Shadow AI
AI components in purchased software or freely used tools are often not inventoried as AI systems. Nevertheless, duties under the EU AI Act, GDPR and internal governance rules may arise.
More on shadow AIEU AI Act · DORA · GDPR
The EU AI Act is in force. Initial obligations already apply. For high-risk AI systems, the Digital Omnibus is likely to shift parts of the timeline, but not the need for robust AI governance.
Since 2 February 2025, the first binding EU AI Act requirements have applied, including the prohibition of certain AI practices and the obligation to ensure AI literacy for people who deploy or operate AI systems.
What many underestimate: the regulatory requirements do not arrive one by one. DORA, NIS2, GDPR and the EU AI Act overlap with different deadlines, authorities and sanction regimes. One AI-related compliance breach can involve the FMA, the data protection authority and the works council at the same time.
For medium-sized regional banks and insurers in Austria, this creates a particular challenge: they often operate the same core systems as large institutions, but with significantly leaner internal compliance resources.
Following the political agreement on the Digital Omnibus of 7 May 2026, rules for certain high-risk areas are expected to apply from 2 December 2027. Until formal publication in the Official Journal, cautious planning should take both timelines into account.
AI components in purchased software or freely used tools are often not inventoried as AI systems. Nevertheless, duties under the EU AI Act, GDPR and internal governance rules may arise.
More on shadow AIThe EU AI Act has been in force since 1 August 2024. Certain prohibitions have applied since February 2025. High-risk duties, transparency obligations and national supervision must now be prepared in a structured way.
More on the EU AI ActThrough Austrian company and banking law, AI governance becomes an organisational duty. Not knowing which AI systems are used is not a viable control concept.
More on board liabilityMarket-leading platforms for core banking, AML, underwriting and HR may contain AI components. Institutions using those systems have their own deployer obligations.
More on vendor AIThe Fundamental Rights Impact Assessment under Art. 27 EU AI Act is especially relevant for creditworthiness assessment and life/health insurance risk assessment.
Understand FRIAChatGPT, Copilot, Claude and other general-purpose AI services require usage rules, privacy review, inventory and provider due diligence.
More on GPAIApps and digital products under an institution's own brand may trigger CRA obligations in addition to DORA. Role allocation is the first step.
Assess CRA relevanceAI systems with employee data, HR or control functions may require works council involvement and works agreements in Austria.
Assess the ArbVG interfaceThe path to EU AI Act compliance is not a single project, but a structured process across several phases: inventory, risk classification, role allocation, gap analysis, governance and ongoing monitoring. International standards such as ISO/IEC 42001:2023 provide a framework, but they do not replace the individual assessment of specific AI systems, business processes and responsibilities in your institution.
AI bias is not only a technical or EU AI Act topic. If AI systems create discrimination risks in HR, lending, underwriting or customer access, these risks may also become relevant for CSRD / ESRS reporting: as a social impact, governance topic, risk-management question or auditable evidence.
The international standard for AI management systems provides structure, but does not cover all EU AI Act-specific duties.
Understand ISO/IEC 42001Without a complete inventory, risk classification, FRIA and governance remain incomplete.
More on the AI inventoryAuditable AI governance means being able to provide inventory, roles, FRIA, logs, reporting paths and evidence at any time.
Build audit readinessWe support Austrian financial institutions from initial inventory to auditable governance structures.
View project supportCore terms from the EU AI Act, ISO/IEC 42001 and AI governance, with links to the relevant topic pages.
Open glossaryWe can discuss your individual situation. An initial conversation is non-binding and gives you a clear view of where your institution currently stands on AI governance.