scieee AI-readable full text Open interactive document viewer

D2.4 Knowledge Base for Trustworthy and Sustainable AI

Mattila, Merja; Laine, Heidi; Kallio, Aleksi

Abstract

Artificial Intelligence (AI) is rapidly transforming society, research, and industry. Within this evolving landscape, European AI factories, such as LUMI AI Factory, play a key role in fostering innovation and developing reliable, safe, and sustainable AI models and systems. However, the inherent complexity, opacity, and autonomy of AI systems, along with the vast data requirements for training, introduce significant risks, including biased decision-making, discrimination, or legal issues. To address these challenges, ethical frameworks are increasingly being integrated into AI development. LUMI AIF approaches ethics from a Western, pan-European perspective. Its goal is not to train AI to deliver morally correct answers, but to support customers in recognising ethical issues and making informed decisions about the value systems and role models that should guide AI behaviour. In addition to ethical support, LUMI AIF helps customers navigate the European regulatory landscape. Adopting a risk-based approach, LUMI AIF ensures that AI models and systems developed within its environment are both compliant and ethically sound. Furthermore, given the supercomputing context in which LUMI AIF operates, environmental sustainability is a central concern. The LUMI supercomputer already meets high sustainability standards. For LUMI AIF Services, sustainability objectives and metrics are still evolving, but the aim is to ensure that both infrastructure and services meet rigorous environmental criteria. By proactively supporting responsible AI development, LUMI AIF fosters trust, strengthens customer confidence, and contributes to a broader ecosystem of ethical and sustainable AI innovation. At the heart of this commitment is the Knowledge Base for Trustworthy and Sustainable AI, which provides structured, contextual support throughout the customer journey. This resource adopts a human-centric, risk-based approach to help a wide range of stakeholders, including startups, SMEs, large enterprises, academic institutions, and public sector organisations, develop AI solutions that respect human values and fundamental rights. The Knowledge Base includes training materials, templates, guidelines, decision-making frameworks, industry examples, and practical tools to help users navigate legal and regulatory obligations, conduct risk assessments, promote transparency and accountability, mitigate bias, and monitor model performance. It also supports environmental sustainability by offering best practices for energy-efficient model training and responsible data usage. Accessible via an AI assistant integrated with LUMI AIF’s Customer Process and Service Portfolio, the Knowledge Base enables intuitive search and guidance for both customers and internal personnel. While it provides expert support aligned with official guidelines, it does not constitute legal advice. Although regulatory sandboxes are currently outside the scope of LUMI AIF, the Knowledge Base includes relevant guidance due to their inclusion in the EU AI Act. As the regulation becomes fully applicable on 2 August 2026, LUMI AIF will continue to update the Knowledge Base in alignment with evolving guidance from the EU AI Office and national authorities. Looking ahead, LUMI AI Factory plans to implement an AI governance model that integrates the regulatory requirements of the EU AI Act with the ISO/IEC 42001 standard. This model will be gradually embedded into LUMI AIF’s operations throughout 2026 and is therefore not described in detail in this document. Declaration on the Use of AI Assistance This report has been prepared with the support of GPT-5-enabled Microsoft Copilot, which was used to assist in drafting text, checking language, and gathering background information. All content has been thoroughly reviewed, fact-checked, and edited by the authors to ensure accuracy and alignment with the objectives of the report.

Full text

LUMI AI Factory Service Center Empowering Europe’s AI Ecosystem D2.4 Knowledge base for Trustworthy and Sustainable AI 2 D2.4 Knowledge Base for Trustworthy and Sustainable AI D2.4 Knowledge base for Trustworthy and Sustainable AI 3 Project Title LUMI AI Factory Service Center Project Acronym LUMI-AIF Project Number 101234208 Type of Action HORIZON-JU-RIA Topic HORIZON-JU-EUROHPC-2025-AI-01-IBA-01 Starting Date of Project 01.03.2025 Ending Date of Project 29.02.2028 Duration of the Project 36 months Website lumi-ai-factory.eu Work Package WP2 Customer Engagement Task Task 2.4 Knowledge Base for Trustworthy and Sustainable AI Lead Authors Merja Mattila (CSC) Contributors Heidi Laine (CSC) Aleksi Kallio (CSC) Peer Reviewers Lukasz Leszczyński (Cyfronet) Juhani Huttunen (CSC) Outi Tasala (CSC) Version 1.0 Due Date 3.10.2025 Submission Date 31.10.2025 Dissemination level X PU: Public SEN: Sensitive – limited under the conditions of the Grant Agreement EU-RES. Classified Information: RESTREINT UE (Commission Decision 2005/444/EC) EU-CON. Classified Information: CONFIDENTIEL UE (Commission Decision 2005/444/EC) EU-SEC. Classified Information: SECRET UE (Commission Decision 2005/444/EC) D2.4 Knowledge base for Trustworthy and Sustainable AI 4 Version History Revision Date Editors Comments 0.1 3.10.2025 Merja Mattila Corrections and additions made 0.2 14.10.2025 Merja Mattila Version of deliverable presented to the SMB 0.3 28.10.2025 Merja Mattila Version sent to PMO for quality check 1.0 31.10.2025 Janina Juuvinmaa Final quality check performed by the PMO, sent to review Glossary of Terms Item Description AI Artificial Intelligence AIF AI Factory AIRS Artificial Intelligence Regulatory Sandboxes CSC CSC – IT Center for Science DaaS Dataset-as-a-Service EC European Commission EU European Union FLOP Floating-point operations FRA Fundamentals Rights Authority FRIA Fundamentals Rights Impact Assessment GenAI Generative Artificial Intelligence GPAI General-purpose AI model GPU Graphics Processing Unit HPC High-Performance Computing IAPP International Association of Privacy Professionals IPR Intellectual Property Rights LUMI AIF LUMI AI Factory LLM Large Language Model LUMI-AI The upcoming EuroHPC AI supercomputer MSA Market Surveillance Authority NCA National Competent Authority NIST AI RMF The NIST AI Risk Management Framework SME Small and Medium-sized Enterprise D2.4 Knowledge base for Trustworthy and Sustainable AI 5 Executive Summary Artificial Intelligence (AI) is rapidly transforming society, research, and industry. Within this evolving landscape, European AI factories, such as LUMI AI Factory, play a key role in fostering innovation and developing reliable, safe, and sustainable AI models and systems. However, the inherent complexity, opacity, and autonomy of AI systems, along with the vast data requirements for training, introduce significant risks, including biased decision-making, discrimination, or legal issues. To address these challenges, ethical frameworks are increasingly being integrated into AI development. LUMI AIF approaches ethics from a Western, pan-European perspective. Its goal is not to train AI to deliver morally correct answers, but to support customers in recognising ethical issues and making informed decisions about the value systems and role models that should guide AI behaviour. In addition to ethical support, LUMI AIF helps customers navigate the European regulatory landscape. Adopting a risk-based approach, LUMI AIF ensures that AI models and systems developed within its environment are both compliant and ethically sound. Furthermore, given the supercomputing context in which LUMI AIF operates, environmental sustainability is a central concern. The LUMI supercomputer already meets high sustainability standards. For LUMI AIF Services, sustainability objectives and metrics are still evolving, but the aim is to ensure that both infrastructure and services meet rigorous environmental criteria. By proactively supporting responsible AI development, LUMI AIF fosters trust, strengthens customer confidence, and contributes to a broader ecosystem of ethical and sustainable AI innovation. At the heart of this commitment is the Knowledge Base for Trustworthy and Sustainable AI, which provides structured, contextual support throughout the customer journey. This resource adopts a human-centric, risk-based approach to help a wide range of stakeholders, including startups, SMEs, large enterprises, academic institutions, and public sector organisations, develop AI solutions that respect human values and fundamental rights. The Knowledge Base includes training materials, templates, guidelines, decision-making frameworks, industry examples, and practical tools to help users navigate legal and regulatory obligations, conduct risk assessments, promote transparency and accountability, mitigate bias, and monitor model performance. It also supports environmental sustainability by offering best practices for energy-efficient model training and responsible data usage. Accessible via an AI assistant integrated with LUMI AIF’s Customer Process and Service Portfolio, the Knowledge Base enables intuitive search and guidance for both customers and internal personnel. While it provides expert support aligned with official guidelines, it does not constitute legal advice. Although regulatory sandboxes are currently outside the scope of LUMI AIF, the Knowledge Base includes relevant guidance due to their inclusion in the EU AI Act. As the regulation becomes fully applicable on 2 August 2026, LUMI AIF will continue to update the Knowledge Base in alignment with evolving guidance from the EU AI Office and national authorities. Looking ahead, LUMI AI Factory plans to implement an AI governance model that integrates the regulatory requirements of the EU AI Act with the ISO/IEC 42001 standard. This model will be gradually embedded into LUMI AIF’s operations throughout 2026 and is therefore not described in detail in this document. D2.4 Knowledge base for Trustworthy and Sustainable AI 6 Table of Contents 1. Introduction ...................................................................................................... 7 1.1 Objectives 7 1.2 Scope 8 1.3 Definitions of AI 10 2. Foundations of Trustworthy and Sustainable AI ................................................. 11 2.1 Ethical principles 11 2.2 Key requirements 12 2.3 Technical and non-technical methods 13 2.4 Regulatory framework and international standards 15 2.5 Risks and requirements related to AI models and AI systems 16 2.6 Responsibilities depending on the AI risk levels and roles 18 2.7 Authorities 19 2.8 Regulatory sandboxes 19 3. Implementation of Knowledge Base .................................................................. 20 3.1 Trustworthy and Sustainable AI at LUMI AIF 20 3.2 Operational environment from a customer’s perspective 24 3.3 Practical implementation and customer support 26 3.4 Knowledge Base structure and integration with LUMI AI Factory Services 27 4. Conclusions and next steps ............................................................................... 29 D2.4 Knowledge base for Trustworthy and Sustainable AI 7 1. Introduction 1.1 Objectives As a provider of high-performance computing, Dataset-as-a-Service, and other related services, LUMI AI Factory (LUMI AIF) plays an important role in shaping the future of customers’ artificial intelligence (AI) models and systems. Due to its role in providing datasets and supercomputing services to startups, large enterprises, academic institutions, and public sector organisations, LUMI AIF operates within a highly regulated environment. In the European Union, several key legislative frameworks govern how LUMI AIF manages data and supports its customers to implement trustworthy and sustainable AI models and systems. These EU legislations include the GDPR1, EU AI Act2, Data Governance Act3, Data Act4, and NIS2 Directive5. Together, these regulations shape LUMI AIF approach to trustworthy and sustainable AI development. Particularly important is the EU AI Act that creates a regulatory framework for AI systems and general-purpose AI models by classifying them based on their risk levels. LUMI AIF visibility to customers’ AI models or into final AI system integrations is inherently limited, and it is essential to recognise that algorithms often reflect the values and assumptions of their developers. To ensure that customers’ AI solution is ethical, trustworthy, and sustainable, LUMI AIF must equip the customers with more than just technical resources – it must also provide guidance, trainings, tools, and best practices that foster trustworthy and sustainable AI development. This is where a dedicated Knowledge Base becomes indispensable. Promoting AI ethics and value-sensitive AI development is critical as AI can significantly impact individuals and society. Ethics should not be an afterthought applied to make an AI model acceptable – it should guide decisions from the outset, shaping what is considered worth building. In addition to the mandatory ethics training to customers and support teams, LUMI AIF is considering the establishment of an Ethical Board to evaluate the most important customers’ resource applications, AI models and use cases, ensuring that ethical and sustainability considerations are embedded in high-impact projects. LUMI AIF has adopted a risk-based approach, which is particularly important in LUMI AIF’s core offering, Dataset-as-a-Service (DaaS), as risks often arise from dataset selection, quality, handling across lifecycle stages, or model complexity. Making appropriate risk assessments during the whole AI life cycle makes risks more visible, and is important to increase transparency, explainability, customer awareness and accountability. By offering templates for documenting training datasets, models, and decisions, along with guidelines for reproducibility and audit trails, the Knowledge Base empowers customers to mitigate bias in training datasets, and to monitor model behaviour and performance effectively. AI models themselves are not inherently good or bad – their impact depends on how they are used and integrated. Since models may be embedded into unknown or varied systems, customers must be able to identify when an AI system qualifies as high-risk under the EU AI Act and understand their obligations 1 The General Data Protection Regulation (EU 2016/679) 2 The European Union Artificial Intelligence Act (EU 2024/1689) 3 The Data Governance Act (EU 2022/868) 4 The European Union Data Act (EU 2023/2854) 5 The European Union Data Act (EU 2023/2854) D2.4 Knowledge base for Trustworthy and Sustainable AI 8 based on their roles. It is also important to note that the EU AI Act (EU AIA) primarily targets AI systems rather than individual models. This distinction between obligations for AI models and AI systems is important, and LUMI AIF aims to ensure that customers have the necessary capabilities to evaluate whether they meet applicable obligations. The Knowledge Base can include training modules, onboarding guides, case studies, practical examples, and decision-making frameworks to help customers make informed decisions and align with legal and regulatory frameworks. Trust in AI systems is reinforced through strong safeguards, and LUMI AIF emphasises information security and data privacy as foundational elements of trustworthy AI. Existing regulations, such as GDPR and copyright laws, remain highly relevant. Requirements related to data minimisation, lawful basis for personal data processing, and human oversight must be considered throughout the AI lifecycle. However, it is important to clarify that the Knowledge Base materials and expert support do not constitute legal advice. Instead, they are designed to promote ethical, trustworthy, and sustainable practices. To strengthen this approach, LUMI AIF strives to align its guidance with official recommendations and guidelines from relevant authorities wherever possible. Supporting sustainable AI development practices is increasingly important as high-performance computing is rather resource intensive. The Knowledge Base can promote environmental responsibility by sharing best practices for energy-efficient model training, helping customers to create technical documentation including energy efficiency, supporting their strategies for reducing computational waste, or insights related to responsible training dataset usage. By proactively supporting responsible AI development LUMI AIF builds trust, strengthens customer confidence in its services, and contributes to a broader ecosystem of ethical and sustainable AI. This is particularly important as customer projects enter the LUMI AI Factory through various channels, which can pose practical challenges in tracking them effectively and ensuring that each project receives the appropriate level of support. The Knowledge Base is one way to build trust between different stakeholders. 1.2 Scope The purpose of this document is to provide a clear understanding of how LUMI AIF's approach to trustworthy and sustainable AI is grounded in pan-European ethical principles and regulation. The aim is to foster AI innovations and to support customers, particularly startups, academic institutions, and public sector organisations who utilise the LUMI AIF service in developing and deploying AI models and systems that are both trustworthy and sustainable. LUMI AIF seeks to inform its users as comprehensively as possible about the relevant ethical and regulatory frameworks. In terms of sustainability, the service provides datasets and guidance for AI model design to help ensure that AI solutions are developed with sustainability in mind. The Knowledge Base describes the key actions taken within LUMI AI Factory to support the ethical, trustworthy, safe, and sustainable development of AI. It outlines the main principles of trustworthy and sustainable AI and how the Knowledge Base provides structured guidance and contextual support throughout the customer journey. D2.4 Knowledge base for Trustworthy and Sustainable AI 9 The Knowledge Base is closely integrated with the LUMI AIF Customer Process and Service Portfolio, which is further divided into a Service Catalogue for external use and a Service Portfolio for internal use. The aim is to ensure that relevant materials are recommended to both LUMI AIF personnel and customers at the right time, supporting a wide range of stakeholders including SMEs, start-ups, large enterprises, academic institutions, and public sector organisations. Materials such as articles, templates, and guidelines are linked to specific service stages and are recommended to customers based on their current engagement. Customers can also access the Knowledge Base independently through an AI assistant, which enables intuitive search and retrieval of tailored guidance and documentation based on the specific needs and context. Internal service teams and other stakeholders are likewise encouraged to use the Knowledge Base to promote consistent and responsible practices. Consultation and support are limited to the use of the Knowledge Base, descriptions of the technical environment, and general-level guidance. Legal obligations—particularly those related to the EU AI Act and GDPR—are addressed through general recommendations, but customers are advised to consult their own legal departments or external experts for formal legal interpretation. While the Knowledge Base does not offer legal advice, it provides strong ethical framing and practical guidance on topics such as data privacy, including privacy by design, data minimisation, and lawful basis for processing personal data. The Knowledge Base covers the entire AI lifecycle, even though LUMI AIF has limited visibility into customers’ activities during model development or after they exit the service. Despite this, LUMI AIF recognises the importance of providing ethical guidance to promote responsible behaviour across all stakeholder groups. Further, to ensure trustworthy and sustainable AI, the Knowledge Base places particular emphasis on customer’s responsibilities across the AI development under the EU AI Act. Throughout the Knowledge Base, key principles and constraints are consistently applied to uphold ethical standards, promote transparency, and encourage sustainable practices. Training customers regardless of their level of expertise ensures responsible AI development. Further, trustworthy AI requires transparency in how models are built and used. The Knowledge Base includes the necessary materials, such as articles, templates, tools, and guidelines, to support the development of ethically sound and environmentally sustainable AI systems. It serves as a central resource for providing guidance for customers throughout their AI journey. Finally, the Knowledge Base supports reliability and performance in AI development through validation practices within the Dataset-as-a-Service (DaaS) model and by promoting appropriate safeguards. The system-level emphasis of the Knowledge Base is aligned with the requirements of the EU AI Act, helping customers to understand and manage their responsibilities effectively. D2.4 Knowledge base for Trustworthy and Sustainable AI 16 transparency in training data, systemic risk evaluations, and cybersecurity safeguards. With extraterritorial reach, the AI Act applies to any AI system whose output affects individuals in the EU, regardless of where it is developed. Its phased implementation began in 2025, with full enforcement expected by 2026–2027, and non-compliance can result in fines of up to €35 million or 7% of global annual turnover. ISO/IEC 42001 is the world’s first international standard for Artificial Intelligence Management Systems (AIMS), providing a structured framework for organisations to govern AI responsibly across its lifecycle. It outlines requirements for leadership, planning, support, operation, performance evaluation, and continual improvement, helping organisations manage risks related to transparency, fairness, privacy, and security. In Europe, ISO/IEC 42001 is often deployed alongside complementary standards such as ISO/IEC 27001 (information security management), ISO/IEC 9001 (quality management), and ISO/IEC 42005, which focuses on AI system impact assessment. Together, these standards support a holistic approach to AI governance, aligning with the goals of the EU AI Act and enabling organisations to demonstrate compliance, build trust, and ensure ethical and sustainable AI development. The EU AI Act and ISO/IEC 42001 are highly complementary frameworks that can be implemented together to establish a robust and compliant AI governance system. The EU AI Act provides a legal foundation with a risk-based approach to regulating AI systems, focusing on transparency, human oversight, and fundamental rights protection. ISO/IEC 42001, on the other hand, offers a structured management system for operationalising these principles within organisations. It includes requirements for leadership, planning, risk management, and continuous improvement - many of which directly support the obligations outlined in the AI Act. By aligning ISO/IEC 42001’s process-based controls with the EU AI Act’s regulatory mandates, organisations can ensure both legal compliance and operational excellence. 2.5 Risks and requirements related to AI models and AI systems The EU AI Act sets out a comprehensive framework to ensure trustworthy and sustainable AI across the European Union. The core objectives of the EU AI Act are to promote safe and trustworthy AI across the EU single market, protect health, safety, and fundamental rights of EU citizens, and ensure transparency, accountability, and sustainability in AI development and deployment. It also encourages innovation, especially among SMEs and startups, and has some specific requirements regarding regulatory sandboxes for testing AI in controlled environments. There are several critical challenges associated with AI models and systems: • Data quality and sourcing: Ensuring the use of high-quality, ethically and legally sourced data is foundational to trustworthy AI. • Privacy and data protection: Safeguarding personal and sensitive information remains a central concern, especially under evolving regulatory frameworks. • Transparency and explainability: Many AI systems operate as “black boxes,” making it essential to enhance interpretability and provide clear insights into decision-making processes. • Bias, discrimination, and fairness: These risks highlight the need for inclusive design practices and rigorous testing to ensure equitable outcomes. • Security and robustness: AI systems must be resilient against adversarial attacks, data poisoning, and other vulnerabilities that could compromise their integrity. D2.4 Knowledge base for Trustworthy and Sustainable AI 17 • AI safety: Managing systemic risks and unforeseen harms – particularly with advanced or autonomous AI – requires proactive safety measures and oversight. • Legal and intellectual property issues: The rapid development of generative AI has introduced new complexities around copyright, ownership, and content attribution. • Third-party assurance: There is a growing demand for independent mechanisms such as audits, impact assessments, and certifications to build trust and accountability across the AI lifecycle. To address these challenges, the EU AI Act adopts a risk-based approach classifying AI systems into four categories based on their potential impact on health, safety, and fundamental rights. As mentioned earlier, AI System is a complete application that uses one or more models to produce decisions, recommendations, or actions. It can operate autonomously or under human supervision, and it affects physical or digital environments. Unacceptable risk means that AI systems are strictly prohibited. These include applications such as social scoring by governments, manipulative or deceptive AI that distorts human behaviour, and systems that exploit vulnerabilities related to age, disability, or socio-economic status. These practices are considered harmful and are banned under Article 5 of the Act. High-risk AI systems are subject to stringent regulatory requirements. These systems are typically used in sensitive domains such as critical infrastructure, education, employment, law enforcement, and healthcare. They also include safety components in regulated products like medical devices, as well as biometric identification and emotion recognition technologies. Providers of high-risk AI must comply with obligations including conducting a conformity assessment, maintaining technical documentation, implementing risk management procedures, and ensuring human oversight. High-risk systems must also be registered in an EU database, and public sector deployers are required to perform fundamental rights impact assessments before deployment. Limited risk AI systems face lighter obligations, primarily focused on transparency. Developers and deployers must ensure that users are clearly informed when they are interacting with AI. This applies to systems such as chatbots and AI-generated content like deepfakes, which must be labelled or disclosed appropriately. Minimal risk AI systems, such as those used in video games or spam filters, are not subject to specific obligations under the AI Act. These applications are considered low-impact and are generally governed by existing laws like GDPR and consumer protection regulations. In contrast, general-purpose AI models (GPAI), such as large language models or foundation models, are subject to a separate set of obligations due to their broad applicability and potential societal impact. Providers of GPAI must ensure transparency by supplying technical documentation, summaries of training data, and relevant information to downstream developers. If a GPAI model is deemed to pose systemic risk, additional requirements apply, including robust risk management procedures, cybersecurity safeguards, and continuous monitoring and reporting. Furthermore, generative AI outputs must be clearly labelled as AI-generated, especially when used in public-facing content, to prevent deception and ensure accountability. These differentiated requirements reflect the EU’s commitment to fostering innovation while safeguarding fundamental rights and public trust. By tailoring obligations to the nature and risk level of D2.4 Knowledge base for Trustworthy and Sustainable AI 18 AI systems, the AI Act aims to create a balanced regulatory environment that supports responsible development and deployment of AI technologies. 2.6 Responsibilities depending on the AI risk levels and roles The EU AI Act defines several key roles to ensure accountability and compliance throughout the lifecycle of AI systems. The provider is the entity that develops or places an AI system on the market under its name or trademark and is responsible for ensuring the system meets all regulatory requirements. The deployer refers to any organisation or individual (excluding private users) that uses an AI system under their authority and must ensure proper oversight and responsible use. The importer brings AI systems from outside the EU into the EU market and must verify that these systems comply with EU standards before distribution. Similarly, the distributor makes AI systems available within the EU without altering them and must ensure that the systems remain compliant and that relevant documentation is passed on. To support compliance, an authorised representative may be appointed by a non-EU provider to carry out regulatory tasks within the EU. For high-risk AI systems, a notified body – an independent organisation – conducts conformity assessments to verify that the systems meet safety and ethical standards. Oversight is further ensured by national supervisory authorities, which monitor and enforce the regulation at the Member State level. At the EU level, the AI Office coordinates enforcement, provides guidance, and facilitates harmonisation across Member States. These roles and their key responsibilities are presented in the table below, offering a clear overview of responsibilities across the AI ecosystem. Table. 1. Roles and obligations D2.4 Knowledge base for Trustworthy and Sustainable AI 19 2.7 Authorities The safety and ethical development of AI products and models is primarily overseen in the European Union through the AI Act. As previously mentioned, the aim of the AI Act and other relevant regulations is to ensure that AI systems do not endanger fundamental rights, health, or safety. The European Commission is responsible for the overall implementation and guidance of the regulations. In practice, the specialised body within the European Commission, The European Artificial Intelligence Office (AIO) has been established to implement and enforce the EU AI Act. The AIO supports the application of regulation and publishes guidance on topics such as risk classification and system definitions and serves as the central hub of AI expertise across the European Union. It has recently launched an AI Act Single Information platform14 including valuable materials, and links to the AI Act Service Desk. National authorities, such as the Finnish Transport and Communications Agency Traficom, and Finnish Medicines Agency Fimea, implement and enforce the AI Act at the member state level. Their main duties include supervising high-risk AI systems to ensure compliance with safety and fundamental rights requirements, investigating incidents and risks associated with AI use, designating and monitoring notified bodies that conduct conformity assessments, and coordinating with the AIO and other member states to ensure consistent application of the law. They also support transparency by collecting documentation from AI providers and may impose penalties for non-compliance. 2.8 Regulatory sandboxes Until recently, AI sandboxes in the EU existed mainly at the national level, without a harmonised legal framework. EU AI Act15 establishes a framework for regulatory sandboxes requiring all EU Member States to set up at least one regulatory sandbox or participate in cross-border ones by August 2026. The national implementation of regulatory sandboxes is underway. For example, Finland is implementing the EU AI Act through a phased legislative process coordinated by the Ministry of Economic Affairs and Employment (TEM16). The second phase includes the establishment of a national AI regulatory sandbox, a registry for high-risk AI systems, and conformity assessment rules. Finland has opted for decentralised model, where multiple market surveillance authorities oversee AI systems based on their domain (e.g. product safety, transport, medical devices, financial services). Traficom17 acts as the single point of contact coordinating these authorities. The government’s proposal is scheduled to be presented to Parliament in February 2026, with full implementation required by 2 August 2026. In contrast, the Czech Republic has already approved a national framework for AI Act implementation. The Ministry of Industry and Trade coordinates the process, supported by The Czech Telecommunications Office (market regulator), The Office for Technical Standardization (ÚNMZ) (conformity bodies), and The Czech Standards Agency (ČAS), which will manage the AI regulatory sandbox. The Czech model emphasises early coordination and collaboration with the Czech Association 14 https://ai-act-service-desk.ec.europa.eu/en 15 EU 2024/1689, Chapter VI, Articles 57-59 16 TEM091:00/2024 17 Finnish Transport and Communications Agency D2.4 Knowledge base for Trustworthy and Sustainable AI 20 of Artificial Intelligence to promote joint research and knowledge exchange. The sandbox will be operated by ČAS, with ÚNMZ acting as the notifying authority. Regulatory sandboxes provide a controlled environment for the development, training, and validation of innovative AI systems under the supervision of a national competent authority, before being placed on the market. Within these sandboxes, providers can test their products and services in real-world conditions while receiving tailored guidance on regulatory requirements and compliance expectations. Upon completion of the testing phase, the authority issues a final report and written evidence of the testing, which can support the conformity assessment required under the EU AI Act. It is important to note that regulatory sandboxes do not apply to AI systems developed and deployed exclusively for scientific research and development, as these fall outside the scope of the regulation. High-risk AI systems can be tested within sandboxes, but only under controlled conditions and regulatory supervision. EU Member States are also required to promote transparency and cross-border cooperation by sharing insights and lessons learned with stakeholders and the European Commission. This includes submitting both annual and final reports on sandbox activities. These practices may influence which customers choose to engage with LUMI AI Factory and future sandbox initiatives. Currently, LUMI AI Factory is actively identifying customers who may benefit from regulatory sandbox participation and is preparing tailored training and support services. These include AI literacy trainings, introductions to the EU AI Act, and practical guidance on engaging with sandbox environments. In parallel, LUMI AIF is exploring compliant solutions for processing sensitive personal data, in accordance with applicable legislation and customer-specific requirements. The final approach will be determined in due course. 3. Implementation of Knowledge Base 3.1 Trustworthy and Sustainable AI at LUMI AIF As previously outlined, the objective of the LUMI AIF AI governance model and its accompanying Knowledge Base is to strengthen stakeholder trust and foster the AI innovations envisioned by LUMI AI Factory. The model is built on clear ethical foundations, which serve as the basis for the principles and requirements of trustworthy and sustainable AI. This relationship is illustrated in the figure below. D2.4 Knowledge base for Trustworthy and Sustainable AI 21 Figure 4. Trustworthy and Sustainable AI at LUMI AIF The figure presents a structured overview of the foundational elements that define Trustworthy and Sustainable AI, highlighting the interplay between benefits, governance requirements, and ethical principles. At the top, the benefits of implementing responsible AI practices are stated: building trust, enabling innovation, and transforming society, research, and industry. These benefits serve as the overarching goals that guide the development and deployment of AI systems within the LUMI AI Factory ecosystem. The core of the figure is divided into two governance domains: requirements for Trustworthy AI and requirements for Sustainable AI. Trustworthy AI demands attributes such as human agency and oversight, technical robustness and safety, privacy and data governance, transparency, diversity, nondiscrimination and fairness, societal and environmental wellbeing, and accountability. Sustainable AI, on the other hand, emphasises energy efficiency and carbon footprint, resource optimisation, data curation, efficient training, the use of compact, modular, and reusable models, and sustainable partnerships. These governance requirements are grounded in four ethical principles: respect for human autonomy, prevention of harm, fairness and non-discrimination, explainability and transparency. Together, these elements form the ethical and operational foundation of the LUMI AI Factory’s governance model, ensuring that AI systems are developed responsibly and with long-term societal impact in mind. In the LUMI AIF, the ethical principles will be operationalised through seven key requirements that should be met. In addition, technical and non-technical measures will be implemented during the life cycle of an AI system that supports the development of Trustworthy and Sustainable AI. The key requirements and possible ways to implement the requirements are described in the following table. D2.4 Knowledge base for Trustworthy and Sustainable AI 22 Table 2. Key requirements for Trustworthy AI No decisions have yet been made on whether to adopt these requirements or whether to adopt a specific standard, such as ISO/IEC 42001, on which the requirements are based. In addition to ethical integrity, the LUMI AI Factory emphasises sustainability, reflecting the European Union’s digital strategy that promotes high-performance computing (HPC) as a tool for climate action and green innovation18. HPC supports environmental modelling, energy-efficient design, and scientific research aligned with the EU’s goals for climate-neutral digital infrastructure. In the HPC environment, where computational intensity is high, green software engineering helps reduce energy consumption and environmental impact while maintaining performance. While the role of AI in the green transition is recognised, regulation and implementation are still evolving. As mentioned, sustainability is a core principle of the LUMI AI Factory, inherited from the LUMI supercomputer. The approach focuses on two impactful strategies: optimising the data centre infrastructure (bottom-up) and improving how AI workloads are designed and executed (top-down). The LUMI and upcoming LUMI AI supercomputers are hosted in Kajaani, Finland, in a facility powered entirely by renewable hydroelectric energy. The centre uses free cooling and repurposes excess heat to warm up to 20% of local homes, significantly reducing CO₂ emissions. Located in a former paper mill, the site avoids construction-related emissions and benefits from the region’s cool climate, making it both environmentally and economically efficient. Beyond infrastructure, LUMI AI Factory works closely with customers to ensure AI is developed and used sustainably, tailored to real needs. This customer-centric approach would not be possible if LUMI AI Factory were only a hardware provider. 18 European Commission. (2025). High performance computing. Shaping Europe’s digital future. Retrieved October 15, 2025, from https://digital-strategy.ec.europa.eu/en/policies/high-performance-computing D2.4 Knowledge base for Trustworthy and Sustainable AI 23 Importantly, the purpose of AI matters. LUMI’s computing power is directed toward projects with positive environmental impact, such as climate modelling, energy optimisation, and sustainable materials research, setting it apart from many other AI data centres. Sustainable AI in the LUMI AI Factory refers to the responsible and energy-efficient development and deployment of AI technologies, with a strong emphasis on environmental, societal, and ethical sustainability19. The Knowledge Base focuses specifically on how green software engineering can minimise the environmental footprint of AI systems, optimising energy efficiency in HPC environments, and promoting applications that contribute to long-term societal and ecological benefits. By integrating sustainability into its ethical framework, LUMI AI Factory Services ensure that AI supports both responsible innovation and broader climate goals. Although the EU AI Act primarily focuses on risk management, transparency, and ethical standards, it also acknowledges the environmental impact of AI systems. The regulation20 encourages voluntary reporting on the sustainability of AI technologies, such as energy consumption and resource use. However, these provisions are not mandatory, and concerns have been raised about whether voluntary measures alone are sufficient to support the EU’s broader climate and sustainability goals21. The debate around integrating binding environmental requirements into future AI regulation is ongoing. The EU AI Act aims to strike a balance between environmental protection and technological innovation, encouraging responsible development without stifling progress. For instance, developers of GeneralPurpose AI (GPAI) models are encouraged to include technical documentation that estimates energy consumption. If precise figures are unavailable, energy use may be approximated based on computational resources used during model training and deployment. In this context, LUMI AI Factory services could play a leading role by enabling customers to track energy consumption per job or calculate the carbon footprint per model. LUMI AIF services could also offer energy dashboards that visualise usage, align with organisational sustainability goals, and support public reporting of environmental metrics. These tools would not only promote transparency but also help organisations meet their climate commitments while using advanced AI infrastructure The LUMI AI Factory will include sustainability in its core operations by adopting a set of well-defined principles that guide the development and deployment of AI systems. These principles span technical, environmental, and ethical dimensions, ensuring that AI innovation aligns with long-term societal and ecological goals The initial measures of trustworthy and sustainable AI in the LUMI AI Factory context are presented in the following table. 19 United Nations. Sustainable Development Goals. United Nations, https://sdgs.un.org/goals. Accessed 15 Oct. 2025. 20 EU 2024/1689, Article 95(2)(b) 21 European Parliament. (2024, October 7). Artificial intelligence (AI) and energy consumption – Parliamentary question P-001974/2024. Retrieved October 15, 2025, from https://www.europarl.europa.eu/doceo/document/P9-2024-001974_EN.html D2.4 Knowledge base for Trustworthy and Sustainable AI 24 Table 3. The initial measures of Trustworthy and Sustainable AI Beyond infrastructure, LUMI AI Factory will emphasise data minimisation and quality, encouraging the use of curated, representative datasets over large, redundant ones. This is particularly evident in healthcare and mobility projects. For example, energy efficiency by design will be achieved through optimised GPU scheduling and liquid cooling, with metrics such as kilowatt-hour per model epoch and Power Usage Effectiveness (PUE) used to monitor performance. Similarly, resource optimisation will focus on maximising memory and compute efficiency, using tools like Slurm profiling and frameworks such as DeepSpeed and PyTorch Lightning to reduce waste. Model efficiency and compression could be supported through techniques like pruning and quantisation, enabling the deployment of lightweight models with reduced latency. Other principles will include lifecycle transparency, carbon footprint monitoring, and ethical deployment, all of which will be backed by measurable indicators such as reproducibility indexes, CO₂ emissions per training run, and explainability scores. Additionally, LUMI will promote sustainable hardware use and skill-building initiatives, such as the “Green AI Bootcamp,” to foster awareness and responsible computing practices among users. Together, these measures will form a holistic framework for sustainable AI within the LUMI ecosystem. 3.2 Operational environment from a customer’s perspective LUMI AI Factory data environment consists of end user and customer services, data management tools, and data management training and guidance materials. In addition to the computing environment the primary data offering of LUMI AIF is the Dataset-as-a-Service (DaaS). The DaaS is designed to provide curated, high-quality datasets close to high-performance computing resources. This enables innovators, researchers, and industry customers to focus on AI development, rather than acquisition and infrastructure management. Dataset-as-a-Service has thoroughly been described in the deliverable D5.2 Dataset as a Service. D2.4 Knowledge base for Trustworthy and Sustainable AI 25 The LUMI AI Factory Knowledge Base will include a comprehensive set of resources to support trustworthy and sustainable use of datasets throughout the AI lifecycle. These materials will focus on secure processing environments for handling sensitive data, including guidance on confidential computing, encryption standards, and access control mechanisms. Privacy-preserving techniques such as differential privacy, federated learning, and synthetic data generation will be covered through tutorials, case studies, and implementation guides. To ensure transparency and accountability, the Knowledge Base will also provide tools and templates for documenting data provenance, lineage, and traceability, enabling users to track how datasets are sourced, transformed, and used in AI development. In addition to technical resources, the Knowledge Base will offer services that support legal and ethical compliance. These include materials on intellectual property rights and copyright management, such as licensing frameworks and data usage agreements. Users will also have access to checklists and frameworks aligned with the EU AI Act and ISO/IEC 42001, helping them assess risks related to bias, fairness, and representativeness. LUMI AI Factory will complement these resources with expert consultations, training programs, and lifecycle assessments of datasets, ensuring that AI solutions built on DaaS are not only high performing but also ethically sound and legally compliant. The following diagram illustrates a comprehensive Knowledge Base ecosystem designed to support users throughout the AI development lifecycle. Figure 5. Operational environment from a customer’s point of view At the core is the User Portal (MyEFP), which serves as the central access point to a wide range of services. These include training programs, user guides, and a help desk, all aimed at enhancing AI literacy and providing practical support. This ensures that users are not only equipped with technical skills but also understand ethical and regulatory requirements. The portal also facilitates access to Dataset-as-aService (DaaS) components, such as a data catalogue for discovering datasets, a data permit system for