Skip to content
Call, 0511 – 47 55 58 11

AI compliance check

We analyse the AI product you have in mind, assess it in legal terms and set out the applicable rules, the limits and the potential risks.

Deploying AI matters more and more. At the same time AI law cuts across other fields: legislation expressly addressing AI, but also more general areas such as data protection, copyright, liability and employment law.

The AI compliance checker

Which rules apply turns on what you deploy, what for, who it affects and what information goes in. The fifth question is about the approval process. The points your answers raise appear at the end.

The tool maps the deployment you have in mind onto the applicable rules and names what remains to be settled in your case. It is not legal advice, and it does not produce a result you could rely on.

Step 1 of 5

What are you deploying?

one answer

What are you deploying it for?

select all that apply

Who is affected by the deployment?

select all that apply

What information is entered into the system?

select all that apply

Is there an approval process?

one answer

What your deployment raises

No answer is selected. Go back and choose what applies to your deployment.

Art. 3(4), Art. 25(1) AI Act

Do you remain a deployer, or do you become a provider?

Anyone using a third-party system under their own responsibility is a deployer under Art. 3(4) AI Act. They become a provider under Art. 25(1) AI Act only where they put their name on a high-risk system or change the intended purpose so that a high-risk system arises.

What remains open

What the intended purpose is follows from Art. 3(12) AI Act, namely from the provider’s instructions for use, its promotional material and its technical documentation.

Provider or deployer

Art. 3(23), Art. 25(1) AI Act

Does the adaptation make you a provider in your own right?

An adaptation makes you a provider under Art. 25(1) AI Act where it substantially modifies a high-risk system or changes the intended purpose so that a high-risk system arises.

What remains open

A modification is substantial under Art. 3(23) AI Act only where it was not provided for in the original conformity assessment. Whether your adaptation reaches that threshold has to be assessed case by case.

Provider or deployer

Art. 8 et seq., Art. 50 AI Act

Which set of obligations applies to you as a provider?

For a high-risk system the AI Act requires above all risk management, technical documentation, conformity assessment and registration. Below that threshold the transparency obligations remain.

What remains open

Which class your system falls into is decided by the intended purpose.

High-risk AI

Art. 3, Art. 25 AI Act

How long does the role remain open to shaping?

The role arises on placing on the market or putting into service and cannot be defined away by contract.

What remains open

Before procurement it can still be influenced, afterwards it can only be established.

Choosing an AI tool

Annex III No. 4, Art. 6(3) AI Act

Does the deployment fall into the high-risk class?

Annex III No. 4 AI Act covers systems used for recruitment, selection and personnel decisions.

What remains open

The classification turns on how strongly the system shapes the decision.

High-risk AI

Art. 50(1) AI Act

Do the people on the other side know they are talking to a system?

Art. 50(1) AI Act requires the provider to design a system intended for direct interaction so that people are informed they are dealing with an AI system. The obligation applies regardless of the risk class and falls away where the fact is obvious.

What remains open

The addressee is the provider and not your organisation as the deployer. Whether the system you bought in actually shows the notice has to be checked before deployment.

Transparency and labelling duties

Art. 50(2), Art. 50(4) AI Act

Is generated content marked in machine-readable form?

For a deployer who publishes content, Art. 50(4) AI Act applies. Deepfakes have to be disclosed, as does AI-generated text published to inform the public on matters of public interest. The machine-readable marking under Art. 50(2) AI Act is owed by the provider instead.

What remains open

Where there is editorial control with named responsibility, the disclosure for text falls away. Whether your process meets that has to be assessed case by case.

Transparency code of practice

Annex III No. 5(b) AI Act, Art. 22 GDPR

Does the system decide about people without anyone stepping in?

Annex III No. 5(b) AI Act covers the evaluation of creditworthiness and credit scoring of natural persons, excluding the detection of financial fraud. Art. 22 GDPR sits alongside it for decisions taken without human involvement.

What remains open

Whether human involvement suffices is decided by its actual effect and not by its presence.

High-risk AI

Sec. 2(2) German Copyright Act

Who owns the generated code, and what is inside it?

No copyright arises in a machine-generated result, because there is no personal intellectual creation. Third-party material carried over remains protected.

What remains open

The degree of your own input at which the result becomes a protected work again has to be assessed case by case.

AI for developers

Art. 6(2), Annex III AI Act

What obligations does your purpose trigger?

The risk class follows from the purpose of use and not from the technology behind it. Annex III AI Act lists the high-risk cases. Below them the transparency obligations under Art. 50 AI Act remain.

What remains open

What your purpose triggers has to be assessed case by case, because it appears in none of the answers here.

High-risk AI

Sec. 87(1) No. 6 Works Constitution Act

Does the works council have to be involved?

Sec. 87(1) No. 6 Works Constitution Act covers technical devices designed to monitor conduct or performance. In the settled case law of the Federal Labour Court, a device is so designed as soon as it is objectively suited to that. No intention to monitor is required.

What remains open

Whether that suitability is present is decided by three circumstances: whether the data relate to individuals, whether the employer has access and what the data say about conduct or performance.

Works council participation and AI

Sec. 823(2) German Civil Code

Who is liable when the result causes harm?

There is no separate liability regime for AI. Attribution follows contract and tort law, and the obligations of the AI Act operate as protective statutes against those deploying it.

What remains open

Who has to answer in the individual case turns on the role and on the contract.

Liability for AI output

Art. 4(1) GDPR

Does the deployment affect people indirectly?

Under Art. 4(1) GDPR, data are personal even where a person can be identified only indirectly. Results drawn from machine and process data also feed into decisions that affect employees or customers.

What remains open

Whether your deployment reaches people indirectly has to be assessed case by case.

Data quality and discrimination

Art. 6 GDPR

Which legal basis are you relying on?

Every deployment needs its own basis under Art. 6 GDPR. Depending on the case, consent, performance of a contract or legitimate interests come into consideration.

What remains open

Which of them applies is decided by the individual use case and not by the tool.

Data protection impact assessment

Sec. 2 No. 1(b) German Trade Secrets Act

Does the protection of your secrets survive?

A trade secret is protected under the German Trade Secrets Act only for as long as it is safeguarded by reasonable steps to keep it secret. Without them the protection falls away.

Trade secrets and AI

Sec. 16(1), Sec. 44b German Copyright Act

May third-party works go into the tool?

Putting a protected work in is a reproduction under Sec. 16(1) German Copyright Act, whether the copy is transient or permanent. It is permitted either by a right of use or by a statutory exception.

What remains open

Whether the text and data mining exception covers your case has to be assessed individually. Where it does not, the right of use decides. It then has to cover the provider using the inputs for its own training as well.

Rights in inputs and outputs

no provision, a question of fact

What ends up in outside systems without a rule in place?

Without a rule, everyone at their desk decides for themselves what to put in. Draft contracts, costings and personnel data are often highly confidential and reach an outside system that way.

What remains open

What is actually being put in only shows on a stocktake.

AI policy

no provision, a question of drafting

Does your rule also cover what gets introduced next?

A policy that permits individual products by name applies to those products only. Once a further tool is introduced or an existing one gains new functions, the policy is open to that extent.

What remains open

Whether your version is open enough technologically shows at the next procurement.

AI policy

Sec. 43 GmbHG, Sec. 93 AktG

Can the arrangement be evidenced in a dispute?

A verbal arrangement is effective, but it binds only those who were part of it and can hardly be proved later. Where the management has to show it exercised care, what counts is the documentation.

What remains open

Whether the arrangement reached everyone who uses the tool only shows on asking around the departments.

AI and the liability of company management

Sec. 43 GmbHG, Sec. 93 AktG

Who is liable for a deployment nobody decided on?

Without settled responsibility each department decides for itself which tool it uses. The management has to answer for it, and its duties of care are set by Sec. 43 GmbHG and Sec. 93 AktG.

What remains open

Whether the arrangement suffices shows in whether it can be evidenced in a dispute who checked what.

AI and the liability of company management

Art. 4 AI Act

Do the people working with it have the competence they need?

Since 2 February 2025 Art. 4 AI Act has required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff, regardless of the risk class.

What remains open

What level is sufficient turns on prior knowledge, on the context of deployment and on who is affected.

AI literacy under Art. 4 AI Act

These points cannot be settled on screen. In the check we work through them against the tool you actually have.

Choose an answer to continue.

How we support your use of AI

How the check runs

  1. Step 1: Record product and deployment

    Which tool, for what purpose, with which data and for which groups of people. The planned deployment decides almost everything that follows.

  2. Step 2: Determine role and classification

    Are you provider or deployer, and which risk class does the system fall into? The set of obligations hangs on that.

  3. Step 3: Review across the fields

    Data protection, copyright, liability, employment law and trade secrets, each in relation to your actual deployment.

  4. Step 4: Overview and recommendations

    You receive a structured overview with the applicable rules, the limits and the risks, plus the next steps in an order.

An AI product under consideration?

The check belongs before procurement, where it is cheapest.

Request a check

Frequently asked questions

When is the right time for the check?

Before procurement. After it, contract, configuration and often the expectations inside the company are already fixed, and corrections cost considerably more than a check beforehand. Where the tool is already running the check still makes sense, then as a review of the existing position.

What do we get at the end?

A structured overview of the planned deployment: which rules apply, which role you take, which obligations follow and where the risks sit. From that follows what belongs in the contract with the provider and what has to be settled internally.

Is this only about the AI Act?

No. AI law cuts across other fields. Alongside legislation expressly addressing AI, more general areas apply such as data protection, copyright, liability and employment law. The check looks at them together, because in practice they arise together.

Related