Skip to content

Guide · EU AI Act

The EU AI Act explained – and what your company needs to do now

Regulation (EU) 2024/1689 governs the use of artificial intelligence across the EU. It affects not only developers but every business that uses AI systems – from chatbots to candidate screening. The first obligation already applies: sufficient AI literacy of your staff.

What is the AI Act?

The AI Act entered into force on 1 August 2024 and applies directly in all EU member states. It follows a risk-based approach: the higher the risk an AI system poses to health, safety and fundamental rights, the stricter the requirements.

Obligations apply mainly to providers (who develop AI systems or place them on the market under their own name) and deployers (who use AI systems professionally). Most companies are deployers – for example when using ChatGPT, Copilot or AI-powered HR and CRM tools.

The four risk classes

  • Unacceptable risk

    Prohibited practices, e.g. social scoring, manipulative AI or emotion recognition in the workplace (narrow exceptions).

  • High risk

    E.g. AI in recruitment, credit scoring or critical infrastructure – extensive duties on risk management, documentation and human oversight.

  • Limited risk

    Transparency duties, e.g. labelling chatbots and AI-generated content (deepfakes).

  • Minimal risk

    E.g. spam filters – no specific duties, but the AI literacy obligation still applies.

Mandatory today

AI literacy: a training duty for managers and employees

Since 2 February 2025, Art. 4 AI Act requires providers and deployers to ensure that their staff and anyone using AI systems on their behalf have a sufficient level of AI literacy. This applies regardless of risk class – even if your team “only” uses ChatGPT or Copilot.

  • In practice, this duty can hardly be met without training – companies must actively upskill their people.
  • The benchmark is technical knowledge, experience, education and the specific context of use – off-the-shelf training is often not enough.
  • Measures should be documented so they can be demonstrated to authorities, business partners and in liability cases.
  • Missing AI literacy increases liability risks – e.g. data protection breaches, leaks of confidential information or flawed AI outputs.

Who needs which skills?

Management & executives

Responsible for implementation: AI strategy, governance, risks, liability and organisational duties.

Employees using AI

Safe everyday use: opportunities and limits, data protection, confidentiality, reviewing outputs.

AI officers & specialist teams

In-depth knowledge of risk classes, documentation, transparency and internal AI policies.

View AI training

Key deadlines

  1. 1 August 2024

    The AI Act enters into force.

  2. 2 February 2025

    Prohibited practices and the AI literacy obligation (Art. 4) apply.

  3. 2 August 2025

    Rules for general-purpose AI models (GPAI), governance and penalties.

  4. 2 August 2026

    Most remaining obligations, incl. transparency duties; high-risk duties under Annex III (timeline partly being adjusted at EU level).

  5. 2 August 2027

    High-risk AI in regulated products (Annex I).

Fines for prohibited practices reach up to €35 million or 7% of global annual turnover.

5 steps to AI compliance

  1. 1

    Inventory

    Which AI systems are used in the company – including “shadow AI”?

  2. 2

    Classify role & risk

    Provider or deployer? Which risk class applies?

  3. 3

    Build AI literacy

    Targeted, documented training for management and staff.

  4. 4

    Introduce an AI policy

    Clear rules on permitted tools, data and approvals.

  5. 5

    Assign responsibility

    Appoint an AI officer and align with data protection and compliance.

AI compliance calculator

Which AI Act obligations apply to you?

5 inputs – get an instant first assessment of your risk and obligations. Nothing is stored.

1.Does your company use AI?
2.What is your role?
3.Is AI used in any of these areas?
4.How many employees do you have?
5.Have your employees been trained on AI?

0 / 5

FAQ on the AI Act

Does the AI Act apply if we only use ChatGPT?

Yes. Anyone using AI systems professionally is a deployer. At least the AI literacy obligation (Art. 4) has applied since February 2025 – possibly transparency duties as well.

Is there really a training obligation?

Art. 4 requires “measures” to ensure sufficient AI literacy. In practice this is only achievable through training and instruction tailored to role and use – for managers and employees alike.

Do we need an AI officer?

The AI Act does not expressly require one. However, a designated responsible person is the most effective way to manage the obligations – internal or external.

How do the AI Act and GDPR interact?

Both apply in parallel. As soon as AI processes personal data, legal basis, transparency and possibly a DPIA must be assessed.

Use AI lawfully – with advice from a single source

As a lawyer for IT law and data protection and a certified AI officer and AI manager, I support you from the initial inventory to training your team – in Düsseldorf, NRW and online.

This guide provides a general overview and does not replace individual legal advice. As of September 2026.

Book a free intro call