5 Comments
User's avatar
Marius Laurusevicius's avatar

The Omnibus used a fourth technique, one that sorts by size rather than sector. Point 26 replaces Article 63(1): SMEs, including start-ups, may comply with certain elements of the Article 17 quality management system in a simplified manner, where the original text limited that to microenterprises. The condition is narrow. The company must have no partner or linked enterprises within the meaning of Recommendation 2003/361/EC, so a small firm inside a group is out. Which elements can be simplified is not settled either. The Commission is to develop guidelines, with no date in the text.

Silvia Stepitova's avatar

I think it's worth being precise about what that relief is. It's a documentation concession, not fewer obligations. And it isn't really usable until the Commission says which elements, and those guidelines have no date yet.

Robert J. Blanchette's avatar

Silvia, your discussion just before “What to Do”—where you distinguish GDPR Article 22 from the AI Act’s Article 86 explanation right—raised a question for me.

You note that the boundary between a decision made by an automated system and a decision made by a person on the basis of AI output is increasingly difficult to draw, particularly after SCHUFA. That seems to create a problem underneath the legal classification itself:

What evidence actually establishes that the consequential decision was substantively made by the human, rather than by the AI system or by the coupled human–AI process?

A human may be formally responsible, review the output, have authority to override it, and leave a complete audit trail. But those facts do not necessarily establish that the human was causally determinative in the outcome.

That also made me read point 4 of your “What to Do” section differently. When two rules pull in different directions, you suggest deciding and documenting the reasoning. That clearly establishes provenance and organizational authority. But I wonder whether there is a separate question about the evidential standing of any causal attribution underlying that decision.

In other words: documented human oversight, formal decision authority, and identifiable human causal control may be three different things.

I’d be very interested in how you see that distinction fitting into the Article 22 / Article 86 overlap you describe.

Silvia Stepitova's avatar

You're right that they're three different things, but only two get tested. What the court asks is whether the output determined the outcome, and the usual proof is how often the human ever overrode it.

Robert J. Blanchette's avatar

Your answer helped me locate the distinction. I have a short paper translating the formal identifiability problem into legal attribution. §2.3 is closest to what I was asking: not whether override frequency is legally usable evidence, but whether the available evidence identifies the underlying causal structure. I’d be interested whether you think that distinction matters in practice. Have a great day. https://doi.org/10.5281/zenodo.19998537