Navigating the EU AI Act: A Methodological Approach to Compliance for Safety-critical Products (2403.16808v2)
Abstract: In December 2023, the European Parliament provisionally agreed on the EU AI Act. This unprecedented regulatory framework for AI systems lays out guidelines to ensure the safety, legality, and trustworthiness of AI products. This paper presents a methodology for interpreting the EU AI Act requirements for high-risk AI systems by leveraging product quality models. We first propose an extended product quality model for AI systems, incorporating attributes relevant to the Act not covered by current quality models. We map the Act requirements to relevant quality attributes with the goal of refining them into measurable characteristics. We then propose a contract-based approach to derive technical requirements at the stakeholder level. This facilitates the development and assessment of AI systems that not only adhere to established quality standards, but also comply with the regulatory requirements outlined in the Act for high-risk (including safety-critical) AI systems. We demonstrate the applicability of this methodology on an exemplary automotive supply chain use case, where several stakeholders interact to achieve EU AI Act compliance.
- “ISO 26262:2018 - Road vehicles – Functional safety, 2nd Edition,” 2018.
- SAE International, “ARP4761 - Guidelines and Methods for Conducting the Safety Assessment Process on Civil Airborne Systems and Equipment,” 1996.
- RTCA, “DO-178C: Software Considerations in Airborne Systems and Equipment Certification,” 2011.
- ——, “D0-254: Design Assurance Guidance for Airborne Electronic Hardware,” 2000.
- “ISO/IEC 25059:2022: Software engineering — Systems and software Quality Requirements and Evaluation (SQuaRE) — Quality model for AI systems,” 2022.
- “ISO/IEC 25010: Systems and software engineering — Systems and software Quality Requirements and Evaluation (SQuaRE) — Product quality model,” 2023.
- “ISO/IEC 25012: Software engineering — Software product Quality Requirements and Evaluation (SQuaRE) — Data quality model,” 2008.
- “ISO/IEC 24028: Information technology Artificial intelligence — Overview of trustworthiness in artificial intelligence,” 2020.
- J. Siebert, L. Joeckel, J. Heidrich, K. Nakamichi, K. Ohashi, I. Namba, R. Yamamoto, and M. Aoyama, “Towards Guidelines for Assessing Qualities of Machine Learning Systems,” in Quality of Information and Communications Technology, M. Shepperd, F. Brito e Abreu, A. Rodrigues da Silva, and R. Pérez-Castillo, Eds. Cham: Springer International Publishing, 2020, vol. 1266, pp. 17–31.
- C. Novelli, F. Casolari, A. Rotolo, M. Taddeo, and L. Floridi, “Taking AI risks seriously: a new assessment model for the AI act,” AI & SOCIETY, pp. 1–5, 2023.
- F. Sovrano, S. Sapienza, M. Palmirani, and F. Vitali, “Metrics, explainability and the european ai act proposal,” J, vol. 5, no. 1, pp. 126–138, 2022.
- J. Walters, D. Dey, D. Bhaumik, and S. Horsman, “Complying with the EU AI act,” 2023.
- J. Siebert, L. Joeckel, J. Heidrich, A. Trendowicz, K. Nakamichi, K. Ohashi, I. Namba, R. Yamamoto, and M. Aoyama, “Construction of a quality model for machine learning systems,” Software Quality Journal, vol. 30, no. 2, pp. 307–335, Jun. 2022.
- “ISO/PAS 8800: Road Vehicles - Safety and artificial intelligence,” Tech. Rep., in work.
- “ISO/PAS 21448: Safety Of The Intended Functionality – SOTIF,” 2022.
- European Commission, “Ethics By Design and Ethics of Use Approaches for Artificial Intelligence,” 2021.
- “ISO/IEC/IEEE 24765: International Standard - Systems and software engineering - Vocabulary,” 2017.
- G. Li, B. Liu, and H. Zhang, “Quality Attributes of Trustworthy Artificial Intelligence in Normative Documents and Secondary Studies: A Preliminary Review,” Computer, vol. 56, no. 4, pp. 28–37, Apr. 2023.
- International Organization for Standardization, “ISO/IEC 22989: Information technology — Artificial intelligence — Artificial intelligence concepts and terminology,” 2022.
- Federal Ministry of Labour and Social Affairs, “Act on Corporate Due Diligence Obligations in Supply Chains,” January 2023.
- P. R. Jeroen Naves, “Proposal for standard contractual clauses for the procurement of artificial intelligence (ai) by public organisations,” September 2023.
- N. N. G. d. Andrade and A. Zarra, “Artificial Intelligence Act: A Policy Prototyping Experiment: Operationalizing the Requirements for AI Systems – Part I,” Rochester, NY, Nov. 2022.
- J. Kelly (59 papers)
- L. Heidemann (1 paper)
- J. Zacchi (1 paper)
- D. Espinoza (2 papers)
- N. Mata (1 paper)
- S. Zafar (1 paper)