What actually applies
Most companies that use AI (ChatGPT, Copilot, Gemini, Claude and the like) build nothing — they are deployers, not providers. Even so, the following obligations are in scope. Only one of them is the high-risk regime everyone worries about; the rest apply regardless of risk tier.
| Obligation | Who it applies to | When | What it means |
|---|---|---|---|
| GDPR (data protection) | Every company processing personal data | Always — no transition period | Employees who put customer or personal data into an unapproved AI tool process it with no legal basis, no data-processing agreement and no record. |
| AI Act Art. 4 — AI literacy | Everyone who uses AI — no exception | Since 02 Feb 2025 | Staff must have sufficient AI literacy: a basic grasp of the opportunities and risks of the tools they use. |
| AI Act Art. 5 — prohibitions | Everyone | Since 02 Feb 2025 | Certain practices are banned outright — e.g. emotion recognition in the workplace, or social scoring. |
| AI Act Art. 50 — transparency | Anyone running chatbots or publishing AI content | From 02 Aug 2026 | Label chatbots as AI; visibly mark AI-generated or AI-edited content. |
| AI Act high-risk (Annex III) | Only for a high-risk use case | From 02 Dec 2027 | Human oversight, logging, informing affected people — triggered e.g. by AI in recruiting (see below). |
| Confidentiality (professional & contract law) | Firms under client or contractual confidentiality | Always | Putting client or customer data into an AI tool can breach confidentiality and trade-secret obligations — independent of the GDPR. |
The point many miss
The AI Act has transition periods. The GDPR does not.
The GDPR applies to every processing of personal data — from the moment someone copies a customer name, an email address or a contract into an AI tool. This is the duty that hits every company immediately, regardless of size, industry or AI-Act risk tier. And in practice the trigger is rarely the regulator: it is the first customer or auditor who asks you to show what your team is sending where. "The high-risk rules are deferred to 2027" is true for the high-risk rules only — it says nothing about the obligations that are already live today.
High-risk — for whom, really
The high-risk regime is narrower than the headlines suggest, and Annex III is an exhaustive list. Three groups are worth knowing:
- Broadly affected — HR & worker management. This is the widest hit. Not just recruiting and CV screening, but also decisions on promotion, task allocation, and monitoring or evaluating employee performance. Almost any company runs at least one of these.
- Industry-specific. Creditworthiness / credit scoring (anyone who assesses credit or grants lending) and risk assessment or pricing in life and health insurance. Narrow, sector-bound.
- Not high-risk. Customer support chatbots and lead qualification are generally limited-risk — here only the Art. 50 transparency duty applies, not the high-risk regime. Framing them as high-risk overstates the case (though the GDPR point still applies to any personal data they touch).
If AI does slip into your HR decisions, the heaviest work — the conformity assessment — sits with the tool's provider. A company using AI there becomes a high-risk deployer and must, operationally: ensure human oversight, run the system per the provider's instructions, monitor operation and suspend it on anomalies, keep the automatically generated logs for at least six months, and inform affected people (and, before workplace deployment, employees and the works council). For the classification mechanics — the two Article 6 routes, every Annex III area, and the exemption filter — see our companion guide on which AI systems are high-risk.
What this means in practice
For most companies the real question isn't "Are we regulated?" but: Do we know which AI tools our team uses — and with what data? And could we prove it if someone asked? Usually the honest answer is no.
That gap — real-time visibility, policy enforcement, and an audit log over AI usage — is what Qadar AI Shield is built to close: discover which AI tools are in use and with what data, govern or block them company-wide, and keep the usage records an auditor would ask for. And where Art. 50 requires you to label AI-generated content or chatbots, Disclose handles that transparency layer. Not because a law forces the purchase — but because you cannot control what you cannot see. If you'd like to talk through your specific situation, get in touch.
Download the one-page overview
Want a printable summary to share internally or with counsel? Download / print the one-page overview — the same obligations, timeline and high-risk breakdown on a single page.
This is not legal advice. This guide is for general guidance only. Regulatory statements reflect the EU AI Act as amended by the Digital Omnibus, which is adopted, with publication in the EU Official Journal still pending at the time of writing — deadlines may change. Seek qualified legal counsel for a binding assessment of your specific case.
Last verified: 20 July 2026.

