EU AI Act and Document Pro­ces­sing: Why Insiders Customers Can Stay Confident

Does your company use AI for document or invoice processing—and do you know how these systems are clas­si­fied under the EU AI Act?

As of 2 August 2026, key pro­vi­sions of the AI Act become enforceable, and many orga­niza­tions are currently assessing which of their AI-supported business processes fall within its scope.

The assess­ment is based on the checklist „Con­for­mity Requi­re­ments under the AI Act“ and takes into account the European Com­mis­si­on’s gui­de­lines on the defi­ni­tion of AI systems as well as pro­hi­bited AI practices. This is therefore not a sub­jec­tive assess­ment, but a trans­pa­rent and well-docu­mented eva­lua­tion that customers can review if required.

How OmnIA Uses Arti­fi­cial Intel­li­gence

OmnIA automates the pro­ces­sing of incoming business documents. It applies machine learning methods to clearly defined, domain-specific tasks rather than operating as a general-purpose AI model that can be used for arbitrary purposes.

Where AI Is Used

OmnIA focuses on three core tasks:
Clas­si­fying incoming documents according to document or tran­sac­tion type, such as invoices, delivery notes, or contracts
Extra­c­ting and struc­tu­ring infor­ma­tion from unstruc­tured documents by trans­forming it into struc­tured data
Vali­da­ting and enriching the extracted data for down­stream business processes such as Purchase-to-Pay, inbound mail pro­ces­sing, and e‑invoicing

Its func­tion­a­lity is limited to these specific tasks. OmnIA does not make auto­no­mous decisions about natural persons.

What This Means for Insiders Customers

OmnIA qualifies as an AI system within the meaning of Article 3(1) of the EU AI Act, meaning that the regu­la­tion applies.

However, OmnIA does not involve pro­hi­bited AI practices such as mani­pu­la­tion, social scoring, or biometric cate­go­riza­tion.

Nor is it clas­si­fied as a high-risk AI system. It is neither a product-related high-risk system nor does it fall under any of the use cases listed in Annex III of the AI Act. Spe­ci­fi­cally, it has no con­nec­tion to biometric iden­ti­fi­ca­tion, critical infra­struc­ture, education, employ­ment, or essential public and private services.

Because OmnIA does not interact directly with indi­vi­duals and does not generate synthetic content, the trans­pa­rency obli­ga­tions under Article 50 also do not apply.

As a result, the use of OmnIA within the European Union is fully permitted under the AI Act.

For you as a customer, this means you are not required to comply with the obli­ga­tions appli­cable to high-risk AI systems, including:

Risk manage­ment
Technical docu­men­ta­tion
CE marking
Dedicated human oversight

Fur­ther­more, OmnIA does not make automated decisions producing legal or similarly signi­fi­cant effects on indi­vi­duals within the meaning of Article 22 GDPR, nor does it perform profiling.

Data pro­tec­tion and infor­ma­tion security are inde­pendently ensured through:

A Data Pro­ces­sing Agreement (DPA) with docu­mented technical and orga­niza­tional measures
ISO/IEC 27001 cer­ti­fi­ca­tion
BSI C5 Type 2 atte­sta­tion for the operation of our cloud services

The Obli­ga­tions That Still Apply

One obli­ga­tion applies regard­less of the AI system’s risk clas­si­fi­ca­tion and therefore also affects OmnIA customers: AI literacy under Article 4 of the AI Act.

Since 2 February 2025, indi­vi­duals who develop, operate, or use AI systems must possess an adequate level of AI literacy.

This obli­ga­tion applies to both providers and deployers. For OmnIA, this means it applies both to us as the provider and to you as the customer once you make the solution available to your own employees or customers.

You should therefore ensure that your users receive appro­priate AI training—even though OmnIA itself is not clas­si­fied as a high-risk AI system.

Con­clu­sion

Orga­niza­tions using OmnIA for document clas­si­fi­ca­tion, data extra­c­tion, or invoice pro­ces­sing currently operate within the minimal-risk category of the EU AI Act.

This means:

No addi­tional product com­pli­ance obli­ga­tions
No trans­pa­rency obli­ga­tions under Article 50
Clearly defined data pro­tec­tion measures
No automated decision-making about indi­vi­duals

The only com­pli­ance obli­ga­tion you actively need to address is ensuring suf­fi­cient AI literacy among your users.

The complete trans­pa­rency statement for OmnIA, including all assess­ment steps, is available as a download. Contact us if you require the assess­ment for your own com­pli­ance docu­men­ta­tion.

FAQs

Ist KI-gestützte Doku­men­ten­ver­ar­bei­tung auto­ma­tisch eine Hoch­ri­siko-KI nach dem AI Act?

L
K

Nein. Die Risi­koklasse hängt vom konkreten Anwen­dungs­fall ab, nicht allein vom Einsatz von KI. Doku­men­ten­ver­ar­bei­tung für Purchase-to-Pay, Post­ein­gang oder E‑Rechnung fällt nicht unter die Hoch­ri­siko-Anwen­dungs­fälle aus Anhang III der KI-VO, solange keine Ent­schei­dungen über Personen in sensiblen Bereichen wie Beschäf­ti­gung, Bildung oder grund­le­genden Diensten getroffen werden.

Gilt die EU-KI-Ver­ord­nung auch für OCR und Rech­nungs­er­ken­nung?

L
K

Ja, sobald Verfahren des maschi­nellen Lernens zum Einsatz kommen, gilt eine Lösung in der Regel als KI-System nach Art. 3 Nr. 1 KI-VO. Das bedeutet aber nicht auto­ma­tisch besondere Pflichten. Die Ein­stu­fung nach Risi­koklasse ent­scheidet, welche Anfor­de­rungen greifen.

Welche Pflichten bestehen bei KI-Com­pli­ance in der Doku­men­ten­ver­ar­bei­tung, wenn kein Hoch­ri­siko-System vorliegt?

L
K

Bei minimalem Risiko entfallen die beson­deren Pflichten für Hoch­ri­siko-KI wie Risi­ko­ma­nage­ment, tech­ni­sche Doku­men­ta­tion, CE-Kenn­zeich­nung oder mensch­liche Aufsicht. Bestehen bleibt die Pflicht zur KI-Kompetenz nach Art. 4 KI-VO, die für Anbieter und Betreiber aller Risi­koklassen gilt.

Was bedeutet die Ein­stu­fung als Hoch­ri­siko-KI für Unter­nehmen konkret?

L
K

Hoch­ri­siko-KI-Systeme unter­liegen unter anderem Pflichten zu Risi­ko­ma­nage­ment, Daten­qua­lität, tech­ni­scher Doku­men­ta­tion, Pro­to­kol­lie­rung, mensch­li­cher Aufsicht und CE-Kenn­zeich­nung. Diese Pflichten gelten für Anwen­dungs­fälle aus Anhang III der KI-VO, etwa in den Bereichen Biometrie, kritische Infra­struktur, Bildung, Beschäf­ti­gung oder grund­le­gende Dienste, nicht für die doku­ment­zen­trierte Auto­ma­ti­sie­rung, wie sie OmnIA bereit­stellt.

Wie ist OmnIA von Insiders Tech­no­lo­gies nach dem EU AI Act ein­ge­stuft?

L
K

OmnIA ist als KI-System mit minimalem Risiko ein­ge­stuft: kein Hoch­ri­siko-System, keine verbotene Praktik, keine beson­deren Trans­pa­renz­pflichten nach Art. 50. Der Einsatz in der EU ist unein­ge­schränkt zulässig. Die voll­stän­dige Ein­stu­fung mit allen Prüf­schritten doku­men­tiert das Infor­ma­ti­ons­blatt „Einsatz von Künst­li­cher Intel­li­genz und Ein­ord­nung nach der EU-KI-Ver­ord­nung“.