Current legal status incl. Digital Omnibus
EU AI Act Compliance

Prohibition of certain AI practices
Obligations for providers of general-purpose AI models
Transparency obligations under Article 50, e.g. for chatbots and AI-generated content
Machine-readable labelling for existing systems (Article 50(2))
Requirements for high-risk AI systems under Annex III
Requirements for high-risk AI in regulated products
Status 15 September 2026, including the Digital Omnibus on AI (Regulation (EU) 2026/1744).

The requirements depend on two questions: what role does your company play, and which category does the AI system fall into? Providers develop AI systems or place them on the market under their own name. Deployers use AI systems under their own responsibility.
Examples: recruitment, creditworthiness assessment. Focus: risk management, documentation and human oversight.
Examples: chatbots, AI-generated text and images. Focus: labelling and user information.
Examples: writing assistance, document recognition, spam filters. Focus: internal rules and good practice.
Many applications in mid-sized companies fall into the transparency or light-requirement categories and can be set up properly with manageable effort.
With clear AI governance, you use artificial intelligence with legal certainty and full transparency. We inventory your AI systems, classify them under the EU AI Act and establish the processes that keep you compliant over time, pragmatic and scaled to the size of your company. Compliance support is part of our AI consulting for mid-sized companies.
We enable teams with our AI training for companies.
Record all AI systems and tools in use, including freely available applications in business units.
Determine role and category for each system and derive the requirements.
Implement transparency, documentation, human oversight and data protection by priority.
Adopt an AI policy, assign responsibilities, train teams and regularly review new systems, changes and legal developments.
For existing systems, machine-readable labelling applies from 2 December 2026. We implement notices, metadata and the related documentation for your systems.
They clearly identify themselves to users as AI.
Text, images, audio and video are labelled in a machine-readable way.
They are clearly disclosed to viewers as artificially generated.

ISO/IEC 42001 is the internationally recognised, certifiable standard for AI management systems. It extends ISO 27001 with the topics that arise specifically when using AI.
Our services: gap analysis, setting up processes and controls (data provenance, prompt-injection protection, testing, model monitoring, third-party model management) and focused preparation for the audit by an accredited certification body.
We inventory your AI systems, classify them and show you the next steps.
We combine the requirements of both frameworks in one process: data protection impact assessments, data processing agreements, deletion concepts for vector databases and hosting in Germany. For AI cloud services, we follow the BSI AIC4 criteria catalogue.
For the highest requirements, we run open-source models in your own infrastructure: Sovereign AI with open-source models.
As soon as your company develops AI systems or uses them professionally, the regulation applies. The AI inventory clarifies which specific requirements are relevant.
It scheduled the high-risk requirements for December 2027 and August 2028 and revised Article 4 on AI literacy. The transparency obligations have applied since August 2026.
The role is voluntary and has proven valuable in practice: a designated person coordinates the inventory, policy and training.
Certification builds trust with customers and partners, especially in regulated industries and supply chains, and gives structure to AI Act implementation.
Inventory and classification usually take two to four weeks; the policy and measures follow over the next weeks.
We inventory your AI systems, classify them and show you the next steps up to 2 December 2026 and beyond.
Let’s Make Things Happen