Skip to content

EU AI Act Applies to Users of Standard Software with AI Functions

The Bottom Line: Users of AI standard software are considered responsible parties for high-risk systems under the EU AI Act and are subject to the same compliance requirements as developers.

The EU AI Act obligates not only AI developers, but also companies that use standard software with integrated AI functions. This potentially affects far more German firms than previously assumed.

The EU AI Act makes no distinction between developers and users of artificial intelligence. Companies that operate standard software with integrated AI components can be classified as so-called “providers” or “users with significant risk” and brought under regulatory obligation. Those who deploy such systems must meet the strict compliance requirements for high-risk AI systems — regardless of whether the software was acquired as a standard product.

However, practical implementation remains unclear: standards for implementing many provisions are lacking, supervisory authority responsibilities are in some cases unresolved, and important deadlines have been postponed. Legal expert Erena Langley warns that this uncertainty poses considerable risks for German firms if they do not transparently document and monitor their AI systems. Those falling into high-risk categories — for example, AI in personnel selection, access to services, or security monitoring — must reckon with audits, risk analyses, and extensive data logging.

CTOs should therefore review which AI functions are embedded in their deployed software and into which high-risk category they fall. A thorough inventory and early coordination with compliance and legal teams is necessary to be prepared for regulatory inspections.


Source: www.security-insider.de · Published 10 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: