Privacy, copyright, confidentiality, and hallucinations
Treat four risk domains separately; one general warning is insufficient.
Privacy is about personal data; confidentiality about business information; copyright about protected material; hallucinations about invented or incorrectly linked content. One use case can affect all four.
For each risk, document the scenario, likelihood, impact, prevention, detection, owner and recovery. Pseudonymisation sometimes reduces risk but does not automatically make data anonymous.
Before a real pilot, add a legal starting check: which application, which organisation and role, which people, which data and which consequences? Check the AI Act for prohibited uses, possible high-risk classification and transparency. A product name or low internal risk score does not answer these questions. The provider places the system on the market or puts it into service under its own name; a deployer uses it professionally under its authority. Have any unclear classification assessed before the relevant practical trial.
In Noor’s ordinary text pilot, the customer stays outside the AI chat: a staff member reviews and sends the reply personally. A bot that talks directly to customers is a different application. Article 50 may then require information about the AI interaction. For publication, relevant cases include deepfakes and certain AI texts on matters of public interest; substantive human review and editorial responsibility may provide an exception for those texts. One general label does not automatically cover every situation or provider obligation.
As of 8 September 2026: the AI Omnibus has changed the timeline. Article 50 generally applies from 2 August 2026; certain existing systems have a transition until 2 December 2026 for the provider obligation under Article 50(2). The main rules for high-risk systems in Annex III follow on 2 December 2027, and those for high-risk AI embedded in regulated products in Annex I on 2 August 2028. Use the official timeline for a real starting decision; existing privacy and employment rules remain relevant in the meantime.
- Personal data
- Trade secret
- Usage rights
- Factual error
- Recovery
A quote assistant processes contact data, secret pricing rules, protected source text, and possibly invented terms.
Use a completely fictional description of a process, without real case files, personal data or secrets. Build four risk registers for [use case]: privacy, confidentiality, copyright and incorrect output. Include prevention, detection, ownership and recovery.Analyze one data flow and assign an owner for each risk.
Source for this lesson
European Commission – Transparency under Article 50
Provider and user roles, direct AI interaction, deepfakes and public texts; conditions and exceptions differ.
Checked: 2026-09-08
European Commission – Current AI Act timeline
Application dates following the AI Omnibus, including the limited transitional regime for Article 50(2).
Checked: 2026-09-08
Official Journal – AI Omnibus 2026/1744
Amending regulation; read alongside the AI Act and current official implementation information.
Checked: 2026-09-08