Search
Contact
Symbolbild zu AI Act
16.07.2024 | KPMG Law Insights

AI Act: The EU wants to get to grips with the risks of AI

The AI Act took effect on August 1, 2024 and has been gradually implemented since then. It is considered the world’s first law regulating artificial intelligence (AI). The AI Act categorizes AI into risk groups. The higher the risk of an application, the stricter the requirements and obligations are supposed to be.

With this regulation, the EU aims to limit the risks that artificial intelligence may pose and to effectively mitigate the significant risks to users.

The idea behind the regulation: the higher the risk of an AI system, the higher the associated requirements and obligations. AI regulation is intended to increase user confidence in AI within the EU and thus also create better conditions for innovation for manufacturers and users of AI applications.

The obligations under the EU AI Act apply in particular to providers, importers, distributors, and operators of AI systems, as well as manufacturers of products in which AI systems are integrated. Given its broad scope, the AI Act may be relevant to a large number of companies that develop, distribute, or use AI.

 

Violations and Liability

Violations can result in fines of up to 35 million euros or up to seven percent of the total global annual turnover of the previous financial year. The sanctions are thus comparable to those of the GDPR.

To address liability issues related to AI, the EU has revised the Product Liability Directive. The new EU Product Liability Directive must be transposed into national law by December 9, 2026. It explicitly includes software and AI systems within its scope and is intended to make it easier to substantiate claims for damages caused by complex technologies.

 

AI with an “unacceptable” level of risk prohibited by the AI Act

The AI Act classifies artificial intelligence into four risk categories: “unacceptable,” “high,” “limited,” and “minimal.”

Placing on the market, putting into service, or using AI systems that pose an unacceptable risk is prohibited. These include, in particular, those AI systems that are designed to subliminally adversely influence human behavior. AI that serves to exploit the weaknesses of vulnerable individuals is also unacceptable and thus prohibited. Also prohibited is the use of AI systems by public authorities to assess or classify the trustworthiness of natural persons (“social scoring”). AI systems may likewise not in principle be used for real-time biometric remote identification of natural persons in publicly accessible spaces for law enforcement purposes.

For AI systems with risk class “high”, special requirements apply

AI systems that pose a high risk to the health and safety or fundamental rights of natural persons are referred to as “high-risk AI systems.” These include, for example, human dignity, respect for private and family life, protection of personal data, freedom of expression and information, and freedom of assembly and association.

The AI Act imposes stringent requirements on the design and use of high-risk AI systems, for example, in terms of the quality of the data basis, security, functionality, and also human documentation and oversight, as well as quality and risk management.

Conformity with the AI Act should be made visible with a CE marking.

 

Lower requirements for systems with “low/minimal” risk class

Unless AI systems are unacceptable and also classified as high-risk AI systems, they fall into the third category. They are then subject to less stringent requirements. However, providers of such systems should still establish codes of conduct and be encouraged to voluntarily apply the regulations for high-risk AI systems. In addition, the EU AI Act requires that even low-risk AI systems must be safe if they are placed on the market or put into service. Security can be ensured in particular by voluntarily observing the regulations for high-risk AI systems.

 

New Regulations for General-Purpose AI Models (GPAI)

The AI Act also contains specific regulations for AI models with a general purpose, also known as general purpose AI (GPAI). These AI models can serve different purposes and act as an independent system or as an integrative component of other systems. In principle, they represent AI systems with limited risk and are therefore subject to the transparency obligations under Art. 52. However, the category of “GPAI models with systemic risk” was also introduced in the new Art. 52a. This includes GPAI models with a “high potential impact”. The potential impact is high if the model’s capabilities match or exceed those of the most advanced EPAI models. This should be determined using benchmarks or on the basis of findings by the EU Commission. If the computational effort for the training, measured in “floating point operations”, exceeds 10^25, it is presumed. There are some obligations for GPAI models, for example: the provision of technical documentation and instructions for use, compliance with copyright and the summary of the content used for the training. For GPAI models with systemic risk, there are additional obligations regarding risk management and ensuring cyber security.

 

When do the various obligations under the AI Act take effect?

The AI Act is being implemented in phases. The Digital Omnibus on AI, which took effect in July 2026, extended the deadlines for high-risk AI systems in particular.

February 2, 2025: Prohibited AI Practices and AI Literacy

As of that date, prohibitions on certain AI practices that the AI Act classifies as posing an unacceptable risk will take effect. These include certain forms of manipulation of individuals or social scoring by government agencies. Companies must take measures to promote AI literacy among individuals who use or operate AI systems on their behalf.

August 2, 2025: New Rules for General-Purpose AI (GPAI)

Providers of general-purpose AI models must, among other things, prepare technical documentation, comply with copyright requirements, and provide information about the content used for training. For GPAI models that pose systemic risk, additional obligations regarding risk management and cybersecurity apply.

August 2, 2026: Transparency requirements take effect

As of August 2, 2026, the transparency requirements of the AI Act will generally take effect. However, transitional provisions will apply to certain labeling requirements for AI-generated content until December 2, 2026.In certain cases, users must be informed that they are interacting with an AI system. In addition, AI-generated or AI-manipulated content must be labeled as such. Furthermore, regulatory enforcement of the GPAI regulations already in effect will begin.

December 2, 2026: New Bans on Certain Deepfakes

As of that date, additional prohibitions will apply to AI systems that generate non-consensual intimate deepfakes or depictions of child sexual abuse.

August 2, 2027: Numerous additional regulations will take effect

As of that date, numerous other provisions of the AI Act will take effect, particularly those relating to governance, market oversight, and regulatory enforcement. The Digital Omnibus has merely postponed certain deadlines for high-risk AI systems, but not the application of the AI Act as a whole.

December 2, 2027: Requirements for Most High-Risk AI Systems

The specific requirements for most autonomous high-risk AI systems will not take effect until that date. These include requirements related to data quality, risk management, documentation, human oversight, and conformity assessment procedures. This deadline was postponed by the Digital Omnibus compared to the original version of the AI Act.

August 2, 2028: High-Risk AI in Regulated Products

For high-risk AI systems that are integrated into certain regulated products, the requirements will not take effect until August 2, 2028. These include, for example, AI components in certain machines or other products that are already subject to sector-specific safety regulations.

 

With AI governance, companies can hedge risks

Organizations should actively evaluate each application and incorporate it into a governance structure.

All AI-based solutions should also be considered. Use cases and the associated risks should be known to companies. Manufacturers of an end product must comply with the vendor obligations set forth in the AI Act and ensure that the AI system embedded in the end product is compliant. Risks also include the liability risk arising from the AI Act.

When building AI governance, the key is who is responsible for grading the risks. To make the assessment as objective as possible, the team should be interdisciplinary.

 

How AI risk management can succeed

Companies should establish guidelines, processes and monitoring solutions for effective risk management. Various institutions and organizations such as BSI, IDW or DIN are already developing standards for this.

It is advisable not to separate compliance and performance. Management and IT should therefore work closely with the legal and compliance functions. Only if it is ensured that legal regulations are complied with and liability risks are minimized can the potential of artificial intelligence actually be exploited.

Once the AI Act is finally enacted, companies should promptly conduct a risk assessment of their AI applications and establish an appropriate governance structure.

 

Explore #more

11.08.2026 | In the media

Guest article in *Versicherungsmonitor* on the topic of cyber claims regulation

Cyberattacks—particularly ransomware campaigns—pose challenges for insurers when it comes to claims settlement. When entire IT infrastructures at insured companies come to a standstill and the…

11.08.2026 | KPMG Law Insights

Transparency Requirements Under Article 50 of the AI Act: Companies Should Address These Questions Now

The transparency requirements of the EU AI Act have been in effect since August 2, 2026. These obligations apply to chatbots, AI assistants, avatars, synthetic…

10.08.2026 | In the media

Op-Ed on the Procurement Acceleration Act and Sustainable Public Procurement

On April 23, 2026, the Bundestag passed the Act on Accelerating the Award of Public Contracts. After the Act was published in the Federal Law…

05.08.2026 | Deal Notifications

KPMG Law and KPMG Advise NMP Germany on the Acquisition of Klöckner Desma Elastomertechnik GmbH

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) and KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG) advised NMP Germany GmbH on the legal, tax, and financial aspects of the transaction…

04.08.2026 | In the media

Portrait of Mathias Oberndörfer in the *Börsen-Zeitung*

Mathias Oberndörfer has been with KPMG for more than 20 years—reason enough for an in-depth profile in the *Börsen-Zeitung*. The Börsen-Zeitung traces his career path…

03.08.2026 | Unkategorisiert

KPMG Law und KPMG beraten NMP Germany beim Erwerb der Klöckner Desma Elastomertechnik GmbH

Die KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) und die KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG) haben die NMP Germany GmbH beim Erwerb der Klöckner Desma Elastomertechnik Gruppe…

03.08.2026 | In the media

Statement by KPMG Law experts on the EU Packaging Regulation in the business magazine *impulse*

Starting January 1, 2030, packaging must consist of at least 70 percent recyclable materials. Starting August 1, 2030, so-called “deceptive packaging” will also be banned.…

30.07.2026 | KPMG Law Insights

CRD VI and Third-Country Banks: Preserving Cross-Border Access to the EU Market

From 11 January 2027, third-country banks will need to reassess whether they may continue to provide banking services into the EU on a cross-border basis.…

28.07.2026 | In the media

Op-ed in the FAZ on the topic “Who is liable when algorithms make decisions?”

Artificial intelligence has made its way into the boardroom. Whether it’s investment decisions, risk analysis, or workforce planning—the results of artificial intelligence are increasingly being…

23.07.2026 | In the media

Statement by KPMG Law experts on Südwestrundfunk (SWR) regarding the GKV Savings Act

On the TV program ” SWR Aktuell Rheinland-Pfalz,” KPMG Law hospital expert Harald Maas discusses the GKV Savings Act and the growing financial pressure…

Contact

Francois Heynike, LL.M. (Stellenbosch)

Partner
Head of Technology Law

THE SQUAIRE Am Flughafen
60549 Frankfurt am Main

Tel.: +49-69-951195770
fheynike@kpmg-law.com

© 2026 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll