EU AI Act: What companies need to consider when choosing an AI gateway
Compliance & Data Protection

Dominik Keller

The EU AI Act (Regulation (EU) 2024/1689) is the EU's first comprehensive AI law. It classifies AI systems according to risk and also holds companies accountable that only deploy AI. This checklist shows what you should look out for when choosing an AI gateway to ensure that the decision is AI-Act-proof.
Key Takeaways
The EU AI Act (Reg. 2024/1689) applies in stages; bans, GPAI and transparency obligations are already applicable.
The Digital Omnibus (Reg. 2026/1744, in force since 27/07/2026) postpones high-risk obligations to 02/12/2027 (Annex III) and 02/08/2028 (Annex I) respectively.
The transparency obligations under Art. 50 were not postponed – they have applied to most gateway use cases since 02/08/2026.
A gateway is the most cost-effective place to centrally fulfill labeling, logging, and model provenance.
There is this moment in almost every company that wants to introduce AI: someone from the legal department asks "Is this actually AI-Act-compliant?" – and the room goes quiet. The EU AI Act is no longer a distant dream, but applicable law with staggered implementation deadlines. Anyone choosing an AI gateway now should not only think about model quality and price, but also about the question: Will this still stand up to an audit in two years' time?
What the AI Act means in practice for gateway usage
The AI Act classifies AI systems according to risk levels – from minimal to unacceptable. For most business use cases (customer service chatbots, internal assistants, document analysis), you usually end up in the "limited risk" or "high risk" category, depending on the area of application. Crucially, the responsibility lies not only with the model provider, but also with you as the company deploying the technology.
An AI gateway sits in a strategically important position – it is the central transit point for all AI requests. This makes it the ideal place to technically implement compliance requirements, instead of retrofitting them individually in ten different applications.
The AI Act entered into force on August 1, 2024, and applies in stages: banned practices have been prohibited since February 2, 2025, obligations for general-purpose AI models (GPAI) have applied since August 2, 2025, and transparency obligations under Art. 50 since August 2, 2026. Violations of banned practices can be punished with fines of up to 35 million euros or 7% of global annual turnover (Art. 99, Regulation (EU) 2024/1689).
Important since July 2026: The Digital Omnibus postpones the high-risk deadlines
Anyone still planning with August 2, 2026, as the key date for high-risk systems is calculating with an outdated deadline. Regulation (EU) 2026/1744 ("Digital Omnibus on AI", adopted on July 8, 2026, published in the Official Journal on July 24, 2026, in force since July 27, 2026) has pushed back the deadlines for high-risk AI systems. This is justified by the fact that the harmonized technical standards are not yet ready and the designation of notified bodies is lagging behind.
Obligations | Original | Now applicable |
|---|---|---|
Banned practices (Art. 5) | February 2, 2025 | unchanged |
GPAI obligations (Art. 53) | August 2, 2025 | unchanged |
Transparency obligations (Art. 50) | August 2, 2026 | unchanged |
High-risk under Annex III (Art. 6 para. 2) | August 2, 2026 | December 2, 2027 |
High-risk under Annex I (Art. 6 para. 1) | August 2, 2027 | August 2, 2028 |
For gateway selection, this means two things. First: the time pressure for high-risk applications is lower than is still being communicated in many places. Second – and this is often overlooked: the transparency obligations under Art. 50 were not postponed. Anyone running a chatbot or delivering AI-generated content has been under obligation since August 2, 2026, regardless of the risk class. It is precisely this obligation that affects the vast majority of gateway use cases.

The Checklist: What to look for when choosing a gateway
AI Act Requirement | What the gateway must be able to do |
|---|---|
Transparency obligation | Label and document which model responds when |
Traceability | End-to-end logging of every request and response |
Model provenance | Clarity on which model is actually responding – no silent model swapping |
Data processing location | EU server location (GDPR applies in parallel) |
Human oversight | Technical capability for intervention, approvals, and escalation |
Can transparency obligations be met?
The AI Act requires that users know they are interacting with an AI for certain applications. A good gateway should allow you to implement this in a clean technical manner and document which model generated which response and when.
Traceability and logging
Can you prove in case of doubt which request led to which response, with which model, and at what time? Without continuous logging, any later audit becomes a blind flight.
Model selection and provenance transparency
Do you know which model actually responds behind your gateway? Swapping models without notice is common practice among some providers – for compliance purposes, this is a problem because risk assessment and model behavior differ depending on the provider.
Data processing location
Even though the AI Act primarily targets the AI system itself, the GDPR remains in force in parallel. A gateway without an EU server location creates two construction sites at the same time instead of one. We have broken down in detail how to use US models in Europe in a legally compliant manner in our article Using OpenAI, Claude, and Gemini in Europe.
Possibility of human oversight
For higher-risk use cases, the AI Act requires mechanisms for human control. Your gateway should technically allow you to integrate interventions, approvals, or escalations – and not just as a late custom development.
Why this matters for your gateway decision today
The most common mistake: companies choose a gateway based on price and model selection, and compliance questions only arise when the staggered AI Act deadlines approach. Then you are faced with the choice of either rebuilding the entire system again or continuing to work with a compliance risk that could actually have been avoided.
A gateway built from the ground up in Europe and designed for European regulations saves exactly this second rebuild. kontinent.ai was developed with this premise: EU hosting, continuous traceability logging (metadata), transparent model provenance, and a DPA that matches the GDPR – not as an afterthought, but as a core framework. Our Comparison of GDPR-compliant LLM routers shows how this compares to other EU routers.
Frequently Asked Questions
Does the EU AI Act also apply to small businesses?
Yes, in principle it applies regardless of the size of the company. The specific obligations depend on the risk class of the AI application used, not on the company size.
From when do I have to comply with the AI Act?
In stages, depending on the risk category. Prohibitions have applied since February 2, 2025, GPAI obligations since August 2, 2025, and transparency obligations under Art. 50 since August 2, 2026. Since the Digital Omnibus, December 2, 2027, applies to high-risk systems under Annex III, and August 2, 2028, under Annex I. Anyone introducing AI systems now should nevertheless think about the requirements from the start, instead of retrofitting later.
Is GDPR compliance not enough?
No. The GDPR regulates the processing of personal data – this includes a proper data processing agreement for AI tools. The AI Act additionally regulates the AI system itself – such as transparency obligations, risk classification, and oversight mechanisms. Both frameworks apply in parallel.
Do I have to check AI Act compliance for each model individually?
A central gateway can bundle this check instead of performing it separately for each individual application – this is one of the practical benefits of a well-configured gateway.
What are the penalties for violating the EU AI Act?
Staggered fines apply depending on the violation. For banned practices, they can be up to 35 million euros or 7% of global annual turnover (Art. 99). For other violations, lower but still significant ranges apply – a reason to think about compliance early on.
Is a gateway with a US server location automatically non-compliant with the AI Act?
Not automatically, but it complicates matters: alongside AI Act obligations, the GDPR applies in parallel, and a data processing location outside the EU creates additional assessment and documentation effort. An EU location reduces both construction sites to one.
Sources
Regulation (EU) 2024/1689 (AI Act) – EUR-Lex
Regulation (EU) 2026/1744 (Digital Omnibus on AI) – EUR-Lex, in force since 27/07/2026
EDPB, Opinion 28/2024 on AI models (18/12/2024)
Regulation (EU) 2016/679 (GDPR) – EUR-Lex
As of: August 27, 2026 · kontinent.ai. Legal status checked against EUR-Lex; no legal advice.