de
All articles

[ regulation × ai ]

The EU AI Act: what it is and what it means for your company.

14 minutesLegal status August 2026

Since 2 August 2026 the AI Act applies in full as a matter of principle. Six days earlier, the EU postponed its strictest deadlines by up to 16 months. What follows for an individual company comes down to two questions: what the AI is used for, and in which role.

[ in three sentences ]

Rarely high risk

Writing assistance, document processing, scheduling, forecasting, quality inspection: lowest tier, no specific obligations.

Due now

Label chatbots as such, make AI-generated content recognisable, build AI literacy in a way you can evidence.

Can wait

Everything around high-risk systems. That starts in December 2027 and August 2028 respectively.

[ context ]

A regulation, not a national law.

The AI Act is an EU regulation, not a directive and not a national law. That is not a legal footnote, it has three practical consequences.

It applies directly.

No national implementing act is needed and there is no additional transposition period. The dates are set out in Art. 113 of the regulation itself.

It applies the same across Europe.

Unlike a directive it does not produce 27 national variants. There is no location advantage to be gained by moving.

National laws only govern execution.

The German implementing act, KI-MIG, assigns responsibilities and procedures. It creates no obligations of its own.

Anyone waiting for a national AI law before starting is waiting for nothing. The substance is already settled.

[ who is covered ]

Does this even apply to us?

If AI systems are used professionally in your organisation: yes. Regardless of sector, legal form and size. There is no threshold below which the regulation does not apply. Companies of every kind, freelancers, associations and public bodies are covered alike.

That includes anyone who merely buys and uses AI. Whoever runs ChatGPT, Copilot or an AI module inside their industry software is a deployer within the meaning of the regulation.

The scope of the obligations, however, differs dramatically. That is what the following sections are about.

[ risk tiers ]

Four tiers with very different consequences.

The role decides.

Whoever buys and uses AI is a deployer and carries a lean set of obligations. Whoever passes a system on under their own name, modifies it substantially or changes its intended purpose becomes a provider under Art. 25 and carries the full programme. This is the most common way an organisation slips into a higher tier without meaning to.

Unacceptable

examples

Social scoring, emotion recognition in the workplace, biometric categorisation by sensitive attributes

consequence

Prohibited since February 2025

High

examples

Candidate screening, creditworthiness assessment, AI in medical devices, admission decisions in education

consequence

Full set of obligations from December 2027 or August 2028

Limited

examples

Chatbot on the website, voicebot on the phone, AI-generated text and images

consequence

Transparency obligations since August 2026

Minimal

examples

Spam filters, spell checking, recommender systems, forecasting models

consequence

No specific obligations

[ annex iii ]

Our use case is not in Annex III. Are we in the clear?

As far as high-risk status goes, usually yes. Annex III is an exhaustive list of eight application areas: biometrics, critical infrastructure, education, employment, essential private and public services, law enforcement, migration, and justice and democratic processes. Classification is not a judgement call, it is a lookup. Candidate screening is high risk regardless of how carefully or casually anyone handles it.

Four things are still worth checking.

  1. 01Annex III describes functions, not products.HR software is not listed, systems for the selection or evaluation of candidates are. A ranking module inside an otherwise unremarkable tool is enough.
  2. 02There is a second route through Annex I.AI as a safety component in products that already carry CE conformity assessment: machinery, medical devices, lifts, vehicles, toys.
  3. 03Not high risk does not mean no obligations.The prohibitions under Art. 5, AI literacy under Art. 4 and transparency under Art. 50 apply regardless of the risk tier.
  4. 04The list can grow.The Commission can extend Annex III by delegated act, and a use case can grow into it through a changed intended purpose.

The exemption under Art. 6(3)

The reverse also holds: a system from an Annex III area is not high risk after all if it only performs a narrow procedural task, improves the result of completed human work or is purely preparatory. Anyone relying on this must document the assessment and still register the system in the EU database.

[ classification ]

How does the AI Act affect your company?

Five questions about role and use case, and a sixth where it is needed. At the end you get a classification, the measures that follow and your deadlines, traceable along the articles that matter. Nothing you enter is stored or transmitted.

Question 1 of 5

In which role does your organisation use AI?

The role decides the scope of every further obligation. It can differ per system, so answer for the case you are checking right now.

This assessment follows the structure of Regulation (EU) 2024/1689 as amended by the Digital Omnibus Regulation (EU) 2026/1744 and does not replace legal advice.

[ deadlines ]

The timeline.

  1. 02.02.2025

    Prohibited practices under Art. 5 and AI literacy under Art. 4

  2. 02.08.2025

    Obligations for providers of general-purpose models, plus the penalty framework

  3. 02.08.2026

    General application: transparency obligations under Art. 50, enforcement begins

  4. 02.12.2026

    Labelling of pre-existing generative systems, plus two new prohibitions

  5. 02.12.2027

    High-risk systems under Annex III

    moved from August 2026

  6. 02.08.2028

    High-risk systems under Annex I

    moved from August 2027

Postponed by the Digital Omnibus Regulation (EU) 2026/1744, in force since 27 July 2026. The reason was not a political retreat but a practical problem: the technical standards for conformity assessment were not ready.

In Germany, supervision sits with the Bundesnetzagentur as the central market surveillance authority, with KoKIVO as a free point of contact. Sector regulators BaFin, BfArM, BSI and the data protection authorities remain responsible in their fields.

[ action plan ]

Which measures to take now.

These six steps build on one another. Without the first, the second cannot be answered.

  1. 01Build an AI inventoryRecord every system in use, including the AI features already sitting inside CRM, ERP, ticketing and industry software. Without an inventory, every further assessment is guesswork.
  2. 02Determine the roleDeployer or provider, and per system. The role decides the scope of every further obligation.
  3. 03Rule out prohibited practicesAbove all emotion recognition in the employment context and biometric categorisation by sensitive attributes.
  4. 04Implement transparencyChatbot notices and labelling of generated content. For systems already in use, the deadline ends on 2 December 2026.
  5. 05Build and document AI literacyDifferentiated by role, with content, audience, date and attendance on record.
  6. 06Start on high-risk candidates early16 months are an implementation window, not a pause. Starting in 2027 wastes the extension.

[ art. 4 ]

When is someone sufficiently trained?

There is no required number of hours, no curriculum and no certification duty. The benchmark is context: the riskier the use, the higher the bar.

One point from the European Commission's FAQ matters here. Penalties are above all likely where an incident demonstrably traces back to insufficient training. Art. 4 therefore works as a burden-of-proof rule once damage occurs. The question is not whether four hours were completed, but whether this person, with this training, could have avoided the mistake.

In practice: differentiate by role, document content and attendance, and refresh whenever tools change.

[ monitoring ]

What has to be reported, and what does not.

The reporting duty under Art. 73 falls on providers, not deployers, and only for high-risk systems. Deployer obligations sit in Art. 26 and start in December 2027.

An example: a general-purpose assistant such as Copilot is not a high-risk system. For the deployer, Art. 4, Art. 5 and Art. 50 apply, and nothing else. Conspicuous or disadvantageous outputs trigger no reporting duty under the AI Act and no duty to produce logs.

What counts instead:

Worth doing voluntarily, for quality rather than compliance reasons: track usage, because it surfaces shadow AI. Watch for purpose drift. Follow the provider's model changes. Sample outputs wherever an application touches individuals or reaches the outside world.

[ implementation ]

Three artefacts and one owner.

An inventory

A table with purpose, system, provider, people affected, role, risk tier and owner.

An AI policy

Two to four pages: what is permitted, which data goes into which systems, who approves, how to report.

A training record

Date, content, attendance list. Art. 4 asks for no more, and less will not do.

A named person

Someone who maintains the inventory and runs approvals. An AI officer is not mandated.

No particular governance structure is prescribed. What is required is a chain without gaps.

  1. Inventory
  2. Role classification
  3. Approval process
  4. Training record
  5. Reporting path
  6. Quarterly review

Two things get expensive later if they are left now: updating contracts, meaning role allocation and liability for bought-in systems, and involving the works council. §§ 87 and 90 BetrVG apply independently of every AI Act deadline.

[ misconceptions ]

Three sentences you hear often.

claim

The Omnibus postponed everything.

in fact

Only the high-risk deadlines moved. Transparency, literacy and the prohibitions apply unchanged.

claim

We have to monitor every AI system and report incidents.

in fact

No. Those duties hang on high-risk classification and mostly fall on providers.

claim

The fine is our biggest risk.

in fact

In practice, warning letters over missing AI labelling, data protection complaints and contractual liability matter more.

[ conclusion ]

The benefit remains the benchmark.

The real loss rarely comes from regulation. It comes from hesitation: from pilots that never reach production because nobody takes responsibility for the step.

A settled framework is exactly what helps against that. Knowing which systems are in use, who is responsible and where the limits run means you can experiment more freely, not less. Compliance is not an end in itself here, it is the condition under which an experiment becomes a productive system.

[ sources ]

Further reading.

The consolidated version on EUR-Lex does not yet reflect the Digital Omnibus amendments. For now, both texts have to be read side by side.

Legal status August 2026. This post is orientation, not legal advice. Only the texts published in the Official Journal of the EU are authoritative.