Industries We Serve
Applying responsible AI principles across diverse and critical sectors to drive innovation and create lasting value.
Finance
Credit scoring and insurance pricing sit in Annex III — and BaFin is already auditing AI as an ICT asset today.
Energy & Utilities
Safety components in grid and supply operation are named in Annex III, on top of an existing NIS2 duty.
Healthcare
Two different regimes and two different dates, decided by whether the AI is inside a regulated device.
Technology & SaaS
The earliest live duties of any sector here — transparency and GPAI obligations are enforceable now, not in 2027.
Real Estate
Tenant screening and financing pre-checks reach Annex III through access to essential private services.
Finance
Credit scoring and insurance pricing sit in Annex III — and BaFin is already auditing AI as an ICT asset today.
What is in scope, and how it is classified
- Creditworthiness assessment and credit scoring of natural persons is named in Annex III point 5(b). Risk assessment and pricing in life and health insurance is named alongside it.
- Fraud detection, AML transaction monitoring and internal model risk sit outside Annex III in most designs, and are reached instead through MaRisk and DORA.
- Article 6(3) allows a system listed in Annex III to fall outside the high-risk tier where it does not materially influence the outcome of a decision. Whether that applies is a per-system finding, documented rather than assumed.
The dates that apply
- 18 Dec 2025 DORA — BaFin guidance on ICT risks in the use of AI at financial entities (already applying)
- 29 Jul 2026 KI-MIG — Began applying, after publication in the Bundesgesetzblatt on 28 July 2026 (already applying)
- 2 Dec 2027 EU AI Act — High-risk duties for stand-alone Annex III systems
What a supervisor asks to see
- A conformity file per high-risk system: risk management, data governance, technical documentation, logging, and the human oversight actually in place.
- For BaFin under DORA, each AI system carried in the ICT asset inventory with lifecycle oversight — data acquisition through to retirement — and reflected in the Register of Information.
- Evidence that GDPR, DORA and AI Act artifacts exist separately. An Article 35 DPIA is not a conformity file, and neither discharges the other.
What Alleina provides for it
Two traps this sector meets most often. A substantial modification restarts the conformity clock, so a system relying on the transitional treatment of models already on the market can lose it through an ordinary retraining. And where a third-party vendor's conformity documentation is incomplete, the obligations of the deploying institution do not fall away — passing documentation along does not pass liability along with it.
Energy & Utilities
Safety components in grid and supply operation are named in Annex III, on top of an existing NIS2 duty.
What is in scope, and how it is classified
- Annex III point 2 names AI used as a safety component in the management and operation of critical digital infrastructure and of the supply of water, gas, heating and electricity.
- Load and demand forecasting, predictive maintenance and trading optimisation are not automatically outside that. Whether a model is a safety component turns on what fails if it is wrong, which is a scoping question rather than a settled exemption.
- German energy suppliers also carry duties under the EnWG that attach to the process rather than to the model — price-change transparency and balancing-group responsibility among them.
The dates that apply
- 6 Dec 2025 NIS2 / BSIG — The German implementation act began applying, with no transition period (already applying)
- 29 Jul 2026 KI-MIG — Began applying, after publication in the Bundesgesetzblatt on 28 July 2026 (already applying)
- 2 Dec 2027 EU AI Act — High-risk duties for stand-alone Annex III systems
What a supervisor asks to see
- A defensible record of which models were assessed as safety components and which were not, with the reasoning, dated.
- For operators in scope of NIS2, cybersecurity risk-management measures and the staged incident-reporting timetable, with BSI registration complete.
- Continuity between the two: an AI incident in a control system is frequently reportable under NIS2 before any AI Act duty is engaged.
What Alleina provides for it
Healthcare
Two different regimes and two different dates, decided by whether the AI is inside a regulated device.
What is in scope, and how it is classified
- AI that is part of a device regulated under the MDR or IVDR is reached through Annex I, and its conformity runs through the existing product-safety route and its notified body rather than beside it.
- Stand-alone health AI that is not a medical device — triage, eligibility, and access to essential healthcare services — is reached instead through Annex III, on the earlier date.
- The same clinical idea can land on either side depending on its intended purpose, which is the classification question rather than a formality.
The dates that apply
- 25 May 2018 GDPR — Began applying across the EU (already applying)
- 29 Jul 2026 KI-MIG — Began applying, after publication in the Bundesgesetzblatt on 28 July 2026 (already applying)
- 2 Aug 2028 EU AI Act — High-risk duties for Annex I systems embedded in regulated products
What a supervisor asks to see
- For Annex I devices, AI Act evidence folded into the existing technical documentation and quality management system rather than filed as a parallel set.
- For Annex III systems, a conformity file in its own right, and a fundamental rights impact assessment where the deployer is a public body or a provider of essential services.
- Article 9 GDPR special-category processing documented independently of both.
What Alleina provides for it
The two dates are 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in an Annex I product. A portfolio containing both carries both.
Technology & SaaS
The earliest live duties of any sector here — transparency and GPAI obligations are enforceable now, not in 2027.
What is in scope, and how it is classified
- A software company shipping a feature built on a model is frequently a provider rather than only a deployer, and the provider duties are the heavier set.
- Article 50 transparency applies now: disclosure that a person is interacting with an AI system, and marking of AI-generated content. Obligations for general-purpose AI models have applied since August 2025.
- Recruiting and HR features are named in Annex III point 4, which places them in the high-risk tier on the 2027 date rather than the live one.
The dates that apply
- 29 Jul 2026 KI-MIG — Began applying, after publication in the Bundesgesetzblatt on 28 July 2026 (already applying)
- 2 Aug 2026 EU AI Act — General application, including Article 50 transparency duties (already applying)
- 2 Dec 2026 Digital Omnibus on AI — New Article 5 prohibitions on AI generating non-consensual intimate imagery or child sexual abuse material
What a supervisor asks to see
- Disclosure and content-marking implemented in the product and evidenced, not described in a policy.
- For general-purpose models, technical documentation, a training-data summary and a copyright policy.
- An inventory that distinguishes provider from deployer role per system, because the duties differ and one organisation is routinely both.
What Alleina provides for it
This is the sector where the deferral changes least. Transparency, prohibitions and general-purpose model duties were untouched by the Omnibus and are enforceable today.
Real Estate
Tenant screening and financing pre-checks reach Annex III through access to essential private services.
What is in scope, and how it is classified
- Annex III point 5 names AI used to evaluate creditworthiness or to determine eligibility for essential private services. Tenant screening, affordability scoring and mortgage or financing pre-checks are the shapes this takes in property.
- Automated valuation models used for pricing rather than for a decision about a named person are a different question, and are scoped rather than assumed in or out.
- In Germany the AGG already bars discriminatory selection in letting today, independently of anything the AI Act adds.
The dates that apply
- 25 May 2018 GDPR — Began applying across the EU (already applying)
- 29 Jul 2026 KI-MIG — Began applying, after publication in the Bundesgesetzblatt on 28 July 2026 (already applying)
- 2 Dec 2027 EU AI Act — High-risk duties for stand-alone Annex III systems
What a supervisor asks to see
- Where a screening decision is automated, the Article 22 GDPR position documented — legal basis, meaningful information about the logic, and the route to human intervention. This applies now, not from 2027.
- Fairness testing across protected characteristics, retained with dates, which is also what an AGG challenge asks for.
- A record of human review that shows a person could and did change an outcome, rather than a rubber stamp.
What Alleina provides for it
The AI Act work here extends controls a letting or financing business is already expected to operate under the GDPR and the AGG. It is rarely a new programme.
General information about the instruments named, not legal advice, and not a substitute for your own legal watch. Whether a particular system falls in scope depends on its facts.