Artificial Intelligence Law in Austria – EU AI Act, Data, IP & Contracts

The EU AI Act has been broadly applicable since 2 August 2026, with specific obligations and transition periods continuing to phase in. Businesses need to identify not only whether they use AI, but which legal role they occupy, which risk category applies and what obligations attach to the specific AI system or use case.

We advise AI providers, integrators, SaaS companies and businesses deploying AI on compliance, product design and contracts. The analysis brings together the AI Act, GDPR, intellectual property, trade secrets, liability and commercial risk.

Legal status – August 2026: The AI Act is broadly applicable from 2 August 2026, while certain high-risk obligations have later application dates. The exact timeline depends on the system and use case.

Key areas of advice

  • EU AI Act Compliance and AI Value-Chain Roles
  • AI Risk Classification and High-Risk Systems
  • Transparency for Chatbots, Deepfakes and AI-Generated Content
  • AI and Data Privacy – GDPR, Profiling and Training Data
  • AI and Intellectual Property
  • AI Contracts, Procurement and Liability

EU AI Act Compliance and AI Value-Chain Roles

A first step is to identify the relevant role: provider, deployer, importer, distributor or another participant in a more complex AI value chain. White-labelling, fine-tuning or substantial modification can alter the legal position compared with the terminology used in a procurement contract.

AI Risk Classification and High-Risk Systems

We assess prohibited practices, potential high-risk classification and other transparency or governance obligations. Different categories of high-risk systems remain subject to specific application dates, so every product should maintain a current compliance timeline.

Transparency for Chatbots, Deepfakes and AI-Generated Content

Key AI Act transparency rules apply from 2 August 2026, including obligations relevant to certain direct AI interactions and certain synthetic or manipulated content. Deepfakes and some AI-generated public-interest content may require specific disclosure.

We help translate these requirements into UX notices, content workflows, documentation and responsibility matrices.

AI and Data Privacy – GDPR, Profiling and Training Data

AI projects may process personal data in training sets, prompts, logs, outputs and evaluation data. We assess legal bases, purpose limitation, minimisation, transparency, profiling, data-subject rights, DPIAs and use of external AI vendors.

AI and Intellectual Property

AI projects raise questions about training data, software licences, protected inputs, generated outputs, trademarks, trade secrets and open source. Contracts should define permitted data use and allocate rights and risks in models, prompts, adaptations and outputs.

AI Contracts, Procurement and Liability

AI agreements should address system scope, model changes, data use, documentation, security, audit, subprocessors, output rights, IP, regulatory assistance and liability. Enterprise customers increasingly need evidence that vendors can support their own compliance obligations.

AI Governance and Internal AI Policies

Businesses should define which AI tools employees may use, which data can be entered, when human review is required and how confidentiality, copyright and privacy risks are controlled. We develop risk-based internal policies and approval processes.