The public debate on the European artificial intelligence regulation has focused on who develops it. For most of our clients, the relevant question is another: what obligations do they assume when implementing a system in their company that has been built by someone else.
Risk level classification
The regulation categorises systems into prohibited practices, high-risk systems, systems subject to transparency obligations, and the rest, with obligations proportional to each level. The category that affects most conventional companies is high risk, because it includes widely used applications in human resources, such as candidate screening or performance evaluation tools.
The person responsible for deployment also has duties
Using the system according to its instructions, assigning human supervision to persons with sufficient competence and authority, monitoring the operation, keeping the generated records, and informing affected workers. These are obligations of the user company and are not transferred to the provider by signing a contract, although the contract does determine who is liable to the other.
Where the claim comes in
The scenarios we already see are not science fiction: an automated selection decision challenged for discrimination, a predictive maintenance system that fails to warn of a fault, an assistant providing incorrect information to a client who follows it. The claim comes through general civil liability if there is damage to a third party, or through professional civil liability if the system is part of a service provided.
What to review in the policy
Three things. That the declared activity includes the use of automated systems, because an old definition may leave the scenario out. That a generic exclusion of artificial intelligence has not been incorporated, which some insurers have started to introduce. And that professional civil liability considers system error and not just human error, a distinction that a policy wording drafted five years ago did not anticipate.



