AI GLOSSARY
EU AI Act
The world’s first comprehensive AI regulation. What the EU AI Act means for your business, what deadlines apply, and how you can set up AI systems to be compliant right now.
✓ 80+ AI experts ✓ 25+ years of technology expertise ✓ ISO-certified ✓ Made in Germany
Risk
Classes
as defined in the EU AI Act
Months
until full implementation starting in 2027
Millions of euros
Maximum fines for violations
Mandatory
modules
for High-Risk AI
Why the EU AI Act Is Relevant for Businesses
The EU AI Act has been in effect since August 2024 and will be phased in by 2027. Anyone who uses AI in their business—whether as a provider or an operator—must fulfill specific obligations by certain deadlines. Addressing these issues early on is a requirement, not an option.
Legal Certainty
Clear requirements enable AI investments with predictable risk. Without AI Act compliance, projects may face corrections or be halted.
Competitive Advantage
Companies with AI Act-compliant processes can win contracts in regulated industries (finance, healthcare, public sector).
Customer Trust
Transparent use of AI strengthens the trust of B2B customers and end consumers—and is increasingly expected.
Heavy Fines
Violations of the EU AI Act can result in fines of up to €35 million or 7% of global annual revenue.
GDPR Compliance
The EU AI Act supplements the GDPR with AI-specific requirements. Much of it builds on existing processes—but with significantly greater depth.
Explainable AI
Documentation and transparency requirements lead to better, more robust AI systems. Compliance and quality go hand in hand.
What is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive regulation of artificial intelligence. It entered into force in August 2024 and will become fully applicable in phases by 2027. Objective: Safety, fundamental rights, and trust in AI applications within the EU.
The approach is risk-based: AI systems are classified into four categories—ranging from unacceptable risk (prohibited) to high-risk AI (subject to strict requirements), transparency obligations, and minimal risk (freely usable).
The EU AI Act applies to both providers (who develop or place AI systems on the market) and operators (who use AI in their businesses). For small and medium-sized enterprises, this means that almost every company is affected as soon as it uses AI in a productive capacity.
Important: The EU AI Act does not replace the GDPR. It supplements it with AI-specific requirements such as training data governance, risk analysis, monitoring, and transparency toward users.
Overview of Obligations for High-Risk AI
If your AI application falls into the high-risk category, a comprehensive list of obligations applies. You must be able to demonstrate compliance with these eight requirements:
Risk Management
Data Quality
Technical Documentation
Record-keeping Requirement
Transparency Requirements
Human supervision
Accuracy & Robustness
Conformity Assessment
Best Practices for Implementing the AI Act
Based on prodot projects preparing for the AI Act, six principles have proven effective in making the difference between panic and planning:
- Take stock: First, identify which AI systems are in use—including “shadow AI” such as the use of ChatGPT in Teams.
- Classify risks: Determine the AI Act class for each system—high risk or subject to transparency requirements?
- Establish governance: Document roles, approvals, and responsibilities—integrated with GDPR and IT compliance.
- Train in AI literacy: Employees who use AI must understand how to handle it—mandatory starting in February 2025.
- Set up monitoring: Continuously measure and document hallucinations, bias, and drift.
- New Vendor Standard: Contractually require AI-Act compliance for AI acquisitions.
Class 1
Unacceptable Risk
Completely prohibited: social scoring, subliminal influence, and emotion recognition in the workplace.
Prohibited
Class 2
High-Risk AI
Strict requirements: HR selection, credit scoring, critical infrastructure, education, the judiciary, medical devices.
Conformity Assessment
Grade 3
Transparency Requirements
AI must be clearly identified: chatbots, deepfakes, and AI-generated content in the media.
Labeling
Common Mistakes in AI Act Preparation
In many companies, preparations for the AI Act are just getting underway. We see these mistakes time and time again—and they’re avoidable:
- Starting too late: If you wait until August 2026, you won’t have enough time to establish robust processes—especially for high-risk AI.
- Ignoring “shadow AI”: Individual use of ChatGPT by employees is covered by the AI Act—but is rarely tracked.
- Treating it as an IT-only issue: The EU AI Act is a compliance, HR, legal, and business issue—not just an IT one.
- No classification: If you don’t know whether a system is high-risk, you can’t fulfill your obligations.
- Forgetting the GDPR: The AI Act and the GDPR are intertwined—separate silos lead to duplicate work and gaps.
EU AI Act vs. GDPR vs. ISO 42001
Three sets of regulations—which together form the compliance framework for AI in Europe:
- EU AI Act: Regulatory, mandatory. Focus: Safety and fundamental rights in AI systems.
- GDPR: Regulatory, mandatory. Focus: Protection of personal data—applies in addition to the AI Act.
- ISO 42001: Voluntary certification. Management system standard for AI—useful as a framework for demonstrating compliance with the AI Act.
Contact Us Now
Frequently Asked Questions About the EU AI Act
-
What is the EU AI Act in a nutshell?
The EU AI Act is the EU's first comprehensive AI regulation. It classifies AI systems by risk and sets out obligations for providers and operators—particularly in the areas of safety, transparency, and human oversight.
-
As a small or medium-sized business, is my company affected by the EU AI Act?
As soon as you start using AI in production—whether you developed it yourself or purchased it as software—you’re affected. The scope and depth depend on the systems’ risk class. An early readiness check provides clarity.
-
What will apply starting in February 2025?
Two things: Prohibited AI practices (e.g., social scoring, emotion recognition in the workplace) are not allowed. And companies must ensure that employees who use AI have sufficient AI literacy.
-
What happens in the event of violations of the EU AI Act?
Fines of up to €35 million or 7% of global annual revenue—whichever is higher. For small and medium-sized businesses, reputational and operational risks (e.g., suspension of sales) are also relevant.
-
How are the EU AI Act and the GDPR related?
Both apply simultaneously. The GDPR governs personal data, while the AI Act governs AI systems. For many applications (e.g., HR tools), both sets of regulations are relevant. We recommend an integrated governance approach rather than separate silos.
-
Is ChatGPT in the browser sufficient for AI Act compliance?
Hardly. For confidential and business-critical applications, you need a controlled, auditable environment—such as Azure AI Foundry or your own deployments with logging, access control, and monitoring.
-
How long will it take to prepare for the EU AI Act?
For an initial overview (inventory, classification, gap analysis), 4–8 weeks are sufficient. For full compliance—especially for high-risk AI—plan on 6–12 months. Important: Start now to be ready by August 2026.
EU AI Act: Setting the Course Now
In a free initial consultation, we’ll work with you to assess the extent to which your company is affected by the EU AI Act—and identify the areas requiring the most urgent action.
As an AI partner for small and medium-sized businesses, we’ll guide you through the entire process—from conducting an initial assessment and classification to ensuring your AI systems operate in compliance with regulations.
What We Offer
- AI Readiness Check — a quick assessment of your current systems, classification, and areas requiring action.
- AI Monitoring — Ongoing quality and compliance measurement of your AI systems.
- AI Literacy Training — Mandatory component for employees starting in February 2025.
- AI Strategy Guide — free download from the media library.