The EU AI Act, Regulation (EU) 2024/1689, sorts AI systems by risk. Prohibitions and general-purpose AI rules already apply, transparency duties have applied since 2 August 2026, and after the Digital Omnibus the high-risk rules follow from 2 December 2027. Teddy's agents build your AI register, classify each system and map the duties that fit your role.

The EU AI Act is an EU regulation and applies directly. Your duties depend on the risk of each AI system and on your role: provider, deployer, importer or distributor. The Digital Omnibus, in force since 27 July 2026, moved the high-risk dates. Here is what applies and where it lives in Teddy.
List every AI system you build or use, and whether you act as provider or deployer for it. Your role decides which duties apply.
Practices such as social scoring and manipulative techniques are banned and have been since 2 February 2025. The Digital Omnibus adds two further prohibitions from 2 December 2026. Fines reach up to €35 million or 7% of worldwide turnover.
AI in areas such as employment, credit scoring, education or critical infrastructure, and AI in regulated products. Duties apply from 2 December 2027 for Annex III and 2 August 2028 for Annex I.
Providers need risk management, data governance, technical documentation, logging, human oversight and a quality management system. Deployers follow the instructions for use, assign trained oversight and keep logs.
People must know when they interact with an AI system, and AI-generated or manipulated content must be marked. These duties have applied since 2 August 2026. Generative systems already on the market before then have until 2 December 2026 to mark their output.
Model providers keep technical documentation, publish a summary of training content and follow EU copyright law. Models with systemic risk carry further duties.
Teams buy AI tools, build features on top of models and switch on assistants in existing software. Before you can comply, you need to know which systems you have and what role you play for each.
Teddy lists AI in your own products and in the tools you buy, including new features.
The duties differ depending on whether you build an AI system or use one. Teddy sets this per system.
Teddy shows what applies today and what comes later for each system.
Legal keeps a list of AI tools in a spreadsheet, HR switched on a screening feature last month, and a product team ships a chatbot. ChatGPT can explain Annex III, but it does not know which systems you run. Teddy builds the AI register from your company model and maps the duties per system and role.
Marie · LegalIs the new CV screening feature high-risk?
Jasmin · HRIt came with the update. We just switched it on.
Leon · ProductOur chatbot launches Monday. Do we need a notice?
Martin · CFOI read the AI Act was delayed. Can we wait?
Carla · CEOWho owns our AI register?
Teddy's agents find, classify and map every AI system. Legal and the system owners decide, and a compliance engineer is there for difficult classifications.
Teddy builds the AI register from your company model and connected tools, and asks each team to confirm what they use and who owns it.
Each system gets a risk class and your role for it, with the reasoning written down, so Legal can confirm the result.
The Policy Agent drafts what is due today, such as the AI notice for your chatbot, and prepares what comes next.
As a deployer, you rely on the provider's documentation. The Evidence Agent tracks what you have, what is missing and whether logs are kept.
AI governance, security and data protection overlap. Teddy maps the EU AI Act, ISO 42001, ISO 27001 and GDPR onto one control set.
Ask in plain language whether a system is high-risk or which date applies. Teddy answers from your live AI register. For difficult cases, our compliance engineers are at your side.
Ask TeddyIs this high-risk? Are we provider or deployer? Teddy knows the AI Act and your systems.
Agents do the workRegister, classification, notices and vendor requests, each with its source.
Our team backs you upCompliance engineers help with classification questions, vendor requests and authority inquiries.
Partly. It moved the high-risk duties to 2 December 2027 for Annex III systems and to 2 August 2028 for AI in regulated products. The prohibitions, the general-purpose AI rules and the Art. 50 transparency duties were not postponed. It also added two prohibitions and a marking deadline for generative systems already on the market, both from 2 December 2026.
You are a provider if you develop an AI system, or have it developed, and place it on the market or put it into service under your name. You are a deployer if you use an AI system under your authority. Many companies are both, for different systems.
Credit scoring of natural persons is high-risk under Annex III, but AI used to detect financial fraud is explicitly excluded. Teddy records the reasoning for every classification.
ISO/IEC 42001 is a voluntary management system standard for AI. It does not replace the AI Act, but its controls cover much of the governance the Act expects, so Teddy maps both onto one control set.
Start with an AI register and a classification of your systems.
Reviewed by Sven Moritz, former CISO · October 2026
More than half of German companies have no concrete measures in place, and most organizations still have no inventory of the AI systems they run.
AI register, classification by risk and role and the duties per system and date, so you know today what December 2027 means for you.
Art. 50 also covers AI-generated images, audio and text you publish. Marketing and product teams create that content every day, often without anyone tracking it.
Classification starts with a list. An inventory, including tools teams bought on their own, is the first step and the basis for the high-risk assessment.
Your obligations depend on your role per system. If you put your name on an AI system or substantially modify it, you can take on provider duties under Art. 25.