Uppsats

Safeguarding Citizens' Rights in the Age of Artificial Intelligence – Whose Responsibility? Examining Fundamental Rights Provisions in the EU AI Act

Yrkesexamen på avancerad nivå

Lunds universitet/Juridiska fakulteten

Publicerad: 2025

Språk: Engelska

Sammanfattning

AI systems are increasingly integrated across numerous sectors. While AI systems can bring efficiency gains, AI systems can also entail risks to fundamental rights of citizens. The EU AI Act tries to solve this through a risk-based approach which introduces legal obligations for providers and deployers of high-risk AI systems. This thesis explores the provisions for AI providers and deployers which require these actors to assess how AI systems affect fundamental rights. Specifically, it analyses the risk management system for providers, as well as the governance and monitoring requirements, and the fundamental rights impact assessment for deployers. The thesis examines and compares the scope of the provisions and what the different assessments encompass. The obligation to establish a risk management system applies to all providers of the so-called high-risk AI systems. Similarly, the governance and monitoring requirements apply to all deployers of high-risk AI systems. However, the requirement to perform a fundamental rights impact assessment only applies to bodies governed by public law, private entities providing public services, as well as banking and insurance service providers. The purpose of this was to reduce compliance costs for small and medium enterprises and not hinder innovation. The EU legislator wants the EU to reap the benefits of AI and compete with other global actors. Yet, this limited scope is problematic as private actors may also have significant impact on fundamental rights of citizens. Moreover, the relevant provisions are vague and leave a too big margin of discretion for private actors. Thus, the AI Act has been criticised for introducing fundamental rights provisions with a too limited scope and letting private actors decide themselves whether they comply with the AI Act. The EU legislator has justified the limited scope with the fact that the AI Act is complementary to other frameworks. These include fundamental rights frameworks, product safety regulations (GPSR and PLD), the General Data Protection Regulation (GDPR) and the Digital Services Act (DSA). Thus, the thesis assesses the extent to which these frameworks fill in the gaps where the AI Act is either not applicable or lacking in its protection of fundamental rights. The study finds that the purpose of the product safety regulations is not to protect fundamental rights on a general level, and do not properly safeguard rights apart from consumer protection. The GDPR is a comprehensive framework which aims to protect the right to personal data and could fill in some of the gaps where the AI Act is not applicable. The DSA aims to protect fundamental rights in the online setting. While there are shortcomings, the DSA is a step towards ensuring accountability for platforms that implement AI systems. The thesis also assesses the room for Member States to pass their own AI legislation to protect fundamental rights in relation to AI. As the AI Act is a regulation which aims to ensure harmonisation, there is limited room for Member States. Nevertheless, the AI Act allows for Member States to pass legislation to a certain extent in limited areas.

Information

Författare
Liljeblad, Ebba
Lärosäte / institution
Lunds universitet/Juridiska fakulteten
Publiceringsdatum
2025
Uppsatstyp
Yrkesexamen på avancerad nivå
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.