Operationalising AI Ethical Principles in Higher Education with the UNESCO Recommendation on the Ethics of Artificial Intelligence by Policy Makers and Global Universities

Executive summary

The rapid use of artificial intelligence (AI) tools in higher education creates new governance challenges. Universities worldwide face growing concerns about safety, privacy, unfair algorithms and threats to learning process and academic integrity. Without proper governance systems, AI tools’ adoption risks increasing inequalities, reducing learning quality and violating the fundamental rights of students and educators.

The UNESCO’s “Recommendation on the Ethics of Artificial Intelligence” adopted in 2021 represents the first global standard on AI ethics and applies to 194 UNESCO member states. It provides a universal framework of values, principles and actions to guide development and use of AI systems and to protect human rights in the AI era. However, putting these principles into practice requires approaches that reflect the diverse social, cultural and political realities across different countries and institutions.

This policy brief examines AI governance strategies across 16 countries on five continents: South America (Chile, Colombia, Ecuador), Africa (Egypt, Ghana, Kenya, Morocco, Rwanda, South Africa, Tunisia), Asia (China, Kazakhstan, United Arab Emirates), Europe (Sweden,  Latvia) and North America (United States). The analysis maps national regulations and institutional practices against UNESCO’s ten core ethical principles. It shows how governments and higher education institutions are implementing global standards in practice in ways relevant to their local contexts.

This analysis leads to five priority recommendations for policymakers and higher education leaders. First, adopt human rights-based AI frameworks with clearly defined red lines. These should align with international human rights standards and link to higher education institutions accreditation requirements. Second, maintain responsible data governance applying the principle of privacy-by-design. Prohibit unauthorised entry of personal data into third-party tools. Conduct impact assessments for high-risk systems. Third, strengthen human oversight, transparency and accountability. Ensure all important AI decisions undergo human review. Fourth, make AI literacy universal and relevant across all disciplines. Embed ethics, critical thinking and responsible use across all programmes both in technical and non-technical disciplines. Support this with funded educator training programmes. Fifth, conduct ethical procurement and evaluation throughout the AI lifecycle. Contracts should include transparency clauses and provisions to prohibit the use of systems that violate ethical standards.

The ethical deployment of AI tools in higher education demands a multi-level commitment: users must possess adequate understanding of these tools, institutions must establish transparent guidelines and enforce them through monitoring mechanisms, and governments must provide resources for capacity development. This necessitates integrated action combining bottom-up institutional initiatives with top-down government legislation and technical support. Implementation requires coordinated action from policymakers, institutional leaders, administrators, faculty, students and community partners. Shared governance and collaboration across disciplines are essential. 

Background. The adoption of artificial intelligence (AI) tools in higher education is at the forefront of conversations worldwide. Universities have become testbeds for generative AI (GenAI) tools in teaching, research and administration (European Commission, 2022). The growing debate on AI in education spans a continuum from innovation to regulation: at one end, those who advocate rapid implementation of AI tools; at the other, those who raise alarms about the existential risks of AI. In the middle, a third group of voices advocates ethical principles and academic standards for the adoption of AI systems that are fair, safe and inclusive for all higher education stakeholders. 

Drawing on diverse voices of higher education institutions (HEI) leaders and researchers from five continents, this policy brief examines AI governance strategies, policies and practices across 16 countries. At the macro level, we review the most prominent national AI regulations, standards and ethical guidelines informing HEIs governance. At the micro level, some exemplary practices at selected HEIs within each country. Recognising that AI governance reflects the unique local social, cultural and political realities of each country, the cases presented aim to encourage reflection and dialogue on what is relevant and has been adopted across different contexts.  

Problem statement. The rapid adoption of AI systems, especially GenAI tools, in higher education presents complex global challenges. Leaders in HEIs are increasingly confronting the reality of AI-assisted work in classrooms and administrative operations. Applications range from personalised content to meet learners’ needs to tutoring support, enrollment processing and AI-enabled chatbots for student support (European Commission, 2022). 

Rising concerns about safety, disinformation, privacy, bias, the absence of transparency, accountability and human oversight pose challenges for governance, equity and inclusion (UNESCO, 2025).  The use of AI-enabled tools in the classroom is associated with mental health impacts, reduced trust in institutions and overreliance on AI systems, with effects on learning quality and student retention (World Bank, 2025). The use of GenAI tools raises concerns about the authenticity of learners’ work, the erosion of their critical thinking skills, the lack of depth in their learning and the loss of human connectedness (Bozkurt et al., 2024). Broader risks to inclusivity arise when AI tools are trained on data from a narrow set of contexts, which can erase diverse perspectives and reinforce stereotypes rooted in specific geographic regions (Miao and Holmes, 2023). The absence of governance mechanisms to ensure that AI tool selection aligns with educational goals, safety and fairness poses an additional challenge for equity and inclusion (OECD, 2024). 

Policy analysis. The implementation of AI ethics in higher education institutions worldwide is as diverse as the countries in which they are located, the types of HEIs, their constituencies and their socio-economic contexts. While national governments and international organisations are increasingly adopting global policy and ethical frameworks to govern AI (CAIDP, 2026), the implementation of these frameworks into ethical principles, policies and regulations reflects their own governance structures, cultural norms and digital readiness. 

The purpose of this policy brief is to share global examples reflecting on: 

(1) How are policymakers and HEIs leaders operationalising the UNESCO Recommendations on the Ethics of AI? 

(2) How can AI ethics, safety and inclusivity in higher education be both globally informed and locally grounded?  

The 16 countries under study constitute a non-exhaustive sample across diverse continents. The analysis is organised according to the ten core principles of the Recommendation and maps national laws, policies and university guidelines. The analysis also considers actions undertaken by countries or specific HEIs, within Policy Area 8: Education and Research, which underscore commitments to adequate AI literacy to enable individuals to make informed decisions about the use of AI systems (para. 101), development of AI ethics curricula (para. 106), support for AI ethics research (para. 107), training of AI researchers on AI ethics, and ensuring critical evaluation of AI research through independent scientific research (para. 110-111) (UNESCO, 2022).

Principle 1: Proportionality and Do No Harm operationalised as Human Rights-Based Frameworks for Harm Prevention 

The use of AI systems must be proportionate to the legitimate aim, should not infringe on human rights and should be scientifically based and appropriate to the context. Provisions must be in place for rigorous risk assessment to prevent and mitigate harm, with final human determination in irreversible or life-and-death decisions (UNESCO, 2022, para. 25 – 26). Ethical  values  and  principles  can  help  develop  and  implement  rights-based  policy measures and legal norms.  

Risk classification systems were enacted in the “European Union (EU) Artificial Intelligence Act” (EU AI Act), the first legally binding AI regulation globally relevant to the EU member states (European Union, 2024). The use of AI systems in admissions, assessment and student monitoring is classified as high risk, ‘with strict requirements, including risk-mitigation systems, high-quality data sets, logging of activity, detailed documentation, clear user information, human oversight, and a high level of robustness, accuracy and cybersecurity’ (European Commission, 2024, para. 4). 

In Ecuador, the proposed bill  “Proyecto de  Ley Orgánica de Regulación y Promoción de la Inteligencia Artificial en Ecuador” sets out a four-tier AI risk classification system, including a ban on extreme-risk systems and on the processing of personal data for purposes incompatible with human rights. The Bill proposes the requirement for public registries for high-risk AI applications (Asamblea Nacional, 2024). In China, the ”Ethical Norms for the New Generation of Artificial Intelligence” (2021) include requirements for the strengthening of risk monitoring systems, the establishment of user exit and feedback mechanisms (Ministry of Science and Technology of the People’s Republic of China, 2021). 

Principle 2: Safety and Security operationalised as Requirements for Technical Robustness and Contingency Plans

Plans must be in place to prevent and address unwanted harms (safety risks) and vulnerabilities to attacks (security risks) throughout the technology life cycle, thereby establishing sustainable, privacy-protective data frameworks for the training and validation of AI models (UNESCO, 2022, para. 27).

In the EU, high-risk AI systems require technical robustness and resilience plans to prevent harmful or undesirable behaviours that adversely affect fundamental rights. This includes fail-safe plans to interrupt the operation when anomalies exist (EU AI Act, 2024, Art. 15).  In Ecuador, the proposed bill  “Proyecto de  Ley Orgánica de Regulación y Promoción de la Inteligencia Artificial en Ecuador” (Asamblea Nacional, 2024, Art. 4d) includes mandates for rigorous tests, human rights impact assessments and safeguards against unintended use and adverse effects. Morocco’s national cybersecurity strategy requires regular penetration testing and intrusion detection systems to prevent harm from misuse or attacks (Hespress, 2025). In China, the ”Ethical Norms for the New Generation of Artificial Intelligence” requires AI systems to be verifiable, auditable, supervisable, traceable, predictable, trustworthy (Art 12), as well as tasks organisations to research and develop emergency mechanisms and loss compensation plans (Ministry of Science and Technology of the People’s Republic of China, 2021, Art 17). 

Principle 3: Right to Privacy and Data Protection operationalised as Adequate Personal Data Protection Measures

The use of AI systems must align with appropriate data protection and governance mechanisms for the collection, use, sharing, archiving and deletion of personal data.  In education, provisions must be in place to ensure that the use of AI supports learning without the extraction of sensitive information or the misuse, misappropriation or criminal exploitation of data collected in interactions with users (UNESCO 2022, para. 32, 33, 34 and 104). 

In Morocco, the General Secretariat of the Government is reviewing the “Digital X.0”, a draft framework law that will govern AI, data and digital identity, with three core priorities: data governance, digital identity and interoperability (Secrétariat Général du Gouvernement, 2025). Digital X.0 will overhaul the provisions of the existing personal data law09-08 (DGSSI, 2009). In Kazakhstan, the new “AI Law” ‘bans harmful practices such as behavioral manipulation, exploitation of vulnerabilities, emotion recognition without consent, social scoring and illegal data collection’ (Omirgazy, 2025a). In Sweden and Latvia, university policies prohibit uploading personal or copyrighted data to third-party AI tools, in accordance with the General Data Protection Regulation (GDPR) requirements (KTH Royal Institute, 2025a; University of Latvia, 2024/2026).

Principle 4: Multi-stakeholder and Adaptive Governance & Collaboration operationalised as Multi-level Collaborative Governance Approaches and Mechanisms

Diverse stakeholders must be involved in governance of AI throughout the AI system life cycle, including governments, intergovernmental organisations, the technical community, civil society, researchers and academia, media, education, policy-makers, private sector, human rights institutions, anti-discrimination monitoring bodies and groups for youth and children. Measures must be in place to enable meaningful participation by marginalised groups, communities, and individuals, and to respect Indigenous Peoples’ self-governance of their data (UNESCO, 2022, para. 47).

The government of Kazakhstan engaged 13 state bodies in developing the first “AI law” to ensure the safe, transparent and ethical use of AI (Omarova, 2025). In Ecuador, the Ministry of Information and Telecommunications (MINTEL) proposed the creation of a collegiate entity with multisectoral representation and administrative independence to govern decisions on AI capability, data management and competitiveness (Albornoz & Gualavisi, 2025). In Morocco, in preparation for the “Draft Law 59.24 on Higher Education and Research”, the Ministry of Higher Education involved universities, research centres, regulatory bodies and NGOs in a coordinated, participatory, and flexible oversight of technology and the broader research ecosystem (Islah, 2025). The University of Los Andes and the Externado University in Colombia host multi-stakeholder roundtables on AI regulation with the participation of academia, civil society and government (University de los Andes, 2025). 

Principle 5: Responsibility and Accountability operationalised as Accountability and Liability Guidelines

The ethical responsibility and liability for decisions and actions based on an AI system should ultimately be attributable to AI actors, in proportion to their roles in the AI system’s lifecycle (UNESCO, 2022, para. 42). Oversight, impact assessments, audit, due diligence, and whistleblower protections must be in place to ensure accountability (para. 43). In learning, strict requirements for monitoring, assessing abilities and predicting learners’ behaviours must be in place (para. 104). Rigorous, independent, multidisciplinary scientific research must ensure a critical evaluation of AI research and proper monitoring of potential misuses or adverse effects (para. 110).

In China, the ”Ethical Norms for the New Generation of Artificial Intelligence”  prescribe that humans are the ultimately responsible entities and must ‘comprehensively heighten awareness of responsibility, and exercise self-reflection and self-discipline at every stage of the AI life cycle’ (Ministry of Science and Technology of the People’s Republic of China, 2021, Art. 3). In the UAE,  theCharter for the Development and Use of Artificial Intelligence(2024) defines accountability as a policy objective and the UAE International Stance on AI Policy (2024) emphasises the need for accountability mechanisms to address any potential violations in AI use (priority 2). 

In Kenya, Aga Khan University established GenAI guidelines to guide the transparent and responsible integration of AI tools into academic and administrative processes (Aga Khan University, 2023). In Kazakhstan, Nazarbayev University establishes the levels of responsibility for the integration of GenAI into learning and teaching, including response, position, acceptable use statements, dissemination, supervision and reporting (Nazarbayev University, 2023). In Latvia, the Guidelines for the Use of AI in the University of Latvia(2024, updated in 2026) define that authors of AI-assisted work ‘still are and remain responsible for the originality of content, truthfulness of the facts and validity of the statements’ (p. 8). In Colombia, Universidad de los Andes states that users bear the ‘responsibility to verify the pertinence, accuracy and veracity of the material generated by GenAI’ (Universidad de los Andes, 2024, section 2.2.1). 

Principle 6: Transparency and Explainability operationalised as Mandatory Disclosure and Contestability Frameworks

AI actors must ensure transparency and explainability as fundamental requirements for accountability and governance. AI systems must operate in ways that are traceable and understandable to those they affect, with disclosure of when and how systems are used, and with provisions to challenge decisions and outcomes that affect their safety or human rights (UNESCO, 2022, para. 37 – 41).

In China, the ”Ethical Norms for the New Generation of Artificial Intelligence” establish the obligation to improve transparency, explainability, understandability in the design, implementation and application of algorithms (Ministry of Science and Technology of the People’s Republic of China, 2021, Art. 12). In Morocco, AI processing of personal data is governed by the “Data Protection Law 09-08”  (CNDP, 2009) which grants citizens the right to seek recourse against automated decisions. CNDP holds hearings with scientific organisations to advance the implementation of the law (CNDP, 2025). 

In Kazakhstan, the guidelines of “Nazarbayev University’s Response to Generative Artificial Intelligence in Learning and Teaching” request faculty and students to disclose the use of AI tools and their details in the design, delivery and assessment of courses, as well as assignment completion (Nazarbayev University, 2023). In Sweden, KTH Royal Institute’s “GenAI Guidelines for studying with GenAI” encourage students to be transparent in whether, how and why students use the AI tools (KTH Royal Institute, 2025a). 

Principle 7: Human Oversight and Determination operationalised as Non-Negotiable Human Determination

Human oversight requires the attribution of ethical and legal responsibility at any stage of the AI lifecycle, as well as the provision of remedies to physical persons or existing legal entities. In cases where humans decide to rely on AI systems for efficacy, the decision to cede control remains with humans. AI systems can never replace ultimate human responsibility and accountability. Life-and-death decisions should not be ceded to AI systems (UNESCO, 2022, para. 35-36).

In the UAE, the “Charter for the Development and Use of AI” (2024) protects the ‘irreplaceable value of human judgment and human oversight over AI to correct any errors or biases that may arise’ (Principle 6). In China, the ”Ethical Norms for the New Generation of Artificial Intelligence” (2021) stipulate the principle of ‘strengthening responsibility’, whereby humans are the ultimate responsible party and should not avoid accountability review or evade responsibilities (Ministry of Science and Technology of the People’s Republic of China, 2021, Art 3). 

In Sweden, the “GenAI Guidelines for studying with GenAI” purposes at KTH Royal Institute establish the ‘human-in-the-loop’ principle whereby students are ‘responsible for all decisions and assessments of what is appropriate and correct’ (KTH Royal Institute, 2025a, Guideline 3), as well as human educators should be the final decision makers about the AI systems used in educational institutions (Jonkoping University, 2023).

Principle 8: Sustainability operationalised as Sustainable Development Goals (SDG) Alignment 

Continuous assessments of the human, social, cultural, economic and environmental impacts of AI technology must be in place, aligned with the evolving goals of the Sustainable Development Goals (SDGs) (UNESCO 2022, para. 31). Data, energy and resource-efficient AI methods must be prioritised. Should there be disproportionate “negative impacts on the environment, AI should not be used” (para. 86). Rigorous and independent scientific research that incorporates interdisciplinary perspectives beyond science, technology, engineering and mathematics must be ensured (UNESCO, 2022, para. 110). 

In Sweden, the KTH Royal Institute (2025b) provides resources on the energy consumption and ecological footprint of generative AI. In China, the discussion of AI and SDGs is active through academic research projects, conferences and reports (The Chinese University of Hong Kong, Shenzhen, n.d.). In Colombia, the guidelines for the use of generative AI (“Lineamientos para el uso de inteligencia artificial generativa (IAG)”) at the University de los Andes stipulate that the use of GenAI must be coherent with and contribute to the SDGs (Universidad de los Andes, 2024)

Principle 9: AI Awareness and Literacy operationalised as Transdisciplinary AI Literacy Initiatives

Governments, academia, civil society, media and the private sector must work jointly on accessible education, civic engagement and AI literacy initiatives so that members of society can make informed decisions and be protected from the undue influence of AI systems (para. 44). Learning must focus on the impact of AI on human rights and access to rights, as well as on the environment and ecosystems (para. 45). Pre-requisite skills for AI education must include an AI ethics curriculum (para. 101-102), aligned with national education programmes and traditions, developed in local and indigenous languages and accessible to persons with disabilities (para. 106) (UNESCO, 2022).

The “EU AI Act” requires AI literacy for providers and deployers (European Union, 2024, Art. 4). In the UAE, the Charter for Development and Use of AI” (2024) stipulates as one of the priorities and key components the promotion of AI awareness (p. 11). In Morocco, “National Strategy “Digital Morocco 2030” invites scientists to ‘engage in multidisciplinary research (digital, legal, sociological, etc.) to reflect on the development of Al and its impact on society’, as well as ‘include digital education as early as primary school’ (Ministry of Digital Transition and Administrative Reform, Morocco, 2024, p. 12 – 13). The UAE Education, Human Development, and Community Development Council established a compulsory AI curriculum across K-12, with 25% of the content devoted to AI ethics (Rasheed, 2025).   Kazakhstan is integrating AI into national curricula at multiple levels (Omirgazy, 2025b). In Rwanda, the National AI Policy includes 21st-century skills and high-level literacy as enablers of the strategy (Republic of Rwanda, Ministry of ICT and Innovation, 2022). Public AI literacy is a key element of Kenya’s national AI strategy (Kenya AI Strategy 2025 – 2030). 

Tsinghua University in China launched an internal AI Literacy website that focuses on the fundamentals and applications of generative AI in teaching and learning, with a dedicated section on the “Responsible Use of Generative AI” with key principles for academic and ethical practice (Tsinghua University, 2025). In the United States, the State Council for Higher Education in Virginia (SCHEV) awarded a grant to a consortium led by Virginia State University, a historically Black institution, Northern Virginia Community College, a major community college, and Brightpoint Community College, to expand AI instruction in dual-enrollment and transfer-pathway programmes. The programme includes AI micro-credentials for professional advancement and open educational resources for wider use across the state’s higher education sector (Northern Virginia Community College, 2025; Virginia State University, 2025). 

Principle 10: Fairness and Non-Discrimination Operationalised as Ex-ante Human Rights Impact Assessments and Remediation

AI actors must promote social justice and safeguard fairness and non-discrimination in line with international law. Inclusive approaches in AI development must consider the specific needs of diverse constituencies to the benefits of AI, regardless of race, colour, gender, age, disability or other grounds. AI actors must make all reasonable efforts to minimise and avoid reinforcing discriminatory or biased applications and outcomes and ensure effective remedies against algorithmic harms (UNESCO, 2022, para. 28-30).

The “African Union Continental Strategy” includes plans for legal protection against algorithmic bias and discrimination, including the need to ‘compensate for bias and discrimination’ (p. 21-22). Member States committed to develop and roll-out AI assessments including the UNESCO Ethical Impact Assessment (EIA) (African Union, Continental AI Strategy, 2024). In Ecuador, the draft bill “Proyecto de  Ley Orgánica de Regulación y Promoción de la Inteligencia Artificial en Ecuador”, proposes the prohibition of algorithmic discrimination against vulnerable groups and historically disadvantaged groups (Asamblea Nacional, 2024, Art. 4b and 29). In Morocco, ethical risk-assessment mechanisms aligned with the UNESCO Recommendation and the “EU AI Act”, will be part of the national AI roadmap announced by the Ministry of Digital Transition and Administrative Reform (Amer, 2025).

Ethical impact assessments are recommended by the University of Latvia, before the adoption of AI-enabled products, to protect users against manipulation and embedded biases (University of Latvia, 2024/2026). In the United States, the Center for Responsible AI (CRAI) at Virginia State University, focuses on the ethical adoption of AI to ensure that ‘AI amplifies opportunity and inclusion, not division’ (n.d.). 

Recommendations

Building on the policy analysis above, in this section we offer five recommendations for policymakers and higher education stakeholders. They are grounded in the Recommendation. The aim is to translate high-profile principles into practice with consideration that ethical AI in higher education has to be both globally informed and locally relevant.

1) Adopt human rights-based AI frameworks with clearly defined red lines. We encourage policymakers to align national or regional frameworks with international human rights standards, and universities to provide clear guidance on the classification of the educational uses of AI tools according to levels of risk. Higher education stakeholders can implement this through institutional risk registers, ethical impact assessments and responsible procurement processes. It is important to ensure that no AI system is adopted without adequate human oversight or harm prevention mechanisms. These measures should be linked to HEIs accreditation standards and public reporting requirements. Universities can look for existing templates and guidance for institutional self-assessment for responsible AI adoption (AI Policy Lab, Umea University, 2025; UNESCO, 2023).

2) Maintain responsible data governance and privacy by design. Protecting personal and sensitive information must be a non-negotiable foundation of any ethical AI policy in higher education. Policymakers should update national privacy guidance for education. It should guarantee that the privacy protection mechanisms go beyond legal compliance. Universities should prohibit the entry of personal or copyrighted data into third-party AI tools unless approved and secure. They should also carry out data protection impact assessments for high-risk AI systems used in teaching, assessment and administrative functions. Additionally, HEIs need to promote secure internal tools, train staff and students on privacy and maintain transparency on how data are collected, stored and deleted. 

3) Reinforce human oversight, transparency and accountability. All high-stakes AI-assisted decisions, including admissions, grading or disciplinary procedures should be subject to human review. Students and staff must be informed when AI tools are used and have the right to contest and request explanations for decisions affecting them. Institutions can lead by example of transparency by publishing databases of the AI systems they use, including information about their purpose, model design and safeguards. 

4) Make digital literacy, including AI literacy, universal and contextual across disciplines. AI literacy should not be limited to computer science but embedded in all programmes with an emphasis on critical thinking, ethics, data protection and the psychological effects of AI on learning and mental health. This requires coordinated policy support to fund educator training, micro-credentials and professional development programmes. Universities should design curricula that integrate AI ethics and responsible innovation into existing courses. It is important to stimulate educational stakeholders to learn to question, interpret and responsibly use AI outputs. 

5) Conduct ethical procurement and evaluation of AI systems throughout the AI lifecycle. Procurement offices should act as gatekeepers of trustworthy AI systems, conducting ethical impact assessments before purchase and throughout the use (Hickok, 2024; UNESCO, 2023). Contracts with AI vendors should include transparency, access and termination clauses. It is important that institutions can discontinue systems that no longer meet ethical standards or where human oversight is impossible. National and regional policymakers can strengthen this process by tying funding and accreditation to proof of ethical procurement and periodic evaluation.

Conclusion

AI tools in higher education cannot be ethical unless users understand how to use them, institutions set clear expectations (guidelines), enforce and monitor them, as well as governments support capacity building in educational settings. This requires both top-down (government legislation and technical support) and bottom-up (institutional action) approaches. For example, using ethical impact assessments before purchasing AI tools, as well as shared agency among faculty, administrators, students and community partners. Ethical AI in higher education must be inclusive, adaptive and globally informed, but locally grounded.

Acknowledgements. This policy brief was produced under the United Nations Higher Education Sustainability Initiative (HESI) as part of the Implementation Group (IG) on “AI Ethics, Safety, and Inclusivity in Higher Education”. The authors appreciate the support of Ms Arianna Valentini and Lily Liu Bosen. The research findings in this policy brief reflect the work of the authors named above. They do not represent the opinion or position of any other organisation, including the United Nations. 

 

References

African Union. 2024, July 20. Continental Artificial Intelligence Strategy. Harnessing AI for Africa’s Development and Prosperity. Available at: https://au.int/sites/default/files/documents/44004-doc-EN-_Continental_AI_Strategy_July_2024.pdf (Accessed: 19 December 2025)

‌Aga Khan University. 2023. The Use of Generative AI in Higher Education at AKU (Draft Guidelines). (n.d.). Available at: https://www.aku.edu/admissions/Documents/policy-use-of-generative-ai.pdf (Accessed: 19 December 2025)

Albornoz, M. B. and Gualavisi, A. Dictamen Técnico sobre la Política Gubernamental aprobada por MINTEL. [Technical Assessment about the Government Policy approved by MINTEL]. Available at: https://unesdoc.unesco.org/ark:/48223/pf0000394822 (in Spanish) (Accessed: 20 December 2025)

Amer, O. M. 2025, Dec. Morocco Accelerates AI Strategy with New Regulations, JAZARI Institutes and Sovereign Cloud Push. Available at https://www.moroccoworldnews.com/2025/12/271574/morocco-accelerates-ai-strategy-with-new-regulations-jazari-institutes-and-sovereign-cloud-push (Accessed: 6 January 2026) 

American Association of University Professors (AAUP). 2025. Artificial Intelligence and Academic Professions. Available at https://www.aaup.org/reports-publications/aaup-policies-reports/topical-reports/artificial-intelligence-and-academic (Accessed: 8 October 2025)

Asamblea Nacional República del Ecuador. 2024, June 20. Proyecto de Ley Orgánica de Regulación y Promoción de la IA en Ecuador. [Draft Organic Law for the Regulation and Promotion of AI in Ecuador]. Available at: https://www.asambleanacional.gob.ec/ (in Spanish) (Accessed: 19 December 2025)

Bozkurt, A., Xiao, J., Farrow, R., Bai, J.Y., Nerantzi, C., Moore, S., Dron, J., Stracke, C.M., Singh, L., Crompton, H. Koutropoulos, A. and others. 2024. The manifesto for teaching and learning in a time of generative AI: A critical collective stance to better navigate the future. Open Praxis, Vol. 16, No. 4, pp. 487-513. https://search.informit.org/doi/pdf/10.3316/informit.T2025011300014191575969861

Center for AI & Digital Policy (CAIDP). 2026. AI and Democratic Values (CAIDP Index) 2026. Available at https://www.caidp.org/reports/caidp-index-2026/ (Accessed: 17 August 2026)

Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP). 2025. Communiqué : IA et protection des données à caractère personnel. Available at: https://www.cndp.ma/wp-content/uploads/2025/03/CNDP-Communique-IA-et-protection-des-donnees-a-caractere-personnel-FR.pdf (in French) (Accessed: 19 December 2025)

Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP). 2009. Loi n° 09-08 relative à la protection des personnes physiques à l’égard du traitement des données à caractère personnel [Law No. 09-08 relating to the protection of natural persons with regard to the processing of personal data.]. Available at https://www.cndp.ma/loi-09-08/ (in French) (Accessed: 19 December 2025)

General Directorate of Information Systems Security (DGSSI). 2009. Loi n° 09-08 relative à la protection des personnes physiques à l’égard du traitement des données à caractère personnel [Law No. 09-08 relating to the protection of natural persons with regard to the processing of personal data]. Available at: https://www.dgssi.gov.ma/fr/loi-09-08-relative-la-protection-des-personnes-physiques-legard-du-traitement-des  (in French) (Accessed: 19 December 2025)

Government of the UAE. 2024, June 10. UAE Charter for the Development and Use of Artificial Intelligence. UAE Legislation. Available at: https://uaelegislation.gov.ae/en/policy/details/the-uae-charter-for-the-development-and-use-of-artificial-intelligence (Accessed: 19 December 2025)

Government of the UAE. 2024, September 2. UAE’s International Stance on Artificial Intelligence Policy. UAE Legislation. Available at: https://uaelegislation.gov.ae/en/policy/details/uae-s-international-stance-on-artificial-intelligence-policy (Accessed: 19 December 2025)

Grūzītis, N., Skadiņa, I., Baranova, S. and Nerenberga, J.  Updated in 2026, January. The Guidelines for the Use of Artificial Intelligence at the University of Latvia.  University of Latvia. Available at: https://www.lu.lv/fileadmin/user_upload/LU.LV/www.lu.lv/Studijas/guidelines_for_
AI_use_at_UL_study_process_2026.pdf
(Accessed: 17 August 2026)

Hespress. 2025, April 29. Morocco doubles down on cybersecurity and AI as digital push gains speed. Available at: https://en.hespress.com/109307-morocco-doubles-down-on-cybersecurity-and-ai-as-digital-push-gains-speed.html  (Accessed: 19 December 2025)

Hickok, M. 2024. Public procurement of artificial intelligence systems: new risks and future proofing. AI & Society, Vol. 39, No. 3, pp.1213-1227. https://link.springer.com/article/10.1007/s00146-022-01572-2 

European Commission, Directorate-General for Education, Youth, Sport and Culture. 2022. Ethical guidelines on the use of artificial intelligence (AI) and data in teaching and learning for educators. Publications Office of the European Union. Available at: https://data.europa.eu/doi/10.2766/153756 (Accessed: 15 October 2025)

European Commission. 2024. European Artificial Intelligence Act comes into force. Available at: https://ec.europa.eu/commission/presscorner/detail/en/ip_24_4123 (Accessed: 15 October 2025)

European Union. 2024. ‌ Artificial Intelligence Act (Regulation (EU) 2024/1689), Official Journal of the European Union. Version of 13 June 2024. Interinstitutional File: 2021/0106(COD). Available at: https://eur-lex.europa.eu/eli/reg/2024/1689/oj  (Accessed: 19 December 2025)

Islah, S. 2025. Enseignement supérieur : El Midaoui fait le point sur les nouveautés, les chantiers et les défis de l’Université. [Higher education: El Midaoui provides an update on the latest developments, projects, and challenges facing the University].  Le Matin. Available at: https://lematin.ma/enseignement/nouveautes-2025-2026-de-lenseignement-superieur/314556 (in French) (Accessed: 19 December 2025)

Jonkoping University, 2023, June 19. Artificial Intelligence Ethical Guidelines. Available at: https://ju.se/portal/educate/en/guides/artificial-intelligence/ethical-guidelines.html  (Accessed: 19 December 2025)

Kenya Ministry of Information, Communications and the Digital Economy. 2025, March. Kenya AI Strategy 2025 – 2030. Available at: https://ict.go.ke/sites/default/files/2025-03/Kenya%20AI%20Strategy%202025%20-%202030.pdf (Accessed: 19 December 2025)

Kingdom of Morocco. Ministry of Digital Transition and Administrative Reform (MMSP). 2024. National StartegyDigital Morocco 2030”. Available at: https://www.mmsp.gov.ma/sites/default/files/2024-09/PlaquetteInstitutionnel_18092024_Ang.pdf (Accessed: 19 December 2025)

KTH Royal Institute of Technology. 2025a, June 24. Considerations for studying with generative AI. Available at: https://www.kth.se/en/student/studier/kurs/generativ-ai/avvagningar-1.1410997 (Accessed: 19 December 2025)

KTH Royal Institute of Technology. 2026, July 17. Generative AI in higher education. Available at: https://intra.kth.se/en/utbildning/systemstod/generativ-ai/oversikt-1.1253698  (Accessed: 17 August 2026)

KTH Royal Institute of Technology. 2025b, April 10. AI and Sustainability- Towards a Fair Future. Documentation from Lunch’n’ Learn. Available at: https://intra.kth.se/en/utbildning/e-larande/e-larande-nyheter/ai-och-hallbarhet-mot-en-rattvis-framtid-1.1398761 (Accessed: 22 December 2025)

Miao, F. and Holmes, W. 2023. Guidance for generative AI in education and research. UNESCO.  Available at: https://unesdoc.unesco.org/ark:/48223/pf0000386693  (Accessed: 19 December 2025)

‌Ministry of Science and Technology of the People’s Republic of China. 2021. 《新一代人工智能伦理规范》发布. [Ethical Norms for the New Generation of Artificial Intelligence].  Available at:  http://www.most.gov.cn/kjbgz/202109/t20210926_177063.html  (in Chinese Mandarin) (Accessed: 19 December 2025)

Nazarbayev University. Nazarbayev University’s Response to Generative Artificial Intelligence in Learning and Teaching. 2023. The Center of Innovation in Learning and Teaching Office of the Provost. Available at: https://regulations.nu.edu.kz/bitstream/123456789/1030/1/NU%20Response%20to%20
Integrating%20Generative%20AI%20into%20Learning%20%26%20Teaching.pdf#page=3.08

(Accessed: 19 December 2025)

Northern Virginia Community College (NOVA). 2025, February 21. NOVA Collaborates on Computer Science Pathway with an AI Focus. Available at: https://www.nvcc.edu/about/news/featured-articles/2025/AI-grant-computer-science.html (Accessed: 19 December 2025)

OECD. 2024. The Potential Impact of Artificial Intelligence on Equity and Inclusion in Education. OECD Artificial Intelligence Papers. No. 23. Available at: https://www.oecd.org/content/dam/oecd/en/publications/reports/2024/08/the-potential-impact-of-artificial-intelligence-on-equity-and-inclusion-in-education_0d7e9e00/15df715b-en.pdf (Accessed: 15 November 2025)

Omarova, Z. 2025, April 8. Kazakhstan Seeks to Attract 10,000 AI Specialists Annually. The Astana Times. Available at: https://astanatimes.com/2025/04/kazakhstan-seeks-to-attract-10000-ai-specialists-annually/ (Accessed: 19 December 2025)

Omirgazy, D. 2025a, November 17. Kazakhstan Adopts Central Asia’s First AI Law. The Astana Times. Available at: https://astanatimes.com/2025/11/kazakhstan-adopts-central-asias-first-ai-law/ (Accessed: 19 December 2025)

Omirgazy, D. 2025b, September 18. Kazakhstan Establishes National Standards for Artificial Intelligence in Education. Available at: https://astanatimes.com/2025/09/kazakhstan-establishes-national-standards-for-artificial-intelligence-in-education (Accessed: 19 December 2025)

Rasheed, A. 2025, August 23. UAE schools to introduce AI curriculum in new academic year. Available at: https://gulfnews.com/uae/education/uae-schools-to-introduce-ai-curriculum-in-new-academic-year-1.500242831 (Accessed: 19 December 2025)

Republic of Rwanda. Ministry of ICT & Innovation (MICT). 2022. The National AI Policy. Available at: https://www.minict.gov.rw/fileadmin/user_upload/minict_user_upload/Documents/Policies/
Artificial_Intelligence_Policy.pdf
(Accessed: 19 December 2025)

Riga Stradins University. 2024. Artificial Intelligence in Higher Education Guidelines [English version]. Available at: https://www.rsu.lv/en/artificial-intelligence-higher-education  (Accessed: 19 December 2025) 

Secrétariat Général du Gouvernement (SGG). 2025, November 8. Journal de la semaine du 03 novembre 2025: Actualités nationales du numérique [Journal of the week of November 3, 2025: National digital news]. Available at: https://www.sgg.gov.ma/Portals/1/veille_juridique/actualite_numerique/aj_03112025.pdf (Accessed: 19 December 2025)

‌The Chinese University of Hong Kong in Shenzhen (n.d.). AI与可持续发展展望. [AI and Sustainable Development Outlook]. Available at: https://www.zhaojunhua.org/reports/AI_SUSTAINABLE_DEVELOPMENT_OUTLOOK_ZH.pdf (in Chinese Mandarin) (Accessed: 19 December 2025)

Titareva T., Tucker J., Carli R., Movchan V., Dignum V. 2026. Question Zero: Why Responsible AI Begins Before AI Adoption. AI Policy Exchange Forum (AIPEX). Available at: https://aipolicylab.se/aipex-contributions/question-zero-why-responsible-ai-begins-before-ai-adoption/ (Accessed: 17 August 2026)

Tsignhua University. 2025. Responsible Use of Generative AI. Available at: https://yuketang.tsinghua.edu.cn/ai/learning-center?selectNodeIds=60876,60878 (for internal use only). (Accessed: 19 December 2025)

UNESCO (n.d.). A human rights approach to AI. Ten core principles lay out a human-rights-centred approach to the Ethics of AI. Available at: https://www.unesco.org/en/artificial-intelligence/recommendation-ethics (Accessed: 19 December 2025)

UNESCO. 2022. Recommendation on the Ethics of Artificial Intelligence. Available at: https://unesdoc.unesco.org/ark:/48223/pf0000381137 (Accessed: 19 December 2025)

UNESCO. 2023. Ethical impact assessment: a tool of the Recommendation on the Ethics of Artificial Intelligence. Available at:  https://unesdoc.unesco.org/ark:/48223/pf0000386276 (Accessed: 19 December 2025)

UNESCO. 2025. AI and Education: Protecting the Rights of Learners. Available at: https://unesdoc.unesco.org/ark:/48223/pf0000395373 (Accessed: 19 December 2025)

Universidad de los Andes. 2024, October. Lineamientos para el uso de inteligencia artificial generativa (IAG) en la Universidad de los Andes. [Guidelines for the use of generative artificial intelligence (GAI) at the University of the Andes]. Available at: https://secretariageneral.uniandes.edu.co/images/documents/lineamientos-uso-inteligencia-artificial-generativa-IAG-uniandes.pdf (in Spanish) (Accessed: 19 December 2025)

Universidad de los Andes. 2025, August. El futuro del trabajo en Colombia en la era de la IA: hallazgos de la décima mesa multiactor sobre regulación de la IA. [Future of Work in Colombia in the AI era. Findings of the 10th Multi-stakeholder roundtable about AI regulation]. Available at: https://gobierno.uniandes.edu.co/el-futuro-del-trabajo-en-colombia-en-la-era-de-la-ia-hallazgos-de-la-decima-mesa-multiactor-sobre-regulacion-de-la-ia/ (Accessed: 19 December 2025)

Virginia State University (VSU). 2025, September 30. Virginia State University Awarded $2 Million Grant From Thurgood Marshall College Fund For AI-Enabled Digital Transformation.  Available at: https://www.vsu.edu/news/2025/vsu-awarded-tmcf-ai.php (Accessed: 19 December 2025)

Virginia State University. (n.d.). Center for Responsible AI (CRAI). Available at https://www.vsu.edu/about/leadership/vp-for-academic-affairs/crai/ (Accessed: 20 December 2025)

World Bank (2024). Global Trends in AI Governance. Available at: https://documents1.worldbank.org/curated/en/099120224205026271/pdf/P1786161ad76ca0ae
1ba3b1558ca4ff88ba.pdf
(Accessed: 19 December 2025)

 

Rethinking the Digital Omnibus’ Impact on the EU AI Act: Simplification or Dilution? 

Introduction

The adoption of the European Union AI Act (hereafter AI Act) marks a milestone in the union’s ambition to shape trustworthy, human-centric artificial intelligence (AI). It reflects an effort to ground innovation in fundamental human rights – an approach that has positioned the EU as a global standard-setter in digital regulation. The proposed Digital Omnibus represents an effort to streamline and harmonise an increasingly complex regulatory landscape. 

However, as the Digital Omnibus Regulation Proposal directly affects the implementation of the AI Act and related data governance frameworks, it raises a number of critical cross-cutting concerns. In particular, certain simplification measures – introduced with the intention to reduce administrative burdens, facilitate compliance procedures, and improve regulatory coherence – may have unintended consequences on the consistency, traceability, and risk-sensitivity of the EU’s digital regulatory ecosystem. These include potential reductions in the consistency of regulatory application, limitations in the traceability of data and AI systems, and a weakening of the granularity required for effective risk assessment within the EU’s digital framework. Moreover, while these measures are designed to ease obligations for AI providers and developers, they may have the effect of shifting complexity downstream onto deployers and end-users. This could result in increased uncertainty for those responsible for the use of AI systems in practice, particularly in high-risk contexts where clear allocation of responsibilities and robust risk assessment remain essential. 

These interactions are especially relevant where data processing rules, access to large-scale datasets, and incident reporting mechanisms intersect with the criteria used to assess and classify high-risk AI systems. Ensuring that these instruments remain coherent in their application is therefore essential to preserving both the safeguards and the credibility of the EU’s risk-based approach. 

In this context, the AI Policy Lab at Umeå University seeks to contribute constructively to the ongoing discussion by highlighting specific areas of concern and putting forward targeted recommendations. The main objective is to ensure that the EU’s regulatory ecosystem remains both effective and future-proof. 

1. Amendments to the GDPR for AI training, Article 3 of the Digital Omnibus proposal 

The Digital Omnibus proposal introduces clarifications regarding the legal bases and conditions under which personal data may be processed for the development and training of AI systems. In particular, it elaborates on the use of legitimate interest as a legal basis and introduces specific derogations for the processing of special categories of data (i.e., sensitive data such as health, biometric, or political information). 

While these changes primarily concern data protection law, they have indirect but significant implications for the application of the AI Act – especially Article 6, which governs the classification of high-risk AI systems. This is due to the fact that the scope, nature, and volume of data used in training are key elements in assessing the risks associated with AI systems. 

Several aspects of the proposal may inadvertently weaken the link between data governance and AI risk classification: 

  • The introduction of derogations for the processing of so-called “residual” sensitive data during model training (§33) risks expanding the volume of sensitive data that can be used without prior scrutiny. This could reduce the ability of regulators to accurately assess whether an AI system should be classified as high-risk under Article 6 of the AI Act. 
  • The broadening of legal bases for data processing in the context of AI training (§§30-31) may weaken the connection between the actual risks posed by a system and its regulatory classification, particularly in the absence of coordinated interpretative guidelines between data protection authorities – such as the European Data Protection Board (henceforth EDPB) – and AI governance bodies – such as the AI Office. 
  • The simplification of transparency obligations, including information notices and Data Protection Impact Assessments (henceforth DPIAs) (§36, §40), may reduce the level of detail available to regulators. This, in turn, could hinder a proper assessment of whether a system meets the criteria for high-risk classification. 

Our Recommendations: 

  1. Introduce a specific notification requirement for AI models trained using the “residual sensitive data” exemption (§33) to preserve traceability of training datasets and support risk classification under the AI Act.    
  2. Provide a DPIA section dedicated to AI systems. This could help preventing the simplification of DPIA (single EU lists) from reducing the granularity necessary to assess AI risk.  

2. Prevent the merger of the Data Act, Digital Governance Act, and Open Data Act from creating “shortcuts” for high-risk AI systems 

The Digital Omnibus seeks to consolidate several existing legislative instruments – the Data Act, the Data Governance Act (henceforth DGA), and the Open Data Directive – into a single, more coherent framework governing access to and reuse of data, including data held by public authorities. This consolidation is intended to facilitate access to large datasets, including non-personal data, and to promote data sharing across sectors. While this can significantly support innovation and the development of AI systems, it may also have implications for how such systems are classified under the AI Act. Among these, it is important to highlight the following:  

  • Easier access to large volumes of data – including datasets that can be combined or enriched – risks enabling the development of AI systems whose purpose or context of use would place them within the scope of Article 6 of the AI Act (high-risk AI systems).  
  • There is a risk that the simplification of data access mechanisms could be interpreted, in practice, as a justification for lowering the perceived risk level of such systems. In other words, increased data availability risks inadvertently being used as an argument to downgrade regulatory scrutiny.  

Our Recommendations: 

  1. Clearly establish that simplified access to data does not affect the criteria for high-risk classification under the AI Act. The availability of data should not be considered a mitigating factor in the assessment of risk. 
  2. Introduce an ex ante assessment requirement for cases where public or publicly accessible data is reused for AI systems that are likely to operate in high-risk domains (such as employment, education, healthcare, or access to essential services). 
  3. Require public administrations, when authorising the reuse of data for AI development, to explicitly indicate whether the intended use is likely to fall within the scope of Article 6 of the AI Act. This would provide greater legal clarity for developers and strengthen regulatory consistency.  

3. Single-entry point for incident reporting (Article 6 and 9 of the Digital Omnibus proposal) 

The proposal to establish a single European entry point for incident reporting constitutes a significant step towards simplifying and harmonising reporting obligations across multiple regulatory frameworks, including NIS2 (cybersecurity), GDPR (data protection), DORA (financial sector resilience), eIDAS (digital identity), and the Critical Entities Resilience (CER) Directive. By centralising notifications through a platform managed at the EU level – specifically by the European Union Agency for Cybersecurity (ENISA) – the proposal aims to reduce administrative burdens for operators and improve the efficiency of information sharing across authorities. 

However, the centralisation of notifications on a single platform managed by ENISA raises some critical issues that deserve careful consideration (in order to ensure the effectiveness of the system and the protection of operators subject to reporting obligations):  

  • Expanding ENISA’s mandate to manage a unified reporting platform may lead to capacity constraints, given the anticipated volume of notifications. Any delays in processing or triaging reports could negatively affect incident response times and overall system resilience. 
  • The single-entry point is designed as a hub rather than a replacement for Member States’ national competent authorities. However, without seamless technical and procedural interoperability with existing national systems, there is a risk of duplication, inefficiencies, or increased administrative complexity.  
  • The proposal does not sufficiently clarify the allocation of responsibilities between operators, ENISA, and national authorities in cases of system malfunction, delays, or errors. This lack of clarity risks exposing operators to legal consequences for circumstances beyond their control.  
  • The centralisation of incident-related data at the EU level also raises questions regarding data governance and technological sovereignty. In the absence of clear guarantees on data localisation, secure infrastructure, and Member State oversight, there is a risk that sensitive operational information – potentially critical for national security – may be insufficiently protected or subject to dependencies on non-EU technological backbones. 

Our Recommendations: 

  1. Establish an independent annual audit mechanism to assess the functioning of the single-entry point. This audit should evaluate: (i) the system’s capacity to handle notification volumes, (ii) the timeliness and accuracy of information processing, (iii) the cybersecurity of the platform, and (iv) its level of interoperability with national systems. Such an audit would help to ensure transparency, reliability and continuous improvement of the system. 
  2. Introduce a mandatory fallback protocol to be activated in the event of technical unavailability. This should include: (i) alternative reporting channels, (ii) clear criteria for demonstrating compliance efforts by operators, and (iii) automatic suspension of notification deadlines during system outages. This would prevent operators from incurring violations due to circumstances beyond their control.  
  3. Clarify the liability framework by explicitly defining the division of responsibilities between ENISA, national authorities, and reporting entities. This should specify: (i) situations in which failures are attributable to the central system, (ii) the implications for operators’ legal obligations, and (iii) the safeguards available in cases of technical malfunction. Clear and predictable rules are essential to ensure legal certainty and the consistent application of reporting obligations across the European Union. 
  4. Introduce explicit requirements ensuring that the infrastructure supporting the single-entry point is based on secure, EU-controlled technological backbones, with clear provisions on data localisation, access control, and Member States’ oversight. This could include, for instance, reliance on trusted European cloud frameworks or “no non-EU backbone” requirements for particularly sensitive categories of incident data. Such safeguards would strengthen trust in AI systems and ensure alignment with broader EU objectives on digital sovereignty. 

Conclusion 

Overall, the Digital Omnibus proposal reflects a necessary and timely effort to streamline an increasingly complex regulatory framework and to facilitate its practical implementation across sectors. At the same time, the analysis above highlights the importance of maintaining a careful balance between simplification and regulatory integrity. Across the areas examined – namely AI training data governance, access to public and non-personal data, and incident reporting mechanisms – there is a common need to preserve traceabilityensure risk-sensitive oversight, and safeguard legal certainty, while also reinforcing the Union’s strategic autonomy. The recommendations above by the AI Policy Lab at Umeå University are intended to support this balance by addressing specific gaps and ambiguities without undermining the overall objectives of the proposal. In doing so, they aim to contribute to a coherent, robust, and future-proof EU regulatory framework for AI and the data economy. 

References  

Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS2), OJ L 333, 27.12.2022, p. 80–152.  

Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities (CER), OJ L 333, 27.12.2022, p. 164–198. 

Proposal for a Regulation of the European Parliament and of the Council establishing a Digital Omnibus for the simplification of Union digital legislation, COM(2025) XXX final. 

Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services (eIDAS), OJ L 257, 28.8.2014, p. 73–114 (as amended).  

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation – GDPR), OJ L 119, 4.5.2016, p. 1–88. 

Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector (DORA), OJ L 333, 27.12.2022, p. 1–79. 

Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L, 12.7.2024.