Zum Hauptmenü Zum Inhalt

False information, real consequences?


Authors: Mathis Fister and Julia Ruiter

The AI Act and its significance for Austrian companies

In early October 2025, the case of a major consulting firm that allegedly used artificial intelligence (“AI”) to prepare a report without disclosing it sparked controversy. The Austrian newspaper Der Standard reported, [l]According to the scientist, the recommendations of the report can no longer be trusted.”

This incident clearly shows that, due to technological progress (e.g., Copilot, ChatGPT, Gemini), it is often no longer immediately recognizable what has been created by humans or generated by AI. This creates uncertainty both among the general public and in the business world.

This is precisely where the AI Act[1] comes in: AI is intended to become safer and more transparent, which also entails obligations for companies.

What significance does the AI Act have for Austrian companies?

1. AI risk management

AI is no longer a topic of the future. Whether it’s chatbots that companies use to automatically respond to (customer) inquiries, AI-supported applicant selection and personnel decisions, or AI systems for evaluating customer profiles: Companies that use AI systems must consider the obligations that this entails.

The obligations under the AI Act are based on a risk classification of AI systems. Transparency requirements as well as user information are a central aspect of this. The AI Act also obliges companies to ensure that all employees who use AI systems possess sufficient AI competence.

To comply with all these obligations of the AI Act, company-specific AI risk management is necessary. Depending on company size and field of activity, it is advisable to appoint an AI officer (a team of several people can also be effective). Furthermore, responsibilities for AI areas within the company should be clearly defined (who is responsible for the selection, risk assessment, deployment, and monitoring of an AI system?). Guidelines for employees can be helpful for the use of AI.

2. Risk classification

The individual obligations resulting from the risk classification are essentially the following:[2]

  • AI with unacceptable risk: Such AI systems are generally prohibited.
  • AI with high risk: These AI systems are subject to strict requirements. The AI Act stipulates comprehensive obligations for providers (conformity assessment and, if necessary, corrective measures required; documentation, retention, and information obligations) and operators (proper use of the AI system, human oversight, documentation, information, retention, and registration obligations) and in particular also includes responsibilities along the supply chain (e.g., product manufacturers or distributors)[3].
  • AI with limited risk: For these AI systems, (reduced) transparency and information obligations apply.
  • AI with minimal risk: These AI systems are not restricted by the AI Act as such; however, voluntary codes of conduct are recommended.werden jedoch freiwillige Verhaltenskodizes empfohlen.

For companies, this means first identifying which AI systems they use and then categorizing them.

3. Information obligations: anyone who uses AI must provide information

With regard to information obligations, a distinction must be made between high-risk AI systems and other AI systems, in particular AI systems with limited risk:

The use of a high-risk AI system must be disclosed to the persons concerned if the AI makes decisions or supports decisions[4], as well as when it is used with employees. This information must be provided before the high-risk AI system is put into operation or used.

AI systems with limited risk are subject to information obligations[5] if users interact directly with an AI system (e.g., chatbots). A labeling obligation also applies to synthetically generated content or deepfakes; in this case, it must be disclosed that the content has been artificially generated or manipulated. If an emotion recognition system is used – provided this is permitted under the AI Act – those affected must be informed of this.

4. Competence obligations: AI requires know-how

Regardless of the risk classification, Article 4 of the AI Act stipulates so-called competence obligations. These are directed at providers and operators of AI systems and include requirements for expertise, qualifications, and training in dealing with AI.

In order for AI to be used not only efficiently but also responsibly, the AI Act obliges companies to specifically build up AI know-how. Regardless of whether an AI system is classified as low-risk or high-risk, providers and operators must ensure that employees possess the necessary expertise. In many cases, technical understanding alone is not sufficient. Legal and ethical aspects also play a central role. Only those who recognize the opportunities and risks of AI systems at an early stage and deal with them competently can use their full potential responsibly – while at the same time meeting the requirements of the AI Act.

Action required by companies

Companies have no choice but to address the requirements of the AI Act that apply to them in a timely manner, build AI competence among their employees, and establish appropriate compliance and risk management in order to lay the foundation for a regulation-compliant and future-proof AI strategy. Those who address the new legal situation in a timely manner can smoothly integrate internal processes and obligations such as information and transparency requirements into everyday business. The use of AI should not become a legal trap, but rather offer companies forward-looking potential.

Disclaimer

This article is for general information only and does not replace legal advice. Haslinger / Nagele Rechtsanwälte GmbH assumes no liability for the content and correctness of this article.


[1] Regulation (EU) 2024/1689.

[2] The obligations listed are not exhaustive.

[3] Article 25 of the AI Act.

[4] Article 26(11) of the AI Act. According to Article 86 of the AI Act, persons affected by such a decision have the right to receive an explanation from the operator about the role of the AI system in the decision-making process.

[5] Article 50 of the AI Act.

Further information on this legal field can be found here

Authors:

Porträtfoto Mathis Fister, Rechtsanwalt Haslinger/Nagele, Portrait von Julia Spicker

Mathis Fister

Attorney-at-Law

 

2. December 2025

 
Go back to News
  • Haslinger/ Nagele: JUVE Top Arbeitgeber Österreich 2025
  • Haslinger/ Nagele: JUVE Awards 2018: Kanzlei des Jahres Österreich
  • Haslinger/ Nagele: JUVE Top 20 Arbeitgeber 2024
  • Haslinger/ Nagele: Chambers Europe Top Ranked 2025 Logo
  • Legal500 EMEA Ranking Logo 2025
  • Promoting the best. Women in Law Award
  • Haslinger/ Nagele: Partner im CTC Cleantech Cluster
  • Haslinger/ Nagele: Mitglied Photovoltaic Austria