scieee AI-readable full text Open interactive document viewer

The European Regulation on Artificial Intelligence. A first constitutional-ethical consideration

Panagopoulou, Fereniki

Abstract

The study critically outlines the key aspects of Regulation (EU) 2024/1689 on Artificial Intelligence (AI Act) and selectively highlights issues of constitutional interest that merit serious consideration. It comprises an Introduction, a General Section, a Special Section, and Conclusions.The Introduction sets out the overall framework of the study and provides a brief clarification of terminology. The General Part describes the process of adopting the Regulation and related legislation, followed by a comparative overview of AI regulation. It then examines the necessity of legislative intervention, outlines the philosophy and objectives of the text, and analyses the guiding principles that should govern the regulatory framework. The section proceeds with an examination of the scope of application and its similarities with Regulation (EU) 2016/679 (General Data Protection Regulation). It continues with the issues of control and supervision at both national and supranational level, and concludes with a systematisation of the sanctions and liability regime and an analysis of the Regulation's entry into force.The Special Section addresses key areas raising significant constitutional questions, including biometric identification, employment, democracy, education, health, and innovation. A separate part considers whether the revising legislator should incorporate AI into the forthcoming constitutional revision. The study concludes with final observations.

Full text

The European Regulation on Artificial Intelligence A first constitutional-ethical consideration Fereniki Panagopoulou Logos Verlag Berlin λογος Fereniki Panagopoulou Associate Professor at Panteion University Ph.D. (Humboldt), M.P.H. (Harvard), LL.M., Ph.D. (NKUA) Bibliographic information published by the Deutsche Nationalbibliothek The Deutsche Nationalbibliothek lists this publication in the Deutsche Nationalbibliografie; detailed bibliographic data are available on the Internet at http://dnb.d-nb.de . This work is licensed under the Creative Commons license CC BY-NC-ND (https://creativecommons.org/licenses/by-nc-nd/4.0/). Creative Commons license terms for re-use do not apply to any content not original to the Open Access publication and further permission may be required from the rights holder. The obligation to research and clear permission lies solely with the party re-using the material. Logos Verlag Berlin GmbH, 2025 ISBN 978-3-8325-6016-4 Printed on Lessebo Design Natural, 100 g/qm, one of the most climate friendly paper qualities in the world. Cradle to Cradle Certified®at Gold level. Logos Verlag Berlin GmbH Georg-Knorr-Str. 4 Geb. 10 D-12681 Berlin phone: +49 (0)30 / 42 85 10 90 https://www.logos-verlag.com Contents INTRODUCTION 7 I. Generalremarks...................... 8 II. Terminology and characteristics of artificial intelligence . . 11 A. Artificial intelligence (AI) ............... 11 B. General Purpose Artificial Intelligence (GPAI) . . . . . 15 C. The parties involved . . . . . . . . . . . . . . . . . . 16 D.Algorithm....................... 17 E. Distinctive characteristics of artificial intelligence . . . 18 F. Difference from human beings . . . . . . . . . . . . 21 G. The issue of the dangerousness of artificial intelligence 22 H. The use of artificial intelligence . . . . . . . . . . . . 24 GENERAL SECTION 25 I. The adoption of the Artificial Intelligence Act and related legislation ......................... 26 II. Comparative overview of the regulation of artificial intelligence outside the EU ................... 31 A. United Kingdom . . . . . . . . . . . . . . . . . . . 31 B. United States of America (U.S.) . . . . . . . . . . . . 32 C.Canada ........................ 35 D.China ......................... 36 E.India.......................... 37 III. Does artificial intelligence require specific regulation? . . . 39 IV. Philosophy and objectives . . . . . . . . . . . . . . . . . 42 V. Guiding principles that should govern artificial intelligence 46 A. Respect for human dignity . . . . . . . . . . . . . . 46 B.Privacy......................... 47 C. Human well-being . . . . . . . . . . . . . . . . . . . 48 D.Pluralism ....................... 48 3 Contents E.Participation...................... 48 F. Algorithmic transparency . . . . . . . . . . . . . . . 49 G. Human control and supervision . . . . . . . . . . . . 51 H.Adaptability...................... 51 I. Sustainability ..................... 52 J. Donoharm...................... 53 K. Prevention and precaution . . . . . . . . . . . . . . . 53 L. Concluding remarks . . . . . . . . . . . . . . . . . . 54 VI. Scope of application . . . . . . . . . . . . . . . . . . . . 55 VII. Similarities with the General Data Protection Regulation (GDPR) .......................... 62 VIII.Keypillars......................... 66 A.General ........................ 66 B. Risk-based categorisation . . . . . . . . . . . . . . . 66 C. Risk mitigation measures: Assessing the impact of highrisk artificial intelligence systems on fundamental rights 72 D. Specific knowledge in the field of artificial intelligence . 78 IX. Obligations of the Parties . . . . . . . . . . . . . . . . . 80 A.Providers ....................... 80 B. Authorised representatives . . . . . . . . . . . . . . . 83 C.Importers ....................... 84 D.Distributors...................... 85 E.Deployers ....................... 85 X. Control and supervision . . . . . . . . . . . . . . . . . . 89 A.Unionlevel ...................... 90 B.Nationallevel ..................... 91 C. The issue of the supervisory authority in Greece . . . . 92 XI. Penalties.......................... 98 XII. Liability.......................... 100 XIII. Entry into force . . . . . . . . . . . . . . . . . . . . . . 109 XIV.Concerns ......................... 111 A. List-based categorisation . . . . . . . . . . . . . . . . 111 B. Insufficient protection of rights . . . . . . . . . . . . 111 C. “Quasi-Directive” Regulation model . . . . . . . . . 113 D. Multiple supervisory authorities . . . . . . . . . . . . 113 E. Lack of guidance . . . . . . . . . . . . . . . . . . . . 113 4 Contents F. Extended scope . . . . . . . . . . . . . . . . . . . . 114 G. Competition with non-European systems . . . . . . . 114 H. Extraterritoriality . . . . . . . . . . . . . . . . . . . 114 SPECIAL SECTION: Constitutional issues for examination 117 I. Biometric identification . . . . . . . . . . . . . . . . . . 119 A.Introduction...................... 119 B.Terminology...................... 119 C.Importance ...................... 120 D. The issue of public trust in the United States (U.S.) . . 121 E. The Union’s legislative framework . . . . . . . . . . . 122 F. The concept of publicly accessible space . . . . . . . . 126 G. The exception of national security . . . . . . . . . . . 127 H. Concluding remarks . . . . . . . . . . . . . . . . . . 131 II. Employment and the workplace . . . . . . . . . . . . . . 133 A. General remarks . . . . . . . . . . . . . . . . . . . . 133 B. Managing employees through artificial intelligence . . 134 C. The response of the EU and national legislator . . . . 135 D. Artificialintelligenceasatoolofpublicpolicytostrengthen the protection of workers . . . . . . . . . . . . . . . 138 E. Artificial intelligence and the future of work . . . . . 138 F. Concluding remarks . . . . . . . . . . . . . . . . . . 139 III. Artificial intelligence and democracy: Towards digital authoritarianism or a democratic upgrade? . . . . . . . . . 140 A.Introduction...................... 140 B. Risks posed for democracy . . . . . . . . . . . . . . . 141 C. Upgrading democratic institutions . . . . . . . . . . 153 D. Changing representative democracy . . . . . . . . . . 159 E. Abstention or conditional acceptance? . . . . . . . . 164 F. Recommendations . . . . . . . . . . . . . . . . . . 165 G. Concluding remarks . . . . . . . . . . . . . . . . . . 168 IV. Artificial intelligence and education: Towards a right to digitalliteracy? ........................ 169 A.Introduction...................... 169 5 Contents B. European legal framework . . . . . . . . . . . . . . . 170 C. The Greek constitutional framework . . . . . . . . . 175 D. Legislative and advisory framework . . . . . . . . . . 177 E.Casestudies ...................... 179 F. Challenges and considerations . . . . . . . . . . . . . 188 G. The question of language . . . . . . . . . . . . . . . 193 H. Concluding remarks . . . . . . . . . . . . . . . . . . 194 V. Applications for predicting illness and death . . . . . . . 196 A.Introduction...................... 196 B. Terminological clarification . . . . . . . . . . . . . . 196 C.History ........................ 197 D. Issues and considerations . . . . . . . . . . . . . . . 201 E. Constitutional analysis . . . . . . . . . . . . . . . . 206 F. The European regulatory framework: Risk categorisation under the Artificial Intelligence Act . . . . . . . 211 G. The matter of oversight . . . . . . . . . . . . . . . . 212 H. Recommendations . . . . . . . . . . . . . . . . . . 212 I. Concluding remarks . . . . . . . . . . . . . . . . . . 214 VI. Regulatory sandboxes . . . . . . . . . . . . . . . . . . . 215 A.Introduction...................... 215 B.Terminology...................... 215 C. Their enshrinement in the Artificial Intelligence Act . 216 D. Rationale for the establishment of regulatory sandboxes 220 E. Regulatory sandboxes and EU innovation policy . . . 221 F. Critical assessment . . . . . . . . . . . . . . . . . . . 224 G. Concluding remarks . . . . . . . . . . . . . . . . . . 227 VII. Isitnecessaryforthe Greekrevisingconstitutionallegislator to regulate artificial intelligence? . . . . . . . . . . . . . . 228 CONCLUSIONS 231 BIBLIOGRAPHY 239 6 INTRODUCTION 7 II. Terminology and characteristics of artificial intelligence AI refers to systems that exhibit intelligent behaviour by analysing their environment and taking steps, with a certain degree of autonomy, to achieve their objectives.14 In this sense, AI systems are designed by humans and are capable of perceiving and interpreting data from their environment, making optimal decisions, and reproducing human cognitive functions, such as learning, planning and decision-making. The discipline of AI engages all five human senses and encompasses variousapproachesandtechniques:(a)machine learning,includingdeep learning and reinforcement learning; (b) machine reasoning, covering design, programming, knowledge representation and reasoning, search, and optimisation; and (c) robotics, which involves control, perception, sensors, and actuators, as well as the integration of all these techniques into cyber-physical systems.15 AI contrasts with human intelligence, as it does not originate from livingbeings.16 Inreality, itconstitutesautomateddecision-makingwithout human mediation, through sequences of logical operations derived frommachinelearningor deeplearning.Machinelearningisdividedinto supervised and unsupervised. In the first case, algorithms are “trained” to draw conclusions based on data provided by their programmers.17 By contrast, in unsupervised machine learning, algorithms have not been trained and are left without guidance in drawing conclusions.18 This in14European Commission, Communication from the Commission to the European Parliament, the European Council, the Council, the European Economic and Social Committee and the Committee of the Regions on Artificial Intelligence for Europe,COM(2018) 237 final, Brussels, April 25, 2018. 15High-Level Expert Group on Artificial Intelligence, A Definition of Artificial Intelligence: Main Capabilities and Scientific Disciplines (Brussels, December 18, 2018), https://ec.europa.eu/futurium/en/system/files/ged/ai_hleg_definition_of _ai_ 18_december_1.pdf 16Konstantinos N. Christodoulou, “Legal Issues Arising from Artificial Intelligence,” in LawandTechnology:22nd ScientificSymposiumoftheUniversity of Piraeus and the HellenicCourtof Audit,28–29 March2019,ed.KorniliaDelouka-Igglesi, AnnaLigomenou, and Aristea Sinanioti-Maroudi (Athens–Thessaloniki: Sakkoulas, 2019), 117 ff. 17ICO,Big Data, Artificial Intelligence, Machine Learning and Data Protection (2017), 7, https://ico.org.uk/media/for-organisations/documents/2013559/big-data-ai-ml-and -data-protection.pdf 18EthemAlpaydin,Introductionto MachineLearning (Cambridge,MA:MIT Press, 2020). 14 Introduction volves the capacity for efficient action with little or no supervision.19 It is important, however, to emphasise the following: (a) machines do not act independently (though they may give the impression of doing so), but mimic human behaviour;20 (b) the knowledge base is the result of human effort; (c) machines do not learn on their own: they are guided by us; and (d) they do not display discriminatory behaviour on their own (for example, on the basis of race, ethnicity, or gender), but reproduce patterns of human behaviour which they copy.21 B. General Purpose Artificial Intelligence (GPAI) According to Article 3(63) of the Regulation, a General Purpose AI (GPAI) model is defined as an AI model trained on very large volumes of data using self-supervision at a scale that demonstrates significant generality. Such a model can competently perform a wide range of discrete tasks, regardless of how it is brought to market, and may be integrated into a variety of downstream systems or applications. This definition does not cover AI models used, prior to market release, for research, development, or prototyping activities. AGPAI system is an AI system based on a GPAI model that has the potential to serve a variety of purposes, both for direct use and for integration into other AI systems. GPAI systems may be used as, or integrated into, high-risk AI systems. GPAI models that do not pose systemic risks will be subject to limited requirements,for exampleon transparency, whereas those that do pose systemic risks will be required to comply with stricter rules. GPAI systems, unlike task-specific AI systems, do not have a single specified purpose of use. For example, a single bot could be used to generate both love poems 19Giorgos Giannakopoulos, Artificial Intelligence: A Discreet Demystification (Athens: Ropi, 2020), 129. 20Georgios I. Zekos, Internet and Artificial Intelligence in Greek Law (Athens–Thessaloniki: Sakkoulas), 73. 21Georgios Giannopoulos, presentation at the webinar of the European Laboratory of Bioethics, Technoethics and Law on Artificial Intelligence, May 16, 2022, https://bioe thics.panteion.gr/webinar-%cf%84%ce%b5%cf%87%ce%bd%ce%b7%cf%84%ce%ae% cf%82-%ce%bd%ce%bf%ce%b7%ce%bc%ce%bf%cf%83%cf%8d%ce%bd%ce%b7%cf %82/ 15 II. Terminology and characteristics of artificial intelligence and hate speech. The system can be likened to digital plasticine: from the same raw material one can fashion outputs of very different risk profiles, depending on how it is used. From the same digital plasticine, one could fashion a harmless toy water pistol, or, if adapted maliciously, something far more dangerous.22 C. The parties involved According to Article 3(3-8), the parties involved are defined as follows: ‘Provider’ means a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge. ‘Deployer’ means a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity. ‘Authorised representative’ means a natural or legal person located or established in the Union who has received and accepted a written mandate from a provider of an AI system or a general-purpose AI model to, respectively, perform and carry out on its behalf the obligations and procedures established by this Regulation. ‘Importer’ means a natural or legal person located or established in the Union that places on the market an AI system that bears the name or trademark of a natural or legal person established in a third country. ‘Distributor’ means a natural or legal person in the supply chain, other than the provider or the importer that makes an AI system available on the Union market. ‘Operator’ means a provider, product manufacturer, deployer, authorised representative, importer or distributor. 22Rolf Schwartmann, Kristin Benedikt, Moritz Köhler, and Markus Wünschelbaum, Erste Hilfe zur KI-Verordnung: KI-Kompetenz, Rechte, Pflichten (Munich: C.H. Beck, 2025), 7. 16 Introduction D. Algorithm The word algorithm derives from the Persian mathematician Muhammadibn M¯ us¯ aal-Khw¯ arizm¯ ı,who lived around825A.D.TheLatin form of his name, Algoritmi, gave rise to the term algorithm.23 Some algorithms have existed for thousands of years.24 An algorithm25 is a finite sequence of actions26, strictly defined and executable within finite time, aimed at solving a problem. It consists of operating rules for solving a problem through a finite number of steps.27 It is a set of predefined rules that must be applied in a specific sequence to solve a problem.28 For example, tying a tie or solving a Rubik’s cube requires a finite sequence of actions. Solving a problem requires not only identifying a logical procedure but also seeking the method that minimises cost in terms of time and resources.29 The sequence of actions leads to the desired result. The sequence is not necessarily unique, since there are multiple ways to tie a tie or solve the cube. The term algorithm survived for a thousand years as a rare expression, meaning a systematic process of numerical manipulation.30 In short, it is a rule-based process.31 23Aurélie Jean, On the Other Side of the Machine: A Journey into the Land of Algorithms, trans. Giorgos Bolierakis (Athens: Stere¯ oma, 2023), 38. 24Introduction to the Principles of Computer Science, available at https://ebooks.edu.gr/ ebooks/v/html/8547/2716/Pliroforiki_B-Lykeiou_html-empl/index2_2.html 25On the concept of the algorithm, see in detail Chryssoula P. Moukiou, Algorithms and Administrative Law (Athens–Thessaloniki: Sakkoulas, 2025), 1 ff. 26Leonidas Kanellos, Applications of Artificial Intelligence in Law and Judicial Practice (Athens: Nomiki Vivliothiki, 2021), 50. 27Aurélie Jean, On the Other Side of the Machine: A Journey into the Land of Algorithms, trans. Giorgos Bolierakis (Athens: Stere¯ oma, 2023), 33. 28Matina Giannakourou, “The Regulation of Algorithmic Labour Administration in the Draft Legislative Initiatives of the EU: Quo vadis, Europa?,” in Artificial Intelligence and Labour Law, ed. Matina Giannakourou and Christina Deliyianni-Dimitrakou, Labour Law Review (2023), 645 ff. (648). 29Aurélie Jean, On the Other Side of the Machine: A Journey into the Land of Algorithms, trans. Giorgos Bolierakis (Athens: Stere¯ oma, 2023), 59. 30Introduction to the Principles of Computer Science (2nd Lyceum) – Student Book (Enriched), available at https://ebooks.edu.gr/ebooks/v/html/8547/2716/Pliroforiki_ B-Lykeiou_html-empl/index2_2.html 31Manolis Andriotakis, Artificial Intelligence for All (Athens: Psychogios, 2022), 27. 17 II. Terminology and characteristics of artificial intelligence An algorithm may use AI techniques and therefore fall within the scope of the AI Act, but if it does not act autonomously and lacks adaptability, it will not fall within that scope. Often, linear algorithms do not fall under the definition of AI. One of the most significant issues associated with algorithms is bias. Biases may arise from many factors, including social environment, education, experience, and statistics.32 Women, for example, are underrepresented in computer science research teams and tend to be perceived as research team secretaries rather than full members.33 Similarly, algorithms may suggest higher insurance premiums for people of colour than for white people, on the basis that, on average, they have lower incomes, drive older cars, and thus pose higher costs to insurers.34 This, however, is not a valid reason to treat such a trend as a systematic condition applying to every person of colour.35 A potential solution would be the development of algorithmic observers, designed to assess the validity and representativeness of the data.36 E. Distinctive characteristics of artificial intelligence It follows from the above that AI is a distinct, autonomous technology, largely dependent on the boundaries set by its developer. On a certain level, AI may be compared to an animal whose nature cannot be fully controlled.37 Given that the AI Act is very recent, that the necessary experience has not yet been acquired, and that case law and interpretative guidelines are still lacking, it is not entirely clear what does and does not fall within the concept of AI under it.38 Notwithstanding the above, if one were 32Aurélie Jean, On the Other Side of the Machine: A Journey into the Land of Algorithms, trans. Giorgos Bolierakis (Athens: Stere¯ oma, 2023), 138. 33Ibid. 34Ibid., 139. 35Ibid. 36Ibid., 154. 37Rolf Schwartmann, Kristin Benedikt, Moritz Köhler, and Markus Wünschelbaum, Erste Hilfe zur KI-Verordnung: KI-Kompetenz, Rechte, Pflichten (Munich: C.H. Beck, 2025), 6. 38Michael Rohrlich, KI und Recht (Munich: Hanser, 2025), 6. 18 Introduction to identify the building blocks of AI under the AI Act, these would be autonomous operation, adaptability, learning, inference, and contextual understanding. A consequence of autonomy is unpredictability.39 The difference between algorithms and AI lies mainly in autonomy, inference, and adaptability.40 This means that a predefined algorithm lacks autonomy and adaptability and does not generate inferences. By contrast, AI canoperate onthebasis of impreciserules, adapt, evolve,and develop autonomously, setting its own operational goals and the means for achieving them.41 The inference mechanism relies on the knowledge base, applying the facts to the rules in order to draw conclusions.42 A classical algorithm is predictable and mechanical, executing the precise instructions programmed into it without any possibility of deviation.43 By contrast, AI does not operate on predefined rules, but relies on learning mechanisms and systems that adapt to data. An algorithm is a precise step-by-step procedure for solving a problem or performing a task, such as tying a tie.44 By contrast, AI relies on algorithms for its operation but uses them to learn and make decisions. An algorithm is a strictly defined sequence of instructions, executed in a predictable manner. Although AI relies on algorithms, it goes beyond them, as it can adjust its behaviour without explicit instruction. In other words,thealgorithm executes, whereas AI evolves.45 According to Christos Papademetriou: “[...] AI is not algorithms [...] theusage iscommon,butit isinaccurate.Analgorithm issomethingelse: it is something we have programmed, corrected, tested, and essentially we know how it works and can more or less predict it. AI is something 39Roman Yampolskiy, Artificial Intelligence: Inexplicable, Unpredictable, Uncontrollable (Athens: Epikentro, 2024), 33. 40Giorgos Giannakopoulos, Artificial Intelligence: A Discreet Demystification (Athens: Ropi, 2020), 128. 41Spyros Vlachopoulos, The Selfish Gene of Law and the Law of Artificial Intelligence (Athens: Eurasia, 2023), 89. 42Giorgos Giannopoulos, Introduction to Legal Informatics (Athens: Nomiki Vivliothiki, 2018), 218, op. cit. 43Panagiotis Soilentakis, Artificial Intelligence at the Core of Constitutional and Administrative Law (Athens: Nomiki Vivliothiki, 2025), 31. 44Ibid. 45Ibid. 19 II. Terminology and characteristics of artificial intelligence far more elusive and unpredictable, more organic. It is an artefact that we have exposed to an astronomical number of experiences, which have subtly reshaped its inner workings in the process of adaptation. And of course,it reproducestheflawsofourculture, sinceitwastrainedonit”.46 In this context, autonomy in AI lies in the ability of a programme to actwithouthumanintervention.Thisactiondoes notconsistofcarrying out a task assigned by the user, but of altering the instructions originally given by the programmer in order to complete it.47 A typical example is the traffic light that regulates traffic without human intervention. A conventional traffic light will alternate between red and green as programmed, for example two minutes green, half a minute red. At certain junctions and times of day this works well, but when conditions change it frustrates drivers, with short green lights at rush hour or standstills despite the absence of traffic.48 This may irritate some drivers, but the technology behind such lights is not dangerous; it merely enforces rules set by humans.49 By contrast, an autonomous traffic light system can change its operation without human intervention and adapt to actual traffic volume. It could, for example, recognise that pedestrians with children need more time to cross, or that the braking distance of a 16-tonne lorry requires the red light to be activated earlier than for a moped. The technological advantage expected from such systems is the automatedpersonalisation of services.50 If it determines on its ownwhen to activate the red and green lights, we are dealing with AI. If, by contrast, it has merely been trained to stop when it detects a parent with a baby, then it is acting non-autonomously on the basis of human instructions, and we are not dealing with AI. AI systems are often described as a black box, reacting and communicating in ways that resemble human behaviour. This is precisely the 46Sofia Christou, “Christos Papadimitriou in Kathimerini: ‘Archimedes Is in Danger,’” Kathimerini, July 10, 2025, https://www.kathimerini.gr/opinion/interviews/563640 649/christos-papadimitrioy-stin-k-o-archimidis-vrisketai-se-kindyno/ 47Rolf Schwartmann, Kristin Benedikt, Moritz Köhler, and Markus Wünschelbaum, Erste Hilfe zur KI-Verordnung: KI-Kompetenz, Rechte, Pflichten (Munich: C.H. Beck, 2025), 16. 48Ibid. 49Ibid. 50Ibid. 20 Introduction aim of modern AI tools: to appear “creative” and generate “new” content. There are various types of AI systems, but most share the feature that – with few exceptions – they are controlled by textual commands, known as prompts. Some AI tools generate text, others create images, some “compose” music, and others produce video, among other outputs. Meanwhile, multimodal systems already exist, such as ChatGPT4.51 Such systems can process not only text, but also voice commands, and can even interpret visual content. Moreover, they can generate not only text but also images and other forms of media.52 Expert systems that merely compare patterns, without being designed for autonomous operation and adaptability, do not fall within the scope of the AI Act. Any system that cannot adapt on its own does not fall within the scope of AI law. Classic examples of non-autonomous systems include corporate tools for assessing contracts according to defined specifications (for example, checking which contract is subject to limitation) and the AI system used in the land registry. Other systems monitor purchasing behaviour to optimise inventory management. In the field of medicine systems can assist in indicating whether an intestinal abnormality or a skin lesion is benign. In this case, the requirements of the GDPR on the obligation of human intervention under Article 22 in automated individual decisions apply, but the AI Act does not.53 F. Difference from human beings AI applications possess vast reserves of knowledge, enabling them to support humans in solving complex problems and making significant decisions for the future of a country and the planet.54 Due to rapid advances 51This is the fourth generation of OpenAI’s software, which has analysed vast amounts of information from across the Internet in order to determine how to generate text resembling human writing and to provide users with detailed answers to questions. 52Michael Rohrlich, KI und Recht (Munich: Hanser, 2025), 7. 53Rolf Schwartmann, Kristin Benedikt, Moritz Köhler, and Markus Wünschelbaum, Erste Hilfe zur KI-Verordnung: KI-Kompetenz, Rechte, Pflichten (Munich: C.H. Beck, 2025), 6. 54Prokopios Pavlopoulos, “‘Dilemmas’ of Legal Science in the Context of the Challenges of Artificial Intelligence,” https://www.constitutionalism.gr/dilimata-tis-nomikis-e pistimis-stis-prokliseis-tis-ai/ 21 II. Terminology and characteristics of artificial intelligence in their programming, they may even surpass human beings.55 In this context, “it is relatively easy to make computers perform well on intelligence tests or in chess matches, but difficult, if not impossible, to endow them with the sensory and motor skills of a one-year-old child”.56 Even so, the transition from AI to “artificial consciousness” remains impossible.57 In the absence of artificial consciousness, AI can function only in a subsidiary role and within defined limits,58 and always under human supervision. An algorithm will never fully understand a human being, as it has no access to the subconscious.59 At the end of the day, AI differs fundamentally from human intelligence: human intelligence lies in the capacity to learn and comprehend,60 whereas AI lies in the ability of machines to perform tasks that, if carried out by humans, would require the exercise of intelligence.61 G. The issue of the dangerousness of artificial intelligence The risk posed by AI is assessed on a case-by-case basis. The technology in question carries both benefits and risks.62 For instance, a translation tool 55Ibid. 56Erik Brynjolfsson and Andrew McAfee, The Second Machine Age: Work, Progress, and Prosperity in a Time of Brilliant Technologies, trans. Giorgos Nathanael (Athens: Kritiki, 2016). 57Prokopios Pavlopoulos, “‘Dilemmas’ of Legal Science in the Context of the Challenges of Artificial Intelligence,” https://www.constitutionalism.gr/dilimata-tis-nomikis -epistimis-stis-prokliseis-tis-ai/; and idem, “Critical Reflections on the Relevance of Aristotle’s Positions on Law and Justice in the Age of Artificial Intelligence,” Public Law Review 1 (2025): 41 ff. (51). 58Prokopios Pavlopoulos, “‘Dilemmas’ of Legal Science in the Context of the Challenges of Artificial Intelligence,” https://www.constitutionalism.gr/dilimata-tis-nomikis-e pistimis-stis-prokliseis-tis-ai/ 59Aurélie Jean, On the Other Side of the Machine: A Journey into the Land of Algorithms, trans. Giorgos Bolierakis (Athens: Stere¯ oma, 2023), 198. 60Michael Negnevitsky, Artificial Intelligence: A Guide to Intelligent Systems, 3rd ed. (Boston: Addison Wesley, 2011), 1. 61Max Tegmark, Rob Shapiro, et al., Life 3.0: Being Human in the Age of Artificial Intelligence (New York: Vintage Books, 2018), 50–51. 62Kyriakos Pierrakakis, introduction to ManolisAndriotakis,ArtificialIntelligenceforAll (Athens: Psychogios, 2022), 9. 22 Introduction can generally be very useful for translating a restaurant menu. If, however, the translation is incorrect, a customer may consume something to which they are allergic and suffer harm. Translation for tourist purposes is largely harmless, but if it is carried out on behalf of a court63 for certificate verification, human oversight is essential.64 Similarly, the use of AI is harmless when generating a shopping list based on a buyer’s preferences but becomes risky when applied in education (for example when assessing trainees) or employment (such as in recruitment processes). Beyond education and employment, AI poses particular risks when applied in health, justice65 and electoral processes. The boundaries between beneficial and harmful uses of AI are often blurred. Consider, for example, an application that can identify why a newborn is crying. At first sight this seems highly useful, yet it raises a dilemma: should a device intrude into the parent–child relationship, or is it preferable for parents to turn to their own child rather than a machine?66 The danger of AI lies in three important capabilities that merit special attention: (a) Its ability to programme, reproduce, and improve itself. (b) Its access through the internet to virtually all services across the globe. 63With Decision 13/2024, the HDPA imposed on the Ministry of Migration and Asylum a fine of €175,000 for the Centaur and Hyperion systems. Two years earlier, the NGO Homo Digitalis, in collaboration with civil society organisations (the Hellenic League for Human Rights and HIAS Greece) and Niovi Vavoula, had filed a complaint against the Ministry for these systems in reception and accommodation centres for asylum seekers. Source: https://homodigitalis.gr 64Rolf Schwartmann, Kristin Benedikt, Moritz Köhler, and Markus Wünschelbaum, Erste Hilfe zur KI-Verordnung: KI-Kompetenz, Rechte, Pflichten (Munich: C.H. Beck, 2025), 9. 65Ibid., 10. 66Giorgos Giannakopoulos, Artificial Intelligence: A Discreet Demystification (Athens: Ropi, 2020), 39. 23 I. The adoption of the Artificial Intelligence Act and related legislation of the Parties, composed of its signatories, tasked with assessing the extent of its implementation. Their findings and recommendations support state compliance with the Framework Convention and safeguard its long-term effectiveness. The Conference of the Parties also facilitates cooperation with stakeholders, including through public hearings on aspects of the Convention’s implementation. Ultimately, the AI Act does not resolve all issues, as other legal regimes continue to apply in parallel, including data protection, labour, consumer protection, media, child protection, and intellectual property law. The introduction of the AI Act is not without its difficulties. According to former Italian Prime Minister Mario Draghi, the AI Act is “a source of uncertainty”. In his view, implementation at this stage should be paused until the drawbacks are better understood. The rules aim to regulate AI systems based on the level of risk they pose to society, ranging from limited oversight to stricter compliance requirements for highrisk systems and outright prohibitions. “The first rules, which included the ban on ‘unacceptable risk’ systems, were introduced without major complications. Codes of practice signed by most major developers, along with the Commission’s guidelines, have clarified responsibilities. The next stage, however, which concerns high-risk AI systems in sectors suchascriticalinfrastructureandhealth,mustremain proportionateand continue to support innovation and development”.80 80“Draghi Calls for Pause to AI Act to Gauge Risks,” Euronews, September 16, 2025, http s://www.euronews.com/my-europe/2025/09/16/draghi-calls-for-pause-to-ai-act-t o-gauge-risks 30 II. Comparative overview of the regulation of artificial intelligence outside the EU A. United Kingdom The UK has distanced itself from the EU’s approach to regulating AI. In its 2023 White Paper on AI regulation, the government outlined a proportionate, innovation-friendly approach designed to enable the UK to seize the opportunities of AI while addressing the risks the technology may pose. This principles-based framework is implemented through the UK’s existing regulators, drawing on their expertise to foster innovation and the uptake of AI across the economy. The White Paper rests on five principles but lacks binding legislative force, as implementation is largely left to regulators, with no obligation to enforce it. In 2024, the Government published its response to the consultation on the White Paper on AI regulation. That same year, ministers asked key sectoral and crosssector regulators to report on how they were implementing the White Paper’s proposals and developing their strategic approaches to AI. The UK Data Act, which received Royal Assent on 19 June 2025, establishes a new regulatory framework for AI and algorithmic systems through amendments to existing data protection laws. The Act imposes strict controls on significant decisions made solely by automated processing. Where algorithms process special categories of data, such as data on health, race, or biometric information, organisations must obtain explicit consent, demonstrate contractual necessity, or hold legal authority. Decisions based on recognised legitimate interests cannot be fully automated. Regardless of the legal basis, controllers must inform affected individuals,allowhumanintervention,andestablishformalproceduresfor challenging automated decisions. To support AI development, the Act broadens the concept of scientific research to include technological development and demonstration, creating clearer legal bases for using per31 II. Comparative overview of the regulation of artificial intelligence outside the EU sonal data in model training. Further processing for research purposes is automatically deemed compatible with the original purposes. Within nine months, the government must present to Parliament an economic impact assessment and a comprehensive report on the implications of AI development for intellectual property rights, including technical standards, licensing, and enforcement mechanisms. New criminal provisions target the creation, and solicitation of creation, of AI-generated personal images without consent. B. United States of America (U.S.) The U.S. has also taken steps to regulate AI. The first federal AI measures wereenactedeither as stand-alonestatutesor as AI-relatedprovisionsembedded in broader laws. Notable among these is the National Artificial Intelligence Initiative Act of 2020 (H.R. 6216), which established a U.S. AI initiative and set guidance for AI research, development, and evaluation across federal science agencies. Other Acts directed agencies to advance AI programmes and policies across the federal government, such as the AI in Government Act (H.R. 2575) and the Advancing American AI Act (S.1353). In the 117th Congress, at least 75 bills were introduced addressing AI, machine learning, or related provisions. Six of these were enacted. In the 118th Congress, as of June 2023, at least 40 AI-related bills had been introduced, none of which have been enacted. AI-related bills have been enacted since 2015. In January 2023, the White House Office of Science and Technology Policy released the Blueprint for an AI Bill of Rights, and the National Institute of Standards and Technology issued its AI Risk Management Framework. In the summer of 2023, two broader policy roadmaps were announced, namely the SAFE Innovation Framework for AI Policy and the Blumenthal–Hawley Comprehensive AI Framework, both seeking bipartisan backing to guide future congressional action on AI. In April 2023, in a joint statement, four federal agencies emphasised that their enforcement powers apply to AI and that advanced technology is no excuse for breaking the law. At state level, Stanford University reports that between 2016 and 2022, fourteen states enacted AI-related legislation, led by Mary32 General Section land (seven bills), followed by California (six), and Massachusetts and Washington (five each).81 On 30 October 2023, President Joe Biden issued an Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence. It builds on earlier initiatives, including an Order directing agencies to tackle algorithmic discrimination and voluntary commitments by major U.S. companies (Amazon, Google, Meta, Microsoft, OpenAI) to deploy AI safely, securely, and responsibly. The Order spans eight policy areas: First, it focuses on new standards for the safety and security of AI. For example, developers of the most powerful AI systems must share safety-test results and other critical information with the U.S. government. Government agencies are tasked with developing standards, tools, and tests to help ensure that AI systems are secure and reliable. New standards will address the risk of using AI to create dangerous biological materials and protect U.S. citizens from AI-enabled fraud and deception. Second, the government will launch an advanced cyber-security programme to develop AI tools that identify and remediate vulnerabilities in critical software. The National Security Council and the White House Chiefof Staff havebeentasked with developing a national-securitymemorandum to guide further action on AI and security. Third, to protect privacy from AI-related risks, the Order prioritises federal support for privacy-preservingtechniques, strengthens related research and technologies, requires agencies to assess how they collect and use commercially available data, and calls for guidelines to evaluate the effectiveness of privacy-preserving methods. Fourth, to promote equity and civil rights, the Order calls for clear guidance for homeowners, federal benefit programmes, and federal contractors; measures to address algorithmic discrimination; and best practices to ensure fairness across the criminal-justice system. It also seeks measures to foster responsible use of AI in healthcare and to support its potential to transform education. 81Stanford Institute for Human-Centered Artificial Intelligence (HAI), AI Index Report 2023, Chapter 6, https://aiindex.stanford.edu/wp-content/uploads/2023/04/HAI_ AI-Index-Report-2023_CHAPTER_6-1.pdf 33 II. Comparative overview of the regulation of artificial intelligence outside the EU Fifth,tosupportworkers,theOrdercallsfor principlesand best practices tomitigate harms and maximisebenefits,and forareport on labourmarket impacts with proposals for mitigation through stronger federal support. Sixth, to promote innovation and competition, the Order aims to catalyse research nationwide, support fair, open, and competitive AI ecosystems, and attract highly skilled immigrants and non-immigrants in critical fields to study, live, and work in the U.S. Seventh, to advance U.S. leadership abroad, the Order calls for expanding bilateral and multilateral AI commitments, accelerating vital AI standards, and promoting safe, responsible, rights-affirming AI development and deployment to address global challenges. Eighth, to ensure responsible and efficient government use of AI, the Order seeks new agency guidelines, faster and more efficient procurement of AI products and services, and accelerated recruitment of AI experts across government. The Executive Order was followed by detailed implementation guidance from the Office of Management and Budget. In 2025, 48 states and Puerto Rico introduced AI-related legislation, while26 states adopted or enactedmore than 75 new measures. Examples include: •Arkansas enacted legislation clarifying ownership of AI-generated content,recognisingeither thepersonwhoprovidesthedataor inputs to train a generative AI model, or the employer if the content is created in the course of employment. The law further requires that such content must not infringe existing copyright or other intellectual property rights. •Montana’s new Right to Compute Act sets requirements for critical infrastructure managed by AI systems. It obliges administrators to develop risk management policies aligned with defined standards, such as the latest version of the National Institute of Standards and Technology’s Artificial Intelligence Risk Management Framework. It further prohibits government restrictions on private ownership or use of computing resources for lawful purposes, unless necessary to serve a compelling public interest. 34 General Section •North Dakota enacted legislation prohibiting the use of AIpowered robots to monitor or harass individuals, thereby extending existing harassment and surveillance laws. •New Jersey has adopted a resolution urging generative AI companies to make voluntary commitments to protect workers who report violations. •New York passed a law requiring state agencies to publish detailed information about automated decision-making tools on public websites. Said law also amended the Public Administration Law to enhance employee protections, including that when an AI system is used by state government, it cannot affect employees’ existing rights under a collective bargaining agreement, and that it must not lead to the replacement or loss of a job. C. Canada In September 2023, François-Philippe Champagne, Minister of Innovation, Science and Industry, announced the Voluntary Code of Conduct for the Responsible Development and Management of Advanced Generative Artificial Intelligence Systems (Artificial Intelligence and Data Act, AIDA). Said Code temporarily provides Canadian companies with common standards and allows them to demonstrate, on a voluntary basis, that they are responsibly developing and using AI generative systems until formal regulation enters into force. The Code, which draws on feedback from the consultation process to develop a Canadian code of practice for generative AI systems, aims to strengthen public confidence in these technologies. Under AIDA, companies are held accountable for AI activities under their control. They must implement governance mechanisms and policies that identify and address risks associated with their AI systems, while providing users with sufficient information to make informed decisions. AIDA would introduce new requirements for firms to ensure the security and fairness of high-impact AI systems at every stage of the process: •Risk-based approach: AIDA would regulate AI systems based on their potential impact, with stricter rules for high-impact systems. 35 II. Comparative overview of the regulation of artificial intelligence outside the EU •Focus on harm prevention: It aimed to minimise the risks of harm to individuals and communities associated with AI systems. •Accountability: AIDA would hold companies accountable for the AI systems they develop and use. •Prohibition of unacceptable risks: It was proposed to ban certain AI applications, such as social scoring and predictive policing. •Transparency and protection of users: AIDA emphasised transparency and the provision of sufficient information to users to enable them to make informed decisions about AI systems. Bill C-27, which contained AIDA, was repealed following the suspension of Parliament, meaning that AIDA is not currently in force and Canada has no specific AI legislation in place. AlthoughAIDA isnot currentlyapplied,the Canadiangovernmentis expected to revisit AI legislation in the future, potentially incorporating some of AIDA’s concepts. D. China On 27 August, the State Council of China released the “AI Plus” plan, designedto integrateartificialintelligence acrossa broadspectrumof sectors. The plan prioritises the adoption of AI in science and technology, industrial development, consumer services, public welfare, governance, and international cooperation. It sets clear milestones for AI integration in key sectors, aiming to exceed 70 per cent by 2027 and 90 per cent by 2030. By 2035, China envisions a fully intelligent economy and society. On22AugusttheMinistryofIndustryand InformationTechnology, together with the Ministry of Science and Technology, the Cyberspace Administration of China and other agencies, issued draft AI ethics rules for public consultation.82 The draft ethics rules apply to all AI research and development and services in China that could affect health and safety, reputation, the environment, public order and sustainability. 82“China Releases ‘AI Plus’ Plan, Rolls Out AI Labelling Law,” IAPP News, August 27, 2025, https://iapp.org/news/a/china-releases-ai-plus-plan-rolls-out-ai-labeling-law 36 General Section Developers and service providers must adhere to principles of fairness, accountability, justice, risk responsibility and respect for life and human dignity. AI projects falling under the rules must undergo ethics review, either internally by ethics committees or externally through qualified service centers. Regulators are also preparing a detailed list of high-risk AI activities, such as algorithms that can mobilize public opinion or automated decision-making systems with major safety and health implications that will require expert second-level review.83 Another major shift came 1 September with the rollout of China’s mandatory AI labeling rules.84AI-generated content service providers must now clearly mark AI-generated content. Visible labels with AI symbols are required for chatbots, AI writing, synthetic voices, face generation/swap and immersive scene creation or editing. For other AIgenerated content, hidden labels, such as watermarks, are acceptable. Internet platforms must act as watchdogs; if they detect or suspect AIgenerated content, they must alert users and may add implicit labels themselves. Non-compliance carries serious consequences, including regulatory investigations, fines, business suspensions and revocation of business permits. In severe cases, criminal liability under the Cybersecurity Law, Data Security Law and Personal Information Protection Law may be triggered.85 E. India The Data Security Board of India has issued a policy template for security, privacy, and governance of AI, which outlines requirements for organisations that use AI systems.86 The standard covers machine learning, generative AI and agent-based AI, including autonomous systems capable of making independent decisions. Organisations are required to establish AI governance committees. 83Ibid. 84Ibid. 85Ibid. 86Data Security Council of India, “AI Security, Privacy and Governance Policy Template,” https://www.dsci.in/resource/content/ai-security-privacy-and-governance-policy-t emplate 37 II. Comparative overview of the regulation of artificial intelligence outside the EU Key requirements include documenting data sources, model selection criteria, and validation results. High-risk applications, such as loan approval and fraud detection, must be subject to human oversight with defined intervention protocols. Organisations must implement safeguards against promptinjection, data poisoning, and unauthorised model extraction. The framework treats policies as “living documents” requiring regular updates. It distinguishes between business-facing and consumer-facing AI. Consumer applications must disclose AI interaction and provide feedback mechanisms for reporting errors or bias. For autonomous AI systems, the standard requires boundary constraints, security mechanisms, and accountability structures for emergent behaviours. It also requires monitoring for cascading failures and unintended interactions between agents. Organisations can determine which provisions apply depending on their context. The standard further includes guidance on data governance, secure deployment, access controls, and privacy protection. 38 III. Does artificial intelligence require specific regulation? A legitimate question that arises is whether specific regulation is needed for AI or whether it could be addressed within the existing institutional framework. Is a new set of legal rules necessary or is the analogous applicationofexistinglegalprinciplesanddoctrinesufficient?87 AI isregarded as the fourth industrial revolution and cannot be placed under the umbrella of existing legislation enacted for other purposes. Therefore, effective legislation is needed that (a) balances the protection of autonomy, privacy, and intellectual property with the promotion of innovation and research, the strengthening of the market, and the protection of competition; and (b) guarantees the security of AI systems. At the same time, legislation must support progress and avoid hindering it. The lawyer’s position on AI, however, is somewhat uneasy, oscillating “in a pendulum between hope and fear”.88 Continuous information and strong reflexes are required to address new risks.89 The call for “no legislation”90 is not without problems, either, as we are not yet ready for such an approach. It is further argued that technology does not in itself change the law, but that the law changes when technology creates a powerful new economic interest.91 87Dimitrios Koukiadis, “The Regulatory Challenges of Artificial Intelligence and the Issue of Recognition of Personality,” Journal of Law and Technology (2020): 17 ff. (19). 88Lilian Mitrou, “The Regulation of Artificial Intelligence,” Ta Nea, January 29, 2022, https://www.tanea.gr/print/2022/01/29/greece/i-rythmisi-tis-texnitis-noimosynis/ 89Eugenia Alexandropoulou-Aigyptiadou, Personal Data (Athens: Nomiki Vivliothiki, 2016), 219. 90Konstantinos Christodoulou, presentation at the webinar of the European Laboratory of Bioethics, Technoethics and Law on Artificial Intelligence, May 16, 2022, https:// www.youtube.com/watch?v=4W3npEt_WDA 91Curtis E. A. Karnow, “Introduction to Law and Artificial,” in Research Handbook on the Law of Artificial Intelligence, ed. Woodrow Barfield and Ugo Pagallo (Cheltenham, UK: Edward Elgar, 2018), xix. 39 V. Guiding principles that should govern artificial intelligence109 The development of AI should be based on the following guiding principles, dictated by the ethics of responsibility.110 A. Respect for human dignity AI systems must be developed in ways that respect the value of human beings and do not reduce human beings to mere instruments to serve other ends. In this respect, the protection of the value of human choice and control is of central importance.111 A classic example of degradation is biometric monitoring, which is in principle prohibited by the AI Act as an unacceptable risk. In the same vein, AI must not be designed to manipulate individuals or influence their will. It is therefore necessary to takemeasuresto preventAI systemsfromexploiting,undermining, ordiminishing people’s self-determination. People must retain the power to make their own choices.112 Furthermore, applications must not exploit the vulnerabilities of at-risk individuals, such as people with dementia. A typical example is the interaction of a patient with a robot, when the patient thinks they are interacting with a human being.113 All these factors must be taken into serious consideration by the algorithm developer 109For an in-depth analysis of the principles, see Plan for Greece’s Transition to the Age of Artificial Intelligence, 15, https://foresight.gov.gr/wp-content/uploads/2024/11/ Sxedio_gia_tin_metavasi_TN_Gr.pdf 110Stavroula Tsinorema, “Artificial Intelligence with a Human Face: Towards a Technoethics of Responsibility”, in Liber Amicorum Ismini Kriari (Athens: Sideris, 2025), 259 ff. (274). 111Ibid. 112Ibid. 113Vasileios Baros and Louis Henri Seukwa, “Article 2, Protection of Human Dignity,” in Artificial Intelligence, Human Rights, Democracy and the Rule of Law, ed. Evripidis Stylianidis (Athens: Nomiki Vivliothiki, 2025), 27 ff. (31). 46 General Section so that the use of AI respects human dignity and does not lead to the instrumentalisation of human beings. B. Privacy The functioning of AI requires the collection and processing of large volumes of data that are difficult to control by the data subject. The dependence of AI reliance on data has created a critical paradox: the more data that are fed into an AI system, the more accurate its output will be, but also the greater the risk of privacy breaches114 by malicious actors seeking to extract sensitive information.115 In short, personal data feeds AI, which in turn generates new – and more – data. The complexity of coexistence between an efficient algorithm, which requires a lot of data for its training, and data protection raises the question of whether existing data protection law can cope with the demands of new technologies, or whether it has become a problem in new developments. The answer to this question is complex. It is a fact that classical data protection principles tend to give priority to the good of data protection over equivalent goods of information, innovation and research.116 For this reason, the regulation of AI requires a holistic approach that considers both data protection and the free flow of information, technology and research. Intelligent systems must not operate in a way that unlawfully interferes with the right to privacy.117 114Mousam Khatri, Data Privacy in the Age of Artificial Intelligence (AI), 2023, https:// www.linkedin.com/pulse/data-privacy-age-artificial-intelligence-ai-mousam-khatri/ 115Accordingto theIdentityTheft ResourceCenter,in 2021therewere1,862databreaches, 23% higher than the previous all-time high (2017). See Cem Dilmegani, Responsible AI: 4 Principles & Best Practices in 2024,AI Multiple Research, 2024, https://research. aimultiple.com/responsible-ai/ 116Fereniki Panagopoulou-Koutnatzi, “Constitutional Consideration of Law 4624/2019 on Data Protection,” DiMEE (2019): 328 ff. (329). 117Stavroula Tsinorema, “Artificial Intelligence with a Human Face: Towards a Technoethics of Responsibility”, in Liber Amicorum Ismini Kriari (Athens: Sideris, 2025), 259 ff. (275). 47 V. Guiding principles that should govern artificial intelligence C. Human well-being AI applications should promote individual well-being, rather than human marginalisation, degradation or decline. This means that they must be recognised as a tool that supports and inspires people to improve their qualityof lifebymakinguse of their unique humanabilities,in the workplace, education, personal relationships, the aesthetic realm, as well as in their interaction with the state. In this sense, measures must be taken to ensure people’s well-being as far as possible.118 AI should not be seen as a means of replacing human labour with the sole aim of reducing costs. Notwithstanding the above, however, the fact that well-being is difficult to measure is a cause for concern. D. Pluralism The principle of pluralism in AI has three main components. First, algorithms must be trained on data that reflect the majority of the population, and not only the characteristics of a single population group. Linguistic, educational and intellectual monoculture should not be promoted. Second, the regulation of AI must take into account human rights, economic well-being, environmental protection, human security and national security, and seek to resolve any tensions between them. Third, regulatory issues must concern a wide range of disciplines, from the mathematical and physical sciences to the humanities and social sciences, since AI applications cover fields ranging from healthcare to the judicial system. E. Participation As AI will permeate and affect all aspects of human life, it is crucial that citizens have equal opportunities to participate in AI through access to relevant education, knowledge, technology, computational resources, and datasets. Such opportunities must exist in various areas, including in basic research related to AI, the development of AI applications, and the 118Ibid., 276. 48 General Section useof AI in the workplace and otherfields.Itis also necessary that AI governance reflects the views of all stakeholders, including citizens. Despite the risk of AI misuse that may threaten democratic processes through misinformation, deepfakes, and other means, it is equally important to recognise the ability of AI tools to support democratic processes, public debate, and large-scale decision-making. The principle of participation is inextricably linked to the principle of fairness, in the sense of determining who is entitled to receive benefits and who must bear the costs of developing AI applications.119 F. Algorithmic transparency120 Algorithms, data and decision-making processes of AI systems must be sufficiently accessible to interested parties so that the functioning of AI systems is understandable, explainable, reliable, justified, and accountable.121 This is a function of visibility and traceability of the decisionmaking process.122 In this sense, the publication of the algorithm is required under the condition laid down by the legislator.123 Transparency is essential for responsible decision-making regarding the development and implementation of AI systems, and for identifying the risks and benefits they entail. The principle of transparency seems to be put to the test in the case of AI. The information requirements imposed by the GDPR in Articles 13 and 14 are onerous, in particular with regard to the metadata recorded in the system’s database. The information provided may be incomplete, either because it is difficult to determine the purpose of the processing in advance with accuracy, or because of the technical complexity of the purpose or of the processing itself. 119Ibid. 120Chryssoula P. Moukiou, Algorithms and Administrative Law (Athens–Thessaloniki: Sakkoulas, 2025), 283. 121Apostolos Vorres, “Can theAlgorithm BeTransparent?”in Can the Algorithm... BeEthical, Be Fair, Be Transparent, Judge and Govern?, ed. Lilian Mitrou (Heraklion: University of Crete University Press, 2023), 151 ff. (151). 122Ibid., 44. 123Ibid., 108, 115. 49 V. Guiding principles that should govern artificial intelligence In addition to any difficulties in providing information, particular emphasis must be placed on the obligation of the controller to explain the logic applied by the AI system in the automated processing of the data, both prior to processing, in the context of informing the data subject in accordance with Articles 12 et seq. GDPR, and afterwards, when the data subject exercises the right of access under Article 15 GDPR. The purposeofprovidingthisinformationistoenablethedecisiontobechallenged.124 This raises concerns about the actual possibility of informing theaverage person—whether bythe controlleror,moregenerally, byany party involved — about the functioning of highly complex information systems and AI algorithms.125 Indeed, some AI systems have reached such a degree of autonomy that it is extremely difficult, if not impossible, for their manufacturers or operators to understand the system’s operating mechanism, let alone explain it in a simple, clear, and comprehensible way to someone without the necessary technical knowledge. These are the so-called “black boxes”, based on complex and constantly evolving algorithms that exceed the limits of human control.126 Theprincipleof transparencyis inextricablylinkedtothe principleof explainability, in the sense that the processes of decision-making through AI must be understandable.127 It must be possible to see and understand 124Ibid., 45. 125ICO,Big Data, Artificial Intelligence, Machine Learning and Data Protection (Wilmslow: Information Commissioner’s Office, 2017), 19, https://ico.org.uk/media/ for-organisations/documents/2013559/big-data-ai-ml-and-data-protection.pdf; and EDPS,Artificial Intelligence, Robotics, Privacy and Data Protection, Room Document, 38th International Conference of Data Protection and Privacy Commissioners, October 2016, 4, https://edps.europa.eu/sites/edp/files/publication/16-10-19_ marrakesh_ai_paper_en.pdf 126Apostolos Vorres and Lilian Mitrou, “Artificial Intelligence and Personal Data: A Perspective under the EU General Data Protection Regulation (GDPR) 2016/679,” Media and Communication Law Review (2018): 460 ff. (463); Agata Ferretti, Manuel Schneider, and Alessandro Blasimme, “Machine Learning in Medicine: Opening the New Data Protection Black Box,” European Data Protection Law Review 3 (2018): 320 ff.; and Chris Reed, “How Should We Regulate Artificial Intelligence?” Philosophical Transactions of the Royal Society A 376, no. 2128 (September 13, 2018). https://doi.org/ 10.1098/rsta.2017.0360 127Stavroula Tsinorema, “Artificial Intelligence with a Human Face: Towards a Technoethics of Responsibility”, in Liber Amicorum Ismini Kriari (Athens: Sideris, 2025), 259 ff. (277). 50 General Section all stages of decision-making. This is directly linked to the principle of clarity.128 G. Human control and supervision Technology must not be left free, but there must be constant human supervision.129 The ultimate responsibility lies with man. The human factor must never be eliminated. To this end, limits must be placed on the powers of AI. It is necessary to establish oversight mechanisms toensure that AI systems uphold the values we seek to govern their operation. Particular attention must be paid to the choice of the appropriate form of supervision, including human oversight, depending on the characteristics of the different AI systems and their field of application. In addition, it is necessary to weigh the risks and benefits associated with them. Nevertheless, supervision is not without problems, as the question arises whether humans can safely maintain control while benefiting from a higher form of intelligence.130 H. Adaptability AI is a multidimensional and constantly evolving technology, which requires an equally detailed and dynamic policy for its management. Such policy must adapt to new opportunities and challenges that arise over time, while maintaining a stable and predictable regulatory environment. International multilateral cooperation: effective regulation of AI cannot be achieved through the efforts of a single state alone. It is therefore crucial for Member States to participate in and contribute to international initiatives, and to draw lessons from the policy pro128Chryssoula P. Moukiou, Algorithms and Administrative Law (Athens–Thessaloniki: Sakkoulas, 2025), 77–78. 129Spyros Tassis, “Can the Algorithm Be Ethical?” in Can the Algorithm ... Be Ethical, Be Fair, Be Transparent, Judge and Govern?, ed. Lilian Mitrou (Heraklion: University of Crete University Press, 2023), 35 ff. (58 ff.). 130Roman Yampolskiy, Artificial Intelligence: Inexplicable, Unpredictable, Uncontrollable (Athens: Epikentro, 2024), 22. 51 V. Guiding principles that should govern artificial intelligence posals of other states, regional bodies and international organisations. International cooperation within the European Union (EU), the United Nations (UN) and the Organisation for Economic Co-operation and Development (OECD) is vital to ensure that AI is developed and applied in ways that promote the common good of humanity. I. Sustainability The rapid development and widespread deployment of powerful generative AI models have environmental consequences, such as increasing electricity and water consumption. The excitement surrounding the potential benefits of AI, from improving worker productivity to advancing scientific research, is hard to ignore. While the explosive growth of this new technology has enabled the rapid development of powerful models across many industries, the environmental consequences of this “golden age” remain difficult to determine. The computing power required to train generative AI models, which often have billions of parameters, such as OpenAI’s GPT-4, can demand vast amounts of electricity, leading to increased carbon emissions and pressures on the power grid. Moreover, deploying these models in real-world applications, enabling millions of people to use generative AI in their daily lives, and subsequently optimising them to improve their performance requires significant amounts of energy long after the initial development. In addition to electricity requirements, large quantities of water are required to cool the hardware used to train, develop, and optimise generative AI models, which can strain local water supplies and disrupt local ecosystems. The growing number of production AI applications has also ledto an increasein demand forhigh-performancecomputinghardware, adding indirect environmental impacts from manufacturing and transportation. All these issues can be addressed if AI is treated as a tool for development and sustainability. AI plays an important role in addressing environmental challenges, from designing more energy-efficient buildings to monitoring deforestation and optimising the development of renewable energy sources. The contribution of AI includes satellite monitoring of global emissions and smart homes that automatically switch off 52 General Section lights or heating after a set period. At the same time, specialised applications can curate, aggregate, and visualise the best available Earth observation and sensor data in near real time, producing forecasts on multiple factors such as atmospheric carbon dioxide concentration, changes in glacier mass, sea level rise, and so on. As experts hope, over time the goal is for the platform to become a mission control centre for planet Earth, where all vital environmental indicators are monitored seamlessly and guide corresponding actions. The solutions will not come from the use of AI alone. In most cases, multiple complementary technologies are combined, such as robotics, the Internet of Things, distributed energy resources, electric vehicles and others. While data and AI are essential for enhanced environmental monitoring, there is also an environmental cost to processing such data that must also be taken into consideration. The above highlights the need to integrate environmental considerations into the design of AI systems. J. Do no harm The principle of “do no harm” plays a central role in the sense of protecting the life and health of individuals.131 In this light, AI tools must not be used in ways that cause actual or potential physical or psychological harm or damage.132 Preventing or averting harm includes preventing both potential and unforeseeable, as well as malicious harm.133 K. Prevention and precaution The principle of prevention requires the discontinuation or reinforcement of applications when specific risks are identified, while the precautionary principle requires the discontinuation or reinforcement of appli131Stavroula Tsinorema, “Artificial Intelligence with a Human Face: Towards a Technoethics of Responsibility”, in Liber Amicorum Ismini Kriari (Athens: Sideris, 2025), 259 ff. (275). 132Ibid., 275. 133Ibid. 53 V. Guiding principles that should govern artificial intelligence cationsevenwhen the risk remainsuncertain.134 The anticipationofrisks takes place within the framework of the impact assessment process. The principle of prevention and the precautionary principle sometimes seem to conflict with the principle of effectiveness.135 This is because anyone who makes use of algorithms is aware of their uncertainty and, therefore, has to take responsibility for them.136 L. Concluding remarks The above principles largely stem from the relationship between Greek philosophy and modern technology.137 This is because the idea of creating autonomous machines that make decisions without human involvement raises important questions regarding control, free will, and dependence.138 This autonomy must be based on responsibility, in the sense of moral responsibility.139 Scientific autonomy should be pursued with an understanding of the relevant concepts, as well as awareness of the risk of hubris.140 Therefore, AI must respect ethical boundaries and consider its wider implications for society and humanity.141 It must serve humanity, and contribute to its advancement.142 Aristotle’s teachings are extremely useful in defining the limits of the use of AI.143 134Ibid., 277. 135Chryssoula P. Moukiou, Algorithms and Administrative Law (Athens–Thessaloniki: Sakkoulas, 2025), 268. 136Ibid. 137Konstantinos Karpouzis, “From Plato’s Forms to the Norms of Artificial Intelligence: A Guide to Modern Technology through Ancient Greek Philosophy,” dia-LOGOS 14 (2014): 275 ff. (278). 138Ibid. 139Ibid. 140Ibid., 280. 141Ibid. 142Manolis Andriotakis, Artificial Intelligence for All (Athens: Psychogios, 2022), 212. 143Prokopios Pavlopoulos, “Critical Reflections on the Relevance of Aristotle’s Positions on Law and Justice in the Age of Artificial Intelligence,” Public Law Review 1 (2025): 41 ff. (41). 54 VI. Scope of application Article 2 of the Regulation defines the scope of its application. According to a literal interpretation, this constitutes the personal scope, as it defines the persons to whom the Regulation applies. In addition to the personal scope, said Article also sets out the territorial – in this case international – scope of the Regulation, introducing the principle of extraterritoriality. According to Article 2, the Regulation applies first and foremost to providers placing on the market or putting into service AI systems or placing on the market general-purpose AI models in the Union, irrespective of whether those providers are established or located within the Union or in a third country. In this respect, the criterion of the undertaking’s place of establishment is adopted.144 This criterion ensures fair competition in the same market, irrespective of the location of the branch, which is essential for digital services.145 ‘Placing on the market’, under Article 3(9) of the Regulation, means the first making available of an AI system or a general-purpose AI model on the Union market. Likewise, according to Article 3(10), ‘making available on the market’ means the supply of an AI system or a generalpurpose AI model for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge. The great difficulty of the AI Act lies in the fact that it is not linked to a traditional physical product, but to a purely software-based product, whose local presence is extremely difficult to determine.146 Ultimately, an AI system or a general-purpose AI model is deemed to be placed on the Union market if it is made available to end-users in the Union with 144Christiane Wendehorst, “Art. 2,” in KI-VO, Kommentar, Verordnung über künstliche Intelligenz, ed. Mario Martini and Christiane Wendehorst (Munich: C.H. Beck, 2024), para. 12. 145Ibid. 146Ibid., para. 15. 55 VII. Similarities with the General Data Protection Regulation (GDPR) AI is directly linked to data protection, as algorithms rely on data. AI is not explicitly mentioned in the GDPR, but many of its provisions are relevant to AI, and some are challenged by new methods of processing personal data172 made possible through AI.173 The AI Act seems to be modelled on the GDPR. In fact, it would not be an exaggeration to describe it as an “imitation” of it.174 The similarity is particularly evident in the following key areas: First, the AI Act is extraterritorial in nature. According to Article 2(1)(a) to (c) it applies to (a) providers placing on the market or putting into service AI systems or placing on the market general-purpose AI models in the Union, irrespective of whether those providers are established or located within the Union or in a third country; (b) deployers of AI systems that have their place of establishment or are located within the Union; and (c) providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union. This means that the provider of the AI does not need to be established in the Union, as long 172Athina Moraiti and Charalampos Stamelos, “The Impact of AI on Data Protection: Evolution of Court of Justice of the European Union Case Law Regarding the General Data Protection Regulation (GDPR) in the Artificial Intelligence Era,” in EU Digital Law in the AI Era, ed. Tatiana-Eleni Synodinou, Philippe Jougleux, Christiana Markou, and Thalia Prastitou-Merdi (Cham: Springer, 2025, forthcoming). 173European Parliamentary Research Service (EPRS), Scientific Foresight Unit (STOA). Study Panel for the Future of Science and Technology. PE 641.530, June 2020, II. https:// www.europarl.europa.eu/RegData/etudes/STUD/2020/641530/EPRS_STU(2020) 641530_EN.pdf 174Vagelis Papakonstantinou and Paul De Hert, The Regulation of Digital Technologies in the EU: Act-ification, GDPR Mimesis, and EU Law Brutality at Play (London: Routledge, 2024). 62 General Section as the AI system exists and operates within the Union.175 The GDPR has a corresponding extraterritorial character. According to Article 3 of the GDPR, its scope extends to the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not, where the processing concerns data subjects located in the EU, such as in cases of online commerce or profiling. Second, the AI Act introduces the concept of quasi-self-regulation, meaning that AI applications are not, as a rule, licensed by a supervisory authority. TheGDPR operatessimilarly,asArticle36(5)leavesitto Member States to determine whether prior authorisation by a supervisory authority is required. Third, in the event of a breach of the Regulation’s provisions, the fines are extremely high.176 The same applies to the high fines provided for under the GDPR.177 Fourth,the AI Act leavesMemberStatesdiscretiontomake their own choices. In practice, it is a Regulation with many features similar to those of a Directive. A typical example is the discretion of Member States to impose fines on public authorities (Article 99(1)). Fifth, the AI Act requires each Member State to designate one or more national competent authorities and a single point of contact (Article 70). At EU level, coordination is ensured by the European Artificial Intelligence Board (Articles 65 and 66). A comparable model is established in the GDPR in Articles 51 et seq. on supervisory authorities and Articles 70 et seq. on the European Data Protection Board. 175Vasilis Tzemos, “The New Regulation on Artificial Intelligence and the Charter of Fundamental Rights of the European Union (CFR),” in Exploring Aspects of Artificial Intelligence: Cutting-Edge Technologies as a Legislative Challenge, 2nd Interdisciplinary Conference on Law and Informatics, ed. Eugenia Alexandropoulou-Aigyptiadou, Theoharis Dalakouras, andChristos Mastrokostas(Athens:NomikiVivliothiki,2025), 99 ff. (100). 176Infra, chapter XI, “Penalties”. 177According to Article 83(6) GDPR, “non-compliance with an order by the supervisory authority as referred to in Article 58(2) shall, in accordance with paragraph 2 of this Article, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher”. 63 VII. Similarities with the General Data Protection Regulation (GDPR) Sixth, the AI Act introduces a set of actors that, although unique in their configuration, resemble those of the GDPR.178 The “provider” is the decision-maker, who, either directly or through intermediaries such as the “importer”, “distributor”, or “authorised representative”, influences the passive recipients, the “deployers”. All these actors are involved in the use of an AI system.179 Seventh, certain provisions of the Regulation are clearly influenced by the GDPR. These include the home use exemption (Article 3(4)), certification mechanisms such as declarations of conformity and codes of conduct (Articles 47 and 95), the AI registration system (Articles 51 and 49), the mandatory appointment of representatives in the Union for any non-EU AI operator (Article 22), and the principle of accountability (Articles 23 and 26(5)).180 Eighth, both the GDPR and the AI Act are guided by the need to facilitate scientific research, recognising its importance. In this regard, regulatory sandboxes are of particular importance. The facilitation of research under the GDPR can be seen in the following aspects: (a) The GDPR adopts the principle of compatibility with the original purpose, thereby granting wide discretion to the controller, who has the final say regarding any change of processing purpose. (b) Exceptionally, according to Recital 33 of the GDPR, broad consent may be granted for certain areas of scientific research, to the extent permitted by the purpose pursued. The aim of this provision is to facilitate scientific research in order to relieve researchers of the burden of obtaining multiple consents when changing the purpose of their research.181 178Article 3 of the AI Regulation. 179Vagelis Papakonstantinou and Paul De Hert, The Regulation of Digital Technologies in the EU: Act-ification, GDPR Mimesis, and EU Law Brutality at Play (London: Routledge, 2024), part 5.2.3. 180Ibid. 181Fereniki Panagopoulou-Koutnatzi, “Research in Historical Sources and Protection of Information,” Media and Communication Law Review (2014): 28 ff. (30 ff.). 64 General Section (c) Similarly, Article 89(2) of the GDPR provides an exception to the storage limitation principle, allowing further retention of personal data where required for historical, statistical, or scientific research purposes. (d) Research purposes constitute an independent and sufficient lawful basis even for the processing of special categories of data, namely sensitive data such as racial or ethnic origin, political opinions, health, criminal prosecutions, and convictions. 65 VIII. Key pillars A. General TheAIAct is ahorizontalinstrumentaimingatproductsafety andariskbasedapproach.It aims to protecthealth, safety, and fundamental rights. It is innovation-friendly, complementing the existing acquis. It applies to public and private entities, both within and outside the EU, where an AI system is placed on the Union market or its use affects individuals in the EU. It does not apply to military, defence, or national security activities, to free and open-source software (with exceptions), or to research, development, and prototyping prior to market placement. B. Risk-based categorisation The AI Act classifies artificial intelligence systems into four categories accordingtothe levelofriskthattheypose.Systemspresentingonlylimited risk are subject to light transparency obligations. High-risk AI systems require conformity assessment and must meet a series of requirements and obligations to access the EU market. Systems involving, for instance, cognitive behavioural manipulation of persons or social scoring are prohibited, as their risk is considered unacceptable. It also prohibits predictive, profiling-based policing and systems using biometric data to categorise people by characteristics such as racial origin, religion, or sexual orientation. 1. Unacceptable risk (Article 5) TheAIActprohibitscertainAI applicationsthatthreatencitizens’rights. This is an agreement not to accept dangerous systems. In particular, the prohibition applies to: 66 General Section (a) The use of subliminal techniques, or manipulative or deceptive practices, that materially distort behaviour in a manner likely to cause significant harm. (b) The exploitation of vulnerabilities related to age, disability, or social or economic situation, in a manner likely to cause significant harm. (c) Biometric categorisation systems that infer specific categories of data (race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation), except where used solely for the labelling or filtering of lawfully acquired biometric datasets, or when carried out by law enforcement authorities under strict conditions. (d) Social scoring, meaning the evaluation or classification of individuals or groups based on social behaviour or personal characteristics, causing harmful or adverse treatment of those individuals. (e) The assessment of the risk of an individual committing criminal actssolelybasedonprofilingorpersonality traits,exceptwhereit is used to reinforce human assessments based on objective, verifiable facts directly related to criminal activity. (f) The compilation of facial recognition databases through untargeted extraction of facial images from the internet or from CCTV footage. (g) Drawing inferences about emotions in workplaces or educational institutions, except for medical or safety reasons. (h) ‘Real-time’ remote biometric identification in publicly accessible spaces for law enforcement purposes, except where it relates to: i. The search for missing persons, abducted victims and victims of trafficking in human beings or sexual exploitation. ii. The prevention of a substantial and imminent threat to life or a foreseeable terrorist attack; or 67 VIII. Key pillars iii. The identification of suspects of serious crimes (such as murder, rape, armed robbery, drug and illegal arms trafficking, organised crime, environmental crime, and so on). The above use is permitted only where non-use of the tool would cause significant harm and must take into account the rights and freedoms of the persons concerned. Prior to deployment, the police must carry out a fundamental rights impact assessment and register the system in the EU database, although, in duly justified cases of urgency, deployment may commence without registration, provided that it is registered later without undue delay. Priortoputting itinto service,authorisationmustbeobtainedfrom a judicial or independent administrative authority, although, in duly justified cases of urgency, deployment may commence without authorisation, provided that authorisation is requested within 24 hours. If authorisation is refused, deployment must cease immediately, with all data, results, and output being erased. 2. High risk (Article 6 et seq.) Most of the AI Act concerns high-risk AI systems, which are subject to specific regulation. These systems require an impact assessment study. The Act lays down clear obligations for high-risk AI systems, due to the significant potential harm they may cause to health, safety, fundamental rights, the environment, democracy, and the rule of law. These systems must assess and mitigate risks, keep usage logs, ensure transparency and accuracy, and guarantee human oversight. Citizens will have the right to lodge complaints about such systems and to receive explanations about decisionsbasedonhigh-risksystemsthataffecttheirrights.High-riskregulation derives from the safety of the products concerned. Asmentionedabove,the AIActprohibits,inprinciple,theuseofbiometric personal identification systems by law enforcement authorities. Exceptionally, the use of such systems is permitted in exhaustively listed and narrowly defined circumstances. In such cases, the use of the systemsmust be limitedin time and geographicscope and subjectto specific prior judicial or administrative authorisation. Such uses may include, for example, the targeted search for a missing person or the prevention of 68 General Section a terrorist attack. The ex-post use of such systems is considered a case of high-risk use, which requires judicial authorisation and is linked to a criminal offence. High-risk AI systems must undergo a third-party conformity assessment unless the AI system: •Performs a narrow procedural task. •Improves the outcome of a previously completed human activity. •Detects patterns of decision-making or deviations from previous decision-making patterns and is not intended to replace or influence the previously completed human assessment without appropriate human review; or •Performs preparatory work for an assessment relevant to the purposes of the following use cases: (a) Non-prohibited biometrics (remote biometric identification systems, AI systems intended to be used for biometric categorisation, according to sensitive or protected attributes or characteristics based on the inference of those attributes or characteristics; and AI systems intended to be used for emotion recognition). (b) Critical infrastructure (safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity). (c) Education and vocational training (AI systems to determine access or admission or assignment of natural persons to educational and vocational training institutions at all levels, evaluation of learning outcomes, assessment of the appropriate level of education, monitoring and detecting prohibited behaviour of students during tests). (d) Employment, employee management, and access to selfemployment (AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job 69 VIII. Key pillars applications, and to evaluate candidates, promotion and termination of contracts, allocation of tasks based on personalityandbehaviouraltraitsorattributes,andmonitoring and evaluation of performance). (e) Access to and enjoyment of essential public and private services (AI systems intended to be used by public authorities or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services; credit assessment, except for financial fraud detection; emergency call assessment and triage, including prioritisation of police, fire, medical assistance and emergency triage services; risk assessments and pricing in health and life insurance). (f) Lawenforcement(AIsystemsusedtoassessaperson’s riskof becoming a victim of crime, polygraphs, assessing the reliability of evidence during criminal investigations or prosecutions,assessing a person’s riskof committingorre-offending not only on the basis of profiling or assessing personality traits or past criminal behaviour, profiling during criminal investigations, interrogations or prosecutions). (g) Management of migration, asylum and border controls (polygraphs, irregular migration or health risk assessments, examination of applications for asylum, visas and residence permits, as well as related complaints concerning eligibility, tracing, identification or identification of persons, except for the verification of travel documents). (h) Justice and democratic processes (AI systems used to investigate and interpret facts and apply the law to specific events or used in alternative dispute resolution). AI systems are always considered high-risk if they create profiles of individuals, that is, the automated processing of personal data to evaluate various aspects of an individual’s life, such as work performance, financial situation, health, preferences, interests, trustworthiness, behaviour, location, or movement. 70 General Section Providers who consider that their AI system, which does not fall under the above categories (a to h), is not high-risk, must substantiate this assessment before the system is placed on the market or put into service. 3. Limited risk Such systems are subject to lighter transparency obligations: providers and developers must ensure that end-users are aware that they are interacting with an AI system (chatbots and deepfakes). 4. Minimal risk Not regulated and covering the majority of AI applications currently available in the EU Single Market, such as AI-enabled video games and spam filters. The AI Act imposes most obligations on high-risk AI systems. Other systems with a lower risk potential are subject mainly to transparency requirements, primarily regulated in Article 50.182 For example, Article 50(1) sets out labelling obligations for AI chatbot providers: Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. This obligation shall not apply to AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, unless those systems are available for the public to report a criminal offence. This rule therefore requires the labelling of AI chatbots. Moreover, AI systems used for the detection, prevention, investigation, or prosecution of criminal offences are not, of course, subject to such transparency obligations. Article 50(2) also sets out labelling obligations for AI systems with which audio, image, video or text content can be generated, such as, in182Michael Rohrlich, KI und Recht (Munich: Hanser, 2025), 168. 71 VIII. Key pillars (d) In the context of migration, asylum or border control management,for the purpose of detecting, recognisingor identifying natural persons, with the exception of the verification of travel documents. 8. Administration of justice and democratic processes: (a) AI systems intended to be used by a judicial authority or on their behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution. (b) To be used for influencing the outcome of an election or referendum or the voting behaviour of natural persons in the exercise of their vote in elections or referenda. D. Specific knowledge in the field of artificial intelligence No later than when an AI system is introduced into an undertaking, there must be at least one person with the necessary specific knowledge of AI technology, both technical and legal. Ideally, a multidisciplinary “AI-competent team” should exist. This may only be feasible in larger organisations. Still, even in smaller companies, AI should not be introduced merely “because the competition does it”. Realistic use cases must be considered in advance, and expertise in AI should be developed and consolidated within the undertaking. Article 4 states that providers and deployers of AI systems shall take measures to ensure, to their best extent, asufficient levelofAI literacyoftheir staffand other personsdealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. Accordingly, providers and deployers of AI systems are legally required to ensure that their staff and other persons working on their behalf have an adequate level of AI literacy. This requirement is so important to the EU legislator that the Regulation expressly defines the term “AI literacy”. According to Article 3(56), this term means skills, knowledge and understanding 78 General Section that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and the possible harm it may cause. The AI Act thus establishes a de facto legal obligation for continuous training.188 188Michael Rohrlich, KI und Recht (Munich: Hanser, 2025), 172. 79 IX. Obligations of the Parties Asnoted,theAIActdistinguishesbetweendifferentcategories:providers, deployers, importers, distributors, and authorised representatives, allocating distinct responsibilities along the AI value chain. A. Providers Under Article 16, providers of high-risk AI systems are under obligation to: (a) Establish and maintain a risk management system throughout the life cycle of the high-risk AI system. (b) Establish a data governance and management system ensuring that training, validation, and testing data sets are relevant, sufficiently representative, free of errors and complete, in accordance with the intended purpose. (c) Draw up and keep the technical documentation demonstrating compliance and provide it to the competent authorities upon request. (d) Design the high-risk AI system for record-keeping so that it can automatically log events relevant to the identification of risks and any substantial modifications throughout the life cycle of the system. (e) Provide instructions for use to subsequent developers so as to enable their compliance. (f) Design the high-risk AI system in such a way that developers are able to apply human oversight. (g) Design the high-risk AI system to achieve appropriate levels of accuracy, robustness, and cybersecurity. 80 General Section (h) Establish quality management systems to ensure compliance. In line with the transparency obligations, general-purpose AI systems and their underlying models must respect EU copyright law and publish detailed summaries of the training data. Moreover, any artificial or manipulated images, sound, or video content (deepfakes) must be explicitly labelled as such. Article17 sets out the obligationsof providersofhigh-risk AI systems, requiring them to put a quality management system in place that ensures compliance with this Regulation. That system shall be documented in a systematic and orderly manner in the form of written policies, procedures and instructions, and shall include at least the following aspects: (a) A strategy for regulatory compliance, including compliance with conformity assessment procedures and procedures for the management of modifications to the high-risk AI system. (b) Techniques, procedures and systematic actions to be used for the design, design control and design verification of the high-risk AI system. (c) Techniques, procedures and systematic actions to be used for the development, quality control and quality assurance of the highrisk AI system. (d) Examination, test and validation procedures to be carried out before, during and after the development of the high-risk AI system, and the frequency with which they have to be carried out. (e) Technical specifications, including standards, to be applied and, where the relevant harmonised standards are not applied in full or do not cover all of the relevant requirements set out in Section 2,themeans to be usedto ensure that the high-riskAI systemcomplies with those requirements. (f) Systems and procedures for data management, including data acquisition, data collection, data analysis, data labelling, data storage, data filtration, data mining, data aggregation, data retention and any other operation regarding the data that is performed 81 IX. Obligations of the Parties before and for the purpose of the placing on the market or the putting into service of high-risk AI systems. (g) The risk management system referred to in Article 9. (h) The setting-up, implementation and maintenance of a postmarket monitoring system, in accordance with Article 72. (i) Procedures related to the reporting of a serious incident in accordance with Article 73. (j) The handling of communication with national competent authorities, other relevant authorities, including those providing or supporting the access to data, notified bodies, other operators, customers or other interested parties. (k) Systems and procedures for record-keeping of all relevant documentation and information. (l) Resource management, including security-of-supply related measures. (m) An accountability framework setting out the responsibilities of themanagement andother staffwithregard toall theaspectslisted in this paragraph. Article 17(2) introduces the criterion of proportionality, as the application of the aspects set out in paragraph 1 must be proportionate to the size of the provider’s organisation. In all cases, providers must respect the degree of rigour and the level of protection necessary to ensure that their high-risk AI systems comply with the Regulation. The obligation to keep documentation is set out in Article 18. In this respect, the provider must keep at the disposal of the national competent authorities,foraperiodoftenyearsafterthehigh-riskAI systemhas been placed on the market or put into service: (a) The technical documentation referred to in Article 11. (b) The documentation concerning the quality management system referred to in Article 17. 82 General Section (c) The documentation concerning the changes approved by the notified bodies, where applicable. (d) The decisions and other documents issued by the notified bodies, where applicable. (e) The documentation concerning the changes approved by the notified bodies, where applicable. (f) The EU declaration of conformity referred to in Article 47. Article 19 provides for the automatic generation of logs, while Article 20 imposes corrective measures and a duty of information on providers of high-risk AI systems who consider or have reason to believe that a high-risk AI system they have placed on the market or put into service does not comply with the Regulation. The measures consist of bringing the system into conformity, withdrawing it, disabling it, or recalling it, as appropriate. They must inform the distributors of the high-risk AI system concerned and, where appropriate, the deployers, the authorised representative, and the importers accordingly. At the same time, Article 21 imposes an obligation on providers of high-risk AI systems to cooperate with the competent authorities, upon a reasoned request from a competent authority. B. Authorised representatives Article 22 imposes on providers established in third countries the obligation to appoint an authorised representative before making their high-risk AI systems available on the Union market. In this respect, the provider must enable the authorised representative to perform the tasks specified in the mandate received from the provider. The authorised representative shall provide the market surveillance authorities, upon request, with a copy of the mandate in one of the official languages of the Union institutions, as indicated by the competent authority. The mandate empowers the authorised representative to perform the following tasks: (a) Verify that the EU declaration of conformity referred to in Article 47 and the technical documentation referred to in Article 11 83 IX. Obligations of the Parties have been drawn up and that an appropriate conformity assessment procedure has been carried out by the provider. (b) Keep at the disposal of the competent authorities and national authorities or bodies referred to in Article 74(10), for a period of ten years after the high-risk AI system has been placed on the market or put into service, the contact details of the provider that appointed the authorised representative, a copy of the EU declaration of conformity referred to in Article 47, the technical documentation and, if applicable, the certificate issued by the notified body. (c) Provide a competent authority, upon a reasoned request, with all the information and documentation, including that referred to in point (b) of this subparagraph, necessary to demonstrate the conformity of a high-risk AI system with the requirements set out in Section 2, including access to the logs, as referred to in Article 12(1), automatically generated by the high-risk AI system, to the extent such logs are under the control of the provider. (d) Cooperate with competent authorities, upon a reasoned request, in any action the latter take in relation to the high-risk AI system, inparticulartoreduceand mitigatetherisks posedbythe high-risk AI system. (e) Where applicable, comply with the registration obligations referred to in Article 49(1) or, if the registration is carried out by the provider itself, ensure that the information referred to in point 3 of Section A of Annex VIII is correct. C. Importers Article 23 lays down the corresponding obligations of importers. Before placing a high-risk AI system on the market, importers shall ensure that the system is in conformity with this Regulation by verifying that: (a) The relevant conformity assessment procedure referred to in Article 43 has been carried out by the provider of the high-risk AI system. 84 General Section (b) The provider has drawn up the technical documentation in accordance with Article 11 and Annex IV. (c) The system bears the required CE marking and is accompanied by the EU declaration of conformity referred to in Article 47 and instructions for use. (d) The provider has appointed an authorised representative in accordance with Article 22(1). Where an importer has sufficient reason to believe that a high-risk AI system is not in conformity with the Regulation, has been falsified, or is accompanied by falsified documentation, it shall not place the system on the market until it has been brought into conformity. Where the highrisk AI system presents a risk within the meaning of Article 79(1), the importer shall inform the provider of the system, the authorised representative, and the market surveillance authorities accordingly. D. Distributors Article 24 sets out the obligations of distributors. More specifically, before making a high-risk AI system available on the market, distributors shall verify that it bears the required CE marking, and that it is accompanied by a copy of the EU declaration of conformity referred to in Article 47.Where a distributor considers or has reason to consider, on the basis of the information in its possession, that a high-risk AI system is not in conformity with the requirements set out in Section 2, it shall not make the high-risk AI system available on the market until the system has been brought into conformity with those requirements. Furthermore, where the high-risk AI system presents a risk within the meaning of Article 79(1), the distributor shall inform the provider or the importer of the system, as applicable, to that effect. E. Deployers Finally, Article 26 defines the obligations of the implementers of highrisk AI systems mainly as follows: 85 IX. Obligations of the Parties Deployers of high-risk AI systems shall take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use accompanying the systems, pursuant to paragraphs 3 and 6. They shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support. The obligations set out above are without prejudice to other deployer obligations under Union or national law and to the deployer’s freedom to organise its own resources and activities for the purpose of implementing the human oversight measures indicated by the provider. Also without prejudice to the above, to the extent the deployer exercises control over the input data, that deployer shall ensure that input data is relevant and sufficiently representative in view of the intended purpose of the high-risk AI system. Deployers shall also monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers in accordance with Article 72. Where they have reason to consider that the use of the high-risk AI system in accordance with the instructionsmayresult in that AI system presenting a risk within the meaning of Article 79(1), they shall, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and shall suspend the use of that system. Where they have identified a serious incident, they shall also immediately inform first the provider, and then the importer or distributor and the relevant market surveillance authorities of that incident. If the deployer is not able to reach the provider, Article 73 shall apply mutatis mutandis. This obligation shall not cover sensitive operational data of deployers of AI systems which are law enforcement authorities. For deployers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law, the monitoring obligation set out in the first subparagraph shall be deemed to be fulfilled by complying with the rules on internal governance arrangements, processes and mechanisms pursuant to the relevant financial service law. Deployers of high-risk AI systems shall keep the logs automatically generated by that high-risk AI system to the extent such logs are under their control, for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in 86 General Section applicable Union or national law, in particular in Union law on the protection of personal data. Deployers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law shall maintain the logs as part of the documentation kept pursuant to the relevant Union financial service law. Before putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers’ representatives and the affected workers that they will be subject to the use of the highrisk AI system. Deployers of high-risk AI systems that are public authorities, or Union institutions, bodies, offices or agencies shall comply with the registration obligations referred to in Article 49. Without prejudice to Directive (EU) 2016/680, in the framework of aninvestigationforthetargetedsearchofapersonsuspectedorconvicted of having committed a criminal offence, the deployer of a high-risk AI systemforpost-eventremotebiometricidentificationshall requestanauthorisation, ex-ante, or without undue delay and no later than 48 hours, by a judicial authority or an administrative authority whose decision is binding and subject to judicial review, for the use of that system, except whenitisusedfortheinitialidentificationofapotentialsuspectbasedon objective and verifiable facts directly linked to the offence. Each use shall be limited to what is strictly necessary for the investigation of a specific criminal offence If the authorisation requested pursuant to the first subparagraph is rejected, the use of thepost-eventremotebiometricidentificationsystem linked to that requested authorisation shall be stopped with immediate effect and the personal data linked to the use of the high-risk AI system for which the authorisation was requested shall be deleted. In no case shall such high-risk AI system for post-event remote biometric identification be used for law enforcement purposes in an untargeted way, without any link to a criminal offence, a criminal proceeding, a genuine and present or genuine and foreseeable threat of a criminal offence, or the search for a specific missing person. It shall be ensured that no decision that produces an adverse legal effect on a person may be taken by the law enforcement authorities based solely on the output of such post-event remote biometric identification systems. Deployers shall 87 X. Control and supervision Eleventh, the European Data Protection Board, together with the European Data Protection Supervisor (EDPS), adopted an opinion welcoming the selection of the EDPS as competent authority for EU institutions and bodies, and recommending that national data protection authorities should likewise be designated as competent authorities for AI in the Member States. Twelfth, issues of unconstitutionality are avoided, since establishing a new authority would remove powers from the constitutionally enshrined HDPA. At the same time, the choice of the HDPA is also associated with certain disadvantages: First, AI constitutes the fourth industrial revolution and cannot fall under the umbrella of an already existing authority that was established for another purpose, namely the protection of personal data alone. Second, the HDPA may be biased in favour of data protection and against the development of research and innovation. From this perspective, it could act as an obstacle to AI. Third, the members of the HDPA specialise in data protection and not in AI. Fourth, the HDPA in its current composition is understaffed and will not be able to meet its newly expanded responsibilities. 2. Establishment of a National Authority for Privacy, Information and Artificial Intelligence (NAPIA) The second option is the transformation of the HDPA and the Hellenic Authority for Communication Security and Privacy (after their merger) into a National Authority for Privacy, Information and Artificial Intelligence (NAPIA), or the creation of a new authority with three departments: Privacy, Information, and AI. A sub-authority for AI could be integrated into the existing structure of the HDPA and the Hellenic Authority for Communication Security and Privacy. This sub-authority would consist of full-time permanent members specialised in personal data and some new members from the fields of innovation and research. 94 General Section This model already exists in Member States, such as France193 and the Netherlands.194 This sub-base could be granted further flexibility to foster synergies with academia, research centres, and AI businesses, as well as to support start-ups. After more than five years of experience in implementing the GDPR (at EU level as well), data protection authorities are mature enough to identify and directly address problems that a new authority would otherwise face, providing the fastest, most effective and most cost-efficient solution for the national legislator. In this way there will be no confusion of competences, since everything related to AI will fall under the NAPIA. The AI department will be responsible for strengthening research and innovation, protecting competition and intellectual property, overseeing technology, certifying AI applications,andadvisingthe legislator.Moreover,the creationofa dedicated AI departmentwill ensure that there is no bias in favourofpersonal data.At thesame time,safeguardingaccessto informationisof particular importance. The modern trend in European legislation, which is in line with the equal treatment of individual rights, is the establishment of a single administrative authority responsible for both the protection of personal data and freedom of information. Therefore, priority should not be given solely to the protection of personal data when other conflicting constitutionally protected legal rights, such as the freedom of information, are also at stake. This position is fully aligned with the GDPR, which emphatically states in Recital 4 that “the right to the protection of personal data is not an absolute right; it must be considered in relation to its function in society and be balanced against other fundamental rights, in accordance with the principle of proportionality. This Regulation respects all fundamental rights and observes the freedoms and principles recognised in the Charter as enshrined in the Treaties, in particular the respect for private and family life, home and communications, the pro193Source: CNIL, “CNIL Creates Artificial Intelligence Department and Begins Work on Learning Databases,” https://www.cnil.fr/en/cnil-creates-artificial-intelligence-dep artment-and-begins-work-learning-databases 194Source: Digital Policy Alert, “Order on Data Protection Authority’s Supervisory Role over AI Algorithms,” https://digitalpolicyalert.org/change/4226-order-on-data-pro tection-authoritys-supervisory-role-over-ai-algorithms 95 X. Control and supervision tection of personal data, freedom of thought, conscience and religion, freedom of expression and information, freedom to conduct a business, the right to an effective remedy and to a fair trial, and cultural, religious and linguistic diversity.” At the same time, the GDPR enshrines in Article 85 thereof the freedom of expression and information, providing for a balance between the right to the protection of personal data and the right to freedom of expression and information, including processing for journalistic purposes. This need for balance is not merely theoretical. Without it, there is a reasonable risk that greater emphasis will be placed on the protection of personal data under the aegis of an independent and constitutionally enshrined authority, while access to information would remain, in practice, “orphaned”. The result is that the controller will reasonably prefer not to provide the data, since there would be no sanction, rather than to disclose it. All members of the Authority shall be appointed in accordance with the requirements of Article 101A of the Greek Constitution. It is deemed necessary to provide for transitional provisions to ensure the completion of the terms of office of members of the existing authorities that may be affected by such changes. 3. Establishment of a National Artificial Intelligence Authority (NAA) The third option is the creation of a specialised authority for AI. This would mean creating a new authority composed of members of the HDPA, the National Commission on Bioethics and Technoethics, and representatives of innovation, research, the market, and other stakeholders. It is a fact that the importance of AI and its strong impact on all areas of contemporary legal life argue in favour of establishing a specialised authority. AI constitutes the fourth industrial revolution, and its particularity does not allow it to be placed under an already existing authority. The protection of the individual is largely linked to the protection of their personal data from the development of AI, but it is also connected with other goods such as research, innovation, competition, system security, and intellectual property, for which the HDPA may not have the appro96 General Section priate expertise. For this reason, the establishment of a specialised supervisory authority for AI should be considered. This authority would be composed of experts from across the full spectrum of fields related to AI. The advantage of this specialised authority lies in the fact that it would focus its attention on all areas that pertain to AI. This option is nevertheless linked to several disadvantages. In particular, the division of responsibilities between the supervisory authority and the HDPA may cause confusion of competences. The question arises as to which cases would fall within the competence of the HDPA and which within that of the specialised supervisory authority. This confusion is further compounded by the uncertainty as to what constitutes AI and therefore falls within the competence of the new authority, and what does not constitute AI and therefore remains under the HDPA. If both authorities were to handle the same case, there would be a risk of multiple sanctions for the same infringement and, consequently, a violation of the principle of ne bis in idem. This model ensures the representation of all stakeholders and addresses the legal obstacle of the ne bis in idem principle, since all independent authorities would be represented. Experience in Greece has shown that this model may lack functionality. It should also be emphasised that if competences for data protection are removed from the HDPA, the new authority will have to meet the constitutional requirements of the HDPA. 97 XI. Penalties Member States are given the discretion to lay down their own rules on penalties, including administrative fines, applicable to infringements of the Regulation and shall take all measures necessary to ensure their correct and effective implementation. The penalties provided for, however, must be effective, proportionate, and dissuasive, and consider the interests and economic viability of SMEs, including start-ups. Fines for infringements of the AI Act shall be set as a percentage of the worldwide annual turnover of the infringing undertaking in the preceding financial year, or as a fixed amount, whichever is higher. SMEs and start-ups are subject to proportionate administrative fines. According to Article 99(2), Member States shall notify the Commissionof theruleson penaltiesand other enforcementmeasuresbythedate of entry into application, and shall notify it without delay of any subsequent amendments. Article 99(3) stipulates that non-compliance with the prohibition of the AI practices referred to in Article 5 shall be subject to administrative fines of up to 35 000 000 EUR or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher. Accordingly, Article 99(4) sets out that noncompliance with any of the following provisions related to operators or notified bodies, other than those laid down in Articles 5, shall be subject to administrative fines of up to 15 000 000 EUR or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher: (a) Obligations of providers pursuant to Article 16. (b) Obligations of authorised representatives pursuant to Article 22. (c) Obligations of importers pursuant to Article 23. (d) Obligations of distributors pursuant to Article 24. 98 General Section (e) Obligations of deployers pursuant to Article 26. (f) Requirements and obligations of notified bodies pursuant to Article 31, Article 33(1), (3) and (4) or Article 34. (g) Transparency obligations for providers and deployers pursuant to Article 50. Article 99(5) stresses the importance of providing accurate information to supervisory authorities. Hence it provides that the supply of incorrect,incompleteormisleadinginformationtonotifiedbodies ornational competent authorities in reply to a request shall be subject to administrative fines of up to 7 500 000 EUR or, if the offender is an undertaking, up to 1 % of its total worldwide annual turnover for the preceding financial year, whichever is higher. Article 99(7) enshrines the principle of proportionality in setting administrative fines. Accordingly, before imposing a fine and in determining its amount, all relevant circumstances of the specific case shall be taken into account and, as appropriate, regard shall be had to the following: (a) The nature, gravity and duration of the infringement and of its consequences, taking into account the purpose of the AI system, as well as, where appropriate, the number of affected persons and the level of damage suffered by them. (b) Whether administrative fines have already been applied by other market surveillance authorities to the same operator for the same infringement. (c) The size, the annual turnover and market share of the operator committing the infringement. Finally, Article 99(8) allows Member States to decide to what extent administrative fines may be imposed on public authorities or bodies established within their jurisdiction. Article 99(9) further provides that, dependingon national legal systems,fines maybe imposedbycompetent courts or other designated bodies, provided that the resulting framework ensures an equivalent effect across Member States. 99 XII. Liability The AI Act is underpinned by the principle of product safety. This principle reflects the aim of broadening the protection of rights, democracy and the rule of law, accounting for systemic risks from specific applicationsandprovidinglegal remedies.195 Theseremediesincludethe right to lodge a complaint with a market surveillance authority (Article 85) and the right to explanation of individual decision-making (Article 86). The Act does not establish an individual right to compensation from harm caused by AI applications. Liability serves as a deterrent against endangeringrights and incentivisesprovidersto design safe systems.196 Thebalancing function of liability is a fundamental element of justice and complements the protection of fundamental rights. A clear liability regime enhances trust in AI.197 When consumers know that concrete mechanisms exist to allocate liability to providers or operators, they are more likely to use the technology and benefit from it.198 The fact is that AI can affect interests and rights protected under EU or national law For example, the use of AI may negatively affect certain fundamental rights such as life, physical integrity, the prohibition of discrimination, and equal treatment. The AI Act sets out requirements designed to mitigate risks to safety and fundamental rights. As mentioned above, however, while these requirements are intended to reduce risks to safety and fundamental rights and to prevent, monitor and address social concerns, they do not provide individual compensation to those who have been harmed by AI. Moreover, the Act does not expressly establish a liability regime. Therefore, 195Christiane Wendehorst, “Art. 1,” in KI-VO, Kommentar, Verordnung über künstliche Intelligenz, ed. Mario Martini and Christiane Wendehorst (Munich: C.H. Beck, 2024), para. 61. 196Ibid., para. 62. 197Ibid. 198Ibid. 100 General Section in the absence of an explicit provision, the question of liability for machines arises. Who is liable if a self-driving car crashes, a management algorithm reaches a decision harmful to the individual concerned, or a medical application recommends, after processing all the data, a treatment that worsens the patient’s health? The answer to this question is complex. The possible solutions are systematised as follows: The first position is that responsibility should be borne and managed by the manufacturer of AI products; this approach is also followed by the existing EU Regulations on medical devices.199 In this way, both the accountability and foresight of the manufacturer will be strengthened. No oneshoulddevelopAI systemswithoutasenseofresponsibilityforthem, even if they are autonomous machine learning systems, since responsibility can now be embedded as information.200 The strict liability of the creator should play a central role in compensating for damage caused by defective products and their components, whether they are tangible or digital.201 The second position argues that liability should be attributed to the operator of the technology, meaning the driver of the car, the administrator or the medical practitioner who applies the technology. This is because the operator of the relevant programme must not only embrace the proposal but must check whether it is fully adapted to the facts of the case and take into account the possibility of algorithmic bias. When absolute reliance on Tesla’s car auto-navigation system resulted in a fatal accident in June 2016, Tesla quickly sought to shift responsibility by claiming that the driver’s actions, not the programmer’s, were to blame for the fatal collision.202 In this vein, Tesla requires buyers to contractu199Articles 10 and 62 of Regulation (EU) 2017/745 on medical devices and Regulation (EU) 2017/746 on in vitro diagnostic medical devices. 200Alan F. T. Winfield and Marina Jirotka. “Ethical Governance Is Essential to Building Trust in Robotics and Artificial Intelligence Systems.” Philosophical Transactions of the Royal Society A: Mathematical, Physical and Engineering Sciences 376, no. 2133 (2018). 201European Commission, Liability for Artificial Intelligence and Other Emerging Digital Technologies (Brussels: European Union, 2019), 8, https://op.europa.eu/en/publicat ion-detail/-/publication/1c5e30be-1197-11ea-8c1f-01aa75ed71a1/language-en 202The Tesla Team, “A Tragic Loss,” Tesla Blog, June 30, 2016, https://www.tesla.com/ blog/tragic-loss; archived at https://perma.cc/94SX-RJCJ 101 XII. Liability ally commit that drivers must keep their hands on the wheel at all times, even when autopilot is engaged.203 The third position consists of sharing liability between the manufacturer or programmer and the operator. Each will be responsible for the share of liability that corresponds to them. This system, while appealing and tending to be the most popular, is not without controversy. The attribution of liability may, in many cases, become a difficult and hardto-prove issue. If there are two or more actors, particularly (a) the person who primarily decides on and benefits from the use of the relevant technology (frontend operator); and (b) the person who continuously determines the characteristics of the relevant technology and provides substantial and ongoing support to the backend (backend operator), objectiveliabilityshouldrest withthe oneexercisinggreatercontrolover the operational risks.204 The fourth position argues in favour of attributing liability to the technology itself.205 Nevertheless, if the technology is to be held liable, it must first be recognised as a subject of law. This solution was rejected in October 2020 by the European Parliament, which adopted three resolutions on the ethical and legal aspects of AI software systems: (a) Resolution 2020/2012(INL) on a framework for ethical aspects of AI, Robotics and related technologies; (b) Resolution 2020/2014(INL) on a civil liability regime for AI; and (c) Resolution 2020/2015(INI) on intellectual property rights for the development of AI technologies. All three resolutions recognise that AI will bring significant benefits in various sectors, including business, the labour market, public transport, and healthcare. However, as noted in the resolution on the ethical aspects of AI, there are concerns that the current legal framework of the Union, including consumer law, the labour and social acquis, data protection legislation, product safety and market surveillance legislation, 203Derdiarian v. Felix Contracting Corp., 414 N.E.2d 666, 671 (N.Y. 1980). 204European Commission, Liability for Artificial Intelligence and Other Emerging Digital Technologies (Brussels: European Union, 2019), 8, https://op.europa.eu/en/publicat ion-detail/-/publication/1c5e30be-1197-11ea-8c1f-01aa75ed71a1/language-en 205Vagelis Papakonstantinou and Paul De Hert, “Refusing to Award Legal Personality to AI: Why the European Parliament Got It Wrong,” European Law Blog, November 20, 2020. 102 General Section and anti-discrimination legislation, may no longer be adequate to effectively address the risks posed by AI, robotics and related technologies. All three resolutions firmly reject the idea of granting legal personality to AI software systems. Therefore, this solution, although tempting, does not seem relevant for the immediate future, though it cannot be ruled out at a later stage, once the concept of digital personality has matured. Support for attributing digital personality to machines does not come as a bolt from the blue. It is a solution that would not be entirely alien to our legal system, as it could be paralleled with limited rights (for instance, those of the unborn or the deceased) and obligations (such as those of an animal owner). Indications already suggest that the dichotomy between natural and legal persons may soon evolve into a trichotomy through the recognition of a digital personality.206 Some striking developments have already occurred, which should not be overlooked. For example, in 2017 Saudi Arabia granted citizenship to Sophia, an AI robot.207 In addition, a web-based system in the form of a seven-year-old boy was granted a residence permit in Tokyo.208 In 2014, it was announced that a Hong Kong venture capital firm had appointed a computer programme called Vital to its board of directors to manage its assets.209 In this context, the creation of limited liability companies without any human members has been advocated. Bill Gates has also proposed the taxation of robots in employment.210 Recently, a robot addressed the British Parliament for the first time on the topics of art and AI. Ai-Da appeared with the face and attire of a woman, informing British MPs that, although an artificial creation, it is capable of produc206Vagelis Papakonstantinou and Paul De Hert, “Structuring Modern Life Running on Software: Recognizing (Some) Computer Programs as New ‘Digital Persons,’” Computer Law & Security Review 34, no. 4 (2018): 732–738. 207Dave Gershgorn, “Inside the Mechanical Brain of the World’s First Robot Citizen,” Quartz, November 12, 2017. 208Anthony Cuthbertson, “Artificial Intelligence ‘Boy’ Shibuya Mirai Becomes World’s First AI Bot to Be Granted Residency,” Newsweek, November 6, 2017. 209Rob Wile, “A Venture Capital Firm Just Named an Algorithm to Its Board of Directors,” Business Insider, May 13, 2014. 210Kevin J. Delaney, “The Robot That Takes Your Job Should Pay Taxes, Says Bill Gates,” Quartz, February 17, 2017. 103 XIII. Entry into force of general-purpose AI models placed on the market before 2 August 2025 must comply with their applicable obligations by 2 August 2027. Thisstudywasfinalisedon15November2025.On19November2025, the European Commission published the “Digital Omnibus” proposal, which suggests adjustments and clarifications concerning the wider digital regulatory framework, including provisions that interact with the AI Act.220 At the time of writing, the proposal remains under negotiation and does not affect the applicability dates or obligations set out in Regulation (EU) 2024/1689. 220European Commission, Digital Omnibus – AI Regulation Proposal, 19 November 2025, https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-ai-regulation-pro posal 110 XIV. Concerns A. List-based categorisation The AI Act aims at a regulation that promotes the market while respecting fundamental rights and safety. It categorises systems based on risk, calibrating the level of regulation according to the degree of risk posed by different AI systems. The aim is to avoid both under-regulation (which fails to protect rights and other values) and over-regulation (which restricts innovation and the effective functioning of the single market). This list-based rather than principle-based approach to determining whether a system is classified as high risk is not without problems. It is extremely difficult to identify in advance the applications of systems that may lead to serious rights violations. As a result, systems currently classified as low risk may not be subject to regulation sufficient to prevent rights violations. This flaw is compounded by concerns that the provisions of the AI Act may displace (a) the more stringent rights protection provided by other EU legislation, and (b) the more stringent rights protection established at the national level by Member States. A further concern is who will perform the risk categorisation and what procedures the impact assessment will be conducted, so that it does not become a mere meaningless process. B. Insufficient protection of rights There is serious concern that the AI Act provides insufficient protection of fundamental rights in the case of AI systems classified as not high risk. The criterion for classifying an AI system as “high risk”, apart from AI systems that serve as safety components of regulated products, takes the form of a reviewable list of specific purposes for which the AI systems are used (Annex III). It is the development within these designated areas that makes an AI system “high risk”. The relevant purposes are set out in Annex III and include biometric identification and categorisation 111 XIV. Concerns of individuals, access to and assessment of educational and vocational training institutions, recruitment and management of employees, law enforcement and administration of justice, access to and enjoyment of basic private and public services and benefits, as well as migration, asylum, and border control. It is, however, doubtful whether high-risk AI systems requiring enhanced regulation can be reliably identified in advance through predefined operational domains. Aclassicexampleisoneofthe“high-risk”domainslistedinAnnexIII, namely AI systems that affect “access to and enjoyment of essential private services and essential public services and benefits” (Annex III, point 5). How does this relate to AI systems used in the provision of healthcare services? Point 5(d) refers to “AI systems intended to evaluate and classify emergency calls by natural persons or to be used to dispatch, or to establish priority in the dispatching of, emergency first response services, including by police, firefighters and medical aid, as well as of emergency healthcare patient triage systems”. This description excludes non-emergency healthcare services. But if a general practitioner were to use an AI system to prioritise patients’ appointment requests, the algorithm could systematically discriminate against patients who are women or members of racial and ethnic minorities, and still not fall within the existing “high-risk” category. This appears to underestimate the seriousness of such discrimination compared with other forms of harm falling within one of the listed areas. This concern extends beyond health services, since the potential for AI systems to cause serious harm, such as breaches of non-discrimination rights, runs through all areas of operation. An example is algorithms that introduce racial discrimination in the allocation of cultural or recreational opportunities, which likewise do not fall within the existing list of designated sectors. If, for example, an algorithm regulating access to theatres or leisure centres were systematically to discriminate against children from ethnic minorities, serious harm would result. The listbased methodology, however, appears to take the perceived importance of a designated sector as the guide to the severity of the risk posed by deploying AI systems within it. As a result, it underestimates the pervasive character of the serious risks inherent in AI systems. 112 General Section C. “Quasi-Directive” Regulation model The model of the Regulation, which has many features of a Directive (a quasi-Directive approach) modelled on the GDPR, seems to leave Member States with significant discretionary choices, which may result in its non-uniform application. A typical example is the choice of supervisory authority, whichmayeitherbe newlyestablishedorplacedundertheauspices of an existing body, such as the HDPA. The model preferred by the national legislator will likely indicate the intention either to grant autonomy to the new supervisory body or to place it under an existing one, which may reinforce its original orientation. D. Multiple supervisory authorities The role of the different actors involved in the AI Act may lead to a blurring of competences. It includes the European Artificial Intelligence Board as a regulatory body with representation of the Commission, Member States, the European Data Protection Supervisor, and subgroups on specific issues. This Board has been criticised for excluding stakeholder groups, lacking a defined organisational structure, and being unable to clearly define its tasks. A further complication arises from the delegation to the Commission of risk assessment responsibilities for updating the list of AI systems. This complexity is compounded by the supervisory authorities established under the sister instruments – the Digital Services Act, the Digital Markets Act, and others. E. Lack of guidance Uncertainty persists regarding the ability of citizens to challenge the outcomes of AI systems. The obligation to provide justification for decisionmaking raises questions about the content, nature, and depth of explanations of AI-based decisions. The scope of explanations is unclear at the level of communication, language, and presentation when individuals are subjected to emotion recognition or biometric categorisation systems. In healthcare, it is unclear when patients must be informed of the use of AI in medical decision-making. Quantitative risk assessment systems also face challenges, as no standardised method exists for evaluating 113 XIV. Concerns their performance. Assessing high-risk systems without clear guidance is therefore difficult. F. Extended scope The scope of the AI Act tends to be extremely broad. Its definition of AI may cover many systems related to everyday data processing, producing an overly inclusive scope where the only common denominator may be data processing. As a result, it becomes difficult to identify programmes that are not captured by the description of AI systems. The Act’s scope has also been criticised for its limitations: its strong emphasis on software to the detriment of hardware, its neglect of relevant use cases and user organisations, and its disregard for the use of AI systems in certain sectors. G. Competition with non-European systems Over-regulation of AI may stifle innovation. The European Union is called upon both to resist and to compete with non-European AI products, primarily from the United States and China, which threaten to fracture the unity of AI philosophy and technology. The European Union is lagging behind in initiatives in this area and any overshadowing of the market by others would undermine the entire effort of human-centred regulation. The key question is how the EU can compete on equal terms with non-European markets without betraying its constitutional identity. H. Extraterritoriality The AI Act, like the GDPR, appears to challenge constitutional assumptions that war and military intervention have not managed to shift.221 Its ambition seems excessive, particularly given that the extraterritoriality model of the GDPR has not, in practice, been vindicated. Fines imposed 221Fereniki Panagopoulou-Koutnatzi, “Constitutional Implications of Mechanisms Extending the Protection of Personal Data beyond the EU: Extraterritorial Application of the GDPR and Cross-Border Data Transfers,” Public Law Review 4 (2019): 504 ff. (509). 114 General Section bynationalauthoritiesonnon-European operators are often merely cautionary,222 remaining effectivelyunpaid,223 therebyunderminingtheambitious plans for extraterritorial application. 222Souzana Papakonstantinou, “HDPA Decision 35/2022. Imposition of a €20,000,000 Fine on Clearview AI, Inc. for Violation of the Principles of Lawfulness and Transparency,” e-Politeia: Journal of Legal Theory and Practice 6 (2023): 268 ff. (279). 223A characteristic example is the €20,000,000 fine imposed by the HDPA pursuant to its Decision No. 35/2022. 115 SPECIAL SECTION: Constitutional issues for examination 117 The AI Act seeks to address, on the basis of the principle of proportionality, issues requiring particular attention. Some of these are discussed in the following chapters. 118 I. Biometric identification A. Introduction The AI Act provides flexibility clauses for Member States regarding enforcement measures. A typical example is biometric identification. This iseitherpermittedasameasuretosafeguardnational securityor,if itdoes not fall within the narrow interpretation of national security, it may fall within the cases set out in Article 5(1)(h). In short, the discretion of the legislatorisbroad, and it is forthelegislatortodecidewhat kind of framework is preferred. Such flexibility, however, may undermine the uniform application of the AI Act. A key consideration is whether the legislator opts for a structured framework that facilitates the work of the police authorities or for a looser framework that does not, leaving the police reliant on half-measures, such as reliance on illegal private cameras, which do not protect citizens’ rights. B. Terminology According to Article 3(35), ‘biometric identification’ means the automated recognition of physical, physiological, behavioural, or psychological human features for the purpose of establishing the identity of a natural person by comparing biometric data of that individual to biometric data of individuals stored in a database. Law enforcement authorities use identification systems when comparing a captured image with an existing database, such as a database of photographs of wanted persons or holders of driving licences. The system scans the new image (possibly from CCTV footage in a public space or from a camera at the scene), creates a template, and then attempts to match it with a previously reg119 I. Biometric identification authority, or by an independent administrative authority. Although the AI Act provides exceptions, authorisation should ideally be obtained before the system is used, or within 24 hours. Exceptions for the use of real-time biometric monitoring for law enforcement purposes are possible only where expressly provided for in national law. Therefore, Member States have flexibility to decide whether such exceptions apply domestically, to impose stricter conditions, or even to enact a blanket ban. The competent market surveillance authority and the national data-protection authority must be informed of each use of a “real-time biometric identification system”. These systems enable targeted and effective interventions, while helping avoid disproportionate stop-andsearch measures based on race, nationality, or other distinguishing physical characteristics. F. The concept of publicly accessible space According to Article 3(44) of the Regulation, ‘publicly accessible space’ means any publicly or privately owned physical place accessible to an undetermined number of natural persons, regardless of whether certain conditions for access may apply, and regardless of the potential capacity restrictions. Under Recital 19, the notion of ‘publicly accessible space’ should be understood as referring to any physical space that is accessible to an undetermined number of natural persons, and irrespective of whether the space in question is privately or publicly owned, irrespective of the activity for which the space may be used, such as for commerce, for example, shops, restaurants, cafés; for services, for example, banks, professional activities, hospitality; for sport, for example, swimming pools, gyms, stadiums;fortransport,forexample,bus,metro andrailwaystations,airports, means of transport; for entertainment, for example, cinemas, theatres, museums, concert and conference halls; or for leisure or otherwise, for example, public roads and squares, parks, forests, playgrounds. A space should also be classified as being publicly accessible if, regardless of potential capacity or security restrictions, access is subject to certain predetermined conditions which can be fulfilled by an undetermined number of persons, such as the purchase of a ticket or title of transport, prior registration or having a certain age. In contrast, a space should not be con126 Special Section sidered to be publicly accessible if access is limited to specific and defined natural persons through either Union or national law directly related to public safety or security or through the clear manifestation of will by the person having the relevant authority over the space. The factual possibility of access alone, such as an unlocked door or an open gate in a fence, doesnot implythat the spaceis publiclyaccessible in thepresence of indications or circumstances suggesting the contrary, such as signs prohibiting or restricting access. Company and factory premises, as well as offices and workplaces that are intended to be accessed only by relevant employees and service providers, are spaces that are not publicly accessible. Publiclyaccessiblespacesshould not include prisons or border control.Some other spaces may comprise both publicly accessible and non-publicly accessible spaces, such as the hallway of a private residential building necessary to access a doctor’s office or an airport. Online spaces are not covered, as they are not physical spaces. Whether a given space is accessible to the public should however be determined on a case-by-case basis, having regard to the specificities of the individual situation at hand. It should be noted that the term refers to a physical space, and not a virtual one. In summary, publicly accessible spaces include business premises (restaurants, cafés, banks, hotels), sports facilities (swimming pools, gyms, stadiums), public transport and associated facilities (buses, metro and railway stations, airports), entertainment venues (cinemas, theatres, museums, concert halls), recreational areas (playgrounds, parks), and public spaces in general (public roads, squares).235 The term “public accessibility” means that any person can visit the space, such as a public market.236 G. The exception of national security Protection from biometric monitoring on grounds of national security appears to promote the interests of the State, but abuse of this exception may give rise to particular concern. The national security requirement is 235Christiane Wendehorst, “Art. 3,” in KI-VO, Kommentar, Verordnung über künstliche Intelligenz, ed. Mario Martini and Christiane Wendehorst (Munich: C.H. Beck, 2024), para. 304. 236Ibid., para. 306. 127 I. Biometric identification overly general and vague, and open to abuse.237 It is a vague concept, as it is impossible to assess objectively whether, and from where, an “imminent threat” arises.238 The term “national security” does not have a universally agreed definition, as its interpretation varies between different states, regimes, and individuals. In the Greek legal order, “national security” appears as a constitutional term in Articles 5A, 19(1), and 48(1) of the Constitution. Beyond these references, the core of the concept is protected, directly or indirectly, in other constitutional provisions. In its narrower form of “national defence”, it is protected under Article 14(3) (publications endangering national defence), Article 18(3) (requisition of property), Article 22(4) (requisition of personal services), Article 30(4) (extension of the term of office of the President of the Republic during war), and Article 53(3) (extension of parliamentary term during war). National security is also indirectly protected in constitutional provisions regulating the status of military personnel in a special relationship of authority with the State (Article 23(2) (prohibition of military strike), Article 29(3) (prohibition of political activities by military personnel), Article 56(1), (3), and (4)(ineligibility of military personnel for election),and Article 96(4) and (5)(jurisdiction ofspecialmilitarycourts)),aswellas inArticle4(3b) (loss of Greek nationality where a person undertakes service in a foreign State contrary to national interests), and Article 28(2a) (conferral of powers on international organisations for the purpose of serving important national interests). A threat against national security may also trigger the application of constitutional provisions intended for addressing emergency needs, such as Article 5(4b) (individual administrative measures restricting movement), Article 41(2) (dissolution of Parliament for a national issue of exceptional importance), Article 44(1) and (3) (acts of legislative content and addresses by the President of the Republic), Article 76(4) and (5) (limited debate and urgent voting of bills on proposal of 237Aristovoulos Manesis, Individual Liberties, vol. A, 3rd ed. (Thessaloniki: Sakkoulas, 1981), 240. 238Nikos Alivizatos, The Constitutional Position of the Armed Forces, I. The Principle of Political Control (Athens–Komotini: Ant. N. Sakkoulas, 1987), 199 ff. 128 Special Section the Government), and Article 103(2) (recruitment of staff to meet unforeseen and urgent needs). “National security” refers to the protection of the country from external threats that undermine its national independence, territorial integrity, peaceful relations with other states, or sovereign rights (such as the exploitation of declared EEZs).239 The term is linked to the state’s position in its external relations (international standing of the state) and is affected by fluctuations in external relations with other states or international organisations.240 According to Alivizatos,241 “the core of national security is related to the state’s status in its external relations. From this perspective, national security is clearly distinguished from public security, which concerns the protection of the Constitution, the constituted powers, and state institutions from internal threats, and from public order, which, aiming at the legal good of ‘common peace’, primarily seeks to safeguard private rather than civil society. As a legal good, national security is also linked to the protection of the armed forces, possibly the security forces, and the civilian services (counterintelligence and intelligence services in general) whose main mission is its defence, and which may also be threatened from within. This is where national security and public security converge [...]”. The term “national security” does not encompasspublic securityingeneral, butthedefenceofthe countryagainst external threats.242 Therefore, the grounds of national security should not extend to reasons of public order, mere facilitation of police work, or the convenience of other administrative authorities.243 As an exception, it should be interpreted narrowly, and it must strictly satisfy necessity and proportionality in light of the legitimate aim 239Efstratios Efstratiou, National Security as an Exception Clause in the Greek Constitution andtheTreatiesof theEuropeanUnion(PhDdiss., Aristotle University of Thessaloniki, Faculty of Law, 2024, unpublished), 23. 240Ibid., 23. 241Nikos Alivizatos, The Constitutional Position of the Armed Forces, vol. I: The Principle of Political Control (Athens–Komotini: Ant. N. Sakkoulas, 1987), 199 ff. 242Panagiotis Tsiris, The Constitutional Safeguard of the Right to Communication (Athens–Komotini: Ant. N. Sakkoulas, 2002), 110 ff. 243Prodromos D. Dagtoglou, Constitutional Law, Individual Rights (Athens–Thessaloniki: Sakkoulas, 2022), 361, para. 542. 129 I. Biometric identification pursued.244 Invoking national security indicates that there is, at least at that time, no offence – certainly not a particularly serious one – and no pending criminal prosecution.245 The information sought concerns external security, because internal security is framed in the Constitution as “public security” (Article 11(2)) and “public order” (Articles 13(2) and 18(3)).246 In criminal law, the constitutional concept of national security aligns with the legal interest of the country’s international standing, encompassing protection of territorial integrity, international peace, defence capability, and state secrets, and is codified in Articles 138–152 of the Penal Code.247 The European Court of Human Rights has extensive case law on measures justified by national security.248 While acknowledging a wide margin of appreciation for domestic legal orders, the Court stresses that the existence of a “pressing social need” justifying national security grounds must be adequately examined by the competent authorities.249 To safeguardthe ruleof lawinademocraticsociety,a blanketnational security exception should be avoided, because it creates a risk of abuse. Accordingly, any exception should be rigorously assessed case by case, in line with the EU Charter of Fundamental Rights and the case law of the CJEU.If anyexception is contemplated,itmust be tightly circumscribed, and any public authority invoking it should be subject to robust transparency and accountability obligations. This includes conducting risk 244Giorgos Karavokyris, “The Face of Democracy,” Constitutionalism, August 16, 2022. 245Evangelos Venizelos, “The Constitutional Limits on Lifting the Telephone Confidentiality of Citizens and Politicians for Reasons of National Security – The Androulakis Case,” Constitutionalism, August 27, 2022. 246Ibid. 247Ibid. 248EkimdzhievandOthers v.Bulgaria, no. 70078/12, Eur.Ct. H.R.,judgment of11 January 2022,paras.291ff.,394 ff.; CentrumförRättvisav.Sweden, no.35252/08, Eur. Ct.H.R., judgment of 19 June 2018, para. 86 ff. 249Dumitru Popescu v. Romania (no. 2), no. 71525/01, Eur. Ct. H.R., judgment of 26 April 2007, para. 61 ff.; Amann v. Switzerland, no. 7798/95, Eur. Ct. H.R., judgment of 16 February 2000, para.76;ValenzuelaContrerasv. Spain,no.58/1997/842/1048,Eur.Ct. H.R., judgment of 30 July 1998, para. 49 ff.; Leander v. Sweden, Series A no. 116, Eur. Ct. H.R., judgment of 26 March 1987, para. 59; Klass and Others v. Germany, Series A no. 28, Eur. Ct. H.R., judgment of 6 September 1978, para. 48. 130 Special Section and impact assessments prior to deployment and throughout the period of use. H. Concluding remarks Biometric monitoring poses an unacceptable risk that society should not, in principle, accept. Such monitoring appears incompatible with human dignity, which underpins European civilisation. Exceptionally, it may be permitted in narrowly defined cases, which must be set out with precision in legislation. It follows from the above that biometric monitoring should be a measure of last resort. The necessary conditions for applying biometric surveillance are as follows: First, the principle of proportionality must be respected.250 This means that the benefits for national security must be significant, and the risks to privacy must be mitigated. Consequently, indiscriminate scanning of everyone’s faces should not occur. Second, legislative clarity is required, with explicit statutes delimiting permissible use of facial recognition in line with European values and human rights. Third, a common EU operational framework is needed. This implies that there will be no divergence between Member States. Fourth, design and governance should be inclusive.251 This entails public dialogue with all stakeholders, including government authorities, technology providers, data providers, data protection authorities, and civil society. Fifth, robust ethical oversight is required through an independent ethics committee to guide and oversee development, and judicial authorisation and supervision for case-specific use.252 It should also be ensured 250Carissa Véliz, “The Surveillance Delusion,” in The Oxford Handbook of Digital Ethics, ed. Carissa Véliz (Oxford: Oxford University Press, 2021; online ed., Oxford Academic, November 10, 2021), https://doi.org/10.1093/oxfordhb/9780198857815.013.30 251Kat Holmes, Mismatch: How Inclusion Shapes Design (Cambridge, MA:MIT Press, 2018), https://doi.org/10.7551/mitpress/11647.001.0001 252Luciano Floridi, TheEthicsofAI (Oxford:OxfordUniversityPress,2023),105,discussing the importance of “context” in choosing appropriate justice measures. 131 I. Biometric identification that the use of the technology by the police is subject to multi-level oversight. Sixth, effective error management is required through procedures to remedy misidentification and unauthorised access. Seventh, logs must be kept for the purposes of explainability, recording all changes and deletions made to a record. Eighth, the system must be based on the principle of transparency and algorithmic fairness, with a mandatory ability to audit algorithms to ensure fairness and accuracy. Ninth, controlled environments must be introduced for system audits and test environments to examine these technologies, explore their usein lawenforcement,andevaluatethem underhigher levels ofscrutiny to ensure compliance with ethical, legal, and human rights standards. Tenth, accountability is required for the consequences of actions caused by an algorithm.253 Eleventh, AI literacy is required, providing a legal framework for ongoing training and educational programmes on AI for law enforcement and civil society. The successful integration of AI technologies in law enforcement requires public trust and acceptance. This necessitates investment in public participation, education, awareness raising, and feedback mechanisms.Strengthening cooperation andknowledgesharingthroughcrossdepartmental collaboration, partnerships with academia and industry, and the involvement of civil society is essential for the successful integration of AI in law enforcement. 253Ibid. 132 II. Employment and the workplace A. General remarks AI has entered many aspects of modern life and can be expected to affect work in various ways. Its advent creates new occupations but also eliminates others. Concerns are expressed that AI will lead to soaring unemployment through the elimination of manual occupations and jobs requiring light or low-level intellectual skills. AI has already eliminated, andis expectedto eliminate even more,repetitiveand predictablejobs.254 These concerns are countered by the argument that AI will require new skills and create new occupations.255 Some tasks may be completely replaced, but a multitude of new requirements will be transformed into new occupations.256 At this point there is also a creative convergence of automation and the utilisation of human labour.257 At the same time, the workforce is subject to algorithmic management.258 This means that it is (pre)selected, (pre)evaluated, controlled, and monitored on the basis of an algorithmic process. This constitutes a new form of algorithmic management.259 It refers to the practices of 254Anastasios G. Gatzoufas, “Everyday Life in the Age of Artificial Intelligence,” diaLOGOS 14 (2024): 293 ff. (300). 255Giorgos Theodosis, “Article 21,” in Artificial Intelligence, Human Rights, Democracy and the Rule of Law, ed. Evripidis Stylianidis (Athens: Nomiki Vivliothiki, 2025), 452 ff. (454). 256Giorgos Giannakopoulos, Artificial Intelligence: A Discreet Demystification (Athens: Ropi, 2020), 33. 257Dimitris Travlos-Tzanetatos, Labour Law in the Fourth Industrial Revolution: Digitalisation,Robotics andArtificialIntelligence(Athens–Thessaloniki: Sakkoulas,2019),253. 258Giorgos Theodosis, “Article 21,” in Artificial Intelligence, Human Rights, Democracy and the Rule of Law, ed. Evripidis Stylianidis (Athens: Nomiki Vivliothiki, 2025), 452 ff. (454). 259Matina Giannakourou, “The Regulation of Algorithmic Labour Administration in the Draft Legislative Initiatives of the EU: Quo vadis, Europa?,” in Artificial Intelligence and Labour Law, ed. Matina Giannakourou and Christina Deliyianni-Dimitrakou, Labour Law Review (2023): 645 ff. (646). 133 II. Employment and the workplace planning, organising, and managing employees via digital platforms.260 It involves the full or partial delegation of personnel management functions and the employer’s powers that constitute managerial authority to AI systems, algorithms, or automated decision-making systems.261 The fundamental aim of AI regulation in the workplace is to serve human well-being, not undermine it. Yet can management truly be delegated to an algorithm?262 B. Managing employees through artificial intelligence In the workplace, extensive data concerning the employee are collected from multiple sources (internet, social networks, evaluations, and so on)263 and include the employee’s CV, degrees, certificates, and skills. Processing these data seeks to create a model of which candidate is suitable or unsuitable for filling a particular post, or even who should be promoted264 or dismissed. This may initially sound positive, as it saves resources and time. Yet it is also linked to negative consequences when discrimination and prejudice intervene, potentially affecting specific population groups, such as vulnerable groups, and aggravating social inequalities.265 Personal data collected from various devices are analysed and reused for automated or semi-automated decision-making.266 Algorithms can, with a certain degree of autonomy and minimal human supervision, select useful outcomes by identifying patterns in existing 260Ibid. 261Ibid. 262Lilian Mitrou, “Can the Algorithm Govern?,” in Can the Algorithm ... Be Ethical, Be Fair, Be Transparent, Judge and Govern?, ed. Lilian Mitrou (Heraklion: University of Crete University Press, 2023), 253 (265). 263Giorgos Theodosis, “Article 21,” in Artificial Intelligence, Human Rights, Democracy and the Rule of Law, ed. Evripidis Stylianidis (Athens: Nomiki Vivliothiki, 2025), 452 ff. (458). 264Rolf Schwartmann, Kristin Benedikt, Moritz Köhler, and Markus Wünschelbaum, Erste Hilfe zur KI-Verordnung: KI-Kompetenz, Rechte, Pflichten (Munich: C.H. Beck, 2025), 37. 265Antonio Aloisi, “Algorithmic Management,” in Artificial Intelligence and Labour Law, ed. Matina Giannakourou and Christina Deliyianni-Dimitrakou, Labour Law Review (2023), 621 ff. (636). 266Ibid., 624. 134 Special Section data that predict future outcomes.267 At the same time, lack of objectivity in data processing can lead to inaccurate estimates.268 When an algorithm has been trained that managerial posts are occupied by white men, it will select a white man. Moreover, processing the vast amount of an employee’s data may produce a detailed psychogram and affect the right to informational self-determination. This blurs the boundaries between personal and private life by mixing professional data with special categories of data (sensitive data), enabling employers to observe, infer, direct, and even prevent human behaviour.269 A new form of algorithmic employer is emerging on the horizon.270 AI assists employers in decision-making, or even makes decisions on their behalf.271 Beyond the risks of algorithmic bias, which may cause discrimination, exclusion, or disadvantage,272 there also emerges a lack of human contact and workplace alienation through the platformisation of work.273 C. The response of the EU and national legislator The Regulation clarifies in Recital 9 that AI must not undermine the right to work. In particular, the Regulation must not affect Union law on social policy and national labour law, in compliance with Union law, concerning employment and working conditions, including health and safety at work, and the relationship between employers and workers. It should also not affect the exercise of fundamental rights as recognised in the Member States and at Union level, including the right or freedom to 267Ibid., 631. 268Rolf Schwartmann, Kristin Benedikt, Moritz Köhler, and Markus Wünschelbaum, Erste Hilfe zur KI-Verordnung: KI-Kompetenz, Rechte, Pflichten (Munich: C.H. Beck, 2025), 37. 269Antonio Aloisi, “Algorithmic Management,” in Artificial Intelligence and Labour Law, ed. Giannakourou and Deliyianni-Dimitrakou, Labour Law Review (2023), 621 ff. (632). 270Ibid., 624. 271Ibid., 631. 272Aurélie Jean, On the Other Side of the Machine: A Journey into the Land of Algorithms, trans. Giorgos Bolierakis (Athens: Stere¯ oma, 2023), 25. 273Rolf Wank, “Algorithmic Management and the Individual Employment Contract,” in Artificial Intelligence and Labour Law, ed. Matina Giannakourou and Christina Deliyianni-Dimitrakou, Labour Law Review (2023), 675 ff. (677). 135 III. Artificial intelligence and democracy 1. Disinformation The operation of algorithms, and the connections they create between individuals, carry considerable weight for the democratic principle. Public debate can be undermined through the mass dissemination of false information.282 A form of targeted disinformation is produced, a distortion of reality283 into which one can easily slip without realising it and from which it is extremely difficult, from a technical perspective, to escape. Facts and information are “manufactured” by digital media and become products of algorithmic choices.284 This type of targeted information can influence electoral outcomes and, to a large extent, the democratic principle,285 in the sense that elections are ultimately not decided by the people but by interest groups with the technical capacity to shape the popular will. In this respect, disinformation constitutes a threat to liberal democracy and its institutions.286 It is crucial for the proper functioning of democracy and the untainted expression of the will of the people in elections.287 Electoral processes can be undermined through practices such as the dissemination of intentional and uninten282Evripidis Stylianidis, “Article 5A,” in Artificial Intelligence, Human Rights, Democracy and the Rule of Law, ed. Evripidis Stylianidis (Athens: Nomiki Vivliothiki, 2025), 145 ff. (153). 283Lilian Mitrou, “Digital Democracy, Participation and Threats,” in Rule of Law and Democracy in the Digital Age, ed. Giorgos Karavokyris (Athens: Hellenic Parliament Foundation for Parliamentarism and Democracy, 2024), 53 ff. (78 ff.). 284Charalampos Tsekeris, “Human Communication in the Whirlwind of the ‘Strange Magic’of SocialNetworks,”EconomicReview,April22, 2024, https://www.economia. gr/ 285Council of Europe, Study on the Human Rights Dimensions of Automated Data Processing Techniques (in Particular Algorithms) and Possible Regulatory Implications, March 2018, available at: https://edoc.coe.int/en/internet/7589-algorithms-and-human-rig hts-study-on-the-human-rights-dimensions-of-automated-data-processing-techniq ues-and-possible-regulatory-implications.html 286Lilian Mitrou, “Digital Democracy, Participation and Threats,” in Rule of Law and Democracy in the Digital Age, ed. Giorgos Karavokyris (Athens: Hellenic Parliament Foundation for Parliamentarism and Democracy, 2024), 82. 287Lina Papadopoulou, “Fake News and Hate Speech,” in Rule of Law and Democracy in the Digital Age, ed. Giorgos Karavokyris (Athens: Hellenic Parliament Foundation for Parliamentarism and Democracy, 2024), 99 ff. (117). 142 Special Section tional disinformation, the spread of deepfake content,288 or the manipulation of individuals through targeted strategies. The misuse of such technologies, for instance the creation of videos by algorithms that distort reality so that the line between true and false289 becomes difficult to discern, poses aseriousthreatto democracies.It enablesmalicious actors, ranging from political opponents to foreign adversaries, to manipulate public perceptions, disrupt electoral processes, and amplify disinformation.290 Particularly dangerous in this respect are the texts generated by generative AI; as these systems produce highly persuasive material, they allow both state and non-state actors to disseminate disinformation and harmful narratives.291 Generative AI models played a significant role in the 2024 US presidential election campaign, with fake images and deepfakes created by AI flooding social media platforms.292 Fabricated images appeared on both sides: Trump reposted an AI-generated picture showing singer Taylor Swift endorsing his campaign, something she never did, while Democrats circulated AI-generated images of Trump being arrested.293 It should be noted that alongside disinformation, overinformation, understood as the provision of an excessive volume of information, also poses a risk, as recipients are unable to evaluate and process it effectively 288According to Recital 134 and Article 3(60) of the AI Act, “deepfake content” is defined as “image, sound or video content produced or manipulated by AI which bears a resemblance to real persons, objects, places, entities or events and which may give the deceptive impression of being genuine or real.” 289Evripidis Stylianidis, “Article 5A,” in Artificial Intelligence, Human Rights, Democracy and the Rule of Law, ed. Evripidis Stylianidis (Athens: Nomiki Vivliothiki, 2025), 145 ff. (153). 290Lina Papadopoulou, “Fake News and Hate Speech,” in Rule of Law and Democracy in the Digital Age, ed. Giorgos Karavokyris (Athens: Hellenic Parliament Foundation for Parliamentarism and Democracy, 2024), 117. 291Ibid. 292Ibid. 293Ibid. 143 III. Artificial intelligence and democracy 2. Exploitation of data Data are of great value. They are rightly described as the “new gold”294 and have acquired exchange value.295 Those who process them can better understand their constituents, optimise their actions, and make datadriven decisions.296 As Harari aptly notes, whoever controls the data controls the future.297 Governance has always required reliance on data. Big data contributes to the effectiveness of public services and strategic planning and shape the interactions between citizens, public institutions, policies and administrative systems.298 AI can collect and analyse these data in real time, training299 algorithms and enabling campaign strategists to adjust their approaches in line with public opinion. Data collection can be used either to identify the electorate’s fundamental needs or simply to influence and manipulate voters. By analysing the distinctive psychographic and behavioural profiles of voters on social media,AI canbe deployedto sway individuals towards a particularcandidate or to spread hostility against opponents in order to influence voting decisions.300 The creation of psychographic profiles and targeted messages, enabled by Big Data, in online campaigns based on deception and intimidation can shape a wide range of activities, from propaganda to policy-making.301 This is because election campaigns are moving increas294Tom Dausy, “Data, the New Gold: How AI Is Unlocking Insights and Driving Business Growth,” Medium, May 19, 2024, https://medium.com/@tomdausy/data-the-new -gold-how-ai-is-unlocking-insights-and-driving-business-growth-c458b5676f08 295Takis Vidalis, “The Impact of Technology on Democracy,” in Liber Amicorum Ismini Kriari (Athens: Sideris, 2025), 21 ff. (27). 296Tom Dausy, “Data, the New Gold: How AI Is Unlocking Insights and Driving Business Growth,” Medium, May 19, 2024, https://medium.com/@tomdausy/data-the-new -gold-how-ai-is-unlocking-insights-and-driving-business-growth-c458b5676f08 297Yuval Noah Harari, 21 Lessons for the 21st Century (Athens: Alexandria, 2018), 87. 298UNESCO,Artificial Intelligence and Democracy (Paris: UNESCO, 2024), 13, https://un esdoc.unesco.org/ark:/48223/pf0000389736 299Government Foresight Centre, Plan for Greece’s Transition to the Age of Artificial Intelligence (Athens: Government Foresight Centre, 2024), 46, https://foresight.gov.gr/ wp-content/uploads/2024/11/Sxedio_gia_tin_metavasi_TN_Gr.pdf 300UNESCO,Artificial Intelligence and Democracy (Paris: UNESCO, 2024), 12, https://un esdoc.unesco.org/ark:/48223/pf0000389736 301Ibid. 144 Special Section ingly online and advertising on digital platforms is influencing election outcomes.302 Governance based on available data is neither neutral nor uncontested because the data themselves are neither universally available nor beyond dispute.303 Algorithms frequently embed biases.304 The social roots of prejudice run deep, and the education required to identify and eliminate them is lacking.305 Algorithms trained on recent recruitment data develop biases against specific groups.306 The vast quantities of data available exceed human capacity to analyse, comprehend, and ultimately make use of them. This has led to increased reliance on automated algorithms to detect patterns and support decision-making, deepening our dependence on such technologies and aggravating power imbalances.307 Biases arise not only from data but also from algorithm design and AI training practices,308 which can either reinforce or mitigate them.309 In short, it is not the algorithm itself that is racist, but its design and training based on existing statistical data. Data inequality stems primarily 302Cornelius Erfort, “Targeting Voters Online: How Parties’ Campaigns Differ,” Electoral Studies 92 (December 2024), https://www.sciencedirect.com/science/article/pii/ S0261379424001306 303Iliana Kosti, “Can the Algorithm Be Fair?,” in Can the Algorithm ... Be Ethical, Be Fair, Be Transparent, Judge and Govern?, ed. Lilian Mitrou (Heraklion: University of Crete University Press, 2023), 97 ff. (103). 304A classic case of bias is the systematic discrimination against women who applied for technical jobs at Amazon, such as software engineering positions. The algorithm developedthis biasbecauseAmazon’s existing pool ofsoftwareengineerswasoverwhelmingly male and white, and the new software was trained on data from their résumés. See Rachel Goodman, “Why Amazon’s Automated Hiring Tool Discriminated Against Women,” ACLU, October 12, 2018, https://www.aclu.org/news/womens-rights/ why-amazons-automated-hiring-tool-discriminated-against 305Iliana Kosti, “Can the Algorithm Be Fair?,” in Can the Algorithm ... Be Ethical, Be Fair, Be Transparent, Judge and Govern?, ed. Lilian Mitrou (Heraklion: University of Crete University Press, 2023), 97 ff. (103). 306Aurélie Jean, On the Other Side of the Machine: A Journey into the Land of Algorithms, trans. Giorgos Bolierakis (Athens: Stere¯ oma, 2023), 146. 307UNESCO,Artificial Intelligence and Democracy (Paris: UNESCO, 2024), 14, https://unesdoc.unesco.org/ark:/48223/pf0000389736 308COMPAS,Correctional Offender Management Profiling for Alternative Sanctions (Northpointe Inc., 2012). 309UNESCO,Artificial Intelligence and Democracy (Paris: UNESCO, 2024), 14, https://unesdoc.unesco.org/ark:/48223/pf0000389736 145 III. Artificial intelligence and democracy from unequal access to it.310 Even where databases are publicly available, only a limited number of people have the skills or resources to analyse, understand, manage, or exploit them.311 Today’s Big Data ecosystem produces significant inequalities, reflecting a different kind of poverty and wealth,312 not based on material goods.313 There are essentially three categories of people when it comes to databases: those who produce them, those who have the capabilities and resources to store them, and those who know how to exploit their value. The last group is the smallest and most privileged one, dictating the rules that govern the use of and participation in Big Data.314 310The European Data Act (the Regulation on harmonised rules for fair access to and use of data – also known as the Data Act – entered into force on 11 January 2024) constitutes a key pillar of the European data strategy and will significantly contribute to achieving the Digital Decade goal of promoting digital transformation. It provides that connected products must be designed and manufactured, and related services must be supplied, in such a way that the data generated by these products and services are directly accessible to users (Article 3). If the data cannot be made directly accessible, they must be made available upon request without undue delay (Article 4). There is an exception to the obligation of direct access or availability upon request where such access would undermine the security of the connected product, leading to serious adverse effects on the health, safety, or protection of natural persons. According to Articles 3 and 4 of the Regulation, the data that must be directly accessible or made available upon request include: (a) product data, i.e. data generated by the use of the connected product, designed to be retrievable via an electronic communications service, physical connection, or access to the device; (b) related service data, i.e. data representing the digitalisation of user actions (including in-app actions) and events related to the connected product, whether deliberately recorded by the user or produced as a by-product of user actions; and (c) metadata necessary for the interpretation of the aforementioned categories of data. 311UNESCO,Artificial Intelligence and Democracy (Paris: UNESCO, 2024), 14, https://un esdoc.unesco.org/ark:/48223/pf0000389736 312Uneecops. “How Data Analytics Drive Growth for Wealth Management Firms.” August 2, 2024. https://www.uneecops.com/blog/data-analytics-for-wealth-managem ent-firm 313UNESCO,Artificial Intelligence and Democracy (Paris: UNESCO, 2024), 14, https://unesdoc.unesco.org/ark:/48223/pf0000389736 314Ibid. 146 Special Section 3. Manipulation The Cambridge Analytica scandal revealed the extent to which the misuse of AI can influence electoral behaviour. This is because the data of internet users can be exploited to build a political, ideological or psychological profile of individual voters, enabling the delivery of personalised advertisementsorautomatedmessages to promote or discredit particular candidates. First, the autonomy of the citizen is undermined: through the creation of a detailed psychological profile and the exploitation of weaknesses, fears, or fixations by means of personalised messages designed to trigger emotions, the citizen is subjected to a form of automated “brainwashing” intended to influence behaviour.315 Second, internet users are rarely informed of, or give their consent to, the use of their data for such purposes.316 Third, there arises the issue of violating the right to stand for election and the principle of equal opportunities among candidates.317 Fourth, algorithms are employed to generate and disseminate false or distorted news, as part of propaganda strategies designed to manipulate the information and steer the emotions of internet users in a given direction.318 For instance, false or distorted reports – such as fabricated statements by political figures about alleged violent crimes committed during the electoral period by migrants or asylum seekers – can be deployed in campaignsspreading fear,intolerance,and xenophobia,thereby promoting extreme ideologies. Fifth, the use of algorithms to create deepfakes (videos in which faces are changed or replaced) with the aim of misleading the public and discrediting political opponents is equally dangerous for democratic processes. Furthermore, attention must be drawn to the risk that the provision of predetermined and curated knowledge may undermine the liberal 315Fereniki Panagopoulou-Koutnatzi, Artificial Intelligence: The Path to a Digital Constitutionalism – An Ethical-Constitutional Approach (Athens: Papazisis, 2023), 286. 316Ibid., 288. 317Latanya McSweeney, “Psychographics, Predictive Analytics, Artificial Intelligence & Bots: Is the FTC Keeping Pace?,” Data Privacy Lab (2013): 514 ff., http://datapriv acylab.org/projects/onlineads/1071-1.pdf 318Fereniki Panagopoulou-Koutnatzi, Artificial Intelligence: The Path to a Digital Constitutionalism – An Ethical-Constitutional Approach (Athens: Papazisis, 2023), 286. 147 III. Artificial intelligence and democracy character of our polity, by imposing the “average” of existing knowledge on science and thought more generally, and entrenching a single, uniform perception of reality.319 The use of AI systems to influence voters politically and shape the outcome of elections has raised serious concerns at both European and international levels. It is therefore reasonable to ask whether legislative intervention is required in order to safeguard the core of liberal democracy. The question is a complex one, since the consolidation of a particular perception may in turn foster the consolidation of a particular electoral preference and, in this way, the indirect manipulation of the electorate. The risks arising from the use of AI in electoral contests may be numerous, difficult to address, and in many cases intolerable (within the meaning of Article 5 of the Regulation), where they result in the manipulation of citizens. It is proposed that legislators accord this issue particular priority, requiring digital platforms, algorithm developers, and distributors to ensure algorithmic transparency and to criminalise the creation and dissemination of harmful deepfake products that enable political manipulation.320 At the same time, software developers and distributors must block audio and video products that generate harmful deepfakes and will be held responsible if their preventive safeguards can be easily circumvented. To this end, mechanisms for verifying the reliability of news must be strengthened (fact-checking, including the labelling of content as true, false, or disputed).321 At the same time, specialised skills must be cultivated to counter the falsification of news, media literacy and education must be enhanced, and stakeholders (citizens, journalists, private and public bodies) must be empowered through the adoption of clear, responsible,fair,and widely acceptedrulesof conductandoperationin the 319Fereniki Panagopoulou-Koutnatzi, “Legal and Ethical Concerns Regarding the Use of ChatGPT in Education,” Journal of Law and Technology (2023): 6 ff. (11). 320Government Foresight Centre, Plan for Greece’s Transition to the Age of Artificial Intelligence (Athens: Government Foresight Centre, 2024), 94, https://foresight.gov.gr/ wp-content/uploads/2024/11/Sxedio_gia_tin_metavasi_TN_Gr.pdf 321Lilian Mitrou, “Digital Democracy, Participation and Threats,” in Rule of Law and Democracy in the Digital Age, ed. Giorgos Karavokyris (Athens: Hellenic Parliament Foundation for Parliamentarism and Democracy, 2024), 83. The note also raises the question of who determines whether news is true, false, or disputed. 148 Special Section new, advanced technological environment.322 The debate is not without difficulties. A reasonable question arises as to who exercises control and on the basis of which principles.323 In this context, the Digital Services Act imposes obligations of transparency and accountability with regard to content moderation.324 4. Towards privatisation of elections? The role played by large private internet companies is of great importance. Their architecture and algorithms shape the way people communicate and determine what information is presented, and in what sequence, to participants.325 In short, private actors often play a decisive role in regulating social behaviour and information.326 Some describe this regime as “techno-feudalism”.327 Almost every stage of AI model development, from computing infrastructure to training data, is controlled by an oligopoly of technology companies. There is very little public oversight of how these systems are developed and governed. The risks associated with the concentration of AI development in monopolistic entities are a cause for serious concern.328 There is a need to find alternative structures for the exploitation and governance of AI that would better serve the public interest with regard to AI development. One of these structures could be shareholding 322Government Foresight Centre, Plan for Greece’s Transition to the Age of Artificial Intelligence (Athens: Government Foresight, 2024), 94, https://foresight.gov.gr/ wp-content/uploads/2024/11/Sxedio_gia_tin_metavasi_TN_Gr.pdf 323Lilian Mitrou, “Digital Democracy, Participation and Threats,” in Rule of Law and Democracy in the Digital Age, ed. Giorgos Karavokyris (Athens: Hellenic Parliament Foundation for Parliamentarism and Democracy, 2024), 87. 324In this sense, this Act constitutes the most significant reform regarding digital platforms. See Ioannis Iglezakis, The Law of the Digital Economy, 2nd ed. (Athens–Thessaloniki: Sakkoulas, 2024), 71. 325Nicolas P. Suzor, “Digital Constitutionalism: Using the Rule of Law to Evaluate the Legitimacy of Governance by Platforms,” Social Media + Society 4, no. 3 (2018): 1–11, https://doi.org/10.1177/2056305118787812 326Ibid., 2. 327Manolis Andriotakis, Artificial Intelligence for All (Athens: Psychogios, 2022), 69. 328Anton Korinek and Jai Vipra, “AI Monopolies,” Economic Policy (panel brief), March 27, 2024, https://www.economic-policy.org/79th-economic-policy-panel/ai-monop olies/ 149 III. Artificial intelligence and democracy schemes.329 These are employee-owned and managed enterprises with a long global history of community-oriented business practices that distribute both control and capital. Today, it is estimated that participatory schemes employ nearly 10% of the world’s population.330 Participatory models are designed to ensure fairer ownership and governance than investor-owned companies.331 Such structures are expected to alleviate growing concerns among various stakeholders: consumers gain greater influence and an economic stake in the technological systems that shape their lives; businesses build trust with consumers and regulators while remaining connected to public needs; and regulators facilitate a competitivemarketplace withthepotential to enhancethesocial impactof AI.332 5. Algorithmic governance? Decision-making largely tends to be algorithmic,333 as automated systems account for a significant share of government decisions.334 Managing complex issues requires algorithmic decision-making. It is difficult to conceive of managing the complexity of modern societies without such processes of this kind, as they process vast amounts of information and 329Sarah Hubbard, Cooperative Paradigms for Artificial Intelligence (Cambridge, MA: Ash Center for Democratic Governance and Innovation, Harvard Kennedy School, November 20, 2024), https://ash.harvard.edu/resources/cooperative-paradigms-for -artificial-intelligence/ 330International Cooperative Alliance, “Co-ops Employ 10% of the Global Employed Population,” September 25, 2017, https://ica.coop/en/media/news/co-ops-employ-10-g lobal-employed-population 331Connor Spelliscy, Sarah Hubbard, Nathan Schneider, and Samuel Vance-Law, “Toward Equitable Ownership and Governance in the Digital Public Sphere,” Stanford Journal of Blockchain Law & Policy (2024), https://stanford-jblp.pubpub.org/pub/equitabl e-ownership-and-governance/release/1 332Sarah Hubbard, Cooperative Paradigms for Artificial Intelligence (Cambridge, MA: Ash Center for Democratic Governance and Innovation, Harvard Kennedy School, November 20, 2024), https://ash.harvard.edu/resources/cooperative-paradigms-for -artificial-intelligence/ 333Fereniki Panagopoulou, “Algorithmic Decision-Making in Public Administration,” in Rule of Law and Democracy in the Digital Age, ed. Giorgos Karavokyris (Athens: Hellenic Parliament Foundation for Parliamentarism and Democracy, 2024), 141 ff. 334John Danaher, “The Threat of Algocracy: Reality, Resistance and Accommodation,” Philosophy&Technology29 (2016): 245–268.https://doi.org/10.1007/s13347-015-0211-1 150 Special Section automate tasks that would otherwise be impossible or less efficient.335 The problem, however, is the extent to which and the manner in which the use of automated decision-making systems is compatible with political decision-making.336 AI systems can improve our understanding of socialpreferencesand facilitate moreobjectiveevaluationsofpublicpolicies. They are also useful in situations where there is a large volume of data and choices are sorted into binary-digit categories.337 Even so, they prove limited in cases of data scarcity or ambiguous situations, where policy decisions are imperative and carry greater certainty than any calculation.Inanycase,in a democracy, the final decisionrests with the people who hold sovereignty, regardless of the extent of data processing.338 Therefore, the algorithm should not replace but assist those who make political decisions.339 6. Have the risks been confirmed? In2024, numerouscountries340 held nationalelections,making that year one of the largest election years in history. It was the largest election year in human history, with 3.7 billion voters in 72 countries going to the polls.341 Despite early public concerns about dramatic AI disruption in the 2024 election, experts agreed that most of those fears did not materialise, while a more nuanced reality is emerging: AI permeates all as335UNESCO,Artificial Intelligence and Democracy (Paris: UNESCO, 2024), 16, https://unesdoc.unesco.org/ark:/48223/pf0000389736 336Ibid. 337Ibid. 338Ibid. 339Fereniki Panagopoulou, “Algorithmic Decision-Making in Public Administration,” in Rule of Law and Democracy in the Digital Age, ed. Giorgos Karavokyris (Athens: Hellenic Parliament Foundation for Parliamentarism and Democracy, 2024), 137 ff. (180). 340“It’s theBiggest ElectionYear inModernHistory. Will DemocracyPrevail?,”NPR,3 July 2024, https://www.npr.org/2024/07/03/1198912778/its-the-biggest-election-year-i n-modern-history-will-democracy-prevail 341BruceSchneier andNathanSanders, “TheApocalypseThatWasn’t:AI WasEverywhere in2024’sElections,butDeepfakesandMisinformationWereOnlyPart ofthePicture,” Ash Center for Democratic Governance and Innovation, Harvard Kennedy School, 4 December 2024, https://ash.harvard.edu/articles/the-apocalypse-that-wasnt-ai-was -everywhere-in-2024s-elections-but-deepfakes-and-misinformation-were-only-par t-of-the-picture/ 151 Bibliography Pavlopoulos,Prokopios.“CriticalReflections on the Relevance of Aristotle’s Positions on Law and Justice in the Age of Artificial Intelligence.” Public Law Review 1 (2025): 41 ff. Pavlopoulos, Prokopios. “Dilemmas of Legal Science in the Age of Artificial Intelligence.” Constitutionalism.gr, February 2025. https://www.constitutionalis m.gr/dilimata-tis-nomikis-epistimis-stis-prokliseis-tis-ai/. Pierrakakis, Kyriakos. Introduction to Manolis Andriotakis, Artificial Intelligence for All, 9–12. Athens: Psychogios, 2022. Polanyi, Karl. The Great Transformation. Boston: Beacon Press, 2001 [1944]. Polymeris, Spyros. “Chaos Theory, Artificial Intelligence and Education: A Discussion.” Public Administration Review (Greece): 81 ff. https://www.lawjournal s.unic.ac.cy/index.php/pareview. Ranchordas, Sofia, and Valeria Vinci. “Regulatory Sandboxes and InnovationFriendly Regulation: Between Collaboration and Capture.” Italian Journal of Public Law 16 (2024): 107, 132. https://papers.ssrn.com/sol3/papers.cf m? abstract_id=4696442 Ranchordas, Sofia. “Experimental Lawmaking in the EU: Regulatory Sandboxes.” EU Law Live, Weekend Edition, October 22, 2021. University of Groningen Faculty of Law Research Paper No. 12/2021. SSRN: https://ssrn.com/ abstract=3963810 Ranchordas, Sofia. “Innovation Experimentalism in the Age of the Sharing Economy.” Lewis & Clark Law Review 19 (2015): 871. Reed, Chris. “How Should We Regulate Artificial Intelligence?” Philosophical Transactions of the Royal Society A 376, no. 2128 (2018). Ringe, Wolf-Georg, and Christopher Ruof. “Keeping Up with Innovation: Designing a European Sandbox for FinTech.” ECMI Commentary no. 58 (2019). https://www.ecmi.eu/publications/commentaries/keeping-innovation-designi ng-european-sandbox-fintech Rizos, Panagiotis. Tartaros Ltd. Athens: Papadopoulos, 2024. Rohrlich, Michael. KI und Recht. Munich: Hanser, 2025. Roden-Bow, Ashley. “Killer Robots and Inauthenticity: A Heideggerian Response to the Ethical Challenge Posed by Lethal Autonomous Weapons Systems.” Conatus – Journal of Philosophy 8, no. 2 (2023): 477–486. https://doi. org/10.12681/cjp.34864. 254 Bibliography Rudschies, Catharina, Ingrid Schneider, and Judith Simon. “Value Pluralism in the AI Ethics Debate: Different Actors, Different Priorities.” International Review of Information Ethics 32 (2024). https://informationethics.ca/index.php/ irie/article/view/419/396 Sarafianos, Dimitris. Interpretation of Article 16 of the Constitution. Athens: Nomiki Vivliothiki, 2017. Sarmas, Dimitris. “Article 14.” In Article-by-Article Commentary on the Charter of Fundamental Rights of the EU, edited by Eugenia R. Sahpekidou and Haris N. Tagaras, 164 ff. Athens: Nomiki Vivliothiki, 2020. Savcisens, Germans, et al. “Using Sequences of Life-Events to Predict Human Lives.” Nature Computational Science (2023). https://doi.org/10.1038/s43588-0 23-00573-5 Schneier, Bruce, and Nathan Sanders. “The Apocalypse That Wasn’t: AI Was Everywhere in 2024’s Elections, but Deepfakes and Misinformation Were Only Part of the Picture.” Ash Center, Harvard Kennedy School, December 4, 2024. https://ash.harvard.edu/articles/the-apocalypse-that-wasnt-ai-was-everywher e-in-2024s-elections-but-deepfakes-and-misinformation-were-only-part-of-t he-picture/ Schwartmann, Rolf, Kristin Benedikt, Moritz Köhler, and Markus Wünschelbaum. Erste Hilfe zur KI-Verordnung: KI-Kompetenz, Rechte, Pflichten. Munich: C.H. Beck, 2025. Selinger, Evan, and Brenda Leong. “Facial Recognition Technology Primer: What Is It and How Is It Used?” In The Oxford Handbook of Digital Ethics, edited by Carissa Véliz, 590 ff. Oxford: Oxford University Press, 2021. Soilentakis, Panagiotis. Artificial Intelligence at the Core of Constitutional and Administrative Law. Athens: Nomiki Vivliothiki, 2025. Spelliscy, Connor, Sarah Hubbard, Nathan Schneider, and Samuel Vance-Law. “Toward Equitable Ownership and Governance in the Digital Public Sphere.” Stanford Journal of Blockchain Law & Policy (2024). https://stanford-jblp. pubpub.org/pub/equitable-ownership-and-governance/release/1 Stiglitz, Joseph E. People, Power, and Profits: Progressive Capitalism for an Age of Discontent. New York: W.W. Norton, 2019. Stratilatis, Konstantinos. “Article 5A of the Constitution: The Right to Information.” In Article-by-Article Commentary on the Constitution, edited by Spy255 Bibliography ros Vlachopoulos, Xenophon Contiades, and Giannis Tasopoulos. Syntagma Watch. https://www.syntagmawatch.gr/my-constitution/arthro-5a/. Stylianidis, Evripidis and Thaleia Chalkidzi. “Article 16.” In Artificial Intelligence, Human Rights, Democracy and the Rule of Law, edited by Evripidis Stylianidis, 306 ff. Athens: Nomiki Vivliothiki, 2025. Stylianidis, Evripidis. “Article 5A.” In Artificial Intelligence, Human Rights, Democracy and the Rule of Law, edited by Evripidis Stylianidis, 145 ff. Athens: Nomiki Vivliothiki, 2025. Stylianidis,Evripidis.“Proposal on Artificial Intelligencein View of the Revision of the Greek Constitution.” In Artificial Intelligence, Human Rights, Democracy and the Rule of Law, edited by Evripidis Stylianidis, 633 ff. Athens: Nomiki Vivliothiki, 2025. Suzor, Nicolas P. “Digital Constitutionalism: Using the Rule of Law to Evaluate the Legitimacy of Governance by Platforms.” Social Media + Society 4, no. 3 (2018): 1–11. Tamamidis,Anastasios.InterpretationofArticle2ofProtocolNo.1ECHR. Athens: Nomiki Vivliothiki, 2021. Tassis, Spyros. “Can the Algorithm Be Ethical?” In Can the Algorithm ... Be Ethical, Be Fair, Be Transparent, Judge and Govern?, edited by Lilian Mitrou, 35 ff. Heraklion: University of Crete Press, 2023. Tegmark, Max, Rob Shapiro, et al. Life 3.0: Being Human in the Age of Artificial Intelligence. New York: Vintage Books, 2018. Tesla Team. “A Tragic Loss.” Tesla Blog, June 30, 2016. Theodosis, Giorgos. “Article 21.” In Artificial Intelligence, Human Rights, Democracy and the Rule of Law, edited by Evripidis Stylianidis, 452 ff. Athens: Nomiki Vivliothiki, 2025. Times of India. “BJP to Use AI to Translate PM’s Speeches.” March 8, 2024. ht tps://timesofindia.indiatimes.com/india/bjp-to-use-ai-to-translate-pms-speec hes/articleshow/108298093.cms Travlos-Tzanetatos, Dimitris. Labour Law in the Fourth Industrial Revolution: Digitalisation, Robotics and Artificial Intelligence. Athens–Thessaloniki: Sakkoulas, 2019. Truby, John, et al. “A Sandbox Approach to Regulating High-Risk Artificial Intelligence Applications.” European Journal of Risk Regulation 13 (2022): 256 Bibliography 270–286. https://ris.utwente.nl/ws/files/304762207/a_sandbox_approach_ to_regulating_high_risk_artificial_intelligence_applications.pdf Tsekeris, Charalambos, Vangelis Karkaletsis, et al. Generative AI Greece 2030: Possible Futures of Generative AI in Greece. Athens: Secretariat for Long-Term Planning, 2023. https://foresight.gov.gr/wp-content/uploads/2024/02/GenAI_ Greece_2030.pdf. Tsekeris, Charalambos. “Human Communication in the Vortex of the ‘Strange Magic’ of Social Networks.” Oikonomiki Epitheorisi, April 22, 2024. https:// www.economia.gr/texnologia-kenotomia/h-anthropini-epikoinonia-sti-dini-t is-paraxenis-mageias-ton-koinonikon-diktion/. Tsiliotis, Charalambos. Public Law Parameters of the Anti-Covid 19 Vaccination. Athens: Nomiki Vivliothiki, 2021 Tsinorema, Stavroula. “Artificial Intelligence with a Human Face: Towards a Technoethics of Responsibility.” In Liber Amicorum Ismini Kriari, 259 ff. Athens: Sideris, 2025. Tsinorema, Stavroula. “Artificial Intelligence with a Human Face: Towards a Technoethics of Responsibility.” Philosophies 1, no. 2 (2021): 8. https://www. mdpi.com/2673-2688/1/2/8 Tsiris, Panagiotis. The Constitutional Protection of the Right to Confidentiality of Communications. Athens–Komotini: Ant. N. Sakkoulas, 2002. Turing, Alan M. “Computing Machinery and Intelligence.” Mind 59, no. 236 (1950): 433–460. Tzemos, Vasilis. “The New AI Regulation and the Charter of Fundamental Rights of the EU.” In Exploring Aspects of Artificial Intelligence: Cutting-Edge Technologies as a Legislative Challenge (2nd Interdisciplinary Conference on Law and Informatics), edited by Eugenia Alexandropoulou-Aigyptiadou, Theoharis Dalakouras, and Christos Mastrokostas, 99 ff. Athens: Nomiki Vivliothiki, 2025. Uneecops.“How Data Analytics Drive Growthfor Wealth ManagementFirms.” August 2, 2024. https://www.uneecops.com/blog/how-data-analytics-drive-g rowth-for-wealth-management-firms/ UNESCO.Artificial Intelligence and Democracy. Paris: UNESCO, 2024. https:// unesdoc.unesco.org/ark:/48223/pf0000388129 Véliz, Carissa, ed. The Oxford Handbook of Digital Ethics. Oxford: Oxford University Press, 2021. 257 Bibliography Véliz, Carissa. “The Surveillance Delusion.” In The Oxford Handbook of Digital Ethics, edited by Carissa Véliz. Oxford: Oxford University Press, 2021; online ed., Oxford Academic, 10 November 2021. https://doi.org/10.1093/oxfordhb/9780 198857815.013.30 Venizelos, Evangelos. “The Constitutional Limits on the Lifting of Telephone Confidentiality of Citizens and Politicians for National Security Reasons – The Androulakis Case.” Constitutionalism, August 27, 2022. Venizelos, Evangelos. Article 25, General Clause for the Protection of Rights. Athens: Nomiki Vivliothiki, 2017. Venizelos, Evangelos. The Constitution and its Enemies. Athens: Sideris, 2021. Venizelos, Evangelos. The Democratic Constitution at Risk. Athens: Papazisis, 2024. Venizelos, Evangelos. The Revisionary Acquis: The Constitutional Phenomenon in the 21st Century and the Contribution of the 2001 Revision. Athens–Komotini: Ant. N. Sakkoulas, 2002. Vidalis, Takis K. “The Impact of Technology on Democracy.” In Liber Amicorum Ismini Kriari, 21 ff. Athens: Sideris, 2025. Vidalis, Takis K. Biolaw, Vol. 1: The Person. Athens–Thessaloniki: Sakkoulas, 2007. Vlachopoulos, Spyridon. “Prenatal Testing and Individual Rights: Developments in Genetics, Scientific Freedom, and the Right to Genetic Ignorance.” Dikaioma tou Anthropou (2002): 363 ff. Vlachopoulos, Spyros V. “The Rule of Law and the Constitution in the Digital Age.” In Rule of Law and Democracy in the Digital Age, edited by Giorgos Karavokyris, 65 ff. Athens: Hellenic Parliament Foundation for Parliamentarism and Democracy, 2024. Vlachopoulos, Spyros. The Selfish Gene of Law and the Law of Artificial Intelligence. Athens: Eurasia, 2023. Warren, Matthew. “The Approach to Predictive Medicine That Is Taking Genomics Research by Storm: Polygenic Risk Scores Represent a Giant Leap for Gene-Based Diagnostic Tests. Here’s Why They’re Still So Controversial.” Nature 562 (2018): 181–83. https://doi.org/10.1038/d41586-018-06956-3 Weizenbaum, Joseph. Computer Power and Human Reason: From Judgment to Calculation. San Francisco: W. H. Freeman, 1976. 258 Bibliography Wendehorst, Christiane. “Art. 1–3.” In KI-VO, Kommentar, Verordnung über künstliche Intelligenz, edited by Mario Martini and Christiane Wendehorst. Munich: C.H. Beck, 2024. Wile, Rob. “A Venture Capital Firm Just Named an Algorithm to Its Board of Directors.” Business Insider, May 13, 2014. https://www.businessinsider.com/ algorithm-named-to-board-of-directors-2014-5 Williams, Ross. “Georgia Political Campaigns Start to Deploy AI but Humans Still Needed to Press the Flesh.” GPB News, 25 April 2024. https://www.gpb. org/news/2024/04/25/georgia-political-campaigns-start-deploy-ai-humans-sti ll-needed-press-the-flesh Winfield, Alan F. T., and Marina Jirotka. “Ethical Governance Is Essential to Building Trust in Robotics and Artificial Intelligence Systems.” Philosophical Transactions of the Royal Society A 376, no. 2133 (2018). WorldBankGroup.GlobalExperiencesfromRegulatory Sandboxes.Washington, DC: World Bank, 2020. Yampolskiy, Roman. Artificial Intelligence: Inexplicable, Unpredictable, Uncontrollable. Athens: Epikentro, 2024. Zekos, Georgios I. Internet and Artificial Intelligence in Greek Law. Athens– Thessaloniki: Sakkoulas, n.d. Zetzsche, Dirk A., et al. “Regulating a Revolution: From Regulatory Sandboxes to Smart Regulation.” Fordham Journal of Corporate & Financial Law 23 (2017): 64. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3018534 Zuboff, Shoshana. The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power. New York: PublicAffairs, 2019. 259