
Lawyers: Purely Legal Professionals or Multidisciplinary Individuals?
August 4, 2026
The AI Act and the Risk-Based Approach to AI Use
August 4, 2026
What Will Be the Role of Law in Enforcing the Rules Governing the Use of Artificial Intelligence?
Are Member States technically prepared to deal with issues of such technological complexity? Where do algorithms and data fit within the legislative framework?
Law has traditionally been reactive rather than proactive. This was the case with the regulation and taxation of cryptocurrencies, and it will certainly be the case with artificial intelligence (hereinafter referred to as “AI”).
The question is what kind of “fire hose” will be needed to extinguish a fire that spreads at the speed of light, leaving no time for the “firefighters” trying to contain it.
On 13 March, the European Parliament approved the Artificial Intelligence Act, a landmark European regulation designed to safeguard fundamental rights, the rule of law, and the environment, while establishing a comprehensive set of rules that will apply across the European Union.
Each Member State will be required to designate one or more competent national authorities responsible for supervising the implementation and enforcement of the Regulation.
In addition, the European Artificial Intelligence Board will be established as an advisory body in which every Member State will be represented by a national supervisory authority. Industry, start-ups, SMEs, civil society, and academia will all have the opportunity to contribute to discussions as stakeholders, alongside representatives of the European Data Protection Authority and the European Commission.
Furthermore, the European Commission will establish a European AI Office, which will oversee general-purpose AI (GPAI) models, such as the well-known ChatGPT, cooperate with the European Artificial Intelligence Board, and receive support from an independent scientific panel of experts.
The AI Act adopts a risk-based approach, defining four levels of risk for AI systems while also identifying specific risks relating to general-purpose AI models. Whether dealing with minimal-risk, high-risk, unacceptable-risk, transparency-related risks, or systemic risks (associated with large generative AI models), the underlying objective is always to ensure compliance with European legislation.
This raises an important question: how will compliance actually be ensured? By taking preventive measures before the fire season begins, or by relying on firefighters once the flames are already out of control?
AI is here to stay. It is already being used—or soon will be used—by businesses and individuals alike. Compliance with the Regulation will be mandatory through an appropriate conformity assessment procedure.
Are Member States technically prepared to deal with issues of such technological complexity? Where do algorithms and data fit within the legislative framework?
Will tomorrow’s lawyers need at least a basic understanding of programming, software engineering, and data science? I am inclined to believe so. Otherwise, we would be like judges at a swimming competition who cannot swim themselves—let alone assess the technique of a good front crawl.
One thing is undeniable: it will be lawyers (and other legal professionals) who will ultimately be responsible for certifying the compliance of AI platforms, ensuring that they operate in accordance with the applicable legal framework.
The Regulation is expected to be formally adopted before the end of the parliamentary term (May 2024). It will enter into force 20 days after its publication in the Official Journal of the European Union and will become fully applicable 24 months later, subject to certain exceptions.
Penalties for non-compliance may reach up to €35 million.
Will we choose prevention or reaction?
Rodrigo Vilela de Matos 29 April 2024




