We analyse the AI product you have in mind, assess it in legal terms and set out the applicable rules, the limits and the potential risks.
Deploying AI matters more and more. At the same time AI law cuts across other
fields: legislation expressly addressing AI, but also more general areas such as
data protection, copyright, liability and employment law.
The AI compliance checker
Which rules apply turns on what you deploy, what for, who it affects and what
information goes in. The fifth question is about the approval process. The
points your answers raise appear at the end.
The tool maps the deployment you have in mind onto the applicable rules and names what remains to be settled in your case. It is not legal advice, and it does not produce a result you could rely on.
Step 1 of 5
What are you deploying?
one answer
What are you deploying it for?
select all that apply
Who is affected by the deployment?
select all that apply
What information is entered into the system?
select all that apply
Is there an approval process?
one answer
What your deployment raises
No answer is selected. Go back and choose what applies to your deployment.
Art. 3(4), Art. 25(1) AI Act
Do you remain a deployer, or do you become a provider?
Anyone using a third-party system under their own responsibility is a deployer under Art. 3(4) AI Act. They become a provider under Art. 25(1) AI Act only where they put their name on a high-risk system or change the intended purpose so that a high-risk system arises.
What remains open
What the intended purpose is follows from Art. 3(12) AI Act, namely from the provider’s instructions for use, its promotional material and its technical documentation.
Does the adaptation make you a provider in your own right?
An adaptation makes you a provider under Art. 25(1) AI Act where it substantially modifies a high-risk system or changes the intended purpose so that a high-risk system arises.
What remains open
A modification is substantial under Art. 3(23) AI Act only where it was not provided for in the original conformity assessment. Whether your adaptation reaches that threshold has to be assessed case by case.
Which set of obligations applies to you as a provider?
For a high-risk system the AI Act requires above all risk management, technical documentation, conformity assessment and registration. Below that threshold the transparency obligations remain.
What remains open
Which class your system falls into is decided by the intended purpose.
Do the people on the other side know they are talking to a system?
Art. 50(1) AI Act requires the provider to design a system intended for direct interaction so that people are informed they are dealing with an AI system. The obligation applies regardless of the risk class and falls away where the fact is obvious.
What remains open
The addressee is the provider and not your organisation as the deployer. Whether the system you bought in actually shows the notice has to be checked before deployment.
Is generated content marked in machine-readable form?
For a deployer who publishes content, Art. 50(4) AI Act applies. Deepfakes have to be disclosed, as does AI-generated text published to inform the public on matters of public interest. The machine-readable marking under Art. 50(2) AI Act is owed by the provider instead.
What remains open
Where there is editorial control with named responsibility, the disclosure for text falls away. Whether your process meets that has to be assessed case by case.
Does the system decide about people without anyone stepping in?
Annex III No. 5(b) AI Act covers the evaluation of creditworthiness and credit scoring of natural persons, excluding the detection of financial fraud. Art. 22 GDPR sits alongside it for decisions taken without human involvement.
What remains open
Whether human involvement suffices is decided by its actual effect and not by its presence.
Who owns the generated code, and what is inside it?
No copyright arises in a machine-generated result, because there is no personal intellectual creation. Third-party material carried over remains protected.
What remains open
The degree of your own input at which the result becomes a protected work again has to be assessed case by case.
The risk class follows from the purpose of use and not from the technology behind it. Annex III AI Act lists the high-risk cases. Below them the transparency obligations under Art. 50 AI Act remain.
What remains open
What your purpose triggers has to be assessed case by case, because it appears in none of the answers here.
Sec. 87(1) No. 6 Works Constitution Act covers technical devices designed to monitor conduct or performance. In the settled case law of the Federal Labour Court, a device is so designed as soon as it is objectively suited to that. No intention to monitor is required.
What remains open
Whether that suitability is present is decided by three circumstances: whether the data relate to individuals, whether the employer has access and what the data say about conduct or performance.
There is no separate liability regime for AI. Attribution follows contract and tort law, and the obligations of the AI Act operate as protective statutes against those deploying it.
What remains open
Who has to answer in the individual case turns on the role and on the contract.
Under Art. 4(1) GDPR, data are personal even where a person can be identified only indirectly. Results drawn from machine and process data also feed into decisions that affect employees or customers.
What remains open
Whether your deployment reaches people indirectly has to be assessed case by case.
Every deployment needs its own basis under Art. 6 GDPR. Depending on the case, consent, performance of a contract or legitimate interests come into consideration.
What remains open
Which of them applies is decided by the individual use case and not by the tool.
A trade secret is protected under the German Trade Secrets Act only for as long as it is safeguarded by reasonable steps to keep it secret. Without them the protection falls away.
Putting a protected work in is a reproduction under Sec. 16(1) German Copyright Act, whether the copy is transient or permanent. It is permitted either by a right of use or by a statutory exception.
What remains open
Whether the text and data mining exception covers your case has to be assessed individually. Where it does not, the right of use decides. It then has to cover the provider using the inputs for its own training as well.
What ends up in outside systems without a rule in place?
Without a rule, everyone at their desk decides for themselves what to put in. Draft contracts, costings and personnel data are often highly confidential and reach an outside system that way.
What remains open
What is actually being put in only shows on a stocktake.
Does your rule also cover what gets introduced next?
A policy that permits individual products by name applies to those products only. Once a further tool is introduced or an existing one gains new functions, the policy is open to that extent.
What remains open
Whether your version is open enough technologically shows at the next procurement.
A verbal arrangement is effective, but it binds only those who were part of it and can hardly be proved later. Where the management has to show it exercised care, what counts is the documentation.
What remains open
Whether the arrangement reached everyone who uses the tool only shows on asking around the departments.
Without settled responsibility each department decides for itself which tool it uses. The management has to answer for it, and its duties of care are set by Sec. 43 GmbHG and Sec. 93 AktG.
What remains open
Whether the arrangement suffices shows in whether it can be evidenced in a dispute who checked what.
Do the people working with it have the competence they need?
Since 2 February 2025 Art. 4 AI Act has required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff, regardless of the risk class.
What remains open
What level is sufficient turns on prior knowledge, on the context of deployment and on who is affected.
Before procurement. After it, contract, configuration and often the expectations inside the company are already fixed, and corrections cost considerably more than a check beforehand. Where the tool is already running the check still makes sense, then as a review of the existing position.
What do we get at the end?
A structured overview of the planned deployment: which rules apply, which role you take, which obligations follow and where the risks sit. From that follows what belongs in the contract with the provider and what has to be settled internally.
Is this only about the AI Act?
No. AI law cuts across other fields. Alongside legislation expressly addressing AI, more general areas apply such as data protection, copyright, liability and employment law. The check looks at them together, because in practice they arise together.