EU AI Act: Everything companies need to know now

EU AI Act [Image content created with AI]

The EU AI Act is no longer a future issue. The first obligations already apply, others will follow on a staggered schedule. For companies, it’s not just whether they develop AI themselves that counts. Anyone who uses chatbots, applicant management, image generators, forecast models or AI functions in standard software can also be recorded as a provider, operator, importer or dealer.

This guide explains the current legal status after the adjustments decided in 2026, classifies the risk classes and shows which steps companies should now implement in practice. It does not replace legal advice, but provides a reliable basis for inventory, risk assessment and internal responsibilities.

The most important thing in brief

  • The EU AI Act does not only apply to AI developers. It also affects companies that use AI systems professionally.
  • Bans on certain AI practices and the obligation to have appropriate AI competence have been in effect since thenFebruary 2, 2025.
  • Rules for general purpose models, brieflyGPAI, have largely been in effect since thenAugust 2, 2025.
  • After the adjustment decided in 2026, new deadlines apply: transparency solutions for artificially generated contentDecember 2, 2026, standalone high-risk AIDecember 2, 2027and product-integrated high-risk AIAugust 2, 2028.
  • Prohibited practices can result in fines of up to35 million euros or 7 percent of global annual salesthreaten.
  • The most sensible starting point is a complete AI inventory with purpose, provider, data types, data subjects and responsible parties.

Short answer: What do companies need to do now?

Companies should record all AI systems used, determine their role and risk class, train employees according to risk, exclude prohibited applications and build evidence on selection, operation, data protection, human control and transparency. If you only start shortly before the respective deadline, you will be under time pressure, especially with contracts, technical documentation and supplier information.

What is the EU AI Act?

The EU AI Act is the European AI regulation, officially Regulation (EU) 2024/1689. It creates a uniform legal framework for the development, provision, import, distribution and use of AI systems in the European Union. The approach is risk-based: the greater the possible risk to health, safety or fundamental rights, the stricter the requirements.

The regulation does not first ask whether software appears spectacular or particularly technically complex. Function, context of use and possible consequences are decisive. A text assistant for internal idea collections usually falls into a different area than a system that pre-sorts applicants, assesses creditworthiness or influences access to education.

The EU AI Act pursues two goals at the same time. People should be protected from manipulative, discriminatory or unsafe AI applications. At the same time, a reliable internal market should be created in which companies know which rules apply. It is precisely this combination that makes the legal framework relevant for management, IT, data protection, human resources, purchasing, product development and compliance.

Anyone who is concerned with the social consequences will find this in the topic areaEthics and artificial intelligencefurther backgrounds. The category brings together technical developments and new toolsArtificial intelligence.

EU AI Act: Current deadlines and schedule 2026 to 2028

The original schedule was adjusted in 2026 by the Digital Omnibus. That’s why there are still many overviews circulating online with deadlines that are now outdated. For corporate planning, a distinction should be made between obligations that already apply, the new transparency deadlines and the postponed rules for high-risk AI.

Date Regulatory area Practical significance
August 1, 2024 Come into effect The AI ​​Regulation is applicable EU law, but will become applicable gradually.
February 2, 2025 Bans and AI competence Certain AI practices are prohibited. Providers and operators must ensure appropriate AI competence.
August 2, 2025 GPAI, governance and sanctions Essential obligations for providers of general-purpose models apply.
December 2, 2026 AI content transparency solutions Providers must implement the adapted requirements for the identification and recognizability of artificially generated content. New bans on non-consensual sexualized deepfakes are also taking effect.
August 2, 2027 National AI real-world laboratories Latest date for the responsible national authorities to set up the planned real-world laboratories.
December 2, 2027 Standalone high-risk AI Requirements for stand-alone high-risk systems, such as personnel, education or critical access decisions, become applicable.
August 2, 2028 Product-integrated high-risk AI Rules apply to high-risk AI embedded in regulated products unless a more specific transitional rule applies.

Practical note:A postponed deadline is not an invitation to wait. Contract addenda, supplier records, data governance, technical documentation, logging and human supervision can rarely be set up cleanly in a few weeks.

Source for the changed schedule:Council of the European Union: final adoption of the simplified AI rules.

Which risk classes does the EU AI Act recognize?

The often-quoted division into four risk levels is a useful working model. Legally, however, we need to take a closer look: Prohibited practices, high-risk systems and special transparency obligations follow different regulations. Models with a general purpose also form their own regulatory area.

category Typical examples Consequence
Unacceptable risk Manipulative systems with significant potential for damage, social scoring, certain biometric or emotion recognition applications Basically prohibited, only narrow legal exceptions
High risk Staffing decisions, education, critical infrastructure, certain medical devices, access to essential services Extensive requirements for risk, data and quality management
Transparency risk Chatbots, deepfakes, synthetic media, specific emotion recognition or biometric categorization Information, labeling and recognizability obligations
Minimal or low risk Spam filters, simple recommendation systems, AI in games, internal assistance functions without sensitive decision-making power No special high-risk obligations, other laws still apply

Why the specific intended use is crucial

The same basic model can be classified very differently depending on its use. A language model that designs product descriptions is not automatically high-risk AI. However, if an application based on this is used to pre-select applicants, it may fall into the high-risk area. Companies must therefore not only document the product name, but also the actual purpose, the people affected and the decision-making chain.

A good classification answers five questions: What does the system do? Who is affected? What decision is being prepared or made? Can a human intervene effectively? What damage would realistically occur in the event of errors, distortions or misuse?

Which AI applications are banned?

The bans have been in force since February 2, 2025. They are directed against applications whose risks to freedom, dignity, security or fundamental rights are considered unacceptable. Companies should place this review at the very beginning of their AI approval process. A better privacy policy or additional training does not make a banned system legal.

Key prohibited practices include:

  • targeted manipulative or subliminally influencing techniques if this threatens to cause significant damage;
  • the exploitation of special needs of protection due to age, disability or social and economic situation;
  • Social scoring that unfairly disadvantages people based on their behavior or attributed characteristics;
  • individual predictions of criminal behavior when based solely on profiling or personality characteristics;
  • the untargeted reading of facial images from the Internet or from surveillance cameras to build facial databases;
  • Emotion recognition in the workplace and in educational institutions, unless a narrow medical or safety-related exception applies;
  • biometric categorization, which is used to derive particularly sensitive characteristics;
  • real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, except in narrowly defined exceptional cases.

With the change decided in 2026, further bans will be added from December 2026. They concern AI systems that produce non-consensual sexualized or intimate depictions of real people, as well as depictions of child sexual abuse. This creates a clear additional testing area for platforms, image services and providers of generative tools.

An official overview is provided by theFederal Network Agency on prohibited AI practices.

Provider, operator or dealer: What is the role of your company?

Many misassessments begin with the sentence: “We’re not developing AI at all.” That falls short. The AI ​​regulation distributes obligations along the value chain. A company can even have multiple roles at the same time.

role When it typically occurs Example
Provider The company develops an AI system or has it developed and markets it under its own name. A software company sells its own AI-supported applicant tool.
operator The company uses an AI system on its own responsibility in a professional context. A human resources department uses an external screening system.
importer An EU-based company brings an AI system from a third-country provider onto the EU market. A German distributor is introducing an AI camera from an Asian manufacturer.
Dealer The company provides an AI system in the supply chain without being a supplier or importer itself. A specialist retailer sells an AI solution that has already been introduced.
Product manufacturer An AI system is placed on the market together with a regulated product under the name of the manufacturer. A manufacturer integrates AI into a medical device or safety component.

When an operator can become a provider

Own labels, significant changes and new purposes are particularly sensitive. Anyone who offers a third-party system under their own name, changes it substantially or uses it for another high-risk purpose can legally slip into the role of provider. Then the obligations increase significantly. This question therefore belongs in every procurement and change process.

AI competence has been mandatory since February 2025

Providers and operators must do their best to ensure that employees and other appointed persons have an appropriate level of AI competence. This applies regardless of industry and company size. This can also include the use of common chatbots or AI functions in office software.

What a robust AI training course should cover

  • Functionality and limitations of the systems used;
  • Hallucinations, distortions and typical misapplications;
  • Handling personal, confidential and proprietary data;
  • permissible and impermissible applications in the company;
  • human control, escalation and incident reporting;
  • Labeling requirements for artificially generated content;
  • Role-related requirements for purchasing, IT, HR, marketing and product teams.

The regulation does not require rigid standard training. External certification or a formally named AI representative are also not generally mandatory. However, the Federal Network Agency recommends documenting measures in a comprehensible manner. What makes sense is the date, target group, content, duration, responsible person and proof of participation. For high-risk applications, a general one-hour introduction is hardly enough.

Official orientation:Federal Network Agency on AI competence according to Article 4.

High-risk AI: When the strictest corporate obligations apply

High-risk AI is not automatically “dangerous AI.” This refers to systems whose errors or misuse can have a particularly serious impact on people, security or fundamental rights. The regulation distinguishes between product-related high-risk systems and independent applications in explicitly mentioned areas of life.

Typical areas of standalone high-risk AI

  • biometric identification and categorization in regulated cases;
  • Management and operation of critical infrastructure;
  • Education, examinations and access to training or further education;
  • employment, personnel selection, promotion and performance monitoring;
  • Access to essential private or public services, such as certain credit or insurance decisions;
  • law enforcement;
  • migration, asylum and border control;
  • Administration of justice and democratic processes.

Core obligations for providers of high-risk systems

  1. Risk management:Risks must be identified, assessed, tested and reduced throughout the entire life cycle.
  2. Data governance:Training, validation and test data must be fit for purpose, sufficiently representative and controlled.
  3. Technical documentation:Structure, capabilities, limits, versions and tests must be described in a comprehensible manner.
  4. Logging:Relevant processes must be able to be recorded automatically.
  5. Information for operators:Operation, performance limits, risks and supervisory measures must be clearly documented.
  6. Human supervision:People must be able to interpret expenses correctly, intervene and stop the system if necessary.
  7. Accuracy, robustness and cybersecurity:The system must be reliable for its intended purpose and protected against manipulation.
  8. Quality management and market observation:After placing on the market, performance, incidents and necessary corrections must be systematically monitored.

Obligations of the operators

Operators must comply with the instructions for use, anchor human supervision in the organization, control input data and maintain relevant logs. Depending on the application, there are additional obligations to provide information to employees or affected persons. Public bodies and certain private operators may be required to carry out a fundamental rights impact assessment before deployment. If the system touches personal data, a data protection impact assessment can be carried out in parallelGDPRbe required.

TheFederal Network Agency explains high-risk AI systemsand the affected areas of application. Our article goes into more depth on questions about physical AI systemslegal rules for humanoid robots.

Transparency obligations for chatbots, deepfakes and AI content

People should be able to recognize when they are interacting with an AI system or when they are viewing artificially generated content. What the information needs to look like depends on the format and context. A general note in the legal notice is not always enough.

Typical transparency cases

  • Chatbots and voice assistants:Users generally need to know that they are communicating with an AI system, unless this is already obvious.
  • Deepfakes:Artificially created or manipulated image, audio and video content must be disclosed as such.
  • Synthetic content:Generative systems providers must support technical solutions that make AI output recognizable in machine-readable form.
  • Texts of public interest:AI-generated texts on topics of public interest may require disclosure. An editorial review with human responsibility can change the rating.
  • Emotion recognition and biometric categorization:Affected people must be informed in permissible cases of use.

The labeling should appear where the content is perceived. For images, this can be a visible indication, a robust metadata solution, or a combination of both. Technical tags alone do not solve every transparency problem because platforms can remove metadata. The article explains more about thisAI watermarks and their limitations. For additional context, see Remove AI watermark: 4 easy methods.

If you choose generative tools, you should check the export and labeling functions during purchasing. The comparison provides a market overviewcurrent AI image generators.

Official details can be found atFederal Network Agency on transparency obligations.

GPAI: What applies to general AI models

GPAI stands for “General Purpose AI”, in German AI models with a general purpose. Such models can fulfill many different tasks and often form the technical basis for chatbots, search functions, programming assistants, image generators or industry-specific applications. For a complementary technical perspective, see The best AI image generators 2026: Create images online for free.

The EU AI Act separates between the model provider and the provider of an AI system based on it. Anyone who simply uses a ready-made interface is not automatically a GPAI provider. Anyone who radically changes a model, offers it under their own name or integrates it into their own product must examine their role more closely.

Essential Responsibilities for GPAI Providers

  • technical documentation about development, capabilities and limitations;
  • Information for providers of downstream AI systems;
  • a strategy for compliance with European copyright law;
  • a sufficiently detailed summary of the content used for the training;
  • for models with systemic risk, additional evaluations, risk mitigation, incident reporting and cybersecurity measures.

Companies that purchase GPAI should not be satisfied with advertising promises. Reliable information is required on model version, data processing, storage locations, training use of inputs, subcontractors, security measures, failure concepts and change notifications. Without such information, your own risk assessment quickly becomes a guessing show.

Official explanations:Federal Network Agency on GPAI models.

The EU AI Act and GDPR often apply at the same time

The EU AI Act does not replace the General Data Protection Regulation. If an AI system processes personal data, both sets of rules apply side by side. The AI ​​Act primarily assesses AI-specific risks and market obligations. The GDPR requires, among other things, a legal basis, purpose limitation, data minimization, transparency, data subject rights and appropriate security.

Four typical overlaps

  1. Employee data:An AI tool in recruiting can be high-risk AI and at the same time process sensitive personnel or applicant data.
  2. Profiling:Automated assessments can trigger information requirements and restrictions on automated individual decisions.
  3. Training and input data:Personal data may not be used solely because an AI provider is technically capable of doing so.
  4. Impact assessments:A fundamental rights impact assessment according to the AI ​​Act and a data protection impact assessment may be necessary in parallel. They should be coordinated, but not equated without checking.

In practice, it is worthwhile to have a joint review process between data protection, information security, specialist departments and compliance. This prevents duplicate documentation and uncovers gaps that often remain undetected in purely technical procurement. This overlap is particularly clear in robotics and sensor technology, for exampleData protection for humanoid household robots.

The data protection classification explains thisFederal Commissioner for Data Protection and Freedom of Information.

Who controls the EU AI Act in Germany?

Germany relies on the Federal Network Agency to play a central role in national implementation. According to the federal government, it will essentially serve as a market surveillance authority and set up a coordination and competence center. Specialized authorities remain involved for individual sectors so that existing specialist supervision is not duplicated.

The German implementing law passed through the Bundestag and Bundesrat in 2026. The Federal Council agreed on July 10, 2026. After drafting and promulgation, the law can come into force. Companies thus receive clearer national contacts, while the material obligations continue to follow directly from the European AI regulation.

The Federal Network Agency should also set up at least one AI real laboratory. Such real-world laboratories enable controlled tests of innovative systems under official supervision. They are not a legal vacuum, but they can help small and medium-sized companies in particular to understand requirements earlier.

Source:Federal government on the implementation of the AI ​​regulation in Germany.

What fines are there for violations?

The amount of the sanction depends on the type, severity, duration and consequences of the violation. Company size, cooperation with authorities, previous violations and economic advantage can also play a role. The maximum amounts nevertheless show that AI compliance is not a voluntary additional project.

violation Maximum possible amount
Violating Prohibited AI Practices Up to 35 million euros or 7 percent of global annual sales
Breach of other core duties Up to 15 million euros or 3 percent of global annual sales
False, incomplete or misleading information provided to authorities Up to 7.5 million euros or 1.5 percent of global annual sales

For companies, the higher amount may be decisive. The legal framework provides for proportionality for smaller companies. Nevertheless, tests, sales stops, recalls, contract disputes and reputational damage can become expensive, even if the maximum fine limit is not exhausted.

Liability remains a separate issue. The AI ​​Act sets out market and organizational obligations, but does not answer every civil claim. This quickly becomes practical with autonomous systems, such as the contributionsLiability for damage caused by humanoid robotsandWhy a robot is not responsible for itselfshow. For a broader industry perspective, see Humanoid Robots and the AI ​​Singularity.

EU AI Act checklist: 11 steps for companies

A practical compliance program does not start with a hundred-page set of rules. It starts with transparency about your own inventory. You can then set priorities based on risk and deadline.

  1. Create AI inventory

    Capture every productive, tested, or decentralized AI application. Note the provider, version, purpose, user group, data types, interfaces, country of use and responsible department. Free browser tools and integrated functions in existing software also belong on the list.

  2. Determine role in the supply chain

    Check whether the company is a supplier, operator, importer, dealer or product manufacturer. Document role changes through private labels, significant changes or new purposes.

  3. Exclude prohibited applications

    Before any further evaluation, carry out a prohibition check. This saves effort and prevents teams from trying to “fix” an unacceptable solution with additional measures.

  4. Check risk class and special law

    Assess operational context, affected individuals and possible consequences. Include privacy, employment, consumer, copyright, product safety and industry law.

  5. Build AI competency by role

    Don’t train all employees the same way. Marketing needs different rules than HR, IT administration, purchasing or management. Record actions and participation.

  6. Sharpen procurement and contracts

    Request technical documentation, safety information, change notices and assistance with government inquiries. Regulate data use, subcontractors, audit options, liability, exit and data return.

  7. Combining data protection and information security

    Check legal bases, data minimization, access, storage periods, third country transfers, logging and protection of confidential information. Use existing ISMS and data protection processes instead of building parallel worlds.

  8. Design human supervision specifically

    “A person looks at it again” is too imprecise. Determine who checks what information is available, when a result is rejected, and how time pressure or automation bias is prevented.

  9. Implement transparency and labeling

    Define cues for chatbots, deepfakes, synthetic media, and public AI texts. Check visible information and machine-readable markings in the real publishing process.

  10. Set up monitoring and incident management

    Monitor error rates, complaints, biases, security incidents, and model changes. Define reporting channels, escalation levels, shutdown criteria and responsibilities.

  11. Update evidence regularly

    AI systems change with new models, prompts, data sources and interfaces. Repeat the assessment for significant updates, new user groups or changes in purpose. A form once filled out is not permanent proof of compliance.

Minimum data set for an AI registry

Field Example
System and version Internal support chatbot, model version 4.2
Purpose Draft customer service responses
Corporate role operator
Affected persons Customers and service employees
Types of data Contact details, order information, free text
Risk Rating Requires transparency, no high risk according to current purpose
Human control No automatic sending, approval by employees
Responsibility Head of customer service and IT
Final test July 24, 2026
Next occasion Change of model, new data source or in twelve months at the latest

These errors are slowing down the EU AI Act implementation

Only IT is made responsible

IT knows systems and interfaces, but not every labor law, data protection or technical consequence. A sustainable team connects IT, data protection, information security, legal, purchasing and the respective specialist department.

ChatGPT is confused with the entire AI inventory

AI has long been in CRM, applicant software, translation, video analysis, fraud detection, search functions and automation platforms. Those who only record well-known chatbots often overlook the riskier systems.

The provider is considered solely responsible without being checked

Operator obligations remain with the using company. Even a market-leading provider does not relieve you of purpose definition, employee training, data protection assessment and human supervision.

A policy only exists on paper

An AI policy without a release process, training and technical controls hardly changes everyday work. Rules must apply where tools are purchased, accounts are created, data is entered and content is published.

Deadlines are confused with project start

The deadline marks the point in time from which the obligation must be complied with. It is not the day on which the project should begin. High-risk systems in particular need advance notice for documentation, testing and contract adjustments.

Why good AI governance is more than just duty

Clean AI governance can accelerate decisions. Teams know which applications are approved, which data can be used and who decides in case of uncertainty. This reduces shadow AI and prevents every project from starting from scratch.

The benefits are also growing in sales. Business customers are more likely to ask about data sources, security concepts, model changes and human control. Anyone who can answer these points in a structured manner appears more reliable than a provider who only advertises “AI-powered”.

The strongest approach is proportional: simple assistance systems receive lean rules, sensitive or decision-related applications receive deeper scrutiny. In this way, compliance does not become a blanket stop to innovation, but rather a filter for viable operations.

Conclusion: With the EU AI Act, preparation before the deadline counts

The EU AI Act turns AI use into a comprehensible management task. Bans and AI competence already apply. Transparency rules will follow at the end of 2026, and the comprehensive high-risk requirements according to the new schedule will follow in 2027 and 2028. Companies gain little if they only look at the latest deadline.

The pragmatic path starts with an AI inventory. This is followed by role clarification, risk assessment, training, contract review and documented human control. This structure not only protects against fines. It improves procurement, data quality and accountability – and separates useful AI projects from risky quick fixes.

Official sources and further information

  • Federal Network Agency: AI service desk and overview of the AI ​​regulation
  • Federal Network Agency: AI competence
  • Federal Network Agency: Prohibited AI practices
  • Federal Network Agency: High-risk AI systems
  • Federal Network Agency: Transparency obligations
  • Federal Network Agency: GPAI models
  • BfDI: AI regulation and data protection
  • Federal Government: National implementation of the AI ​​regulation
  • Council of the European Union: Digital Omnibus and new application dates

Editorial note: The article reflects the publicly documented legal status as of July 24, 2026. For specific products, high-risk applications or official procedures, an individual legal review makes sense.

Frequently asked questions about the EU AI Act

Does the EU AI Act also apply to small companies?

Yes. The regulation generally applies regardless of the size of the company if a company takes on a covered role. However, the scope and priority of the measures depend heavily on the system used and its risk; For small companies, the principles of proportionality apply to sanctions and offers of support.

Does the EU AI Act apply if we only use ChatGPT or similar tools?

The professional use of general AI tools can also trigger operator obligations, especially with regard to AI competence, data protection and internal usage rules. The tool is not just a high-risk system because of its popularity. What matters is what it is specifically used for and what decisions depend on it.

Since when does the obligation to have AI competence apply?

The obligation has been in effect since February 2, 2025. Providers and operators should do their best to ensure an appropriate level of competence among all people who use or operate AI systems on their behalf. The scope and content depend on role, previous knowledge, system and risk.

Does every company need an AI representative?

No, the EU AI Act does not require a formal AI representative across the board. Clear internal responsibility still makes sense. Depending on the size, this task may lie with an interdisciplinary AI governance team, the compliance function or a designated responsible person.

When do the high-risk rules of the EU AI Act apply?

According to the Digital Omnibus adopted in 2026, the rules for standalone high-risk AI will apply from December 2, 2027. For high-risk AI that is embedded in regulated products, August 2, 2028 will generally apply. Special sectoral rules and the specific product type must be additionally examined.

Is all AI in HR automatically high-risk AI?

No. Systems that significantly influence access to employment, selection, promotion, termination, distribution of tasks or performance monitoring are particularly high risk. A pure text assistant without a decision-making function can be classified differently, although data protection and labor law still apply.

Does AI-generated content always have to be labeled?

Not every internal draft needs a visible reference. Labeling requirements apply primarily when interacting with AI, deepfakes, synthetic media and certain published content of public interest. Format, editorial control and specific use determine the design.

Does the EU AI Act replace the GDPR?

No. As soon as personal data is processed, the GDPR applies in parallel. Companies must therefore examine AI-specific risks as well as the legal basis, transparency, data minimization, rights of those affected and data security.

How high are the fines under the EU AI Act?

For prohibited practices, up to 35 million euros or 7 percent of global annual sales are possible. For other key violations, up to 15 million euros or 3 percent can apply. The specific amount depends, among other things, on the severity, duration, company size and cooperation.

What is the first sensible step towards compliance?

The best place to start is with a full AI inventory. It should include system, version, purpose, provider, company role, data types, data subjects, risk classification and responsible parties. Only with this overview can training, contracts and controls be prioritized sensibly.

Bewerte den Beitrag hier!
[Total: 0 Average: 0]
Nico Nuss [Image content created with AI]

Author Nico Nuss has been working on mobile computing and automation software since 2001. Drawing on his experience and strong interest in future technologies, he focuses on robotics and AI.