The EU AI Act has been in force since August 2024. And while most software companies are still waiting, the deadlines are already running.
The problem: the regulation is complex, implementation is phased, and the question “Does this even apply to us?” is harder to answer than expected. Especially when you’re not training AI yourself, but integrating GPT or Claude via API into an existing product.
Here’s what we’ve gathered from working with several companies on concrete findings.
Deadlines at a Glance
The AI Act doesn’t implement everything at once. The key dates:
- February 2025: Bans on certain AI practices already apply (social scoring, subliminal manipulation). Also the AI literacy obligation - your employees must be adequately trained.
- August 2025: Obligations for General Purpose AI model providers (affects OpenAI, Anthropic & Co., not you as a user of these models).
- August 2026: The main deadline. Obligations for standalone high-risk AI systems, transparency requirements, full enforcement powers.
- August 2027: Obligations for AI in regulated products (medical devices, machinery).
There’s currently a legislative process (Digital Omnibus) proposing to postpone the high-risk deadline to December 2027. But: this is still a proposal. August 2026 remains the legally binding date. Anyone using the potential postponement as an excuse is gambling.
The Four Risk Levels
The AI Act categorizes AI systems into four tiers:
Prohibited - Social scoring, subliminal manipulation, real-time biometric surveillance in public spaces, emotion recognition in the workplace. In effect since February 2025.
High risk - AI systems in eight defined areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice. The strictest requirements apply here.
Limited risk - Chatbots, AI-generated content, deepfakes. Transparency obligations: users must know they’re interacting with AI. Generated content must be machine-readably labeled.
Minimal risk - Spam filters, writing assistants, internal optimization. No obligations, voluntary codes of conduct recommended.
The question most software companies ask: where do we fall? If your product uses AI for recruiting, credit scoring, insurance pricing, or educational assessment, you’re very likely in the high-risk category.
The Point Most People Miss: When Am I a “Provider”?
This is where it gets concrete for software companies. The AI Act distinguishes between provider and deployer. The obligations are very different.
You’re a provider if you develop an AI system and place it on the market under your name. And here’s the crucial point:
If you integrate GPT or Claude via API into your SaaS product and distribute it under your brand name, you’re a provider of an AI system. Not a deployer. Not a user. A provider.
This means: you bear full compliance responsibility. Regardless of whether the underlying model itself is compliant. OpenAI and Anthropic must provide you with information to fulfill your obligations. But the responsibility lies with you.
What High-Risk Providers Must Concretely Do
Seven core requirements:
- Quality management system - Documented processes for development, operations, and monitoring.
- Risk management - Systematic risk identification across the entire lifecycle. Not one-time, but continuous.
- Data governance - Quality assessment of training and test data, bias analysis, documentation of data provenance.
- Technical documentation - Architecture, performance metrics, training methodology, security measures. Minimum 10-year retention requirement.
- Transparency - Instructions for deployers, explanation of functionality and limitations.
- Human oversight - Users must be able to override and stop the system. No autonomous AI system without human-in-the-loop.
- Conformity assessment - Internal assessment suffices for most systems. Affix CE marking. Register in the EU database.
And after launch: post-market monitoring with a 15-day reporting deadline for serious incidents.
What Does This Mean for Companies Using GPT/Claude via API?
Four points that must be clear:
- You are not a GPAI model provider. The obligations for foundation models are borne by OpenAI, Anthropic, and others.
- You are a provider of an AI system if you integrate the model into your own product.
- You must conduct your own risk assessment. How do the model’s capabilities interact with your specific use case?
- Fine-tuning can change the role: anyone who substantially modifies a GPAI model (more than one-third of the original training compute) becomes a GPAI provider themselves.
Penalties
Three tiers:
- Prohibited AI practices: up to EUR 35 million or 7% of annual turnover
- High-risk violations: up to EUR 15 million or 3% of annual turnover
- False statements: up to EUR 7.5 million or 1% of annual turnover
For SMEs, the lower of the two values applies in each case. Still: the amounts are serious.
Additionally: national authorities can order the withdrawal of non-compliant AI systems from the EU market.
What to Do Now
Immediately: Take Stock
- What AI systems do you use or develop?
- What role do you have in each case - provider, deployer, or both?
- What risk category does each system fall into?
- What foundation models do you use, through which APIs?
By Summer 2026: Gap Analysis
- Review existing processes. GDPR, ISO 27001, and QM systems are a good starting point.
- Identify gaps. What’s missing compared to AI Act requirements?
- Get legal advice, especially for borderline cases in classification.
The Most Common Mistake
Companies wait for final guidelines and harmonized standards. Understandable. But: the transparency obligations and AI literacy requirement already apply. And compliance preparation typically takes three to six months.
If you want to be compliant by August 2026, you need to start now. Not in the summer.
Conclusion
The EU AI Act is not a paper tiger. The deadlines are running, the penalties are substantial, and the question “Does this apply to us?” can be clearly answered with yes for most software companies with AI features.
The good news: if you’re already GDPR-compliant and have proper quality management, you’re not starting from zero. Many of the requirements build on existing processes.
The bad news: waiting is not a strategy. At least not a good one.
The Risk Check
What category does your AI system fall into? Four questions, clear result.
AI Act Risk Check
What risk category does your AI system fall into? 4 questions, clear result.
Question 1 / 4
Do you use AI or machine learning in your product?
About the author
Michael Jauk
Co-Founder & Managing Director
All posts by Michael →