Navigation
FIDA Blog
Knowledge - Success Stories - White Papers
newspaper Overview chevron_right Artificial Intelligence chevron_right Blog chevron_right Cross-Industry
Blog

AI Act: How Will the EU AI Regulation Affect Businesses?

While the EU aims to ensure safety and transparency for its citizens through the AI Act, companies are increasingly uncertain about the legal obligations the AI Act imposes on them. One thing is certain: AI has long since become part of everyday business life.

In this article, we’ll explain in detail how you can use AI in your company in a legally compliant manner under the EU AI Act—and what consequences you may face for noncompliance.

What are the fundamentals of the EU AI Regulation?

The Regulation on Artificial Intelligence [Regulation (EU) 2024/1689], commonly known as the EU AI Act (also referred to as the AI Regulation), is the world’s first comprehensive regulatory framework for artificial intelligence. The regulation applies directly to all EU member states and does not require transposition into national law.

In fact, the EU AI Act entered into force on August 1, 2024. The provisions relevant to businesses will gradually take effect starting in February 2025. The European Commission’s current timeline for implementing the EU AI Act calls for full implementation by August 2, 2027.

The goal of the regulation is to ensure that AI systems are designed in a manner consistent with fundamental rights, safe, and transparent. At the same time, it aims to promote innovation in the single market.

At the core of the AI Act is, on the one hand, the risk-based classification of AI systems, which includes a general prohibition on unacceptable AI practices (Art. 5 of the AI Regulation) . On the other hand, the AI Act distinguishes between providers and operators of these AI systems and imposes corresponding obligations. We’ve compiled a clear overview of the obligations under the EU AI Act—including who they apply to and when they take effect—for you here:

We explain exactly what these obligations entail in the section titled “Detailed Explanation of the Obligations Under the AI Act.”

The AI Act sets specific deadlines for certain providers and operators. This applies to:

  1. Existing systems in government agencies: Providers and operators of high-risk AI systems that were already in use by government agencies prior to August 2026 must comply with the requirements by August 2, 2030 (exception under Art. 113(2), sentence 2 of the AI Regulation).

  2. GPAI models on the market: Providers of GPAI models (general-purpose AI models/ models for general purposes) that were already placed on the market prior to August 2, 2025, have until August 2, 2027, to achieve compliance (exception under Article 113(3) of the AI Regulation).

  3. Large-scale IT systems: AI components in large-scale IT systems (e.g., the Schengen Information System) must be brought into compliance with the Regulation by December 31, 2030 (exception under Article 111(1) of the AI Regulation).

Important: These different deadlines do not apply to the prohibition on unacceptable AI practices under Article 5 of the AI Regulation.

How does the EU AI Act distinguish between providers and operators?

To determine which obligations under the AI Act apply to you, the first step is to clarify whether your company is a provider or an operator and which risk class the AI systems you use fall into.

Is your company a provider or an operator?

To determine which specific obligations under the EU AI Act apply to your company, you must first determine whether your company is a provider or an operator as defined by the AI Act.

Providers are…

“Providers” bear the primary responsibility for ensuring that the AI system meets the requirements of the Regulation, particularly in the case of high-risk AI systems.

Definition under the AI Act: Providers (as defined in the English text of the law) are, according to Article 3(3) of the AI Regulation, natural or legal persons, public authorities, bodies, or other entities that (or a general-purpose AI model) or have it developed and place it on the market under their own name or trademark, or put the AI system into service under their own name or trademark. This applies regardless of whether the provision is made for a fee or free of charge.

Your company is therefore a provider of AI systems within the meaning of the AI Regulation if all four of the following apply:

  • Your company must be a natural or legal person, an institution, or another entity (including public authorities)

  • Your company develops a general-purpose AI system or AI model, or commissions its development

Definition of an AI system from , Art. 3, No. 1

An AI system is a machine-based system designed for operation with varying degrees of autonomy and capable of adapting after it begins operation . Based on the inputs it receives for explicit or implicit objectives, it determines how to generate outputs such as predictions, content, recommendations, or decisions —that caninfluence physical or virtual environments.

Definition of a general-purpose AI model (GPAI) from Art. 3 No. 63

An AI model—including cases where it is trained using a large amount of data under comprehensive self-monitoring—that exhibits significant general applicability and is capable of competently performing a wide range of different tasks , regardless of how it is placed on the market . It is also characterized by the fact that it can be integrated into a wide variety of downstream systems or applications.

Distinction Between an AI System and a GPAI

A GPAI model does not in and of itself constitute an AI system, but is often its essential component. For a model to become a system, additional components, such as a user interface, must be added.

  • Your company markets the AI system or model under its own name or brand name

Definition of “Placing on the Market” fromArticle 3(9) of

This refers to the first time a general-purpose AI system or AI model is made available on the Union market.

  • It does not matter whether the service is provided for a fee or free of charge.

Did you know?

The AI Act adopts key definitions directly from the GDPR to ensure consistency. These include terms such as:

  • Personal data

  • Non-personal data

  • Biometric data

  • Special categories of personal data (sensitive data)

  • Profiling

Furthermore, the AI Act clarifies that the fundamental right to the protection of personal data continues to be fully safeguarded by the GDPR and other relevant legal acts.

Examples of providers include:

  • A technology company: A company that develops software for AI-based analysis of image data (e.g., damage photos) and sells it under its brand name to insurers and energy providers.

  • A government agency: A government entity that commissions the development of an AI system for the automated assessment of applications for social benefits and implements this system for its internal administrative processes.

  • A company that rebrands existing systems: A distributor or importer that takes an existing high-risk AI system from another manufacturer, labels it with its own name or brand, and makes it available on the EU market.

  • An entity making substantial modifications: A person who makes a “substantial modification” to a high-risk AI system already placed on the market, such that it continues to be classified as a high-risk system, and who assumes the role and obligations of the provider for that system

  • Entities that repurpose AI systems: A person or company that changes the intended use of an AI system (including a general-purpose system) in such a way that it must legally be classified as a high-risk AI system.

  • Product manufacturers as providers: A manufacturer (such as a manufacturer of elevators or industrial machinery) that integrates an AI system into its product as a safety component and places the finished product on the market under its own name.

Operators are…

An operator differs from a provider in that they do not develop the AI system themselves, but rather use it for their specific professional purposes while retaining control over the input data.

Definition according to the AI Act: According to Article 3(4) of the AI Regulation,operators (referred to as “deployers” in the English text of the law) are natural or legal persons, including public authorities, institutions, or other entities, that use an AI system under their own responsibility. An exception applies if the system is used solely for personal, non-professional purposes.

Your company is therefore a controller of AI systems within the meaning of the AI Regulation if these two conditions are met:

  1. Your company must be a natural or legal person, an institution, or another entity (including public authorities)

  2. AI systems are used in your company for commercial purposes and not for the private use of employees.

Examples of operators include:

  • Banks and insurance companies: Financial institutions that use AI systems to assess individuals’ creditworthiness or to evaluate risk in health and life insurance.

  • Public authorities: Government agencies or EU bodies that deploy AI systems, for example, to review applications for social benefits or for border control purposes.

  • Employers: Companies that use AI systems in the workplace, such as to monitor employee performance or to assign work tasks.

  • Educational institutions: Schools or universities that use AI systems to assess learning outcomes or to monitor students during exams.

  • Emergency services: Organizations that use AI to assess and prioritize emergency calls (e.g., fire departments or police).

Do the rules of the EU AI Act also apply to private individuals?

No, as long as an AI system is used exclusively for personal and NOT for professional activities, the rules of the AI Act do not apply to private individuals.

Recital 13 of the AI Regulation confirms that the use of AI systems under the authority of an individual isnot considered “operating” within the meaning of the Regulation if it takes place in a private, non-commercial context.

Although a natural person (i.e. ,a private individual) may belegally classifiedas a “provider, in such a case the person generally no longer acts in a purely private capacity but rather as a market participant.

What is the risk pyramid?

The risk pyramid is the central and best-known element of the AI Act. It reflects the regulation’s risk-based approach, in which the intensity of regulation increases linearly with the potential risk posed by an AI system to health, safety, and fundamental rights.

The risk pyramid is divided into four main levels:

  1. Unacceptable Risk (Prohibited Practices under Art. 5 of the AI Regulation)

  2. High Risk (High-Risk AI Systems)

  3. Low Risk / Specific Transparency Risk

  4. Minimal risk

Unacceptable risk (prohibited practices under Article 5 of the AI Regulation)

At the top of the pyramid are AI practices that are classified as so dangerous that they are generally prohibited in the Union. These systems violate the Union’s values and human dignity.

Examples: AI-enabled subliminal manipulation of individuals, the exploitation of vulnerability (e.g., due to age or a disability), “social scoring” by public authorities, and certain forms of real-time remote biometric identification for law enforcement purposes in public spaces

High Risk (High-Risk AI Systems)

This category includes systems that may have significant adverse effects on safety or fundamental rights. They are subject to strict requirements (see 3.3 and 3.5).
A system is considered high-risk if it is either incorporated as a safety component in products subject to third-party conformity assessment (e.g., machinery or toys) or if it is used in specific areas listed in Annex III of the AI Act.

Examples: Use in critical infrastructure, general and vocational education, employment and human resources management (e.g., screening resumes), access to essential private and public services (e.g., creditworthiness/credit checks), and biometric recognition for law enforcement and immigration

High-risk AI systems are not prohibited, but may only be placed on the market if they meet strict, binding requirements.

Low Risk / Specific Transparency Risk

Certain AI systems are subject to specific transparency requirements, regardless of whether they are classified as high-risk. The goal here is to prevent users from being misled.

Examples: Users interacting with AI (e.g., chatbots); content generated or manipulated by AI (deepfakes); synthetic texts that inform the public about topics of general interest

Minimal Risk

This category encompasses the vast majority of AI systems currently in use (e.g., AI-powered video games or spam filters). These systems are not subject to any specific requirements under the AI Act.

However, providers are expressly encouraged to voluntarily establish codes of conduct to address aspects such as environmental sustainability or accessibility.

Special Category: General-Purpose AI (GPAI) Models

In addition to this framework, the regulation introduces rules for GPAI models, with models posing systemic risk (those that are particularly powerful due to their high computational capacity) subject to additional obligations regarding risk assessment and cybersecurity.

What obligations does the AI Act impose on companies?

Once you’ve determined whether your company is a provider and/or operator and which risk class your AI system falls into, you can easily use the overview provided at the beginning to figure out which obligations apply to you. We’ll explain exactly what these entail below.

Reminder: Unacceptable AI practices are strictly prohibited!

Article 5 defines AI practices that are generally prohibited due to their unacceptable risk to fundamental rights and Union values .

These include, in particular, manipulative techniques, the exploitation of vulnerability (e.g., due to age or disability), government social scoring, and the indiscriminate collection of facial images for databases.

Also prohibited are emotion recognition in the workplace or in educational institutions, as well as real-time remote biometric identification in public spaces, although narrowly defined exceptions for law enforcement purposes exist for the latter.

Requirement #1: Requirement to Promote AI Literacy

Article 4 of the AI Regulation sets forth specific requirements for promoting AI literacy.

Who is subject to the AI training requirement?

This obligation applies to both providers and operators of AI systems. They must ensure that their staff and other individuals involved in the operation and use of AI systems on their behalf receive adequate training.
The training requirement generally applies to the use of AI systems. Since Article 4 is part of the general provisions (Chapter I), this requirement is not limited to high-risk AI systems but applies to the use of AI systems in a professional context in general.

What are the requirements for promoting AI competence?

Providers and operators must take measures to impart a “sufficient level” of AI competence. In doing so, the following factors must be taken into account:

  • the existing technical knowledge and experience of the staff

  • necessary education and training

  • the context in which the AI systems are used

  • the individuals or groups to whom the AI systems are intended to be applied

  • The goal is for those involved to use AI systems competently and to be aware of the opportunities, risks, and potential harms

Requirement #2: Transparency Requirements

Marketing departments, in particular, must pay close attention to AI-generated content as of August 2, 2026. The transparency requirements set forth in Article 50 of the EU AI Act impose new transparency and labeling obligations on all companies regarding AI-generated content.

Who must comply with the transparency requirements?

Depending on the use case, the obligations apply equally to providers and/or operators of AI systems. Individuals who use AI systems for personal purposes are not subject to the transparency obligations.

What must be labeled?

It must be disclosed when content or interactions have an artificial origin. This applies to:

  1. The AI interacts directly with people.
    Individuals must be informed that they are interacting with an AI system (unless this is obvious).

  2. AI is used to generate synthetic content.
    Audio, image, video, or text outputs must be recognizable as artificially generated or manipulated.

  3. AI is used for emotion recognition or biometric classification.
    Data subjects must be informed about the operation of emotion recognition or biometric classification systems.

  4. Deepfakes are created using AI.
    It must be disclosed when content (image, audio, video) is artificially generated or manipulated and bears a deceptively realistic resemblance to real people or places (so-called deepfakes).
    “Real” here is not limited to actual existence, but refers to anything that appears as if it could exist in reality. Thus, the deepfake need only look like a real person or place; it does not have to depict an actual person or place.
    It also does not matter whether there is an intent to deceive, but rather whether the result is capable of deceiving the consumers of the content.

  5. Texts on topics of public interest are published .
    AI-generated texts on topics of general interest (e.g., politics, consumer issues) must also be labeled as such. However, labeling public information texts is not required if they have undergone human review or editorial oversight.
    Advertising copy, product descriptions, emails, and similar content are not texts on topics of general interest. No labeling is required in these cases.

How should such content be labeled?

The regulation sets forth certain requirements regarding the method of labeling, which are supplemented by the Competition Center’s guidelines on labeling AI-generated content and the European Commission’s Code of Conduct on the Transparency of AI-Generated Content. The following must be observed:

  • The timing of the labeling: The information must be provided no later than the time of the first interaction with the content.

  • The format: Information must be provided in a clear and visible manner.

    • The European Commission has not specified a uniform, mandatory symbol for labeling. Therefore, a custom label—such as “AI-generated” for fully generated content or “AI-modified” for altered content—may be chosen for labeling. On some social media platforms (e.g., YouTube), it is possible to label AI-generated content using the features of the upload studios.

    • The label must be clearly and prominently placed within the content (e.g., in the corner of an image or video; for videos, a note indicating AI generation at the beginning of each AI-generated sequence; or for audio content, an audible disclaimer at the beginning).

ATTENTION: AI labeling is an additional requirement!

Copyright and personality rights can still be infringed upon by the content. Just because content is AI-generated does NOT mean that real people or characters may be used freely.

  • Machine-readability: For synthetic content, the labeling must be in a machine-readable format (e.g., through watermarks or metadata), provided this is technically feasible. AI system providers are responsible for implementing this labeling. Anthropic has already announced how this labeling requirement will be implemented in upcoming Claude models. By December 2, 2026, at the latest, AI labeling must be in place for all models, including those that were released before August 2, 2026.

What specific obligations apply to operators of high-risk AI systems?

Articles 26 and 27 of the AI Regulation (EU) 2024/1689 set forth the specific obligations for operators (referred to as “deployers” in English) of high-risk AI systems. While Article 26 focuses on general operational obligations, Article 27 governs the conduct of a fundamental rights impact assessment for certain stakeholders.

To whom do Articles 26 and 27 apply?

Article 26 applies to all operators of high-risk AI systems (natural or legal persons, public authorities, or other bodies) who use such a system under their own responsibility in a professional context

Article 27 applies to a more limited group of operators , namely public authorities, private entities providing public services (e.g., in the fields of education or social services), and operators of systems used for creditworthiness assessments or risk assessments in life and health insurance

Obligations under Article 26 of the AI Regulation: Operation of High-Risk AI Systems

These obligations are intended to ensure that safety and fundamental rights are safeguarded during the actual use of the system.

Examples of Art. 26

An employer that uses an AI system to evaluate job applicants must inform the works council and ensure that trained HR staff review the results rather than relying blindly on the AI.

A bank that uses AI for credit decisions must ensure that the customer data used is representative and retain the system logs for possible future audits.

Obligations under Art. 27 of the AI Regulation: Fundamental Rights Impact Assessment (FRIA)

This obligation supplements the provider’s obligations and focuses on the specific context of use.

What does the obligation entail? Operators must conduct a comprehensive assessment of the impact on fundamental rights in accordance with Article 27(1)(a–f) and (3)–(5) prior to the system’s initial operation. This assessment must include:

  • Description of the procedures: An explanation of how the system is used in the specific process

  • Timeframe: A description of the duration and frequency of use

  • Categorization of data subjects: Identification of the groups of individuals who could be affected by the system

  • Risk analysis: Identification of specific risks of harm to fundamental rights (e.g., risks of discrimination) using information from the provider’s operating instructions

  • Definition of remedial measures: Planning of steps to be taken if the risks materialize (e.g., complaint mechanisms or specific oversight provisions)

  • Reporting: The results must be reported to the market surveillance authority (the AI Office provides a template for this purpose)

Examples of Article 27

A municipal government that implements an AI system for the automated allocation of daycare spots or social benefits must first assess whether certain population groups could be disadvantaged by the algorithms.

An insurance company that uses AI for risk assessment in health insurance must document the measures it is taking to prevent the potential financial exclusion of vulnerable individuals.

What are the specific obligations for providers of GPAI?

What is GPAI? What is the legal basis? To whom do the obligations apply? When do they take effect?
What do the obligations entail? What measures must be taken to comply with each obligation? What are some examples?

Chapter V (Articles 51 through 56) of the AI Act establishes specific requirements for general-purpose AI ( GPAI) models, as they play a key role in the AI value chain.

RECAP: What is GPAI?

A general-purpose AI (GPAI) model is a model that exhibits significant general applicability and is capable of competently performing a wide range of different tasks, regardless of how it is deployed.

Typical examples include large generative models that can flexibly generate text, images, audio, or video content.

The regulations for GPAI models took effect on August 2, 2025, for models newly introduced to the market. Manufacturers of models that were already on the market before August 2, 2025, have until August 2, 2027, to ensure compliance.

Tip: The AI Office regularly publishes new documents and guidelines that providers can use as a reference to establish a presumption of conformity.

Essential Obligations for All GPAI Providers (Art. 53)

Providers must ensure transparency and respect copyright.

Exception for Open Source: The obligations regarding technical documentation and the provision of information to downstream providers do not apply to models licensed under a free and open-source license, provided that their parameters (including weights and architecture) are publicly available. However, this does not apply if the model poses a systemic risk.

Specific Obligations for GPAIs with Systemic Risk (Art. 55)

A GPAI model is considered a model posing systemic risk if it possesses capabilities with high impact (assumed to be the case for computational power exceeding 10²⁵ FLOPs) or has been classified as such by the Commission. Additional obligations for GPAI providers are:

What specific obligations apply to providers of high-risk AI systems?

The specific obligations for providers of high-risk AI systems form a central pillar of the AI Regulation, aimed at ensuring safety and fundamental rights within the Union. They are set forth in Chapter III, Section 3 (Articles 16 through 25) of the Regulation. The technical requirements that these providers must ensure are set out in Section 2 (Articles 8 through 15).

What do these obligations entail, and what measures are required?

According to Article 16, providers must take a number of steps to ensure compliance:

Examples of High-Risk AI Providers and Measures

  • HR solutions software company: A company develops an AI-powered tool for pre-screening job applicants.
    Measure: The provider must train the system to detect and correct discriminatory biases in the datasets (data governance pursuant to Art. 10).

  • Fintech company: A provider launches a system for assessing the creditworthiness of individuals.
    Measure: The provider must create an operating manual that clearly explains to the operator (the bank) how to monitor the system and what limitations exist regarding the accuracy of the results (transparency under Art. 13).

  • Medical device manufacturer: A company integrates AI for the automated diagnosis of diseases into an X-ray machine.
    Action: Since this is considered a safety-critical component, the provider must maintain a comprehensive risk management system that assesses potential risks to patients throughout the entire lifecycle (Art. 9).

  • Technology providers in the public sector: A company develops a system for remote biometric identification for government agencies.
    Measure: The provider must ensure that the system’s results can be independently verified by at least two natural persons (human oversight under Article 14).

What are the consequences of failing to comply with the obligations under the AI Act?

In the event of violations of the AI Regulation, the EU AI Act provides for a graduated system of sanctions, particularly fines, as well as various supervisory and corrective measures. When determining sanctions, authorities must take into account, among other factors, the nature, severity, and duration of the violation; the size and market share of the entity; and the degree of cooperation with the authorities. The applicable framework is set forth in the AI Regulation as follows:

Fines (Art. 99–101 AI Regulation)

The amount of the fines is scaled according to the severity of the violation. For companies, fines are calculated based on global annual turnover or fixed amounts (whichever is higher):

  • Violations of prohibited AI practices (Art. 5) may be punishable by fines of up to 35,000,000 EUR or up to 7% of total annual global revenue.

  • Violations of other obligations (e.g., for high-risk systems or transparency rules): may be punishable by fines of up to 15,000,000 EUR or up to 3% of global annual revenue.

  • Providing inaccurate or misleading information to authorities: may be subject to fines of up to 7,500,000 EUR or up to 1% of global annual turnover.

Special Provisions for SMEs and Startups

Under Article 99(6) of the AI Regulation, a cap applies to small and medium-sized enterprises and startups: The fine is limited to the lower of the two amounts specified (percentage or total).

Penalties for Other Parties

  • Providers of GPAI models (general-purpose AI models): The Commission may impose fines of up to 3% of annual turnover or 15,000,000 EUR for intentional or negligent violations.

  • Union institutions and bodies: In these cases, the European Data Protection Supervisor may impose fines (up to EUR 1,500,000 for prohibited practices; otherwise, up to EUR 750,000).

Corrective measures (Articles 79, 83, 93 of the AI Regulation)

Regardless of fines, the competent market surveillance authorities may take measures to avert risks:

  • Request for compliance: The supplier must take measures within a specified timeframe to ensure compliance with the rules

  • Market restrictions: Authorities may prohibit or restrict the placing on the market.

  • Recall and withdrawal from the market: A non-compliant system may be withdrawn from the market or recalled by operators.

  • Measures against GPAI models: The Commission may require providers to withdraw the model or implement specific risk mitigation measures.

Rights of Data Subjects (Art. 85 & 86 AI Regulation)

Violations may also be sanctioned through individual actions by citizens or legal entities:

  • Right to File a Complaint: Any person who suspects a violation may file a complaint with the competent market surveillance authority.

  • Right to an explanation: Individuals who are significantly affected by a decision made by an operator based on a high-risk AI system have the right to receive a clear and meaningful explanation of the role of AI in that process.

Our 5-step roadmap for legally compliant implementation of the AI Act in your company:

Step 1: AI Inventory

  • A centralized overview of which AI tools are used within the company is the starting point for a systematic implementation of the AI Act.

  • Conduct an inventory of all AI tools used in your company:

    • Identify where AI is being used to deliver services within your company. What tools are your employees already using, and for what purposes?

    • Also review contracts with third-party providers to see if AI is used for services that your company utilizes.

    • Are there any AI systems you might even be developing yourselves?

  • Next, determine whether you are the provider or operator of the respective AI systems.

Step 2: Risk Classification

  • Classify your AI systems within the risk pyramid. Assess the risks based on each use case. Also identify GPAI models in your existing systems.

  • Tip: Most marketing and office AI systems fall into the “low-risk” category. However, HR software that, for example, pre-sorts applicants is a high-risk system!

Step 3: Obligations at a Glance

  • Use the overviews from “3. AI Act Obligations Explained in Detail” to get a clear picture of the measures you need to take, and prioritize the adjustments required for high-risk systems.

  • Also review your contracts with third-party providers to ensure compliance with these obligations. Does the provider supply sufficient documentation? Do the systems you use meet the obligations of the AI Act? If not, you should renegotiate the contracts or switch providers.

Step 4: Adjustments, Process Definition, and Documentation

  • Prioritize the adjustments you must make to high-risk systems. Integrate emergency and shutdown mechanisms. If necessary, plan compliance assessments well in advance. Ensure traceability and create simplified technical documentation.

  • Compliance with the AI Act’s transparency and labeling requirements is also a priority. To this end, develop an editorial approval process.

  • Implement governance structures. Define responsibilities and approval processes, and document them in an internal AI policy. Also specify which AI tools are permitted for use within the company.

Step 5: Train Employees

  • Provide your employees with information on the AI systems in use, their respective risk classifications, associated compliance obligations, your AI policy, and process documentation.

  • Additionally, offer at least one AI training session per year to promote AI literacy. Our FIDAcademy would be happy to provide this training for you.

Do you need help implementing the EU AI Act? FIDA is here for you!

At FIDA, we bring together AI experts under one roof to meet the needs of SMEs, insurers, energy providers, and government agencies: Our colleagues at FIDA AI Consulting are here to help you establish AI governance! Our FIDAcademy offers training on AI skills and much more. Feel free to schedule a consultation so we can share the best path into the AI era with you!

FAQ: Frequently Asked Questions from Companies About the EU AI Act

The EU AI Act is the European regulation governing artificial intelligence. It takes a risk-based approach and sets different requirements for companies depending on the specific AI system. It applies to both companies that develop or offer AI systems and those that use AI systems in a professional context.

In principle, any company can be affected as soon as it uses AI systems for business purposes or develops or offers them itself. The specific obligations that apply depend, among other things, on whether the company acts as a provider or an operator and on the risk class to which the AI system in use is assigned.

A provider is defined as a company that develops an AI system or AI model—or has it developed—and places it on the market or puts it into service under its own name or brand.

An operator uses an AI system under its own responsibility for professional purposes. For example, a company that uses an external AI tool for document analysis or in human resources may thereby become an operator within the meaning of the AI Act.

The EU AI Act distinguishes between four risk levels:

  • Unacceptable risk: Certain AI practices are prohibited.

  • High risk: High-risk AI is subject to extensive requirements regarding safety, transparency, documentation, and human oversight.

  • Low or specific transparency risk: Information and labeling requirements apply in particular here.

  • Minimal risk: For many everyday AI applications, there are no specific obligations under the AI Act.

In addition, special regulations apply to general-purpose AI (GPAI) models.

Yes. Article 4 of the EU AI Act requires providers and operators to ensure an adequate level of AI literacy among the individuals who work with AI systems on their behalf.

In this context, training must take into account, among other things, employees’ existing knowledge, the specific area of application, and the associated opportunities and risks. The requirement for AI literacy is not limited exclusively to high-risk AI but applies to the professional use of AI in general.

In certain cases, yes. The transparency requirements of the AI Act stipulate, among other things, that users must be informed when they are interacting directly with an AI system. Certain types of synthetically generated or manipulated content, such as deepfakes, must also be labeled accordingly.

Special labeling requirements also apply to AI-generated texts on topics of general interest. For example, labeling is not required if such a text has undergone human review or editorial oversight.

The transparency requirements under Article 50 of the EU AI Act have been in effect since August 2, 2026. Companies should therefore verify whether labeling is required, particularly when creating and publishing AI-generated images, videos, audio files, and certain types of text.

When using high-risk AI, operators face additional requirements. These include, among other things, the proper use of the system, adequate human oversight, the use of appropriate input data, and the retention of relevant logs.

For certain companies and organizations, a fundamental rights impact assessment (FRIA) may also be required. Its purpose is to identify potential impacts of the AI system on fundamental rights and to define appropriate countermeasures.

High-risk AI can be used, among other things, in areas that have particularly sensitive implications for people. These include, for example, certain applications in human resources, education, critical infrastructure, or the assessment of access to essential private and public services.

Whether a specific system is actually classified as high-risk AI depends on its specific intended use and the requirements of the AI Act.

Violations of the AI Act can have significant financial consequences. Depending on the nature and severity of the violation , fines of up to 35 million euros or 7 percent of global annual revenue may be imposed. Lower maximum limits apply to other violations.

When determining a penalty, factors such as the severity and duration of the violation, the size and market share of the company, and other circumstances are taken into account. Special rules regarding the amount of fines apply to SMEs and startups.

Companies should first develop an overview of all AI systems in use within the organization. Next, for each system, they should assess the company’s role, determine which risk class the system falls into, and identify the specific obligations that arise from this.

Building on this, companies should, among other things, define responsibilities, train employees, establish transparency and documentation processes, and scrutinize the use of high-risk AI with particular care. This approach ensures that the use of AI is structured and compliant with the law.

About the Author

Dr. Simon Kroll ist Data Scientist bei der FIDA und entwickelt LLM-basierte Lösungen mit Fokus auf Datenanalyse, Sprachverarbeitung und MLOps. Er begleitet Projekte von der ersten Idee bis zum produktiven Einsatz, unter anderem MsDAISIE, fraudify und GPT4YOU. Zudem verantwortet er als Head of FIDAcademy Schulungen im Bereich KI und Data Science und stärkt die KI- und Datenkompetenzen von Teams, um generative KI verantwortungsvoll und wirksam einzusetzen.

Related Articles

Symbolbild für KI im Einsatz im HR-Management. Virtueller Bildschirm mit Symbolen aus dem Personalbereich, wie einem Lebenslauf. Eine reale Person bedient diesen Bildschirm mit einem Stift.
Use Case
Lebensläufe auf Knopfdruck - Unsere KI im Einsatz bei einer Agentur für Personalvermittlung

Die Herausforderung: Ein zeitaufwendiger, manueller Prozess zur Erstellung von Lebensläufen für eine führende Personalvermittlung. Die Lösung: Der Einsatz unserer maßgeschneiderten KI-Lösung GPT4YOU.

Learn more
Mann nutz KI
Blog
What problem does RAG (Retrieval Augmented Generation) solve for businesses?

An employee asks the internal AI assistant about the current vacation policy. The answer sounds convincing—but it’s still wrong. The language model isn’t familiar with the actual company policy; instead, it generates a plausible-sounding response based on its training data. You may be familiar with this exact problem from your own experience.

Learn more
Titelbild Schadenportal
Use Case
Porting and optimization of B2C claims applications to modern architectures and technologies

Modernization of complex applications to modern architectures & technologies is no problem for us.

Learn more