Many companies are currently asking themselves the same question: When will the EU AI Act actually apply to us?
The short answer is: The EU AI Act is already in effect. However, it will become fully applicable in phases.
And it is precisely this phased implementation that makes things a bit tricky. After all, the AI Act isn’t a law that shows up one morning, sets down its briefcase, and says, “Starting today, everything has to be different.” It’s being rolled out in stages. Some obligations are already in effect. Others will follow. Some transition periods depend on which AI systems a company uses, develops, or offers.
For companies, this means: Don’t wait until the final deadline. Instead, assess now which AI applications are in use within the company, what risks are associated with them, and who is responsible for keeping track of them internally.
This is exactly where the role of the AI Officer comes into play.
The EU AI Act entered into force on August 1, 2024. Most of its provisions will take effect on August 2, 2026. However, there are important interim steps in the meantime and thereafter.
An overview of the most important dates:
As of February 2, 2025, prohibitions on certain AI practices that pose an unacceptable risk, among other things, will take effect. These include, for example, certain forms of social scoring, manipulative AI practices, and impermissible biometric applications. Also relevant since then is the requirement for AI competence: Companies that offer or use AI systems must ensure that employees and other individuals who work with AI systems possess a sufficient level of AI competence.
As of August 2, 2025, key requirements for general-purpose AI models have been in effect. In addition, governance rules and structures at the European level are now in place.
Starting August 2, 2026, the AI Act will become particularly relevant for most companies in practice. At that time, many of the general obligations will take effect, including transparency requirements and numerous organizational requirements that companies must take into account when dealing with AI systems.
Special transition periods apply to certain high-risk AI systems and AI integrated into products. This depends heavily on the sector in which an AI system is used and the role the company plays.
The question “When does the EU AI Act take effect?” is important. But it’s not enough.
After all, it’s not just the effective date of the AI Act that matters. What matters is the role a company plays under the AI Act.
Depending on the answer, the obligations change significantly.
A company that uses AI only occasionally for drafting text faces different challenges than a provider that develops an AI-based system for candidate selection, credit checks, education, medical devices, or critical infrastructure.
The AI Act is risk-based. This means that not all AI is treated the same. However, every AI system should first be properly classified.
Many companies are already using AI. Sometimes officially, sometimes on the side, sometimes as a browser tab that has a surprisingly big impact on day-to-day work.
That is why the first step is not a lengthy legal treatise. The first step is to take stock of the situation.
These questions sound simple. In practice, however, they are often the moment when companies realize: AI has been here for a long time. It’s just that governance hasn’t caught up yet.
The term “AI Officer” is not defined in the EU AI Act as a mandatory role for every company. Therefore, there is no simple rule such as: “Every company must have an AI Officer as of date X.”
Nevertheless, the role is becoming increasingly important in practice.
An AI Officer can help companies structure their approach to AI—not as a fancy title for a business card, but as a clear role responsible for AI governance.
For example, the AI Officer can coordinate:
Precisely because the AI Act will be implemented in phases, we need someone who doesn't just focus on individual deadlines but keeps an eye on the entire process.
One particularly early and important aspect is AI literacy.
Starting in February 2025, providers and operators of AI systems must take steps to ensure that individuals working with AI systems have a sufficient level of AI literacy. This applies not only to developers, but also to line departments, executives, HR, marketing, sales, legal, IT, and all areas where AI is used in practice.
The AI Officer can play a key role here.
He or she can identify training needs, distinguish between target groups, develop internal guidelines, and ensure that AI literacy is not treated as a one-time training session. After all, AI literacy isn’t just a box to check off a list. It is the foundation for ensuring that AI is used in the company in a meaningful, secure, and legally compliant manner.
Or, to put it less formally: Anyone who uses AI should have a general idea of what they're doing—and what they shouldn't be doing.
The greatest benefit of an AI Officer often lies in their role as a liaison.
AI rarely affects just one department. An AI tool in marketing can raise data protection issues. An AI system in recruiting can involve risks related to labor law and anti-discrimination laws. An AI application in customer service can trigger transparency requirements. An AI model in a product can raise questions about high-risk AI, product safety, or documentation.
The AI Officer brings these topics together.
He doesn't replace data protection officers, information security officers, legal staff, or IT. But he ensures that AI issues don't fall through the cracks and gather dust there.
This can be particularly crucial for small and medium-sized businesses. That’s because they often don’t have their own large AI compliance department. Nevertheless, the same questions arise: What are we allowed to do? What do we need to document? Who reviews the tools? Who approves their use? Who monitors changes?
K11 helps companies answer these questions in a structured manner. This includes assessing AI applications, establishing AI governance, providing training on AI competencies, and defining the role of an AI officer.
This role can be established internally or supported by an external AI Officer. What matters is not the title, but the function: Companies need a position that addresses AI not only from a technical perspective, but also from regulatory, organizational, and practical standpoints.
The AI Officer is therefore not something to be put off until later. It is a sensible response to a very pressing question: How do we maintain an overview as AI accelerates and regulation lags behind?
The EU AI Act won't just take effect sometime in the distant future.
It has been in effect since August 1, 2024. The first obligations took effect on February 2, 2025. Additional requirements, particularly those concerning general-purpose AI models and governance structures, took effect on August 2, 2025. For many companies, August 2, 2026, will be the key deadline, as that is when a large portion of the regulations will become applicable in practice.
So the better question is not just: When does the EU AI Act take effect?
Rather:
This is exactly where the AI Officer's work begins.
After all, AI regulation isn't just a matter of timing. It's a governance issue.