{"id":6530,"date":"2026-09-18T11:34:42","date_gmt":"2026-09-18T11:34:42","guid":{"rendered":"https:\/\/blog.cortado.com\/?p=6530"},"modified":"2026-09-18T11:41:06","modified_gmt":"2026-09-18T11:41:06","slug":"ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require","status":"publish","type":"post","link":"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/","title":{"rendered":"AI in the Workplace: What Data Protection and the EU AI Act Really Require"},"content":{"rendered":"\n<p>A guest contribution by <a href=\"https:\/\/www.linkedin.com\/in\/roosbehkarimi\/\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-contrast-color\">Roosbeh Karimi<\/mark><\/a> \u00a0|\u00a0<a href=\"https:\/\/karimi.legal\/kanzlei\/roosbeh-karimi\"><mark style=\"background-color:rgba(0, 0, 0, 0);color:#203778\" class=\"has-inline-color\">KARIMI.legal<\/mark><\/a><\/p>\n\n\n\n<p>Many companies still assume that obligations relating to artificial intelligence are something for the future. A look at the timeline of the EU AI Act shows otherwise: key requirements are already in force, and since August 2026, enforcement in Germany has become active. It is therefore a good time to clearly outline the most important   <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"572\" src=\"https:\/\/blog.cortado.com\/wp-content\/uploads\/\/converted-1789476308634-1024x572.png\" alt=\"\" class=\"wp-image-6528\" srcset=\"https:\/\/blog.cortado.com\/wp-content\/uploads\/converted-1789476308634-1024x572.png 1024w, https:\/\/blog.cortado.com\/wp-content\/uploads\/converted-1789476308634-300x167.png 300w, https:\/\/blog.cortado.com\/wp-content\/uploads\/converted-1789476308634-768x429.png 768w, https:\/\/blog.cortado.com\/wp-content\/uploads\/converted-1789476308634.png 1376w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-ai-literacy-is-not-optional-it-is-mandatory\"><strong>AI literacy is not optional \u2013 it is mandatory<\/strong> <\/h4>\n\n\n\n<p>The legal basis is Article 4 of the EU AI Act. It requires providers and deployers to ensure that their staff have a sufficient level of AI literacy \u2013 regardless of the risk category of the AI system being used. Importantly, this obligation has applied since February 2, 2025, not only since the media coverage in August 2026.   <\/p>\n\n\n\n<p>Anyone who thinks this applies only to software manufacturers is mistaken. The legal definition in Article 3 of the EU AI Act defines a &#8220;deployer&#8221; very broadly: any natural or legal person, public authority, agency or other body using an AI system under its own authority falls within the scope. This means that most organizations using tools such as chatbots or large language models in their day-to-day work are affected \u2013 not just the companies that develop them. The requirement also applies not only to employees, but explicitly to contractors.    <\/p>\n\n\n\n<p>What is not required, however, is a specific certificate, a prescribed training format, a minimum number of training hours or the appointment of a formal AI officer. What matters is that organizations can demonstrate that they have taken appropriate measures \u2013 for example through training, documentation and clear internal rules.  <\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-data-protection-actually-protects\"><strong>What data protection actually protects<br><\/strong> <\/h4>\n\n\n\n<p>A common misconception is that data protection protects data itself \u2013 that is the role of data security. Data protection protects people&#8217;s right to determine how information relating to them is processed.werden.  <\/p>\n\n\n\n<p>The basic principle is that processing personal data is prohibited unless there is a legal basis that permits it. Responsibility lies with the organization, not with the individual employee using the tool  <\/p>\n\n\n\n<p>In practice, it is useful to distinguish between three categories of data: <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Personal data<\/strong> \u2013 any information that can be linked to an identifiable person, such as a name, IP address or customer number<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Special categories of personal data<\/strong> \u2013 such as health data or information about ethnic origin, which are subject to particularly strict protection<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Non-personal data<\/strong> \u2013 this is where one of the most common mistakes occurs: merely pseudonymizing data, for example by replacing a person&#8217;s name with an employee number, is not enough. Only genuine anonymization, where it is no longer possible to identify the person, qualifies as non-personal data.<br><\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-public-versus-internal-ai-systems\"><strong>Public versus internal AI systems<\/strong> <\/h4>\n\n\n\n<p>When public AI services are used, company data leaves the organization and is processed on the provider&#8217;s servers. Depending on the service, storage and the use of data for model training may also be possible, particularly with free services. <\/p>\n\n\n\n<p>A useful rule of thumb for everyday work is simple: do not enter anything into a public AI tool that you would not also be comfortable saying publicly or writing on a postcard. <\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-the-four-risk-levels-under-the-eu-ai-act\"><strong>The four risk levels under the EU AI Act<\/strong> <\/h4>\n\n\n\n<p>The EU AI Act distinguishes between four risk levels: <\/p>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>Unacceptable risk<\/strong> \u2013 prohibited altogether, for example social scoring or emotion recognition in the workplace<\/li>\n<\/ol>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li><strong>High risk<\/strong> \u2013 permitted, but subject to strict requirements under Article 6, for example in recruitment or credit decisions<\/li>\n<\/ol>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li><strong>Limited risk<\/strong> \u2013 subject to transparency obligations under Article 50, for example certain chatbots<\/li>\n<\/ol>\n\n\n\n<ol start=\"4\" class=\"wp-block-list\">\n<li><strong>Minimal risk<\/strong> \u2013 no specific additional obligations, for example spelling assistants<\/li>\n<\/ol>\n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-transparency-obligations-since-august-2026\"><strong>Transparency obligations since August 2026<\/strong> <\/h4>\n\n\n\n<p>Since August 2, 2026, the transparency obligations under Article 50 have applied \u2013 and they are more nuanced than they may initially appear.<br>People interacting with an AI system must generally be able to recognize that they are dealing with AI, unless this is already obvious from the circumstances.<br>For text content, one key factor is who performed the final review. If a text \u2013 whether generated entirely by AI or merely revised linguistically by an AI system \u2013 is published without substantive human review, the transparency obligation may apply. A purely spelling or grammar-related correction does not itself trigger such a requirement. The decisive point is whether a person has actually reviewed the content and assumed editorial responsibility for it.    <\/p>\n\n\n\n<p>Synthetic content and deepfakes must also be labeled accordingly. This is particularly relevant for content concerning matters of public interest, such as images or texts dealing with socially or politically significant topics.Regardless of the legal minimum, transparent labeling is rarely a disadvantage \u2013 even where it is not strictly mandatory.   <\/p>\n\n\n\n<p>Violations of these and other obligations can result in significant penalties. Depending on the type of infringement, fines can reach up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, and up to EUR 15 million or 3% for other violations of the Act. <\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-the-biggest-everyday-risk-data-input\"><strong>The biggest everyday risk: data input<\/strong> <\/h4>\n\n\n\n<p>In practice, the biggest risk often lies not in the technology itself, but in the moment data is entered into a tool. When information is entered into a public service, the organization gives up a degree of control over how that data is processed. From a data protection perspective, this may constitute disclosure of data to a third party and therefore requires an appropriate legal basis and, in many cases, a data processing agreement.  <\/p>\n\n\n\n<p>Certain types of information should generally never be entered into unapproved public AI tools: <\/p>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<ul class=\"wp-block-list\">\n<li>Personal data relating to third parties <\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<ul class=\"wp-block-list\">\n<li>Recruitment documents and employee records <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Special categories of personal data <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Trade secrets and confidential internal information <\/li>\n<\/ul>\n<\/div>\n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-automated-decisions-humans-remain-in-the-loop\"><strong>Automated decisions: humans remain in the loop<\/strong> <\/h4>\n\n\n\n<p>Under Article 22 of the General Data Protection Regulation, individuals generally have the right not to be subject to a decision based solely on automated processing if that decision produces legal effects or similarly significantly affects them.<br>There are limited exceptions, for example where explicit consent has been given. As a general rule, however, important decisions should ultimately be made by a human.  <\/p>\n\n\n\n<p><strong>Practical rules for everyday work<\/strong> <\/p>\n\n\n\n<p>Good practice includes: <\/p>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<ul class=\"wp-block-list\">\n<li>Only use approved tools <\/li>\n\n\n\n<li>Review results for accuracy and verify whether the information is still up to date<\/li>\n\n\n\n<li>Label AI-generated content where appropriate<\/li>\n\n\n\n<li>Replace personal data with placeholders wherever possible<\/li>\n\n\n\n<li>Ask for guidance when in doubt<\/li>\n<\/ul>\n<\/div>\n\n\n\n<p>The following should be avoided: <\/p>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<ul class=\"wp-block-list\">\n<li>Entering personal data or trade secrets into public AI tools<\/li>\n\n\n\n<li>Allowing AI to make important decisions on its own<\/li>\n\n\n\n<li>Secretly using unapproved tools \u2013 so-called &#8220;shadow AI&#8221;<\/li>\n\n\n\n<li>Forwarding AI-generated results without reviewing them<\/li>\n\n\n\n<li>Concealing incidents<\/li>\n<\/ul>\n<\/div>\n\n\n\n<p>A simple four-question check can help in everyday situations: Is the tool approved? Where does the data go? Does it contain personal data? What will happen with the result?    <\/p>\n\n\n\n<p>What to do if something goes wrong <\/p>\n\n\n\n<p>In the event of a data protection incident, different reporting obligations may apply independently of one another.<br>A personal data breach may have to be reported to the relevant supervisory authority within 72 hours of the organization becoming aware of it. If there is a high risk to the affected individuals, those individuals must also be informed without undue delay. In addition, serious incidents involving high-risk AI systems may need to be reported without undue delay to the market surveillance authority and the provider.<br>The most important rule is therefore: report the incident immediately, document what happened and inform the responsible internal team. Do not try to handle the situation alone and never simply ignore the incident.  <\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-conclusion\"><strong>Conclusion<\/strong> <\/h4>\n\n\n\n<p>AI is a tool \u2013 responsibility remains with people.<br>Personal and confidential data does not belong in unapproved AI tools. AI-generated results should always be reviewed critically, because confident language does not necessarily mean that the information is correct. AI content may need to be labeled, and incidents must be reported.<br>The EU AI Act follows a risk-based approach. What matters is therefore not the technology itself, but how it is used in a specific context.    <\/p>\n\n\n\n<p><strong>Rules alone are not enough \u2013 they need the right technical implementation<\/strong><\/p>\n\n\n\n<p>These principles work best in practice when they are supported by appropriate technical measures. <a href=\"https:\/\/aiverti.ai\/en\">Aiverti<\/a> was developed precisely for this purpose: a GDPR-compliant AI platform with built-in anonymization for personal data, contractually secured data processing agreements with all integrated model providers, and the ability to connect company-specific knowledge through a RAG system \u2013 without using company data to train third-party models. <\/p>\n\n\n\n<p>Another practical issue remains particularly relevant: so-called <a href=\"https:\/\/blog.cortado.com\/en\/shadow-ai-in-the-enterprise-when-employees-are-already-using-ai-before-it-is-ready\/\">shadow AI<\/a>, meaning the use of private or unapproved AI tools for work-related purposes \u2013 especially on mobile devices.<br>This is where <a href=\"https:\/\/www.cortado.com\/en\/\">Cortado MDM<\/a> comes in. Centralized device management allows IT teams to control which apps are available on corporate devices. Approved AI applications can be deployed in a targeted way, while reducing the risk of business data unintentionally ending up in unapproved tools.<br>In this way, data protection expertise, a GDPR-compliant AI platform and centrally managed devices complement one another. Together, they help organizations turn AI literacy under Article 4 from a policy requirement into something that can be implemented \u2013 and demonstrated \u2013 in everyday work.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A guest contribution by Roosbeh Karimi \u00a0|\u00a0KARIMI.legal Many companies still assume that obligations relating to artificial intelligence are something for the future. A look at the timeline of the EU AI Act shows otherwise: key requirements are already in force, and since August 2026, enforcement in Germany has become active. It is therefore a good [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":6529,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[440],"tags":[],"class_list":["post-6530","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-mobile-strategies-work-models"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v24.1 (Yoast SEO v25.6) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>AI in the Workplace: What Data Protection and the EU AI Act Really Require<\/title>\n<meta name=\"description\" content=\"AI literacy, data protection and labeling requirements: What the EU AI Act has required of companies since August 2026 \u2013 and how to implement it safely in everyday work fundamentals.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AI in the Workplace: What Data Protection and the EU AI Act Really Require\" \/>\n<meta property=\"og:description\" content=\"AI literacy, data protection and labeling requirements: What the EU AI Act has required of companies since August 2026 \u2013 and how to implement it safely in everyday work fundamentals.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/\" \/>\n<meta property=\"og:site_name\" content=\"Cortado Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-18T11:34:42+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-18T11:41:06+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blog.cortado.com\/wp-content\/uploads\/converted-1789476308634.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1376\" \/>\n\t<meta property=\"og:image:height\" content=\"768\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Guest Contribution\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Guest Contribution\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/\"},\"author\":{\"name\":\"Guest Contribution\",\"@id\":\"https:\/\/blog.cortado.com\/en\/#\/schema\/person\/fdf6a5b729d2231e7e4f581ea048ae1d\"},\"headline\":\"AI in the Workplace: What Data Protection and the EU AI Act Really Require\",\"datePublished\":\"2026-09-18T11:34:42+00:00\",\"dateModified\":\"2026-09-18T11:41:06+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/\"},\"wordCount\":1485,\"publisher\":{\"@id\":\"https:\/\/blog.cortado.com\/en\/#organization\"},\"image\":{\"@id\":\"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/blog.cortado.com\/wp-content\/uploads\/converted-1789476308634.png\",\"articleSection\":[\"Mobile Strategies &amp; Work Models\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/\",\"url\":\"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/\",\"name\":\"AI in the Workplace: What Data Protection and the EU AI Act Really Require\",\"isPartOf\":{\"@id\":\"https:\/\/blog.cortado.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/blog.cortado.com\/wp-content\/uploads\/converted-1789476308634.png\",\"datePublished\":\"2026-09-18T11:34:42+00:00\",\"dateModified\":\"2026-09-18T11:41:06+00:00\",\"description\":\"AI literacy, data protection and labeling requirements: What the EU AI Act has required of companies since August 2026 \u2013 and how to implement it safely in everyday work fundamentals.\",\"breadcrumb\":{\"@id\":\"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/#primaryimage\",\"url\":\"https:\/\/blog.cortado.com\/wp-content\/uploads\/converted-1789476308634.png\",\"contentUrl\":\"https:\/\/blog.cortado.com\/wp-content\/uploads\/converted-1789476308634.png\",\"width\":1376,\"height\":768},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.cortado.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AI in the Workplace: What Data Protection and the EU AI Act Really Require\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.cortado.com\/en\/#website\",\"url\":\"https:\/\/blog.cortado.com\/en\/\",\"name\":\"Cortado Blog\",\"description\":\"News from Cortado\",\"publisher\":{\"@id\":\"https:\/\/blog.cortado.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.cortado.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/blog.cortado.com\/en\/#organization\",\"name\":\"Cortado Blog\",\"url\":\"https:\/\/blog.cortado.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.cortado.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/blog.cortado.com\/wp-content\/uploads\/cortado-blog-logo.svg\",\"contentUrl\":\"https:\/\/blog.cortado.com\/wp-content\/uploads\/cortado-blog-logo.svg\",\"width\":226,\"height\":32,\"caption\":\"Cortado Blog\"},\"image\":{\"@id\":\"https:\/\/blog.cortado.com\/en\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.cortado.com\/en\/#\/schema\/person\/fdf6a5b729d2231e7e4f581ea048ae1d\",\"name\":\"Guest Contribution\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.cortado.com\/en\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/83b036c2bc064e8a2370d4b204753504?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/83b036c2bc064e8a2370d4b204753504?s=96&d=mm&r=g\",\"caption\":\"Guest Contribution\"},\"url\":\"https:\/\/blog.cortado.com\/en\/author\/marketing\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"AI in the Workplace: What Data Protection and the EU AI Act Really Require","description":"AI literacy, data protection and labeling requirements: What the EU AI Act has required of companies since August 2026 \u2013 and how to implement it safely in everyday work fundamentals.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/","og_locale":"en_US","og_type":"article","og_title":"AI in the Workplace: What Data Protection and the EU AI Act Really Require","og_description":"AI literacy, data protection and labeling requirements: What the EU AI Act has required of companies since August 2026 \u2013 and how to implement it safely in everyday work fundamentals.","og_url":"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/","og_site_name":"Cortado Blog","article_published_time":"2026-09-18T11:34:42+00:00","article_modified_time":"2026-09-18T11:41:06+00:00","og_image":[{"width":1376,"height":768,"url":"https:\/\/blog.cortado.com\/wp-content\/uploads\/converted-1789476308634.png","type":"image\/png"}],"author":"Guest Contribution","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Guest Contribution","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/#article","isPartOf":{"@id":"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/"},"author":{"name":"Guest Contribution","@id":"https:\/\/blog.cortado.com\/en\/#\/schema\/person\/fdf6a5b729d2231e7e4f581ea048ae1d"},"headline":"AI in the Workplace: What Data Protection and the EU AI Act Really Require","datePublished":"2026-09-18T11:34:42+00:00","dateModified":"2026-09-18T11:41:06+00:00","mainEntityOfPage":{"@id":"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/"},"wordCount":1485,"publisher":{"@id":"https:\/\/blog.cortado.com\/en\/#organization"},"image":{"@id":"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.cortado.com\/wp-content\/uploads\/converted-1789476308634.png","articleSection":["Mobile Strategies &amp; Work Models"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/","url":"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/","name":"AI in the Workplace: What Data Protection and the EU AI Act Really Require","isPartOf":{"@id":"https:\/\/blog.cortado.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/#primaryimage"},"image":{"@id":"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.cortado.com\/wp-content\/uploads\/converted-1789476308634.png","datePublished":"2026-09-18T11:34:42+00:00","dateModified":"2026-09-18T11:41:06+00:00","description":"AI literacy, data protection and labeling requirements: What the EU AI Act has required of companies since August 2026 \u2013 and how to implement it safely in everyday work fundamentals.","breadcrumb":{"@id":"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/#primaryimage","url":"https:\/\/blog.cortado.com\/wp-content\/uploads\/converted-1789476308634.png","contentUrl":"https:\/\/blog.cortado.com\/wp-content\/uploads\/converted-1789476308634.png","width":1376,"height":768},{"@type":"BreadcrumbList","@id":"https:\/\/blog.cortado.com\/en\/ai-in-the-workplace-what-data-protection-and-the-eu-ai-act-really-require\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.cortado.com\/en\/"},{"@type":"ListItem","position":2,"name":"AI in the Workplace: What Data Protection and the EU AI Act Really Require"}]},{"@type":"WebSite","@id":"https:\/\/blog.cortado.com\/en\/#website","url":"https:\/\/blog.cortado.com\/en\/","name":"Cortado Blog","description":"News from Cortado","publisher":{"@id":"https:\/\/blog.cortado.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.cortado.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/blog.cortado.com\/en\/#organization","name":"Cortado Blog","url":"https:\/\/blog.cortado.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.cortado.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/blog.cortado.com\/wp-content\/uploads\/cortado-blog-logo.svg","contentUrl":"https:\/\/blog.cortado.com\/wp-content\/uploads\/cortado-blog-logo.svg","width":226,"height":32,"caption":"Cortado Blog"},"image":{"@id":"https:\/\/blog.cortado.com\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/blog.cortado.com\/en\/#\/schema\/person\/fdf6a5b729d2231e7e4f581ea048ae1d","name":"Guest Contribution","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.cortado.com\/en\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/83b036c2bc064e8a2370d4b204753504?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/83b036c2bc064e8a2370d4b204753504?s=96&d=mm&r=g","caption":"Guest Contribution"},"url":"https:\/\/blog.cortado.com\/en\/author\/marketing\/"}]}},"_links":{"self":[{"href":"https:\/\/blog.cortado.com\/en\/wp-json\/wp\/v2\/posts\/6530"}],"collection":[{"href":"https:\/\/blog.cortado.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.cortado.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.cortado.com\/en\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.cortado.com\/en\/wp-json\/wp\/v2\/comments?post=6530"}],"version-history":[{"count":0,"href":"https:\/\/blog.cortado.com\/en\/wp-json\/wp\/v2\/posts\/6530\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.cortado.com\/en\/wp-json\/wp\/v2\/media\/6529"}],"wp:attachment":[{"href":"https:\/\/blog.cortado.com\/en\/wp-json\/wp\/v2\/media?parent=6530"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.cortado.com\/en\/wp-json\/wp\/v2\/categories?post=6530"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.cortado.com\/en\/wp-json\/wp\/v2\/tags?post=6530"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}