Skip to main content
NexPatch
AI Compliance · EU AI Act

AI compliance and the EU AI Act.

The EU AI Act classifies AI systems by risk and attaches staggered duties to each class, with deadlines running from August 2024 to August 2027. What matters most for a company is which risk category a specific system falls into and which deadline applies to it. This page gives you the practical classification - it does not replace legal advice for your specific case.

Data Intake
Version Control
Output Monitoring
Audit Export

What the EU AI Act regulates

The EU AI Act is the European regulation governing AI systems. Unlike many earlier digital laws, it does not start from the technology, but from the risk a specific system poses to people. A facial recognition system used in public spaces is therefore treated differently from a system for internal scheduling, even though both can rest on similar technical foundations.

For working with the law in practice, one thing matters most: it is not the language model itself that gets classified, but the specific purpose it is used for. The same model can pose minimal risk in one use case and high risk in another, depending on which decision it prepares or makes.

The four risk categories

Risk categoryExampleConsequence
Unacceptable riskSocial scoring of people by the stateProhibited
High riskSystems under Annex III, such as employment selection or credit checksExtensive duties, including documentation, human oversight, risk management
Limited riskChatbots with direct user contactTransparency obligation - users must be able to tell they are dealing with a system
Minimal riskInternal tools with no material effect on peopleNo specific obligations under the Act

The key deadlines

DateWhat takes effect
1 August 2024The EU AI Act enters into force
2 February 2025Prohibited practices may no longer be used
2 August 2025Obligations for general-purpose AI models apply
2 August 2026Obligations for high-risk systems under Annex III apply
2 August 2027Obligations for embedded high-risk systems in already-regulated products apply

These deadlines affect different kinds of systems at different points in time. For most Mittelstand companies, 2 August 2026 matters most, because it covers classic high-risk applications such as employment selection or credit checks.

What this means in practice for your AI project

The first question for any new project is which risk category the planned system falls into. Most internal tools - an agent that pre-sorts emails or summarises documents, for example - fall into the minimal or limited risk category and trigger no extensive obligations. Systems that help decide on employment, credit, access to education or similarly consequential outcomes, on the other hand, often fall under high risk and require documentation, human oversight and risk management that we build in from the start. We review the classification with you during the assessment on every project, before the actual pilot begins.

This page does not replace legal advice. For a binding legal assessment in a specific case, please consult a specialised law firm; we provide the technical and organisational classification that prepares such a review.

Anyone still unsure today whether a planned project even falls under the EU AI Act should not leave that question until shortly before one of the deadlines above. The classification takes time, because it has to account for the specific use case, the people affected and the data used, not just the technology deployed. The earlier this classification happens, the more likely a system can be built from the outset so the later review holds no surprises.

How we build compliance into delivery

When building private AI infrastructure and rolling out AI agents, we review the risk category, document the decisions made, and set up the approval logic so a later review by a regulator or an audit stays traceable. Detail on the technical foundation is at private AI infrastructure and AI agents for companies, detail on our ongoing operating commitment at Operations.

Frequently asked questions