A guest contribution by Roosbeh Karimi | KARIMI.legal
Many companies still assume that obligations relating to artificial intelligence are something for the future. A look at the timeline of the EU AI Act shows otherwise: key requirements are already in force, and since August 2026, enforcement in Germany has become active. It is therefore a good time to clearly outline the most important

AI literacy is not optional – it is mandatory
The legal basis is Article 4 of the EU AI Act. It requires providers and deployers to ensure that their staff have a sufficient level of AI literacy – regardless of the risk category of the AI system being used. Importantly, this obligation has applied since February 2, 2025, not only since the media coverage in August 2026.
Anyone who thinks this applies only to software manufacturers is mistaken. The legal definition in Article 3 of the EU AI Act defines a “deployer” very broadly: any natural or legal person, public authority, agency or other body using an AI system under its own authority falls within the scope. This means that most organizations using tools such as chatbots or large language models in their day-to-day work are affected – not just the companies that develop them. The requirement also applies not only to employees, but explicitly to contractors.
What is not required, however, is a specific certificate, a prescribed training format, a minimum number of training hours or the appointment of a formal AI officer. What matters is that organizations can demonstrate that they have taken appropriate measures – for example through training, documentation and clear internal rules.
What data protection actually protects
A common misconception is that data protection protects data itself – that is the role of data security. Data protection protects people’s right to determine how information relating to them is processed.werden.
The basic principle is that processing personal data is prohibited unless there is a legal basis that permits it. Responsibility lies with the organization, not with the individual employee using the tool
In practice, it is useful to distinguish between three categories of data:
- Personal data – any information that can be linked to an identifiable person, such as a name, IP address or customer number
- Special categories of personal data – such as health data or information about ethnic origin, which are subject to particularly strict protection
- Non-personal data – this is where one of the most common mistakes occurs: merely pseudonymizing data, for example by replacing a person’s name with an employee number, is not enough. Only genuine anonymization, where it is no longer possible to identify the person, qualifies as non-personal data.
Public versus internal AI systems
When public AI services are used, company data leaves the organization and is processed on the provider’s servers. Depending on the service, storage and the use of data for model training may also be possible, particularly with free services.
A useful rule of thumb for everyday work is simple: do not enter anything into a public AI tool that you would not also be comfortable saying publicly or writing on a postcard.
The four risk levels under the EU AI Act
The EU AI Act distinguishes between four risk levels:
- Unacceptable risk – prohibited altogether, for example social scoring or emotion recognition in the workplace
- High risk – permitted, but subject to strict requirements under Article 6, for example in recruitment or credit decisions
- Limited risk – subject to transparency obligations under Article 50, for example certain chatbots
- Minimal risk – no specific additional obligations, for example spelling assistants
Transparency obligations since August 2026
Since August 2, 2026, the transparency obligations under Article 50 have applied – and they are more nuanced than they may initially appear.
People interacting with an AI system must generally be able to recognize that they are dealing with AI, unless this is already obvious from the circumstances.
For text content, one key factor is who performed the final review. If a text – whether generated entirely by AI or merely revised linguistically by an AI system – is published without substantive human review, the transparency obligation may apply. A purely spelling or grammar-related correction does not itself trigger such a requirement. The decisive point is whether a person has actually reviewed the content and assumed editorial responsibility for it.
Synthetic content and deepfakes must also be labeled accordingly. This is particularly relevant for content concerning matters of public interest, such as images or texts dealing with socially or politically significant topics.Regardless of the legal minimum, transparent labeling is rarely a disadvantage – even where it is not strictly mandatory.
Violations of these and other obligations can result in significant penalties. Depending on the type of infringement, fines can reach up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, and up to EUR 15 million or 3% for other violations of the Act.
The biggest everyday risk: data input
In practice, the biggest risk often lies not in the technology itself, but in the moment data is entered into a tool. When information is entered into a public service, the organization gives up a degree of control over how that data is processed. From a data protection perspective, this may constitute disclosure of data to a third party and therefore requires an appropriate legal basis and, in many cases, a data processing agreement.
Certain types of information should generally never be entered into unapproved public AI tools:
- Personal data relating to third parties
- Recruitment documents and employee records
- Special categories of personal data
- Trade secrets and confidential internal information
Automated decisions: humans remain in the loop
Under Article 22 of the General Data Protection Regulation, individuals generally have the right not to be subject to a decision based solely on automated processing if that decision produces legal effects or similarly significantly affects them.
There are limited exceptions, for example where explicit consent has been given. As a general rule, however, important decisions should ultimately be made by a human.
Practical rules for everyday work
Good practice includes:
- Only use approved tools
- Review results for accuracy and verify whether the information is still up to date
- Label AI-generated content where appropriate
- Replace personal data with placeholders wherever possible
- Ask for guidance when in doubt
The following should be avoided:
- Entering personal data or trade secrets into public AI tools
- Allowing AI to make important decisions on its own
- Secretly using unapproved tools – so-called “shadow AI”
- Forwarding AI-generated results without reviewing them
- Concealing incidents
A simple four-question check can help in everyday situations: Is the tool approved? Where does the data go? Does it contain personal data? What will happen with the result?
What to do if something goes wrong
In the event of a data protection incident, different reporting obligations may apply independently of one another.
A personal data breach may have to be reported to the relevant supervisory authority within 72 hours of the organization becoming aware of it. If there is a high risk to the affected individuals, those individuals must also be informed without undue delay. In addition, serious incidents involving high-risk AI systems may need to be reported without undue delay to the market surveillance authority and the provider.
The most important rule is therefore: report the incident immediately, document what happened and inform the responsible internal team. Do not try to handle the situation alone and never simply ignore the incident.
Conclusion
AI is a tool – responsibility remains with people.
Personal and confidential data does not belong in unapproved AI tools. AI-generated results should always be reviewed critically, because confident language does not necessarily mean that the information is correct. AI content may need to be labeled, and incidents must be reported.
The EU AI Act follows a risk-based approach. What matters is therefore not the technology itself, but how it is used in a specific context.
Rules alone are not enough – they need the right technical implementation
These principles work best in practice when they are supported by appropriate technical measures. Aiverti was developed precisely for this purpose: a GDPR-compliant AI platform with built-in anonymization for personal data, contractually secured data processing agreements with all integrated model providers, and the ability to connect company-specific knowledge through a RAG system – without using company data to train third-party models.
Another practical issue remains particularly relevant: so-called shadow AI, meaning the use of private or unapproved AI tools for work-related purposes – especially on mobile devices.
This is where Cortado MDM comes in. Centralized device management allows IT teams to control which apps are available on corporate devices. Approved AI applications can be deployed in a targeted way, while reducing the risk of business data unintentionally ending up in unapproved tools.
In this way, data protection expertise, a GDPR-compliant AI platform and centrally managed devices complement one another. Together, they help organizations turn AI literacy under Article 4 from a policy requirement into something that can be implemented – and demonstrated – in everyday work.