KI FÜR MÜNCHEN AI adoption. Done right.

LEGAL · 6 July 2026 · 10 min READ

EU AI Act for Product Developers: Risk Categories, Roles, Deadlines

On 2 August 2026, the next major tier of obligations under the EU AI Act takes effect. What companies with in-house development need to know now — risk categories, the underestimated shift to the provider role, and what to do immediately.

The EU AI Act is no longer forthcoming regulation — it is in force. Regulation (EU) 2024/1689 has applied since August 2024 and is being phased in step by step. The first stage has long been live: since February 2025, certain AI practices have been prohibited, and since then the obligation to ensure adequate AI literacy within your own organisation has also applied. On 2 August 2026 the largest stage follows: that is when the obligations for high-risk systems and the general transparency rules take effect.

For companies with their own software and hardware development, the AI Act is doubly relevant: once for the AI they use internally — and once for the AI they intend to build into their products. This article sets out what applies, to whom, and from when. It is orientation, not legal advice — but after reading it, you will know which questions to put to your lawyer.

The Basic Principle: Risk Determines Obligations

The AI Act does not regulate “AI” as such, but specific applications — graded by risk:

Prohibited practices. Manipulative techniques, social scoring, certain forms of biometric surveillance and emotion recognition in the workplace. Rarely relevant for SMEs — but anyone contemplating AI-supported employee monitoring, for instance, is moving into prohibited territory here. In force since February 2025.

High-risk systems. The heart of the Regulation, with two routes in: Annex III lists fields of use such as recruitment, credit scoring, critical infrastructure or education — anyone deploying AI there is operating a high-risk system. Annex I concerns product developers directly: AI as a safety component in products that are already EU-harmonised — machinery, medical devices, lifts, toys. More on that shortly.

Transparency obligations. Chatbots must identify themselves as such, AI-generated content and deepfakes must be labelled. Affects many — but is readily manageable.

Minimal risk. The great majority of applications: code assistance, document analysis, internal automation. Here the AI Act demands little — good governance is nevertheless in your own interest.

The practical consequence: Without an inventory and classification of your AI applications, you cannot know your obligations. That is always the first step.

The Underestimated Point: Deployer or Provider?

The AI Act distinguishes between roles — and the obligations hinge on the role:

Deployer is whoever uses an AI system under its own responsibility. That is you already, with every AI tool in the building. Deployer obligations are manageable: use in accordance with the instructions, human oversight, monitoring of operation, and for high-risk systems additionally logging and informing the affected employees — think works council.

Provider is whoever develops an AI system and places it on the market under its own name. And here lies the trap for product developers: Whoever builds AI into their product moves from deployer to provider. With the full catalogue of obligations: risk management system, data governance, technical documentation, logging, human oversight, evidence of accuracy and robustness, quality management system, conformity assessment, CE marking, registration.

Also important: whoever substantially modifies a third-party system or markets it under their own name can likewise slip into the provider role — faster than some would like.

The Deadlines at a Glance

  • Since 2 February 2025: Prohibited practices banned; obligation to ensure AI literacy (Art. 4) — your employees who work with AI must be demonstrably trained. That applies now, not at some point.
  • Since 2 August 2025: Obligations for providers of general-purpose AI models (GPAI); Member States’ penalty regimes.
  • From 2 August 2026: The main stage. High-risk obligations for the Annex III fields of use, transparency obligations, deployer obligations — the bulk of the Regulation becomes applicable.
  • From 2 August 2027: High-risk obligations for AI as a safety component in Annex I products (machinery, medical devices etc.). That is the deadline product developers must write into their project plans — anyone wanting to ship an AI feature in 2027 must factor conformity into development now, not retrofit it.

What Happens in the Event of Infringements

The fines are deliberately designed to sting: up to 35 million euros or 7 per cent of worldwide annual turnover for prohibited practices, up to 15 million euros or 3 per cent for most other infringements. Reduced ceilings apply to small and medium-sized enterprises — which is hardly reassuring. More realistic than the maximum fine is in any case a different scenario: the major customer or OEM who asks about your AI Act conformity in a supplier audit and, absent an answer, does not place the order.

What to Do Now — in This Order

  1. Inventory and classification. Record all AI applications — including the unofficial ones — and determine the risk category and your own role for each application. Result: a risk register you can present to auditors and customers.
  2. Make AI literacy demonstrable. The training obligation has applied since February 2025. Targeted training per department fulfils it — and incidentally solves the real adoption problem: nobody has time to teach themselves AI.
  3. Set up governance. Responsibilities, approval processes, human oversight, documentation. An AI management system in line with ISO/IEC 42001 provides the framework within which the AI Act obligations become manageable — more on this in our article on ISO 42001.
  4. Check the product roadmap against the 2027 deadline. If AI is to go into the product: conformity assessment, documentation and test concepts belong in development from the outset. Compliance by design is cheaper than retrofitting — always.

The AI Act rewards precisely what distinguishes good engineering anyway: defined processes, clean documentation, traceable behaviour. Whoever introduces AI transparently, tested and deterministically has already covered most of the ground — the Regulation then merely writes down what they are already doing.

This article was created with AI assistance and editorially reviewed under the responsibility of Stephan Walkowiak. See our AI transparency statement for details.

NEXT STEP

Apply this to your company?

In an initial consultation we discuss what this topic looks like in your specific case — honestly, even if the answer is "not yet".