CybersicherheitJune 29, 2026·6 min read

EU AI Act from August 2026: These obligations apply to high-risk AI

In August 2026, the bulk of the AI Regulation becomes applicable. Which systems count as high-risk and which obligations hit providers and deployers under Art. 9 et seq.

The AI Regulation's timeline

Regulation (EU) 2024/1689 — the EU AI Act — applies in stages: the prohibitions on unacceptable AI practices have been applicable since February 2025, and the obligations for providers of general-purpose AI models since August 2025. From August 2, 2026, the bulk of the regulation becomes applicable, including the requirements for high-risk systems under Annex III; for high-risk AI as a safety component of regulated products under Annex I, an extended deadline until August 2027 applies.

Which systems count as high-risk?

Annex III lists the critical areas of use: among others, employment and workforce management (such as AI-assisted candidate selection), creditworthiness assessment, critical infrastructure, education, law enforcement, and access to essential services. What matters is the purpose of use, not the technology — the same language model can mean minimal or high risk depending on how it is used. You can find a classification of all four risk classes in the overview EU AI Act: risk categories.

The provider obligations under Art. 9 et seq.

  • Risk management system (Art. 9): a documented, iterative process across the entire lifecycle
  • Data governance (Art. 10): training, validation, and test data must be relevant, representative, and as error-free as possible
  • Technical documentation and record-keeping (Art. 11, 12): demonstrability of conformity, automatic logging
  • Transparency and human oversight (Art. 13, 14): understandable instructions for use, effective means of intervention
  • Accuracy, robustness, cybersecurity (Art. 15), plus conformity assessment and CE marking before placing on the market

Deployers have obligations too

Anyone who merely uses a high-risk system is obligated as a deployer under Art. 26: use in accordance with the instructions for use, assignment of human oversight to competent persons, control of input data, retention of logs, and informing affected employees before putting the system into service. Employers using AI-assisted recruiting tools, for example, should not underestimate these obligations — on top of which, since February 2025, comes the AI literacy obligation for staff under Art. 4.

What you should do now

First, take inventory of all AI systems in use and planned, and assign each system to a risk class. For high-risk candidates, clarify your role — provider or deployer — and the obligations that follow from it. The EU AI Act Agent supports classification and documentation. Fines range under Art. 99 up to €35 million or 7% of global annual turnover.

Matching tool

Ready to automate Cybersicherheit?

EU AI Act Agent → Try it now

Frequently asked questions

Am I a provider or a deployer within the meaning of the AI Act?

A provider is anyone who develops an AI system or places it on the market under their own name; a deployer is anyone who uses it professionally under their own authority. Caution: anyone who substantially modifies a third-party high-risk system or offers it under their own brand can themselves become a provider under Art. 25, with all provider obligations.

Does using ChatGPT or similar tools fall under the high-risk obligations?

The mere office use of generative AI is generally not a high-risk use case. What matters is the purpose of use: if such a tool is used, for example, to evaluate job applicants or make credit decisions, the use case can fall under Annex III. Regardless of this, transparency obligations and the AI literacy obligation for staff under Art. 4 apply.

What does the conformity assessment for high-risk AI involve?

Before placing the system on the market, the provider must demonstrate that it meets the requirements of Art. 9 to 15. For most Annex III systems, an internal control based on harmonized standards is sufficient; the EU declaration of conformity and CE marking are then issued and the system is registered in the EU database.

Is there relief for small companies?

Yes. The regulation provides for SMEs and start-ups simplified technical documentation, preferential and free access to AI regulatory sandboxes, and consideration of their economic situation when setting fines. However, company size does not exempt anyone from the substantive requirements for high-risk systems.

Related articles

Cybersicherheit

The 7 most expensive compliance mistakes made by German SMEs

From the missing LUCID registration to the late data breach notification: these seven omissions regularly cost mid-sized companies five- to seven-figure sums.

Cybersicherheit

NIS2 for suppliers: How supply chain clauses hit small businesses too

Under 50 employees and still NIS2 requirements in the contract? Why regulated customers pass their obligations on to suppliers — and how you should respond.

← All articles