1. Home/
  2. Services/
  3. Digital Transformation/
  4. KI Kuenstliche Intelligenz/
  5. EU AI Act En

Newsletter abonnieren

Bleiben Sie auf dem Laufenden mit den neuesten Trends und Entwicklungen

Durch Abonnieren stimmen Sie unseren Datenschutzbestimmungen zu.

A
ADVISORI FTC GmbH

Transformation. Innovation. Sicherheit.

Firmenadresse

Kaiserstraße 44

60329 Frankfurt am Main

Deutschland

Auf Karte ansehen

Kontakt

info@advisori.de+49 69 913 113-01

Mo-Fr: 9:00 - 18:00 Uhr

Unternehmen

Leistungen

Social Media

Folgen Sie uns und bleiben Sie auf dem neuesten Stand.

  • /
  • /

© 2024 ADVISORI FTC GmbH. Alle Rechte vorbehalten.

ADVISORI Logo
BlogCase StudiesAbout Us
info@advisori.de+49 69 913 113-01
Your browser does not support the video tag.
Regulatory Certainty for Your AI Systems

EU AI Act Compliance

The EU AI Act (Regulation (EU) 2024/1689) requires organizations to achieve compliance for high-risk AI systems by August 2026 — with fines of up to €35 million or 7% of annual turnover. Prohibitions on manipulative AI and social scoring have already been in effect since February 2025. ADVISORI combines AI transformation and regulatory expertise under one roof: we classify your AI systems, build your governance framework, and guide you to audit-ready compliance — on time and with a practical focus.

  • ✓Comprehensive gap analysis of your AI systems against EU AI Act requirements
  • ✓Risk classification of all AI applications across the four risk tiers
  • ✓Development of an AI governance framework for sustainable compliance
  • ✓Certified consultants with expertise in AI regulation and information security

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

  • Your strategic goals and objectives
  • Desired business outcomes and ROI
  • Steps already taken

Or contact us directly:

info@advisori.de+49 69 913 113-01

Certifications, Partners and more...

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

EU AI Act — Deadlines, Risk Classes, and Obligations at a Glance

ADVISORI in Numbers

11+

Years of Experience

120+

Employees

520+

Projects

We guide you through a proven step-by-step model from initial assessment to ongoing monitoring.

Our Approach:

AI Inventory: Recording all AI systems, models, and use cases within the organization — including purchased SaaS solutions with embedded AI and internally developed models

Risk Classification: Categorizing each system into the four tiers of the EU AI Act (unacceptable, high, limited, minimal risk) with documented justification and assignment to Annex I or III

Gap Analysis: Systematic comparison against the requirements of Art. 9–15 (risk management, data quality, documentation, logging, transparency, human oversight, robustness) — result: prioritized action plan

Governance Setup: Establishing an AI Management System with defined roles (AI Officer, Risk Owner), approval processes, documentation standards, and integration into existing ISMS and data protection management

Implementation & Conformity: Implementing technical and organizational measures, creating documentation per Annex IV, conducting the conformity assessment, and preparing the EU Declaration of Conformity

Post-Market Monitoring & Audit: Establishing an ongoing monitoring system per Art. 72, conducting regular internal audits, implementing incident reporting processes, and performing annual compliance reviews with adjustments to new guidelines and standards

Our Services

We offer you tailored solutions for your digital transformation

AI Inventory & Risk Classification

Systematic recording of all AI systems within your organization — from chatbots and scoring models to automated decision-making systems. Each system is classified into one of the four risk tiers based on the criteria of the EU AI Act. Deliverables: complete AI register, classification documentation with justification per system, prioritization matrix for high-risk systems under Annex III and Annex I. This forms the basis for all subsequent compliance measures.

    Gap Analysis & Compliance Roadmap

    Detailed comparison of your AI systems against the requirements of Regulation (EU) 2024/1689: risk management (Art. 9), data quality (Art. 10), technical documentation (Art. 11), logging obligations (Art. 12), transparency (Art. 13), human oversight (Art. 14), and accuracy/robustness (Art. 15). Deliverables: gap report per high-risk system, prioritized list of measures, timeline with milestones through August 2026, and estimated effort per measure.

      AI Governance Framework & AIMS

      Establishing an AI Management System (AIMS) with clearly defined roles, responsibilities, and processes — modeled on ISO/IEC 42001. Definition of AI approval processes, risk assessment cycles, documentation obligations, and escalation paths. Integration with existing ISMS (ISO 27001), data protection management (GDPR), and quality management. Deliverables: governance handbook, role matrix (AI Officer, Risk Manager, Data Owner), process map, KPI framework for AI compliance.

        Technical Documentation & Conformity Assessment

        Creation of complete technical documentation per Annex IV of the EU AI Act for high-risk AI systems: system description, design specifications, training and test data, performance metrics, risk management measures, and validation results. Preparation for the conformity assessment — conducted internally or by notified bodies. Deliverables: technical dossier per system, Declaration of Conformity, audit trail for regulatory inquiries.

          GPAI Compliance & Model Governance

          Specialized advisory services for providers and operators of General Purpose AI (GPAI): implementation of transparency obligations under Art. 53, creation of model cards, copyright compliance, and training data summaries. For GPAI models with systemic risk (>10^25 FLOPs): adversarial testing, red teaming, model evaluation, and incident reporting to the EU AI Office. Deliverables: GPAI compliance checklist, model card, risk assessment, incident response plan.

            Training, Audit & Ongoing Monitoring

            Practical training programs to fulfill the AI competence obligation (Art. 4): executive briefings for management and supervisory boards, workshops for specialist departments, and technical deep dives for development teams. Regular internal audits to verify compliance. Establishment of a post-market monitoring system for high-risk AI in accordance with Art. 72. Deliverables: training materials, audit reports, monitoring dashboard, annual compliance report.

              Looking for a complete overview of all our services?

              View Complete Service Overview

              Our Areas of Expertise in Digital Transformation

              Discover our specialized areas of digital transformation

              Digital Strategy

              Development and implementation of AI-supported strategies for your company's digital transformation to secure sustainable competitive advantages.

              ▼
                • Digital Vision & Roadmap
                • Business Model Innovation
                • Digital Value Chain
                • Digital Ecosystems
                • Platform Business Models
              Data Management & Data Governance

              Establish a robust data foundation as the basis for growth and efficiency through strategic data management and comprehensive data governance.

              ▼
                • Data Governance & Data Integration
                • Data Quality Management & Data Aggregation
                • Automated Reporting
                • Test Management
              Digital Maturity

              Precisely determine your digital maturity level, identify potential in industry comparison, and derive targeted measures for your successful digital future.

              ▼
                • Maturity Analysis
                • Benchmark Assessment
                • Technology Radar
                • Transformation Readiness
                • Gap Analysis
              Innovation Management

              Foster a sustainable innovation culture and systematically transform ideas into marketable digital products and services for your competitive advantage.

              ▼
                • Digital Innovation Labs
                • Design Thinking
                • Rapid Prototyping
                • Digital Products & Services
                • Innovation Portfolio
              Technology Consulting

              Maximize the value of your technology investments through expert consulting in the selection, customization, and seamless implementation of optimal software solutions for your business processes.

              ▼
                • Requirements Analysis and Software Selection
                • Customization and Integration of Standard Software
                • Planning and Implementation of Standard Software
              Data Analytics

              Transform your data into strategic capital: From data preparation through Business Intelligence to Advanced Analytics and innovative data products – for measurable business success.

              ▼
                • Data Products
                  • Data Product Development
                  • Monetization Models
                  • Data-as-a-Service
                  • API Product Development
                  • Data Mesh Architecture
                • Advanced Analytics
                  • Predictive Analytics
                  • Prescriptive Analytics
                  • Real-Time Analytics
                  • Big Data Solutions
                  • Machine Learning
                • Business Intelligence
                  • Self-Service BI
                  • Reporting & Dashboards
                  • Data Visualization
                  • KPI Management
                  • Analytics Democratization
                • Data Engineering
                  • Data Lake Setup
                  • Data Lake Implementation
                  • ETL (Extract, Transform, Load)
                  • Data Quality Management
                    • DQ Implementation
                    • DQ Audit
                    • DQ Requirements Engineering
                  • Master Data Management
                    • Master Data Management Implementation
                    • Master Data Management Health Check
              Process Automation

              Increase efficiency and reduce costs through intelligent automation and optimization of your business processes for maximum productivity.

              ▼
                • Intelligent Automation
                  • Process Mining
                  • RPA Implementation
                  • Cognitive Automation
                  • Workflow Automation
                  • Smart Operations
              AI & Artificial Intelligence

              Leverage the potential of AI safely and in regulatory compliance, from strategy through security to compliance.

              ▼
                • Securing AI Systems
                • Adversarial AI Attacks
                • Building Internal AI Competencies
                • Azure OpenAI Security
                • AI Security Consulting
                • Data Poisoning AI
                • Data Integration For AI
                • Preventing Data Leaks Through LLMs
                • Data Security For AI
                • Data Protection In AI
                • Data Protection For AI
                • Data Strategy For AI
                • Deployment Of AI Models
                • GDPR For AI
                • GDPR-Compliant AI Solutions
                • Explainable AI
                • EU AI Act
                • Explainable AI
                • Risks From AI
                • AI Use Case Identification
                • AI Consulting
                • AI Image Recognition
                • AI Chatbot
                • AI Compliance
                • AI Computer Vision
                • AI Data Preparation
                • AI Data Cleansing
                • AI Deep Learning
                • AI Ethics Consulting
                • AI Ethics And Security
                • AI For Human Resources
                • AI For Companies
                • AI Gap Assessment
                • AI Governance
                • AI In Finance

              Frequently Asked Questions about EU AI Act Compliance

              What are the deadlines under the EU AI Act?

              The EU AI Act (Regulation (EU) 2024/1689) entered into force on

              1 August

              2024 and is being applied in stages: Since

              2 February 2025, AI systems with unacceptable risk have been prohibited — including social scoring, manipulative AI, and real-time remote biometric identification. Since

              2 August 2025, transparency obligations for GPAI models apply. From

              2 August 2026, high-risk AI systems under Annex III (including biometrics, education, employment, and credit scoring) must be fully compliant. High-risk systems under Annex I (product safety) have until

              2 August 2027. For certain AI in large-scale EU IT systems, an extended deadline of

              31 December

              2030 applies.

              Which AI systems are classified as high-risk under the EU AI Act?

              Annex III of the EU AI Act defines eight high-risk areas: (1) Biometric identification and categorization of persons, (2) Management and operation of critical infrastructure (energy, transport, water, gas), (3) General and vocational education (access, assessment, exam monitoring), (4) Employment and human resources management (candidate selection, promotion, termination), (5) Access to essential services (credit scoring, insurance, social benefits), (6) Law enforcement (risk assessment, lie detection, evidence analysis), (7) Migration and border control (visa applications, asylum procedures), (8) Administration of justice and democratic processes. In addition, AI systems embedded in products with CE marking fall under Annex I.

              What obligations do providers of high-risk AI systems have?

              Providers of high-risk AI systems must meet comprehensive requirements under the EU AI Act: a risk management system covering the entire lifecycle (Art. 9), quality requirements for training, validation, and test datasets (Art. 10), complete technical documentation per Annex IV (Art. 11), automatic logging capability (Art. 12), transparency and provision of information to operators (Art. 13), measures for human oversight (Art. 14), and accuracy, robustness, and cybersecurity (Art. 15). Prior to placing on the market, a conformity assessment must be conducted and an EU Declaration of Conformity must be issued.

              What fines can be imposed for violations?

              The fines under the EU AI Act are structured in three tiers: Up to €

              35 million or 7% of global annual turnover (whichever is higher) for the use of prohibited AI practices. Up to €

              15 million or 3% of turnover for violations of obligations relating to high-risk AI systems or GPAI models. Up to €7.5 million or 1.5% of turnover for providing false or incomplete information to authorities. Proportionally lower caps apply to SMEs and start-ups. Fines are also reduced for natural persons not acting in a commercial capacity.

              What rules apply to general-purpose AI models (GPAI)?

              GPAI models such as GPT-4, Claude, or Gemini have been subject to their own obligations since August 2025: providers must create technical documentation, publish a summary of training data, comply with EU copyright law, and cooperate with downstream providers. GPAI models with systemic risk (threshold: training compute exceeding 10^

              25 FLOPs) have additional obligations: model evaluation according to the state of the art, adversarial testing and red teaming, assessment and mitigation of systemic risks, cybersecurity measures, and incident reporting to the EU AI Office. The AI Office oversees compliance directly at EU level.

              How does the EU AI Act differ from the GDPR and NIS2?

              The EU AI Act, the GDPR, and the NIS 2 Directive address different aspects with some overlap: The GDPR protects personal data — the AI Act regulates AI systems regardless of whether they process personal data. NIS 2 focuses on cybersecurity for critical infrastructure — the AI Act additionally requires robustness and accuracy specifically for AI. The Cyber Resilience Act (CRA) governs product security for connected devices and overlaps with the AI Act in the area of embedded AI. The EU Product Liability Directive extends liability to AI-related damages. Organizations need an integrated compliance strategy that covers all regulatory frameworks — which is exactly what ADVISORI provides from a single source.

              What does the AI competence obligation under Art. 4 mean?

              Since February 2025, providers and operators of AI systems must ensure that their staff possess sufficient AI competence (Art.

              4 EU AI Act). This encompasses technical knowledge, an understanding of regulatory requirements, and awareness of associated risks. The obligation applies regardless of risk class — including organizations that only deploy AI systems with minimal risk. In practice, this means: training programs for employees who develop, operate, or make decisions about AI. Documentation of qualification measures. ADVISORI offers tailored training formats for this purpose — from 90-minute board briefings to multi-day hands-on workshops for development teams.

              Why is ADVISORI the right partner for EU AI Act compliance?

              ADVISORI is one of the few consulting firms that combines AI transformation and regulatory expertise under one roof. As an ISO 27001/9001/14001-certified organization, we bring proven expertise in information security, risk management, and compliance. Our consultants are familiar with the interfaces to GDPR, NIS2, DORA, and CRA and develop integrated compliance strategies. With our own multi-agent AI platform Synthara, we not only implement AI from a regulatory perspective but also use it operationally — giving us firsthand knowledge of requirements from both the provider and operator perspective. As a Microsoft, AWS, and Google Cloud partner, we cover all relevant AI technology stacks. This sets us apart from pure legal advisory firms or IT service providers without hands-on AI experience.

              Success Stories

              Discover how we support companies in their digital transformation

              Generative KI in der Fertigung

              Bosch

              KI-Prozessoptimierung für bessere Produktionseffizienz

              Fallstudie
              BOSCH KI-Prozessoptimierung für bessere Produktionseffizienz

              Ergebnisse

              Reduzierung der Implementierungszeit von AI-Anwendungen auf wenige Wochen
              Verbesserung der Produktqualität durch frühzeitige Fehlererkennung
              Steigerung der Effizienz in der Fertigung durch reduzierte Downtime

              AI Automatisierung in der Produktion

              Festo

              Intelligente Vernetzung für zukunftsfähige Produktionssysteme

              Fallstudie
              FESTO AI Case Study

              Ergebnisse

              Verbesserung der Produktionsgeschwindigkeit und Flexibilität
              Reduzierung der Herstellungskosten durch effizientere Ressourcennutzung
              Erhöhung der Kundenzufriedenheit durch personalisierte Produkte

              KI-gestützte Fertigungsoptimierung

              Siemens

              Smarte Fertigungslösungen für maximale Wertschöpfung

              Fallstudie
              Case study image for KI-gestützte Fertigungsoptimierung

              Ergebnisse

              Erhebliche Steigerung der Produktionsleistung
              Reduzierung von Downtime und Produktionskosten
              Verbesserung der Nachhaltigkeit durch effizientere Ressourcennutzung

              Digitalisierung im Stahlhandel

              Klöckner & Co

              Digitalisierung im Stahlhandel

              Fallstudie
              Digitalisierung im Stahlhandel - Klöckner & Co

              Ergebnisse

              Über 2 Milliarden Euro Umsatz jährlich über digitale Kanäle
              Ziel, bis 2022 60% des Umsatzes online zu erzielen
              Verbesserung der Kundenzufriedenheit durch automatisierte Prozesse

              Let's

              Work Together!

              Is your organization ready for the next step into the digital future? Contact us for a personal consultation.

              Your strategic success starts here

              Our clients trust our expertise in digital transformation, compliance, and risk management

              Ready for the next step?

              Schedule a strategic consultation with our experts now

              30 Minutes • Non-binding • Immediately available

              For optimal preparation of your strategy session:

              Your strategic goals and challenges
              Desired business outcomes and ROI expectations
              Current compliance and risk situation
              Stakeholders and decision-makers in the project

              Prefer direct contact?

              Direct hotline for decision-makers

              Strategic inquiries via email

              Detailed Project Inquiry

              For complex inquiries or if you want to provide specific information in advance

              Latest Insights on EU AI Act Compliance

              Discover our latest articles, expert knowledge and practical guides about EU AI Act Compliance

              EZB-Leitfaden für interne Modelle: Strategische Orientierung für Banken in der neuen Regulierungslandschaft
              Risikomanagement

              EZB-Leitfaden für interne Modelle: Strategische Orientierung für Banken in der neuen Regulierungslandschaft

              July 29, 2025
              8 Min.

              Die Juli-2025-Revision des EZB-Leitfadens verpflichtet Banken, interne Modelle strategisch neu auszurichten. Kernpunkte: 1) Künstliche Intelligenz und Machine Learning sind zulässig, jedoch nur in erklärbarer Form und unter strenger Governance. 2) Das Top-Management trägt explizit die Verantwortung für Qualität und Compliance aller Modelle. 3) CRR3-Vorgaben und Klimarisiken müssen proaktiv in Kredit-, Markt- und Kontrahentenrisikomodelle integriert werden. 4) Genehmigte Modelländerungen sind innerhalb von drei Monaten umzusetzen, was agile IT-Architekturen und automatisierte Validierungsprozesse erfordert. Institute, die frühzeitig Explainable-AI-Kompetenzen, robuste ESG-Datenbanken und modulare Systeme aufbauen, verwandeln die verschärften Anforderungen in einen nachhaltigen Wettbewerbsvorteil.

              Andreas Krekel
              Read
               Erklärbare KI (XAI) in der Softwarearchitektur: Von der Black Box zum strategischen Werkzeug
              Digitale Transformation

              Erklärbare KI (XAI) in der Softwarearchitektur: Von der Black Box zum strategischen Werkzeug

              June 24, 2025
              5 Min.

              Verwandeln Sie Ihre KI von einer undurchsichtigen Black Box in einen nachvollziehbaren, vertrauenswürdigen Geschäftspartner.

              Arosan Annalingam
              Read
              KI Softwarearchitektur: Risiken beherrschen & strategische Vorteile sichern
              Digitale Transformation

              KI Softwarearchitektur: Risiken beherrschen & strategische Vorteile sichern

              June 19, 2025
              5 Min.

              KI verändert Softwarearchitektur fundamental. Erkennen Sie die Risiken von „Blackbox“-Verhalten bis zu versteckten Kosten und lernen Sie, wie Sie durchdachte Architekturen für robuste KI-Systeme gestalten. Sichern Sie jetzt Ihre Zukunftsfähigkeit.

              Arosan Annalingam
              Read
              ChatGPT-Ausfall: Warum deutsche Unternehmen eigene KI-Lösungen brauchen
              Künstliche Intelligenz - KI

              ChatGPT-Ausfall: Warum deutsche Unternehmen eigene KI-Lösungen brauchen

              June 10, 2025
              5 Min.

              Der siebenstündige ChatGPT-Ausfall vom 10. Juni 2025 zeigt deutschen Unternehmen die kritischen Risiken zentralisierter KI-Dienste auf.

              Phil Hansen
              Read
              KI-Risiko: Copilot, ChatGPT & Co. -  Wenn externe KI durch MCP's zu interner Spionage wird
              Künstliche Intelligenz - KI

              KI-Risiko: Copilot, ChatGPT & Co. - Wenn externe KI durch MCP's zu interner Spionage wird

              June 9, 2025
              5 Min.

              KI Risiken wie Prompt Injection & Tool Poisoning bedrohen Ihr Unternehmen. Schützen Sie geistiges Eigentum mit MCP-Sicherheitsarchitektur. Praxisleitfaden zur Anwendung im eignen Unternehmen.

              Boris Friedrich
              Read
              Live Chatbot Hacking - Wie Microsoft, OpenAI, Google & Co zum unsichtbaren Risiko für Ihr geistiges Eigentum werden
              Informationssicherheit

              Live Chatbot Hacking - Wie Microsoft, OpenAI, Google & Co zum unsichtbaren Risiko für Ihr geistiges Eigentum werden

              June 8, 2025
              7 Min.

              Live-Hacking-Demonstrationen zeigen schockierend einfach: KI-Assistenten lassen sich mit harmlosen Nachrichten manipulieren.

              Boris Friedrich
              Read
              View All Articles