77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
AI Act obligations: What companies really have to implement from August 2026
Governance & Compliance

AI Act obligations: What companies really have to implement from August 2026

11 July 202613 min readBy Dr. Henrik Bauer
CIVAC

The AI ​​regulation (Regulation (EU) 2024/1689) brings the first hard deadlines in 2026. What obligations apply to providers, operators and importers of AI systems, and how do you organise evidence in a verifiable, audit-proof manner and without file chaos?

Regulation (EU) 2024/1689 (AI Regulation, AI Act) came into force on August 1, 2024 and unfolds its obligations staggered until August 2027. For most companies, two dates are crucial: February 2, 2025 (bans according to Art. 5, AI competence according to Art. 4) and August 2, 2026 (duties for High-risk AI, governance structures, sanctions framework according to Article 99). Anyone who uses AI in a company is at least an operator within the meaning of Art. 3 No. 4 and is therefore obliged to do so, regardless of whether their own model is trained or whether a purchased foundation model such as ChatGPT, Claude or Gemini is used. Supply chains are also being targeted: contractual clauses on AI compliance will become market standard from 2026.

This article organises the obligations by role, risk class and deadline. You receive an operational map: which documents have to be created, which registers have to be kept, which training courses have to be carried out and which reporting channels have to be established. The focus is on the question of how the evidence is stored so that it is available within the set deadline in the event of a market surveillance request. The appointment certificate, signed, filed, verifiable. CIVAC accompanies the implementation as a compliance platform and officer-as-a-service with 490 ready-to-use audit templates, EU data residency and ISO/IEC 27001:2022-certified ISMS. This saves weeks of research and makes the proof a matter of pressing a button instead of researching files.

Key Takeaways

  • The AI ​​Act distinguishes four risk classes: prohibited, high-risk, limited-risk and minimal-risk AI; the depth of duties increases with the class.
  • Pure operators (e.g. a medium-sized company that uses an HR tool) are also required to: operational register, aptitude test, human supervision, information for those affected.
  • Deadline August 2, 2026: High-risk obligations, governance structures and sanctions (up to 35 million euros or 7% of group sales) are binding.

Scope: Who is the provider, operator, importer or dealer?

Art. 3 of the AI ​​Regulation defines four roles along the value chain. Providers develop or have developed an AI system and place it on the market under their own name. Operators (deployers) use the system on their own responsibility for their own purposes. Importers bring AI systems from third countries into the Union market. Traders provide an AI system on the market without being a supplier, importer or operator. The chain of obligations runs parallel: A group can simultaneously be a provider (for a self-developed tool), an operator (for purchased ChatGPT Enterprise) and an importer (for a US model without EU representation). Each role triggers its own catalogue of duties and must be kept clearly separated in the internal compliance documentation, including contract chains and responsibilities.

What is important is the so-called role shift according to Art. 25: Anyone who significantly changes an AI system (e.g. fine-tuning of a foundation model, changing the intended purpose, using it under their own brand name) becomes a provider themselves and takes on the full chain of duties. In practice, this affects many companies that adapt open source models or build custom GPTs for high-risk applications. The Compliance Officer should document the role clarification in writing, for each AI system and each context of use, ideally coupled with a formal release process for new AI applications. CIVAC provides a role register in the workspace that automatically derives the roles from configuration fields and versions them in an audit-proof manner. In the event of a market surveillance request, the respective scope of obligations for each system is available as an audit package within minutes, including version history, responsible parties, evidence artifacts and the associated supplier contracts. The platform also links directly to the agent roles that are relevant to you, so that the role assignment to the list of duties comes together in a single data model. Others run compliance like a filing cabinet. We run it like software.

Four risk classes and their depth of obligations

The AI ​​regulation follows a risk-based approach. Prohibited practices under Article 5 have been prohibited since February 2, 2025: social scoring by authorities, manipulation through subliminal techniques, real-time remote biometric identification in public spaces (with narrow exceptions for law enforcement), emotion recognition in the workplace and in educational institutions, and undirected scraping of facial images from the Internet to build biometric databases. Violations are sanctioned under Article 99 Para. 3 with up to 35 million euros or 7% of global group sales, whichever is higher. Regulatory authorities can also prohibit operations and order withdrawals from the market.

High-risk AI (Annex III, Art. 6) covers eight areas, including biometrics, critical infrastructure, education, employment (HR filters, performance assessment), access to essential services (credit scoring, private health insurance), law enforcement, migration and justice. The full list of obligations in Articles 8 to 27 applies to these systems: risk management, data governance, technical documentation, record-keeping obligations, transparency, human supervision, accuracy, cybersecurity and conformity assessment. Limited risk systems (e.g. chatbots, deepfakes, generative texts) are subject to transparency obligations according to Art. 50: The user must recognise that they are interacting with an AI or that content is synthetic; synthetic content must be marked in a machine-readable manner. Minimally risky systems (spam filters, AI in video games, recommendation algorithms without profiling) are free, and voluntary codes of conduct are recommended. The classification of each system used is the operational basis of every further compliance measure and must be documented in an AI register, with justification, person responsible and version history for later audits. Reclassifications are possible, but must be justified, dated and approved, otherwise the register will lose its evidential value in the event of a supervisory audit or civil proceedings under the new product liability directive.

Obligations of high-risk AI providers

High-risk AI providers are bearing the brunt. Article 9 requires a documented risk management system over the entire life cycle, with identification, assessment and treatment of foreseeable risks as well as ongoing review after market launch. Article 10 requires data governance: Training, validation and testing data must be relevant, representative and as free as possible from errors and biases, with documented selection criteria, assumptions and pre-processing steps. Article 11 prescribes the technical documentation according to Annex IV, including architectural description, training methods, performance metrics, foreseeable abuse scenarios and specification of human supervision. Art. 12 requires automatic records (logs) during operation, Art. 13 understandable instructions for use for operators, Art. 14 robust concepts for human supervision and Art. 15 an appropriate level of accuracy, robustness and cybersecurity.

According to Art. 43, a conformity assessment must be carried out before placing on the market, in most cases as an internal control (Module A), in the case of biometric systems with the participation of a notified body. The CE mark according to Art. 48 is affixed, the EU declaration of conformity according to Art. 47 is issued and kept for at least ten years after it has been placed on the market. Registration in the EU database according to Article 71 is mandatory and publicly accessible, with the exception of criminal law applications. After it has been placed on the market, Art. 72 (post-market monitoring) and Art. 73 (reporting of serious incidents within 15 days, in special cases within 72 hours or two days of becoming aware) apply. The auditor calls, the evidence is ready. CIVAC stores the templates for technical documentation, declaration of conformity and incident report in the workspace, pre-filled for the respective role and with automatic versioning, so that the entire life cycle proof according to Art. 12 remains complete and is available for external audits within hours instead of weeks.

Obligations of the operator: often underestimated

Operators according to Art. 26 have less comprehensive obligations than providers, but are by no means free. You must use the AI ​​system in accordance with the instructions for use, ensure human supervision by qualified personnel, control the input data as much as possible and keep records (logs) for at least six months, unless Union law or national requirements require a longer period. Employee representatives must be informed before its introduction in the workplace (Art. 26 Para. 7), regardless of the threshold of the Works Constitution Act. Natural persons subject to a decision by a high-risk system have the right, under Article 86, to an explanation of the role that the system played in the decision. This explanation must be given immediately, clearly and comprehensibly, which operationally requires a response template and a clearly named input channel.

Art. 27 requires special attention: Before the first use of a high-risk system by authorities or by certain private actors (creditworthiness check, life and health insurance risk assessment), a fundamental rights impact assessment (Fundamental Rights Impact Assessment, FRIA) must be carried out. It documents affected groups of people, risks, risk reduction measures, supervisory mechanisms and reporting channels. The FRIA must be reported to the responsible market surveillance authority with the result, supplemented by a completed standard form from the EU Commission. In the mandate of the external data protection officer, the FRIA can be combined with the data protection impact assessment in accordance with Art. 35 GDPR, which avoids duplication of effort and documents both obligations in an audit-proof manner. It is precisely this bundling that is a core advantage of the CIVAC platform: one data model, two duty regimes, consolidated evidence with a common version history. Audit-proof, documented, Art. 27-firm, Art. 35-firm. If you rely on isolated solutions, in case of doubt you will have duplicate inventories, contradictory risk classifications and no single contact person for the supervisory authority, which significantly extends the processing time for the audit.

AI competence according to Art. 4: the underestimated training obligation

Art. Since February 2, 2025, 4 KI-VO requires that providers and operators take measures to ensure that their staff and other people who are involved in the operation and use of AI systems on their behalf have sufficient AI competence. This is not a recommendation, but a binding obligation without a transition period. The supervisory authorities, in Germany probably the Federal Network Agency as the central body, will check compliance as part of market surveillance. The term AI competence is defined in Article 3 No. 56 as the skills, knowledge and understanding that make it possible to use AI systems competently, to recognise opportunities and risks and to avoid possible damage. The depth depends on function, previous knowledge and risk class.

Operationally, this means: You need a documented training concept, a training register with participant records, regular refreshers and role-based differentiation. A specialist in the HR team who uses an AI-supported application tool needs different skills than a developer who integrates foundation models. Board members need governance knowledge in order to fulfil their supervisory obligation in accordance with Section 93 AktG or Section 43 GmbHG, and the works council expects co-determination documents in accordance with Section 87 Paragraph 1 No. 6 BetrVG. CIVAC delivers 490 ready-to-use audit templates in Workspace, including an AI competency curriculum with learning objectives, test questions, participant logging, and automatic reminders for refreshers. If necessary, an appointed compliance officer from the CIVAC pool takes over the implementation and documentation, including reporting lines to management and quarterly reports on the training status per functional area. This means proof remains a push of a button, not a briefcase full of PDFs from three different learning management systems. In the event of a dispute before a labour court or a supervisory inquiry, it is not goodwill that counts, but rather the verifiable training results per person, per role, per deadline.

Interaction with GDPR, NIS-2 and product liability

The AI ​​Act does not stand in isolation. Anyone who processes personal data in AI systems is also subject to the GDPR, with the legal basis according to Art. 6, information to those affected according to Art. 13/14, rights of those affected according to Art. 15 ff., data protection impact assessment according to Art. 35 and obligation to report data breaches according to Art. Deadline begins as soon as we become aware of it. The AI ​​Regulation complements, but does not replace: both regimes apply side by side, with their own sanction framework, their own supervisory authorities and their own documentation requirements. The Conference of Data Protection Supervisory Authorities (DSK) made it clear in a position paper from May 2024 that the GDPR remains fully applicable to training data with personal reference and that legal bases for training, testing and operation must be examined separately.

NIS-2 (Directive (EU) 2022/2555) affects operators of essential and important facilities as soon as they use AI in critical services: The AI system becomes part of the IT security architecture and is therefore subject to risk management, Reporting obligations (24h early warning, 72h follow-up report) and management liability according to Art. 20 NIS-2. The Product Liability Directive (EU) 2024/2853, in force since December 2024 and to be implemented nationally by December 2026, expressly includes AI systems in the product definition. An incorrect AI decision can trigger civil liability for the provider, regardless of fault. The planned AI liability directive would also make it easier for victims to provide evidence. For you this means: audit-proof, documented, AI-Act-proof, GDPR-proof, NIS-2-proof, and ideally all three regimes consolidated in one platform, with a common asset register, harmonised reporting channels and a single compliance officer mandate instead of three parallel isolated solutions that do not fit together in the event of an audit. The economic leverage lies not in the selection of tools, but in the reduction of redundant inventories and the consolidation of reporting channels to management.

Deadlines, sanctions, supervisory structure

The application data of the KI-VO are regulated in Art. 113. Chapter I (general provisions, AI competence according to Art. 4) and Chapter II (prohibited practices according to Art. 5) have been in effect since February 2, 2025. From August 2, 2025, the rules for general-purpose AI models (Articles 51 to 56), the governance structures (Articles 64 to 70, including the AI ​​Board and national authorities) and the sanctions (Article 99) are applicable. The key deadline is August 2, 2026: From this day onwards, the high-risk regulations of Annex III apply in full as well as the obligations for providers, operators, importers and dealers, including conformity assessment and CE marking. For high-risk AI that is embedded in regulated products (Annex I, e.g. medical devices, machines, toys, elevators), the deadline runs until August 2, 2027.

Sanctions staggered in Art. 99: Violations of prohibitions according to Art 1%. SME privileges apply at the lower amount. In Germany, the planned AI Implementation Act regulates national market surveillance, probably with the leadership of the Federal Network Agency and the participation of BfDI, BaFin, BSI and state data protection authorities depending on the sector. The BfArM remains responsible in the area of ​​medical devices, BaFin in the area of ​​financial services and the BSI in the area of ​​critical infrastructures. The CIVAC platform continuously maintains a consolidated overview of the national authorities and makes it available as an interactive map in the workspace, supplemented by sample texts for authority inquiries and the respective response deadlines, so that no time is lost for research in the event of a supervisory measure.

Operational approach: from inventory to evidence

We recommend a five-step implementation. First: create an AI inventory, list every system used and developed, with purpose, data sources, responsible person, supplier and contract status. Second: risk classification, assigning each system to one of the four risk levels, documented, versioned and justified. Third: Role clarification, provider, operator, importer or dealer, with particular attention to significant changes under Article 25 that may trigger a role change. Fourth: obligation mapping, list the applicable articles for each system, name those responsible, track deadlines, link evidence artifacts. Fifth: Store evidence architecture, documents, logs, training and incidents so that they can be exported as an audit package at the push of a button, with a time stamp and unchangeable version history. These five steps are not linear, but iterative: every new AI application follows the same path in a compressed form.

The CIVAC platform delivers this architecture as an integrated module. In the workspace you will find an AI register, templates for risk management (Article 9), technical documentation (Annex IV), FRIA (Article 27), incident reporting (Article 73) and a training module for Article 4. Licence the workspace for your internal representatives, or have our representatives order it. The second variant makes sense if there is no qualified compliance officer available internally or if the start-up phase needs to be secured with expertise, for example in the hot phase before August 2, 2026. The appointment certificate, signed, filed, verifiable, with CIVAC SLA of two working days instead of the classic two to six weeks. The platform is certified according to ISO/IEC 27001:2022 with 93 controls, hosts exclusively in the EU, so that the Schrems II conflict for training and audit data is eliminated, and logs every change in an audit-proof manner in accordance with Art. 12 AI-VO. The reporting line to management is standardised, with quarterly reports, KPIs (open obligations, upcoming deadlines, incidents) and automatic escalation if critical thresholds are exceeded, so that no deadline slips through.

From reading to implementation

In the coming months, the AI ​​regulation will move from an abstract regulation to a hard basis for testing. Anyone who is not in place in August 2026 not only risks fines under Article 99, but also civil consequences from the new product liability directive and contractual penalties from supplier clauses that major customers and public clients already include in framework contracts. The operational answer lies not in another Excel list, but in a platform that consolidates AI registers, GDPR, NIS 2 and AI Act obligations, with EU data residency, ISO/IEC 27001:2022 certified ISMS, 93 controls and audit-proof versioning. Anyone who has a fragmented tool landscape today doesn't expand, but rather consolidates.

CIVAC combines both: compliance platform and officer-as-a-service. Licence the workspace for your internal representatives, or have our representatives appointed, with an appointment certificate, reporting line to management and 490 ready-to-use audit templates. A detailed overview of the duties from August 2026 can be found in the current CIVAC news article; an introduction to the operational role distribution is provided by the overview of the representative roles on the platform page. Turn reading into a mandate.: Write to info@civac.de or use the contact form on civac.de, which will directly create an appointment with a qualified Officer-as-a-Service consultant. You will receive an initial assessment of your obligations within one working day, free of charge and confidentially, including a recommendation for bundling roles with the data protection or compliance officer and an initial gap analysis for the deadlines 2025, 2026 and 2027. Upon request, we will create a prioritised action plan that specifically names the top 5 gaps, with an effort estimate in person-days and a recommendation for internal or external filling of the respective officer role, tailored to the industry, group structure and Budget.

FAQ

When do companies have to implement the AI ​​Act obligations?

Bans under Article 5 and the AI ​​competence requirement under Article 4 have been in effect since February 2, 2025 without a transition period. General purpose AI obligations and sanctions according to Art. 99 apply from August 2, 2025. The central deadline for high-risk AI according to Annex III is August 2, 2026; The deadline for high-risk AI embedded in regulated products according to Annex I is August 2, 2027. All obligations should be documented by then.

Does the AI ​​Act also apply to us if we only use ChatGPT or Copilot?

Yes. As an operator according to Art. 3 No. 4, you are subject to the obligations under Art. 4 (AI competence), Art. 26 (appropriate use, human supervision, logs six months) and, depending on the intended use, Art. 27 (FRIA for high-risk applications) and Art. 50 (transparency towards users and those affected, labelling of synthetic content). The obligations apply regardless of company size and industry.

Who is the supervisory authority for the AI ​​Act in Germany?

The national AI implementation law is in the process and will regulate responsibilities in a binding manner. The Federal Network Agency is expected to take over central coordination, with sectoral responsibilities of BfDI (data protection), BaFin (financial services), BSI (cybersecurity), BfArM (medical devices) and state authorities depending on the area of ​​application. The final authority structure is expected by the August 2026 deadline and will be coordinated by the AI ​​Board.

How much does a violation of the AI ​​Act cost?

Article 99 provides for up to 35 million euros or 7% of global group turnover for violations of prohibitions under Article 5, for other obligations up to 15 million euros or 3%, for false information to authorities up to 7.5 million euros or 1%. The higher amount applies; SME and start-up privileges apply at the lower value, which cushions the burden on smaller companies.

Do we need our own AI representative?

There is no explicit legal obligation to appoint an AI representative in the AI ​​Act. In practice, bundling with the compliance or data protection officer is recommended, as areas of responsibility and evidence artifacts overlap. CIVAC offers the role of Officer-as-a-Service with an appointment certificate, reporting line to management and an SLA of two working days from request, including substitution arrangements.

How does the AI ​​Act integrate with GDPR and NIS-2?

The three regimes operate in parallel and operationally overlap. A data protection impact assessment according to Art. 35 GDPR can be combined with a FRIA according to Art. 27 AI-VO because fields and risk classes are similar. NIS 2 risk management according to Article 21 includes AI-supported IT security architecture systems. CIVAC maintains the evidence in a consolidated workspace with a common asset register.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles