Germany → worldwide
WZ-IT Logo

The EU AI Act for companies: what it requires

Timo WevelsiepTimo WevelsiepUpdated: 23.07.2026

Editorial note: Versions, commands and prices may change. Please verify critical steps independently before production use. This guide does not replace individual consulting.

Have AI operated responsibly and verifiably? WZ-IT builds and operates AI on your own infrastructure - with logging and traceability as the basis for compliance, GDPR-compliant from one team. See managed AI

With the EU AI Act, the use of artificial intelligence gets a binding European legal framework for the first time. For companies the central question is not "whether" but "which obligations apply to my application". This article explains the risk-based approach, the categories, the rules for foundation models and the timeline - as orientation, not legal advice. As of July 2026.

Table of contents

What the EU AI Act regulates

The EU AI Act is the European regulation for artificial intelligence. Its core is a risk-based approach: not every AI is treated the same, but according to the risk arising from its concrete use. The higher the risk, the stricter the obligations.

Important for classification: the EU AI Act ties to the use case, not the technology or operating location. The same model can trigger hardly any obligations in a harmless application and extensive ones in a critical area. The first step is therefore always to assign your own application to a risk category.

The four risk categories

The EU AI Act distinguishes four levels:

  • Prohibited practices - applications like social scoring or certain manipulative systems are banned.
  • High-risk systems - for example in critical infrastructure, HR or certain regulated products. They must demonstrate risk management, data governance, logging, human oversight and a conformity assessment.
  • Limited risk - transparency obligations apply here. A chatbot, for instance, must identify itself as AI.
  • Minimal risk - the majority of applications; largely without special obligations.

Most enterprise applications fall into the lower two categories. But anyone deploying AI in sensitive areas should examine the high-risk requirements early.

GPAI: rules for foundation models

A category of its own is general-purpose AI models (GPAI) - the large foundation models on which many applications build. Their providers have their own obligations, such as technical documentation and information about the training data; models with systemic risk are subject to additional requirements.

For companies that only use such models (rather than provide them), the obligations from the risk category of their application are mainly authoritative. Anyone who self-operates an open model should nonetheless know under which license and with which documentation it comes.

The phased timeline

The EU AI Act enters into force in stages, spread across several key dates. Prohibited practices and AI literacy requirements apply since early 2025, the GPAI obligations since mid-2025, and the extensive high-risk requirements follow in further stages.

The exact deadlines are still being adjusted politically - there are proposals to postpone individual high-risk dates. The current version is therefore authoritative; the timeline belongs on the watch list. Violations can incur fines of up to 35 million euros or 7 percent of global annual turnover.

What companies should do

The pragmatic start is a stocktaking: which AI applications are in use or planned, and into which risk category do they fall? From that follows which obligations are relevant at all - for most applications it is transparency and documentation, not full high-risk conformity.

A recurring requirement across the categories is traceability: being able to demonstrate what a system did in response to which input. That is exactly what self-operated, sovereign operation delivers more easily - logging via an observability layer like Langfuse, control over the data via sovereign, local AI. The EU AI Act does not replace a legal assessment in individual cases - but anyone operating AI on controlled infrastructure has the more dependable basis for fulfilling their obligations.

Rather have it operated?

You'd rather not run Local & Sovereign AI yourself? WZ-IT handles setup, operations and maintenance - GDPR-compliant from Germany.

Frequently Asked Questions

Answers to the most important questions

The EU AI Act is the European regulation for governing artificial intelligence. It follows a risk-based approach: the higher the risk of an AI application, the stricter the obligations. Prohibited practices are banned, high-risk systems are subject to extensive requirements, and general-purpose AI models (GPAI) have their own rules.

Four. Prohibited practices (such as social scoring or manipulative systems) are banned. High-risk systems (such as in critical areas) must demonstrate risk management, data governance, logging and human oversight. Systems with limited risk are subject to transparency obligations - a chatbot, for instance, must identify itself as AI. Systems with minimal risk are largely free.

Yes, the EU AI Act ties to the use case and the risk, not the operating location. A self-hosted model does not exempt you from the obligations. But self-operation makes fulfillment easier: logging, traceability and control over the data flows are considerably simpler to implement on your own infrastructure.

GPAI stands for general-purpose AI, that is broadly usable foundation models. Their providers have their own obligations, such as technical documentation and information about the training data; models with systemic risk are subject to additional requirements. For companies that only use such models, the obligations from the risk category of the application are mainly relevant.

The EU AI Act enters into force in stages: prohibited practices and AI literacy requirements apply since early 2025, the GPAI obligations since mid-2025, and the extensive high-risk requirements follow later. The exact deadlines are still being adjusted politically - the current version is authoritative, which is why the timeline should be kept in view.

Considerable. For serious violations the EU AI Act provides for fines of up to 35 million euros or 7 percent of global annual turnover, whichever is higher. For violations related to GPAI models, tiered caps apply. The amount underlines that compliance is not a side issue.

Contact

Let's Talk About Your Idea

Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.

E-Mail
[email protected]

Leading companies trust WZ-IT

  • ml&s
  • Rekorder
  • Keymate
  • Führerscheinmacher
  • SolidProof
  • ARGE
  • Boese VA
  • nextGYM
  • Maho Management
  • Golem.de
  • Millenium
  • Paritel
  • Yonju
  • EVADXB
  • Mr. Clipart
  • Aphy AG
  • Negosh
  • ABCO Water Systems
Timo Wevelsiep & Robin Zins - CEOs of WZ-IT

Timo Wevelsiep & Robin Zins

Managing Directors of WZ-IT

1/3 - Topic Selection33%

What is your inquiry about?

Select one or more areas where we can support you.