{"id":20012,"date":"2026-02-18T08:00:31","date_gmt":"2026-02-18T08:00:31","guid":{"rendered":"https:\/\/letslaw.es\/?p=20012"},"modified":"2026-02-10T16:55:06","modified_gmt":"2026-02-10T16:55:06","slug":"analysis-artificial-intelligence-act","status":"publish","type":"post","link":"https:\/\/letslaw.es\/en\/analysis-artificial-intelligence-act\/","title":{"rendered":"A legal analysis following the EU Artificial Intelligence Act (AI Act)"},"content":{"rendered":"<p>The adoption of <strong>Regulation (EU) 2024\/1689 (the AI Act)<\/strong> reshapes the liability framework associated with artificial intelligence in the EU. Going forward, it will no longer be sufficient to invoke \u201cbest practices\u201d or \u201cethical use\u201d: it will be essential to demonstrate, through traceability and evidence, that the system has been designed, placed on the market, and used in accordance with a framework of due diligence, governance, and risk management.<\/p>\n<p>As regards timing, the AI Act provides that it will enter into force twenty days after its publication in the Official Journal of the European Union and that it will <strong>apply generally from 2 August 2026<\/strong>, with staggered obligations anticipated as early as 2025. Accordingly, the period 2025\u20132026 operates as a transition phase towards increasingly enforceable compliance.<\/p>\n<p>Within this framework, three vectors are already consolidating:<\/p>\n<ol>\n<li>The allocation of duties according to each actor\u2019s role in the value chain.<\/li>\n<li>The progressive insurability of risk through the standardisation of controls.<\/li>\n<li>Ex ante assessment as a legal threshold for market entry.<\/li>\n<\/ol>\n<h2>Allocation of Responsibilities: \u201cProper Use\u201d as a Duty of Care<\/h2>\n<p>The AI Act is built on a central premise: liability is organised according to roles and control within the value chain, not solely by reference to the ultimate harm. The Regulation imposes <strong>obligations on providers, deployers<\/strong> (professional users), <strong>importers, distributors, and other operators<\/strong>, including those established outside the EU where the system is placed on the market or used within the Union.<\/p>\n<p>\u201cProper use\u201d is legally articulated along two axes of diligence:<\/p>\n<ol>\n<li>On the one hand, the provider must place on the market a system with safeguards appropriate to its risk profile.<\/li>\n<li>On the other, the deployer determines the context of use and must avoid improper or deviating uses, ensure meaningful human oversight, and comply with the applicable conditions and instructions (particularly in sensitive domains).<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>For high-risk systems, the standard is heightened: the AI Act requires a <strong>continuous risk management system<\/strong> throughout the entire lifecycle. In practice, this shifts the focus towards evidentiary matters: it will be decisive to demonstrate which risks were identified, how they were assessed, which measures were adopted, and how these were reviewed in light of changes to the system or its deployment context.<\/p>\n<p>In addition, for certain high-risk deployments, a <strong>Fundamental Rights Impact Assessment (FRIA)<\/strong> is required prior to use, particularly in the public sector and in certain private entities providing public services. The FRIA must set out the intended use, the groups potentially affected, the risks to fundamental rights, the human oversight measures in place, and the mitigation actions. If it is missing or treated as a mere formality, it may increase both regulatory and civil liability risk.<\/p>\n<p>Moreover, the AI Act does not replace other legal regimes: the application of the GDPR, privacy rules, and other frameworks (consumer, contractual, and product liability) remains in force, making \u201cmulti-front\u201d liability scenarios increasingly common.<\/p>\n<h2>Insurance risk: from uncertainty to auditability<\/h2>\n<p>The insurance market is reconfiguring coverage because AI-related risk is rarely purely technical. It typically manifests as a composite risk: third-party harm, contractual breaches, security failures, discrimination claims or challenges linked to automated decision-making, and, particularly in regulated sectors, exposure to corrective or sanctioning measures.<\/p>\n<p>Here, the AI Act produces an indirect but decisive effect: it introduces a <strong>regulatory standard that facilitates the auditability of risk<\/strong> and, therefore, its insurability, provided that the organisation can demonstrate governance and controls. In this vein, EIOPA has promoted criteria to integrate AI into existing internal control and risk management frameworks within the insurance sector.<\/p>\n<p>In parallel, <strong>Directive (EU) 2024\/2853<\/strong> on liability for defective products broadens the concept of \u201cproduct\u201d to cover, inter alia, software, thereby reinforcing exposure to strict liability in certain scenarios. Consequently, the importance of a coherent strategy that aligns technical compliance, contractual design, and insurance management is heightened.<\/p>\n<h2>Ex Ante Assessment and Lifecycle Approach: The New Market-Entry Threshold<\/h2>\n<p>From a business perspective, the most significant change is that placing a system on the market ceases to be a purely technological milestone and becomes a legal diligence threshold. For high-risk systems, the minimum requirement is structured around the <strong>risk management system<\/strong>: a continuous, documented, and updatable process to identify and mitigate risks, subject to periodic review.<\/p>\n<p>Where required, the FRIA functions as the connecting element between the system and fundamental rights in the specific case. And where personal data are involved, alignment with the GDPR is indispensable: a project may be reasonably aligned with the AI Act and yet still be non-compliant due to deficiencies regarding lawful basis, transparency, data minimisation, or the exercise of data subject rights.<\/p>\n<p>Finally, compliance does not end at launch. The AI Act imposes a lifecycle approach: <strong>monitoring, detection of deviations, review in response to significant changes, and the capacity to respond to incidents<\/strong>. In short, this is the approach that will, in practice, distinguish merely \u201cpilot-ready\u201d projects from those that are truly \u201cscalable\u201d in an increasingly demanding regulatory environment.<\/p>\n<div class=\"cyp_post_formulario\"><h2>Contact Us<\/h2>\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f3074-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"3074\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/20012#wpcf7-f3074-o1\" method=\"post\" class=\"wpcf7-form init wpcf7-acceptance-as-validation\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"3074\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.5\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f3074-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<div class=\"campo_nombre\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Name\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span><\/div>\n<div class=\"campo_telefono\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-phone\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-tel datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"your-phone\" \/><\/span><\/div>\n<div class=\"campo_email\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span><\/div>\n<div class=\"campo_asunto\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-asunto\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Subject\" value=\"\" type=\"text\" name=\"your-asunto\" \/><\/span><\/div>\n<div class=\"campo_mensaje\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-mensaje\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Message\" name=\"your-mensaje\"><\/textarea><\/span><\/div>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"\" type=\"hidden\" name=\"cyp_form_url\" \/>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"cyp_zonaweb\" type=\"hidden\" name=\"zonaweb\" \/>\n<span class=\"wpcf7-form-control-wrap recaptcha\" data-name=\"recaptcha\"><span data-sitekey=\"6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" class=\"wpcf7-form-control wpcf7-recaptcha g-recaptcha\"><\/span>\r\n<noscript>\r\n\t<div class=\"grecaptcha-noscript\">\r\n\t\t<iframe loading=\"lazy\" src=\"https:\/\/www.google.com\/recaptcha\/api\/fallback?k=6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" frameborder=\"0\" scrolling=\"no\" width=\"310\" height=\"430\">\r\n\t\t<\/iframe>\r\n\t\t<textarea name=\"g-recaptcha-response\" rows=\"3\" cols=\"40\" placeholder=\"Aqu\u00ed la respuesta de reCAPTCHA\">\r\n\t\t<\/textarea>\r\n\t<\/div>\r\n<\/noscript>\r\n<\/span>\n<div style=\"width:100%\">\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important;margin-bottom:15px !important\">\nBy clicking on \"Send\" you accept our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup_ingles\">+ Info<\/a>\n<\/p>\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important\">\n<span class=\"wpcf7-form-control-wrap\" data-name=\"checkbox-173\"><span class=\"wpcf7-form-control wpcf7-checkbox wpcf7-exclusive-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"checkbox-173\" value=\"\" \/><span class=\"wpcf7-list-item-label\"><\/span><\/label><\/span><\/span><\/span> I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup\">+ Info<\/a>\n<\/p>\n<\/div>\n<div class=\"vc_col-sm-12 botton-datos-contacto\"><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/><\/div><input type='hidden' class='wpcf7-pum' value='{\"closepopup\":false,\"closedelay\":0,\"openpopup\":false,\"openpopup_id\":0}' \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<div>","protected":false},"excerpt":{"rendered":"<p>The new era of AI accountability: legal analysis following the Artificial Intelligence Act (AI Act).<\/p>\n","protected":false},"author":2,"featured_media":20014,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[258],"tags":[],"class_list":["post-20012","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-law"],"_links":{"self":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/20012","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/comments?post=20012"}],"version-history":[{"count":3,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/20012\/revisions"}],"predecessor-version":[{"id":20017,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/20012\/revisions\/20017"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media\/20014"}],"wp:attachment":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media?parent=20012"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/categories?post=20012"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/tags?post=20012"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}