Home/Consulting/EU AI Act
EU AI Act · AI Regulation

Use AI without getting caught up in regulatory pitfalls.

The EU AI Act is the world's first comprehensive law on artificial intelligence - and it already applies in stages. We classify your systems, determine the relevant obligations, and establish the necessary governance at both technical and organizational levels.

Risk classes

Four risk levels - your obligations depend on the classification

The EU AI Act does not regulate “AI” in general, but rather the specific use case. Only the correct classification reveals what you need to do - and what you do not.

01

Prohibited practices

Prohibited practices include social scoring, manipulative influence, exploitation of vulnerabilities, and unlawful biometric categorization. These prohibitions have applied since February 2025. We assess whether a use case inadvertently falls into this category.

02

High-risk AI

The strictest requirements apply to AI in critical areas such as recruitment, lending, education, critical infrastructure, or as a safety component of products. Risk management, data governance, technical documentation, human oversight, and conformity assessment are mandatory.

03

Limited risk

Transparency obligations: users must know that they are interacting with AI (chatbots), and AI-generated content must be labeled as such (deepfakes, synthetic media). This is often the most relevant category in practice for SMEs.

04

Minimal risk

Most current applications fall into this category - spam filters, recommendation systems, and simple automation. There are no specific obligations, although voluntary codes of conduct are recommended. What matters is documented evidence that the classification is correct.

Obligations by class

What the classification means in practice

01

Providers of high-risk AI

Risk management system, data and governance requirements, technical documentation, automatic logging, transparency, human oversight, robustness, CE marking, and registration in the EU database.

01
02

Deployers (users) of AI

Use in accordance with the instructions, assurance of human oversight, monitoring during operation, retention of logs and - for relevant applications - information for affected persons.

02
03

Cross-cutting obligation: AI literacy

Since February 2025, providers and deployers have been required to ensure that their personnel have sufficient AI literacy. We provide practical training for your teams, tailored to your specific use cases.

03
Deadline timeline

Staggered application from 2025 to 2027

The Regulation entered into force in August 2024, with its obligations applying gradually. Planning early avoids costly rework.

Step 01

February 2025 - prohibitions & AI literacy

Prohibited AI practices are banned. Providers and deployers must ensure that their personnel have sufficient AI literacy.

Step 02

August 2025 - GPAI & governance

Obligations for general-purpose AI models apply; governance structures and national authorities begin their work.

Step 03

August 2026 - high-risk AI (Annex III)

Most obligations for high-risk systems under Annex III become applicable - including transparency obligations for limited-risk systems.

Step 04

August 2027 - AI integrated into products

Extended deadline for high-risk AI embedded in regulated products as a safety component (Annex I).

Careful documentation work at a computer
Staggered application from 2025 to 2027
Our services

AI governance that grows with you

We combine legal classification with technical implementation - so compliance does not become a barrier to innovation.

  • AI inventory & classification of all systems in use and planned.
  • Risk management in accordance with the requirements for high-risk AI.
  • Technical documentation and audit-ready logging.
  • Data governance for training, validation, and test data.
  • Transparency solutions - labeling of AI interactions and AI-generated content.
  • AI policy & training for legally compliant everyday use.
  • Interface with the GDPR - consistent integration of data protection and AI obligations.
Risk of fines

Up to €35 million or 7% of annual turnover

These are the potential penalties for prohibited practices - higher than under the GDPR. Breaches of other obligations can result in graduated fines. Accurate classification early in the project is the most effective protection.

As an official Odoo partner, we understand business systems in practice - and recognize where AI features in standard software may fall under the Regulation unnoticed.

Governance

AI Compliance Officer and ISO 42001

For companies, this is not just about a one-off assessment, but about roles, governance, and a robust management system.

  • Build internal expertise by training and qualifying an AI compliance manager.
  • An external AI Compliance Officer from Nuviax when no suitable internal role is available.
  • Ongoing monitoring, reporting, and coordination with data protection, IT security, and legal functions.
  • Governance, policies, and certification preparation in accordance with ISO 42001, the international standard for AI management systems.
ISO 42001

A management system instead of a one-off check

ISO 42001 structures responsibilities, controls, documentation, and improvement processes around AI. Nuviax integrates these requirements with existing ISO 27001, data protection, and security structures.

FAQ

Frequently asked questions about the EU AI Act

Yes. As a deployer, you also have obligations: you must use the system as intended, ensure human oversight, and, depending on the application, disclose that AI is being used. The AI literacy obligation also applies to your personnel, regardless of whether you develop AI or only use it.
The decisive factor is the area of application, not the technology. Annex III lists sensitive areas such as recruitment, credit scoring, education, and critical infrastructure. AI used as a safety component of regulated products is also included. We document this classification for each of your systems - it is the foundation for everything that follows.
Both apply in parallel. As soon as your AI processes personal data, you need a legal basis under the GDPR, often a data protection impact assessment and appropriate technical measures - in addition to the AI-specific obligations. We bring both regulatory frameworks together consistently instead of addressing them separately.
Absolutely. The prohibitions and AI literacy obligation already apply, while the high-risk obligations for 2026/2027 require advance preparation for documentation and processes. An AI inventory and initial classification provide immediate clarity - and prevent costly retrofitting of ongoing projects later.

Use AI - and rest easy

Let us classify your AI systems and draw up a pragmatic roadmap for the deadlines. In 30 minutes, you will know where you stand.