Compliance & Regulation

Regulation is not a project. It is an operating condition.

Articles on the EU AI Act, the GDPR, AI governance, and Germany’s implementing act.

The EU AI Act, the GDPR, and the German implementing act do not ask for one push. They ask for evidence that holds at any moment: which systems are in use, in which risk class, on which data, and under whose responsibility. The articles here sort the obligations by deadline and say what each one means in practice, including shadow AI, the usage nobody registered.

A company does not become auditable through a policy. It becomes auditable through traces: decisions that can be followed, owners with names, and documented data lineage. Those traces are produced in daily operations or not at all. Which is why regulation belongs in the architecture rather than in a binder.

What the EU AI Act actually requires, ordered by deadline.

See the EU AI Act page

Articles in this topic 7 articles

7 articles

  • Compliance & Regulation

    GDPR and AI: privacy-compliant AI in companies

    57 percent of companies see data protection as an AI brake. Learn how GDPR-compliant AI deployment succeeds in 2026—with a practical checklist and concrete action steps.

  • Compliance & Regulation

    EU AI Act: what midsize companies need to do now

    A practical guide for midsize companies to implementing the EU AI Act: from risk classification and AI literacy under Article 4 to a 90-day plan, with a checklist, an industry example, and concrete recommendations.

  • Compliance & Regulation

    Running MCP servers in compliance with the GDPR

    86 percent of MCP deployments run with full system privileges. Learn how to operate MCP servers in compliance with GDPR and secure your AI integration.

  • Compliance & Regulation

    Shadow AI: the security risk of uncontrolled AI use

    76 percent of data leaders confirm: governance has not kept pace with AI usage. Learn what risks Shadow AI creates, why three regulations are striking simultaneously, and how to regain control in five steps.

  • Compliance & Regulation

    Shadow AI and AI governance: a compliance guide

    Shadow AI affects 60 percent of knowledge workers. Learn how to detect uncontrolled AI usage, comply with the EU AI Act and NIS2, and regain control with managed AI layers.

  • Compliance & Regulation

    KI-MIG: What Germany’s AI law means for businesses

    The KI-MIG implements the EU AI Act in Germany and has been in force since July 29, 2026: supervision, penalties, deadlines, and a 10-step checklist for your company.

  • Compliance & Regulation

    EU AI Act: what freelancers and business owners need to know

    Practical guide to the EU AI Act for midsize companies and freelancers. What obligations apply from 2026, what must be documented, and how AI can be deployed in compliance with the law. With checklists and concrete recommendations.

Back to the overview

Next step

Business data strategy for your company

From the target state to supervised delivery. We advise you and enable your organization.

Book an initial call

45 minutes, by video, free of charge.

Start the check

How ready is your decision? Check it in 3 minutes.

Call +49 6021 625 63 40