Artifical Intelligence (AI)

Artificial Intelligence (AI) is revolutionizing industries worldwide, integrating seamlessly into business operations. However, AI also presents regulatory and ethical challenges. To address these risks, the European Union has introduced the Artificial Intelligence Act (AI Act)—a comprehensive framework to regulate the development, deployment, and use of AI systems.

Key Deadlines and Compliance Requirements

The AI Act came into force on August 1, 2024, with full applicability starting on August 2, 2026. However, certain key provisions take effect earlier:

  • February 2, 2025: Organizations must ensure employees using AI possess adequate AI skills (Article 4).
  • August 2, 2025: Some provisions take effect, requiring businesses to audit AI systems.
  • Prohibited AI Practices: AI practices deemed manipulative or deceptive will be banned (Article 5).

Non-compliance with the AI Act can result in severe penalties—fines of up to €35 million or 7% of global annual revenue (Article 99). To mitigate risks, organizations should immediately assess their AI systems, identify potential non-compliant applications, and implement employee training programs.

How We Support Your AI Compliance Journey

We provide end-to-end AI compliance solutions, ensuring your business adheres to the AI Act while leveraging AI responsibly and securely.

Our AI Consulting Services

Our consulting covers the following AI Act-regulated areas:

  • Risk Classification of AI Applications (Articles 5, 6, and 51): We help categorize your AI systems, identifying those classified as prohibited, general, specific, or high-risk, and outline the specific legal requirements for each category.
  • Development and Maintenance of a Risk and Quality Management System (Articles 9 and 17): Essential for high-risk AI systems, we assist in establishing comprehensive risk management and quality control processes.
  • Advisory on Record-Keeping, Documentation, Reporting, and Notification Obligations (Articles 11, 12, 13, 18, 50, and 73): We guide you through the requirements for maintaining accurate records, providing necessary documentation, and reporting incidents.
  • Fundamental Rights Impact Assessment (Article 27): Our experts conduct assessments to ensure your AI systems respect fundamental rights.
  • Registration of AI Applications in the EU Database (Articles 49 and 71): We manage the registration process, ensuring your AI applications are compliant with EU requirements.
  • Support with Conformity Assessment Procedures (Articles 43 and 47): We assist in conducting conformity assessments to verify compliance with the AI Act.

Appointing an AI Officer: Streamlined Oversight for Your Organization

Our role as your dedicated AI Officer covers all consulting activities in a single package. We start with a thorough inventory of your AI systems based on your processing activity records (as required by Article 30 of the GDPR for applications involving personal data). We classify your systems according to their risk levels and document the results in our DSN port management system.

Our AI Officer services include:

  • Employee Training: We provide tailored training programs, including eLearning courses and workshops, for project leaders and executives to align your AI strategy with regulatory requirements.
  • Risk and Quality Management Setup: We help establish the necessary systems for managing high-risk AI applications.
  • Ongoing Strategic and Data Protection Advisory: We continuously support your compliance efforts, keeping you informed about new regulations and assisting with AI-related data protection assessments.

AI Representative Services: Compliance for Non-EU AI Providers

Under Article 54 of the AI Act, providers of general-purpose AI models based outside the EU must appoint an AI Representative established within the Union. This representative is responsible for ensuring the quality of technical documentation and supporting evidence, which must be available to national and EU authorities.

We offer the expertise to serve as your AI Representative, ensuring full compliance with the AI Act. Contact us to learn more.

AI Competency Training: Ensuring Your Workforce is AI-Ready

According to Article 4 of the AI Act, companies must ensure that employees who use AI systems possess adequate AI competency. We offer comprehensive training programs to meet these requirements, delivered through:

  • Seminars and Webinars via our DSN Academy: Flexible training options tailored to your organizational needs.
  • Custom eLearning Solutions: Interactive courses for both general AI knowledge and specialized AI competency for project managers.
  • Workshops for Strategic AI Implementation: Sessions designed for executives and AI project leaders to align AI initiatives with business goals.

eLearning by DSN train

Training Demo by FIRST PRIVACY

Data Protection Compliance: Safeguarding Personal Data in AI Applications

In addition to the AI Act, organizations must comply with data protection regulations (GDPR) when processing personal data with AI systems. We provide full support in:

  • Data Protection Impact Assessments: Assessing AI applications for compliance with GDPR requirements.
  • Contractual and Documentation Review: Ensuring that data processing agreements and privacy notices meet legal standards.
  • Integration of Synergies: Leveraging overlaps between GDPR and AI Act requirements for high-risk AI systems.

Integrating AI into Your Information Security Management System (ISMS)

With AI playing an increasing role in organizational processes, ensuring the confidentiality, availability, and integrity of AI systems is crucial. We assist in integrating AI into an existing or new ISMS, such as those based on ISO/IEC 27001 standards.

Conducting Penetration Tests for AI Applications

AI systems, particularly those utilizing large language models (LLMs), may have vulnerabilities. We perform security scans and penetration tests on your AI applications, following OWASP Top 10 guidelines for LLMs, and provide detailed reports to help you address any security issues.

Let us support you in navigating AI compliance and maximizing the benefits of AI technology. Contact us to discuss how we can tailor our services to your specific needs.


Why Choose Us?

With over 20 years of expertise in compliance, data protection, and information security, we support businesses in navigating AI regulation complexities. Our solutions ensure that your AI initiatives remain compliant, ethical, and future-proof.

Contact Us for Customized AI Consulting!

Stay ahead of regulatory changes and unlock AI’s full potential while remaining compliant. Get in touch with our AI experts today for tailored guidance on implementing AI responsibly and in accordance with the AI Act.

Peter Suhren

Peter Suhren, Lawyer

Managing Director

Email: psuhren@re-move-this.first-privacy.com

Phone: +49 421 69 66 32-822

FIRST PRIVACY GmbH, Bremen

Cihan Parlar

Cihan Parlar, LL.M. (Tilburg), Lawyer

Managing Director

Email: cparlar@re-move-this.first-privacy.com

Phone: +31 20 211 7116

FIRST PRIVACY B.V., Amsterdam

If your inquiry concerns an organization based in Germany, these contacts will help you

Sven Venzke-Caprarese

Sven Venzke-Caprarese, Lawyer

Managing Director

Email: svenzke-caprarese@re-move-this.datenschutz-nord.de

Phone: +49 421 69 66 32-318

datenschutz nord GmbH, Bremen

Christian Borchers

Dr. iur.

Christian Borchers, Lawyer

Managing Director

Email: office@re-move-this.datenschutz-sued.de

Phone: +49 931 30 49 76-0

datenschutz süd GmbH, Würzburg

FAQ

AI Assessment Checklist for High-Risk AI Systems

If you're unsure whether your AI system falls under the regulations for high-risk AI systems, we provide an assessment checklist to help you determine its classification. You can access the checklist via the following link. Should you have any questions or need further assistance, please feel free to contact us anytime.

Checklist

We’re here to help you navigate the requirements and ensure compliance with the AI Act.