31.07.2025
Blog
Europe
Regulatory
Data & AI

EU AI Act: AI to be subject to oversight from August 2025

From 2 August 2025, the next phase of the EU AI Act will come into force – bringing further obligations for businesses and public authorities. Providers and users of general-purpose AI (GPAI) models will be particularly affected. Anyone who uses, trains or integrates AI systems must comply with new requirements regarding documentation, transparency, risk management and compliance – including deadlines, technical requirements and potential fines. In this article, we outline what lies ahead, why action is needed now, and what steps you should take today.

Heike Abels
Corporate Communications Officer

On this date, several key provisions of the EU AI Act will come into force, which are primarily aimed at so-called GPAI models – that is, general-purpose AI models that can be used for a wide range of purposes (text, code, language, images, etc.). These include, for example, models such as GPT, LLaMA and Claude. These are therefore AI models that have not been developed solely for a specific task, but are capable of performing a wide range of tasks across different fields.

Obligations for providers of GPAI

Providers of GPAI models will in future have to comply with new requirements under the EU AI Act, which demand greater transparency and accountability in the use of AI. This includes technical documentation that clearly explains how the model is structured, what data it was trained on, and how much computing power was required for this.

In addition, transparency reports must be published, disclosing the model’s known weaknesses, risks and limitations. Furthermore, testing is mandatory to ensure that the AI does not produce discriminatory or dangerous results. The energy efficiency of the training process must also be documented to make resource consumption more transparent.

Another key point is the disclosure of the training data used. Providers should explain, in an easily understandable way, what data the model was trained on and where it came from. This is to ensure that it remains clear how the AI learns – and whether its basis is reliable and fair.

Additional requirements apply to particularly powerful models that are classified as posing systemic risk:

  • Obligation to carry out risk assessments
  • Adversarial testing to prevent misuse
  • Introduction of risk mitigation measures
  • Obligation to report incidents to supervisory authorities

The EU Member States themselves must also be in a position to act by then: they must designate national supervisory and notification authorities and put in place the necessary enforcement infrastructure.

Obligations for users of GPAI

In addition to providers, users of General-Purpose AI (GPAI) models are also subject to new requirements – particularly where GPAI is integrated into high-risk applications, such as in the fields of human resources, healthcare or finance. In such cases, users must ensure that the systems they use comply with the provisions of the EU AI Act, including documentation obligations, risk assessments and transparency requirements.

Why this issue is highly relevant right now

The provisions of the AI Act are no longer just theory – they have been adopted, have a set timetable and are accompanied by clear sanction mechanisms. From August 2025, companies and public authorities that develop, purchase or use AI technology may be subject to scrutiny by the authorities and face sanctions in the event of non-compliance.

The penalties are severe:

  • Up to 35 million euros or 7 % of global annual turnover for breaches of prohibitions
  • Up to 15 million euros or 3 % of annual turnover for failure to comply with GPAI obligations
  • Even providing false information to supervisory authorities can result in a fine of up to 7.5 million euros or 1.5 %

A particularly pressing issue is that many technical requirements (e.g. regarding training data or system boundaries) have not yet been fully standardised. The EU’s announced ‘Code of Practice’ is not expected to be published until the end of 2025 – companies should therefore keep a close eye on developments and respond appropriately once it is published.

To-do list: What do you need to prepare now?

1. Stock-take & risk classification

Compile a comprehensive AI inventory: Which systems do you use? Are they in-house developments or third-party models? Is GPAI being used?

Classify them according to the risk categories set out in the AI Act (prohibited, high-risk, GPAI, systemic). This forms the basis for all further measures.

2. Technical documentation and transparency

For all GPAI systems, you will need:

  • Model descriptions and the architecture in which the system is deployed
  • A list and categorisation of the training data (e.g. text, images, audio, licence status)
  • Details of training time, energy consumption and the infrastructure used
  • Evidence of bias tests, robustness and failure behaviour

This data must be verifiable internally and presentable to the authorities.

3. Establish governance structures

Define internal responsibilities for:

  • AI compliance and regulatory monitoring
  • Data protection and AI ethics
  • Incident reporting and audits

Integrate these structures into your existing risk and IT management. This is particularly important as the risk analysis, once documented within the context of the enterprise architecture (as described in point 2), may lead to new insights.

4. Review contracts and supply chains

If you use third-party AI (e.g. via APIs or in SaaS solutions), check the following:

  • Are there contractual assurances regarding AI compliance?
  • Are you informed about training data, system risks and limitations?
  • Do you have access to audit reports and security certifications?

You may need to amend your procurement policies or introduce new standard clauses. Don’t forget your public liability insurance and cyber insurance!

5. Training & internal awareness

The AI Act requires companies to ensure staff have adequate knowledge of how to handle AI. Develop:

  • Basic training courses for managers and specialist departments
  • Specialist training for IT, data science, procurement and legal departments
  • Processes for continuous professional development and documentation

What comes next?

Further milestones will follow in 2026, particularly for high-risk AI systems (e.g. in HR, the healthcare sector and finance). There will also be mandatory certifications, compliance procedures and extensive audit requirements at that stage.

Furthermore, new EU regulations such as the Cyber Resilience Act and the Data Act are closely linked to the AI Act. Anyone taking a strategic approach to AI compliance should factor these developments into their planning today.

Heike Abels
Corporate Communications Officer

Heike Abels works at Materna as a Corporate Communications Officer. She is responsible for the editorial content of various formats used for external communications. Her work focuses on Cross Market Services, which includes Enterprise Service Management, Customer Service and Cyber Security.

Related articles

Short News
Think ahead
Cyber Security
26.08.2026
Quantum computers: The end of encryption as we know it

Why post-quantum readiness extends far beyond cryptography and is becoming a key prerequisite for digital sovereignty – for public administration, critical infrastructure, industry and all organisations with data that requires long-term protection.

Read more
Blog
Think ahead
19.02.2026
Key factors for successful and effective transformation projects

Find out how to successfully manage your digital transformation and which best practices will help you ensure your project is sustainable.

Read more
Blog
Think ahead
06.01.2026
IT Trends 2026: Artificial Intelligence for Efficiency and Security

By 2026, artificial intelligence will have become an integral part of day-to-day IT operations. The key question for IT organisations is no longer …

Read more
Blog
Think ahead
18.11.2025
Thinking about, supporting and steering transformation holistically

At first glance, many projects appear to be purely about tools or processes. In reality, however, they represent far-reaching transformations. Anyone…

Read more
Blog
Think ahead
30.09.2025
Digital transformation: 7 mistakes to avoid

Digital transformation projects are complex and challenging undertakings which, even when approached using agile methods, require careful planning,…

Read more
Blog
Think ahead
Data & AI
23.09.2025
Enterprise GPTs based on a general, modular platform

Artificial intelligence (AI) is rapidly becoming a key factor in business success. To ensure that the use of AI assistants does not result in a…

Read more
Blog
Think ahead
Versicherungen
16.09.2025
The insurance industry in transition: How insurance services can now win over Gen Z

Generation Z wants security – but it must be digital, straightforward and sustainable. Traditional insurance products are becoming less relevant, even…

Read more
Blog
Think ahead
09.09.2025
Hybrid chatbots: architecture and technical implementation

In the first part of our series, we showed why hybrid chatbots represent the perfect combination of traditional, rule-based approaches and modern…

Read more
Blog
Think ahead
01.07.2025
How spatial computing creates new spaces for experiences

How will we change our world when digital information no longer exists solely on screens, but is embedded directly within our physical space? Welcome…

Read more
Blog
Regulatory
Think ahead
05.06.2025
Compliance meets sustainability: ITSM & ITIL in the age of the EU AI Act

Compliance with the EU AI Act is of crucial importance for organisations that use artificial intelligence (AI). IT service management (ITSM) and ITIL…

Read more