An AI system that touches people in the EU answers to two laws at once: the AI Act, which regulates the system, and the GDPR, which regulates the personal data flowing through it. Neither is an afterthought you bolt on before launch — both decide architecture: which model, hosted where, under which contract, with which disclosure and which human in the loop. This page sets out the rules as they stand, how this website applies them, and how we build client systems to meet them.
The AI Act applies in stages. In July 2026 the Digital Omnibus on AI moved the high-risk deadlines back and left the transparency duties where they were. Dates as published in the Official Journal:
| What applies | From |
|---|---|
| AI Act — Regulation (EU) 2024/1689 — enters into force | 2024-08-01 |
| Prohibited practices banned; duty to ensure AI literacy of staff | 2025-02-02 |
| Obligations for general-purpose AI models; penalty regime | 2025-08-02 |
| Digital Omnibus on AI — Regulation (EU) 2026/1744 — enters into force, amending the timeline | 2026-07-27 |
| Transparency duties (Art. 50): people must be told when they interact with an AI system; AI-generated or manipulated content and deepfakes must be disclosed | 2026-08-02 |
| Machine-readable marking of AI output, for generative systems already on the market before 2 August 2026 | 2026-12-02 |
| High-risk obligations for stand-alone systems (Annex III — e.g. recruitment, creditworthiness, education, access to essential services). Previously 2 August 2026 | 2027-12-02 |
| High-risk obligations for AI in products under EU product legislation (Annex I). Previously 2 August 2027 | 2028-08-02 |
| Data Omnibus: proposed changes to the GDPR and the cookie rules. Still in Parliament committee, no Council mandate — the GDPR applies unchanged | pending |
As of 2026-09-11 · Reg. (EU) 2024/1689 · Reg. (EU) 2026/1744 · EP Legislative Train
The AI Act sorts systems by risk: prohibited practices, high-risk systems, systems with transparency duties such as chatbots and generated content, and everything else, which carries no specific obligations beyond AI literacy. Most business automation sits in the last two tiers. Within a tier, the obligations follow your role — and the GDPR applies alongside, unaffected (Art. 2(7) AI Act).
This site is run by AI agents and is itself subject to both laws, so it is the first place to check our work. Each row can be verified with a browser’s developer tools or against the privacy policy.
| Requirement | How this site meets it | Basis |
|---|---|---|
| No tracking without consent | No analytics service, no advertising or tracking cookies — so no consent banner. The one cookie stores your language, and only after you press the switch. | § 25 TDDDG |
| No third parties on page load | Fonts, scripts and 3D assets come from our own server in Germany. No font service, no CDN, no social plugins. | Art. 5, 6 GDPR |
| Consent that can be proven | Newsletter by double opt-in. The confirmation link only activates on a button press, so mail scanners that open every link cannot subscribe anyone. No tracking pixels, no click tracking. | Art. 7 GDPR |
| Retention by design | Chat history deleted within 30 minutes, the chat’s IP record within one hour. Form rate limits keep truncated hashes, deleted after 26 hours. The country filter resolves IPs locally and stores nothing. | Art. 5(1)(c, e) |
| Every transfer named | Two flows leave the EU, both named with recipient and legal basis: the chat’s language model (Ollama, Inc., USA) and the model lookup on the memory calculator, which runs only when you type a model name (Hugging Face, Inc., USA). | Art. 13, 44 ff. |
| You know you are talking to an AI | The chat assistant introduces itself as an AI, not a human, in its first message. | Art. 50(1) AI Act |
| AI-generated text is labelled | Every blog post names the pipeline and models that produced it. The digest and the glossary state that AI writes them and that they publish without individual human review. | Art. 50(4) AI Act |
| No automated decisions about people | Nothing on this site takes a decision with legal or similarly significant effect on a visitor. | Art. 22 GDPR |
| A human where it matters | Every video is approved by a person before it posts. Every model call in the publishing pipelines is traced on self-hosted infrastructure. | cf. Art. 14 |
The same rules, applied before the first line of code. Compliance decided at design time costs a meeting; decided after launch, it costs a rebuild.
A closed group needed confidential messaging with an AI assistant and no third-party platform in between. The pilot has run since August 2026; the group stays anonymous here.
This page describes how we work; it is not legal advice. For regulated use cases we build together with your legal counsel and data protection officer — they own the legal assessment, we make the system match it and keep the evidence that it does.
→ Discuss your use case → Privacy policy (German) → How this company runs
The AI news that matters — in your inbox by 07:30 CET. Free, no spam.