EU AI Act and Document Processing: Why Insiders Customers Can Stay Confident
Does your company use AI for document or invoice processing—and do you know how these systems are classified under the EU AI Act?
As of 2 August 2026, key provisions of the AI Act become enforceable, and many organizations are currently assessing which of their AI-supported business processes fall within its scope.
The assessment is based on the checklist „Conformity Requirements under the AI Act“ and takes into account the European Commission’s guidelines on the definition of AI systems as well as prohibited AI practices. This is therefore not a subjective assessment, but a transparent and well-documented evaluation that customers can review if required.
How OmnIA Uses Artificial Intelligence
OmnIA automates the processing of incoming business documents. It applies machine learning methods to clearly defined, domain-specific tasks rather than operating as a general-purpose AI model that can be used for arbitrary purposes.
Where AI Is Used
OmnIA focuses on three core tasks:
Classifying incoming documents according to document or transaction type, such as invoices, delivery notes, or contracts
Extracting and structuring information from unstructured documents by transforming it into structured data
Validating and enriching the extracted data for downstream business processes such as Purchase-to-Pay, inbound mail processing, and e‑invoicing
Its functionality is limited to these specific tasks. OmnIA does not make autonomous decisions about natural persons.
What This Means for Insiders Customers
OmnIA qualifies as an AI system within the meaning of Article 3(1) of the EU AI Act, meaning that the regulation applies.
However, OmnIA does not involve prohibited AI practices such as manipulation, social scoring, or biometric categorization.
Nor is it classified as a high-risk AI system. It is neither a product-related high-risk system nor does it fall under any of the use cases listed in Annex III of the AI Act. Specifically, it has no connection to biometric identification, critical infrastructure, education, employment, or essential public and private services.
Because OmnIA does not interact directly with individuals and does not generate synthetic content, the transparency obligations under Article 50 also do not apply.
As a result, the use of OmnIA within the European Union is fully permitted under the AI Act.
For you as a customer, this means you are not required to comply with the obligations applicable to high-risk AI systems, including:
Risk management
Technical documentation
CE marking
Dedicated human oversight
Furthermore, OmnIA does not make automated decisions producing legal or similarly significant effects on individuals within the meaning of Article 22 GDPR, nor does it perform profiling.
Data protection and information security are independently ensured through:
A Data Processing Agreement (DPA) with documented technical and organizational measures
ISO/IEC 27001 certification
BSI C5 Type 2 attestation for the operation of our cloud services
The Obligations That Still Apply
One obligation applies regardless of the AI system’s risk classification and therefore also affects OmnIA customers: AI literacy under Article 4 of the AI Act.
Since 2 February 2025, individuals who develop, operate, or use AI systems must possess an adequate level of AI literacy.
This obligation applies to both providers and deployers. For OmnIA, this means it applies both to us as the provider and to you as the customer once you make the solution available to your own employees or customers.
You should therefore ensure that your users receive appropriate AI training—even though OmnIA itself is not classified as a high-risk AI system.
Conclusion
Organizations using OmnIA for document classification, data extraction, or invoice processing currently operate within the minimal-risk category of the EU AI Act.
This means:
No additional product compliance obligations
No transparency obligations under Article 50
Clearly defined data protection measures
No automated decision-making about individuals
The only compliance obligation you actively need to address is ensuring sufficient AI literacy among your users.
The complete transparency statement for OmnIA, including all assessment steps, is available as a download. Contact us if you require the assessment for your own compliance documentation.
FAQs
Ist KI-gestützte Dokumentenverarbeitung automatisch eine Hochrisiko-KI nach dem AI Act?
Nein. Die Risikoklasse hängt vom konkreten Anwendungsfall ab, nicht allein vom Einsatz von KI. Dokumentenverarbeitung für Purchase-to-Pay, Posteingang oder E‑Rechnung fällt nicht unter die Hochrisiko-Anwendungsfälle aus Anhang III der KI-VO, solange keine Entscheidungen über Personen in sensiblen Bereichen wie Beschäftigung, Bildung oder grundlegenden Diensten getroffen werden.
Gilt die EU-KI-Verordnung auch für OCR und Rechnungserkennung?
Ja, sobald Verfahren des maschinellen Lernens zum Einsatz kommen, gilt eine Lösung in der Regel als KI-System nach Art. 3 Nr. 1 KI-VO. Das bedeutet aber nicht automatisch besondere Pflichten. Die Einstufung nach Risikoklasse entscheidet, welche Anforderungen greifen.
Welche Pflichten bestehen bei KI-Compliance in der Dokumentenverarbeitung, wenn kein Hochrisiko-System vorliegt?
Bei minimalem Risiko entfallen die besonderen Pflichten für Hochrisiko-KI wie Risikomanagement, technische Dokumentation, CE-Kennzeichnung oder menschliche Aufsicht. Bestehen bleibt die Pflicht zur KI-Kompetenz nach Art. 4 KI-VO, die für Anbieter und Betreiber aller Risikoklassen gilt.
Was bedeutet die Einstufung als Hochrisiko-KI für Unternehmen konkret?
Hochrisiko-KI-Systeme unterliegen unter anderem Pflichten zu Risikomanagement, Datenqualität, technischer Dokumentation, Protokollierung, menschlicher Aufsicht und CE-Kennzeichnung. Diese Pflichten gelten für Anwendungsfälle aus Anhang III der KI-VO, etwa in den Bereichen Biometrie, kritische Infrastruktur, Bildung, Beschäftigung oder grundlegende Dienste, nicht für die dokumentzentrierte Automatisierung, wie sie OmnIA bereitstellt.
Wie ist OmnIA von Insiders Technologies nach dem EU AI Act eingestuft?
OmnIA ist als KI-System mit minimalem Risiko eingestuft: kein Hochrisiko-System, keine verbotene Praktik, keine besonderen Transparenzpflichten nach Art. 50. Der Einsatz in der EU ist uneingeschränkt zulässig. Die vollständige Einstufung mit allen Prüfschritten dokumentiert das Informationsblatt „Einsatz von Künstlicher Intelligenz und Einordnung nach der EU-KI-Verordnung“.
