AI Providers as ICT Third-Party Providers under DORA
DORA treats AI providers as ICT third-party providers under Art. 28. It covers the duties involved and where AI Act deadlines start to matter.
Read more →KomplAI blog
Short, evidence-backed articles on the EU AI Act, DORA and GDPR — every citation checked against the official EUR-Lex texts.
DORA treats AI providers as ICT third-party providers under Art. 28. It covers the duties involved and where AI Act deadlines start to matter.
Read more →DORA requires documented ICT risk management for AI services in the financial sector under Art. 5 and 6 of DORA – plus AI Act duties from 2026.
Read more →How Section 26 BDSG limits the use of AI in recruitment and workforce analytics, and why necessity and co-determination remain decisive factors.
Read more →Art. 32 GDPR requires appropriate TOMs based on risk. What this means in practice, typical gaps, and how to document compliance.
Read more →When AI providers process personal data, you need an Art. 28 contract. What must be included and where the typical gaps lie.
Read more →Training AI models with personal data requires a lawful basis under Art. 6 GDPR. We examine legitimate interest, purpose change and typical common gaps.
Read more →Art. 22 GDPR: when automated decisions and AI profiling are lawful – covering obligations, exceptions and typical compliance gaps in practice.
Read more →AI systems almost always trigger a data protection impact assessment under the GDPR. What Art. 35 GDPR requires and where the typical gaps lie in practice.
Read more →Art. 99 AI Act sets fines of up to EUR 35 million or 7% of global turnover – three tiers, SME rules and assessment criteria for your compliance team.
Read more →Art. 4 AI Act has applied since 02.02.2025: staff and contractors must have adequate AI literacy. What this means and where the typical gaps are.
Read more →Art. 6 AI Act determines whether your AI system is high-risk. An overview of Annex III, carve-outs and the postponed 2 December 2027 deadline.
Read more →The AI Act's Art. 5 prohibitions have applied since 02.02.2025. Here's what's banned, which exemptions apply, and where companies still have gaps.
Read more →From 2 August 2026, Art. 50 AI Act sets labelling duties for chatbots and AI-generated content. Here's what providers and deployers must implement now.
Read more →Art. 26 EU AI Act sets out deployer obligations: human oversight, logging, and incident reporting. What businesses must actually implement in practice.
Read more →Art. 10 AI Act requires documented data governance for high-risk AI: the requirements, bias checks and the gaps teams typically run into.
Read more →Art. 27 AI Act requires public bodies to carry out a fundamental rights impact assessment. An overview of mandatory content, timing and gaps.
Read more →Art. 15 AI Act requires accuracy, robustness and cybersecurity for high-risk AI systems. What this means in practice for development and operations.
Read more →Your AI provider owes you just one document by law: the Art. 13 instructions for use. Technical documentation and the declaration go to the authorities.
Read more →Which procedure applies to high-risk AI systems: Annex VI or VII? Obligations under Art. 43 AI Act explained – including common gaps.
Read more →Art. 14 AI Act requires effective human oversight of high-risk AI systems. Learn how to design roles, training and stop mechanisms correctly.
Read more →Art. 12 EU AI Act demands comprehensive logging and traceability for high-risk AI. What this means in practice for providers and deployers.
Read more →Art. 17 AI Act requires a documented quality management system for high-risk AI providers. What it covers and where typical gaps arise.
Read more →Before high-risk AI systems under Annex III go live, providers must register them in the EU database under Art. 49 AI Act. Find out what applies and when.
Read more →What Article 11 and Annex IV of the EU AI Act require for the technical documentation of high-risk AI systems – and where gaps typically occur.
Read more →What Art. 13 AI Act requires for instructions for use of high-risk AI systems – mandatory content, gaps and tips for providers and deployers.
Read more →The risk management system under Art. 9 EU AI Act is the obligation most high-risk projects stumble on — plus the five most common gaps.
Read more →