The EU AI Act and Document Processing: Why Insiders' Customers Can Rest Easy

    Published: July 29, 2026

    Last update: September 15, 2026

    Does your company use AI for document or invoice processing—and do you know how these systems are classified under the EU AI Act? Enforcement of key obligations under the AI Regulation will begin on August 2, 2026, and many companies are currently assessing which of their AI-powered processes are affected.

    We’ve already conducted this review for our OmnIA customers. The result, documented in a dedicated information sheet: OmnIA falls into the safest category. The assessment is based on the “Conformity Requirements from the AI Regulation” checklist and takes into account the European Commission’s guidelines on the definition of AI systems as well as prohibited practices. It is therefore not a gut decision, but is transparently justified, and customers can review it if needed.

    How OmnIA Uses Artificial Intelligence

    OmnIA automatically processes incoming business documents. In doing so, it uses machine learning methods for narrowly defined, domain-specific tasks—not for a general-purpose AI model that could be used arbitrarily.

    Where the AI Actually Works

    Three tasks are central:

    • Classifying incoming documents by document or transaction type, such as invoices, delivery notes, or contracts
    • Extracting and structuring content from unstructured documents—that is, converting it into structured data
    • Validating and enriching the recognized data for further processing in business processes such as purchase-to-pay, incoming mail, or e-invoicing.

    The scope of functionality is limited to these tasks. OmnIA does not make independent decisions regarding natural persons.

    What this means for Insiders’ customers

    OmnIA is an AI system as defined in Article 3(1) of the AI Regulation; therefore, the Regulation applies. Prohibited practices such as manipulation, social scoring, or biometric categorization do not occur. OmnIA also does not qualify as high-risk AI: There is neither a product-related high-risk category nor a use case listed in Annex III—meaning no involvement with biometrics, critical infrastructure, education, employment, or essential services. Furthermore, because OmnIA does not interact directly with individuals and does not generate synthetic content, the transparency obligations under Article 50 do not apply. The use of OmnIA in the EU is therefore permitted without restriction under the AI Regulation.

    For you as a customer, this means: You are not required to comply with the obligations for high-risk AI, specifically:

    • Risk management
    • Technical documentation
    • CE marking
    • separate human oversight

    OmnIA does not make automated decisions about individuals that have legal effects within the meaning of Article 22 of the GDPR, and no profiling takes place.

    Data protection and information security are ensured independently of this: through a data processing agreement with documented technical and organizational measures, as well as through ISO/IEC 27001 certification and the BSI C5 Type 2 certificate for the operation of our cloud services.

    What Obligations Still Apply

    One obligation applies regardless of the risk class and therefore also affects OmnIA customers: AI competence as defined in Article 4 of the AI Regulation. As of February 2, 2025, individuals who operate or use AI systems must possess a sufficient level of AI competence. This obligation applies equally to providers and operators—in the case of OmnIA, this means us as the provider and you as the customer, as soon as you make the solution available to your own customers or employees. Therefore, please ensure that your users receive appropriate training, even if OmnIA itself is not a high-risk system.

    Conclusion

    Anyone who uses OmnIA for document classification, data extraction, or invoice processing falls into the “minimal risk” category under the current AI Regulation: there are no additional product or transparency requirements, data protection is clearly regulated, and no automated decisions are made regarding individuals. The only obligation you must actively help shape is your users’ AI literacy.

    The complete transparency information on OmnIA, including all assessment steps, is available for download. Please contact us if you need the assessment for your own compliance documentation.

    Download the information sheet:

    FAQ

    • Nein. Die Risikoklasse hängt vom konkreten Anwendungsfall ab, nicht allein vom Einsatz von KI. Dokumentenverarbeitung für Purchase-to-Pay, Posteingang oder E‑Rechnung fällt nicht unter die Hochrisiko-Anwendungsfälle aus Anhang III der KI-VO, solange keine Entscheidungen über Personen in sensiblen Bereichen wie Beschäftigung, Bildung oder grundlegenden Diensten getroffen werden.
    • Ja, sobald Verfahren des maschinellen Lernens zum Einsatz kommen, gilt eine Lösung in der Regel als KI-System nach Art. 3 Nr. 1 KI-VO. Das bedeutet aber nicht automatisch besondere Pflichten. Die Einstufung nach Risikoklasse entscheidet, welche Anforderungen greifen.
    • Bei minimalem Risiko entfallen die besonderen Pflichten für Hochrisiko-KI wie Risikomanagement, technische Dokumentation, CE-Kennzeichnung oder menschliche Aufsicht. Bestehen bleibt die Pflicht zur KI-Kompetenz nach Art. 4 KI-VO, die für Anbieter und Betreiber aller Risikoklassen gilt.
    • Hochrisiko-KI-Systeme unterliegen unter anderem Pflichten zu Risikomanagement, Datenqualität, technischer Dokumentation, Protokollierung, menschlicher Aufsicht und CE-Kennzeichnung. Diese Pflichten gelten für Anwendungsfälle aus Anhang III der KI-VO, etwa in den Bereichen Biometrie, kritische Infrastruktur, Bildung, Beschäftigung oder grundlegende Dienste, nicht für die dokumentzentrierte Automatisierung, wie sie OmnIA bereitstellt.
    • OmnIA ist als KI-System mit minimalem Risiko eingestuft: kein Hochrisiko-System, keine verbotene Praktik, keine besonderen Transparenzpflichten nach Art. 50. Der Einsatz in der EU ist uneingeschränkt zulässig. Die vollständige Einstufung mit allen Prüfschritten dokumentiert das Informationsblatt „Einsatz von Künstlicher Intelligenz und Einordnung nach der EU-KI-Verordnung“.