de
All articles

[ regulation × ai ]

The EU AI Act: what it is and what it means for your company.

12 minutesLegal status August 2026

Since 2 August 2026 the AI Act applies in full as a matter of principle. Six days earlier, the EU postponed its strictest deadlines by up to 16 months. What follows for an individual company comes down to two questions: what the AI is used for, and in which role.

[ in three sentences ]

Rarely high risk

Writing assistance, document processing, scheduling, forecasting, quality inspection: lowest tier, no specific obligations.

Due now

Label chatbots as such, make AI-generated content recognizable, build AI literacy in a way you can evidence.

Use the time gained

High-risk systems have until December 2027 or August 2028. Until then, the inventory, role classification, risk management, and technical documentation have to be built.

[ context ]

A regulation, not a national law.

The AI Act is an EU regulation, not a directive and not a national law. That is not a legal footnote; it has three practical consequences.

It applies directly.

No national implementing act is needed and there is no additional transposition period. The dates are set out in Art. 113 of the regulation itself.

It applies the same across Europe.

Unlike a directive it does not produce 27 national variants. There is no location advantage to be gained by moving.

National laws only govern execution.

The German implementing act, KI-MIG, assigns responsibilities and procedures. It creates no obligations of its own.

[ who is covered ]

Are we affected?

If AI systems are used professionally in your organization: yes. Regardless of sector, legal form, and size. There is no threshold below which the regulation does not apply. Companies of every kind, freelancers, associations, and public bodies are covered alike.

That includes anyone who merely buys and uses AI. Anyone running ChatGPT, Copilot or an AI module inside their industry software is a deployer within the meaning of the regulation.

The scope of the obligations, however, differs dramatically. That is what the following sections are about.

[ risk tiers ]

Four risk classes with different consequences.

Unacceptable

examples

Social scoring, emotion recognition in the workplace, biometric categorization by sensitive attributes

consequence

Prohibited since February 2025

High

examples

Candidate screening, creditworthiness assessment, AI in medical devices, admission decisions in education

consequence

Full set of obligations from December 2027 or August 2028

Limited

examples

Chatbot on the website, voicebot on the phone, AI-generated text and images

consequence

Transparency obligations since August 2026

Minimal

examples

Spam filters, spell checking, recommender systems, forecasting models

consequence

No specific obligations

Monitoring and reporting hang on this classification alone.

Reporting serious incidents under Art. 73 falls on providers of high-risk systems. Their deployers monitor operation and notify the provider, which is Art. 26 and applies from December 2027. Outside the high-risk class, the AI Act creates neither a monitoring nor a reporting duty.

An example: a general-purpose assistant such as Copilot is not a high-risk system. For the deployer, Art. 4, Art. 5 and Art. 50 apply, and nothing else. Conspicuous or disadvantageous outputs trigger no reporting duty under the AI Act and no duty to produce logs.

The role decides.

Anyone who buys and uses AI is a deployer and carries a lean set of obligations. Anyone who passes a system on under their own name, modifies it substantially or changes its intended purpose becomes a provider under Art. 25 and carries the full program. This is the most common way an organization slips into a higher class without meaning to, typically when a standard tool is put to an Annex III purpose.

[ annex i & iii ]

Where high risk is written down.

Whether a system counts as high risk is not a judgment call. The regulation writes it down in two places. The first route runs through Annex I: it lists the EU rules governing products such as machinery, medical devices, lifts, vehicles, and toys. If AI sits inside such a product as a safety component, it is high risk. The second route runs through Annex III: a list of application areas, regardless of which product the AI works in. For most companies, this second route is the decisive one.

Our use case is not in Annex III. Are we in the clear?

As far as high-risk status goes, usually yes. Annex III is an exhaustive list of eight application areas: biometrics, critical infrastructure, education, employment, essential private and public services, law enforcement, migration, and justice and democratic processes. Classification is not a judgment call; it is a lookup. Candidate screening is high risk regardless of how carefully or casually anyone handles it.

Four things are still worth checking.

  1. 01Annex III describes functions, not products.HR software is not listed, systems for the selection or evaluation of candidates are. A ranking module inside an otherwise unremarkable tool is enough.
  2. 02There is a second route through Annex I.AI as a safety component in products that already carry CE conformity assessment: machinery, medical devices, lifts, vehicles, toys.
  3. 03Not high risk does not mean no obligations.The prohibitions under Art. 5, AI literacy under Art. 4, and transparency under Art. 50 apply regardless of the risk tier.
  4. 04The list can grow.The Commission can extend Annex III by delegated act, and a use case can grow into it through a changed intended purpose.

The exemption under Art. 6(3)

The reverse also holds: a system from an Annex III area is not high risk after all if it only performs a narrow procedural task, improves the result of completed human work or is purely preparatory. Anyone relying on this must document the assessment and still register the system in the EU database.

[ classification ]

How does the AI Act affect your company?

Five questions about role and use case, and a sixth where it is needed. At the end you get a classification, the measures that follow, and your deadlines, traceable along the articles that matter. Nothing you enter is stored or transmitted.

Question 1 of 5

In which role does your organization use AI?

The role decides the scope of every further obligation. It can differ per system, so answer for the case you are checking right now.

This assessment follows the structure of Regulation (EU) 2024/1689 as amended by the Digital Omnibus Regulation (EU) 2026/1744 and does not replace legal advice.

[ deadlines ]

The timeline.

02.02.2025

Prohibited practices under Art. 5 and AI literacy under Art. 4

02.08.2025

Obligations for providers of general-purpose models, plus the penalty framework

02.08.2026

General application: transparency obligations under Art. 50, enforcement begins

02.12.2026

Labelling of pre-existing generative systems, plus two new prohibitions

02.12.2027

High-risk systems under Annex III

moved from August 2026

02.08.2028

High-risk systems under Annex I

moved from August 2027

Postponed by the Digital Omnibus Regulation (EU) 2026/1744, in force since 27 July 2026. The reason was not a political retreat but a practical problem: the technical standards for conformity assessment were not ready.

In Germany, supervision sits with the Bundesnetzagentur as the central market surveillance authority, with KoKIVO as a free point of contact. Sector regulators BaFin, BfArM, BSI, and the data protection authorities remain responsible in their fields.

[ action plan ]

Which measures to take now.

These six steps build on one another. Without the first, the second cannot be answered.

  1. 01Build an AI inventoryRecord every system in use, including the AI features already sitting inside CRM, ERP, ticketing, and industry software. Without an inventory, every further assessment is guesswork.
  2. 02Determine the roleDeployer or provider, and per system. The role decides the scope of every further obligation.
  3. 03Rule out prohibited practicesAbove all emotion recognition in the employment context and biometric categorization by sensitive attributes.
  4. 04Implement transparencyChatbot notices and labeling of generated content. For systems already in use, the deadline ends on 2 December 2026.
  5. 05Build and document AI literacyDifferentiated by role, with content, audience, date, and attendance on record.
  6. 06Start on high-risk candidates early16 months are an implementation window, not a pause. Logging belongs here too: deployers must retain automatically generated logs for at least six months, insofar as those logs are under their control. The default setting of common cloud platforms is often shorter.

[ art. 4 ]

When is someone sufficiently trained?

There is no required number of hours, no curriculum, and no certification duty. The benchmark is context: the riskier the use, the higher the bar.

One point from the European Commission's FAQ matters here. Penalties are above all likely where an incident demonstrably traces back to insufficient training. Art. 4 therefore works as a burden-of-proof rule once damage occurs. The question is not whether four hours were completed, but whether this person, with this training, could have avoided the mistake.

In practice: differentiate by role, document content and attendance, and refresh whenever tools change.

[ conclusion ]

How to put your company on safe ground.

No particular governance structure is prescribed. What is required is a chain without gaps, and it rests on four artifacts.

An inventory

A table with purpose, system, provider, people affected, role, risk tier, and owner.

An AI policy

Two to four pages: what is permitted, which data goes into which systems, who approves, how to report.

A training record

Date, content, attendance list. Art. 4 asks for no more, and less will not do.

A named person

Someone who maintains the inventory and runs approvals. An AI officer is not mandated.

[ next step ]

Let us put your use of AI on safe ground.

Take the inventory, determine the role per system, assign the obligations, and put what is open into an order that fits your day-to-day business. After that it is settled what actually concerns you and what does not.

The real loss rarely comes from regulation. It comes from hesitation: from pilots that never reach production because nobody takes responsibility for the step. A settled framework makes experimenting freer, not narrower.

[ sources ]

Further reading.

The consolidated version on EUR-Lex does not yet reflect the Digital Omnibus amendments. For now, both texts have to be read side by side.

Legal status August 2026. This post is orientation, not legal advice. Only the texts published in the Official Journal of the EU are authoritative.