IT Governance and Compliance

    Implementing the AI Act

    By Redaktion techport.ai, IT-Beratung · Last updated on

    The AI Act affects mid-sized companies more often than they expect, and usually in a different role than assumed. Very few develop AI systems. Almost all deploy them, frequently without knowing, because AI features are built into standard software and arrive with an update.

    The regulation is not a reason to avoid AI. It requires you to know what you deploy, which risk class it falls into and which duties follow. For most mid-market use cases that can be met with manageable effort.

    How you notice it

    • Nobody can say which AI features are active in the systems in use.
    • It is unclear whether you count as a provider or as a deployer.
    • Staff use AI tools without any training having taken place.
    • Customer questions about AI usage cannot be answered reliably.

    Why this happens

    The regulation is extensive, its deadlines have been adjusted several times, and assigning a risk class requires interpretation in individual cases. On top of that, AI features do not arrive as a project but as part of software already in use. So there is no point at which someone makes a decision, and therefore no trigger for an assessment either.

    How we go about it

    1. Take inventory. We record all AI features and AI tools in the company, including features in existing software, and describe per application its purpose, the data processed, the user group and the effect on people.
    2. Determine role and risk class. We clarify per application whether you are a provider or a deployer and assign a risk class: prohibited practice, high risk, limited risk with transparency duties, or minimal risk. The result is documented with reasoning.
    3. Implement the duties. We implement what follows: labelling of AI generated content and chatbots, human oversight for relevant decisions, information for affected individuals, logging and, for high risk applications, the further requirements.
    4. Anchor literacy and approval. We train the staff working with these systems and set up an approval process that captures new tools and new features before they go into productive use.

    What you gain

    • A documented classification you can present to customers and authorities.
    • Clarity about which applications are unproblematic and which need attention.
    • Compliance with the training duty, which applies regardless of risk class.

    From our projects

    The inventory regularly surfaces AI features that nobody deliberately activated, because they arrived with a new version of the software. That applies particularly to assistants in office applications, suggestion features in ERP and CRM systems, and analytics in the HR area. The second recurring finding: most mid-market use cases do not fall into the high risk class but under transparency duties. That insight relaxes the discussion considerably, but it presupposes that the classification was actually made and documented. Exceptions occur particularly in HR, where selection and evaluation are explicitly treated as high risk.

    Good to know

    Regulation (EU) 2024/1689, the AI Act, entered into force on 1 August 2024 and has applied in general terms since 2 August 2026. The prohibitions on certain practices have applied since 2 February 2025, as has the AI literacy duty under Article 4. Obligations for general purpose AI models have applied since 2 August 2025. The Digital Omnibus Regulation (EU) 2026/1744 entered into force on 27 July 2026 and postponed the duties for standalone high-risk systems under Annex III to 2 December 2027 and for systems embedded in products under Annex I to 2 August 2028. Market surveillance in Germany sits with the Federal Network Agency. The postponement concerns the high-risk duties, not the prohibitions and transparency requirements already in force.

    Häufige Fragen

    Are we a provider or a deployer?

    You are a deployer if you use an AI system that someone else supplies, which applies to most mid-sized companies. You become a provider if you develop a system or place it on the market under your own name. Take care with substantial modifications to a purchased system, or when you use a system for a purpose other than the intended one, because that can move you into the provider role.

    What applies to chatbots on our website?

    Users must be able to recognise that they are interacting with a system rather than a person, unless that is obvious. Artificially generated or manipulated content has to be labelled accordingly. Added to that are the usual data protection requirements for processing the inputs, particularly retention and transfer to the provider.

    Let us talk about Implementing the AI Act

    In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.

    Further reading

    Back to the field IT Governance and Compliance

    Sources