The roadmap in five steps
The following five steps build on each other and reference the specific modules in this course where they were covered in detail.
Step 1: Inventory
List every AI system in use and check it against the concrete lists from “The Risk Pyramid in Detail”: prohibited practices, Annex III categories, or “just” a chatbot or minimal risk. Write it down, don't just think it through.
Step 2: Clarify the role
For every system in the inventory, answer the role question from “Provider or Deployer?” – in particular checking whether your own brand, a substantial modification, or a change of purpose triggers an unnoticed provider role.
Step 3: Build competence and oversight
Introduce documented, role-tiered training following the pattern from “The AI Literacy Duty”. For high-risk systems, additionally implement real human oversight and – where applicable – a fundamental rights impact assessment per “Human Oversight and the Fundamental Rights Impact Assessment”. If there's a works council, it belongs at the table from the start, per “What This Means for Employees: Information, Co-Determination, Works Councils”.
Step 4: Implement labelling
Visibly label chatbots, AI-generated content, and deepfakes per “Transparency Obligations for Chatbots, Deepfakes & AI Content (Art. 50)”. Anyone using their own models, or even providing them, should additionally check the vendor or provider obligations from “If You Deploy or Provide Models Yourself: GPAI Obligations”.
Step 5: Stay audit-ready
Document all the results from steps 1–4 so they can be shown on request from the Bundesnetzagentur (see “Who Checks This? Enforcement, Fines, and the Bundesnetzagentur”) – including the six-month minimum retention of automatically generated logs.
Practice section: the roadmap is a living document, not a one-off project
The AI Act itself is still in motion – the high-risk deadlines for Annex III systems (December 2027) and embedded systems (August 2028) are still ahead, and the legal framework keeps being adjusted. So the roadmap doesn't belong in an archive – it belongs on a recurring review list: revisit it with every new AI tool, every substantial change to an existing system, and every new deadline. This classification doesn't replace case-by-case legal advice – for the concrete implementation in your own company, bring in a specialist.