AI Act Compliance: Obligations, deadlines and evidence for management
The EU AI Regulation (Regulation 2024/1689) has been in force gradually since August 1, 2024. This article explains risk classes, management obligations, evidence architecture and the operational bridge to GDPR and ISO/IEC 27001:2022.
The EU Regulation 2024/1689 (AI Regulation, AI Act) came into force on August 1, 2024 and unfolds its obligations in stages until August 2, 2027. Since February 2, 2025, the bans according to Article 5 as well as the obligation for AI competence according to Article 4 apply. From August 2, 2026, the central obligations apply Annex III high-risk AI systems, including risk management, data quality, technical documentation and human oversight. For management, this means: AI Act compliance is not a staff task, but rather a line responsibility that requires documentation and has a clear reporting chain and a comprehensible supervisory organisation. Anyone who uses AI systems in human resources, in credit assessment or as a security component in regulated products must now set up a conformity assessment, inventory and training track.
This article classifies the obligations of the AI regulation into an operational architecture. You get a robust methodology for AI inventory, risk classification, compliance assessment and reporting line. We show how AI Act obligations can be connected to existing structures from GDPR, ISO/IEC 27001:2022 and NIS-2 instead of building parallel compliance silos. You will find out which deadlines apply in 2025, 2026 and 2027, which duties management can and cannot delegate, how a conformity assessment according to Article 43 works in practice and what sanctions Article 99 provides for. The article is aimed at management, compliance officers, data protection officers and information security officers of medium-sized and large organisations. CIVAC is the compliance platform and officer-as-a-service that represents this integration in the workspace.
Key Takeaways
- The AI Act has been in effect gradually since August 1, 2024; Obligations for high-risk AI under Annex III apply from August 2, 2026.
- Fines under Article 99 range up to 35 million euros or 7 percent of global annual turnover for violations of Article 5.
- AI Act compliance lives in interaction with GDPR, ISO/IEC 27001:2022 and NIS-2 and requires a central AI inventory with a reporting line to management.
Scope: When the AI Act applies to your company
The AI Act distinguishes four actor roles according to Article 3: provider (provider), operator (deployer), importer (importer) and dealer (distributor). Most German companies are operators within the meaning of Article 3 Number 4, i.e. entities that use an AI system on their own responsibility. Anyone who significantly changes a model, renames an existing name or sells it as a private label becomes a provider according to Article 25 and assumes the full chain of obligations according to Article 16. This role clarification is the first step in any reliable conformity assessment and cannot be delegated to IT. It requires a joint reading of purchasing, law and specialist departments because the contractual structure with the provider determines whether an operator becomes liable in the event of damage.
The duty profile also depends on the risk class. Article 5 completely prohibits certain practices, such as social scoring by authorities or emotion recognition in the workplace. Annex III lists high-risk applications, including AI in human resources (recruiting, promotion, termination), credit assessment of natural persons, student assessment, and critical infrastructure. In addition, transparency obligations under Article 50 apply to generative systems, chatbots and deepfakes. The territorial scope of application under Article 2 also covers third-country providers if the result of the AI system is used in the Union. This means that the regulation also applies to US SaaS solutions that are used in Germany.
The Compliance Officer clarifies this classification together with IT, data protection and specialist departments and feeds the result back into a central AI inventory. Only on this basis can it be decided which articles and appendices actually apply and which conformity assessment needs to be prepared and to what extent. The appointment certificate, signed, filed, verifiable.
Deadline cascade until 2027: What applies when
The AI Regulation follows a multi-stage application according to Article 113. Since February 2, 2025, the bans according to Article 5 and the obligation for AI competence according to Article 4 apply, according to which providers and operators must ensure that staff with sufficient training in AI topics work. This training obligation is not delegation-proof and applies to every person who develops, deploys or supervises an AI system. Training content, participant lists and repeat dates are subject to proof. A one-time awareness email is not enough; What is required is a structured learning unit with reference to the specific systems and roles used.
From August 2, 2025, the obligations for general-purpose AI models in accordance with Chapter V apply, including the obligation for technical documentation in accordance with Article 53 and the extended obligations for GPAI models with systemic risk in accordance with Article 55. At the same time, the sanction provisions in accordance with Article 99 will take effect insofar as they relate to obligations that already apply. Member States must designate their competent authorities and establish the Chapter VII governance model. For operators, this means: Each time a provider is selected, the provider's GPAI documentation must be checked and referenced in their own AI inventory.
The central deadline is August 2, 2026: On this day, the obligations for high-risk AI systems according to Annex III come into effect. This includes risk management system according to Article 9, data governance according to Article 10, technical documentation according to Article 11, record-keeping obligations according to Article 12, transparency according to Article 13, human supervision according to Article 14 and robustness/cybersecurity requirements according to Article 15. For high-risk AI installed as a security component of regulated products (Annex I), an extended deadline applies until August 2, 2027. Who today If you use AI systems in human resources or credit assessment, you have less than an operational financial year to set up the evidence architecture, conformity assessment and CE marking.
Understanding risk classes: Prohibited, High Risk, Transparency, Minimal
The AI Act follows a risk-based approach. Prohibited practices under Article 5 include manipulative techniques that exploit cognitive-behavioral weaknesses, untargeted scraping of facial images from the Internet to build biometric databases, and emotion recognition in employment and educational settings unless justified for medical or safety reasons. Social scoring by authorities and certain biometric real-time remote identification in public spaces are also prohibited. Violations of Article 5 trigger the highest level of sanctions under Article 99. Existing applications have either been switched off or placed under strict exemptions by February 2, 2025.
High-risk systems according to Annex III concern, among other things, AI in law enforcement, migration control, education, human resources and the creditworthiness assessment of natural persons. There is also Annex I, which covers high-risk AI as a safety component of products under sectoral product regulation, such as medical devices according to Regulation (EU) 2017/745, machines according to Regulation (EU) 2023/1230 or toys according to Directive 2009/48/EC. For these Annex I cases, the responsible sectoral supervision remains in place and the AI Act requirements are integrated into the existing product assessment.
The transparency obligations under Article 50 are relevant for most companies: anyone who operates a chatbot must inform users that they are interacting with an AI. Anyone who creates synthetic content (images, audio, video, text) must mark it in a machine-readable way as AI-generated. Deepfakes according to Article 50 paragraph 4 must also be disclosed to the viewer. AI systems with minimal risk (spam filters, AI-supported image processing in standard software) are not subject to any further obligations, but benefit from voluntary codes of conduct according to Article 95. The operational consequence: You need a documented classification process that assigns each newly introduced AI system to a risk class and stores the result in an audit-proof manner.
Obligations of management under the AI Act
The AI regulation does not address management by name like Section 38 BDSG or Section 130 OWiG, but in fact derives an organisational obligation. Article 26 requires operators of high-risk AI to take appropriate technical and organisational measures to ensure that the system is used in accordance with the instructions for use, qualified personnel exercise human supervision, input data is relevant and representative, and records referred to in Article 12 are retained for at least six months. If the management fails to comply with this supervisory organisation, Section 130 OWiG applies with fines of up to 10 million euros in accordance with Section 30 OWiG, regardless of the sanctions under Article 99 AI Act. The double sanction is regularly examined by the Federal Network Agency and the data protection supervisory authority.
In addition, there is the obligation for AI competence according to Article 4: Employees who develop or use AI systems must be sufficiently trained. This training obligation is not part of the delegation, but is part of the organisational responsibility. Management therefore needs a documented reporting line on AI topics, a clear distribution of roles between IT, data protection, departments and compliance, as well as an AI inventory that can be provided with information at any time. Corporations with several subsidiaries must also clarify whether supervision is organised centrally or decentrally; The regulation allows both models, but requires continuous documentation.
Others run compliance like a filing cabinet. We run it like software. In the CIVAC workspace, the AI inventory is located next to the list of processing activities in accordance with Art. 30 GDPR and the risk assessment in accordance with ISO/IEC 27001:2022, so that overlapping obligations can be mapped without media disruption. The reporting line to management is stored there as a workflow, with escalation deadlines, responsibilities and audit trail. Licence the workspace for your internal representatives or have our representatives order it.
Conformity assessment and CE marking for high-risk AI
High-risk AI systems referred to in Article 6 must undergo a conformity assessment before being placed on the market or put into service. Article 43 distinguishes between two paths: internal control under Annex VI for most Annex III applications and the involvement of a notified body under Annex VII, for example for biometric identification. After a successful assessment, the provider issues an EU declaration of conformity in accordance with Article 47 and affixes the CE marking in accordance with Article 48. The technical documentation in accordance with Annex IV must be kept for ten years and presented to the market surveillance authority upon request. Substantial changes to the system trigger a re-evaluation.
The conformity assessment covers a full stack of obligations: risk management system (Article 9), training, validation and test data with documented governance (Article 10), technical documentation (Article 11), automatic logging (Article 12), transparency for operators (Article 13), human oversight (Article 14), accuracy, robustness and cybersecurity (Article 15). Operators are required to register certain high-risk applications in the EU database in accordance with Article 49. Authorities as operators are regulated separately in Article 49 paragraph 3. The database is operated by the European Commission and is publicly accessible as long as no business secrets are affected.
CIVAC provides 490 ready-to-use audit templates that can be specifically compiled for conformity assessment. Templates include risk register, data governance sheet, oversight plan, incident register and supplier questionnaire with AI Act clauses. Each template is tailored to the respective Annex IV requirements and linked to existing GDPR and ISO documentation. The auditor calls, the evidence is ready. The Overview of the AI Act obligations in August 2026 arranges these steps in time and names the respective responsibilities in the line.
Interfaces to GDPR, ISO 27001:2022 and NIS-2
The AI Act does not stand in isolation. If an AI system processes personal data, the GDPR applies at the same time. A data protection impact assessment in accordance with Art. 35 GDPR is regularly required, for example in the case of automated decisions within the meaning of Art. 22 GDPR. Recital 9 of the AI Act clarifies that the Regulation complements, but does not replace, the GDPR. Anyone who uses an AI system in human resources documents the legal basis according to Art. 6 GDPR, the DPIA according to Art. 35 GDPR and the AI Act classification according to Annex III in a consolidated directory. The supervisory authorities for data protection and AI exchange information in accordance with Article 74 Paragraph 8 of the AI Act. Duplicate file management only creates risk and effort. An integrated view also reduces the effort involved in government inquiries because one click makes the DPIA, the ISMS risk register and the AI Act conformity assessment visible at the same time.
ISO/IEC 27001:2022 with its 93 controls provides the technical and organisational basis for cybersecurity in accordance with Article 15 AI Act and for the due diligence obligations in accordance with Section 13 NIS2UmsuCG (NIS 2 Implementation Act). Controls such as A.5.7 (Threat Intelligence), A.8.16 (Monitoring activities) and A.8.28 (Secure coding) can be directly connected to the robustness requirements of the AI Act. Anyone who operates a certified ISMS has already fulfilled some of the Article 15 obligations and, above all, must supplement the AI-specific extensions (adversarial robustness, model drift monitoring).
ISO/IEC 42001:2023 (AI Management System) is increasingly used as a sectoral supplement, but is not a harmonised standard within the meaning of Article 40 AI Act. Until the European Commission adopts harmonised standards via CEN-CENELEC mandate M/593, companies must demonstrate compliance through their own documentation. The Information Security Officer is responsible for the technical due diligence, and the compliance officer is responsible for the regulatory one. Both roles coordinate via a common reporting line in the workspace.
Building an AI inventory: methodology and minimum content
A resilient AI inventory is the operational backbone of AI Act compliance. At least the following should be documented for each system: clear name and version status, provider and reference model (in-house development, open source, GPAI via API), training data used or model base, processing purpose and departmental responsibility, risk class according to the AI Act (prohibited, high risk, transparency, minimal), GDPR legal basis and, if applicable, DSFA reference, technical and organisational measures, human supervision and escalation path as well as reporting and incident path. There are also fields for interfaces to Annex I product regulation, sectoral supervision and contractual obligations of the provider. The inventory links directly to data inventory, DPIA, ISMS risk entry and training certificates so that audit inquiries can be answered without a research loop.
The inventory methodology follows a fixed four-step process. First: Discovery through departmental interviews, IT scans and structured supplier inquiries, including shadow IT in marketing, HR and sales. Second: classification with three dimensions (risk class + GDPR reference + ISMS reference). Third: Assessment with gap analysis against Articles 9 to 15 AI Act and against the relevant controls from ISO/IEC 27001:2022. Fourth: Control with an action plan, responsibilities, deadlines and follow-up. Each step creates an audit-proof entry in the audit trail.
The inventory is not an Excel document for an audit, but a continuously maintained database that is integrated into the reporting line to management. Every change to the system (version update, new data set, changed purpose) triggers a re-classification. CIVAC maps this structure in the workspace, including versioning, task distribution and audit trail with EU data residency. Licence the workspace for your internal representatives or have our representatives appoint them if you do not want to set up your own officer function. Inventory maintenance is confirmed quarterly by supervisory reviews and is part of the management's reporting routine.
Fines and supervision: What threatens violations
Article 99 AI Act provides for a three-tier sanctions regime. Violations of the prohibited practices under Article 5 may be punished with fines of up to 35 million euros or 7 percent of annual worldwide turnover, whichever is greater. Violations of the obligations for high-risk AI under Articles 16, 22, 23, 24, 25, 26, 27, 50 or 55 result in up to 15 million euros or 3 percent of global annual turnover. False or misleading information provided to authorities can be fined up to 7.5 million euros or 1 percent of annual turnover. According to Article 99 paragraph 6, the lower amount applies to SMEs and start-ups. Group companies are jointly and severally liable if there is a single economic unit. The limitation period generally follows national law, i.e. Section 31 OWiG in German procedures.
In Germany, supervision is divided between the Federal Network Agency (BNetzA) as the central market surveillance authority and sectoral authorities. The data protection supervisory authority remains responsible for personal data processing. BaFin is involved in the financial sector; the market surveillance regime of the respective product regulation applies to regulated products. The coordination between authorities takes place via the national single point of contact model, supplemented by the European AI Board according to Article 65.
In addition, there are information and access rights of the authorities according to Article 74 as well as whistleblower protection according to Article 87, which moves whistleblower reports about suspected AI Act violations into the scope of protection of the HinSchG. The reporting line for AI Act violations must therefore be interlinked with the reporting office according to the HinSchG. In addition, in the case of serious incidents involving high-risk AI, Article 73 requires reporting within 15 days. Audit-proof, documented, AI Act-proof.
Anchoring AI Act compliance operationally with CIVAC
AI Act compliance does not depend on memos, but on routines. An AI inventory that is not maintained is waste after three months. A conformity assessment without connection to the ISO/IEC 27001:2022 controls and the GDPR directory creates double effort and blind spots. A reporting line without a signed appointment certificate is not evidence within the meaning of the supervisory organisation according to Section 130 OWiG. The Federal Network Agency's supervisory practice is clearly based on the line of data protection supervision: documented processes beat good will. Anyone who can demonstrate a credible supervisory organisation regularly benefits from sanctions practice through reduced fines or warnings instead of formal procedures.
The operational levers are: a central AI inventory in the workspace, a reporting line to management with documented escalation, a prepared conformity assessment with the 490 CIVAC audit templates, a training and awareness track for Article 4 and a clear escalation to the internal reporting office according to HinSchG. There is also an incident register with connection to the 15-day reporting period according to Article 73 and the 72-hour period according to Article 33 GDPR. Anyone who neatly links these levers reduces the risk of fines and gains operational speed when rolling out new AI applications.
CIVAC is the compliance platform and officer-as-a-service with EU data residency and ISO/IEC 27001:2022-certified ISMS. In the workspace, the obligation strands from the AI Act, GDPR, ISO/IEC 27001:2022 and NIS-2 are interlinked without media disruption. Licence the workspace for your internal representatives or have our representatives order it. Turn reading into a mandate.: Write to info@civac.de or use the contact form on civac.de to arrange an initial analysis of your AI applications against the obligations of Regulation 2024/1689. The CIVAC SLA for the Officer appointment is 2 business days instead of the classic 2 to 6 weeks.
FAQ
When does the AI Act apply to my company?
The AI Regulation 2024/1689 came into force on August 1, 2024 and applies gradually. Prohibitions under Article 5 and the obligation for AI competence under Article 4 have been in effect since February 2, 2025. The central obligations for high-risk AI according to Annex III will take effect from August 2, 2026, and for security components of regulated products from August 2, 2027.
Do I need an AI representative?
The AI Act does not prescribe an independent role, but requires a supervisory organisation according to Article 26 and AI competence according to Article 4. In practice, the task is delegated to compliance officers, data protection officers or ISBs, with a documented reporting line to management. What is important is the bundling of responsibility with an appointment certificate, a uniform AI inventory and a consistent escalation chain, not the title on the door.
What fines are there for violations?
Article 99 of the AI Act provides for fines of up to 35 million euros or 7 percent of global annual turnover for violations of the prohibited practices under Article 5. Violations of high-risk obligations can be punished with up to 15 million euros or 3 percent, while false statements can be punished with up to 7.5 million euros or 1 percent of annual sales.
How does the AI Act relate to the GDPR?
The AI Act complements the GDPR, but does not replace it. If an AI system processes personal data, both sets of rules apply in parallel. A data protection impact assessment according to Art. 35 GDPR is regularly required, especially for automated decisions according to Art. 22 GDPR and for high-risk systems according to Annex III. The supervisory authorities exchange information in accordance with Article 74 Paragraph 8 of the AI Act.
What must an AI inventory contain?
At least per system: name and version, provider, processing purpose, risk class according to the AI Act, GDPR legal basis, technical and organisational measures, human supervision and reporting line to management. There are also fields for Annex I reference, sectoral supervision and staff training level. The inventory is continuously maintained and is the basis for conformity assessment, ISO/IEC 27001:2022 audits and reports to the supervisory authority.
Who is the responsible supervisory authority in Germany?
The Federal Network Agency (BNetzA) is responsible for central market surveillance for the AI Act in Germany. Sectoral authorities remain responsible in their areas, such as BaFin in the financial sector and the BfArM for medical devices. The data protection supervisory authority remains responsible for personal processing. Regulatory structures will be fully named by August 2, 2026 and coordinated via the European AI Board.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.