EU AI Act: What Requirements Apply to Your AI System?

From High-Risk AI to Transparency Requirements: What Companies Should Consider

EU AI Act – Why Compliance Starts with Proper Classification

What obligations apply to our AI system?

The EU AI Act is extensive. That, at first glance, isn't surprising. European regulations are rarely drafted with the ambition of fitting comfortably on the back of a postcard.

For companies, however, this raises a very practical question:

What obligations actually apply to our specific AI system?

The answer does not depend solely on whether artificial intelligence is used anywhere. Rather, the decisive factors are the company’s role, the system’s purpose, its risk class, and the way it is developed, offered, or deployed.

That's why AI Act compliance doesn't start with a folder full of policies.

It begins with classification.

The first question: Is it even an AI system?

Not all automated software is automatically an AI system as defined by the EU AI Act.

The regulation covers machine-based systems that operate with a certain degree of autonomy and use inputs to generate outputs such as predictions, content, recommendations, or decisions. These outputs, in turn, can influence real or virtual environments.

That sounds technical. In everyday business, however, it’s all about very specific applications:

  • Chatbots and AI assistants,
  • Candidate selection systems,
  • automated credit assessments,
  • AI-powered medical applications,
  • Biometric recognition systems,
  • generative AI for text, images, audio, or video,
  • AI components in machines and other products.

Before discussing obligations, it is therefore necessary to clarify whether the specific use case falls under the definition at all.

After all, even regulation needs a point of entry. You just need to know which door to go through.


EU AI Act

What role does the company play?

One of the most important questions in the EU AI Act is not: “Do you use AI?”

The question is: In what capacity are you acting?

Among other things, the AI Act distinguishes between providers, operators, importers, distributors, product manufacturers, and authorized representatives.

A supplier develops an AI system or has one developed and brings it to market under its own name. An operator deploys an AI system under its own responsibility. An importer brings a system from a supplier based outside the EU to the European market. Distributors make systems available within the supply chain.

These roles are not merely a legal formality. They determine which obligations apply.

A company that uses a ready-made AI chatbot internally is often in a different position than a company that offers its own AI service under its own brand.

On top of that, roles can change.

Anyone who significantly modifies an existing AI system, redefines its purpose, or markets it under their own name may become a provider themselves. What may seem like a minor adjustment can thus result in a significantly broader set of obligations.

So the EU AI Act does indeed recognize the moment when “We just made a minor adjustment” turns into a regulatory “Then you’re now responsible.”

Not every AI system is high-risk

The EU AI Act follows a risk-based approach. The greater the potential risk to health, safety, or fundamental rights, the more extensive the requirements are.

Certain practices are completely prohibited. These include, for example, various forms of manipulative AI, social scoring, and certain biometric or predictive applications.

In addition, there are high-risk AI systems. These may include systems in areas such as employment, education, critical infrastructure, medical applications, credit scoring, law enforcement, migration, or the justice system.

Whether a system is actually considered high-risk AI, however, does not depend solely on a broad industry classification.

Among other things, the following should be reviewed:

  • What is the purpose of the system?
  • Does it influence decisions regarding natural persons?
  • Could it significantly compromise health, safety, or fundamental rights?
  • Is it a component of a regulated product?
  • Is this product subject to a conformity assessment?
  • Does the AI merely support a preparatory or narrowly defined task?
  • Is there adequate human oversight?

An AI system used in human resources is therefore not automatically considered high-risk simply because the word “application” appears somewhere. At the same time, a system that influences decision-making should not be labeled as a harmless assistant if it actually shapes selection decisions.

The classification must reflect actual use—not the most flattering description in the project proposal.

High risk means systematic governance

If an AI system is classified as high-risk, it is subject to comprehensive requirements.

Providers must take into account, among other things, risk management, technical documentation, data quality, logging, human oversight, accuracy, robustness, and cybersecurity. A conformity assessment may also be required before the product is placed on the market.

Operators must use high-risk systems in accordance with the instructions for use, monitor their operation, and assign appropriate personnel to oversee them. Depending on the area of application, additional information, documentation, or audit requirements may apply.

This shows that AI compliance is not a single legal document.

It combines law, technology, processes, information security, data protection, quality management, and corporate responsibility.

That is precisely why AI systems should not be evaluated from a legal perspective only shortly before their implementation. The relevant question is not, “Can we still document this in the end?”

Rather: “Did we make it manageable from the very beginning?”

Transparency Requirements for Chatbots and Generative AI

Even AI systems that are not classified as high-risk can give rise to legal obligations.

Transparency requirements for interactive and generative AI systems are particularly relevant. People should be able to recognize when they are interacting directly with an AI system. In certain cases, generated or manipulated content must be technically labeled or disclosed in a way that is visible to those affected.

This applies, for example, to:

  • Chatbots and AI agents,
  • synthetically generated images, audio, or video content,
  • Deepfakes,
  • Systems for emotion recognition or biometric categorization,
  • AI-generated texts on topics of public interest.

Here, too, it depends on the role. Providers must design their systems accordingly from a technical standpoint. In certain cases, operators must inform the individuals concerned or label the content.

So a text doesn't become "human" just because it's published without robot emojis.

AI expertise isn't just for specialists

One key requirement is already in place: Providers and operators must ensure an appropriate level of AI expertise.

This does not apply only to developers. Employees who operate AI systems, evaluate results, or base decisions on them must also have a sufficient understanding of their capabilities and risks.

The appropriate training depends on the operational context.

A marketing department that uses generative AI for design requires different skills than a human resources department that uses AI-powered evaluations. Executives, in turn, must understand the responsibilities they bear and the control structures that are necessary.

AI literacy, therefore, does not mean showing everyone the same presentation and then printing out a certificate of participation.

It must be role-based, practical, and easy to understand.

What Role an AI Officer Can Play

The EU AI Act does not generally require every company to appoint an AI officer.

Nevertheless, a feature like this can be very useful.

The AI Officer can coordinate:

  • which AI systems are used in the company,
  • what roles the company plays in this process,
  • how systems are classified on a risk-based basis,
  • which departments need to be involved,
  • what documentation and training are required,
  • how changes to systems are evaluated,
  • and how regulatory developments are monitored.

However, the AI Officer does not replace data protection officers, information security, legal, compliance, or IT. Instead, it brings these perspectives together.

After all, many problems don't arise because no one is responsible. They arise because five people are each partially responsible, and each of them reasonably assumes that the others will take care of the rest.

An AI inventory as a starting point

Companies should start by compiling a comprehensive AI inventory.

It should include at least the following points:

  • Name and description of the AI system,
  • Vendor and model used,
  • Department in charge,
  • Purpose and specific use,
  • data used,
  • affected individuals,
  • Role of the company,
  • possible risk class,
  • Transparency requirements,
  • human control mechanisms,
  • existing contracts and documentation,
  • Planned changes or additions.

Such an inventory does not in itself ensure full compliance. But without an inventory, any governance framework remains incomplete.

After all, you can only manage what you know. That doesn't automatically mean the rest is problem-free—it's just less well understood.

Conclusion

The EU AI Act cannot be effectively implemented using a single checklist for all systems.

Each exam begins with a specific use case:

  • Is it an AI system?
  • What role does the company play?
  • Does the application fall within the scope of this regulation?
  • Is this a prohibited practice, high-risk AI, or a system subject to transparency requirements?
  • What organizational and technical measures result from this?

Only then can it be determined which obligations actually apply.

An AI Officer can coordinate this process and ensure that classification, documentation, AI expertise, and ongoing monitoring do not operate in isolation from one another.

After all, under the EU AI Act, not every AI system is treated the same.

But each one deserves a thorough review.

```