A short, honest overview of which obligations actually apply when a company uses AI — and which don't. Meant as guidance, not a sales pitch.
The EU AI Act bans no company from using ChatGPT, Copilot & co., and simple, everyday AI use carries few mandatory product obligations. But “nothing at all” is wrong. Three duties apply across every company — and the GDPR applies anyway, from the very first record.
| Obligation | Who | When | What it means |
|---|---|---|---|
| GDPRData protection | Every company processing personal data | always | Employees who put customer or personal data into an unapproved AI tool process it with no legal basis, no data-processing agreement and no record. |
| AI Act · Art. 4AI literacy | Everyone who uses AI — no exception | since 02 Feb 2025 | Staff must have sufficient AI literacy — a basic grasp of the opportunities and risks of the tools they use. |
| AI Act · Art. 5Prohibitions | Everyone | since 02 Feb 2025 | Certain practices are banned — e.g. emotion recognition in the workplace or social scoring. |
| AI Act · Art. 50Transparency | Anyone running chatbots or publishing AI content | from 02 Aug 2026 | Label chatbots as AI; visibly mark AI-generated or AI-edited content. |
| AI Act · High-riskAnnex III | Only for a high-risk use case | from 02 Dec 2027 | Human oversight, logging, informing affected people. Triggered e.g. by AI in recruiting (see below). |
| ConfidentialityProfessional & contract law | Firms under client or contractual confidentiality | always | Putting client or customer data into an AI tool can breach confidentiality and trade-secret obligations — independent of the GDPR. |
It applies to every processing of personal data — from the moment someone copies a customer name, an email address or a contract into an AI tool. This is the duty that hits every company immediately — regardless of size, industry or AI-Act risk tier. The usual trigger isn't the regulator, but the first customer or auditor who asks for evidence.
HR & worker management. Recruiting and CV screening, but also promotion, task allocation and performance monitoring of employees.
Creditworthiness (anyone assessing credit or lending) and insurance pricing (life / health).
Support chatbots and lead qualification — only the transparency duty (Art. 50) applies here, not the high-risk regime.
02 Dec 2027 doesn't suddenly make every company high-risk. But from then on the deployer duties for high-risk AI are live — and the most common way to slip into that category is AI in HR: recruiting, promotion, task allocation or performance monitoring. The heaviest part (the conformity assessment) sits with the tool's provider; a company using AI there becomes a high-risk deployer and must then, operationally:
For most companies the question isn't “Are we regulated?” but: Do we know which AI tools our team uses — and with what data? And could we prove it if someone asked? Usually the honest answer is no. That gap — real-time visibility, policy enforcement and an audit log over AI usage — is exactly what Qadar AI closes. Not because a law forces it, but because you can't control what you can't see.
This document is for guidance and is not legal advice. Regulatory statements as of July 2026, EU AI Act as amended by the Digital Omnibus (adopted; publication in the EU Official Journal pending at the time of writing). Deadlines may change. Seek legal counsel for a binding assessment of your specific case.