Implementing the AI Act
The EU AI Act (Regulation (EU) 2024/1689) confronts companies with two tasks: they have to classify their AI systems, document measures and build AI literacy – and they have to be able to receive reports of infringements of the regulation. preeco supports both sides with two products.
Requirements
What the AI Act Triggers Inside a Company
The application dates are staggered: prohibitions and AI literacy have applied since 2 February 2025, the rules for general-purpose AI models since 2 August 2025, and the majority of the regulation since 2 August 2026.
Classify AI Systems
Every AI system in use is assigned to one of the regulation's risk classes – minimal, limited, high or unacceptable. Purpose, area of use, affected persons and the reasons for the classification are documented in a traceable way.
Document Measures
Dedicated technical and organisational measures are recorded for AI systems – from bias avoidance and explainability to data quality, human oversight and monitoring of system performance.
Receive Reports of AI Act Infringements
Article 87 of the AI Act declares the EU Whistleblower Directive (2019/1937) applicable to the reporting of infringements of the regulation. This creates a case type in the reporting office that was not yet foreseen when many reporting channels were set up.
Build AI Literacy
Article 4 of the regulation requires a sufficient level of AI literacy among everyone working with AI systems. People who understand AI also recognise when something is wrong with how it is used – training and reporting channel work together.
What Article 87 Means for an Existing Reporting Office
Article 87 of the AI Act contains no procedural rules of its own. For reports of infringements of the regulation it refers to the EU Whistleblower Directive (2019/1937) – that is, to the same protective mechanisms and the same processes that reporting offices already know. Whether and to what extent this creates a need for action in your company is a legal assessment you make together with your legal advisors. Organisationally, it comes down to a manageable set of steps:
Create the category: a dedicated area of application for reports about the use of AI, so that such reports do not disappear under "Other".
Clarify responsibilities: the reporting office handles the case, but the technical assessment often sits elsewhere – with IT, data protection or the role responsible for AI. That handover belongs in the checklist.
Deadlines stay the same: acknowledgement of receipt within 7 days, feedback within 3 months – even if the technical review of an AI system takes longer. A status update keeps the communication open.
Review the form: people who encounter AI systems in production, logistics or administration do not report in technical language. A multilingual, low-threshold form decides whether the report is ever written at all.
Brief the case handlers: whoever receives reports should understand what AI systems in the workplace involve – this is where AI literacy under Article 4 feeds directly into the work of the reporting office.
The timeline for parts of the high-risk regime is politically contested and subject to the European Commission's Digital Omnibus proposals. Companies should follow the state of the legislative process rather than rely on a single date.
FAQ
Frequently Asked Questions
Article 87 of the AI Act declares the EU Whistleblower Directive (2019/1937) applicable to the reporting of infringements of the regulation and to the protection of reporting persons. It therefore does not create a separate procedure but builds on the reporting routes and protective mechanisms already established. This provision belongs to the part of the regulation that has applied since 2 August 2026.
Whether and to what extent action is required in your company is a legal assessment you make together with your legal advisors. Technically, the adjustment is uncritical: in preeco | whistleblower you add an additional area of application with its own checklist, without changing the existing reporting channel, its URL or its deadlines. Freely definable categories are already part of the product.
Two products cover two different tasks. preeco | data protection supports the classification of AI systems by risk class, the documentation of AI-specific technical and organisational measures, and AI literacy through included online training. preeco | whistleblower provides the reporting channel through which reports of infringements arrive confidentially and optionally anonymously and are processed in a structured way.
No. Because Article 87 of the AI Act refers to the EU Whistleblower Directive, the same processes apply as for other protected reports: acknowledgement of receipt within seven days, feedback within three months. preeco | whistleblower monitors these deadlines automatically and documents the entire communication in a traceable way – regardless of which category a report is assigned to.
No, the AI Act applies alongside data protection law. Anyone processing personal data in or with an AI system still needs a legal basis under Art. 6 GDPR, must observe purpose limitation and data minimisation, fulfil data subject rights and, where applicable, carry out a data protection impact assessment. In preeco | data protection, the AI compliance check and the processing activity are therefore linked to each other.
Implement the AI Act with preeco
In a free consultation, learn how to document AI systems in a structured way and handle reports of AI Act infringements in your reporting channel.