Life Sciences & Health Care
Representing interests and protecting innovation

Authors: Mathis Fister and Julia Ruiter
In early October 2025, the case of a major consulting firm that allegedly used artificial intelligence (“AI”) to prepare a report without disclosing it sparked controversy. The Austrian newspaper Der Standard reported, “[l]According to the scientist, the recommendations of the report can no longer be trusted.”
This incident clearly shows that, due to technological progress (e.g., Copilot, ChatGPT, Gemini), it is often no longer immediately recognizable what has been created by humans or generated by AI. This creates uncertainty both among the general public and in the business world.
This is precisely where the AI Act[1] comes in: AI is intended to become safer and more transparent, which also entails obligations for companies.
AI is no longer a topic of the future. Whether it’s chatbots that companies use to automatically respond to (customer) inquiries, AI-supported applicant selection and personnel decisions, or AI systems for evaluating customer profiles: Companies that use AI systems must consider the obligations that this entails.
The obligations under the AI Act are based on a risk classification of AI systems. Transparency requirements as well as user information are a central aspect of this. The AI Act also obliges companies to ensure that all employees who use AI systems possess sufficient AI competence.
To comply with all these obligations of the AI Act, company-specific AI risk management is necessary. Depending on company size and field of activity, it is advisable to appoint an AI officer (a team of several people can also be effective). Furthermore, responsibilities for AI areas within the company should be clearly defined (who is responsible for the selection, risk assessment, deployment, and monitoring of an AI system?). Guidelines for employees can be helpful for the use of AI.
The individual obligations resulting from the risk classification are essentially the following:[2]
For companies, this means first identifying which AI systems they use and then categorizing them.
With regard to information obligations, a distinction must be made between high-risk AI systems and other AI systems, in particular AI systems with limited risk:
The use of a high-risk AI system must be disclosed to the persons concerned if the AI makes decisions or supports decisions[4], as well as when it is used with employees. This information must be provided before the high-risk AI system is put into operation or used.
AI systems with limited risk are subject to information obligations[5] if users interact directly with an AI system (e.g., chatbots). A labeling obligation also applies to synthetically generated content or deepfakes; in this case, it must be disclosed that the content has been artificially generated or manipulated. If an emotion recognition system is used – provided this is permitted under the AI Act – those affected must be informed of this.
Regardless of the risk classification, Article 4 of the AI Act stipulates so-called competence obligations. These are directed at providers and operators of AI systems and include requirements for expertise, qualifications, and training in dealing with AI.
In order for AI to be used not only efficiently but also responsibly, the AI Act obliges companies to specifically build up AI know-how. Regardless of whether an AI system is classified as low-risk or high-risk, providers and operators must ensure that employees possess the necessary expertise. In many cases, technical understanding alone is not sufficient. Legal and ethical aspects also play a central role. Only those who recognize the opportunities and risks of AI systems at an early stage and deal with them competently can use their full potential responsibly – while at the same time meeting the requirements of the AI Act.
Companies have no choice but to address the requirements of the AI Act that apply to them in a timely manner, build AI competence among their employees, and establish appropriate compliance and risk management in order to lay the foundation for a regulation-compliant and future-proof AI strategy. Those who address the new legal situation in a timely manner can smoothly integrate internal processes and obligations such as information and transparency requirements into everyday business. The use of AI should not become a legal trap, but rather offer companies forward-looking potential.
This article is for general information only and does not replace legal advice. Haslinger / Nagele Rechtsanwälte GmbH assumes no liability for the content and correctness of this article.
[1] Regulation (EU) 2024/1689.
[2] The obligations listed are not exhaustive.
[3] Article 25 of the AI Act.
[4] Article 26(11) of the AI Act. According to Article 86 of the AI Act, persons affected by such a decision have the right to receive an explanation from the operator about the role of the AI system in the decision-making process.
[5] Article 50 of the AI Act.


2. December 2025
You need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Turnstile. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information