DACH legal. EU AI Act and GDPR for AI operators
What's been binding since February 2025, what gets enforced from August 2026. What SMBs and freelancers must implement now. No legalese, just duties.
Anyone using AI tools professionally can no longer rely on legal "coming later". The EU AI Act has been partly binding since February 2025, the first enforcement wave rolls in from August 2026. Plus GDPR which still applies. Plus DDG (formerly TMG), plus §356a German Civil Code if you close online contracts. Here's what's actually relevant for you as an AI operator or AI-using firm, no lawyer vocabulary.
Disclaimer
This isn't legal advice. I'm not a lawyer; this is a summary from research and from applying it in my own companies. For concrete cases, ask an AHK, an IHK, or a lawyer. What you read here are the questions you should ask.
Article 4 EU AI Act. AI literacy is mandatory
In force since 2 February 2025. Enforcement from 2 August 2026.
What it requires: every firm using AI systems must ensure that staff working with AI have "a sufficient level of AI competence". The wording is vague, but the EU Commission has clarified there's no mandatory exam, documented training measures are enough.
What you concretely need:
- A written AI use policy.
- Every staff member with AI contact has done a training.
- Training records (who, when, which module) kept.
- New hires get the training within probation.
- Annual refresher.
As a solo freelancer: only affects you indirectly via your clients. If you do B2B and your clients implement AI tools, they'll expect the proof set from you. These clients will pay attention from August 2026.
Article 5 and risk categories
The AI Act distinguishes four categories:
- Forbidden (social scoring, subliminal manipulation, biometric mass surveillance).
- High-risk (AI in HR selection, credit decisions, critical infrastructure, education when grading).
- Transparency-required (chatbots must identify themselves as AI, deepfakes must be marked, AI-generated journalistic text must be flagged).
- Minimum risk (the rest, no special duties).
Most things you build are "Transparency-required" or "Minimum risk". No panic, no looming forbidden category.
Important: if you run a chatbot on your website, the user has to recognize it's AI. That suffices as a label "AI Assistant" or "this chat is answered by AI". Don't hide it.
GDPR and AI, the real stumbling blocks
GDPR is older than ChatGPT, but it applies to everything you do in your AI tool. Three real questions:
What happens to data going into ChatGPT/Claude?
OpenAI and Anthropic retain inputs and outputs for operations and abuse purposes. Different durations depending on plan and settings. That's processing on your behalf under GDPR if you submit personal data.
Two implications:
- You need a DPA (Data Processing Agreement) with the provider. Anthropic and OpenAI offer these but you have to actively sign them.
- You may NOT casually process sensitive data (health, religion, biometric) in standard tools. Needs separate enterprise agreements or own models.
What about US transfer?
The providers host primarily in the US. GDPR requires SCCs (Standard Contractual Clauses) or adequacy decisions for US transfer. Anthropic has SCCs, OpenAI too. You must be able to demonstrate the SCCs on data requests.
For sensitive data, SCCs often don't suffice (Schrems II ruling). Those cases need additional technical measures: pseudonymization before sending, or EU-hosted models (Mistral, Aleph Alpha) instead of US providers.
What about memory systems?
If you store data in an external memory server (like StudioMeyer Memory or self-hosted), the server operator is a processor. DPA needed. With self-hosted memory, you yourself are responsible: GDPR-compliant hosting (encryption, access logs, deletion rights).
DDG (Digital Services Act, replaces TMG since May 2024)
Relevant for anyone running a website or app. Core points:
- Imprint duty remains. §5 DDG instead of §5 TMG, content-wise the same.
- Contact options must be "easy". Email + contact form + phone is gold standard.
- "User-generated content" on your platform: you're liable if you don't react quickly to reports of illegal content.
§356 and §356a BGB, withdrawal on online contracts
If you sell AI services online to consumers (B2C), distance-selling rules apply:
- §356 BGB: withdrawal 14 days after contract conclusion. No reason needed.
- §356(5): digital content. Withdrawal waiver possible, but must be explicitly checked (checkbox UNCHECKED initially).
- §356a: button rule, the buy button must be unambiguously labeled ("order with payment obligation" or equivalent).
Practical consequence: if you sell digital products and the customer says "actually no" three days later, you have to refund unless they explicitly waived withdrawal and were informed. A general "no withdrawal on digital products" no longer suffices.
Copyright. AI-generated belongs to no one really
AI-generated works aren't copyright-protected as long as there's insufficient human contribution. That means:
- A purely AI-written image can't be copyrighted.
- AI text you just copy from the tool can't either.
- Once you do meaningful editorial work (rearrange, augment, shorten, fact-check), a protectable work emerges, but only your share.
For agency work that means: if you deliver AI outputs to clients without meaningful editing, the client can't exclusively protect the work. Often not a problem (marketing text, presentations rarely need copyright), but for software and book publications it is.
My concrete recommendations for freelancers and small SMBs
- Imprint + privacy + ToS on your website. DDG + GDPR + withdrawal notice if B2C.
- DPAs with OpenAI and Anthropic (both have standard portals).
- AI use policy written (2 pages enough), have staff + freelancers sign it, keep signed copy.
- Chatbot label on every web app using AI.
- Sensitive data not in standard ChatGPT or Claude. For health / finance / law: enterprise plan, EU-hosted, or not at all.
- Cookie banner if you use analytics (Umami is GDPR-compliant and needs no banner, good).
- Deletion rights documented: how can a user / customer delete their data with you.
Those are the seven measures that cover 95 percent of all cases.
What actually gets enforced on August 2, 2026
As of April 2026, three months before the deadline, the enforcement-relevant points are:
High-risk full enforcement. From August 2, 2026 all high-risk obligations from Annex III are in full effect. This affects AI in hiring, credit decisions, education grading, critical infrastructure and a few other domains. If you're in this category, you need a conformity-assessed system with CE marking. This is NOT relevant for 95 percent of freelancers and SMEs, but if you build an HR tool for a client that auto-sorts applicants, look closer.
Transparency obligations for end users. AI content labeling becomes enforcement-mandatory from August 2026. In practice: AI-generated texts, images and audio that the user sees must be identifiable as AI. This covers deepfakes (stricter) and synthetic editorial content. For a website with an AI chatbot, a clear hint is enough; for AI-generated marketing images you need a watermark or caption.
GPAI penalty range active. In force since August 2, 2025, but practically relevant via the full enforcement wave. Violations of GPAI obligations (transparency, technical documentation, training-data summary for model providers) can cost up to 15 million euros or 3 percent of worldwide annual revenue, whichever is higher. This primarily hits the model providers (OpenAI, Anthropic, Mistral), not you as a user. But if you train a foundation model yourself and pass the GPAI threshold, then yes.
AI sandbox per member state. From August 2026 every EU member state must operate an "AI regulatory sandbox" where companies can test their AI systems before rollout, with oversight but without immediate sanctions. In Germany the Bundesnetzagentur in Bonn handles this and has set up an "AI Service Desk" for SMEs. If you're in a borderline area (AI in education or HR), ask there beforehand. Saves trouble later.
MCP server security, what the OX Security story means for DACH compliance
In April 2026 OX Security disclosed a systemic RCE vulnerability in the MCP STDIO transport. 11 CVEs across production frameworks (LangFlow, Windsurf, Flowise, LiteLLM, Bisheng, Upsonic and more), up to 200,000 vulnerable instances estimated. Anthropic positioned this as "expected behavior", arguing sanitization is the developer's responsibility.
For GDPR compliance this is a concrete point. If your company runs MCP servers that process personal data, Article 32 GDPR requires technical and organizational measures (TOMs). One TOM is selecting software that does not ship with known RCE gaps. In practice, before deploying an MCP server in production, you check the source, ideally with a documented selection process. If a data protection audit later asks why you picked a specific MCP server, you don't want to answer "we took the first one ChatGPT suggested".
Concrete recommendation for SMEs and freelancers, three points. First, maintain a list of all MCP servers in production use. Who built them, where they came from, which tool calls are active. Second, only run MCP servers from trusted sources (official Anthropic releases, established OSS projects with active maintainers, your own builds with code review). Third, if you build and ship MCP servers to clients, sanitization of tool arguments is mandatory and part of your security documentation. See the dedicated playbook "MCP STDIO security" for the technical details and code patterns.
Data processor agreement angle: if an MCP server processes data on your behalf (e.g. a cloud-hosted MCP server), you need a data processing agreement with the provider just like any other sub-processor, plus the standard guarantees for transfers outside the EU.
Bundesnetzagentur note: the AI Service Desk in Bonn is also the contact point for security questions around MCP. If you are unsure whether your setup is compliance-fit, ask there before an incident rather than after.
Bundesnetzagentur is the national authority
DACH-specific: the Bundesnetzagentur in Bonn is the German oversight body for the AI Act. The "AI Service Desk" is SME-friendly and free for first inquiries. If you're unsure whether your use case is high-risk, ask there. Two weeks of wait beat a nasty audit after going live. Austria has RTR, Switzerland is formally outside the AI Act but aligns with EU standards for cross-border providers.
What's still going to change
The EU AI Office continues working on concrete guidance. By end of 2026 these are likely:
- Concrete training standards for AI literacy (Article 4).
- Technical standards for transparency labeling.
- Code of Practice for general-purpose AI.
- More concrete thresholds for high-risk categorization.
Stay current via the EU AI Office portal, Bundesnetzagentur AI Service Desk updates, or specialist media like Heise, c't, or IHK newsletters.
Onwards
If you build AI systems for yourself or for clients, Level 5 Lesson 5 Human-in-the-Loop helps you build the right approval points, which is additionally legally mandatory for "high-risk" systems.
And Level 6 shows how to host your memory systems and MCP servers yourself, often the cleanest way for GDPR-sensitive applications.