目录 Risk assessment

Policing and borders

Risk assessment

AI border assessment of a person’s security, irregular-migration or health risk is generally listed as high-risk, not prohibited. A qualifying narrow, preparatory or assistive system without material decision influence or significant risk may be classified otherwise, but profiling remains high-risk. The associated AI Act duties are scheduled for 2 December 2027. Until then, using AI for this purpose is not unlawful merely because it is AI, but other Union and national law, including data-protection law, still applies.12

From that date, Articles 9 to 16 will require providers of qualifying systems to manage risks, govern datasets, keep logs and documentation, support human oversight, and address accuracy, robustness and cybersecurity. Article 26 will require border-authority deployers to appoint competent oversight, use controllable relevant input data, monitor operation, suspend risky use and retain controllable logs. Article 74(8) authorities will enforce these provider and deployer duties.12

Article 27 will also require a public border authority to complete a fundamental-rights impact assessment before first deployment and notify the market-surveillance authority. The deployer bears this duty, the Article 74(8) authority enforces it, and it starts on 2 December 2027. Under Article 26(11), the deployer will generally have to tell affected people that high-risk AI is being used, with law-enforcement processing following the Law Enforcement Directive information regime instead. The same authority and start date apply.1 These organisational duties are not personal rights to admission or a favourable assessment.

Since 2 August 2026, Article 86 has given a significantly and adversely affected person a right to an explanation from the deployer about a qualifying Annex III system’s role and the decision’s main elements, subject to Union or national restrictions and only where Union law does not already provide that right. Article 85 permits a complaint to the relevant market-surveillance authority.1 How Article 86 operates before Annex III classification begins has not been resolved. The Act sets no request format, response deadline or dedicated appeal route, and, as of 7 September 2026, the Commission list still had blank or pending national designations.3

Where the GDPR governs, Article 15 lets you seek your personal data and information about qualifying automated decision-making. Article 22 restricts solely automated decisions with legal or similarly significant effects and requires safeguards in specified permitted cases. The controller bears these duties, national data-protection authorities and courts enforce them, and they have applied since 25 May 2018. Article 77 supplies a data-protection complaint route.4 For criminal-law-enforcement processing, the Law Enforcement Directive may apply instead.

Boundary. The applicable data-protection law depends on the authority, purpose and system. National-security systems and qualifying cooperation systems can fall outside the AI Act. Some older components of specified large-scale EU border systems have a separate transition until 31 December 2030.1

参考文献

测验
  1. Complete the general rule: qualifying border risk assessment is ____, although a qualifying narrow, preparatory or assistive system without material influence or significant risk may be classified otherwise, and profiling remains high-risk.

    • generally high-risk rather than prohibited
    • automatically unlawful everywhere
    • outside all regulatory safeguards

    The Act generally lists these systems as high-risk. Qualifying narrow, preparatory or assistive systems may be classified otherwise, but profiling always remains high-risk.

  2. Where the GDPR governs a border authority, which action can address personal data used in an assessment?

    • Request access to personal data and complain to a data-protection authority
    • Use the AI Office complaint form as the universal appeal route for national border-authority decisions
    • Wait until every deferred high-risk duty has entered into application

    GDPR access and complaint routes already apply where the GDPR governs, independently of the delayed AI Act safeguards.

  3. A border risk assessment is already prohibited whenever software contributes to the authority’s evaluation.

    • True
    • False

    AI involvement alone does not trigger a prohibition. Existing data-protection and other applicable laws can still restrict the assessment.

评论

还没有评论,来说第一句吧。