Management & executives
Responsible for implementation: AI strategy, governance, risks, liability and organisational duties.
Guide · EU AI Act
Regulation (EU) 2024/1689 governs the use of artificial intelligence across the EU. It affects not only developers but every business that uses AI systems – from chatbots to candidate screening. The first obligation already applies: sufficient AI literacy of your staff.
The AI Act entered into force on 1 August 2024 and applies directly in all EU member states. It follows a risk-based approach: the higher the risk an AI system poses to health, safety and fundamental rights, the stricter the requirements.
Obligations apply mainly to providers (who develop AI systems or place them on the market under their own name) and deployers (who use AI systems professionally). Most companies are deployers – for example when using ChatGPT, Copilot or AI-powered HR and CRM tools.
Unacceptable risk
Prohibited practices, e.g. social scoring, manipulative AI or emotion recognition in the workplace (narrow exceptions).
High risk
E.g. AI in recruitment, credit scoring or critical infrastructure – extensive duties on risk management, documentation and human oversight.
Limited risk
Transparency duties, e.g. labelling chatbots and AI-generated content (deepfakes).
Minimal risk
E.g. spam filters – no specific duties, but the AI literacy obligation still applies.
Mandatory today
Since 2 February 2025, Art. 4 AI Act requires providers and deployers to ensure that their staff and anyone using AI systems on their behalf have a sufficient level of AI literacy. This applies regardless of risk class – even if your team “only” uses ChatGPT or Copilot.
Management & executives
Responsible for implementation: AI strategy, governance, risks, liability and organisational duties.
Employees using AI
Safe everyday use: opportunities and limits, data protection, confidentiality, reviewing outputs.
AI officers & specialist teams
In-depth knowledge of risk classes, documentation, transparency and internal AI policies.
1 August 2024
The AI Act enters into force.
2 February 2025
Prohibited practices and the AI literacy obligation (Art. 4) apply.
2 August 2025
Rules for general-purpose AI models (GPAI), governance and penalties.
2 August 2026
Most remaining obligations, incl. transparency duties; high-risk duties under Annex III (timeline partly being adjusted at EU level).
2 August 2027
High-risk AI in regulated products (Annex I).
Fines for prohibited practices reach up to €35 million or 7% of global annual turnover.
Inventory
Which AI systems are used in the company – including “shadow AI”?
Classify role & risk
Provider or deployer? Which risk class applies?
Build AI literacy
Targeted, documented training for management and staff.
Introduce an AI policy
Clear rules on permitted tools, data and approvals.
Assign responsibility
Appoint an AI officer and align with data protection and compliance.
AI compliance calculator
5 inputs – get an instant first assessment of your risk and obligations. Nothing is stored.
0 / 5
Yes. Anyone using AI systems professionally is a deployer. At least the AI literacy obligation (Art. 4) has applied since February 2025 – possibly transparency duties as well.
Art. 4 requires “measures” to ensure sufficient AI literacy. In practice this is only achievable through training and instruction tailored to role and use – for managers and employees alike.
The AI Act does not expressly require one. However, a designated responsible person is the most effective way to manage the obligations – internal or external.
Both apply in parallel. As soon as AI processes personal data, legal basis, transparency and possibly a DPIA must be assessed.
As a lawyer for IT law and data protection and a certified AI officer and AI manager, I support you from the initial inventory to training your team – in Düsseldorf, NRW and online.
This guide provides a general overview and does not replace individual legal advice. As of September 2026.