Your team already uses AI. That alone brings your company under the EU AI Act - and parts of it apply right now, not in some distant future. You don't have to build AI to be regulated by it; using ChatGPT, Copilot or any AI tool at work makes you a Deployer with obligations of your own. This page explains exactly what applies today, what arrives next, and how to get your EU AI Act compliance in order without the last-minute scramble.
AI Act violations can cost up to €35M or 7% of worldwide annual turnover, GDPR violations up to €20M or 4%, and both can apply at once - beyond the fine, management can be personally liable where supervisory duties are breached (under German law: §130 OWiG, §43 GmbHG). ETHYX brings AI inventory, risk assessment, deployer documentation and AI literacy into one platform, so it never comes to that.
EU AI Act Timeline: What Applies Today and What Arrives Next
What is already enforceable - and what changes later?
The EU AI Act is not a single switch that flips on one date. It applies in stages. Two obligations already bind every company using AI: AI literacy (Article 4) and the ban on unacceptable-risk practices (Article 5), both enforceable since February 2025. The next stage arrives on 2 August 2026, when transparency duties (Article 50) and national enforcement begin. The high-risk obligations, for deployers as well as providers, have moved to December 2027 and beyond under the Digital Omnibus.
The dates that actually matter for your company
| When | What it means for you as a deployer | Status |
|---|---|---|
| Since Feb 2025 | AI literacy (Art. 4) + ban on unacceptable-risk practices (Art. 5) | Enforceable now |
| Since 2018 | GDPR - every AI tool that touches personal data | In force |
| Aug 2025 | Rules for general-purpose AI models (provider-side; reaches you through your vendors) | In force |
| 2 Aug 2026 | Transparency obligations (Art. 50) + start of national enforcement | Applies |
| 2 Dec 2026 | New ban on AI generating CSAM / non-consensual intimate content; transition deadline for AI-content watermarking | Applies |
| 2 Dec 2027 (Annex III) · 2 Aug 2028 (Annex I) | Full high-risk obligations for providers and deployers (incl. Art. 26) - postponed under the Digital Omnibus | Moved out |
A note on the Digital Omnibus: the amendment postponing the high-risk obligations has been adopted. The European Parliament approved it on 16 June 2026, the Council on 29 June 2026, and the final act was signed on 8 July 2026; it takes effect on publication in the Official Journal, expected before 2 August 2026. The postponement covers the full set of Annex III high-risk obligations, for providers and for deployers: Article 26 duties now apply from 2 December 2027. What it does not move are the transparency duties (Article 50) and enforcement, which start on 2 August 2026, and AI literacy, which is already binding. The direction of travel is unchanged: more obligations over time, not fewer.
Deployer vs. Provider: Does the EU AI Act Apply to My Company?
We don't build AI - we just use ChatGPT. Does the EU AI Act still apply to us?
Yes. The AI Act separates companies that develop AI systems (Providers) from companies that use ready-made AI systems at work (Deployers). If your team uses ChatGPT, Microsoft Copilot, Gemini or comparable tools in a professional context, you are a Deployer - with specific obligations under Article 26. That covers the overwhelming majority of SMEs operating in Germany. Most don't know it yet.
What are my obligations as a Deployer, in plain terms?
You inventory, classify and document the AI systems you use; you ensure a human stays in control of automated decisions; and you train your staff to use AI responsibly. This is not best-practice advice - it is a legal requirement under the EU AI Act. The AI literacy and oversight parts apply now; transparency duties start in August 2026, and high-risk documentation follows from December 2027.
EU AI Act Quick Facts: Articles 4, 26 and 50 Explained
What does Article 4 require - AI literacy?
Every employee who works with an AI system must have enough competence to use it safely and responsibly. That does not mean technical training for everyone. It means each person understands the limits, risks and responsibilities of the tools in their role - what AI-assisted candidate screening can and can't do, or which customer data may be passed to an AI. This obligation applies today.
What does Article 26 require - deployer obligations?
Article 26 is the core of deployer AI compliance: technical documentation of the AI systems you use, demonstrable human oversight of automated decisions, a risk management approach for high-risk applications, and a Data Protection Impact Assessment, supplemented by a Fundamental Rights Impact Assessment (FRIA) under Art. 27 AI Act for public bodies and for creditworthiness or insurance risk assessment. Purpose limitation runs through all of it - an AI system may only be used for the purpose you documented.
What does Article 50 require - transparency?
When AI interacts directly with people - chatbots, automated emails, AI-generated content - those people must be told. Clearly, at the start of the interaction, not buried in a footer. AI-generated images, text and voices used in public must be identifiable as such.
Step 1: AI System Inventory - Finding Shadow AI in Your Organisation
What is Shadow AI, and why is it your biggest AI compliance risk?
Shadow AI is every AI tool your employees use without IT's knowledge or approval - ChatGPT in the browser, AI features inside Canva, Grammarly in the mail client. These tools routinely process customer data the company doesn't know about. That makes Shadow AI an EU AI Act problem and a GDPR problem at the same time, and you can only govern what you can see.
How do you build a complete AI system inventory?
A structured inventory captures every AI tool in use, with its purpose, the data types it processes, and the departments involved. It is not a one-off project - it needs updating each time a new tool appears.
A three-step approach:
1. Survey every department for the tools they use - including unofficial ones.
2. Add technical discovery via IT logs and browser monitoring.
3. Record everything in a central register with a risk classification.
AI System Inventory Template (Excel)
Step 2: AI Risk Assessment - Which Risk Class Applies to You?
How does the EU AI Act classify AI systems?
The AI Act sorts every AI system into one of four risk classes, and the class decides which obligations apply:
| Risk class | Typical examples | Key obligation |
|---|---|---|
| Minimal risk | Spam filters, basic recommendation engines | No specific requirements |
| Limited risk | Chatbots, AI-generated text | Transparency (Art. 50) |
| High-risk | AI in HR, credit scoring, safety systems | Full documentation, human oversight, FRIA |
| Unacceptable risk | Social scoring, biometric mass surveillance | Prohibited |
Does the risk class depend on the tool - or how it's used?
On how it's used. ChatGPT drafting internal documents is limited risk. The same model used to screen job applicants in HR is high-risk, with far stricter requirements. Your AI risk assessment has to be done per use case, not per tool.
AI Risk Assessment Checklist (PDF)
Deployer Obligations (Art. 26): Documentation and Oversight
What exactly do I document under Article 26?
Technical documentation of the AI systems in use, demonstrable human oversight of automated decisions, a risk management approach for high-risk applications, and a DPIA, supplemented by a FRIA under Art. 27 AI Act for public bodies and for creditworthiness or insurance risk assessment. Purpose limitation applies throughout: a system may only be deployed for its documented use.
What do authorities check during an inspection?
They don't ask whether you know the rules - they ask for the documentation. A company that can't produce a coherent, current compliance record has no defence, regardless of whether the underlying use was sound. And the legal exposure doesn't sit with the company alone - where supervisory duties are breached it can reach management personally (under German law: §130 OWiG, §43 GmbHG).
Deployer Documentation Package (Art. 26 / 4 / 50, DOCX)
AI Literacy Training (Art. 4): Requirements and Checklist
What does "sufficient AI competence" mean under the law?
Article 4 does not ask for technical experts in every team. It asks that everyone working with an AI system understands the specific risks, limits and responsibilities of their own use of it. An HR employee should know what AI-assisted screening gets wrong. A salesperson should know which customer data may go into an AI tool.
AI literacy checklist: what must your company show?
- Every AI tool in use is inventoried and approved.
- Training is documented - content, date, participants.
- A process exists to repeat training when new tools are introduced.
- Accountability for AI literacy is clearly assigned.
- Training content is tailored to roles and departments.
AI Literacy Training Template (DOCX)
Transparency Obligations (Art. 50): Chatbots, Marketing, Customer Service
When do I have to disclose that AI is being used?
Whenever AI interacts directly with people, or AI-generated content is published without a label. Three common cases for SMEs:
Chatbots and automated customer service: when a bot talks to customers, say so clearly at the start - not in the footer.
AI-generated content in marketing and PR: synthetic images, AI-written text and generated voices must be labelled wherever they appear publicly.
Automated decisions about people: credit decisions, price segmentation, offer filtering - wherever AI shapes an outcome for a person, disclosure is required.
Quick check: does this apply to me?
Do you use AI in email marketing? Run a chatbot on your site? Create AI-generated images for customer communication? If you answered yes to even one, Article 50 transparency obligations are part of your AI Act readiness - and the underlying GDPR duties apply today.
AI Compliance + GDPR: One Workflow, Not Two (ROPA, DPIA + FRIA)
Why shouldn't I treat the AI Act and GDPR as separate projects?
Because almost every AI use in daily business touches personal data. ChatGPT processes customer data in emails; HR AI processes applicant data; analytics tools process user behaviour. The EU AI regulation and GDPR therefore apply at the same time, routinely. Running two separate processes doesn't just double the work - it produces contradictory documentation that becomes a problem under audit.
How do I connect ROPA and FRIA in a single workflow?
Your Record of Processing Activities (ROPA) under GDPR gets extended for AI: which model processes which data, for which purpose, in which context. The DPIA is supplemented by a Fundamental Rights Impact Assessment (FRIA) for high-risk AI. Both fit into one process - if the documentation is structured that way from the start.
ROPA extension for AI: guide
DPIA + FRIA: combined implementation
External DPO with EU AI Act expertise
ETHYX AI Compliance Software - How It Works
What does the ETHYX Compliance Checker actually deliver?
In under five minutes, the checker assesses your current EU AI Act compliance status. You answer ten questions about your AI tools, your data protection documentation and your internal setup, and you get back, straight away:
- Your AI Act risk level and your GDPR gap status.
- A prioritised action list for the next 90 days.
- A PDF report your legal team can use directly.
What happens after the check?
You receive the full report by email. No automatic sales call - the report is yours. If you want to see how ETHYX takes over the implementation, booking a demo is the next step.
Your AI Act Readiness Roadmap
Where do I actually start?
Start with what's already enforceable, then work outward. Compliance takes real work - the point of a structured plan is that none of that work is wasted. The sequence below puts the live obligations first and the postponed high-risk items where they belong: later, but planned for.
The roadmap, phase by phase
Phase 1 - AI inventory and risk classification. Capture every AI tool, classify each use case, set up the compliance register.
Start the AI Compliance Checker
Phase 2 - Live obligations first. Close the gaps that already bind you: AI literacy training (Art. 4), the GDPR overlap (ROPA, DPIAs) for AI that touches personal data, and any unacceptable-risk use.
ROPA extension for AI
Phase 3 - Transparency now, deployer documentation next (August 2026 and December 2027). Put Article 50 disclosures in place for chatbots, marketing and automated decisions before August 2026; then build the Article 26 documentation and record human oversight ahead of December 2027.
Phase 4 - Stay ahead of what's coming. Map your exposure to the high-risk obligations arriving in 2027-2028, so you're prepared early rather than scrambling when they land.
Audit readiness guide
AI Act Readiness Roadmap (DOCX)
Common Mistakes and Fines - What Companies Underestimate
Mistake 1: "We only use ChatGPT - that doesn't count."
It does. Every professional use of an AI tool falls under the EU AI Act, regardless of company size or how casual the use looks. ChatGPT, Copilot, Grammarly, Midjourney, Notion AI - all of them.
Mistake 2: Treating AI compliance as a one-time project.
Tools change, use cases grow, teams turn over. Documentation that was complete in early 2026 may be outdated by year-end. AI governance is an ongoing process, not a closing task.
Mistake 3: Running the EU AI Act and GDPR separately.
Double the effort, contradictory records, double the audit risk. An integrated approach is both more efficient and more legally consistent.
What are the actual consequences of non-compliance?
EU AI Act: up to €35M or 7% of worldwide annual turnover, whichever is higher. GDPR: up to €20M or 4%. Both can be imposed at once, and management can additionally be personally liable in both (under German law: §130 OWiG, §43 GmbHG). The cost of getting ready is predictable; the cost of being caught unprepared is not.
Get Ahead - Free AI Act Assessment
Compliance takes time when it starts too late. There's a real advantage in starting now: the company whose AI governance is already in order is the one that keeps deals moving when a client, investor or regulator asks - while competitors are still assembling theirs.