The AI Pact: Compliance Guidelines with the AI Act for Developers and Providers of Artificial Intelligence Systems

September 2024 marked the beginning of a new phase in the regulation of artificial intelligence (AI) in Europe, with the launch of the AI Pact, an initiative promoted by the European AI Office aimed at supporting industry players in implementing the AI Act.

Although the European regulation will enter into force in phases starting in February 2025, the Pact encourages companies to voluntarily commit to complying with its requirements, promoting ethical practices, transparency, and risk management—proactive steps to begin aligning with the key provisions immediately.

In November 2023, the first call for expressions of interest in the AI Pact was launched, receiving responses from over 550 organizations of various sizes, sectors, and countries.

The Pact is based on two key elements:

  • Exchange of best practices: Participating organizations share experiences and guidelines to comply with the law, through seminars and collaborative platforms.
  • Early preparedness: Companies sign “commitment declarations” and must implement concrete compliance measures, such as risk assessment and the creation of internal processes.

The benefits for participants are evident: they will have the opportunity to develop a common understanding of the AI Act’s objectives, prepare their organizations for the implementation of the new regulation through concrete actions, and gain greater visibility and credibility for the safeguards put in place.

Organizations that expressed interest were involved in a consultation process that culminated in the workshop held on 4 September 2024 to define the core commitments and provide input on the initial draft.

The AI Office published the final version of the commitments, shaped by the contributions received from stakeholders, and shared it with the goal of collecting official signatures by October.

Core Commitments

For the period beginning with the submission of AI Pact commitments and ending with the entry into force of the relevant AI Act provisions, all participating organizations commit to making their best efforts to comply with—or contribute to complying with—three core commitments, with the possibility of taking on additional ones depending on their specific activities.

The main commitments focus on promoting transparency and managing high-risk AI systems and include the following points:

  • AI governance strategy: Organizations must adopt an AI governance strategy to support the integration of AI into their activities and work towards compliance with the AI Act.
  • Mapping of AI systems: Companies must map the AI systems they use or provide, especially those considered high-risk.
  • Training and awareness: Organizations must promote AI literacy and awareness among their employees, taking into account the context and risks associated with the use of AI systems.

In addition to the core commitments, organizations are encouraged to respect—or help enforce—additional commitments, differentiated between providers and deployers.

For organizations that develop AI systems, the following activities should be undertaken:

  • Risk identification: Implement processes to identify known and foreseeable risks to health, safety, and fundamental rights linked to the use of AI systems.
  • Data quality: Ensure the quality of datasets used for training, validation, and testing of AI systems.
  • Traceability and information: Implement logging features to ensure the traceability of AI systems and inform users on how to correctly use relevant AI systems, their capabilities, limitations, and potential risks.
  • Human oversight: Ensure effective human oversight of high-risk AI systems, in line with the requirements of the AI Act.
  • Risk mitigation: Implement policies and processes to mitigate risks associated with the use of relevant AI systems, in line with applicable obligations and requirements under the AI Act, to the extent possible.
  • Transparency: Organizations using generative AI systems must take measures to ensure that generated content is clearly identifiable as artificially created. They must implement technical solutions such as watermarking and metadata, and provide tools to label AI-generated content—including text, images, audio, or video—especially in the case of deepfakes.

For organizations using AI systems developed by third parties, the following implementations are expected:

  • Risk mapping: Organizations using AI systems commit to mapping known and reasonably foreseeable risks to the fundamental rights of individuals and groups potentially affected by the use of relevant AI systems.
  • Human oversight: Implement concrete measures to ensure human oversight of the functioning of high-risk AI systems, as defined by the AI Act.
  • Transparency: Clearly and distinctly label AI-generated content and inform users when they are directly interacting with an AI system. In the case of decisions that negatively affect an individual’s health or fundamental rights, provide clear and meaningful explanations of the decision-making processes.

Participating organizations in the AI Pact commit to publicly sharing their adopted commitments and reporting on the results achieved within twelve months of publication.

The AI Pact represents an opportunity for organizations to demonstrate their proactivity in complying with new regulations, strengthening trust in AI technologies, and preparing for the future European regulatory landscape. Furthermore, their guidance can serve as a useful reference for all sector operators—not just Pact participants—as a roadmap for meeting the requirements of the AI Act.

 

Laura Turini