scieee AI-readable full text Open interactive document viewer

EXPLORING THE EU ARTIFICIAL INTELLIGENCE ACT: PERSPECTIVES OF PROFESSIONALS IN FINLAND

Mensah, Benjamin

Full text

Benjamin Mensah EXPLORING THE EU ARTIFICIAL INTELLIGENCE ACT: PERSPECTIVES OF PROFESSIONALS IN FINLAND UNIVERSITY OF JYVÄSKYLÄ FACULTY OF INFORMATION TECHNOLOGY 2024 ABSTRACT Mensah, Benjamin Exploring the EU artificial intelligence act: Perspectives of professionals in Finland Jyväskylä: University of Jyväskylä, 2024, 57 pp. Information Systems, Master’s Thesis Supervisor(s): Seppänen, Ville As artificial intelligence continues to find its way into our lives, with or without our consent. There has been the need to put safeguards in place to ensure it operates within acceptable standards. Governments and organizations want to ensure the rights of citizens are protected over business interests, hence the introduction of the European Union artificial intelligence act. The European Union's Artificial Intelligence Act (EU AI Act) represents a significant regulatory effort to govern the development and deployment of AI technologies across member states. This master’s thesis researches the perspective of professionals in Finland on the EU AI act using qualitative research approach including semi-structured interviews and conventional content analysis. Key themes emerged, highlighting the act's focus on ethics, transparency, accountability, and bias mitigation. The study interviewed 9 professionals in Finland whose work involved AI and had some knowledge about the regulation. The findings suggest that while the EU AI Act is viewed as a critical step towards embedding ethical AI practices and fostering public trust, the study also revealed concerns about the potential impact on innovation and the variability in awareness and understanding of the Act among professionals. These insights contribute to the broader discourse on AI regulation, emphasizing the need for continuous policy development, technological innovation, and interdisciplinary collaboration to address evolving challenges. Future research should consider larger, more diverse professionals, the use of surveys, and comparative analyses across different fields like healthcare, legal, manufacturing and consumer services to further understand the Act's impact and effectiveness. Keywords: Artificial Intelligence, EU AI Act, bias, ethics, transparency Glossary AI Artificial Intelligence EU European Union GDPR General Data Protection Regulation FRIA Fundamental Rights Impact Assessment DPIA Data Protection Impact Assessment ML Machine Learning DL Deep Learning HLEG High Level Expert Group NLP Natural Language Processing DORA Digital Operational Resilience Act FIGURE 1: Types of machine Learning (Agbese, 2021) ......................................... 17 FIGURE 2: Layers of Neural Network (Garg et al., 2020) ...................................... 18 FIGURE 3: Opportunity and risk model of AI (Floridi et al., 2018) ..................... 20 FIGURE 4: EU AI Act pyramid of risk(Sisodia, 2023) ............................................ 23 FIGURE 5: China’s Artificial Intelligence Development Plan (AIDP)(Roberts et al., 2021) ............................................................................................................................... 25 FIGURE 6: Proposed bias reduction model(Buiten, 2019) ..................................... 28 TABLE 1: Job title of interviewees ............................................................................. 30 TABLE OF CONTENTS ABSTRACT FIGURES TABLES Table of Contents INTRODUCTION ....................................................................................... 8 1.1 Overview of Artificial Intelligence (AI) and its applications ................ 8 1.2 Introduction to the EU Artificial Intelligence Act ................................... 9 1.3 Significance of the topic ............................................................................ 10 1.4 Research Questions .................................................................................... 11 2 LITERATURE REVIEW ................................................................... 13 2.1 Overview of AI regulation ....................................................................... 13 2.2 Functional Classification of AI ................................................................. 15 2.3 Methodology based classification ........................................................... 16 2.3.1 Machine Learning (ML) ...................................................................... 16 2.3.2 Deep Learning (DL) ............................................................................ 17 2.4 Global trends in AI regulation ................................................................. 18 2.5 Key principles and objectives of AI regulation ..................................... 19 2.6 The EU Artificial Intelligence Act............................................................ 20 2.6.1 Summary of key provisions and guidelines ........................................ 21 2.6.2 Risk-Based classification of AI System .............................................. 22 2.6.3 Requirements for High-Risk AI Systems ............................................ 23 2.6.4 Comparison with other AI regulatory frameworks ............................. 24 2.7 Previous studies on professionals' attitudes towards AI regulation .............. 26 2.8 Factors influencing professionals' perceptions of AI regulation .................. 26 6 3 METHODOLOGY ............................................................................ 29 3.1 Research Design: Qualitative Research Approach ............................... 29 3.1.1 Selection criteria for participants ................................................... 29 3.2 Data Collection ............................................................................................. 30 3.3 Data recording and transcription procedures ................................................ 31 3.4 Data Analysis ................................................................................................ 32 3.4.1 Conventional content analysis approach ...................................... 32 4 RESULTS............................................................................................ 33 4.1 Background and Perspectives ....................................................................... 33 4.1.1 Knowledge and understanding of artificial intelligence and the EU AI Act ....................................................................................................... 33 4.1.2 Areas of clarity and confusion ............................................................ 35 4.1.3 Effects on Organisations in Finland .................................................... 36 4.1.4 On innovation and technological development ................................... 36 4.1.5 Accountability,Explainability/Transparency,Bias and Ethical Consideration .................................................................................................. 37 4.1.6 Identified challenges in complying with the EU AI Act ..................... 39 4.1.7 Recommendations for improving AI regulation and implementation. ............................................................................................................. 40 5 DISCUSSION .................................................................................... 42 5.1 Interpretation of findings in relation to research questions ................ 42 5.2 Implications for the implementation of the EU AI Regulation in Finland .............................................................................................................. 42 5.3 How the findings contribute to the broader understanding of AI regulation .......................................................................................................... 43 5.4 Discussion of unexpected findings or contradictions .......................... 43 5.5 Limitations and future research .............................................................. 44 6 CONCLUSION ................................................................................. 45 7 6.1 Answers to Research Questions .............................................................. 45 7 REFERENCES ................................................................................... 47 APPENDIX 1: INTERVIEW FORM AND QUESTIONS IN ENGLISH 53 INTRODUCTION 1.1 Overview of Artificial Intelligence (AI) and its applications The term artificial intelligence (AI) has become a common term in the Information technology arena, however, there are different explanations for this term. There is no single definition for artificial intelligence (Čerka et al., 2017) . According to (Perucica & Andjelkovic, 2022) the first AI workshop was held in 1956 at Dartmouth under the direction of American mathematician John McCarthy. Any object which mimics the characteristics of humans as a result of the information fed to it can be described as artificially intelligent. (Trotta et al., 2023)defined AI as, a machine with human-like intelligence and capacity for learning. Artificial Intelligence involves the use of computers to replicate human consciousness, identity and thought processes to offer a new level of human-computer interaction (Zhou, 2021). (European Commission. Joint Research Centre., 2020) describes AI systems as being either through the use of symbolic rules or learn a numeric model, and they can also adapt their behaviors by analyzing how the environment is affected by their previous actions. For instance, (Besinovic et al., 2022) explained that, machine learning, deep learning and big data is used by scientists as the basis for AI definition whiles practitioners use different terms resulting in a confusion of the unique definition. Countries and regional AI regulations have also restricted the definition to suit the scope of their laws(Bradley, 2022). The OECD defines AI as, ’A machine-based system that can for a given set of humadefined objectives, make predictions, recommendations, or decisions influencing real or virtual environments and operating with a certain level of autonomy’(OECD, 2024). The confusion for AI definition was due to the subjective nature of intelligence and the field, the AI was being applied(Buiten, 2019). The Oxford dictionary defines AI as ‘the capacity of computers or other machines to exhibit or simulate intelligent behaviors; the field of study concerned with this. In later use also: software used to perform tasks or produce output previously thought to require human intelligence, esp. by using machine learning to extrapolate from large collections of data’(OED, n.d.). (OED, n.d.). In their article, 9 (Kolfschooten, 2022) defined AI as rational behaving systems using their environment and information to determine the best action to take for a given assignment. According to (Lazăr Pleşa et al., 2023) John McCarthy originally suggested in 1955 that ten people study artificial intelligence for two months in order to figure out how to educate computers to develop thoughts and solve issues that could only be resolved by humans Artificial Intelligence (AI) has become the leader in disruptive technologies causing a lot of transformations which are accelerating the impact of use-cases. Artificial intelligence (AI) has become established far more quickly than other cutting-edge technologies since so many businesses are utilizing it to improve their operations. The pervasive nature of AI can be seen in how people interacts with robots, how crime is solved, who gets a loan and medical diagnosis(Bartneck et al., 2023). This technology has been used to create music, poetry and unique artworks which has enhanced people’s lives. AI systems used to be transactional, that is basically input/output, but we now have generative AI in the music and entertainment industry. AI can now be compared to electricity since it can be found in any household directly or indirectly (Pathni, 2023)This can be seen in voice assistants, televisions, mobile phones, temperature regulation sensor etc. Artificial intelligence usage has seen a rapid increase with the advent of generative AI and use of prompt engineering, causing a concern among stakeholders. According to (Pathni, 2023), the revolution introduced by AI’s have resulted in transformations in businesses leading to a spike in their efficiency, however, the autonomy in the AI’s performance is an area of concern. The era of AI being a fiction in movies is now a thing of the past and now a common tool available to anyone with internet access. Just like fire, AI can be of good use and can also be used to cause harm making it necessary to have safeguards in its use. In fields like healthcare, AI’s have produced potential new drugs, treatment and speed up drug discovery. In the railway sector, AI is used to assist decision making by suggesting appropriate methods to researchers (Besinovic et al., 2022). In the manufacturing sector, it has revolutionized new products designs, innovation and efficiency. In education, AI technologies have produced virtual and customized tutors for students with learning challenges. Concerns of stakeholders include proprietary information, data protection, privacy, risk and obligations(Rakha, 2023). Without robust regulation for AI usage, people and organizations may use it unethically without consideration for human values. 1.2 Introduction to the EU Artificial Intelligence Act Please The transformations associated with artificial intelligence applies to small things like language translation to bigger one’s like diseases prediction. This transformation has made it important to find the right way to use AI to help in 16 2.3 Methodology based classification This involves classifying AI systems based on the methodology used for the algorithm. 2.3.1 Machine Learning (ML) This AI learns from data, which is called the training data and is the popular methodology used in most AI systems. Due to its extensive application, most research is based on machine learning models. (Ma & Sun, 2020) attributed the popularity of ML to the vast amount of data generated daily from interactions with people and machines could be processed by ML models. ML is further divided into: • Supervised Learning: labelled data is used to train the algorithm in this instance (LeCun et al., 2015). The algorithm uses the data to make prediction by drawing inference and exploring the connection in the data(Ma & Sun, 2020). Supervised ML is used in developing models using big datasets. • Unsupervised Learning: The algorithm in this ML identifies patterns in unstructured data. This is an exploratory nature where only the inputs is fed the algorithm with no defined constraints. According to (Ma & Sun, 2020) data of different format and types is ideal for unsupervised learning processing. • Reinforcement Learning: Systems learn by interacting with their environment and receiving feedback (Sutton & Barto, 2018). This method uses discovery to come up with which action produces the best results by allowing the algorithm to be intuitive. This is further corroborated by (Ma & Sun, 2020) by describing reinforcement learning as observation and interaction with the environment for results optimization. The ability to use data in whichever format to make decisions and produce results makes ML ideal for exploring AI systems. The processing of these data is based on the design in the complex processing which is effective in prediction than explanation for the results. The types of machine learnings is presented in figure 1. 17 FIGURE 1: Types of machine Learning (Agbese, 2021) 2.3.2 Deep Learning (DL) A subset of machine learning known as "deep learning" makes use of hierarchical designs to facilitate unsupervised learning. The developed models are applied to classification and related tasks. (LeCun et al., 2015) defined deep learning as a branch of machine learning that uses multi-layer neural networks. DL has demonstrated efficacy in domains including voice and picture recognition. By using hierachies, it analyses from the basic to the highest level. Hierarchical learning involves understanding both basic and complex features through multiple layers of activations, which can be either linear or nonlinear. This approach aligns with the deep learning techniques used in modern multi-layer neural networks(Usama et al., 2019). Deep learning is used predominatly in natural language processing, computer vison and speech recognition. The basis of deep learning is on the concept of how the brain function, using several nodes and touch points. The algorithms in deep learning is neural networks. Neural networks as the name suggest consist of nodes, which are interconnected to form a network mesh facilitating communication accross the various nodes. These nodes are represnt a weight adjusted during training. The neural networks 18 operates with three (3) layers namely, input , hidden and output. A basic illustration of neural networks is depicted in Figure 2. FIGURE 2: Layers of Neural Network (Garg et al., 2020) In the field of image classification, facial recognition and object detection, deep learning has provided alot of success (Krizhevsky et al., 2017). Neural networks have also been used in text generation, transalation and sentimental analysis resulting in an improved performance of NLP applications(Vaswani, et al., 2023). Deep learning also involves the use of intensive computational resources which requires more memory and compute resources. It also faces the coomon problem of artificial intelligence blackbox processing the interprectation and validity of their results questionable. 2.4 Global trends in AI regulation The need for AI regulation has become necessary in Europe due to its high application in every field of discipline. In addition, the United States of America and China have a regulation for using AI and Europe implementing this regulation will protect and help businesses to provide assurance to their stakeholders. Countries like China and the United States of America has passed laws on artificial intelligence regulation. Intentional abuses including deepfakes, cyberattacks, warfare, people-manipulation, espionage, and poor levels of democracy can lead to certain problems (De Almeida et al., 2021). For China’s AI regulation, the focus is on content control which was categorized as a secondary risk. China's 2015 internet action guidelines took society and the economy into consideration while allocating resources for AI research and development (Roberts et al., 2021). They seek to solve issues with algorithmic bias and prejudice, information abuse and distortion, content moderation, and transparency. China also considered a balance between service provider obligations and innovation and governance, as 19 opposed to service user supervision. Furher, the chinese approach is limited to its technological and industrial policies, this is in line with China’s New Generation AI development plan with fcous on areas like data governance and ethics. The united states has no comprehensive national AI laws although, it is part of the countries with the most AI services. By using the National Institute of Standards and Technology (NIST), safeguards are provided for AI related risk management. The GDPR was used as a compensating law to regulate some aspects of AI technologies in the EU due to the strict data protection rules. (Gasser & Almeida, 2017) advocated for an adapive regulation for AI which will offer flexible regulatory frameworks thereby producing sandboxes to try and refine these laws. As AI continue to evolve, the use of adaptive regulations will offer a windows for timely adjustment when new concerns arise which demands to be checked. 2.5 Key principles and objectives of AI regulation The need to regulate artificial intelligence was emphasized when, an experiment was conducted to see how these algorithms will behave when unregulated, In an experiment reported by(De Almeida et al., 2021), a game involving two algorithms, it was projected that one would only eliminate the other if there was an extreme lack of resources, however, the weaker algorithms were instantly eliminated by the introduction of a more sophisticated one. By this experiment, the need to regulate artificial intelligence becomes critical since ethical issues need to be considered in the design and deployment of AI systems. Human values need to be embedded in these systems, but in the absence of that, there need to be checks and balances on their use. The lack regulation to back ethics in artificial intelligence was discussed by (Vakkuri et al., 2019)as lacking practical implementation, since they were just guidelines and principles which had no consequential penalties when ignored. (Munoko et al., 2020)used data and algorithm related concerns to point some ethical issues, they described that people may be unaware of AI capturing their activities, information and trend in terms data concerns whiles algorithmic concerns involve intelligence, opacity and retrieval. In the absence of regulation, organizations do things their own way without compliance and focus only on profits whiles giving less attention to the concerns of customers. Using artificial intelligence to perform task is efficient, however, when technology influences human behavior, an ethically acceptable form of that technology is needed (Munoko et al., 2020). Concerns about privacy, safety bias and transparency have been some of the arguments for promoters of AI regulation. AI systems use bigger datasets which have the tendency to include personal data causing concern about data storage and usage when left unchecked. The risk of using 20 personal data in AI model training is a concern for stakeholders(Mittelstadt, 2019). By knowing the data used to train the algorithms and AI systems, the issue of transparency and explainability can be addressed to give assurance that decisions were made in a fair transparent manner. (Doshi-Velez & Been, 2017) explained that ethical consideration in AI regulation should be transparent to provide explanations related to their decisions. The opportunities and risk associated with AI was graphically summarized by (Floridi et al., 2018) how AI could be used (opportunities) and misused or overused (risks). This was given as 1) enabling human self-realization, 2) enhancing human agency, 3) increasing societal capabilities and 4) cultivating societal cohesion for opportunities whiles the corresponding risk was 1) devaluing human skills, 2) removing human responsibility, 3) reducing human controls and 4) eroding human self-determination. The model is presented below in Figure 3. FIGURE 3: Opportunity and risk model of AI (Floridi et al., 2018) In order for society to maximise the opportunity of AI to foster social progress, there has to be self realisation without devaluing human abilities(Floridi et al., 2018). 2.6 The EU Artificial Intelligence Act The European Union’s white paper on artificial intelligence regulation gave the extensive stakeholder engagement it undertook before coming out with the proposed regulation. The use of the High-Level Expert Group (HLEG) was a means of ensuring concerns about the law were considered. According to (Samoili et al., 2021) the European Commission defined AI to have: 21 • Information processing, which involves gathering and analyzing input data. • Environmental awareness, recognizing and understanding the complexities of real-world environments. • Achievement of specific goals, the primary purpose of AI systems is to successfully achieve predefined objectives. • Decision making (including reasoning and learning): with a certain level of autonomy making informed decisions and performing tasks which consist of responding and adapting to changes in the environment. The effect of the law is yet to be felt since it is not yet operational, however, stakeholders envisage the effect of the regulation when it comes into force. According to (Tallberg et al., 2024) the release of ChatGPT for academic and content creation in November 2022 was part of the catalyst for the debate of AI regulation, resulting in evaluation of citizens attitudes of AI regulation. The regulation's regulatory framework, the scale of the EU's digital market, and its policies on developing technologies make it crucial for research (Justo-Hanani, 2022). (Albawwat & Frijat, 2021) explained that, prior to implementing any new intervention, stakeholders must be persuaded that it would improve their services; this can be done by looking at perceived utility and benefit to their customers. The implementation of quality control and compliance monitoring following the regulation's ratification will enable an assessment of the risks associated with artificial intelligence. Individuals have rights under the GDPR regarding their personal data; nevertheless, these rights extend to AI systems whenever personal data is used, regardless of where the system is developed or deployed. The AI Act encourages innovation by utilizing regulatory sandboxes—controlled environments where companies can develop and test AI systems under regulatory oversight(Gasser & Almeida, 2017). This setup enables the experimentation with AI technologies while ensuring adherence to legal and ethical guidelines. 2.6.1 Summary of key provisions and guidelines The EU AI regulations text is being finalized as member states consider it for ratification before adoption. Being the first comprehensive legislation in the world, it will influence upcoming AI regulations across the world. The regulation adopted (OECD, 2024)definition for artificial intelligence. For general purpose AI (GPAI), there needs to be provided documentation to show compliance with the EU intellectual property laws. Some AI systems were categorized as banned unless for the purposes of research and security and intelligence work. Some of the 22 actions classified as prohibited are emotional recognition, biometric processing, social scoring, and others. The regulation was formulated on a risk-based approach with four levels of classification. The regulation classifies AI’s into banned, high, limited, and general purpose. The aim was also to promote innovation by using regulatory sandboxes. Breach of the regulation attracts a fine of 1.5% to 7.5% of global revenue. Organizations have a 2-year window to prepare to be compliant, whiles operators of banned AI must be compliant in 6 months. 2.6.2 Risk-Based classification of AI System The four risk categories are further explained below: • Unacceptable/Prohibited Risk: These are AI systems which pose a significant threat to the livelihood and existence of humans by affecting their lives negatively. Issues like human dignity, manipulation of weaknesses and exploitation by these systems are banned within the European Union. • High Risk: This category can link to essential industry regulation like healthcare, safety and rights related to criminal justice systems, biometric processing, recruitment, and educational research. These areas are required to strictly comply with the regulation on accuracy, data governance, human oversight (Rahwan, 2018), and risk management. Due to its level of sensitivity, it is required for such systems to pass conformity assessment prior to deployment. • Limited Risk: This class of AI systems must be transparent and explain their processing and results. They pose some amount of risk to users, chatbots which interact gives information to humans as a service. It is required for deployers to inform users that their interaction is with an AI and explain how they operate with options for users to decide on using their services or not. • Low/General Purpose AI: This pose is minimal or have residual risk which are acceptable to users, however business are encouraged to issue some guidance and apply best practices. They are normally used in the field of entertainment. 23 FIGURE 4: EU AI Act pyramid of risk(Sisodia, 2023) 2.6.3 Requirements for High-Risk AI Systems As these risk classification of AI gives a general overview of what is expected of AI developers and deployers in Europe, high risk AI systems had a detailed and strict requirement. Each requirement is outline below: • Risk Management: Providers are obligated to establish and maintain a risk management strategy for the entire lifecycle of the AI systems. • Data and Data Governance: To reduce risks and guarantee appropriate operation, high-quality datasets must be used for AI system approval, testing, and learning. • Technical Documentation and Record Keeping: The act requires high risk AI systems to maintain documented records in compliance with the EU AI act. • Transparency and Provision of Information: Users must be informed about the AI system's capabilities and limitations. • Human Oversight: AI systems must be designed to allow human intervention and oversight to prevent or minimize risks. (Rahwan, 2018) 24 explained that, human in the loop will ensure AI system will be guided to operate within laws. • Robustness, Accuracy, and Security: AI systems must be robust enough to handle errors, malfunctions, or performance inconsistencies. According to (Smuha, 2021), the heightened awareness of the risks associated with AI technology has amplified demands for regulators to not only focus on its advantages but also to implement stringent regulation. These regulations are crucial to ensure that AI systems are ”trustworthy” encompassing legality, ethics, and robustness(Smuha, 2021). For limited risk AI systems, the transparency obligation is essential by ensuring that, users are interracting with AI systems and the role it was used in delivering services, for example if it was used in content generation. 2.6.4 Comparison with other AI regulatory frameworks The EU artificial intelligence Act is a comprehensive regulatory framework which aims to promote responsible and innovative application of AI. The core of the regulation is promotion of human centric AI where accountability, explainability and human oversight is considered. Whiles the EU regulatory framework is based on risk, other countries like the United States of America and China adopted different approaches(Yan, 2024) 2.6.4.1 United States of America Whiles the US has no centralized AI regulatory law, it uses its already existing guidelines on technology to nationally regulate AI. Directives of the Federal Trade Commission (FTC) and National Institute of Standards and Technology (NIST) framework and guidelines are used as a compensating control for AI regulation. For example, use of AI in medical devices and services is approved by the Food and Drugs Authority (FDA) according to (Pesapane et al., 2018). Some states like California and Illinois have state laws which address the use of AI, the California Consumer Privacy Act and Biometrics Information Privacy Act of Illinois are laws which attempt to address some aspect of AI usage. According to (Shatz & Chylik, 2020) the CCPA places a great deal of responsibility and duties on companies to make sure that customers are aware of and able to use their rights. The US approach is tailored to specific industries and states whiles the EU regulation is a comprehensive risked based approach applicable to all sectors and member states. 25 2.6.4.2 China China’s artificial intelligence regulation is based on gaining competitive advantage and accelerate development. The regulation was published in 2017 with a three-phased staged rollout to 2030. The milestones are set for the years 2020, 2025 and 2030 with obtaining competitive advantage in global markets, application of AI in all Chinese economic zones and being the AI global leader respectively(Filipova, 2024). In terms of approach, China uses vertical approach by employing separate legislation to address specific AI challenges, whereas the EU takes a noticeably more horizontal approach by applying flexible standards and requirements across a wide spectrum of AI applications(Yan, 2024). Despite the differences, the general idea is to use AI within the territorial laws for the improvement of citizens. The plan for China’s artificial intelligence development is depicted in Figure 5. FIGURE 5: China’s Artificial Intelligence Development Plan (AIDP)(Roberts et al., 2021) 32 of the adherence to all academic ethics including the protection of their identities. In some cases, the EU AI act is explained to the interviewees and their knowledge about it is sought. To allow for the free expression of opinions, the interviewees were anonymized in the analysis and referred to as Interviewee 1-7 (I1-I7). The interview questions were shared with the interviewees prior to the interview, so that they can familiarize themselves with themes due to the recent nature of the EU AI regulation. The questions are based on, 1. Knowledge about the European Union AI Act and 2. The effect on people and organizations after the implementation of the law. One mock interview was conducted to streamline the interview questions to elicit answers aligned with the themes. 3.4 Data Analysis 3.4.1 Conventional content analysis approach The choice of conventional content analysis was due to the limited literature on people’s reaction and thoughts on the EU AI act in Finland. This approach is used by researchers to gain new insights (Hsieh & Shannon, 2005). In addition, the research’s aim of studying the effect of the implementation of the European Union AI act from a professional viewpoint, made semi-structured interviews the best option. To get insights from the interviews, the transcriptions were analyzed into themes. This process involves organizing and interpreting data to make conclusions and outcomes clear. Key phrases were used to develop the themes, these were common in the responses of the interviewees. Conclusions drawn from the data are valid because the interview information was verified and complete. The responses were analyzed individually to understand the perspectives and to identify patterns. The interviews were compared to spot similarities and differences. 33 4 RESULTS The findings from the study were obtained through the analysis of the empirical data based on the themes. A total of 7 professionals were interviewed for the study using the same interview questions to get their views on the topic. Their responses were analyzed with the aim of seeking their perspectives on the EU AI act in Finland. No hidden meanings were inferred from the responses, but rather all answers were taken at face value. The interviewees are people whose work involves some form of artificial intelligence, that is assessing the usage of AI, using AI to develop solutions and services. Themes were pre-defined and based on common occurring topics. The responses were analyzed for similarities and differences. Additionally, other themes came up which provided a new theme category from the interviews resulting in the expansion of themes. The effects of the EU AI act were found to be diverse based on interviewees’ field of work with some now trying to understand the regulation for its long-term and short-term effects. The findings from the research and themes is addressed in this chapter. 4.1 Background and Perspectives 4.1.1 Knowledge and understanding of artificial intelligence and the EU AI Act As part of the interview process, the interviewees were asked about their work background, use of artificial intelligence in their work and knowledge about AI regulations. This is because the focus of the research is on artificial intelligence, regulation and specifically on the EU AI regulation. After years of deliberation about a common regulation for AI, professionals working with it have started sharing their views on the effect. The interviewees were given the definition of artificial intelligence by the High-Level Expert Group (HLEG) of the European Commission to streamline the interview and put the answers within that context. Some of the professionals expect the law to gain traction in the coming years. Interviewee 2: “I use AI in my work especially as a software engineer as a help, boost of productivity. It is also used as a boost in productivity in generative AI. I have no idea about the European Union AI regulations. I think regulation is good because people use AI to cause harm. However, I still need details of the new regulation”. According to the interviewee, the benefit of AI is known to them and use it in their work, however, they have no knowledge about the law which is going to regulate artificial intelligence. The interviewee sees regulation as a good thing 34 because it will reduce the harm caused by malicious use of AI and will need the details of the new regulation to see how it affects their work. Other interviewees also mentioned that they have heard about the EU AI act but do not know what it is about. Interviewee 1: “I have heard about it but I haven’t got chance to read about the standards but I am aware they have released some standards about AI management”. Interviewee 6: "I have a basic understanding of its concepts but no deep knowledge. I am familiar only with the high-level elements discussed within the institution I work at, which is, the risk-based nature of it. I just know it is made of four levels of general-purpose AI, high risk, prohibited, and limited, I am not sure but have to confirm." Interviewee 3: “So basically it’s a risk based approach to help individuals to protect their rights and freedoms in the European Union, so that’s kind of its objective and also to foster innovation for European companies with these regulatory sandboxes but the main thing is that, it is going to have like a categorization of different systems AI, basically four categories are with unacceptable AI systems that are not allowed to be used in the EU, then we have the high risk AI systems that are okay to use but have certain implications, and we the, am not sure about the new names may be limited risk and general AI systems, so basically a categorization of these different kinds of AI systems and requirements and also there is going to be apparently the listing of all these AI systems that are CE marked, so basically they are certified this will help organizations’, if I have I understood it correctly, basically the CE will help organizations to say OK we have this list and we can see that we have been talking with this AI company, it’s on this list and its better than an uncertified”. Considering the responses by the interviewees, people are aware of the coming into effect of the EU AI act, however, they have not reviewed the details of the regulation and how it affects their organizations and work. Although artificial intelligence usage has seen a massive increase, the growing processing capabilities was the driver for the need for the regulation. The interviewees unanimously confirm their knowledge about the existence of the act, however, because the regulation was just accepted, they are yet to familiarize themselves with the details. 35 4.1.2 Areas of clarity and confusion The analysis reveals that professionals view the EU AI Act as a comprehensive regulatory framework aimed at addressing critical challenges in AI use. Key themes include ensuring ethical AI use and data protection, enhancing transparency and accountability, promoting trustworthy AI, and navigating the implementation challenges. However, there was no clarity on what the law sought to address. From the interviews, Interviewee 4: "This question will be partially answered as I stated earlier, I am yet to see the details of the law, but I believe the challenges the AI act aims to address are related to the development and deployment of AI technologies. I believe the main goal of the act is to limit the malicious use of AI and incentivize what is called 'Trustworthy AI.' I know there may be other issues, but this is what readily comes to mind." Interviewee 7: "Well, from my understanding, it will address the challenges of you know, it’s not possible to do anything we want to, like ethical use, personal data of people, and their rights. For example, the unacceptable risk AI systems, you are not allowed to use this for real-time monitoring of people so basically, it sets limits." Interviewee 3: "The regulation seeks to streamline the use of AI in EU with Finland inclusive. The issue of ethics, I think, will be a challenge the regulation will address. The ethical use of AI has been central to AI challenges, organizations and individuals have complained about how AI is used to process their data which they have no control over. This can be explained also in terms of transparency in the models and algorithms used. For transparency, there are concerns about the test data used to train the model while its application goes beyond the boundaries of the test data. For example, there have been concerns about how some AI systems pick candidates for interviews. All these factors coupled with the pervasive nature pose risks which need to be addressed." The professionals acknowledge that implementing the EU AI regulation will present challenges, particularly in the development and deployment of AI technologies. It is also clear from the responses that the regulation seeks to prevent malicious use of AI technologies. Ensuring that AI systems comply with ethical standards and transparency requirements while fostering innovation will be complex. 36 4.1.3 Effects on Organizations in Finland The conventional content analysis reveals that Finnish professionals have a nuanced view of the EU AI Act. They recognize the importance of compliance and monitoring, see market opportunities and the potential to leverage Finland's technological reputation, and acknowledge both the challenges and supportive measures for innovation within the regulatory framework. The need for comprehensive integration with existing regulations like the GDPR is also highlighted, ensuring a robust and cohesive approach to AI governance. These insights underscore the multifaceted impact of the AI regulation on the Finnish technology sector and its broader implications for AI development and deployment. Interviewee 4: "As an EU member state, Finnish companies will need to align their operations with the AI regulatory framework set by the EU. I also see that there can be potential market opportunities for Finnish companies in the technology sector. This is when they can tell customers their AI systems are compliant and do only good things. Finland is noted for good technology due to some of the big Finnish companies who have done good business abroad, so this is also a good opportunity I will say." Interviewee 2: "From what I have heard, this regulation also has problems with the development of AI because, it is restricting it, that is what they say apparently that, the US and China where there is not so extensive regulation, they are innovating and here we are kind of restricted by these regulations, so potentially to be bad but I am not sure for the innovative part, but at least on paper, one of the objectives for the regulation was to foster innovation in the EU so basically if there is this regulatory sandboxes to help companies develop these AI systems, but let's see." As expressed by the interviewees, the establishment of rules and standards has both advantages and disadvantages. However, ongoing, and continuous application of the law will lead to organization and professionals getting the best from the law. 4.1.4 On innovation and technological development To understand how the regulation will impact innovation and development, the interviewees gave their views based on their area of work. (Voss, 2021) argues 37 that the EU AI act will maintain legal stability to encourage investment and AI innovation. This can be viewed as a check on originality and promotion of development. This question captures the different perspectives by the interviewees to strike the balance between innovation and development. Interviewee 2: “I think it is going to make not very smart people very smart, so certainly that will help them especially those people who only know how to use prompting, I mean prompt engineering is a thing now where you write your question with the context and you keep replaying the same thing over and over and you try to refine that thing as much as possible”. Interviewee 1: “For example, on innovation, movies will be completed in a month’s time and there will be virtual actors, you won’t even need real humans to be playing as actors and things are going to look real”. The answers were similar but in different domains, whiles the respondent saw the benefits of the law, they could not readily relate it to their field of work but rather opted for other easy disciplines like media and entertainment. This implies there is an anticipated effect on innovation and development, but the focus of the professionals is restricted to prevention of adversarial use of AI systems. 4.1.5 Accountability,Explainability/Transparency,Bias and Ethical Consideration Addressing the issues of AI accountability, explainability, bias, and ethics is crucial for the responsible development and deployment of AI technologies. The EU AI regulation also factored this quartet in design of the AI act. These concepts are interrelated and collectively ensure that AI systems operate transparently, fairly, and under appropriate oversight. As AI continues to evolve, ongoing research, regulation, and ethical scrutiny will be essential to mitigate risks and enhance the benefits of AI systems for society. In terms of the role in the EU AI regulation, interviewees gave their perspective as follows: 38 Interviewee 3: “The act itself embodies ethical considerations by restricting organizations from misusing personal information, such as through realtime monitoring, with strict rules even for law enforcement. Its core principle is transparency, exemplified by requirements for limited risk AI systems like chatbots and deepfakes to clearly indicate they are not real people. High-risk AI systems will undergo Fundamental Rights Impact Assessments (FRIA) and conformity assessments to enhance transparency, though achieving complete transparency remains challenging due to the "black box" nature of AI. Data privacy responsibilities lie with data controllers and processors, who face fines for misuse of personal data. Addressing bias is uncertain, but transparency, human oversight, and training may help mitigate biases in AI systems”. Interviewee 3: "The issues outlined, I believe is the core of the regulation, I checked your issues you raised, and I think it is same or similar. Ethics and transparency go hand-in-hand, for example AI was sued in the US for being biased when it comes to the conviction of crimes. It was noticed that the algorithm tends to convict people of color easily prompting lawyers to investigate further, it was traced to bias in the training data so I believe regulation will help address some of these issues. Recently, due to generative AI, people are producing a lot of contents which have become contentious making people doubt the originality of art vs AI produced results, the law will make people accountable by declaring if AI was used in the work process or it is purely intellectual property. It is difficult to separately explain these issues but just like I have said, they work hand-in-hand." The interconnected nature of these issues underscores the need for a holistic approach to AI regulation, with regulatory authorities playing a central role in enforcement. These insights highlight the critical elements that the EU AI Act seeks to address, contributing to the responsible development and deployment of AI technologies. While there are challenges, particularly in achieving full transparency, the regulation sets high-level guidelines that promote responsible and fair use of AI. As pointed out by (Estella, 2023), trust is the basis for the EU AI regulation whiles commitment to these four deliverables addresses the bottlenecks. 39 4.1.6 Identified challenges in complying with the EU AI Act In identifying and addressing the challenges, the respondent was unanimous in their responses, they were unable to point a common issue which will be a challenge, however, gap assessment, compliance strategy and classification of systems these organizations use were identified as some of the areas which can be improved to reduce any unforeseen challenges. These insights underscore the importance of proactive and strategic planning to ensure that organizations are well-prepared to meet the requirements of the AI regulation challenges. Interviewee 5: "As with most new regulations, organizations should start by understanding the requirements of the act, then perform a gap assessment to identify what needs to be done to achieve compliance in their operations. Finally, they should develop a strategy to ensure future compliance. I think it should include everything that needs to be considered and not only capacity development." Interviewee 3: "Yeah so basically for now, it hasn’t come into force yet and when it will come into force there is going to be this basically 2-year transition with a few exceptions so during this transition time organizations need to act, so they can already start the preparation. One of the first things will be for example to identify every AI 0.system the organization uses to kind of have it documented, ready to know who owns the system, so when the regulation comes into force, it already the first step has been done so at that place, you don’t need to start to identify do the inventory so you already have it and also the draft of the regulation is online so it’s possible to have a look at it, prepare yourself and also there is for the categorization of the AI systems, there are already those, like if it this kind of system, its high risk so basically the organization has already identified, they can start to categorize them and when they have done that, they can see ok like, this is like no risk so basically you don’t have to do anything with it, so you know this is a high risk AI system so when the regulation comes to force, we have for example 2 years to make it compliant. So, we know that we need to do FRIA, let’s start doing that, that is kind of identify and categorize the AI systems that are already in use." Interviewee 4: "I think organizations are already planning for this law, so far as they have been compliant with the GDPR, this will be a bit easier for them. This can be done by getting the compliance departments to examine the regulation and then classify their AI systems according to the law. After that, they can use the 6 months – 2 years window of compliance to address any 40 pressing issues. They also have to develop the capacity of their staff to handle the regulation such that it does not cost them too much money." The response although different from followed the same theme of classification challenges, conformity assessments and increased administrative costs. (Justo-Hanani, 2022) questions complexity of existing laws with the EU AI regulation. 4.1.7 Recommendations for improving AI regulation and implementation. The provided responses highlight varying views on the feasibility of AI regulation, its impact on specific fields, and its intersection with existing regulations like the GDPR. This analysis identifies key themes and insights derived from the responses on improvement for the EU AI act. Interviewee 3: "Already some AI systems with the GDPR have requirements, for example in HR if you use AI system for recruitment, you have the implications and the requirements that an individual can also not accept that they are being processed automatically and it has implications that you have to do this kind of data protection impact assessment (DPIA) so they already have some implications but I don’t know yeah possibly content creators will be impacted very much, it will also depend if it is a B2B or B2C maybe I am not actually sure, I have to think about it." Interviewee 5: "Without examining the regulation in detail, my personal view is that creating thorough regulations at this stage, when AI is constantly developing, is nearly impossible. However, it must be acknowledged that the AI act sets high-level boundaries that will likely apply widely across the industry. With my limited knowledge, I believe the implementation will be a bit difficult." Interviewee 6: Yes, in the fields of healthcare, there will be upholding of ethics and safety will be paramount. Patients' data will not be left for AI systems to process without safeguards. If well implemented, there will be trust in AI health diagnostics resulting in an improvement of patients' outcomes. I think one untapped field is the public sector, where governments lose a lot of money due to bureaucracy and inefficiency. The AI systems with proper regulation can be used to manage social assistance and welfare programs." 41 The respondents demonstrated little knowledge about how the regulation can be improved and made little suggestion to that effect. This can be attributed to the low knowledge about the details of the regulation. By addressing these issues, the EU can lead the way in establishing a balanced and effective approach to AI regulation, ensuring that AI technologies develop in a manner that is safe, ethical, and beneficial for society. 48 Čerka, P., Grigienė, J., & Sirbikytė, G. (2017). Is it possible to grant legal personality to artificial intelligence software systems? Computer Law & Security Review, 33(5), 685–699. https://doi.org/10.1016/j.clsr.2017.03.022 Chamberlain, J. (2023). The Risk-Based Approach of the European Union’s Proposed Artificial Intelligence Regulation: Some Comments from a Tort Law Perspective. European Journal of Risk Regulation, 14(1), 1–13. https://doi.org/10.1017/err.2022.38 Cheng, J. Y., Abel, J. T., Balis, U. G. J., McClintock, D. S., & Pantanowitz, L. (2021). Challenges in the Development, Deployment, and Regulation of Artificial Intelligence in Anatomic Pathology. The American Journal of Pathology, 191(10), 1684–1692. https://doi.org/10.1016/j.ajpath.2020.10.018 De Almeida, P. G. R., Dos Santos, C. D., & Farias, J. S. (2021). Artificial Intelligence Regulation: A framework for governance. Ethics and Information Technology, 23(3), 505–525. https://doi.org/10.1007/s10676-021-09593-z Doshi-Velez, F., & Been, K. (2017). Towards A rigorous science of interpretable machine learning. . Ithaca: Retrieved from https://www-proquest- com.ezproxy.jyu.fi/working-papers/towards-rigorous-science-interpreta- ble-machine/docview/2075249272/se-2 Erdélyi, O. J., & Goldsmith, J. (2022). Regulating artificial intelligence: Proposal for a global solution. Government Information Quarterly, 39(4), 101748. https://doi.org/10.1016/j.giq.2022.101748 Eriksson, P., & Kovalainen, A. (2008). Qualitative Methods in Business Research. SAGE Publications Ltd. https://doi.org/10.4135/9780857028044 Estella, A. (2023). Trust in Artificial Intelligence Analysis of the European Commission proposal for a Regulation of Artificial Intelligence. Indiana Journal of Global Legal Studies, 30(1), 39–64. https://doi.org/10.2979/gls.2023.a886162 European Commission. Joint Research Centre. (2020). AI watch: Defining Artificial Intelligence : towards an operational definition and taxonomy of artificial intelligence. Publications Office. https://data.europa.eu/doi/10.2760/382730 Farisco, M., Evers, K., & Salles, A. (2022). On the Contribution of Neuroethics to the Ethics and Regulation of Artificial Intelligence. Neuroethics, 15(1), 4. https://doi.org/10.1007/s12152-022-09484-0 Filipova, I. A. (2024). Legal Regulation of Artificial Intelligence: Experience of China. Journal of Digital Technologies and Law, 2(1), 46–73. https://doi.org/10.21202/jdtl.2024.4 Finocchiaro, G. (2023). The regulation of artificial intelligence. AI & SOCIETY. https://doi.org/10.1007/s00146-023-01650-z Flores, A. W., Bechtel, K., & Lowenkamp, C. T. (2016). False Positives, False Negatives, and False Analyses: A Rejoinder to “Machine Bias: There’s Software Used Across the Country to Predict Future Criminals. And It’s Biased Against Blacks.” Federal Probation, 80(2), 38-46,66. Floridi, L., Cowls, J., Beltrametti, M., Chatila, R., Chazerand, P., Dignum, V., Luetge, C., Madelin, R., Pagallo, U., Rossi, F., Schafer, B., Valcke, P., & Vayena, E. (2018). AI4People—An Ethical Framework for a Good AI Society: 49 Opportunities, Risks, Principles, and Recommendations. Minds and Machines, 28(4), 689–707. https://doi.org/10.1007/s11023-018-9482-5 Fournier-Tombs, E. (2021). Towards a United Nations Internal Regulation for Artificial Intelligence. Big Data & Society, 8(2), 205395172110394. https://doi.org/10.1177/20539517211039493 Garg, A., Singh, S., Li, W., Gao, L., Cui, X., Wang, C., Peng, X., & Rajasekar, N. (2020). Illustration of experimental, machine learning, and characterization methods for study of performance of Li‐ion batteries. International Journal of Energy Research, 44(12), 9513–9526. https://doi.org/10.1002/er.5159 Gasser, U., & Almeida, V. A. F. (2017). A Layered Model for AI Governance. IEEE Internet Computing, 21(6), 58–62. https://doi.org/10.1109/MIC.2017.4180835 Goh, H.-H., & Vinuesa, R. (2021). Regulating artificial-intelligence applications to achieve the sustainable development goals. Discover Sustainability, 2(1), 52. https://doi.org/10.1007/s43621-021-00064-5 Goltz, N. S., Cameron-Huff, A., & Dondoli, G. (2019). Rethinking Global-Regula- tion: World’s law meets artificial intelligence. Information & Communications Technology Law, 28(1), 36–45. https://doi.org/10.1080/13600834.2019.1557400 Hill, C., & Anderson, L. (1993). The interview as a research tool. New Ideas in Psychology, 11(1), 111–125. https://doi.org/10.1016/0732-118X(93)90024-8 Hsieh, H.-F., & Shannon, S. E. (2005). Three Approaches to Qualitative Content Analysis. Qualitative Health Research, 15(9), 1277–1288. https://doi.org/10.1177/1049732305276687 Iphofen, R., & Kritikos, M. (2021). Regulating artificial intelligence and robotics: Ethics by design in a digital society. Contemporary Social Science, 16(2), 170– 184. https://doi.org/10.1080/21582041.2018.1563803 Jarota, M. (2023). Artificial intelligence in the work process. A reflection on the proposed European Union regulations on artificial intelligence from an occupational health and safety perspective. Computer Law & Security Review, 49, 105825. https://doi.org/10.1016/j.clsr.2023.105825 Justo-Hanani, R. (2022). The politics of Artificial Intelligence regulation and governance reform in the European Union. Policy Sciences, 55(1), 137–159. https://doi.org/10.1007/s11077-022-09452-8 Kolfschooten, H. V. (2022). EU regulation of artificial intelligence: Challenges for patients’ rights. Common Market Law Review, 59(Issue 1), 81–112. https://doi.org/10.54648/COLA2022005 König, P. D., Wurster, S., & Siewert, M. B. (2023). Sustainability challenges of artificial intelligence and Citizens’ regulatory preferences. Government Information Quarterly, 40(4), 101863. https://doi.org/10.1016/j.giq.2023.101863 Krizhevsky, A., Sutskever, I., & Hinton, G. E. (2017). ImageNet classification with deep convolutional neural networks. Communications of the ACM, 60(6), 84– 90. https://doi.org/10.1145/3065386 Laux, J., Wachter, S., & Mittelstadt, B. (2024). Trustworthy artificial intelligence and the European Union AI act: On the conflation of trustworthiness and 50 acceptability of risk. Regulation & Governance, 18(1), 3–32. https://doi.org/10.1111/rego.12512 Lazăr Pleşa, T., Popescu, C., & Pleşa, I. T. (2023). From Digitization to Artificial Intelligence in External Public Audit. Valahian Journal of Economic Studies, 14(1), 47–59. https://doi.org/10.2478/vjes-2023-0006 LeCun, Y., Bengio, Y., & Hinton, G. (2015). Deep learning. Nature, 521(7553), 436– 444. https://doi.org/10.1038/nature14539 Ma, L., & Sun, B. (2020). Machine learning and AI in marketing – Connecting computing power to human insights. International Journal of Research in Marketing, 37(3), 481–504. https://doi.org/10.1016/j.ijresmar.2020.04.005 McKee, M., & Wouters, O. J. (2022). The Challenges of Regulating Artificial Intelligence in Healthcare Comment on “Clinical Decision Support and New Regulatory Frameworks for Medical Devices: Are We Ready for It? - A Viewpoint Paper.” International Journal of Health Policy and Management, 1. https://doi.org/10.34172/ijhpm.2022.7261 Mehrabi, N., Morstatter, F., Saxena, N., Lerman, K., & Galstyan, A. (2022). A Survey on Bias and Fairness in Machine Learning. ACM Computing Surveys, 54(6), 1–35. https://doi.org/10.1145/3457607 Miller, T. (2019). Explanation in artificial intelligence: Insights from the social sciences. Artificial Intelligence, 267, 1–38. https://doi.org/10.1016/j.artint.2018.07.007 Mittelstadt, B. (2019). Principles alone cannot guarantee ethical AI. Nature Machine Intelligence, 1(11), 501–507. https://doi.org/10.1038/s42256-019-0114- 4 Munoko, I., Brown-Liburd, H. L., & Vasarhelyi, M. (2020). The Ethical Implications of Using Artificial Intelligence in Auditing. Journal of Business Ethics, 167(2), 209–234. https://doi.org/10.1007/s10551-019-04407-1 Myers, M. D., & Newman, M. (2007). The qualitative interview in IS research: Examining the craft. Information and Organization, 17(1), 2–26. https://doi.org/10.1016/j.infoandorg.2006.11.001 OECD. (2024). Recommendation of the Council on Artificial Intelligence (OECD/LEGAL/0449). OECD. https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449 OED. (n.d.). Artificial Intelligence. In Oxford Educational Dictionary. Retrieved April 5, 2024, from https://www.oed.com/dictionary/artificial-intelli- gence_n?tab=meaning_and_use#38531565 Pathni, R. K. (2023). Artificial Intelligence and the Myth of Objectivity: Need for Regulation of Artificial Intelligence in Healthcare. Journal of Healthcare Management Standards, 3(1), 1–14. https://doi.org/10.4018/JHMS.329234 Patton, M. Q. (2002). Qualitative research & evaluation. SAGE Publications Ltd. Perucica, N., & Andjelkovic, K. (2022). Is the future of AI sustainable? A case study of the European Union. Transforming Government: People, Process and Policy, 16(3), 347–358. https://doi.org/10.1108/TG-06-2021-0106 Pesapane, F., Volonté, C., Codari, M., & Sardanelli, F. (2018). Artificial intelligence as a medical device in radiology: Ethical and regulatory issues in 51 Europe and the United States. Insights into Imaging, 9(5), 745–753. https://doi.org/10.1007/s13244-018-0645-y Ploug, T., & Holm, S. (2023). The right to a second opinion on Artificial Intelligence diagnosis—Remedying the inadequacy of a risk‐based regulation. Bioethics, 37(3), 303–311. https://doi.org/10.1111/bioe.13124 Rahwan, I. (2018). Society-in-the-loop: Programming the algorithmic social contract. Ethics and Information Technology, 20(1), 5–14. https://doi.org/10.1007/s10676-017-9430-8 Rakha, N. A. (2023). AI and the Law: Unraveling the Complexities of Regulatory Frameworks in Europe. International Bulletin of Young Scientist, 1(2), 1–7. Roberts, H., Cowls, J., Morley, J., Taddeo, M., Wang, V., & Floridi, L. (2021). The Chinese approach to artificial intelligence: An analysis of policy, ethics, and regulation. AI & SOCIETY, 36(1), 59–77. https://doi.org/10.1007/s00146- 020-00992-2 Samoili, S., Montserrat, L. C., Delipetrev, B., Martinez-Plumed, F., Gomez, E., & De Prato, G. (2021). AI watch. Defining artificial intelligence 2.0. Towards an operational definition and taxonomy of AI for the AI landscape. Shatz, s, & Chylik, S. E. (2020). The California Consumer Privacy Act of 2018: A Sea Change in the Protection of California Consumers’ Personal Information. The Business Lawyer, 75(2), 1917–1924. Sisodia, jai. (2023). Understanding the EU AI Act. ISACA Journal. https://www.isaca.org/resources/news-and-trends/industrynews/2023/understanding-the-eu-ai- act?gad_source=1&gclid=CjwKCAjwjeuyBhBuEiwAJ3vuoQDUVsAsOrk- wvFd2BIFL61sc54bezU2KfirK3urDtsCsGx3Fl4McehoCcAYQAvD_BwE Smuha, N. A. (2021). From a ‘race to AI’ to a ‘race to AI regulation’: Regulatory competition for artificial intelligence. Law, Innovation and Technology, 13(1), 57–84. https://doi.org/10.1080/17579961.2021.1898300 Sutton, R. S., & Barto, A. G. (2018). Reinforcement Learning: An Introduction,. Trends in Cognitive Sciences, 3(9), 360. https://doi.org/10.1016/S1364- 6613(99)01331-5 Tallberg, J., Lundgren, M., & Geith, J. (2024). AI regulation in the European Union: Examining non-state actor preferences. Business and Politics, 1–22. https://doi.org/10.1017/bap.2023.36 Trotta, A., Ziosi, M., & Lomonaco, V. (2023). The future of ethics in AI: Challenges and opportunities. AI & SOCIETY, 38(2), 439–441. https://doi.org/10.1007/s00146-023-01644-x Usama, M., Qadir, J., Raza, A., Arif, H., Yau, K. A., Elkhatib, Y., Hussain, A., & Al-Fuqaha, A. (2019). Unsupervised Machine Learning for Networking: Techniques, Applications and Research Challenges. IEEE Access, 7, 65579– 65615. https://doi.org/10.1109/ACCESS.2019.2916648 Vakkuri, V., Kemell, K.-K., & Abrahamsson, P. (2019). AI Ethics in Industry: A Research Framework. Tethics 2019: Proceedings of the Third Seminar on Technology Ethics, Aachen. http://ceur-ws.org/Vol-2505/paper06.pdf 52 Vasiljeva, T., Kreituss, I., & Lulle, I. (2021). Artificial Intelligence: The Attitude of the Public and Representatives of Various Industries. Journal of Risk and Financial Management, 14(8), 339. https://doi.org/10.3390/jrfm14080339 Vaswani, A., Shazeer, N., Parmar, N., & Uszkoreit, J. (2023). Attention is all you need. Veale, M., & Zuiderveen Borgesius, F. (2021). Demystifying the Draft EU Artificial Intelligence Act—Analysing the good, the bad, and the unclear elements of the proposed approach. Computer Law Review International, 22(4), 97–112. https://doi.org/10.9785/cri-2021-220402 Voss, W. G. (2021). AI ACT: THE EUROPEAN UNION’S PROPOSED FRAMEWORK REGULATION FOR ARTIFICIAL INTELLIGENCE GOVERNANCE. Journal of Internet Law, 25(4), 1–17. Wang, P. (2019). On Defining Artificial Intelligence. Journal of Artificial General Intelligence, 10(2), 1–37. https://doi.org/10.2478/jagi-2019-0002 White, J. M., & Lidskog, R. (2022). Ignorance and the regulation of artificial intelligence. Journal of Risk Research, 25(4), 488–500. https://doi.org/10.1080/13669877.2021.1957985 Yan, W. (2024). Do not go gentle into that good night: The European Union’s and China’s different approaches to the extraterritorial application of artificial intelligence laws and regulations. Computer Law & Security Review, 53, 105965. https://doi.org/10.1016/j.clsr.2024.105965 Zhou, G. (2021). Research on the problems of enterprise internal audit under the background of artificial intelligence. Journal of Physics: Conference Series, 1861(1), 012051. https://doi.org/10.1088/1742-6596/1861/1/012051 53 APPENDIX 1: INTERVIEW FORM AND QUESTIONS IN ENGLISH Master of Science- Information Systems Science Interview Questionnaire Thesis Topic: Exploring the EU Artificial Intelligence Act: Perspectives of Professionals in Finland Background: The European Union parliament has passed the EU AI ACT and is awaiting ratification by the EU member states. The European Commission’s High Level Expert Group HLEG) define AI as: “Artificial intelligence (AI) systems are software (and possibly also hardware) systems designed by humans (2) that, given a complex goal, act in the physical or digital dimension by perceiving their environment through data acquisition, interpreting the collected structured or unstructured data, reasoning on the knowledge, or processing the information, derived from this data and deciding the best action(s) to take to achieve the given goal. AI systems can either use symbolic rules or learn a numeric model, and they can also adapt their behavior by analyzing how the environment is affected by their previous actions." This interview seeks to obtain from respondents, the perceived effect on society, individuals, and businesses in Finland when the act is implemented. Interview Questions 1. What is your understanding of the EU AI Act? 2. In your opinion, what are the key challenges or barriers that AI act aim to address? 3. What are the implications for AI development and deployment in Finland? 4. How do you think the EU AI Act address issues of: a. Ethical considerations b. Transparency/Explainability c. Accountability d. Bias 5. How can organizations plan for compliance with the implementation? 6. Are there specific areas or fields where you expect to see significant changes or improvements because of AI regulation? 7. For those companies operating in Finland, who should be responsible for ensuring that they are following the EU AI Act? 54 8. To what extent do you believe this new AI legislation will work together with other recent digital legislative measures? For instance, the Digital Operational Resilience Act, General Data Protection Regulation? 9. How do you foresee the implementation of the EU AI Act influencing global AI governance frameworks?