AI compliance and the EU AI Act.
The EU AI Act classifies AI systems by risk and attaches staggered duties to each class, with deadlines running from August 2024 to August 2027. What matters most for a company is which risk category a specific system falls into and which deadline applies to it. This page gives you the practical classification - it does not replace legal advice for your specific case.
What the EU AI Act regulates
The EU AI Act is the European regulation governing AI systems. Unlike many earlier digital laws, it does not start from the technology, but from the risk a specific system poses to people. A facial recognition system used in public spaces is therefore treated differently from a system for internal scheduling, even though both can rest on similar technical foundations.
For working with the law in practice, one thing matters most: it is not the language model itself that gets classified, but the specific purpose it is used for. The same model can pose minimal risk in one use case and high risk in another, depending on which decision it prepares or makes.
The four risk categories
| Risk category | Example | Consequence |
|---|---|---|
| Unacceptable risk | Social scoring of people by the state | Prohibited |
| High risk | Systems under Annex III, such as employment selection or credit checks | Extensive duties, including documentation, human oversight, risk management |
| Limited risk | Chatbots with direct user contact | Transparency obligation - users must be able to tell they are dealing with a system |
| Minimal risk | Internal tools with no material effect on people | No specific obligations under the Act |
The key deadlines
| Date | What takes effect |
|---|---|
| 1 August 2024 | The EU AI Act enters into force |
| 2 February 2025 | Prohibited practices may no longer be used |
| 2 August 2025 | Obligations for general-purpose AI models apply |
| 2 August 2026 | Obligations for high-risk systems under Annex III apply |
| 2 August 2027 | Obligations for embedded high-risk systems in already-regulated products apply |
These deadlines affect different kinds of systems at different points in time. For most Mittelstand companies, 2 August 2026 matters most, because it covers classic high-risk applications such as employment selection or credit checks.
What this means in practice for your AI project
The first question for any new project is which risk category the planned system falls into. Most internal tools - an agent that pre-sorts emails or summarises documents, for example - fall into the minimal or limited risk category and trigger no extensive obligations. Systems that help decide on employment, credit, access to education or similarly consequential outcomes, on the other hand, often fall under high risk and require documentation, human oversight and risk management that we build in from the start. We review the classification with you during the assessment on every project, before the actual pilot begins.
This page does not replace legal advice. For a binding legal assessment in a specific case, please consult a specialised law firm; we provide the technical and organisational classification that prepares such a review.
Anyone still unsure today whether a planned project even falls under the EU AI Act should not leave that question until shortly before one of the deadlines above. The classification takes time, because it has to account for the specific use case, the people affected and the data used, not just the technology deployed. The earlier this classification happens, the more likely a system can be built from the outset so the later review holds no surprises.
How we build compliance into delivery
When building private AI infrastructure and rolling out AI agents, we review the risk category, document the decisions made, and set up the approval logic so a later review by a regulator or an audit stays traceable. Detail on the technical foundation is at private AI infrastructure and AI agents for companies, detail on our ongoing operating commitment at Operations.