31.07.2025
Blog
Europe
Regulatory
Data & AI

EU AI Act: AI to be subject to oversight from August 2025

From 2 August 2025, the next phase of the EU AI Act will come into force – bringing further obligations for businesses and public authorities. Providers and users of general-purpose AI (GPAI) models will be particularly affected. Anyone who uses, trains or integrates AI systems must comply with new requirements regarding documentation, transparency, risk management and compliance – including deadlines, technical requirements and potential fines. In this article, we outline what lies ahead, why action is needed now, and what steps you should take today.

Heike Abels
Referentin für Unternehmenskommunikation

On this date, several key provisions of the EU AI Act will come into force, which are primarily aimed at so-called GPAI models – that is, general-purpose AI models that can be used for a wide range of purposes (text, code, language, images, etc.). These include, for example, models such as GPT, LLaMA and Claude. These are therefore AI models that have not been developed solely for a specific task, but are capable of performing a wide range of tasks across different fields.

Obligations for providers of GPAI

Providers of GPAI models will in future have to comply with new requirements under the EU AI Act, which demand greater transparency and accountability in the use of AI. This includes technical documentation that clearly explains how the model is structured, what data it was trained on, and how much computing power was required for this.

In addition, transparency reports must be published, disclosing the model’s known weaknesses, risks and limitations. Furthermore, testing is mandatory to ensure that the AI does not produce discriminatory or dangerous results. The energy efficiency of the training process must also be documented to make resource consumption more transparent.

Another key point is the disclosure of the training data used. Providers should explain, in an easily understandable way, what data the model was trained on and where it came from. This is to ensure that it remains clear how the AI learns – and whether its basis is reliable and fair.

Additional requirements apply to particularly powerful models that are classified as posing systemic risk:

  • Obligation to carry out risk assessments
  • Adversarial testing to prevent misuse
  • Introduction of risk mitigation measures
  • Obligation to report incidents to supervisory authorities

The EU Member States themselves must also be in a position to act by then: they must designate national supervisory and notification authorities and put in place the necessary enforcement infrastructure.

Obligations for users of GPAI

In addition to providers, users of General-Purpose AI (GPAI) models are also subject to new requirements – particularly where GPAI is integrated into high-risk applications, such as in the fields of human resources, healthcare or finance. In such cases, users must ensure that the systems they use comply with the provisions of the EU AI Act, including documentation obligations, risk assessments and transparency requirements.

Why this issue is highly relevant right now

The provisions of the AI Act are no longer just theory – they have been adopted, have a set timetable and are accompanied by clear sanction mechanisms. From August 2025, companies and public authorities that develop, purchase or use AI technology may be subject to scrutiny by the authorities and face sanctions in the event of non-compliance.

The penalties are severe:

  • Up to 35 million euros or 7 % of global annual turnover for breaches of prohibitions
  • Up to 15 million euros or 3 % of annual turnover for failure to comply with GPAI obligations
  • Even providing false information to supervisory authorities can result in a fine of up to 7.5 million euros or 1.5 %

A particularly pressing issue is that many technical requirements (e.g. regarding training data or system boundaries) have not yet been fully standardised. The EU’s announced ‘Code of Practice’ is not expected to be published until the end of 2025 – companies should therefore keep a close eye on developments and respond appropriately once it is published.

To-do list: What do you need to prepare now?

1. Stock-take & risk classification

Compile a comprehensive AI inventory: Which systems do you use? Are they in-house developments or third-party models? Is GPAI being used?

Classify them according to the risk categories set out in the AI Act (prohibited, high-risk, GPAI, systemic). This forms the basis for all further measures.

2. Technical documentation and transparency

For all GPAI systems, you will need:

  • Model descriptions and the architecture in which the system is deployed
  • A list and categorisation of the training data (e.g. text, images, audio, licence status)
  • Details of training time, energy consumption and the infrastructure used
  • Evidence of bias tests, robustness and failure behaviour

This data must be verifiable internally and presentable to the authorities.

3. Establish governance structures

Define internal responsibilities for:

  • AI compliance and regulatory monitoring
  • Data protection and AI ethics
  • Incident reporting and audits

Integrate these structures into your existing risk and IT management. This is particularly important as the risk analysis, once documented within the context of the enterprise architecture (as described in point 2), may lead to new insights.

4. Review contracts and supply chains

If you use third-party AI (e.g. via APIs or in SaaS solutions), check the following:

  • Are there contractual assurances regarding AI compliance?
  • Are you informed about training data, system risks and limitations?
  • Do you have access to audit reports and security certifications?

You may need to amend your procurement policies or introduce new standard clauses. Don’t forget your public liability insurance and cyber insurance!

5. Training & internal awareness

The AI Act requires companies to ensure staff have adequate knowledge of how to handle AI. Develop:

  • Basic training courses for managers and specialist departments
  • Specialist training for IT, data science, procurement and legal departments
  • Processes for continuous professional development and documentation

What comes next?

Further milestones will follow in 2026, particularly for high-risk AI systems (e.g. in HR, the healthcare sector and finance). There will also be mandatory certifications, compliance procedures and extensive audit requirements at that stage.

Furthermore, new EU regulations such as the Cyber Resilience Act and the Data Act are closely linked to the AI Act. Anyone taking a strategic approach to AI compliance should factor these developments into their planning today.

Heike Abels
Referentin für Unternehmenskommunikation

Heike Abels arbeitet bei Materna als Referentin für Unternehmenskommunikation. Sie betreut redaktionell verschiedene Formate für die externe Kommunikation. Thematischer Schwerpunkt ist der Bereich Cross Market Services. Dazu zählen Enterprise Service Management, Customer Service und Cyber Security.

Related articles

Event
Frankfurt am Main
18.11.2026
BMC Helix Roadshow 2026

Meet Materna at the BMC Helix Roadshow 2026 on 18 November in Frankfurt and discover how modern service management, Agentic AI and compliance requirements work together successfully. Look forward to exclusive insights into the BMC Helix roadmap, the…

Read more
Event
Dortmund
05.11.2026
XCS Day (Xchange in Cyber Security)

At XCS Day, experts from the business and public sectors will once again come together to discuss current challenges and strategies relating to cyber security and regulation. Find out how organisations are strengthening their resilience to cyber…

Read more
Event
Dortmund
03.11.2026
FMS Information Day

On 3 November 2026, we will update you on the latest developments relating to the Federal Government’s FMS and encourage mutual exchange. The keen interest you show in every issue demonstrates that the FMS is, and will remain, a key element of…

Read more
Event
Wien
13.10.2026
Agentic AI Roundtable in Vienna

How does Agentic AI deliver real added value for IT and service organisations? At the Agentic AI Roundtable in Vienna, Materna, BMC Helix and other experts will discuss specific use cases, current challenges and next steps for businesses. Look…

Read more
Event
Berlin
13.10.2026 - 15.10.2026
Smart Country Convention (SCCON)

Come and meet us in Hall 27 at Stand 206 at the leading event for the digital state and public services. SCCON is a must-attend event for all stakeholders actively driving and shaping digital transformation. At our stand, you’ll find a use case…

Read more
Event
Amsterdam
06.10.2026 - 08.10.2026
Atlassian Team ’26 Europe

From 6 to 8 October 2026, Atlassian will be bringing the community together for ‘Team ’26 Europe’ in Amsterdam. Look forward to hands-on sessions covering AI, new products and features, live demos and certification opportunities. You’ll also have the…

Read more
Event
Berlin
01.10.2026
Open Insurance Dialog 4.0 (#OID4.0)

Open Insurance Dialog 4.0: FiDA, Identity and New Opportunities for Insurers

The insurance industry is facing a profound transformation: FiDA (Financial Data Access) and Open Insurance are creating new opportunities for data-driven services,…

Read more
Event
Online
30.09.2026
Webcast: ‘Understanding the mainframe, accelerating migration: How banks and insurers are harnessing hidden knowledge’

Mainframe and legacy systems contain decades of business logic – often inadequately documented and difficult to access. From 10.00 to 11.30, Materna and Nomain will demonstrate how AI-powered analyses can make business logic, dependencies and…

Read more
Event
Düsseldorf
30.09.2026
27th NRW ÖV Symposium

Artificial intelligence, digital sovereignty, the cloud, the data economy and cyber security form the framework for the digital transformation of public administration in North Rhine-Westphalia. This popular platform for information and dialogue on…

Read more
Event
Public Sector
Online
24.09.2026
Webcast: ‘From a jungle of registers to a digital ecosystem.’

How register modernisation, the ‘once-only’ principle and NOOTS are bringing about lasting change in public administration. Find out what challenges public authorities face, which strategies are proving effective, and how a future-proof register…

Read more