Blog

Regulatory analysis of the AI Act and the GDPR for SMEs

AI literacy: what Article 4 requires now that the Omnibus rewrote it

Article 4 required measures to ensure a sufficient level of literacy. The Digital Omnibus replaced it: now the measures must support its development, and the article itself denies that anyone's specific level has to be guaranteed.

Private healthcare: the sector where high risk really is in the core activity — and through two different routes

In most companies, high risk sits in Human Resources. Not in healthcare: there it sits in the consulting room. But it arrives by two paths that get confused — Annex I with its two conditions, and Annex III for emergency triage.

AI regulatory sandboxes slipped to 2027, and almost nobody has covered it

The AI Act requires every Member State to have an AI regulatory sandbox operational. The date was August 2026; the Digital Omnibus moved it to August 2027. It is an obligation of the States, not of companies.

Annex III: the high-risk date is December 2027, not August 2026

Half the internet places Annex III's high-risk obligations in August 2026. They were there, and that's exactly why the mistake is so common: the Digital Omnibus moved that date to 2 December 2027.

When you stop being the deployer and become the provider: the three scenarios under Article 25

This whole series explains obligations that don't fall on you because they belong to the provider. Article 25 says when they do — and there are three closed-list circumstances, not a grey area.

Serious incidents: the provider reports, but the clock starts when you find out

Article 73 requires the provider to report serious incidents. Its deadlines — fifteen days, ten or two depending on the case — are counted from when the provider or the deployer becomes aware. Your delay eats into someone else's deadline.

Post-market monitoring: the system belongs to the provider, the information is yours

Article 72 requires the provider to establish a post-market monitoring system. The deploying company doesn't build it, but Article 26(5) requires it to monitor operation, inform in accordance with that article and, where applicable, suspend use.

What an authority can ask you: the article that usually gets cited belongs to the provider, not you

Article 21 — cooperation with the authorities — binds providers, and sets no deadline. What reaches the deployer is Article 26(12). The difference changes what can be demanded of you, and what can't.

Annex IV is not an obligation: it's the index of someone else's document

Annex IV turns up on task lists for companies deploying AI. It imposes nothing on anyone: it specifies what the technical documentation Article 11 requires from the provider must contain.

Minimal risk or high risk: what each one requires, article by article

The difference between the two classifications isn't one of degree. A minimal-risk system is resolved with Article 4. A high-risk one opens the whole of Article 26, and none of its obligations is met on its own.