Regulation (EU) 2024/1689, amended by (EU) 2026/1744

EU AI Act

How ThinkLocAI supports your use of AI under the AI Act – and which obligations remain with you as the deployer.

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI law. It does not regulate the technology but the purpose: the higher the risk of an application, the stricter the obligations. On 27 July 2026 the Digital Omnibus on AI – Regulation (EU) 2026/1744 – entered into force and moved some of the deadlines. This page sets out transparently what has applied since 2 August 2026, how ThinkLocAI is classified, and which steps you as the deploying organisation have to take yourself.

Page last reviewed: 2 August 2026Regulation text

What applies when

  • Transparency, Art. 50since 2 Aug 2026
  • Prohibitions, Art. 5since 2 Feb 2025
  • Penalties and market surveillancesince 2 Aug 2026
  • High-risk, Annex IIIfrom 2 Dec 2027
  • High-risk, Annex Ifrom 2 Aug 2028
Our role
Provider
ThinkLocAI UG develops and supplies the AI system (Art. 3(3)).
Your role
Deployer
You operate the system under your own authority (Art. 3(4)).
Risk class as delivered
Limited risk
Transparency obligations under Art. 50 – not a high-risk system out of the box.
Deployment model
100% on-premise
Logs, documents and models stay inside your infrastructure.
01(EU) 2026/1744

What the Digital Omnibus changed

Regulation (EU) 2026/1744 of 8 July 2026 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026 – five days before the headline deadline. It defers the obligations for high-risk systems and leaves the transparency obligations untouched.

Applies and is being enforced

Since 2 August 2026 unless stated otherwise

  • Transparency obligations under Art. 50

  • Penalty regime and national market surveillance

  • Commission supervision of GPAI model providers

  • Prohibitions under Art. 5

    unchanged since 2 February 2025

  • AI literacy under Art. 4

    softened on 27 July 2026: support the development rather than ensure a level

  • Two new prohibitions under Art. 5

    non-consensual intimate imagery, child sexual abuse material – from 2 December 2026

Deferred

New deadlines under Regulation (EU) 2026/1744

  • High-risk systems under Annex III

    HR, credit, education and others · from 2 August 2026 to 2 December 2027

  • High-risk AI as a safety component under Annex I

    from 2 August 2027 to 2 August 2028

  • Marking under Art. 50(2)

    transitional period until 2 December 2026, only for systems already on the market before 2 August 2026

02Art. 3, 16, 25, 26

Who is responsible for what?

The AI Act distributes obligations along the value chain. The key distinction is between provider and deployer. With self-hosted AI a substantial share of the responsibility sits with you – that is not a drawback, it is the price of full control.

Provider

ThinkLocAI UG – provider

Develops the platform and places it on the market under its own name.

Art. 3(3), Art. 16, Art. 50(1) and (2)

  • Supply technical documentation for the system and the models in use
  • Provide instructions for use covering intended purpose, limitations and known risks (Art. 13)
  • Design the system so that effective human oversight is possible (Art. 14)
  • Provide logging capabilities that enable traceability (Art. 12)
  • Enable transparency marking for AI interaction and AI-generated content (Art. 50)
  • Inform you about security-relevant changes and incidents that come to our attention
Deployer

Your organisation – deployer

Uses the system under its own authority for a specific purpose.

Art. 3(4), Art. 26, Art. 27, Art. 50(3) and (4)

  • Ensure use in line with the instructions for use and the defined intended purpose
  • Assign human oversight to competent, trained persons (Art. 26(2))
  • Ensure input data is relevant and sufficiently representative (Art. 26(4))
  • Retain automatically generated logs for at least 6 months (Art. 26(6))
  • Inform workers before the system is used in the workplace (Art. 26(7))
  • Inform affected persons when the system contributes to decisions about them (Art. 26(11))
  • Ensure a sufficient level of AI literacy among your staff (Art. 4)

Important: you can become the provider

Under Art. 25(1) you are considered the provider of a high-risk AI system yourself if you place the system on the market under your own name or trademark, make a substantial modification to it, or change its intended purpose such that it becomes high-risk within the meaning of Art. 6. In that case the full provider obligations under Chapter III Section 2 apply to you – including a risk management system, conformity assessment, CE marking and registration in the EU database. Clear high-risk scenarios with your legal department or a specialised law firm before going live.

03Art. 6, Annex III

Risk classification

The AI Act defines four levels. What matters is not the model but what you use it for. ThinkLocAI ships as a general-purpose assistance system for document analysis, research and text work.

Unacceptable risk – prohibited

Practices banned across the EU since 2 February 2025, such as social scoring, manipulative techniques or emotion recognition in the workplace. Two further prohibitions take effect on 2 December 2026.

Art. 5

Contractually excluded

High risk

Systems in sensitive areas such as recruitment, creditworthiness assessment or critical infrastructure. Extensive obligations for providers and deployers – from 2 December 2027 for Annex III systems, and from 2 August 2028 for safety components under Annex I.

Art. 6 in conjunction with Annex III

Only via your intended purpose

Limited risk – transparency obligations

Systems that interact directly with people or generate content. Users must be able to tell that they are talking to an AI and that content is AI-generated.

Art. 50

ThinkLocAI as delivered

Minimal risk

All remaining applications, such as full-text search or spell checking. No specific obligations, voluntary codes of conduct possible.

Art. 95

Individual functions only

What this means in practice: As delivered, ThinkLocAI is not a high-risk AI system. Whether your deployment becomes one is decided by the intended purpose you define. An assistant that summarises contracts stays in the limited-risk category. The same assistant used to pre-screen job applications falls under Annex III point 4 and therefore under the high-risk regime.

When your deployment becomes a high-risk use case

Annex III lists the areas in which AI systems are considered high-risk. Since the Digital Omnibus the associated obligations only bite on 2 December 2027 – you should still classify now, because the answer drives architecture, logging and procurement. The following areas are the most relevant for ThinkLocAI customers.

Area under Annex IIIReferenceTypical scenario in our platform
Employment and worker managementAnnex III(4)Screening or ranking of job applications, task allocation, performance evaluation, decisions on promotion or termination.
Access to essential private servicesAnnex III(5)(b) and (c)Creditworthiness assessment of natural persons as well as risk assessment and pricing for life and health insurance.
Access to essential public servicesAnnex III(5)(a) and (d)Eligibility assessment for public assistance benefits and triage in emergency and first-response services.
Education and vocational trainingAnnex III(3)Evaluation of learning outcomes, admission decisions or monitoring of examinations.
BiometricsAnnex III(1)Remote biometric identification and biometric categorisation. Not intended and not supported in ThinkLocAI.
Critical infrastructureAnnex III(2)Safety components in the operation of traffic, water, gas, electricity or digital infrastructure.

Derogation under Art. 6(3): a system in an Annex III area is not considered high-risk if it only performs a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns or deviations, or performs a purely preparatory task. The derogation does not apply as soon as the system performs profiling of natural persons. The assessment must be documented before the system is put into service.

04Art. 9 – 15

High-risk requirements and how we support them

If your use case falls under Annex III, the requirements of Chapter III Section 2 apply – from 2 December 2027, and from 2 August 2028 for safety components under Annex I. The overview below shows what the AI Act demands and which platform capabilities support you. Meeting the obligations remains the responsibility of the accountable organisation.

Art. 9

Risk management system

A continuous process across the entire lifecycle to identify, evaluate and mitigate risks.

Configurable access and usage boundaries per role, documented system architecture and model parameters as the basis for your risk analysis.

Art. 10

Data governance

Training, validation and test data must be relevant, representative and as free of errors as possible.

Your documents and vector indexes never leave your infrastructure. User-scoped storage and traceable source attribution for every answer.

Art. 11

Technical documentation

Documentation in line with Annex IV, available before the system is placed on the market and kept up to date.

We provide system documentation, details on the base models in use and version records for your compliance file.

Art. 12

Record-keeping

Automatic recording of events over the lifetime of the system to enable traceability.

Complete audit trail across queries, document access and users – stored on your servers, with configurable retention.

Art. 13

Transparency and instructions for use

Operation must be sufficiently transparent; instructions for use state intended purpose, accuracy, limitations and known risks.

Instructions for use in AI Act format plus source citations with quoted evidence for every generated answer.

Art. 14

Human oversight

Systems must be designed so that natural persons can effectively oversee, correct and stop them.

No automated execution without confirmation, traceable sources for cross-checking, role-based approvals and the ability for your administrators to shut the system down at any time.

Art. 15

Accuracy, robustness and cybersecurity

An appropriate level of accuracy and resilience against errors, faults and attempts at manipulation.

Operation without external API calls, role-based access control, encrypted storage and an optional AI firewall with whitelisting and DLP inspection.

05Art. 50

Transparency obligations under Art. 50

The Digital Omnibus did not defer these obligations. They have applied since 2 August 2026 regardless of risk class, as soon as a system interacts with people or generates content. Under Art. 99, infringements can be fined up to EUR 15 million or 3% of worldwide annual turnover.

01

Disclosure of AI interaction (Art. 50(1))

Users must be able to tell that they are communicating with an AI system rather than a human. In the ThinkLocAI web interface the assistant is consistently identified as AI; if you embed the platform into your own front ends via the API, you must place that notice there yourself.

02

Marking of AI-generated content (Art. 50(2))

Synthetic text, image, audio or video content must be marked in a machine-readable format as artificially generated or manipulated. Exported answers can carry a corresponding notice and metadata. Systems already on the market before 2 August 2026 have until 2 December 2026; systems placed on the market after that date must mark from day one.

03

Emotion recognition and biometric categorisation (Art. 50(3))

Deployers of such systems must inform the people exposed to them. ThinkLocAI offers neither emotion recognition nor biometric categorisation – use in the workplace would in any case be prohibited under Art. 5(1)(f).

04

Disclosure for published content (Art. 50(4))

Where AI-generated text is published to inform the public on matters of public interest, the AI origin must be disclosed – unless the content has undergone human review and a natural or legal person holds editorial responsibility.

06Art. 5

Prohibited practices – our terms of use

Art. 5 has prohibited certain AI practices outright since 2 February 2025, and the Digital Omnibus adds two more from 2 December 2026. Infringements carry fines of up to EUR 35 million or 7% of worldwide annual turnover (Art. 99(3)). Using ThinkLocAI for the following purposes is contractually excluded:

  • Subliminal or purposefully deceptive techniques that materially distort behaviour and can cause significant harm
  • Exploitation of vulnerabilities due to age, disability or a specific social or economic situation
  • Social scoring of natural persons leading to detrimental treatment in unrelated contexts
  • Predicting criminal offences solely on the basis of profiling or personality traits
  • Untargeted scraping of facial images from the internet or CCTV footage to build facial recognition databases
  • Inferring emotions in the workplace or in education, except for medical or safety reasons
  • Biometric categorisation to infer specially protected attributes such as race, political opinions, trade union membership, religion or sexual orientation
  • Real-time remote biometric identification in publicly accessible spaces for law enforcement outside the narrow statutory exceptions
  • New from 2 December 2026: generating or manipulating intimate imagery of a person without their freely given, specific, informed and explicit consent
  • New from 2 December 2026: generating or manipulating child sexual abuse material

These restrictions form part of our licence terms. Whether a planned scenario falls under them is your assessment to make, with legal advice where in doubt. We are happy to answer questions about how our licence terms are meant.

07Art. 4, Chapter V

AI literacy under Art. 4

An AI literacy obligation has applied since 2 February 2025. The Digital Omnibus softened it with effect from 27 July 2026: providers and deployers must now support the development of AI literacy among their staff rather than ensure a sufficient level. The obligation was not removed, and there is still no exemption for small organisations. Demonstrably promoting literacy meets the new standard and prepares you for the oversight duties under Art. 14.

  • The obligation is yours directly. It cannot be outsourced to a provider – not to us either.
  • Proportionate means differentiated: by prior knowledge, role and context of use. Someone processing cases needs something different from a person with oversight duties under Art. 14.
  • Usual content covers how generative models work and where their limits are, handling hallucinations and automation bias, and the role and permission model, logging and retention periods.
  • Keep records: who was trained, when, and on what.
  • What we contribute: the system documentation and instructions for use for your version as a basis for your own material. The training itself and its documentation are yours.
  • For our own organisation we meet Art. 4 independently of that – we use AI tools ourselves and train our staff accordingly.

Base models and general-purpose AI models

ThinkLocAI runs open language models in GGUF format inside your infrastructure. Such general-purpose AI (GPAI) models have carried their own obligations under Chapter V since 2 August 2025.

  • We document which base models are shipped in which version and quantisation, including licence and provenance
  • The obligations under Art. 53 – technical documentation, information for downstream providers, copyright policy and a public summary of training content – fall on the respective model providers. We pass on the model cards and licence information available to us
  • Models with systemic risk under Art. 51 and 55 (training compute above 10^25 FLOP) are not deployed by default
  • Fine-tuning carried out by you can make you the provider of the adapted model – we flag this during the project
  • Model changes and version updates are documented under version control so that your technical documentation stays current
08Art. 26, 27

Your deployer checklist

Complete these steps before going into production. Steps 1 to 4 have been relevant since 2 August 2026 and apply to every deployment. Steps 5 to 10 concern high-risk use cases; those obligations bite for Annex III systems on 2 December 2027 – which is not much runway if logging and your oversight model only start then.

  1. 1

    Determine your role

    Art. 3(4), Art. 25

    Establish in writing whether you remain a deployer or become a provider through your own branding, a substantial modification or a new intended purpose.

  2. 2

    Classify your use cases

    Art. 6, Annex III

    Record every planned purpose separately and classify it. Also document the cases you assess as not high-risk, together with the reasoning under Art. 6(3).

  3. 3

    Build AI literacy

    Art. 4

    Train everyone who uses or oversees the system and retain the evidence.

  4. 4

    Establish transparency

    Art. 50

    Tell users they are interacting with AI and mark published AI-generated content. Pay particular attention to your own front ends built on our API.

  5. 5

    Set up human oversight

    Art. 26(2) and (4)

    Name responsible people with sufficient competence and authority, ensure suitable input data and define when an answer has to be cross-checked.

  6. 6

    Retain logs

    Art. 26(6)

    Configure retention of the automatically generated logs to at least six months, unless longer periods apply.

  7. 7

    Meet information duties

    Art. 26(7) and (11)

    Inform workers and their representatives before putting the system into service in the workplace, and inform affected persons about decisions the system contributes to.

  8. 8

    Check whether a FRIA is required

    Art. 27

    Public bodies, private deployers providing public services and use cases under Annex III(5)(b) and (c) must carry out a fundamental rights impact assessment before first use.

  9. 9

    Connect it to data protection

    Art. 26(9), Art. 35 GDPR

    Use the results of the AI Act assessment for your data protection impact assessment and your record of processing activities.

  10. 10

    Define reporting paths

    Art. 26(5), Art. 73

    Define who detects malfunctions and serious incidents, escalates them internally and reports them to the provider and the competent authority.

This checklist is an orientation aid, not legal advice and not a complete list of your obligations. What we supply is the product side of it – system documentation and instructions for use for your version: support@thinklocai.com

Regulatory timeline

The AI Act applies in stages. This overview helps you prioritise your measures.

  1. 1 August 2024

    Entry into force

    Regulation (EU) 2024/1689 enters into force; obligations start applying in stages.

  2. 2 February 2025

    Prohibitions and AI literacy

    Chapters I and II apply: prohibited practices under Art. 5 and the AI literacy obligation under Art. 4.

  3. 2 August 2025

    GPAI, governance and penalties

    Obligations for providers of general-purpose AI models, designation of national authorities and the penalty regime.

  4. 27 July 2026

    Digital Omnibus on AI enters into force

    Regulation (EU) 2026/1744 of 8 July 2026 amends the AI Act: high-risk deadlines are deferred, the Art. 4 AI literacy obligation is softened and two new prohibitions are added.

  5. 2 August 2026

    Now

    Transparency, penalties and supervision

    The transparency obligations under Art. 50 apply – not deferred. So do the penalty regime, market surveillance by national authorities and the Commission's enforcement powers over providers of GPAI models.

  6. 2 December 2026

    New prohibitions and end of the marking transition

    The two new prohibitions under Art. 5 take effect. The transitional period for machine-readable marking under Art. 50(2) ends for systems that were already on the market before 2 August 2026.

  7. 2 December 2027

    High-risk systems under Annex III

    The requirements of Chapter III Section 2 and the deployer obligations under Art. 26 apply to stand-alone high-risk systems – such as applicant screening, credit scoring or educational assessment. The original date was 2 August 2026.

  8. 2 August 2028

    Product-related high-risk systems

    Art. 6(1) for AI as a safety component in products under Annex I. The original date was 2 August 2027.

The deferred deadlines are preparation time, not an all-clear: classification, logging and your oversight model shape architecture decisions you are making today. The authoritative source is always the official text of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. We review this page regularly.

09Art. 73, Art. 26(5)

Serious incidents and malfunctions

Art. 73 requires providers of high-risk systems to report serious incidents to the market surveillance authorities. Under Art. 26(5) deployers must inform the provider without undue delay when they identify a risk or an incident. Please report anything unusual to us promptly:

  • Report to us without undue delay after becoming aware, so that we can meet the statutory deadlines
  • Standard authority reporting deadline: 15 days after becoming aware of the incident and the causal link
  • Shortened deadline: 2 days for widespread infringements or serious disruption of critical infrastructure
  • In the event of a death: report immediately, and no later than 10 days after the date of awareness
  • Useful details: timestamp, affected function, system version, log excerpt and immediate measures taken

Reporting contact

ThinkLocAI UG (haftungsbeschränkt)

Brandweg 1, 73432 Aalen, Germany

support@thinklocai.com

AI transparency on this website

We also disclose where AI is involved in our own web presence.

  • This website runs no chatbot and no AI system that interacts with you. No automated decision-making about visitors takes place.
  • The interactive demos on the feature pages are simulations using prepared sample data. They do not show output from a running AI model.
  • The texts on this website are produced with the support of AI tools, for drafts and phrasing suggestions among other things. Every published text is reviewed by a person before release; ThinkLocAI UG (haftungsbeschränkt) holds editorial responsibility.
  • That triggers the exemption in Art. 50(4) subpara. 2, which removes the disclosure duty where content is human-reviewed and a legal person carries editorial responsibility. We disclose the use of AI anyway – on every article and here.
  • The machine-readable marking obligation under Art. 50(2) falls on the providers of the generation tools we use, not on us as a user.
  • Details on cookies, analytics and your data subject rights are set out in our privacy policy.

Frequently asked questions

Legal notice

This page is provided for information purposes only. It does not constitute legal advice, and we do not provide legal services within the meaning of the German Legal Services Act. Classifying your use cases, assessing your obligations and producing your documentation are yours to do, with the support of a lawyer where needed. This page replaces neither an assessment of your specific use case nor advice from your legal department or a specialised law firm. The authoritative source is the official text of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, together with its future interpretation by authorities and courts. Statements about product functions refer to the respective current version; the contractually agreed scope of services prevails.

Where the binding information is

This page explains the AI Act and sets out how ThinkLocAI is classified. It is an information resource – we do not advise on the AI Act and we do not produce classifications for you. Assessing your use cases remains your task. Only the official text of the regulation is binding; the sources below are the official points of reference.

Questions about the product, the system documentation or the instructions for use are a different matter – ask us any time:

Request a demo