
EU AI Act: What companies must implement now
The AI Act has applied in stages since August 2024. For companies using AI, the obligation regarding AI literacy has already been binding since February 2025.
ISO 27001 · Microsoft Solution Partner
Most companies do not develop AI: they deploy it. This comes with obligations that many are not yet aware of. The most important one already applies: AI literacy among employees.
The timeline at a glance
Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in stages:
- Since 2 February 2025: Prohibition of certain AI practices (such as social scoring or manipulative systems) and the obligation regarding AI literacy pursuant to Article 4, for providers as well as deployers.
- Since 2 August 2025: Obligations for providers of general-purpose AI models as well as governance structures at EU level.
- From 2 August 2026: The majority of the Regulation, in particular the requirements for high-risk systems under Annex III and transparency obligations.
- From 2 August 2027: High-risk systems embedded as safety components in regulated products.
Provider or deployer? The decisive distinction
The Regulation primarily distinguishes between providers (who develops an AI system and places it on the market) and deployers (who uses an AI system under their own responsibility). Anyone using Microsoft Copilot, ChatGPT or an AI phone system in their company is generally a deployer.
Caution: A deployer can become a provider, for instance, if a system is substantially modified, made available under its own name, or used for a purpose other than intended by the provider. This classification should be documented.
Four risk classes
Prohibited practices: including social scoring, exploitation of vulnerabilities, and untargeted scraping of facial images. Prohibited since February 2025.
High-risk systems: such as in employment (applicant selection, performance evaluation), critical infrastructure, education, or credit scoring. Extensive obligations from 2026.
Systems with transparency obligations: Chatbots, emotion recognition, synthetic content. Users must be able to recognise that they are dealing with AI.
Low risk: the majority of business applications. Here, AI literacy and general duties of care primarily apply.
The outer layer represents most business uses of AI; the core contains what is prohibited altogether.
Obligations for deployers
- AI literacy (Art. 4): Employees operating AI systems must possess sufficient knowledge, appropriate to their role, prior training, and context of use. This is the obligation that already applies today and can be proven most quickly: through training, usage policies, and documented instructions.
- Use in accordance with provider instructions: Systems must be used as provided for in the instructions for use. Deviations may alter the role of the deployer.
- Human oversight: For systems with significant impacts, a person must be able to review the results and intervene, and be qualified and authorised to do so.
- Transparency towards affected persons: Where AI interacts with humans or generates content, this must be clearly indicated.
- Data protection remains applicable in parallel: The AI Act does not replace DSGVO/GDPR. Personal data in AI systems still requires a legal basis, purpose limitation, and data subject rights.
What this means in practice
For most companies, it comes down to four building blocks: a register of deployed AI systems with purpose and classification, a usage policy, clarifying what is permitted and prohibited, a training concept for AI literacy, and technical guardrails, so that sensitive data does not reach unsuitable systems.
Precisely these building blocks are covered by AI Governance for Microsoft 365, from sensitivity labels and permissions to logging. In addition, the Copilot Readiness Assessment clarifies whether the data basis is suitable for safe deployment, and the LLM strategy, which tools should actually be deployed.
How NMS supports you
NMS audits the inventory of AI systems, classifies them by risk class, develops the usage policy, sets up technical guardrails in Microsoft 365 and Azure, and conducts training for AI literacy, fully documented so that implementation is verifiable. Where AI regulation meets information security, the approach interlocks with NIS2 and ISO 27001.
Legal notice: NMS provides technical and organisational IT consultancy, not legal advice within the meaning of the Legal Services Act (Rechtsdienstleistungsgesetz). The deadlines, thresholds, and penalty ranges mentioned here reflect the state of information as of the date specified and do not replace individual legal review. Binding information is provided by the competent authorities (in particular the BSI) as well as specialised legal counsel. Status: July 2026
Does the EU AI Act also apply to us if we only use Microsoft Copilot?
Yes. Anyone deploying an AI system within their company is a deployer within the meaning of the Regulation. The obligation regarding AI literacy pursuant to Article 4 has applied since 2 February 2025, regardless of whether the system was purchased or developed in-house.
What does AI literacy pursuant to Article 4 mean in practice?
Employees operating AI systems must understand their functionality, limitations, and risks to the extent required by their role. In practice, this means: role-based training, an understandable usage policy, and documentation of who was instructed when.
Are our AI applications high-risk systems?
Usually not. Typical office applications such as drafting text or summaries fall into the low-risk category. It becomes high-risk in cases such as systems for applicant selection, performance evaluation, credit scoring, or the operation of critical infrastructure. The classification should be documented for each system.
What happens in the event of non-compliance?
The Regulation provides for tiered fines, with upper limits of up to €35 million or 7 per cent of global annual turnover for prohibited practices; lower limits apply for other infringements. The national supervisory structure and the specific case are decisive.
How long does implementation take in medium-sized enterprises?
Taking inventory, classification, and drafting a usage policy are usually completed in a few weeks. Setting up technical guardrails and training the workforce takes longer, both can easily be combined with an ongoing Microsoft 365 rollout.

Solutions in a new dimension.
One conversation is enough to find out where IT, Microsoft Cloud and AI can take real weight off day-to-day business.
Your contact: Jan Emmerich, Managing Director