An initiative by Solutive AG
solutive.ag
AI Governance

The EU AI Act: Requirements, roles, and action items for businesses

The EU AI Act is the world's first comprehensive AI regulatory framework. It applies extraterritorially and designates SAP customers as deployers.
April 28, 2026
min Lesezeit
14

EU AI Act: Four risk classes, two roles, one extraterritorial scope

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI regulation. It entered into force on August 1, 2024, and is being implemented in stages. Its scope is extraterritorial: the Act applies to all providers placing AI systems on the EU market or putting them into service, regardless of where those providers are based. It also applies to deployers (users of AI systems) based in the EU.

The EU AI Act follows a risk-based approach. AI systems are categorized into four classes:

Unacceptable risk. AI systems that threaten fundamental rights are prohibited. Examples include social scoring by public authorities, real-time biometrics in public spaces (with narrow exceptions), and manipulative systems that exploit unconscious vulnerabilities. These prohibitions have been in effect since February 2, 2025.

High risk (Annex III). AI systems in specific high-risk areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and the judiciary. These systems are subject to strict requirements: technical documentation, risk management systems, data governance, transparency, human oversight, accuracy, and robustness. Providers must conduct a conformity assessment and register the system in the EU database. Deployers have their own obligations under Article 26.

Limited risk. Transparency obligations under Article 50. AI systems that interact directly with humans (chatbots, deepfakes, generated text) must disclose this. These obligations apply from August 2, 2026.

Minimal risk. No specific requirements. Voluntary codes of conduct are encouraged by the Commission.

Timeline, sanctions, and the role of SAP as a GPAI provider

The EU AI Act comes into force in stages:

August 1, 2024: Entry into force. February 2, 2025: Prohibitions apply. August 2, 2025: Requirements for General-Purpose AI (GPAI) models apply. August 2, 2026: High-risk requirements under Annex III and transparency obligations under Article 50 apply. August 2, 2027: Requirements for AI systems in products under Annex I apply.

Sanctions. Up to 35 million euros or 7 percent of total worldwide annual turnover for violations of prohibitions. Up to 15 million euros or 3 percent for other violations. Up to 7.5 million euros or 1.5 percent for providing incorrect information.

SAP as a GPAI provider. SAP has achieved ISO 42001 certification and is positioning itself as a compliant AI provider. SAP products such as Joule are based on large language models and potentially fall under the GPAI requirements of Article 51 et seq. of the EU AI Act. As a provider, SAP bears the obligations under Article 16 (high-risk systems) and Article 53 (GPAI models). SAP customers, as deployers, bear the obligations under Article 26.

AI inventory, deployer obligations, and transparency requirements from August 2026

AI inventory as a mandatory foundation. No inventory, no compliance. All AI systems used or operated by the company are recorded and classified according to the risk categories of the EU AI Act. The inventory forms the basis for all further compliance measures.

Deployer obligations under Article 26. Deployers of high-risk AI systems must: use the system in accordance with the provider's instructions, ensure human oversight by qualified personnel, retain logs for at least six months, conduct a Fundamental Rights Impact Assessment (FRIA) for specific contexts, and report serious incidents. Deployers cannot delegate these obligations to the provider.

Transparency obligations under Article 50. Starting August 2, 2026, deployers of AI systems that interact directly with humans must disclose this. This applies to chatbots, AI assistants, and systems that generate text, images, or other content. Joule in customer contact: transparency obligation. Joule in internal use by employees: depends on the context.

Classification uncertainty and lead times for conformity assessments

Classification gap. The Commission promised guidelines for interpreting Article 6 (classification of high-risk systems). The deadline was February 2, 2026. The guidelines have not been published. Companies must classify without official guidance. The uncertainty particularly affects systems in the gray area between limited risk and high risk.

Lead times for conformity assessments. A full conformity assessment for a high-risk AI system takes three to six months, depending on the system and the organization. Anyone wanting to be compliant by August 2026 must start today. Anyone who does not yet have an AI inventory has no basis for a conformity assessment.

Digital Omnibus on AI. In March 2026, the EU Commission introduced a proposal to postpone the high-risk deadlines. The trilogue is ongoing. Even if the postponement happens: the transparency obligations under Article 50 are explicitly excluded and will apply from August 2, 2026. Furthermore, lead times for conformity assessments will not be shortened by a postponement.

Dual-track planning and conservative classification in cases of doubt

Dual-track planning. Track A: Transparency obligations and inventorying by August 2026, regardless of the Digital Omnibus. Track B: Conformity assessments and high-risk compliance with the original target of August 2026, prepared for a postponement to December 2027. The tracks run in parallel. Track B will not be paused, even if the Digital Omnibus is passed.

Conservative classification in cases of doubt. If you are unsure whether a system falls under high risk, classify it provisionally as high risk and implement the requirements. A later reclassification to limited risk is easier than a retroactive conformity assessment under time pressure.

Actively request provider documentation. As a provider, SAP is obligated under Article 13 to provide deployers with the information necessary to fulfill their deployer obligations. This documentation should be actively requested and anchored within contract management.

Tool Landscape

Summary

The EU AI Act designates SAP customers as deployers with obligations under Article 26. Transparency requirements begin in August 2026, requiring dual-track planning for high-risk readiness and a conservative classification approach until guidance is issued.

Autor:
Christian Steiger