AI Act: What it means for businesses

- The EU AI Regulation regulates AI systems based on their risk potential.
- AI systems with "unacceptable risk," such as social scoring, have been banned since February 2025.
- High-risk AI systems are subject to strict requirements and conformity assessments.
- Companies must ensure risk assessments, transparency, and comprehensive documentation.
- Violations can result in fines of up to 35 million Euros or 7% of global annual turnover
What is the EU AI Act?
The Artificial Intelligence Act (AI Act) is the world's first comprehensive law regulating AI systems. It applies directly in all EU member states—no transposition into national law is required.
The AI Act pursues four central objectives:
- Protecting the fundamental rights and safety of EU citizens
- Monitoring and Regulating the use of AI in businesses
- Creating a secure innovation framework for European AI developments
- Strengthening consumer and business trust in AI technologies
What does the EU AI Act regulate?
The AI Act defines an AI system as "a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments."
Three features are therefore decisive: the system operates to a certain degree autonomously, it derives results from inputs rather than just executing predefined rules, and its outputs have an impact on the environment. Classic, fully rule-based software does not fall under this definition.
Risk-based classification of AI systems
The strictness of the regulation depends on the risk potential of the AI system. The regulation divides AI into four categories:
1. AI with unacceptable risk: Prohibited
AI systems that pose a clear threat to fundamental rights have been banned in the EU since February 2025. These include:
- social scoring by public or private entities
- Real-time remote biometric identification in public spaces for law enforcement purposes (with narrow exceptions)
- emotion recognition in the workplace or in educational institutions
2. High-risk AI systems: Strict regulation
High-risk AI systems are used in critical areas, such as:
- Human resources: AI-powered applicant tracking systems
- Healthcare: AI diagnostics
- Critical infrastructure: Management of energy or transport networks
- Law enforcement & judiciary: Risk assessment in judicial proceedings
Example: A software company developing an AI-based recruiting tool must conduct conformity assessments and prepare technical documentation.
3. AI with specific transparency obligations
AI systems such as chatbots or deepfake generators may be used, provided that users are clearly informed that they are interacting with an AI. To this end, operators of AI tools must clearly label certain AI-generated content and chatbots as such starting August 2, 2026.
Tool providers must also ensure that AI-generated content is marked in a technically machine-readable format. For systems already placed on the market, a transition period for the technical labeling requirement applies until December 2, 2026.
4. Minimal-risk AI: No specific requirements
AI systems such as spam filters or AI-powered video games are not subject to any special requirements. The AI literacy obligation under Art. 4 of the AI Act and data protection law apply regardless of the risk category.
When do the regulations of the AI Act come into force?
The AI Act entered into force on August 1, 2024 . However, staggered transition periods apply.
Latest developments regarding the EU AI Act at a glance
The Digital Omnibus Regulation on AI has been in effect since July 2026. With this, the European legislator has amended the AI Act in several places and extended deadlines. The definition of high-risk has been narrowed, the literacy obligation has been adjusted, and there are simplifications for SMEs.
In our magazine, you can learn more about the contents of the EU's Digital Omnibus.
Who does the AI Act apply to?
The AI Act ties obligations to roles rather than company size. It is primarily aimed at providers, deployers, and importers of AI systems:
- Providers: develop AI systems and bring them to market
- Operators: use AI systems within their own company
- Importers and distributors: bring AI systems into the EU or resell them
Most small and medium-sized enterprises are operators.
Please note: Anyone who distributes a purchased AI system under their own name or significantly changes its intended purpose becomes a provider themselves.
What requirements does the EU AI Act impose on SMEs?
The following key requirements are relevant for companies that use AI in their day-to-day operations.
1. Risk assessment and risk management
Companies must conduct and document a comprehensive risk assessment of their AI systems:
- What risks arise from the use of the AI system?
- What measures are being taken to minimize these risks?
- How is the system monitored and updated?
2. Transparency requirements
Users must be clearly informed that they are interacting with an AI system, especially in the case of chatbots or systems that recognize emotions or biometric data.
3. Documentation and record-keeping
What you need to document depends on your role:
- As a provider of a high-risk AI system: technical documentation on system architecture, training, validation and testing data, performance limits, risk management, and changes (Art. 11, Annex IV AI Act).
- As a deployer: the logs automatically generated by the system as well as evidence of human oversight, training, and reported incidents (Art. 26 AI Act).
Regardless of the risk category, a central AI register is recommended: Which AI systems are in use, who is responsible for them, what data do they process, and what role do you play? This register forms the basis for any subsequent classification and can be managed with the Record of processing activities pursuant to Art. 30 GDPR connect.
4. AI literacy in the company
Providers and operators must ensure that their staff possess a sufficient level of AI literacy . The regulation does not prescribe a specific format. The decisive factor is that the level of competence matches the respective application: the higher the risk of the application, the higher the requirement.
Previously, providers and operators were required to ensure AI literacy. Since the Digital Omnibus for AI came into force, it is sufficient to promote it. Affected companies do not have to prove a verified level of competence, but must be able to demonstrate what they have done. This has turned an obligation to achieve a result into an obligation to take action.
Special regulations for high-risk AI systems
A uniformly high level of protection applies to high-risk AI systems. The provider is responsible for technical implementation, while the operator is responsible for appropriate use. These systems must:
✅ Be robust and secure
✅ Not infringe on the fundamental rights of users
✅ Be subject to rigorous conformity assessment must undergo
✅ Human oversight enable (human-in-the-loop)
Compliance under the AI Act
The conformity assessment is a core component of the AI Act. For high-risk AI systems, your role determines the level of effort required.
Steps to compliance for providers:
1. Risk classification: Should your AI system be classified as high-risk?
2. Establish a risk management system
3. Technical documentation creation
4. Quality management system implementation
5. Conduct conformity assessment – internally or via a notified body
6. Issue EU declaration of conformity and affix CE marking
7. Registration in EU database
This applies to operators
If you are using a purchased system, the focus is not on documentation, but on proper operation (Art. 26 AI Act):
- Use the system as intended in the instructions for use
- Establish human oversight and appoint competent individuals for this purpose
- Keep logs and inform the provider of any risks
- Inform employees before commissioning (Art. 26 para. 7 AI Act)
- Fundamental rights impact assessment, if applicable (Art. 27 AI Act)
Enforcement of the regulation and potential penalties
In Germany, the authority responsible for monitoring and enforcing the AI Act is the Federal Network Agency . As a market surveillance authority , it monitors compliance with the regulation and serves as a point of contact for European institutions. The new Coordination and Competence Center for the AI Act (KoKIVO) also collaborates with other public bodies and provides advice on decision-making.
What penalties do companies face for violating the AI Act?
The fines follow the structure of the GDPR, though the maximum amounts are higher. For SMEs and start-ups, the lower of the two amounts applies in each case:
Challenges in implementing the AI Act
The AI Act creates a secure legal framework for the use of AI for the first time. Nevertheless, there are points of criticism:
1. Unclear risk classification: Many companies are unsure whether their AI systems are considered high-risk.
2. High bureaucratic burden: In particular, SMEs fear the documentation and auditing requirements.
3. Stifling innovation: Strict regulations could put European companies at a disadvantage in global competition.
Outlook: What’s next for the AI Act
With the AI Act, the European Union has taken an important step toward making the use of AI safer and more responsible.
For companies, this means:
✅ Take action now: Don't wait until the next deadline
✅ Rely on experts: AI compliance is complex
✅ Leverage synergies: Integrated approach to GDPR, NIS2, and the AI Act
✅ Centralize your documentation: Compliance platforms save up to 70% of your time
We provide guidance on implementing the EU AI Act and keep you up to date on deadlines and developments like the Digital Omnibus.
Still have questions? We have the answers.
The AI Act came into force on August 1, 2024. Full applicability for high-risk AI systems will apply from August 2, 2026. The prohibition of AI with unacceptable risk has already been in effect since February 2, 2025.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.














