Zum Inhalt springen

AI Regulation

iAs of: September 2026

Regulatory state as of September 2026. Important: Since August 2, 2026, the EU AI Act transparency obligations apply and authorities can impose fines. The stricter high-risk obligations were postponed to December 2027 by the Digital Omnibus.

Wissen

The EU AI Act: Europe's Answer to the AI Revolution

The European Union has created the world's first comprehensive law for regulating Artificial Intelligence with the EU AI Act. It has been in force since 2024 and is being fully implemented in stages until 2028. The goal is to make AI safe and trustworthy -- without hindering innovation.

The Four Risk Classes

The EU AI Act classifies AI systems into four risk classes -- the higher the risk, the stricter the rules:

1. Unacceptable Risk (Prohibited)

These AI applications are fundamentally banned in the EU:

  • Social scoring: Rating people based on social behavior (as in China)
  • Mass biometric surveillance: Real-time facial recognition in public spaces
  • Manipulation: AI systems that deliberately exploit human vulnerabilities

2. High Risk (Strictly Regulated)

Strict requirements apply to these applications, including transparency, documentation, and human oversight:

  • AI in medical diagnostics
  • AI in hiring decisions (evaluating job applications)
  • AI in credit decisions
  • AI in educational institutions (grades, admissions)

3. Limited Risk (Transparency Obligation)

These systems must clearly indicate that AI is being used:

  • Chatbots: Must disclose that you are talking to an AI
  • AI-generated content: Images, videos, and texts must be labeled as AI-generated
  • Deepfakes: Must be clearly marked as artificial

4. Minimal Risk (Few Requirements)

Most AI applications fall into this category and can be used freely:

  • Spam filters
  • AI in video games
  • Recommendation algorithms (with some restrictions)
Unacceptable RiskHigh RiskLimited RiskMinimal Risk

Tap a level to see details

Under which risk class of the EU AI Act does an AI system that automatically evaluates job applications fall?

GDPR and AI: Your Data, Your Rights

The European General Data Protection Regulation (GDPR) also applies to AI systems. In practice, this means:

  • Data minimization: AI providers may only collect data that is truly necessary
  • Right of access: You can ask which data about you is stored
  • Right to erasure: You can request the deletion of your data
  • Right to explanation: If an AI-based decision affects you (e.g., credit denial), you have the right to an explanation

iYour rights as an AI user

As a user, you have rights -- for example, to find out whether a decision was made by AI. The EU AI Act and the GDPR protect you. If you feel that an automated decision was unfair, you can request a human review.

Verstehen

Why does AI need regulation at all? Because AI systems make decisions that affect people's lives: Who gets a loan? Who gets invited to a job interview? Which news do you see in your feed? Without rules, AI could amplify existing discrimination or be misused for harmful purposes.

What right do you have under the GDPR when an AI-based decision affects you?

Anwenden

Practical Tips for Everyday Life

What does all this mean for you as an AI user?

  1. Protect personal data: Do not share sensitive information (health data, financial data) in AI chatbots
  2. Pay attention to labeling: Watch for whether content is labeled as AI-generated
  3. Know your rights: You have the right to an explanation for AI-based decisions
  4. Stay critical: Question AI results, especially for important decisions

Reflect

Regulation often sounds dry and far removed from everyday life. But the EU AI Act affects you directly: It determines which AI applications you may use, how transparent providers must be, and what rights you have. As an informed user, you can actively exercise these rights.