NMS - New Media Service GmbH
Der Hegau Tower in Singen, Sitz der NMS

AI Act: are you ready? All to-dos at a glance

Artificial intelligence (AI) is a central factor in digital transformation and drives innovation across various industries.

News

Article header: a person with a covered face and large sunglasses in an NMS polo shirt sitting on a sofa, with the question Wer ist dein KI-Beauftragter? below

Artificial intelligence (AI) has long been a key driver of digital transformation. Whether in industry, healthcare or the financial sector – AI technologies promote innovation and open up new business potential. To shape this progress responsibly, the European Union has, with the Artificial Intelligence Act (AI Act), created a comprehensive legal framework. The aim is to promote trustworthy AI systems while minimising risks.

The regulation is based on a risk-based approach and has been in force since 1 August 2024. EU Member States are now required to transpose the AI Act into national law. In many places, the specific implementation of the requirements is still underway.

Companies that develop or deploy AI should nevertheless familiarise themselves with the new regulations at an early stage. This is because the requirements are complex and affect numerous areas – from transparency obligations to risk assessments and documentation standards. Proactive engagement with the AI Act is crucial to ensure timely compliance and continue to safely exploit innovation potential.


Who does the AI Act apply to and what role does your company play?

The AI Act applies regardless of a company's location – the decisive factor is whether an AI system:

  • is placed on the market in the EU or
  • has an impact on individuals in the EU

From developers and importers to operators, the AI Act holds all actors along the AI value chain accountable.

Companies can assume the following roles:

Providers

Develop AI systems and make them available for use or place them on the market under their own name or trademark

Operators

Deploy AI systems for business purposes without developing them further or offering them under their own brand.

Product manufacturers

Offer or distribute AI applications under their own name or brand in the EU as a product or component of a product.

Importers

AI systems from abroad are brought onto the European internal market.

Distributors

AI systems are sold to end users or other companies.

What risks are associated with the use of AI systems?

The AI Act specifies different requirements for a wide variety of AI systems. These requirements are based on the respective risk potential. In principle: The higher the risk, the stricter the requirements.

Every company must categorise its AI systems according to the classified risks in order to implement appropriate measures. The risk is divided into the following risk groups:

Unacceptable risk

Prohibited AI practices under Article 5 of the AI Act

Since February 2025 certain AI applications have been prohibited in the EU as they represent an unacceptable risk to fundamental rights, security and EU values.

These include:

  • Manipulative techniques
    AI systems that influence people through subliminal or deceptive techniques and significantly restrict their freedom of choice.
  • Exploitation of vulnerable groups
    Systems that specifically exploit the vulnerabilities of children, elderly people, people with disabilities or those in precarious circumstances to influence their behaviour.
  • Social scoring
    Evaluation of individuals based on their social behaviour or personal characteristics, which can lead to unjustified disadvantage – e.g. by landlords or authorities.
  • Real-time remote biometric identification
    Use of facial recognition in public spaces in real time – with exceptions for law enforcement in cases of serious crimes, counter-terrorism or missing person searches.
  • Biometric categorisation
    Deduction of sensitive characteristics such as ethnic origin, religion, political opinion or sexual orientation – with narrow exceptions for law enforcement.
  • Emotion recognition in the workplace or in educational institutions
    Prohibited without explicit consent – permitted only for medical or safety-related purposes.

High risk

  • High-risk AI systems in the AI Act

Most regulations of the AI Act concern so-called high-risk AI systems, as they are used in sensitive areas and can have a significant impact in the event of malfunctions – e.g. in autonomous driving. For these systems, strict requirements apply.

When is an AI system considered high-risk?

A system falls into the high-risk category if it:

  • Annex I: is part of a product covered by existing EU product regulations (e.g. toys, machinery, vehicles) and requires a conformity assessment.
  • Annex III: is used in one of the following eight sensitive areas of application : Remote biometric identification(e.g. facial recognition)
    Critical infrastructures(e.g. energy supply, transport)
    Education(e.g. evaluation of exams or access to education)
    Employment & human resources management(e.g. recruitment procedures, promotions)
    Access to essential services(e.g. loans, insurance, emergency services)
    Law enforcement(e.g. lie detectors, evaluation of evidence)
    Migration & border control(e.g. asylum applications, identity verification)
    Justice & democratic processes(e.g. supporting courts, influencing elections)

Limited risk

  • Transparency obligations for low-risk AI systems

Even AI systems with low risk, such as chatbots, are subject to certain requirements:

  • Labelling requirement: Users must be clearly informed that they are interacting with an AI or that content (e.g. images, text, videos) has been artificially generated.
  • Deepfakes: Content that appears deceptively real and is potentially manipulative or misleading must be clearly labelled as AI-generated – by both providers and operators.
  • Systemic risk: For particularly powerful AI models, additional, tiered regulations apply, as they can pose a higher systemic risk.

Low risk

This includes low-risk AI systems, such as spam filters. There are no mandatory requirements for these applications. However, companies are recommended to voluntarily develop a code of conduct for the responsible use of AI and implement it.

The AI Act provides that within twelve months of the regulation coming into force, the European Commission will make such a voluntary AI code of conduct available for support.

Pyramid of the four risk classes of the AI Act, from top to bottom: unacceptable risk with a ban on certain practices, high risk permitted under requirements, limited risk permitted with transparency and disclosure obligations, minimal risk with no requirements beyond existing law

Which implementation deadlines do companies need to know?

To introduce the requirements of the AI Act step by step, the EU has established a clear timeline for implementing the AI laws. With our overview of all key implementation deadlines up to 2026, you will be prepared and won't miss any deadlines.

Timeline of the EU AI Act implementation deadlines in four stages: since February 2025 the ban on certain AI systems applies, from August 2025 the obligations for providers of general-purpose AI models, from August 2026 the remaining provisions and from August 2027 the classification rules for high-risk systems