European Union - Trustworthy AI Guidelines
Ethics Guidelines for Trustworthy AI (High-Level Expert Group on AI)
European Union
RAI-EU-NA-EGTAHXX-2019The Ethics Guidelines for Trustworthy AI, published by the EU High-Level Expert Group on Artificial Intelligence on 8 April 2019, provide a non‑binding, risk‑based set of principles and seven key requirements to guide the design, development and deployment of ethical, lawful and robust AI. The document introduces operational questions and an assessment list (piloted and later developed into ALTAI) to help developers and deployers implement Trustworthy AI across sectors.
Summary
The Ethics Guidelines for Trustworthy AI were prepared by the European Commission’s High-Level Expert Group on Artificial Intelligence and published on 8 April 2019. They set out a non‑binding, principled and operational framework aiming to promote AI that is lawful (compliant with applicable laws and regulations), ethical (respecting ethical principles and values) and robust (safe and technically reliable). The Guidelines synthesise high-level ethical imperatives — respect for human autonomy, prevention of harm, fairness and explicability — into seven actionable requirements that should apply across an AI system’s lifecycle: 1) human agency and oversight; 2) technical robustness and safety; 3) privacy and data governance; 4) transparency; 5) diversity, non‑discrimination and fairness; 6) societal and environmental well‑being; and 7) accountability. Each requirement is paired with practical assessment questions and an operational assessment list intended to support self‑evaluation and improvement by developers and deployers. The document is explicitly voluntary and designed to be piloted across sectors: a piloting phase began in June 2019 and closed in December 2019; feedback led to the Assessment List for Trustworthy Artificial Intelligence (ALTAI) published in July 2020 as a self‑assessment tool. While not legally binding, the Guidelines are positioned as a foundational ethical framework informing EU policy development (including the Commission’s 2019 Communication on a human‑centric approach to AI) and later legislative efforts such as the EU AI Act proposal. The Guidelines emphasise embedding ethics by design, continuous risk assessment, documentation and auditability, meaningful human oversight (human‑in‑the‑loop/on‑the‑loop/in‑command), data governance aligned with data protection rules (including GDPR), mechanisms for transparency and explainability tailored to stakeholder needs, and accessible redress mechanisms. They also encourage stakeholder engagement, multi‑disciplinary governance arrangements and international cooperation to foster global convergence around trustworthy AI norms. Because the text is non‑binding, responsibilities are framed as recommended practices rather than enforceable obligations; legal compliance (e.g., with EU fundamental rights and data protection law) remains mandatory. The Guidelines have been widely referenced in EU policy, industry guidance and academic literature as a central reference point for AI ethics in Europe and internationally.
Full article
Read full text ↗Overview
The Ethics Guidelines for Trustworthy AI, published by the European Commission’s High‑Level Expert Group on Artificial Intelligence on 8 April 2019, provide a voluntary, practical framework to foster AI that is lawful, ethical and robust. The Guidelines translate four ethical imperatives (respect for human autonomy; prevention of harm; fairness; explicability) into seven concrete requirements to be observed throughout an AI system’s lifecycle, and present an assessment list to operationalise those requirements. The document was followed by a piloting phase (June–December 2019) and the later release of the Assessment List for Trustworthy AI (ALTAI) in July 2020. Although non‑binding, the Guidelines were explicitly designed to inform EU policy and practice, offering concrete questions, suggested governance measures and pointers to self‑assessment tools that developers, deployers and public authorities can use to reduce risks and increase societal trust in AI.
Definitions
The Guidelines define 'Trustworthy AI' as AI that is lawful, ethical and robust. Lawfulness requires compliance with EU law (including fundamental rights and data protection law). Ethical alignment is assessed against ethical principles and values (e.g., human dignity, autonomy, prevention of harm, fairness, explicability). Robustness covers technical reliability, safety and resilience to both foreseeable and unforeseeable issues. The document also supplies an internal definition of 'Artificial Intelligence' used for the Guidelines' scope (available on the Commission's Futurium platform) and frames AI systems to include data, models, human‑machine interfaces, and operational processes across the lifecycle (design, development, deployment, maintenance).
Governance and Institutional Framework
The Guidelines recommend governance arrangements at multiple levels: organisational governance inside developer and deployer entities (roles, responsibilities, boards, ethics committees); sectoral governance where domain‑specific oversight is required; and public governance where regulators and public authorities ensure legal compliance and public interest safeguards. They call for multidisciplinary expertise (ethics, legal, technical, social sciences) to be embedded in decision‑making, for clear allocation of responsibility across life cycle stages, and for documentation and audit trails to enable external review. The Guidelines explicitly advise institutions to engage with the European AI Alliance and to use publicly available tools such as the ALTAI self‑assessment list to translate principles into practices. The document positions the High‑Level Expert Group as an advisory body and the European Commission (DG CONNECT / AI Office) as the primary EU steward promoting implementation, while national authorities and sectoral regulators are encouraged to adapt governance measures to local contexts.
Key Focus Areas
The Guidelines identify seven interlocking requirements that are the core of Trustworthy AI. Human agency and oversight: systems must support meaningful human decision‑making and enable oversight through human‑in/‑on/‑command models and accessible redress. Technical robustness and safety: systems should be resilient, secure, accurate and include fallback and mitigation strategies. Privacy and data governance: data quality, integrity, lawful access and alignment with data protection rules (e.g., GDPR) are required. Transparency: traceability, communication of capabilities/limitations and explanations tailored to stakeholders are necessary for informed human decisions. Diversity, non‑discrimination and fairness: design and testing should prevent and mitigate bias, involve inclusive datasets and stakeholder participation, and support accessibility. Societal and environmental well‑being: developers should consider sustainability, social impact and the welfare of current and future generations. Accountability: mechanisms such as logging, documentation, auditability and governance structures must support responsibility and redress. For each focus area the Guidelines provide concrete assessment questions and suggested operational measures to facilitate adoption across sectors, including healthcare and finance.
Implementation Framework
To operationalise the seven requirements the Guidelines propose an assessment list and pilot process: organisations should perform context‑sensitive risk assessments, maintain documentation (data sheets, model cards, decision logs), run validation/testing protocols, and design human‑machine interfaces that preserve human agency. The document emphasizes embedding ethics by design and by default, iterative monitoring (pre‑ and post‑deployment), stakeholder engagement across the lifecycle, and transparency measures proportionate to risk and the stakeholder group. It also recommends the creation of multidisciplinary review boards, training for staff in ethics and governance, and mechanisms for internal and external audits. The ALTAI tool (published subsequently) is presented as the practical instrument for self‑assessment and continuous improvement.
Monitoring and Evaluation
The Guidelines encourage continuous monitoring through structured testing, validation and reporting practices. Monitoring encompasses technical metrics (accuracy, robustness, resilience), fairness audits (bias testing across subgroups), privacy impact assessments, transparency checks (explainability tests tailored to users), and post‑deployment surveillance to identify emergent risks. The document recommends measurable KPIs, logging for reproducibility and auditability, periodic reviews by multidisciplinary oversight teams, and public reporting where appropriate to build stakeholder trust. Piloting and stakeholder feedback are promoted as essential to refine the assessment list and to adapt governance measures in different domains.
Penalties, Liability, and Appeals
As a voluntary set of guidelines, the document itself does not establish penalties, enforcement mechanisms or liability rules. Instead, it clarifies that legal compliance (including obligations under the EU Charter of Fundamental Rights and the GDPR) remains mandatory and enforceable under existing law. Where risks materialise, liability and redress are to be addressed through applicable national and EU legal frameworks; the Guidelines recommend that organisations design accessible redress mechanisms and preserve documentation to facilitate accountability, investigations and remedies. The Guidelines therefore act as a risk‑mitigation and governance complement to legally binding instruments rather than a source of penalties.
Relationship to Other Instruments
The Guidelines situate themselves alongside and as a complement to EU legal instruments and policy initiatives: the Commission’s 2018/2019 AI strategy and the 2019 Communication "Building Trust in Human‑Centric Artificial Intelligence", the GDPR and EU Charter of Fundamental Rights, sectoral rules, and later legislative proposals (notably the EU AI Act proposal). They serve as an ethical and operational bridge between high‑level principles (Charter, GDPR) and technical or regulatory instruments (conformity assessment, standardisation activities). The Guidelines also informed the development of the ALTAI self‑assessment tool and influenced standardisation discussions at EU and ISO levels.
International Alignment
While focused on the EU context, the Guidelines explicitly call for international cooperation and convergence on AI ethics and governance. They reference global initiatives and advocates for dialogue with multilateral organisations, standardisation bodies and other jurisdictions to build shared understandings of trustworthy AI. By packaging principles with operational assessment tools, the Guidelines aim to support uptake beyond the EU and to influence international norms while respecting differing legal frameworks (e.g., data protection regimes) and cultural values.
Implementation Timeline
| Event | Date |
|---|---|
| Draft Guidelines published (HLEG) | 2018-12-18 |
| Final Guidelines published (HLEG / European Commission) | 2019-04-08 |
| Piloting of Assessment List started | 2019-06-26 |
| Piloting phase closed | 2019-12-01 |
| Assessment List (ALTAI) final published | 2020-07-17 |
Sources and References
| Source | Type |
|---|---|
| Ethics Guidelines for Trustworthy AI (European Commission / AI HLEG) | Primary Source |
| Assessment List for Trustworthy AI (ALTAI) | Primary Source |
Requirements for a company
What an organisation has to do under European Union - Trustworthy AI Guidelines, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Adopted). These requirements apply once the instrument takes effect and may change before then.
Must do
13- Comply with all applicable EU law, including fundamental rights and data protection regulations.All entities designing, developing, or deploying AI systems.
- Ensure AI systems align with data protection rules, such as the GDPR.Providers and deployers of AI systems.
- Ensure AI systems support meaningful human decision-making and enable effective human oversight.Providers and deployers of AI systems.
- Design AI systems to be technically robust, secure, accurate, and include fallback strategies.Providers and deployers of AI systems.
- Ensure high data quality, integrity, and lawful access for AI systems.Providers and deployers of AI systems.
- Provide traceability, communicate AI capabilities and limitations, and offer explanations tailored to stakeholders.Providers and deployers of AI systems.
- +7 more in the table below
Must not do
0Nothing in this category.
Should do
2- Establish multidisciplinary expertise (ethics, legal, technical) in AI decision-making processes.Organisations developing and deploying AI systems.
- Use publicly available tools like ALTAI for self-assessment and continuous improvement of AI systems.Institutions and organisations using AI.
Should not do
0Nothing in this category.
Who must do what
The obligations under European Union - Trustworthy AI Guidelines, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | All entities designing, developing, or deploying AI systems. | Comply with all applicable EU law, including fundamental rights and data protection regulations. “Lawfulness requires compliance with EU law (including fundamental rights and data protection law).” | — | — | Critical |
| 2 | Providers and deployers of AI systems. | Ensure AI systems align with data protection rules, such as the GDPR. “Privacy and data governance: data quality, integrity, lawful access and alignment with data protection rules (e.g., GDPR) are required.” | — | — | Critical |
| 3 | Providers and deployers of AI systems. | Ensure AI systems support meaningful human decision-making and enable effective human oversight. “Human agency and oversight: systems must support meaningful human decision‑making and enable oversight through human-in/-on/-command models and accessible redress.” | Before placing on market | — | Important |
| 4 | Providers and deployers of AI systems. | Design AI systems to be technically robust, secure, accurate, and include fallback strategies. “Technical robustness and safety: systems should be resilient, secure, accurate and include fallback and mitigation strategies.” | Before placing on market | — | Important |
| 5 | Providers and deployers of AI systems. | Ensure high data quality, integrity, and lawful access for AI systems. “Privacy and data governance: data quality, integrity, lawful access and alignment with data protection rules (e.g., GDPR) are required.” | Before placing on market | — | Important |
| 6 | Providers and deployers of AI systems. | Provide traceability, communicate AI capabilities and limitations, and offer explanations tailored to stakeholders. “Transparency: traceability, communication of capabilities/limitations and explanations tailored to stakeholders are necessary for informed human decisions.” | Before placing on market | — | Important |
| 7 | Providers and deployers of AI systems. | Design and test AI systems to prevent and mitigate bias, using inclusive datasets and stakeholder participation. “Diversity, non‑discrimination and fairness: design and testing should prevent and mitigate bias, involve inclusive datasets and stakeholder participation, and support accessibility.” | Before placing on market | — | Important |
| 8 | Providers and deployers of AI systems. | Establish mechanisms such as logging, documentation, and audit trails to support accountability and redress. “Accountability: mechanisms such as logging, documentation, auditability and governance structures must support responsibility and redress.” | Before placing on market | — | Important |
| 9 | Organisations developing and deploying AI systems. | Perform context-sensitive risk assessments for AI systems throughout their lifecycle. “organisations should perform context‑sensitive risk assessments, maintain documentation (data sheets, model cards, decision logs), run validation/testing protocols...” | Before placing on market | — | Important |
| 10 | Organisations developing and deploying AI systems. | Maintain comprehensive documentation, including data sheets, model cards, and decision logs. “maintain documentation (data sheets, model cards, decision logs)” | Before placing on market | — | Important |
| 11 | Organisations developing and deploying AI systems. | Implement validation and testing protocols for AI systems. “run validation/testing protocols” | Before placing on market | — | Important |
| 12 | Organisations developing and deploying AI systems. | Embed ethics by design and by default in AI system development and deployment. “The document emphasizes embedding ethics by design and by default, iterative monitoring...” | Before placing on market | — | Important |
| 13 | Organisations developing and deploying AI systems. | Design accessible redress mechanisms to facilitate accountability, investigations, and remedies. “organisations design accessible redress mechanisms and preserve documentation to facilitate accountability, investigations and remedies.” | Before placing on market | — | Important |
| 14 | Organisations developing and deploying AI systems. | Establish multidisciplinary expertise (ethics, legal, technical) in AI decision-making processes. “They call for multidisciplinary expertise (ethics, legal, technical, social sciences) to be embedded in decision‑making...” | — | — | Recommended |
| 15 | Institutions and organisations using AI. | Use publicly available tools like ALTAI for self-assessment and continuous improvement of AI systems. “The Guidelines explicitly advise institutions to engage with the European AI Alliance and to use publicly available tools such as the ALTAI self‑assessment list...” | — | — | Recommended |
Related Regulations
Assessment List for Trustworthy Artificial Intelligence (ALTAI) — self-assessment tool
European Union94% similar
Recommendation of the Council on Artificial Intelligence
OECD93% similar
Malta — Towards Ethical and Trustworthy AI (Malta's Ethical AI Framework)
Malta93% similar
Recommendation on the Ethics of Artificial Intelligence
UNESCO93% similar
Principles for the Ethical Use of Artificial Intelligence in the United Nations System
United Nations92% similar
© Regulations.AI · updated on 13-Jun-2026