EU AI Act · Legal
EU AI Act for legal teams and general counsel
Management carries personal liability. The EU AI Act requires auditable documentation and clear accountability – and where AI vendors process personal data, a data processing agreement under Art. 28 GDPR applies. SimpleAct keeps the materials for security and procurement reviews in one place, kept current through the audit history.
Typical situations in legal departments
- Procurement asks for DPA, AVV and subprocessor lists – nearly impossible without a structured data basis
- Regulators demand evidence: which AI system, what risk, who is responsible?
- Customer contracts contain AI compliance clauses – internally the overview is missing
- Liability exposure from unknown or undocumented AI systems inside the organisation
- External legal advisors produce opinions but no defensible operational documentation
What this looks like in practice
Procurement receives a request: which AI systems process personal data, is there a DPA in place, and where does the data reside? The inventory holds provider, data category and DPA status per system; the compliance report exports as PDF and the DPA documents live in the Trust Centre. The answer rests on one record instead of an email chain across departments.
What SimpleAct delivers for legal teams
- Audit-ready documentation
- All AI systems centrally captured, risks classified, changes traceable in an append-only audit log – exportable as PDF or DOCX for regulators and internal reviews.
- DPA / AVV and subprocessors
- Data processing agreement under Art. 28 GDPR, SLA, and subprocessor list available. Hosting in Germany, no third-country transfer.
- Clear accountability
- RBAC roles define who is responsible for which AI systems. Owners, reviewers, and approvers are documented per system.
- Annex IV technical documentation
- For high-risk AI systems, SimpleAct generates the Annex IV Technical Documentation directly from the inventory – no manual effort.
What your legal department gets
- DPA/AVV under Art. 28 GDPR – available immediately
- Subprocessor list fully documented
- Annex IV technical documentation for high-risk AI
- Exportable compliance reports (PDF/DOCX)
- Append-only audit log for regulatory requests
- Security whitepaper with technical and organisational measures (TOM)
Frequently asked questions from legal
Who is liable if an AI system violates the EU AI Act?
Deployers are liable for correct use. For high-risk AI, documentation, risk assessment, and human oversight are mandatory. SimpleAct provides the foundation – legal classification remains with your team.
Which documents does our procurement review need?
SLA, DPA (incl. subprocessor list), security whitepaper and architecture overview – all available at /security and /legal/avv-dpa.
Does SimpleAct cover GDPR requirements too?
SimpleAct is built with GDPR orientation. The intersection of GDPR and the EU AI Act – e.g. DPIAs for high-risk AI – is structurally supported, but does not replace legal advice.
When must companies be EU AI Act compliant?
The main deadline for high-risk AI under Annex III is 2 December 2027 (postponed by the Digital Omnibus). Art. 50 transparency obligations already apply from 2 August 2026; product-integrated AI under Annex I (e.g. medical devices) has until 2 August 2028. Now is the right time to build the inventory – regardless of your specific deadline.
Can we use SimpleAct reports as evidence for customers?
Yes. Compliance reports and Trust Centre documents are explicitly designed to document your implementation status for customers, partners, and regulators. They do not replace a conformity assessment.
Compliance documentation that withstands audits
Start with a free trial or request the procurement documents directly.
View Trust Centre