Skip to content

Support & Help

AI-powered answers to common questions, plus a community Q&A. Can't find what you need? Ask below.

Ask a Question

Common Questions

What is a high-risk AI system under the EU AI Act?
High-risk AI systems are listed in Annex III of the EU AI Act. They include AI used in: biometric identification, critical infrastructure, education, employment decisions, access to essential services, law enforcement, migration/asylum management, and administration of justice. These require conformity assessments, technical documentation (Art. 11), and human oversight (Art. 14).
When does the EU AI Act become fully applicable?
The EU AI Act has a phased rollout: prohibited AI provisions (Art. 5) applied from February 2025; GPAI model obligations (Art. 51-56) from August 2025; high-risk AI system requirements (Art. 8-15) fully apply from August 2026. Some high-risk systems in Annex I have until 2028 if already CE-marked.
When must a DPIA be conducted under GDPR?
Under GDPR Article 35, a Data Protection Impact Assessment (DPIA) is required when processing is "likely to result in a high risk" — in particular: systematic profiling with legal effects, large-scale processing of special category data, systematic monitoring of publicly accessible areas, and automated decision-making with significant effects on individuals.
What is the GDPR 72-hour breach notification requirement?
Under GDPR Article 33, a personal data breach must be notified to the relevant supervisory authority "without undue delay and, where feasible, not later than 72 hours after having become aware" of it. If notification is not made within 72 hours, a reasoned justification for the delay must be provided.
What are the maximum fines under the EU AI Act?
The EU AI Act provides for fines up to €35 million or 7% of total worldwide annual turnover (whichever is higher) for violations of the prohibited practices (Art. 5). For other violations of high-risk AI requirements: €15 million or 3% of turnover. For providing incorrect information to authorities: €7.5 million or 1% of turnover.
Does the EU AI Act apply to my business outside the EU?
Yes. The EU AI Act has extraterritorial scope. It applies to: (1) providers placing AI systems on the EU market regardless of where they are established, (2) providers whose AI systems output is used in the EU, (3) importers and distributors of AI in the EU. Similar to GDPR, if your AI affects EU residents, you are likely covered.
What is NYC Local Law 144 about AI in hiring?
NYC Local Law 144 requires employers using automated employment decision tools (AEDTs) in NYC to conduct annual bias audits by independent third parties, publish summary results publicly, and notify candidates/employees before using AEDTs. Violations can result in fines of $500 for a first violation, $500–$1,500 per day for each subsequent violation.
What is the Colorado AI Act (SB 21-169)?
Colorado SB 205 (AI Act) imposes requirements on developers and deployers of "high-risk" AI systems making consequential decisions (employment, education, lending, housing, healthcare). Requirements include: bias risk assessments, disclosure to consumers, and opt-out rights. Enforced by the Colorado AG.
What does SOC 2 Type II require for AI systems?
SOC 2 Type II requires evidence of controls operating effectively over a period (typically 6-12 months). For AI systems: the Trust Service Criteria (CC6, CC7, CC9) require: logical access controls, change management for model updates, risk assessment of AI vendor relationships, availability monitoring, and incident response procedures including model failures.
What is the NIST AI Risk Management Framework?
NIST AI RMF (2023) provides a voluntary framework with four core functions: GOVERN (establish culture and accountability), MAP (identify context and risks), MEASURE (analyze and assess risks), MANAGE (prioritize and respond to risks). It maps to AI Act categories and can be used alongside ISO 42001 as an implementation guide.

Need urgent help? Use the in-app feedback form (signed-in users) for faster response.

Legal matters, press inquiries, and payment disputes are handled by a human within 3 business days.