KI-Governance und verantwortungsvolle KI

← AI governance

Implement the EU AI Act in practice

Inventory AI use, structure roles and risks and implement effective governance into operations.

The EU AI Act organizes obligations by role, AI system, purpose and risk. Companies should therefore first record their use of AI, delineate provider and deployer roles and check prohibited, transparent and potentially high-risk use cases. This results in governance, documentation, human supervision and technical and organisational measures. Whether a specific system falls within the scope of application or is considered high-risk must be assessed on a case-by-case basis.

Background

KI-Governance und verantwortungsvolle KI

AI is often introduced decentrally: through specialist applications, embedded assistants, in-house developments or external services. Without a reliable inventory, the purpose, data use, those responsible and the models used remain unclear. This makes both risk decisions and controlled operations more difficult.

The essential task is therefore not to pre-emptively assign every AI tool to a category. What is crucial is a repeatable process that captures AI systems before deployment, documents the company's role and context of use, assesses risks, controls approvals and tracks changes in operations.

Technical context

Regulation (EU) 2024/1689 (AI Act) takes a risk-based approach. It contains, among other things, bans on certain practices, requirements for high-risk AI, transparency obligations for certain systems and rules for providers of general-purpose AI models (GPAI). The specific scope of duties depends not only on the model name used, but also on the role, purpose and context of use, among other things.

Provider develop an AI system or have it developed and market it under their own name or brand or put it into operation. Deployer use an AI system under their supervision; certain private, non-professional uses are excluded. Roles can vary along a supply chain and must be checked per system.

For high-risk AI, the AI Act calls for a system of risk management, data governance, technical documentation, logging, transparency and information for deployers, human oversight, accuracy, robustness and cybersecurity. These requirements are not a checklist for every AI system; they concern high-risk AI and must be interpreted in terms of the specific distribution of roles.

The AI Act stands alongside the GDPR. If personal data is processed, the requirements of the GDPR remain independently applicable. The page GDPR in IT and cloud deepens roles, access, protection, deletion and verifiability.

AI Act timeline

Abstrakte Illustration: Shield/Check und Dokumente in Blau.
1 August 2024

Regulatory status: The AI Act enters into force.

2 February 2025

Regulatory status: Bans, definitions and measures for sufficient AI competence apply.

2 August 2025

Regulatory status: Governance rules and GPAI obligations apply.

2 August 2026

Regulatory status: Many other regulations and the transparency obligations under Article 50 apply.

2 December 2027

Regulatory status: Rules for high-risk AI in accordance with Article 6 paragraph 2 in conjunction with Annex III apply.

2 August 2028

Regulatory status: Rules for product-integrated high-risk AI in accordance with Article 6 Paragraph 1 in conjunction with Annex I apply.

The current amending regulation (EU) 2026/1744 determines the application dates mentioned for high-risk AI. When making specific decisions, the current consolidated legal status must be checked.

Role and Risk Triage

In what role does the organisation act?

First classification: Provider, deployer, importer or dealer must be checked based on the specific system and supply chain.

What risk category is considered?

First classification: First check for prohibited practices, transparency requirements, GPAI reference and possible high-risk AI.

What follows from triage?

First classification: Document low-risk or other cases; Deepen relevant cases with legal, compliance, data protection and specialist functions.

What companies need to clarify specifically

Abstrakte Illustration: KI‑Netzwerk und Datenplattform in Blau.
  • Which AI systems, models, functions and automated decisions are used, developed, procured or significantly changed in the company.
  • Which company or entity could be the provider, deployer, importer, dealer or other actor in which case.
  • What purpose, which data subjects, what data and what potential effects are associated with the use.
  • Whether prohibited practices, transparency obligations, GPAI references or an examination for high-risk AI come into consideration.
  • How approvals, human oversight, changes, security incidents, performance monitoring and shutdown are controlled.
  • Which documents, protocols, tests and proof of training must be available in a comprehensible manner for the respective application.

From requirements to implementation

AI inventory and roles

Risk: unknown systems and responsibilities
Organisational measure: Reporting, evaluation and approval process
Technical implementation: central catalogue, ownership and lifecycle status
Possible evidence: Inventory, Role decision, Release

Risk assessment

Risk: unsuitable use or fundamental rights risks
Organisational measure: Use-case assessment and escalation path
Technical implementation: documented earmarking, testing and control criteria
Possible evidence: Assessment file, risk and action log

Human Supervision

Risk: uncontrolled automated effect
Organisational measure: Clear rights to intervene, check and cancel
Technical implementation: Approval points, escalation, auditability
Possible evidence: Role description, work instructions, test evidence

Traceability

Risk: Decisions and outputs cannot be verified
Organisational measure: Documentation and change process
Technical implementation: Logging, version and access management
Possible evidence: technical documentation, logs, change history

Robustness and data protection

Risk: Manipulation, failure or unauthorized data processing
Organisational measure: Security and data protection check
Technical implementation: Access control, data minimization, monitoring
Possible evidence: Security reviews, configurations, DPIA/data protection related

Limitations and dependencies

Abstrakte Illustration: Roadmap, Use-Cases und KI‑Chip in Blau.

ADIUMENTO does not provide legal advice and does not make a binding determination of affectedness or risk class. This depends in particular on the specific system, its intended purpose, the role in the value chain and the context of use. Technical implementation does not replace the legal assessment or the responsibility of the responsible corporate functions.

The law continues to evolve through guidance, standards, enforcement practices and changes. In particular, the application dates for high-risk AI changed by Regulation (EU) 2026/1744 must be checked against the current legal status when making specific decisions.

Orientation

Frequently asked questions

Do we need to treat every AI tool as high-risk AI?

No. The AI Act differentiates according to system, purpose and risk. A complete inventory and a clear assessment process help identify potentially relevant cases without pre-asserting a legal classification.

Is an AI policy sufficient?

No. A policy provides guidance, but must be supplemented by responsibilities, approvals, technical access controls, documentation, training and auditable operations.

Does the Digital Omnibus postpone all AI Act obligations?

No. As of July 31, 2026, existing regulations, including bans, AI competence and GPAI obligations, will remain in place. In particular, Regulation (EU) 2026/1744 changed the dates for high-risk AI in accordance with Article 6 and Annexes I and III.

Next sensible step

Abstrakte Illustration: Datenplattform und KI‑Netzwerk in Blau.

Start with governance and readiness preparation for a limited area: capture systems, purposes, data, responsible parties and existing controls. For operational handling of Microsoft Copilot and Shadow AI, read Copilot governance and Shadow AI.