Compliance

AI Compliance and AI Act – Requirements for Companies

The use of artificial intelligence offers companies significant opportunities, but it also creates new legal and organizational requirements. The European Artificial Intelligence Act (AI Act) follows a risk-based approach and imposes different obligations depending on the type and use of an AI system and the role of the company concerned.

In addition to the AI Act, companies must also consider applicable requirements relating to data protection, employment law, intellectual property and confidentiality.

Our lawyers specializing in legal compliance advise companies on how to organize the use of artificial intelligence in a legally compliant manner, identify risks at an early stage and implement appropriate internal policies and control processes.

What requirements does the AI Act impose on companies?

The AI Act distinguishes in particular between the role of a company and the level of risk associated with the relevant artificial intelligence system. A company may, for example, qualify as a provider or deployer of an AI system. The applicable requirements therefore depend on the system concerned and the way in which it is used.

Several provisions of the AI Act already apply. These include prohibitions on certain AI practices and requirements relating to AI literacy. Since August 2, 2026, transparency obligations also apply to certain AI systems and certain AI-generated or manipulated content. Specific requirements for high-risk AI systems apply according to the phased implementation schedule provided for by the AI Act.

Our lawyers specializing in legal compliance assess your company’s role under the AI Act and determine which requirements apply to the AI systems you use.

Which AI systems can companies use and which AI practices are prohibited?

The AI Act follows a risk-based approach. Many artificial intelligence tools used by companies are not subject to the specific requirements applicable to high-risk AI systems. Certain applications, however, are prohibited or subject to enhanced regulatory requirements.

Particular attention is required when artificial intelligence is used in human resources. Certain systems used for recruitment, employee selection, evaluation or management may qualify as high-risk AI systems. Certain practices, including certain forms of emotion recognition in the workplace, are prohibited.

Companies should therefore first identify which AI systems are being used, for what purposes and in relation to which individuals, and then conduct a legal risk assessment for each relevant use case.

Our lawyers assist companies with the classification of AI systems and the legal assessment of permitted uses. For employment-related issues involving artificial intelligence, see also our Human Resources practice.

What requirements apply when employees use AI tools?

Generative AI applications, translation software, analytical tools and automated assistants are increasingly used directly by employees in their day-to-day work. Companies should therefore establish clear rules specifying which tools may be used and which data and information may be entered into AI systems.

Under the AI Act, providers and deployers of AI systems must also take measures to support the development of AI literacy among employees and other persons who operate or use AI systems on their behalf. Appropriate measures should take into account factors such as the employees’ technical knowledge and experience, the context in which the AI system is used and the persons affected by its use.

In practice, companies should implement appropriate training, clear internal guidelines, defined responsibilities and awareness measures addressing the principal legal risks associated with the use of artificial intelligence.

Our lawyers advise companies on the development of appropriate training and compliance measures for the professional use of AI.

How should companies implement an internal AI policy?

An internal AI policy should define which AI tools may be used, by whom and for which purposes. It should reflect the company’s actual business processes and should not be limited to general prohibitions.

An AI policy may address in particular:

  • approved and prohibited AI systems;
  • the handling of trade secrets and confidential information;
  • the processing of personal data;
  • the review and verification of AI-generated results;
  • applicable transparency and labeling requirements;
  • the use of AI-generated texts, images and other content;
  • internal responsibilities and approval procedures;
  • documentation requirements and procedures for reporting risks or incidents.

The AI policy should be integrated into the company’s overall compliance system and regularly reviewed to reflect technological and regulatory developments.

Our lawyers work with companies to develop practical internal AI policies and governance structures tailored to their needs.

How can companies establish an effective AI compliance system?

An effective AI compliance system begins with an inventory of the artificial intelligence systems used within the company. On this basis, the company should determine its legal role, assess the risks associated with each use case and identify the applicable legal requirements.

In practice, an AI compliance system may include:

  • an internal inventory of AI systems in use;
  • classification according to the company’s role and the relevant level of risk;
  • clear responsibilities for AI governance;
  • an internal AI policy;
  • a review and approval process for new AI tools before they are introduced;
  • appropriate employee training;
  • data protection and information security assessments;
  • contractual requirements for AI providers;
  • documentation and control procedures;
  • regular reviews and updates of the compliance system.

For international corporate groups, these processes should also be coordinated at group level while taking into account the legal requirements applicable in the different jurisdictions in which the group operates.

Our lawyers specializing in legal compliance advise companies on the design and implementation of an AI compliance system tailored to their organization and business activities.

En pratique, un dispositif de conformité IA peut notamment comprendre :

  • un inventaire interne des systèmes d’IA utilisés ;
  • une classification des systèmes en fonction de leur rôle et de leur niveau de risque ;
  • la définition de responsabilités claires en matière de gouvernance de l’IA ;
  • une politique interne relative à l’utilisation de l’intelligence artificielle ;
  • une procédure de validation des nouveaux outils d’IA avant leur utilisation ;
  • des formations adaptées pour les salariés ;
  • des contrôles en matière de protection des données et de sécurité de l’information ;
  • des exigences contractuelles à l’égard des fournisseurs de solutions d’IA ;
  • des procédures de documentation et de contrôle ;
  • une révision régulière du dispositif.

Dans les groupes internationaux, ces processus doivent également être coordonnés à l’échelle du groupe tout en tenant compte des exigences juridiques applicables dans les différents pays.

Nos avocats en droit numérique vous accompagnent dans la conception et la mise en œuvre d’un dispositif de conformité IA adapté à votre entreprise.

What data protection and confidentiality requirements must companies consider when using AI?

The AI Act does not replace the General Data Protection Regulation (GDPR). If an AI system processes personal data, the requirements of the GDPR continue to apply in addition to the AI Act.

Depending on the intended use, companies may need to assess the legal basis for processing, transparency requirements, data minimization, the use of processors, international data transfers and, where appropriate, the need to conduct a data protection impact assessment.

Companies must also protect trade secrets and other confidential business information. When using external generative AI services in particular, companies should determine which information is processed or stored by the provider and whether data entered into the system may be used to develop or improve its models.

Our lawyers advise companies on the interaction between AI compliance and data protection and assess the legal implications of AI tools and service providers used by the company.

You have any other questions?

Feel free to ask them directly here.

Benötigen Sie eine persönliche Beratung?

Hinterlassen Sie uns Ihre Kontaktdaten und ein Mitglied unseres Teams wird Sie in Kürze zurückrufen, um Ihre Fragen zu beantworten und Sie bei Ihren Verfahren zu unterstützen.

"*" indicates required fields