The AI Compliance Staircase NEW
Which obligation applies at which AI maturity stage? The roadmap model for executives, with self-check.
See the AI Compliance StaircaseEU AI Act · DORA · GDPR
The EU AI Act is in force. Since 2 August 2026 the transparency obligations apply, among others. The Digital Omnibus has postponed the high-risk deadlines, but not the need for robust AI governance.
Since 2 February 2025, the first binding EU AI Act requirements have applied, including the prohibition of certain AI practices and the obligation to ensure AI literacy for people who deploy or operate AI systems.
What many underestimate: the regulatory requirements do not arrive one by one. DORA, NIS2, GDPR and the EU AI Act overlap with different deadlines, authorities and sanction regimes. One AI-related compliance breach can involve the FMA, the data protection authority and the works council at the same time.
For medium-sized regional banks and insurers in Austria, this creates a particular challenge: they often operate the same core systems as large institutions, but with significantly leaner internal compliance resources.
Beyond this financial-sector focus, AI governance also becomes a management and oversight topic for stock corporations outside the financial sector: management board, supervisory board, internal controls and reporting need one coherent framework.
The Digital Omnibus on AI was published as Regulation (EU) 2026/1744 in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. The postponement is therefore binding law: requirements for high-risk AI systems under Annex III apply from 2 December 2027, those under Annex I from 2 August 2028. The transparency obligations under Art. 50 were not postponed and have applied since 2 August 2026.
Which obligation applies at which AI maturity stage? The roadmap model for executives, with self-check.
See the AI Compliance StaircaseAI components in purchased software or freely used tools are often not inventoried as AI systems. Nevertheless, duties under the EU AI Act, GDPR and internal governance rules may arise.
More on shadow AIThe EU AI Act has been in force since 1 August 2024. Prohibitions and AI literacy have applied since February 2025, the transparency obligations since 2 August 2026. Annex III high-risk duties follow on 2 December 2027.
More on the EU AI ActUnder Section 84 AktG and Section 39 BWG, AI governance becomes an organisational duty. Not knowing which AI systems are used is not a viable control concept.
More on management board liabilityManagement and supervisory boards need an auditable framework for AI inventory, controls, risk management, reporting and decisions of governing bodies.
AI governance for stock corporationsMarket-leading platforms for core banking, AML, underwriting and HR may contain AI components. Institutions using those systems have their own deployer obligations.
More on vendor AIThe Fundamental Rights Impact Assessment under Art. 27 EU AI Act is especially relevant for creditworthiness assessment and life/health insurance risk assessment.
Understand FRIAChatGPT, Copilot, Claude and other general-purpose AI services require usage rules, privacy review, inventory and provider due diligence.
More on GPAIApps and digital products under an institution's own brand may trigger CRA obligations in addition to DORA. Role allocation is the first step.
Assess CRA relevanceAI systems with employee data, HR or control functions may require works council involvement and works agreements in Austria.
Assess the ArbVG interfaceThe path to EU AI Act compliance is not a single project, but a structured process across several phases: inventory, risk classification, role allocation, gap analysis, governance and ongoing monitoring. International standards such as ISO/IEC 42001:2023 provide a framework, but they do not replace the individual assessment of specific AI systems, business processes and responsibilities in your institution.
AI bias is not only a technical or EU AI Act topic. If AI systems create discrimination risks in HR, lending, underwriting or customer access, these risks may also become relevant for CSRD / ESRS reporting: as a social impact, governance topic, risk-management question or auditable evidence.
The international standard for AI management systems provides structure, but does not cover all EU AI Act-specific duties.
Understand ISO/IEC 42001Without a complete inventory, risk classification, FRIA and governance remain incomplete.
More on the AI inventoryAuditable AI governance means being able to provide inventory, roles, FRIA, logs, reporting paths and evidence at any time.
Build audit readinessWe support Austrian financial institutions from initial inventory to auditable governance structures.
View project supportCore terms from the EU AI Act, ISO/IEC 42001 and AI governance, with links to the relevant topic pages.
Open glossaryWe can discuss your individual situation. An initial conversation is non-binding and gives you a clear view of where your institution currently stands on AI governance.