Exclusive Student Offer

Prime for Young Adults

Get a 6-month trial with premium college perks & fast delivery.

Start Free Trial
Listen Anywhere

Audible Standard Trial

Get 30 days of audiobooks free. Cancel anytime, keep your books.

Claim Free Books

The Digital Omnibus has postponed deadlines for high-risk AI, yet it hasn’t alleviated the responsibilities associated with AI deployment. Starting from August 2, 2026, the transparency obligations under the EU AI Act remain pertinent. SAP customers who integrate Joule or develop their agents in business processes must therefore evaluate their roles, specific use cases, and the obligations arising from those.

The Misunderstanding Surrounding the Deadline Extension

Many SAP departments mistakenly infer from the Digital Omnibus message that AI regulations have been postponed until 2027. This conclusion can be misleading. While the application of essential obligations for high-risk AI—those categorized under Annex III—has indeed been shifted to December 2, 2027, and for certain AI in a product context to August 2, 2028, the transparency obligations outlined in Article 50 of the EU AI Act take effect much earlier. This means that companies must adapt to transparency requirements starting from August 2, 2026, for systems already in use. There’s also a transition period until December 2, 2026, for technical, machine-readable labeling of generated content that came into circulation before this date.

Implications for SAP Customers

For those involved in providing or operating an AI system, it’s crucial to examine whether individuals interacting with that AI need to be informed and if special transparency requirements apply to generated or manipulated content. For instance, when using a Joule interface or a self-developed agent, there should be clear indications such as: “You are interacting with an AI-driven assistant. Please verify the outcomes before making any business decisions.” Furthermore, specific labeling or disclosure obligations could apply to generated or modified images, audio, and video content.

Understanding Provider vs. Operator Responsibilities

Responsibilities differ significantly between those who develop AI systems and those who operate them. SAP typically acts as the provider for features under Joule, while customers assume the role of an operator when deploying Joule or their self-developed agents within their operations. The obligations arising from these roles depend on use cases, inherent risks, and categorization as either provider or operator.

Steps for Compliance with the EU AI Act

Now is the time for SAP customers to take action regarding the EU AI Act. Here are four essential steps to consider:

Create Transparency in AI Landscape

Businesses should begin by documenting where Joule is utilized and what self-developed agents are created via Joule Studio. It’s essential to clarify who is responsible for each use case, what data is being utilized, what actions the agent is permitted to execute, and whether people or critical business processes are affected.

Legal and Organizational Classification of Use Cases

It’s not prudent to classify every Joule usage hastily as high-risk AI. Instead, organizations should thoroughly assess their role as a provider or operator, specific purposes, risk classifications, and the relevant transparency obligations. Here, Article 50 of the EU AI Act is vital, addressing the need for disclosure about AI interactions and certain labeling obligations for any generated or manipulated content.

Implement a Risk-Based Approval and Control System

For agents accessing corporate data or making business-critical decisions, companies need to develop a risk-based approval and control framework. This should include clear permissions, documented approvals, logging policies, escalation protocols, and, where necessary, human oversight checkpoints.

Boost AI Literacy Among Employees

Ensuring that employees who employ or supervise AI systems possess adequate AI knowledge is crucial. This doesn’t necessarily require a certification program for everyone but should focus on target-group-specific training. Staff must learn to interpret results appropriately, control data access and integrations, evaluate risks, and understand their roles in oversight.

The Role of the SAP AI Agent Hub

The SAP AI Agent Hub can serve as a foundational technical resource for the first three action points. SAP is establishing this hub as a vendor-neutral solution for discovery, inventory, and governance of agents and Model Co-Pilot (MCP) servers. While it aids in structured assessments, including risk classification and compliance, companies still hold the ultimate responsibility for the acceptance of agents and determining acceptable risk levels.

In conclusion, businesses must not view the shift in deadlines as an opportunity for complacency. The urgency of addressing transparency obligations should prompt action now, emphasizing the development of robust AI governance as an ongoing need in complex operational landscapes.

Get Audible 30-Day Free Trial

As an Amazon Associate, we earn from qualifying purchases.