10. Penalties are 7, 3 and 1 percent — but Article 100 caps EU institutions at roughly 1.5 million euro. Asymmetric.