
AI Act: are you ready? All to-dos at a glance
Artificial intelligence (AI) is a central factor in digital transformation and drives innovation across various industries.
News

Artificial intelligence (AI) has long been a key driver of digital transformation. Whether in industry, healthcare or the financial sector – AI technologies promote innovation and open up new business potential. To shape this progress responsibly, the European Union has, with the Artificial Intelligence Act (AI Act), created a comprehensive legal framework. The aim is to promote trustworthy AI systems while minimising risks.
The regulation is based on a risk-based approach and has been in force since 1 August 2024. EU Member States are now required to transpose the AI Act into national law. In many places, the specific implementation of the requirements is still underway.
Companies that develop or deploy AI should nevertheless familiarise themselves with the new regulations at an early stage. This is because the requirements are complex and affect numerous areas – from transparency obligations to risk assessments and documentation standards. Proactive engagement with the AI Act is crucial to ensure timely compliance and continue to safely exploit innovation potential.
Who does the AI Act apply to and what role does your company play?
The AI Act applies regardless of a company's location – the decisive factor is whether an AI system:
- is placed on the market in the EU or
- has an impact on individuals in the EU
From developers and importers to operators, the AI Act holds all actors along the AI value chain accountable.
Companies can assume the following roles:
Providers
Develop AI systems and make them available for use or place them on the market under their own name or trademark
Operators
Deploy AI systems for business purposes without developing them further or offering them under their own brand.
Product manufacturers
Offer or distribute AI applications under their own name or brand in the EU as a product or component of a product.
Importers
AI systems from abroad are brought onto the European internal market.
Distributors
AI systems are sold to end users or other companies.
What risks are associated with the use of AI systems?
The AI Act specifies different requirements for a wide variety of AI systems. These requirements are based on the respective risk potential. In principle: The higher the risk, the stricter the requirements.
Every company must categorise its AI systems according to the classified risks in order to implement appropriate measures. The risk is divided into the following risk groups:
Unacceptable risk
Prohibited AI practices under Article 5 of the AI Act
Since February 2025 certain AI applications have been prohibited in the EU as they represent an unacceptable risk to fundamental rights, security and EU values.
These include:
- Manipulative techniques
AI systems that influence people through subliminal or deceptive techniques and significantly restrict their freedom of choice. - Exploitation of vulnerable groups
Systems that specifically exploit the vulnerabilities of children, elderly people, people with disabilities or those in precarious circumstances to influence their behaviour. - Social scoring
Evaluation of individuals based on their social behaviour or personal characteristics, which can lead to unjustified disadvantage – e.g. by landlords or authorities. - Real-time remote biometric identification
Use of facial recognition in public spaces in real time – with exceptions for law enforcement in cases of serious crimes, counter-terrorism or missing person searches. - Biometric categorisation
Deduction of sensitive characteristics such as ethnic origin, religion, political opinion or sexual orientation – with narrow exceptions for law enforcement. - Emotion recognition in the workplace or in educational institutions
Prohibited without explicit consent – permitted only for medical or safety-related purposes.
High risk
- High-risk AI systems in the AI Act
Most regulations of the AI Act concern so-called high-risk AI systems, as they are used in sensitive areas and can have a significant impact in the event of malfunctions – e.g. in autonomous driving. For these systems, strict requirements apply.
When is an AI system considered high-risk?
A system falls into the high-risk category if it:
- Annex I: is part of a product covered by existing EU product regulations (e.g. toys, machinery, vehicles) and requires a conformity assessment.
- Annex III: is used in one of the following eight sensitive areas of application : Remote biometric identification(e.g. facial recognition)
Critical infrastructures(e.g. energy supply, transport)
Education(e.g. evaluation of exams or access to education)
Employment & human resources management(e.g. recruitment procedures, promotions)
Access to essential services(e.g. loans, insurance, emergency services)
Law enforcement(e.g. lie detectors, evaluation of evidence)
Migration & border control(e.g. asylum applications, identity verification)
Justice & democratic processes(e.g. supporting courts, influencing elections)
Limited risk
- Transparency obligations for low-risk AI systems
Even AI systems with low risk, such as chatbots, are subject to certain requirements:
- Labelling requirement: Users must be clearly informed that they are interacting with an AI or that content (e.g. images, text, videos) has been artificially generated.
- Deepfakes: Content that appears deceptively real and is potentially manipulative or misleading must be clearly labelled as AI-generated – by both providers and operators.
- Systemic risk: For particularly powerful AI models, additional, tiered regulations apply, as they can pose a higher systemic risk.
Low risk
This includes low-risk AI systems, such as spam filters. There are no mandatory requirements for these applications. However, companies are recommended to voluntarily develop a code of conduct for the responsible use of AI and implement it.
The AI Act provides that within twelve months of the regulation coming into force, the European Commission will make such a voluntary AI code of conduct available for support.

Which implementation deadlines do companies need to know?
To introduce the requirements of the AI Act step by step, the EU has established a clear timeline for implementing the AI laws. With our overview of all key implementation deadlines up to 2026, you will be prepared and won't miss any deadlines.


Solutions in a new dimension.
One conversation is enough to find out where IT, Microsoft Cloud and AI can take real weight off day-to-day business.
Your contact: Daniel Penninger, Managing Director