Text Link
1/5

Desired Service

PROJECT DETAILS

2/5

BUDGET

3/5

TIMEFRAME

4/5

CONTACT DETAILS

We use your details solely to process your enquiry. Details in our privacy policy.

5/5

THANK YOU

Our AI agent was quick: the reply to your initial enquiry is already in your inbox.

ERROR

THANK YOU!

We will get back to you shortly.

EU AI Act · operator obligations

Documentation that holds up

The transparency obligations have applied since August 2026. We classify your AI systems and deliver the technical documentation you have to keep as the operator.

Article 50 since 08/2026Technical documentationRegister across systemsNot legal advice
Art. 50
Transparency duty
in force since 2 August 2026
4
Risk classes
from minimal to prohibited
2 weeks
Per system
from access to the material
0 EUR
First classification
in the initial call
EU AI Act
The EU AI Act is Regulation (EU) 2024/1689, the European Union’s regulation on artificial intelligence. It sorts AI systems into four risk classes and attaches obligations to them. Those obligations fall mainly on the companies operating a system, not only on the ones who built it.
01 The situation

The duty sits with the operator, not the maker.

Many companies have been using AI for a while without calling it that. An assistant in customer service, a sorting step in the inbox, a drafting tool in marketing.

To a regulator each of those is an AI system with an operator. Whether the tool was bought or commissioned changes little. The questions go to the company putting it to use.

The uncomfortable part is rarely the obligation itself. It gets uncomfortable when nobody can say which systems are running and what data they work with.

52.52 % name the legal position
Of the enterprises that considered AI and dropped it, 52.52 % give lack of clarity about the legal consequences as the reason, second only to missing expertise. Documentation removes exactly that reason.
Source: Eurostat, Use of artificial intelligence in enterprises, 2024 survey, published December 2025. ec.europa.eu/eurostat
02 Classification

Four classes, and where you probably land

The regulation grades by risk. For mid sized companies the third step is almost always the relevant one.

Level 1

Unacceptable risk

Social scoring of people, targeted exploitation of vulnerabilities, real time biometric identification in public spaces. These uses are banned outright.

Prohibited
Level 2

High risk

Systems in recruitment, credit decisions, critical infrastructure or medical devices. Risk management, data quality requirements, logging and conformity assessment are added.

Extensive obligations
Level 3

Limited risk

Chatbots, assistants, knowledge agents, text generators. A notice to users and traceable documentation of the use. This covers nearly every project we build.

This is the normal case
Level 4

Minimal risk

Spell checking, spam filters, recommendations without personal data. Voluntary codes are possible, nothing is mandatory.

No specific obligations
03 Deliverables

What we hand over

A folder you can put in front of an audit without spending two weeks searching first.

01

System register

An overview of every AI system in the company, with purpose, owner, provider and risk class. The starting point for everything else.

InventoryOwners
02

Risk classification

For each system the class with reasoning, not just the claim. Checkable against the criteria in the regulation.

Article 6Annex IIIReasoning
03

Technical description

Models, providers, processing locations, data sources and interfaces. The first thing an auditor asks about.

ModelsData flowsEU servers
04

Human oversight

Who checks which outputs, where an approval sits, when the system is switched off. Described and implemented in the system.

Article 14ApprovalsShutdown
05

User notice

How users can tell they are talking to a machine. Wording, placement, and evidence that it is visible.

Article 50Notices
06

Link to GDPR

Connection to your record of processing activities, deletion concept and, where required, the data protection impact assessment.

Art. 30DPIARetention
04 Process

Four steps to the folder

We work along the risk classes. Whatever is classed high comes first.

You receive the material as editable files, not as a PDF nobody can carry forward.

Step 1

Inventory

Which systems run, who operates them, what data flows.

Step 2

Classification

Risk class per system, argued along the regulation.

Step 3

Close the gaps

Missing notices, logging or oversight get retrofitted.

Step 4

Handover

Documentation, register and instructions for keeping it current.

05 Terms

What this costs

First classification
Free of charge. In the initial call we tell you which class applies in our view.
One system
One to two weeks from access to the technical material.
Several systems
The register first, then worked through by risk class.
For our own projects
Part of the handover. Anyone who has us build gets the documentation at no extra cost.
Keeping it current
Included in support. Model changes or new data sources are carried forward.
Scope
Technical documentation and classification. Legal assessment belongs to your law firm.
06 Self check

Five questions for your company

If three of them are not answerable on the spot, a register is worth doing.

  • Which AI systems run in your company? That includes the tools departments introduced themselves.
  • Who owns each system? Not IT in general, but a person.
  • Can users tell it is a machine? And can you show that the notice is visible?
  • Where is the data processed? Provider, region and legal basis.
  • Who checks the outputs? And what happens when the system is obviously wrong?
07 Common questions

EU AI Act: common questions

What applies since 2 August 2026?+
The transparency obligations under Article 50 of the AI Act are in force. Anyone operating an AI system that interacts with people or generates content has to make that recognisable and document the use. Systems classed as high risk carry further obligations with their own deadlines.
Does this cover a simple chatbot?+
Yes. An assistant that talks to customers or staff almost always falls under limited risk. The obligation is manageable: it has to be recognisable that the answer comes from a machine, and the use has to be documented.
Who is liable, us or the supplier?+
The operator obligations sit with the company that puts the system to use, which means you. As the integrator we hand over the technical documentation with the system so that you can meet them. Who is responsible for which part is put in writing.
What belongs in the documentation?+
Purpose, risk classification with reasoning, the models and providers in use, the data sources, measures for human oversight, logging, and the notice shown to users. Plus the link to your GDPR record of processing activities.
Is this legal advice?+
No. We are a technical supplier and deliver technical documentation and a reasoned classification. Legal assessment in the individual case belongs to your legal department or a law firm. We work towards that assessment rather than replacing it.
We already run AI systems. Where do we start?+
We record the existing systems, classify them and close the gaps in the documentation. That is usually much faster than rebuilding, because the technical facts already exist and only need collecting.
How long does it take?+
For a single system we plan one to two weeks from getting access to the technical material. With several systems we start with a register and work through it by risk class.
What happens when the system changes?+
The documentation is a living document. Every model change, every new data source and every extension of purpose belongs in it. Our support agreements account for that.
08 Read on

Related topics

09 Sources

Where these figures come from

The articles and deadlines named on this page are in the regulation itself. The primary sources, for anyone who wants to read them.

EU AI Act
Regulation (EU) 2024/1689 of 13 June 2024, Official Journal of the EU. Risk classes are in Article 6 and Annex III, transparency obligations in Article 50, human oversight in Article 14. eur-lex.europa.eu
GDPR
Regulation (EU) 2016/679. The record of processing activities we tie the AI documentation into is Article 30. eur-lex.europa.eu
Supervisory authority
Kuroko Labs falls under the Bavarian Data Protection Authority. lda.bayern.de

Last checked August 2026. We revisit these figures when the regulation text or the application dates change.

Next step

Tell us what is running.

Thirty minutes are enough for a first classification. If there is nothing to do at your end, we say that too.

DEJPEN