The model behind it
Gartner's Analytic Ascendancy Model (2012) describes four analytics stages: Descriptive, Diagnostic, Predictive and Prescriptive. With each stage, business value rises — and the share of decision-making shifts step by step from human to machine. That shifting share of decision-making is precisely the regulatory lever.
Our thesis: Regulatory burden rises in step with autonomy. The analytics stages follow Gartner; the compliance mapping is an original format by Mag. Eiler & Partner OG.
Stage 1 — Descriptive: "What happened?"
- Typical systems: Reports & BI dashboards — regulatory reporting, Power BI/Fabric dashboards, portfolio/claims reports.
- Obligations: usually not yet an AI system within the meaning of Art. 3 AI Act; GDPR principles, data quality (BCBS 239 logic), NIS2/DORA baseline hygiene.
- Key question: Is your data foundation robust enough to build models on later?
Stage 2 — Diagnostic: "Why did it happen?"
- Typical systems: AI assistants and chatbots (internal/customer-facing), Copilot use, RAG over internal documents.
- Obligations: Art. 50 AI Act (from 2 Aug 2026, NOT postponed by the Digital Omnibus) — disclosure of AI interaction; Art. 4 AI Act (since 2 Feb 2025) — AI literacy; shadow-AI inventory; GDPR for customer data in context.
- Key question: Do users know they are talking to an AI — and what its limits are?
Stage 3 — Predictive: "What will happen?"
- Typical systems: Scoring, fraud detection, churn/claims forecasting, self-service analytics.
- Obligations: Validation governance (model risk, method logging, drift monitoring); Annex III assessment per use case — creditworthiness assessment and life/health insurance pricing are explicitly high-risk (Annex III No. 5); classification decision must be documented since the Digital Omnibus; deadline 2 Dec 2027; ISO/IEC 42001/23894/42005; Art. 10 data governance for high-risk; DORA; works-council involvement for HR-related predictions.
- Key question: Who validates the models — and who detects faulty predictions when business users without statistical training run the analyses?
Stage 4 — Prescriptive: "What should be done?" (autonomous decision)
- Typical systems: Automated credit decisions, dynamic underwriting/pricing, automated claims settlement, agentic workflows.
- Obligations (the regime change): full high-risk programme Art. 9–15, 17, 26 (deadline 2 Dec 2027); Art. 14 — human oversight by design, with express safeguards against automation bias (para. 4 lit. b); Art. 22 GDPR (automated individual decision-making); FMA model-governance expectations; management liability (Sec. 84 Austrian Stock Corporation Act / Sec. 39 Austrian Banking Act); FRIA where applicable (Art. 27).
- Key question: Is human oversight effectively designed and evidenced — or merely asserted on paper?
The staircase doubles as a timeline
The sequence of stages is also a sequence of deadlines: the higher the autonomy, the later the programme obligations bite — while the immediate obligations of the lower stages already apply.
| Date | What applies | Staircase context |
|---|---|---|
| 2 February 2025 | Art. 4 AI Act (AI literacy), prohibition of certain AI practices | Immediate obligation from stage 2 — already applies. |
| 2 August 2026 | Art. 50 AI Act (disclosure of AI interaction), enforcement of Art. 4 | Immediate obligation of stage 2 — NOT postponed by the Digital Omnibus. |
| 2 December 2027 | High-risk obligations under Annex III (Art. 9–15, 17, 26) | Programme obligations of stages 3–4. |
Stages 1–2 are immediate obligations (2025/2026); stages 3–4 are programme obligations (by 2 Dec 2027). The staircase doubles as a timeline.
The Digital Omnibus has been finally adopted (Council, 29 June 2026); publication in the Official Journal is pending.
Which stage is your institution on?
Answer a few questions on deployment and compliance coverage — you receive your position on the staircase, your compliance gap and the obligations that apply next.