The actual use matters more than the label
Whether and which duties apply depends on factors including the organisation's role, the system's purpose, people affected and the effects of outcomes or actions. Not every AI system is automatically a high-risk AI system.
Providers, deployers, importers and other parties may have different responsibilities. The classification needs to be documented for the actual system and context of use.
Application status of the EU AI Act on 11 August 2026
The EU AI Act applies in stages. Prohibitions on specified practices have applied since 2 February 2025. The Digital Omnibus (EU) 2026/1744, in force since 27 July 2026, amended Article 4: providers and deployers must take measures to support the development of AI literacy among staff and others operating or using AI systems on their behalf, but need not guarantee any specific individual level. Governance and GPAI provisions have applied since 2 August 2025; other provisions apply from 2 August 2026 or under the amended transitional dates.
The Digital Omnibus moved application of the high-risk rules to 2 December 2027 for high-risk AI systems listed in Annex III and to 2 August 2028 for high-risk AI systems that are components of regulated products. The current consolidated official text is always decisive for an assessment.
- status date: 11 August 2026
- identify role and purpose
- justify risk category
- check current transitional rule
- document evidence and ownership
High-risk duties cover the lifecycle
For high-risk AI systems, the AI Act addresses areas including risk management, data and quality requirements, technical documentation, logging, transparency, human oversight, accuracy, robustness and cybersecurity. Deployers may have additional duties depending on the case.
This list does not classify a particular project. Similar controls may still be sound technical and organisational practice before any formal high-risk classification.
The GDPR examines purpose and personal-data processing
Where personal data is processed, principles including purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability remain relevant. Data protection by design and by default belong in solution design.
Legal basis, information duties, data-subject rights, processors, transfers and a possible data protection impact assessment require case-specific review by qualified specialists.
Information security protects the system, data and knowledge base
Risk analysis considers confidentiality, integrity and availability of input, knowledge sources, tools and outcomes. Least privilege, separated roles, reviewed sources, secure interfaces, change evidence, recovery and stop procedures can limit harm.
Generative AI adds risks such as manipulated input or knowledge collections, unintended disclosure and unreliable output. BSI recommends a use-case and lifecycle assessment rather than a blanket security claim.
Questions for the project decision
Before a pilot or expansion, purpose, participants, data categories, permitted actions, possible effects and necessary human controls are considered together. Open legal or security-critical questions are not replaced by technical assumptions.
- What role does the organisation have?
- Which data and people are affected?
- Which outcomes or actions have an effect?
- Who may review, approve and stop?
- Which evidence, tests and ongoing controls are necessary?
- Which qualified legal or security review is still missing?
Source note
Status: 11 August 2026. General guidance based on the official EU AI Act and GDPR texts, amending Regulation (EU) 2026/1744, current European Commission guidance and BSI risk analysis. This is not legal advice and does not classify or claim conformity for a specific system.
Primary sources
Official sources, editorially checked on 11 August 2026.
- Regulation (EU) 2024/1689 — Artificial Intelligence ActEUR-Lex
- Regulation (EU) 2026/1744 — Digital Omnibus on AIEUR-Lex
- Navigating the AI ActEuropean Commission
- Regulation (EU) 2016/679 — General Data Protection RegulationEUR-Lex
- Generative AI Models: Opportunities and Risks for Industry and AuthoritiesBundesamt für Sicherheit in der Informationstechnik (BSI)


