[ regulation × ai ]
The EU AI Act: what it is and what it means for your company.
14 minutesLegal status August 2026
Since 2 August 2026 the AI Act applies in full as a matter of principle. Six days earlier, the EU postponed its strictest deadlines by up to 16 months. What follows for an individual company comes down to two questions: what the AI is used for, and in which role.
[ in three sentences ]
Rarely high risk
Writing assistance, document processing, scheduling, forecasting, quality inspection: lowest tier, no specific obligations.
Due now
Label chatbots as such, make AI-generated content recognisable, build AI literacy in a way you can evidence.
Can wait
Everything around high-risk systems. That starts in December 2027 and August 2028 respectively.
[ context ]
A regulation, not a national law.
The AI Act is an EU regulation, not a directive and not a national law. That is not a legal footnote, it has three practical consequences.
It applies directly.
No national implementing act is needed and there is no additional transposition period. The dates are set out in Art. 113 of the regulation itself.
It applies the same across Europe.
Unlike a directive it does not produce 27 national variants. There is no location advantage to be gained by moving.
National laws only govern execution.
The German implementing act, KI-MIG, assigns responsibilities and procedures. It creates no obligations of its own.
Anyone waiting for a national AI law before starting is waiting for nothing. The substance is already settled.
[ who is covered ]
Does this even apply to us?
If AI systems are used professionally in your organisation: yes. Regardless of sector, legal form and size. There is no threshold below which the regulation does not apply. Companies of every kind, freelancers, associations and public bodies are covered alike.
That includes anyone who merely buys and uses AI. Whoever runs ChatGPT, Copilot or an AI module inside their industry software is a deployer within the meaning of the regulation.
The scope of the obligations, however, differs dramatically. That is what the following sections are about.
[ risk tiers ]
Four tiers with very different consequences.
The role decides.
Whoever buys and uses AI is a deployer and carries a lean set of obligations. Whoever passes a system on under their own name, modifies it substantially or changes its intended purpose becomes a provider under Art. 25 and carries the full programme. This is the most common way an organisation slips into a higher tier without meaning to.
Unacceptable
examples
Social scoring, emotion recognition in the workplace, biometric categorisation by sensitive attributes
consequence
Prohibited since February 2025
High
examples
Candidate screening, creditworthiness assessment, AI in medical devices, admission decisions in education
consequence
Full set of obligations from December 2027 or August 2028
Limited
examples
Chatbot on the website, voicebot on the phone, AI-generated text and images
consequence
Transparency obligations since August 2026
Minimal
examples
Spam filters, spell checking, recommender systems, forecasting models
consequence
No specific obligations
[ annex iii ]
Our use case is not in Annex III. Are we in the clear?
As far as high-risk status goes, usually yes. Annex III is an exhaustive list of eight application areas: biometrics, critical infrastructure, education, employment, essential private and public services, law enforcement, migration, and justice and democratic processes. Classification is not a judgement call, it is a lookup. Candidate screening is high risk regardless of how carefully or casually anyone handles it.
Four things are still worth checking.
- 01Annex III describes functions, not products.HR software is not listed, systems for the selection or evaluation of candidates are. A ranking module inside an otherwise unremarkable tool is enough.
- 02There is a second route through Annex I.AI as a safety component in products that already carry CE conformity assessment: machinery, medical devices, lifts, vehicles, toys.
- 03Not high risk does not mean no obligations.The prohibitions under Art. 5, AI literacy under Art. 4 and transparency under Art. 50 apply regardless of the risk tier.
- 04The list can grow.The Commission can extend Annex III by delegated act, and a use case can grow into it through a changed intended purpose.
The exemption under Art. 6(3)
The reverse also holds: a system from an Annex III area is not high risk after all if it only performs a narrow procedural task, improves the result of completed human work or is purely preparatory. Anyone relying on this must document the assessment and still register the system in the EU database.
[ classification ]
How does the AI Act affect your company?
Five questions about role and use case, and a sixth where it is needed. At the end you get a classification, the measures that follow and your deadlines, traceable along the articles that matter. Nothing you enter is stored or transmitted.
Question 1 of 5
In which role does your organisation use AI?
The role decides the scope of every further obligation. It can differ per system, so answer for the case you are checking right now.
This assessment follows the structure of Regulation (EU) 2024/1689 as amended by the Digital Omnibus Regulation (EU) 2026/1744 and does not replace legal advice.
[ deadlines ]
The timeline.
02.02.2025
Prohibited practices under Art. 5 and AI literacy under Art. 4
02.08.2025
Obligations for providers of general-purpose models, plus the penalty framework
02.08.2026
General application: transparency obligations under Art. 50, enforcement begins
02.12.2026
Labelling of pre-existing generative systems, plus two new prohibitions
02.12.2027
High-risk systems under Annex III
moved from August 2026
02.08.2028
High-risk systems under Annex I
moved from August 2027
Postponed by the Digital Omnibus Regulation (EU) 2026/1744, in force since 27 July 2026. The reason was not a political retreat but a practical problem: the technical standards for conformity assessment were not ready.
In Germany, supervision sits with the Bundesnetzagentur as the central market surveillance authority, with KoKIVO as a free point of contact. Sector regulators BaFin, BfArM, BSI and the data protection authorities remain responsible in their fields.
[ action plan ]
Which measures to take now.
These six steps build on one another. Without the first, the second cannot be answered.
- 01Build an AI inventoryRecord every system in use, including the AI features already sitting inside CRM, ERP, ticketing and industry software. Without an inventory, every further assessment is guesswork.
- 02Determine the roleDeployer or provider, and per system. The role decides the scope of every further obligation.
- 03Rule out prohibited practicesAbove all emotion recognition in the employment context and biometric categorisation by sensitive attributes.
- 04Implement transparencyChatbot notices and labelling of generated content. For systems already in use, the deadline ends on 2 December 2026.
- 05Build and document AI literacyDifferentiated by role, with content, audience, date and attendance on record.
- 06Start on high-risk candidates early16 months are an implementation window, not a pause. Starting in 2027 wastes the extension.
[ art. 4 ]
When is someone sufficiently trained?
There is no required number of hours, no curriculum and no certification duty. The benchmark is context: the riskier the use, the higher the bar.
One point from the European Commission's FAQ matters here. Penalties are above all likely where an incident demonstrably traces back to insufficient training. Art. 4 therefore works as a burden-of-proof rule once damage occurs. The question is not whether four hours were completed, but whether this person, with this training, could have avoided the mistake.
In practice: differentiate by role, document content and attendance, and refresh whenever tools change.
[ monitoring ]
What has to be reported, and what does not.
The reporting duty under Art. 73 falls on providers, not deployers, and only for high-risk systems. Deployer obligations sit in Art. 26 and start in December 2027.
An example: a general-purpose assistant such as Copilot is not a high-risk system. For the deployer, Art. 4, Art. 5 and Art. 50 apply, and nothing else. Conspicuous or disadvantageous outputs trigger no reporting duty under the AI Act and no duty to produce logs.
What counts instead:
- Art. 25 flips the roleas soon as a standard tool is put to an Annex III purpose.
- Discrimination liability exists anywaythrough the German equal treatment act AGG with its eased burden of proof in § 22, through Art. 22 GDPR and through § 87(1) no. 6 of the works constitution act BetrVG. These claims do not need the AI Act.
- Check how long logs are keptFrom December 2027, deployers of high-risk systems must retain automatically generated logs for at least six months, insofar as those logs are under their control. The default setting of common cloud platforms is often shorter.
Worth doing voluntarily, for quality rather than compliance reasons: track usage, because it surfaces shadow AI. Watch for purpose drift. Follow the provider's model changes. Sample outputs wherever an application touches individuals or reaches the outside world.
[ implementation ]
Three artefacts and one owner.
An inventory
A table with purpose, system, provider, people affected, role, risk tier and owner.
An AI policy
Two to four pages: what is permitted, which data goes into which systems, who approves, how to report.
A training record
Date, content, attendance list. Art. 4 asks for no more, and less will not do.
A named person
Someone who maintains the inventory and runs approvals. An AI officer is not mandated.
No particular governance structure is prescribed. What is required is a chain without gaps.
- Inventory
- Role classification
- Approval process
- Training record
- Reporting path
- Quarterly review
Two things get expensive later if they are left now: updating contracts, meaning role allocation and liability for bought-in systems, and involving the works council. §§ 87 and 90 BetrVG apply independently of every AI Act deadline.
[ misconceptions ]
Three sentences you hear often.
claim
The Omnibus postponed everything.
in fact
Only the high-risk deadlines moved. Transparency, literacy and the prohibitions apply unchanged.
claim
We have to monitor every AI system and report incidents.
in fact
No. Those duties hang on high-risk classification and mostly fall on providers.
claim
The fine is our biggest risk.
in fact
In practice, warning letters over missing AI labelling, data protection complaints and contractual liability matter more.
[ conclusion ]
The benefit remains the benchmark.
The real loss rarely comes from regulation. It comes from hesitation: from pilots that never reach production because nobody takes responsibility for the step.
A settled framework is exactly what helps against that. Knowing which systems are in use, who is responsible and where the limits run means you can experiment more freely, not less. Compliance is not an end in itself here, it is the condition under which an experiment becomes a productive system.
[ sources ]
Further reading.
- Regulation (EU) 2024/1689, full text on EUR-Lex
Annex I and Annex III are at the end of the document.
- Annex III: the high-risk application areas in detail
Edited version with cross references.
- Digital Omnibus Regulation (EU) 2026/1744
The regulation that moved the high-risk deadlines.
- European Commission FAQ on AI literacy under Art. 4
The source for the benchmark training is measured against.
The consolidated version on EUR-Lex does not yet reflect the Digital Omnibus amendments. For now, both texts have to be read side by side.
Legal status August 2026. This post is orientation, not legal advice. Only the texts published in the Official Journal of the EU are authoritative.