AI Risks, Mitigation and Maintenance
Delft University of Technology
2026-03-27
ERGO context
Pan-European insurer (Munich Re subsidiary), operating across EU, US, and Asia
| Article | Relevance to SmartPolicy |
|---|---|
| Art. 5 | Data minimisation: collect only what is strictly necessary |
| Art. 9 | Special categories: health, driving behaviour data require explicit consent or legal basis |
| Art. 22 | Automated decisions: right not to be subject to solely automated decisions with significant effects; special-category data further restricted |
| Art. 35 | DPIA mandatory when processing sensitive data at scale for profiling (definitely , ) |
Tip
Recommendation: prioritise EU rollout first. The EU AI Act provides a clear, comprehensive framework.
End-to-end auditing framework as reference point:
FOSS Practices
In the FOSS space, essentially all code is treated packages (facilitates usage, extensibility, …)
| Document | Trigger | |
|---|---|---|
| Datasheets (Gebru et al., 2021) | Per training dataset | |
| Model cards (Mitchell et al., 2019) | Per model release | |
| Technical documentation (EU AI Act Art. 11) | commit; PR; release |