AI-REG

In the AI-REG project we study the European Artificial Intelligence Act proposal (AI Act) that has been proposed by the European Commission in April 2021 and entered into force in August 2024. The AI Act will regulate the development and use of AI systems in Europe. We focus on how public sector and healthcare organizations deal with ambiguity/uncertainty that arises from regulation-in-the-making.

Project information

Project duration

-

Funded by

Research Council of Finland - Academy Project

Project coordinator

University of Oulu

Contact information

Project leader

Other persons

Project description

In the AI-REG project we study ambiguity that arises from the European Artificial Intelligence Act proposal (AI Act) that has been proposed by the European Commission in April 2021. The AI Act will regulate the development and use of AI systems in Europe. Political agreement between the European Council and the European Parliament has been reached in December 2023, the AI Act was voted on by the 27 EU member states on 2.2.2024 and received full support, and the wording of the AI Act will be finalized in spring 2024. After the expected adoption of the AI Act in late spring 2024, it will enter into force in different stages starting from end of 2024.

The underlying goal of the AI Act is to ensure that Europeans could trust AI systems. The AI Act distinguishes 4 risk classes of AI systems: unacceptable-, high-, limited-, and minimal risk. AI systems which would be judged to have unacceptable risk would be outright forbidden, and high-risk AI systems would have to conform to requirements both during development of the system and in the use of such a system. In addition, in the later stages of negotiations about the AI Act, also general purpose AI models were taken into the scope of the AI Act. The AI Act is thus expected to heavily affect the development and use especially of high-risk AI systems. However, the AI Act is also ambiguous/unclear on many parts, beginnig with the definition of what will be classified as an AI system, or how a specific system would be classified as high-risk vs. low-risk system. Ambiguity means that something can be interpreted in several different ways, and ambiguity in legal regulation - although being an integral part or feature of law - is potentially problematic as it reduces legal certainty.

The AI Act is a horizontal and broad regulation proposal. In the AI-REG project we have two focus areas: 1) High risk AI-system use in public sector organizations, and 2) Development of (high-risk) AI-based healthcare technology.

In the AI-REG project, we study

  • What kind of ambiguities arise from the AI Act
  • What challenges and critiques are seen in the context of the AI Act
  • What legal formulations and requirements cause the ambiguity
  • What characteristics of AI systems make an AI system subject to ambiguity
  • How does regulation affect development of AI-based healthcare technology and AI-system use in public sector organizations
  • How to organizatios prepare for the upcoming AI Act, and how do they deal with ambiguity arising from the Act?

In the AI-REG project, we have a qualitative research approach

  • Identification of ambiguity/unclarity that different stakeholders identify in the AI Act
  • Interviews in mostly in Finland, but also Sweden and Norway, with 1) public sector organizations that use AI systems, and 2) organizations that develop AI-based healthcare technology, 3) ministries, and 4) other stakeholders of interest.
  • Study how focus organizations interpret the AI Act and deal with the uncertainty that arises from the AI Act regarding requirements of compliance
  • Study whether it is possible to develop a taxonomy of AI systems in the light of the AI Act that would help determine whether an AI system is in or out of the AI Act's scope and which risk category it falls into.

Project trainings

Project results

Publications

Journal publications

  • Vainionpää, F., Väyrynen, K., Lanamäki, A., Parmiggiani, E., & Hietala, H. (2026). Anticipation practices of public sector organizations in liminal AI design spaces–the case of the EU AI Act. European Journal of Information Systems, 1-29. https://doi.org/10.1080/0960085X.2026.2651227
  • Lanamäki, A., Väyrynen, K., Vainionpää, F., Hietala, H., Tervo, E., Moltzau, A., Weerts, S., and Niemeyer, D. (2025). What to Expect from the Upcoming EU AI Act Sandboxes: Panel Report. Digital Society, 4 (42). https://link.springer.com/article/10.1007/s44206-025-00201-x
  • Väyrynen, K., Lanamäki, A., Laari-Salmela, S., Iivari, N., and Kinnula, M. (2025). Unpacking the Regulatory Ambiguity Mechanism: Implications for Industry-Level Digital Transformation. Information Systems Journal. forthcoming.https://onlinelibrary.wiley.com/doi/abs/10.1111/isj.12595
  • Väyrynen, K., Laari-Salmela, S., Iivari, N., Lanamäki, A., and Kinnula, M. (2025). Conceptualizing IT Artefacts for Policymaking - How IT Artefacts Evolve as Policy Objects. Communications of the Association for Information Systems, 56, 274-304. https://aisel.aisnet.org/cais/vol56/iss1/11
  • Lanamäki, A., Viljanen, M., Väyrynen, K., & Bennett Moses, L. (2025). Legal Compliance and the Open Texture of Law. Journal of the Association for Information Systems, 26(1), 1-8. https://doi.org/10.17705/1jais.00922
  • Lanamäki, A., Väyrynen, K., Hietala, H., Parmiggiani, E., Vassilakopoulou, P. (2024). Not Inevitable: Navigating Labor Displacement and Reinstatement in the Pursuit of AI for Social Good. Communications of the Association for Information Systems. Vol. 55. https://aisel.aisnet.org/cais/vol55/iss1/30/

Conference publications (peer-reviewed)
  • Tervo, E., Väyrynen, K., and Iivari, N. (2026). If the authorities do not have sufficient resources it can become a bottleneck and a hindrance to the adoption of AI technolgoies" - Regulatory intermediaries as a source of AI Act regulatory uncertainty. European Conference on Information Systems (ECIS 2026 Proceedings), Milan, Italy. https://aisel.aisnet.org/ecis2026/is_policy/is_policy/4/
  • Tervo, E., Väyrynen, K., and Iivari, N. (2026). Regulatory Intermediaries and Chains - the Complex Process of Sensemaking for AI Act Implementation in Finland. Proceedings of the 59th Hawaii International Conference on System Sciences (HICSS-59). https://urn.fi/URN:NBN:fi:oulu-202601261374
  • Tervo, E., Väyrynen, K., and Iivari, N. (2025). The Role of the AI Pact - Compliance Co-creation in the Context of the AI Act. Proceedings of the Scandinavian Conference on Information Systems (SCIS 2025), Oslo, Norway. https://urn.fi/URN:NBN:fi:oulu-202511046575
  • Lanamäki, A., Väyrynen, K., Hietala, H., and Sky, N. (2025). Sociotechnical Imaginaries of Upcoming AI Act Regulatory Sandboxes. Scandinavian Conference on Information Systems, Oslo, Norway. Forthcoming.
  • Hietala, H., Ciriello, R., Vainionpää, F., Väyrynen, K., and Lanamäki, A. (2024). Dialectics of Reconception: Framing Compliant AI Innovation in the Public Sector. International Conference on Information Systems (ICIS), https://aisel.aisnet.org/icis2024/iot_smartcity/iot_smartcity/4/
  • Tervo, E., Väyrynen, K., and Iivari, N. (2024). Increasing Understanding about the Role of Regulatory Intermediaries in Regulation - A Scoping Review and Implications for the European AI Act. Proceedings of the Mediterreanean Conference on Information Systems (MCIS). https://aisel.aisnet.org/mcis2024/9/
  • Lanamäki, A., & Siponen, M. (2024). Mechanisms without Critical Realism. Proceedings of the Scandinavian Conference on Information Systems (SCIS 2024), Uddevalla, Sweden. https://urn.fi/URN:NBN:fi:oulu-202409035694
  • Lanamäki, A., Väyrynen, K., and Vainionpää, F. (2024). The European Union's Regulatory Challenge: Conceptualizing Purpose in Artificial Intelligence. Proceedings of the European Conference on Information Systems (ECIS). https://oulurepo.oulu.fi/handle/10024/49234
  • Vainionpää, F., Väyrynen, K., Lanamäki, A., and Parmiggiani, E. (2024). Practices of Anticipation: How Public Sector Organizations Anticipate Artificial Intelligence and Its Regulation. Proceedings of the European Conference on Information Systems (ECIS). https://oulurepo.oulu.fi/handle/10024/49294
  • Vainionpää, F., Väyrynen, K., Lanamäki, A., and Bhandari, A. (2023). A Review of Challenges and Criticisms of the European Artificial Intelligence Act. Proceedings of the International Conference on Information Systems (ICIS). https://urn.fi/URN:NBN:fi:oulu-202402061598
  • Väyrynen, K., Lanamäki, A., Laari-Salmela, S., Iivari, N., Kinnula, M. (2022) Policy Ambiguity: a Problem, a Tool, or an Inherent Part of Policymaking? Proceedings of the International Conference on Informaiton Systems (ICIS), Copenhagen, Denmark. AIS Electronic Library (AISeL) - ICIS 2022 Proceedings: Policy Ambiguity: a Problem, a Tool, or an Inherent Part of Policymaking? (aisnet.org)
  • Konttila, J., Väyrynen, K. (2022). Challenges of current regulation of AI-based healthcare technology (AIHT) and potential consequences of the European AI Act proposal. Proceedings of the 13th Scandinavian Conference on Information Systems (SCIS), Denmark. jultika.oulu.fi/Record/nbnfi-fe2022092059659

Master's Theses