DE

EU AI Act · GDPR · DORA

The AI Compliance Staircase: Your Obligation Roadmap from Analytics to Autonomous Decisions

Regulatory burden rises in step with autonomy. Tell us which analytics stage your AI operates on — the staircase tells you which obligations already apply today, and which ones you acquire with the next stage.

The AI Compliance Staircase Four ascending steps from Descriptive to Prescriptive. Value and regulatory burden rise with autonomy. Time markers: 2 Aug 2026 at step 2, 2 Dec 2027 between steps 3 and 4. Value & regulatory burden Autonomy 1 · Descriptive What happened? GDPR · Data quality · DORA basics 2 · Diagnostic Why did it happen? Art. 50 · Art. 4 AI Act 3 · Predictive What will happen? Annex III? · ISO 42001 · Validation 4 · Prescriptive What should be done? Art. 9–15 · Art. 14 · Art. 22 GDPR 2 Aug 2026 2 Dec 2027 The AI Compliance Staircase © Mag. Eiler & Partner OG · Analytics stages after Gartner (2012)
The AI Compliance Staircase: four analytics stages mapped to the obligations that apply at each stage.

The model behind it

Gartner's Analytic Ascendancy Model (2012) describes four analytics stages: Descriptive, Diagnostic, Predictive and Prescriptive. With each stage, business value rises — and the share of decision-making shifts step by step from human to machine. That shifting share of decision-making is precisely the regulatory lever.

Our thesis: Regulatory burden rises in step with autonomy. The analytics stages follow Gartner; the compliance mapping is an original format by Mag. Eiler & Partner OG.

Stage 1 — Descriptive: "What happened?"

  • Typical systems: Reports & BI dashboards — regulatory reporting, Power BI/Fabric dashboards, portfolio/claims reports.
  • Obligations: usually not yet an AI system within the meaning of Art. 3 AI Act; GDPR principles, data quality (BCBS 239 logic), NIS2/DORA baseline hygiene.
  • Key question: Is your data foundation robust enough to build models on later?

Stage 2 — Diagnostic: "Why did it happen?"

  • Typical systems: AI assistants and chatbots (internal/customer-facing), Copilot use, RAG over internal documents.
  • Obligations: Art. 50 AI Act (from 2 Aug 2026, NOT postponed by the Digital Omnibus) — disclosure of AI interaction; Art. 4 AI Act (since 2 Feb 2025) — AI literacy; shadow-AI inventory; GDPR for customer data in context.
  • Key question: Do users know they are talking to an AI — and what its limits are?

Stage 3 — Predictive: "What will happen?"

  • Typical systems: Scoring, fraud detection, churn/claims forecasting, self-service analytics.
  • Obligations: Validation governance (model risk, method logging, drift monitoring); Annex III assessment per use case — creditworthiness assessment and life/health insurance pricing are explicitly high-risk (Annex III No. 5); classification decision must be documented since the Digital Omnibus; deadline 2 Dec 2027; ISO/IEC 42001/23894/42005; Art. 10 data governance for high-risk; DORA; works-council involvement for HR-related predictions.
  • Key question: Who validates the models — and who detects faulty predictions when business users without statistical training run the analyses?

Stage 4 — Prescriptive: "What should be done?" (autonomous decision)

  • Typical systems: Automated credit decisions, dynamic underwriting/pricing, automated claims settlement, agentic workflows.
  • Obligations (the regime change): full high-risk programme Art. 9–15, 17, 26 (deadline 2 Dec 2027); Art. 14 — human oversight by design, with express safeguards against automation bias (para. 4 lit. b); Art. 22 GDPR (automated individual decision-making); FMA model-governance expectations; management liability (Sec. 84 Austrian Stock Corporation Act / Sec. 39 Austrian Banking Act); FRIA where applicable (Art. 27).
  • Key question: Is human oversight effectively designed and evidenced — or merely asserted on paper?

The staircase doubles as a timeline

The sequence of stages is also a sequence of deadlines: the higher the autonomy, the later the programme obligations bite — while the immediate obligations of the lower stages already apply.

DateWhat appliesStaircase context
2 February
2025
Art. 4 AI Act (AI literacy), prohibition of certain AI practicesImmediate obligation from stage 2 — already applies.
2 August
2026
Art. 50 AI Act (disclosure of AI interaction), enforcement of Art. 4Immediate obligation of stage 2 — NOT postponed by the Digital Omnibus.
2 December
2027
High-risk obligations under Annex III (Art. 9–15, 17, 26)Programme obligations of stages 3–4.
Remember

Stages 1–2 are immediate obligations (2025/2026); stages 3–4 are programme obligations (by 2 Dec 2027). The staircase doubles as a timeline.

Digital Omnibus status

The Digital Omnibus has been finally adopted (Council, 29 June 2026); publication in the Official Journal is pending.

Which stage is your institution on?

Answer a few questions on deployment and compliance coverage — you receive your position on the staircase, your compliance gap and the obligations that apply next.

From self-check to positioning

The AI Governance Maturity Assessment delivers your position on the staircase, including an obligation roadmap per stage. See the assessment

Get in touch

Sources

Notice: This page is for general information about regulatory developments and does not constitute legal advice. It does not replace advice from lawyers specialising in AI law or specialised AI compliance consulting. Content reflects the status as of July 2026 and may change through new legal acts, national implementing laws or official interpretations. At the time of review, the Digital Omnibus had been finally adopted (Council, 29 June 2026); publication in the Official Journal was pending.