
Insights · Data protection
The EU AI Act
The training obligation under the new EU AI Act has applied since 2 February 2025. It ensures that everyone working with AI systems understands what matters: recognising risks, using opportunities and deploying this technology responsibly.
- Published
- 8 July 2025
- Author
- Dr. Markus Hülper
- Reading time
- 8 min read
Fasten your seat belts, because 2025 will be an exciting year. Alongside the usual New Year’s resolutions, companies in the EU face an entirely new challenge: the EU AI Act. And no, it is not just another bureaucratic monster — even if it may feel that way at first glance.
What is the EU AI Act? And why should you take it seriously?
The AI Act is the world’s first comprehensive legislation on artificial intelligence. The EU has set out to regulate the use of artificial intelligence (AI) — strictly, but fairly. The idea is to build trust, minimise risks and promote innovation at the same time.
For medium-sized companies that do not develop high-risk AI systems (think autonomous cars or medical diagnostic systems), that may sound reassuring at first. But take care: the first obligations have applied to many companies since 2 February 2025 — including those that “only” use AI-based tools or develop simple systems.
What should you expect?
The rules of the EU AI Act follow a risk-based approach. This means that the riskier an AI system is, the stricter the requirements. For “ordinary” medium-sized
companies that do not use high-risk AI, the requirements are somewhat less intimidating — but by no means trivial.
From 2025, the EU AI Act brings new requirements that companies must observe:
- Disclose when AI systems are used (transparency obligations).
- Ensure that the systems used do not produce discriminatory outcomes.
- Observe data protection and cybersecurity — and not just superficially.
- Document how AI systems are developed and used. (Yes, that means more paperwork.)
High-risk systems, such as biometric surveillance or AI-supported recruitment tools, are subject to even stricter requirements — but we will cover those in a separate article.
The EU AI Act requires companies to act
Our white paper “Die EU-KI-Verordnung: Ein Clarius-Guide” explains the background, objectives and core content of the EU AI Act, as well as the associated challenges, and provides practical recommendations for companies.
Download the white paper here with no obligation!
Why should you act now?
When faced with new rules, most medium-sized companies often think: “We’ll wait until things become more concrete.” That is not a good idea this time. Why?
Reason 1: the first obligations apply from February
The training obligation under the new EU AI Act has applied since 2 February 2025. It ensures that everyone working with AI systems understands what matters. The aim is to understand risks, use opportunities and deploy this technology responsibly.
What exactly does it involve?
The EU wants to ensure that nobody works with AI systems unprepared. Whether someone develops them, integrates them into a company or “merely” uses them, a certain basic level of knowledge is mandatory. This includes:
- How does AI work? Detailed knowledge is not required, but a sound understanding of the fundamentals is.
- What are the risks? For example, AI may reinforce bias or make incorrect decisions.
- How do I use AI safely and effectively? So that it becomes a tool rather than a stumbling block.
Who is affected?
The training obligation applies to everyone who deals with AI systems. This includes:
- Developers and providers, who must ensure that their AI is not only innovative but also safe.
- Companies and users that use AI in their everyday work. They should understand how to apply the technology correctly without unintentionally causing harm.
Why is this important?
AI systems are becoming increasingly complex, and their effects are often not immediately apparent. The training obligation ensures that everyone involved works from the same foundation of knowledge. This minimises risks and strengthens trust in the technology.
In other words: companies should use AI sensibly and responsibly.
The EU AI Act takes compliance with its requirements very seriously — and this is also evident in its sanctions and fines. Those who ignore the rules risk not only reputational damage but also significant financial consequences.
Reason 2: penalties are expensive
Since 2 February 2025, the message has been clear: do not fear AI, but do not be naive about it either. The EU makes clear that knowledge is the key to using AI systems safely and responsibly. Companies and employees should see training as an opportunity to prepare properly for working with AI. Ignoring the obligation risks not only technical problems but also fines.
Which infringements are penalised?
The Regulation distinguishes between different types of infringement with varying degrees of severity. Sanctions may be imposed, for example, for:
- Failure to comply with the requirements for high-risk AI systems: using an AI system in an unsafe or discriminatory way can be costly.
- Lack of transparency: concealing the fact that AI is involved, for example in deepfakes, is a clear breach of the rules.
- Breaches of the training obligation: companies must ensure that their employees are adequately trained — there are no excuses.
- Inadequate risk management: anyone who fails to take steps to minimise risks breaches the principles of the Regulation.
How high can the fines be?
The EU has set clear upper limits depending on the severity of the infringement:
- Up to EUR 30 million or 6% of a company’s worldwide annual turnover — whichever is higher. This applies to particularly serious infringements, such as failure to comply with the requirements for high-risk AI.
- Up to EUR 20 million or 4% of worldwide annual turnover for less serious but still significant breaches.
- Up to EUR 10 million or 2% of worldwide annual turnover for smaller infringements, such as breaches of transparency requirements.
Why so strict?
The EU wants to ensure that the EU AI Act does not merely exist on paper but is actually followed. The fines are intended to act as a deterrent, because AI systems can have a major impact on society. Negligent or irresponsible use could cause substantial harm.
In other words: serious sanctions may be imposed.
The sanctions under the EU AI Act are not merely a symbolic threat, but a serious enforcement tool. Companies should regard compliance with the rules as an investment in security and trust. The consequences of breaches are not only financially painful; they may also cause lasting damage to a company’s reputation.
Reason 3: AI is everywhere
Many medium-sized companies already use AI technologies — often without even realising it. AI has long since made the leap from high-tech laboratories into everyday work and is hidden within tools and processes that we use as a matter of course.
Where is AI already used today?
-
Customer support: Chatbots that answer questions around the clock are generally based on AI, as are automated email analysis tools.
-
Marketing: From personalised advertisements to optimising social media campaigns, many of these processes are controlled by AI.
-
Human resources: Applicant management systems that pre-screen CVs and employee feedback tools often use AI to support decisions.
-
Logistics and production: Optimised route planning, demand forecasting and quality control — AI delivers efficiency and cost savings here.
-
Finance: Fraud detection systems and AI-supported accounting are standard in many companies.
Why are so many people unaware of this?
AI sits “under the bonnet” of many software solutions. This means users are not consciously aware of the complex mechanisms behind them. To many, it is simply a tool that works — and is not necessarily recognised as AI.
In other words: AI systems are being used without everyone being aware of it
Medium-sized businesses have long been part of the AI world, even if this is not always obvious. That is precisely why it is important to understand the technologies being used. The better companies understand where AI is already at work, the more purposefully they can use its potential — and meet the requirements of the new EU AI Act.
But do not panic — we will tackle this together
At Clarius, we specialise in everything related to compliance, data protection and information security — and the AI Act is a natural fit for our strengths. Our aim is to guide you through the maze of regulations so that you can focus on what you do best: running your company successfully.
How we can help:
- Advice: We assess which obligations apply to you and how you can implement them efficiently.
- E-learning: Our cybersecurity and AI courses prepare your team effectively — clearly, practically and engagingly
- Compliance check: We help you structure your AI systems and their use so that they meet the legal requirements.
One final tip: knowledge is power (and saves money)
The requirements of the AI Act may be new, but they are based on principles that should be familiar: data protection, transparency and security. And best of all? With the right support, these requirements are manageable — and can even provide a genuine competitive advantage.
If you are now thinking, “That all sounds good, but I still don’t know where to start”, do not worry — that is what we are here for. Contact us and we will work together to ensure that you are not merely ready, but thoroughly prepared.
PS: Why put it off? Our e-learning courses on AI and cybersecurity are starting soon — reserve your place and gain the knowledge you need.
Do you have questions about this topic?
We can assess what the development means for your organisation and advise you directly.


