Contact Us

Is Your Company Compliant with Current Regulations?

Compliance obligations are expanding rapidly — data protection, anti-money laundering and, most recently, artificial intelligence regulation. Below we provide a general framework; we would be pleased to assess your company's specific situation together with you.

(Video coming soon — contact us for a brief introductory meeting.)

What Is Changing in Corporate Compliance?

In recent years, the compliance burden on companies has expanded rapidly: data protection under the GDPR and KVKK, anti-money laundering (AML) obligations, supply chain due diligence (LkSG-type regulations) and whistleblower reporting mechanisms now directly concern mid-sized companies as well.

The newest and most comprehensive addition is the EU Artificial Intelligence Act. For companies using AI tools or offering them to their clients, new obligations are entering into force, graduated according to the area of use.

AI Obligations in Germany

As an EU regulation, the EU AI Act (Regulation (EU) 2024/1689) applies directly in all Member States, including Germany; in addition, a national implementing act (the draft KI-MIG) establishing the supervisory structure is being prepared. This act does not create new obligations — the substantive rules derive from the EU regulation; however, the Federal Network Agency (Bundesnetzagentur) is envisaged as the competent market surveillance authority in Germany.

The regulation enters into force in stages: in February 2025, certain AI practices (e.g. social scoring) were prohibited and basic AI literacy for employees became mandatory. In August 2025, the rules for general-purpose AI models took effect. For high-risk systems and transparency obligations (e.g. informing users that they are communicating with a chatbot, labelling AI-generated content), the envisaged date was August 2026; however, a revision process (the Digital Omnibus) providing for postponements is under way — the current timetable may change.

The administrative fines envisaged are substantial: up to 7% of global turnover for prohibited practices and up to 3% for infringements involving high-risk systems. The German implementing act additionally provides for separate fines for breaches of cooperation and information obligations.

What Should Be Done?

The approach varies from company to company, but the general framework consists of three steps: taking an inventory of the AI tools in use, classifying those tools by risk (prohibited / high-risk / subject to transparency obligations / low-risk), and establishing a compliance process and documentation accordingly.

01

Inventory

Together we identify which AI tools are used in your company, where and for what purpose.

02

Risk Classification

We assess each tool against the risk categories of the EU AI Act.

03

Compliance Plan

We prepare a practicable compliance and documentation plan tailored to your company.

How Can We Support You?

At Kurtoğlu Legal, we support you in reviewing your existing compliance obligations (including GDPR/KVKK and AML) and in establishing an up-to-date compliance framework that also covers your use of AI. Contact us for an initial assessment meeting.

Request a consultation

The information on this page is for general information purposes only and does not constitute legal advice; the implementation timetable of the EU AI Act may change due to ongoing revision procedures. Please contact us for an assessment tailored to your company.