Artificial intelligence (hereinafter “AI”) has already become an integral part of modern business operations. Companies use AI to automate processes, generate text and images, analyze large datasets, recruit staff, assess credit risks, provide customer service, and make management decisions. At the same time, the rapid development of these technologies has presented governments with new challenges: how to ensure the safe use of artificial intelligence without stifling innovation.
The European Union (EU) Regulation 2024/1689, better known as the AI Act, was created in response to these challenges. It is the world’s first comprehensive regulatory act establishing uniform rules for the development, deployment, and use of AI systems. Although the document applies directly to EU countries, its impact is already being felt by companies around the world, including Ukrainian businesses that collaborate with European partners or operate in the European Union market
What Is the AI Act and Why Is Its Adoption a Historic Event?
Before the AI Act, most countries did not have specific legislation that comprehensively regulated the use of AI. Legal issues were addressed through regulations on personal data protection, copyright, manufacturer liability, or consumer protection.
However, with the development of generative artificial intelligence and the emergence of ChatGPT, Gemini, Copilot, and other AI systems, it has become clear that existing mechanisms are no longer sufficient. Algorithms have begun to influence decisions regarding employment, lending, medical treatment, education, and even the activities of government agencies.
That is why the European Union decided to establish uniform rules that would simultaneously stimulate technological development and guarantee the protection of fundamental human rights.
The main feature of the AI Act is that it does not ban the use of AI. Instead, the Regulation sets requirements based on the level of risk posed by a specific system.
How the AI Act Classifies AI Systems
The new regulation is based on a risk-based approach. The regulation divides AI systems into several categories depending on their potential impact on human rights and safety.
“Unacceptable risk” refers to systems whose use in the European Union is effectively prohibited. These include technologies that can manipulate human behavior, conduct mass social scoring of citizens, use biometric data without proper justification, or otherwise violate fundamental rights.
High-risk systems are those used in the fields of healthcare, education, employment, banking, insurance, law enforcement, critical infrastructure, and public administration.
These systems are subject to the strictest requirements regarding risk assessment, technical documentation, data quality control, human oversight, and cybersecurity.
The “limited risk” category includes, in particular, generative AI systems and chatbots. In such cases, the main requirement is transparency. The user must be aware that they are interacting with AI, not a human.
The “minimal risk” category includes systems whose use does not require additional legal requirements. Examples include recommendation algorithms or machine translation tools. This approach helps avoid overregulation and focuses attention specifically on those AI solutions that can have a real impact on people’s lives.
The Corporate Sector: What to Do Today
The AI Act not only establishes new legal requirements but also fundamentally changes the approach to corporate governance.
Companies are already advised to conduct an internal audit of their AI usage. First and foremost, they need to identify exactly which AI tools are used in their operations, for which processes they are applied, and what potential risks may arise.
Special attention should be paid to the use of generative AI for creating text, marketing materials, program code, images, or analyzing personal data.
It is also advisable for businesses to develop internal policies on AI use, designate responsible individuals, update contracts with digital service providers, and establish mechanisms to monitor employees’ use of artificial intelligence. Such measures are gradually becoming an integral part of corporate compliance, alongside policies on personal data protection, cybersecurity, and anti-corruption.
How Does the AI Act Relate to Intellectual Property?
The issue of intellectual property deserves special attention. Modern generative AI models are trained on vast amounts of information, including books, photographs, musical works, source code, videos, and other copyrighted works. This has been the cause of numerous legal disputes between authors and developers of AI systems.
The AI Act does not directly amend copyright law, but it does establish transparency requirements for providers of general-purpose AI (GPAI) models. Specifically, they must provide information about the use of copyrighted materials and comply with EU intellectual property law.
For companies that use generative AI in their operations, this means they need to pay closer attention to issues of copyright, content licensing, and the legality of using AI-generated output.
EU Regulation 2024/1689 (the AI Act) is the first comprehensive piece of legislation to establish rules governing the operation of AI. Its adoption signals that AI is gradually transitioning from the realm of innovative technologies to that of clear legal regulation.
For Ukrainian businesses, this means that it is already time to assess their own AI usage processes, develop internal policies, and take these new requirements into account when collaborating with European partners. Timely adaptation will not only help avoid legal risks but also enhance the company’s competitiveness in the international market.
If your company uses AI solutions or plans to integrate AI into its business processes, please contact our law firm. We will help you assess legal risks, develop the necessary documentation, and ensure that your operations comply with current AI legislation.



