EU AI Act
How ThinkLocAI supports your use of AI under the AI Act – and which obligations remain with you as the deployer.
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI law. It does not regulate the technology but the purpose: the higher the risk of an application, the stricter the obligations. On 27 July 2026 the Digital Omnibus on AI – Regulation (EU) 2026/1744 – entered into force and moved some of the deadlines. This page sets out transparently what has applied since 2 August 2026, how ThinkLocAI is classified, and which steps you as the deploying organisation have to take yourself.
What applies when
- Transparency, Art. 50since 2 Aug 2026
- Prohibitions, Art. 5since 2 Feb 2025
- Penalties and market surveillancesince 2 Aug 2026
- High-risk, Annex IIIfrom 2 Dec 2027
- High-risk, Annex Ifrom 2 Aug 2028
- Our role
- Provider
- ThinkLocAI UG develops and supplies the AI system (Art. 3(3)).
- Your role
- Deployer
- You operate the system under your own authority (Art. 3(4)).
- Risk class as delivered
- Limited risk
- Transparency obligations under Art. 50 – not a high-risk system out of the box.
- Deployment model
- 100% on-premise
- Logs, documents and models stay inside your infrastructure.
What the Digital Omnibus changed
Regulation (EU) 2026/1744 of 8 July 2026 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026 – five days before the headline deadline. It defers the obligations for high-risk systems and leaves the transparency obligations untouched.
Applies and is being enforced
Since 2 August 2026 unless stated otherwise
Transparency obligations under Art. 50
Penalty regime and national market surveillance
Commission supervision of GPAI model providers
Prohibitions under Art. 5
unchanged since 2 February 2025
AI literacy under Art. 4
softened on 27 July 2026: support the development rather than ensure a level
Two new prohibitions under Art. 5
non-consensual intimate imagery, child sexual abuse material – from 2 December 2026
Deferred
New deadlines under Regulation (EU) 2026/1744
High-risk systems under Annex III
HR, credit, education and others · from 2 August 2026 to 2 December 2027
High-risk AI as a safety component under Annex I
from 2 August 2027 to 2 August 2028
Marking under Art. 50(2)
transitional period until 2 December 2026, only for systems already on the market before 2 August 2026
Who is responsible for what?
The AI Act distributes obligations along the value chain. The key distinction is between provider and deployer. With self-hosted AI a substantial share of the responsibility sits with you – that is not a drawback, it is the price of full control.
ThinkLocAI UG – provider
Develops the platform and places it on the market under its own name.
Art. 3(3), Art. 16, Art. 50(1) and (2)
- Supply technical documentation for the system and the models in use
- Provide instructions for use covering intended purpose, limitations and known risks (Art. 13)
- Design the system so that effective human oversight is possible (Art. 14)
- Provide logging capabilities that enable traceability (Art. 12)
- Enable transparency marking for AI interaction and AI-generated content (Art. 50)
- Inform you about security-relevant changes and incidents that come to our attention
Your organisation – deployer
Uses the system under its own authority for a specific purpose.
Art. 3(4), Art. 26, Art. 27, Art. 50(3) and (4)
- Ensure use in line with the instructions for use and the defined intended purpose
- Assign human oversight to competent, trained persons (Art. 26(2))
- Ensure input data is relevant and sufficiently representative (Art. 26(4))
- Retain automatically generated logs for at least 6 months (Art. 26(6))
- Inform workers before the system is used in the workplace (Art. 26(7))
- Inform affected persons when the system contributes to decisions about them (Art. 26(11))
- Ensure a sufficient level of AI literacy among your staff (Art. 4)
Important: you can become the provider
Under Art. 25(1) you are considered the provider of a high-risk AI system yourself if you place the system on the market under your own name or trademark, make a substantial modification to it, or change its intended purpose such that it becomes high-risk within the meaning of Art. 6. In that case the full provider obligations under Chapter III Section 2 apply to you – including a risk management system, conformity assessment, CE marking and registration in the EU database. Clear high-risk scenarios with your legal department or a specialised law firm before going live.
Risk classification
The AI Act defines four levels. What matters is not the model but what you use it for. ThinkLocAI ships as a general-purpose assistance system for document analysis, research and text work.
Unacceptable risk – prohibited
Practices banned across the EU since 2 February 2025, such as social scoring, manipulative techniques or emotion recognition in the workplace. Two further prohibitions take effect on 2 December 2026.
Art. 5
High risk
Systems in sensitive areas such as recruitment, creditworthiness assessment or critical infrastructure. Extensive obligations for providers and deployers – from 2 December 2027 for Annex III systems, and from 2 August 2028 for safety components under Annex I.
Art. 6 in conjunction with Annex III
Limited risk – transparency obligations
Systems that interact directly with people or generate content. Users must be able to tell that they are talking to an AI and that content is AI-generated.
Art. 50
Minimal risk
All remaining applications, such as full-text search or spell checking. No specific obligations, voluntary codes of conduct possible.
Art. 95
What this means in practice: As delivered, ThinkLocAI is not a high-risk AI system. Whether your deployment becomes one is decided by the intended purpose you define. An assistant that summarises contracts stays in the limited-risk category. The same assistant used to pre-screen job applications falls under Annex III point 4 and therefore under the high-risk regime.
When your deployment becomes a high-risk use case
Annex III lists the areas in which AI systems are considered high-risk. Since the Digital Omnibus the associated obligations only bite on 2 December 2027 – you should still classify now, because the answer drives architecture, logging and procurement. The following areas are the most relevant for ThinkLocAI customers.
| Area under Annex III | Reference | Typical scenario in our platform |
|---|---|---|
| Employment and worker management | Annex III(4) | Screening or ranking of job applications, task allocation, performance evaluation, decisions on promotion or termination. |
| Access to essential private services | Annex III(5)(b) and (c) | Creditworthiness assessment of natural persons as well as risk assessment and pricing for life and health insurance. |
| Access to essential public services | Annex III(5)(a) and (d) | Eligibility assessment for public assistance benefits and triage in emergency and first-response services. |
| Education and vocational training | Annex III(3) | Evaluation of learning outcomes, admission decisions or monitoring of examinations. |
| Biometrics | Annex III(1) | Remote biometric identification and biometric categorisation. Not intended and not supported in ThinkLocAI. |
| Critical infrastructure | Annex III(2) | Safety components in the operation of traffic, water, gas, electricity or digital infrastructure. |
Derogation under Art. 6(3): a system in an Annex III area is not considered high-risk if it only performs a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns or deviations, or performs a purely preparatory task. The derogation does not apply as soon as the system performs profiling of natural persons. The assessment must be documented before the system is put into service.
High-risk requirements and how we support them
If your use case falls under Annex III, the requirements of Chapter III Section 2 apply – from 2 December 2027, and from 2 August 2028 for safety components under Annex I. The overview below shows what the AI Act demands and which platform capabilities support you. Meeting the obligations remains the responsibility of the accountable organisation.
Risk management system
A continuous process across the entire lifecycle to identify, evaluate and mitigate risks.
Configurable access and usage boundaries per role, documented system architecture and model parameters as the basis for your risk analysis.
Data governance
Training, validation and test data must be relevant, representative and as free of errors as possible.
Your documents and vector indexes never leave your infrastructure. User-scoped storage and traceable source attribution for every answer.
Technical documentation
Documentation in line with Annex IV, available before the system is placed on the market and kept up to date.
We provide system documentation, details on the base models in use and version records for your compliance file.
Record-keeping
Automatic recording of events over the lifetime of the system to enable traceability.
Complete audit trail across queries, document access and users – stored on your servers, with configurable retention.
Transparency and instructions for use
Operation must be sufficiently transparent; instructions for use state intended purpose, accuracy, limitations and known risks.
Instructions for use in AI Act format plus source citations with quoted evidence for every generated answer.
Human oversight
Systems must be designed so that natural persons can effectively oversee, correct and stop them.
No automated execution without confirmation, traceable sources for cross-checking, role-based approvals and the ability for your administrators to shut the system down at any time.
Accuracy, robustness and cybersecurity
An appropriate level of accuracy and resilience against errors, faults and attempts at manipulation.
Operation without external API calls, role-based access control, encrypted storage and an optional AI firewall with whitelisting and DLP inspection.
Transparency obligations under Art. 50
The Digital Omnibus did not defer these obligations. They have applied since 2 August 2026 regardless of risk class, as soon as a system interacts with people or generates content. Under Art. 99, infringements can be fined up to EUR 15 million or 3% of worldwide annual turnover.
Disclosure of AI interaction (Art. 50(1))
Users must be able to tell that they are communicating with an AI system rather than a human. In the ThinkLocAI web interface the assistant is consistently identified as AI; if you embed the platform into your own front ends via the API, you must place that notice there yourself.
Marking of AI-generated content (Art. 50(2))
Synthetic text, image, audio or video content must be marked in a machine-readable format as artificially generated or manipulated. Exported answers can carry a corresponding notice and metadata. Systems already on the market before 2 August 2026 have until 2 December 2026; systems placed on the market after that date must mark from day one.
Emotion recognition and biometric categorisation (Art. 50(3))
Deployers of such systems must inform the people exposed to them. ThinkLocAI offers neither emotion recognition nor biometric categorisation – use in the workplace would in any case be prohibited under Art. 5(1)(f).
Disclosure for published content (Art. 50(4))
Where AI-generated text is published to inform the public on matters of public interest, the AI origin must be disclosed – unless the content has undergone human review and a natural or legal person holds editorial responsibility.
Prohibited practices – our terms of use
Art. 5 has prohibited certain AI practices outright since 2 February 2025, and the Digital Omnibus adds two more from 2 December 2026. Infringements carry fines of up to EUR 35 million or 7% of worldwide annual turnover (Art. 99(3)). Using ThinkLocAI for the following purposes is contractually excluded:
- Subliminal or purposefully deceptive techniques that materially distort behaviour and can cause significant harm
- Exploitation of vulnerabilities due to age, disability or a specific social or economic situation
- Social scoring of natural persons leading to detrimental treatment in unrelated contexts
- Predicting criminal offences solely on the basis of profiling or personality traits
- Untargeted scraping of facial images from the internet or CCTV footage to build facial recognition databases
- Inferring emotions in the workplace or in education, except for medical or safety reasons
- Biometric categorisation to infer specially protected attributes such as race, political opinions, trade union membership, religion or sexual orientation
- Real-time remote biometric identification in publicly accessible spaces for law enforcement outside the narrow statutory exceptions
- New from 2 December 2026: generating or manipulating intimate imagery of a person without their freely given, specific, informed and explicit consent
- New from 2 December 2026: generating or manipulating child sexual abuse material
These restrictions form part of our licence terms. Whether a planned scenario falls under them is your assessment to make, with legal advice where in doubt. We are happy to answer questions about how our licence terms are meant.
AI literacy under Art. 4
An AI literacy obligation has applied since 2 February 2025. The Digital Omnibus softened it with effect from 27 July 2026: providers and deployers must now support the development of AI literacy among their staff rather than ensure a sufficient level. The obligation was not removed, and there is still no exemption for small organisations. Demonstrably promoting literacy meets the new standard and prepares you for the oversight duties under Art. 14.
- The obligation is yours directly. It cannot be outsourced to a provider – not to us either.
- Proportionate means differentiated: by prior knowledge, role and context of use. Someone processing cases needs something different from a person with oversight duties under Art. 14.
- Usual content covers how generative models work and where their limits are, handling hallucinations and automation bias, and the role and permission model, logging and retention periods.
- Keep records: who was trained, when, and on what.
- What we contribute: the system documentation and instructions for use for your version as a basis for your own material. The training itself and its documentation are yours.
- For our own organisation we meet Art. 4 independently of that – we use AI tools ourselves and train our staff accordingly.
Base models and general-purpose AI models
ThinkLocAI runs open language models in GGUF format inside your infrastructure. Such general-purpose AI (GPAI) models have carried their own obligations under Chapter V since 2 August 2025.
- We document which base models are shipped in which version and quantisation, including licence and provenance
- The obligations under Art. 53 – technical documentation, information for downstream providers, copyright policy and a public summary of training content – fall on the respective model providers. We pass on the model cards and licence information available to us
- Models with systemic risk under Art. 51 and 55 (training compute above 10^25 FLOP) are not deployed by default
- Fine-tuning carried out by you can make you the provider of the adapted model – we flag this during the project
- Model changes and version updates are documented under version control so that your technical documentation stays current
Your deployer checklist
Complete these steps before going into production. Steps 1 to 4 have been relevant since 2 August 2026 and apply to every deployment. Steps 5 to 10 concern high-risk use cases; those obligations bite for Annex III systems on 2 December 2027 – which is not much runway if logging and your oversight model only start then.
- 1
Determine your role
Art. 3(4), Art. 25
Establish in writing whether you remain a deployer or become a provider through your own branding, a substantial modification or a new intended purpose.
- 2
Classify your use cases
Art. 6, Annex III
Record every planned purpose separately and classify it. Also document the cases you assess as not high-risk, together with the reasoning under Art. 6(3).
- 3
Build AI literacy
Art. 4
Train everyone who uses or oversees the system and retain the evidence.
- 4
Establish transparency
Art. 50
Tell users they are interacting with AI and mark published AI-generated content. Pay particular attention to your own front ends built on our API.
- 5
Set up human oversight
Art. 26(2) and (4)
Name responsible people with sufficient competence and authority, ensure suitable input data and define when an answer has to be cross-checked.
- 6
Retain logs
Art. 26(6)
Configure retention of the automatically generated logs to at least six months, unless longer periods apply.
- 7
Meet information duties
Art. 26(7) and (11)
Inform workers and their representatives before putting the system into service in the workplace, and inform affected persons about decisions the system contributes to.
- 8
Check whether a FRIA is required
Art. 27
Public bodies, private deployers providing public services and use cases under Annex III(5)(b) and (c) must carry out a fundamental rights impact assessment before first use.
- 9
Connect it to data protection
Art. 26(9), Art. 35 GDPR
Use the results of the AI Act assessment for your data protection impact assessment and your record of processing activities.
- 10
Define reporting paths
Art. 26(5), Art. 73
Define who detects malfunctions and serious incidents, escalates them internally and reports them to the provider and the competent authority.
This checklist is an orientation aid, not legal advice and not a complete list of your obligations. What we supply is the product side of it – system documentation and instructions for use for your version: support@thinklocai.com
Regulatory timeline
The AI Act applies in stages. This overview helps you prioritise your measures.
1 August 2024
Entry into force
Regulation (EU) 2024/1689 enters into force; obligations start applying in stages.
2 February 2025
Prohibitions and AI literacy
Chapters I and II apply: prohibited practices under Art. 5 and the AI literacy obligation under Art. 4.
2 August 2025
GPAI, governance and penalties
Obligations for providers of general-purpose AI models, designation of national authorities and the penalty regime.
27 July 2026
Digital Omnibus on AI enters into force
Regulation (EU) 2026/1744 of 8 July 2026 amends the AI Act: high-risk deadlines are deferred, the Art. 4 AI literacy obligation is softened and two new prohibitions are added.
2 August 2026
NowTransparency, penalties and supervision
The transparency obligations under Art. 50 apply – not deferred. So do the penalty regime, market surveillance by national authorities and the Commission's enforcement powers over providers of GPAI models.
2 December 2026
New prohibitions and end of the marking transition
The two new prohibitions under Art. 5 take effect. The transitional period for machine-readable marking under Art. 50(2) ends for systems that were already on the market before 2 August 2026.
2 December 2027
High-risk systems under Annex III
The requirements of Chapter III Section 2 and the deployer obligations under Art. 26 apply to stand-alone high-risk systems – such as applicant screening, credit scoring or educational assessment. The original date was 2 August 2026.
2 August 2028
Product-related high-risk systems
Art. 6(1) for AI as a safety component in products under Annex I. The original date was 2 August 2027.
The deferred deadlines are preparation time, not an all-clear: classification, logging and your oversight model shape architecture decisions you are making today. The authoritative source is always the official text of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. We review this page regularly.
Serious incidents and malfunctions
Art. 73 requires providers of high-risk systems to report serious incidents to the market surveillance authorities. Under Art. 26(5) deployers must inform the provider without undue delay when they identify a risk or an incident. Please report anything unusual to us promptly:
- Report to us without undue delay after becoming aware, so that we can meet the statutory deadlines
- Standard authority reporting deadline: 15 days after becoming aware of the incident and the causal link
- Shortened deadline: 2 days for widespread infringements or serious disruption of critical infrastructure
- In the event of a death: report immediately, and no later than 10 days after the date of awareness
- Useful details: timestamp, affected function, system version, log excerpt and immediate measures taken
Reporting contact
ThinkLocAI UG (haftungsbeschränkt)
Brandweg 1, 73432 Aalen, Germany
support@thinklocai.comAI transparency on this website
We also disclose where AI is involved in our own web presence.
- This website runs no chatbot and no AI system that interacts with you. No automated decision-making about visitors takes place.
- The interactive demos on the feature pages are simulations using prepared sample data. They do not show output from a running AI model.
- The texts on this website are produced with the support of AI tools, for drafts and phrasing suggestions among other things. Every published text is reviewed by a person before release; ThinkLocAI UG (haftungsbeschränkt) holds editorial responsibility.
- That triggers the exemption in Art. 50(4) subpara. 2, which removes the disclosure duty where content is human-reviewed and a legal person carries editorial responsibility. We disclose the use of AI anyway – on every article and here.
- The machine-readable marking obligation under Art. 50(2) falls on the providers of the generation tools we use, not on us as a user.
- Details on cookies, analytics and your data subject rights are set out in our privacy policy.
Frequently asked questions
Legal notice
This page is provided for information purposes only. It does not constitute legal advice, and we do not provide legal services within the meaning of the German Legal Services Act. Classifying your use cases, assessing your obligations and producing your documentation are yours to do, with the support of a lawyer where needed. This page replaces neither an assessment of your specific use case nor advice from your legal department or a specialised law firm. The authoritative source is the official text of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, together with its future interpretation by authorities and courts. Statements about product functions refer to the respective current version; the contractually agreed scope of services prevails.
Where the binding information is
This page explains the AI Act and sets out how ThinkLocAI is classified. It is an information resource – we do not advise on the AI Act and we do not produce classifications for you. Assessing your use cases remains your task. Only the official text of the regulation is binding; the sources below are the official points of reference.
- Regulation (EU) 2024/1689 in the Official JournalThe official text, as amended by (EU) 2026/1744
- AI Act Service Desk of the European CommissionOfficial interpretation guidance, deadlines and guidelines
Questions about the product, the system documentation or the instructions for use are a different matter – ask us any time:
Request a demo