AI Implementation for Your Business in the EU and Estonia – A Practical Legal Guide 

Key takeaways: 
  • The legal risk of an AI tool depends on how it is used, not on what it is called. The same model can be low-risk in one workflow and high-risk in another; 
  • Compliance is now part of the product. For companies that build or sell AI-enabled products, a significant part of the product’s value lies in demonstrable legal compliance, not merely in having a system that works; 
  • Several AI Act duties already apply: AI literacy measures, the prohibited practices and, since 2 August 2026, the transparency rules for chatbots and deepfakes. Further prohibitions apply from 2 December 2026; 
  • The core high-risk obligations for recruitment and workforce-management tools now apply from 2 December 2027. Systems procured today are likely to remain in use by then, so these should be anticipated; 
  • Use of AI systems also requires GDPR, employment and equal treatment law, copyright and business-secrets analysis in full today, irrespective of the AI Act timetable. 
  • Vendor labels such as “enterprise” or “no training on your data” do not replace a company’s own analysis of data flows, confidentiality and ownership of output. 
  • A short, documented process – inventory, classification, data mapping, vendor due diligence, human oversight and training – addresses most risks at proportionate cost and it is more cost-efficient to do it before implementation.

Introduction 

Introducing an AI tool in a company is rarely just an IT purchase. A company also decides, among other things, what information the tool may receive, whose interests its output may affect, how much discretion remains with the employees, and who bears responsibility for the output. Those choices also determine the legal analysis when an AI system is being implemented. The same underlying model may be a comparatively low-risk drafting assistant in one workflow, a transparency-regulated chatbot in another, and part of a high-risk recruitment system in a third. 

For companies in the EU and Estonia, the main rules come from the directly applicable EU Artificial Intelligence Act, the General Data Protection Regulation, sector-specific EU law and employment, copyright and business-secrets legislation. These apply alongside contract, consumer protection, equality and cybersecurity rules. Compliance therefore works best as part of product design and implementation, not as a final legal step after a tool has already been connected to the company’s systems. 

This guide explains which rules matter in practice and illustrates them with cases and a examples. It closes with an implementation sequence and answers to questions that frequently arise when businesses adopt AI. 

Preface regarding applicability 

Mostly, the same rules apply across the EU. This article is not only relevant to Estonian companies. The EU Artificial Intelligence Act is a regulation that applies directly and in identical terms in every Member State, without national implementing legislation. For example, the prohibited practices, the AI literacy duty, the transparency obligations and the high-risk regime therefore bind a company in Helsinki, Warsaw or Lisbon exactly as they bind one in Tallinn, and on the same dates. 

The AI Act also reaches beyond the EU’s borders. It applies to providers placing AI systems on the EU market wherever they are established, to deployers located in the EU, and to non-EU providers and deployers whose systems are used in the EU. The national differences are limited, largely to which authorities supervise compliance, how penalties are imposed within the limits, and procedure. Many of the Estonian statutes cited on employment, copyright and business secrets implement EU directives, so comparable rules exist throughout the EU. The detail should nevertheless be assessed under local law. In short, if your company develops or uses AI in the EU, the principles in this article apply to you.

Key terms for roles in the AI supply chain

  • Vendor – Not a term defined in the AI Act. A commercial label for the business from which a company buys or licenses an AI tool. A vendor may be the provider, a distributor or a reseller; its legal role depends on the facts, not on the label used in the contract. 
  • Provider – A person or organisation that develops an AI system or a general-purpose AI model, or has it developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge. 
  • Deployer – A person or organisation using an AI system under its authority, other than in the course of a personal, non-professional activity. Most businesses that use AI tools in their own operations are deployers. 
  • Downstream provider – A provider of an AI system that integrates an AI model, whether the model is its own or supplied by another company under a contract. A company that builds its own product on a third-party large language model is typically a downstream provider. 
  • Distributor – A person in the supply chain, other than the provider or the importer, that makes an AI system available on the EU market, such as a reseller. 

What is considered “AI” 

Under the EU AI Act, “AI” is a functional legal category. What matters is how a system works, rather than whether its developer calls it “AI”. 

An “AI system”, paraphrased, is a computer-based system that: 

  • Operates with some degree of independence from human intervention; 
  • Pursues objectives that may be expressly specified or implicit; 
  • Infers from its inputs how to produce predictions, generated content, recommendations or decisions; 
  • Produces outputs capable of affecting a physical or digital environment; 
  • May adapt after deployment, but continued learning is optional. 

The most important boundary is inference. The definition covers both systems that learn patterns from data and certain systems that reason from encoded knowledge. Ordinary software that merely executes fixed instructions generally falls outside it. However, “it uses rules” is not sufficient to exclude a system: some expert systems use rules to draw conclusions and can qualify. 

The European Commission’s guidelines on the definition of an AI system, published in February 2025, give further orientation. They indicate that systems used only for basic data processing, classical heuristics, mathematical optimisation or simple statistical prediction may fall outside the definition because their capacity to infer is limited. The guidelines are not binding, and the assessment always depends on the specific system.[13] 

Illustrative classification of common business tools: 

Spreadsheet formula applying a fixed discount rule – Outside the definition (Executes instructions written by a person, no inference.) 

Sales forecast based on a simple moving average – Likely outside (Simple statistical prediction, as described in the Commission guidelines). 

Expert system drawing conclusions from encoded technical knowledge – May qualify (Reasoning from encoded knowledge can amount to inference). 

Machine-learning fraud-detection model – AI system (Learns patterns from data and infers its outputs).

Chatbot or writing assistant built on a large language model – AI system (Generates content by inference, often also subject to the Article 50 transparency rules). 

Legal risk follows the use case 

The first question is not whether a vendor markets its product as artificial intelligence. Instead, the company should record what the system does, which data it uses, what output it produces, who relies on that output, and what happens if it fails. Under the AI Act, a business using a system under its authority is usually a deployer. A business that develops a system or has it developed and places it on the market or puts it into service under its own name may be a provider. Rebranding, changing the intended purpose or substantially modifying an AI system can move a company into provider obligations. The allocation in the vendor contract does not override these statutory roles.[1] 

A common scenario illustrates the distinction. An Estonian software company that integrates a third-party large language model into its own customer-support product and sells that product under its own brand is the provider of that AI system, even though it did not train the underlying model. The developer of the model has separate obligations as a provider of a general-purpose AI model. The software company’s business customers, which use the product in their own operations, are deployers.[1] 

The role analysis also matters for civil liability. Under the revised Product Liability Directive (EU) 2024/2853, which applies to products placed on the market after 9 December 2026, software, including AI systems, is a product. A business that substantially modifies a product outside the original manufacturer’s control may be treated as its manufacturer. Member States must transpose the Directive by 9 December 2026. The European Commission, by contrast, abandoned its separate proposal for an AI Liability Directive in 2025, so claims continue to be governed by national law, in Estonia principally the Law of Obligations Act.[14] 

Another useful example is an AI-enabled camera on a production line. If it identifies defects in products and does not assess individuals, the use may remain outside the AI Act’s high-risk list. If the same feed is used to rank workers by speed, error rate or behaviour, the system moves into employment and worker-management territory. The facts of the workflow, including later repurposing, matter more than the product name. 

The regulatory calendar also matters. Most of the AI Act has applied since 2 August 2026. Prohibited practices and the AI literacy duty have applied since 2 February 2025, while the rules for providers of general-purpose AI models started to apply on 2 August 2025. Although, for example some of the core obligations for high-risk systems, including many recruitment and employee-management tools, and high-risk systems embedded in regulated products have been postponed, the postponement is preparation time, not permission to ignore the GDPR, or existing employment duties. [1][2][16] 

Key AI Act application dates: 

2 February 2025 – Prohibited practices (Article 5) and the AI literacy duty (Article 4). 

2 August 2025 – Obligations for providers of general-purpose AI models, governance and penalty framework. 

2 August 2026 – Most remaining provisions, including the Article 50 transparency obligations. 

2 December 2026 – New prohibitions added by Regulation (EU) 2026/1744; machine-readable marking deadline under Article 50(2) for generative AI systems placed on the market before 2 August 2026. 

2 December 2027 – High-risk obligations for stand-alone systems listed in Annex III, including employment, education and creditworthiness assessment. 

2 August 2028 – High-risk obligations for AI systems in products covered by Annex I, such as medical devices. 

The AI Act duties already in force 

Every provider and deployer must take measures that support the AI literacy of staff and others operating AI on its behalf. It is important to note that measures, rather than a guaranteed outcome, are required: it does not prescribe a certificate or require every employee to reach the same level. Training should match the person’s role, the system’s risks and the people affected. 

A procurement specialist needs to recognise contractual and data-flow issues, an HR user needs to understand bias, limits and effective human review; a developer needs to understand testing, logging and security. A short generic webinar will rarely be enough for all three groups. Records of training content, audiences and attendance will be the practical evidence that the duty has been met.[1] 


 

IN PRACTICE

A proportionate programme for a 50-person company might combine a one-page acceptable-use rule for all staff, a short practical session on verifying AI output and protecting confidential data, and deeper, role-specific training for the few people who configure AI tools or rely on them for decisions about customers or staff. An attendance list and a copy of the materials are sufficient evidence. 


 

Article 5 of the AI Act prohibits specified practices. Of particular relevance to employers is the ban on using AI to infer a person’s emotions in the workplace or during recruitment from biometric data, except for narrowly framed medical or safety reasons. Calling a video-interview feature a measure of engagement or cultural fit does not remove it from the prohibition if it is designed to infer emotions. Similarly, a call-centre analytics tool that scores agents’ frustration or anger from their voices falls within the workplace ban, whereas a tool that only transcribes calls and flags keywords does not, because it does not infer emotions from biometric data.[1][2][15] 

Article 50 transparency rules have applied since 2 August 2026. People must be told when they interact directly with certain AI systems, unless the AI nature is obvious in the circumstances. Deepfakes and some AI-generated or manipulated text published to inform the public on matters of public interest also require disclosure. The rule contains qualifications, including for human review and editorial responsibility, so it does not follow that every sentence polished with an AI writing tool needs a label. A customer-service chatbot, however, should never be presented as a human agent, and its escalation route should be clear. Providers of generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to implement the machine-readable marking of synthetic content required by Article 50(2).[1][2] 

By way of example, a video campaign in which a company’s chief executive appears, through an AI-generated voice and likeness, to deliver a message he or she never recorded is a deepfake and must be disclosed as such. Where content forms part of an evidently artistic, creative, satirical or fictional work, the disclosure may be made in a manner that does not hamper its display or enjoyment.[1] 

Enforcement is already possible. Under Article 99, infringements of the prohibitions can lead to fines of up to EUR 35 million or 7% of worldwide annual turnover, and breaches of most other operator duties, including deployer and transparency obligations, up to EUR 15 million or 3%. For SMEs, the lower of the two amounts applies, and Regulation (EU) 2026/1744 extends mitigated penalties to small enterprises. In Estonia, the Consumer Protection and Technical Regulatory Authority (TTJA) has announced that it will act as a competent authority for the supervision of AI systems, including prohibited practices, transparency obligations and high-risk uses such as workforce management. At the time of writing, its guidance describes that supervisory role as forthcoming. The Data Protection Inspectorate continues to supervise AI-related processing of personal data.[1][15][16] 

The delayed high-risk regime remains commercially important. Recruitment screening, candidate evaluation, decisions on promotion or termination, task allocation based on personal behaviour or traits, and monitoring or evaluation of worker performance appear in Annex III. When the relevant provisions apply, deployers will need competent human oversight, suitable input data, monitoring, incident escalation and retention of system logs under Article 26. Deployers that are public bodies or private entities providing public services, and deployers using high-risk systems to assess creditworthiness or to price life and health insurance, will also need a fundamental rights impact assessment under Article 27. Employers will also have to inform affected workers and their representatives before workplace use. Building those controls into a 2026 procurement is usually cheaper than renegotiating an opaque service in late 2027.[1] 

Not every tool used in an Annex III area is automatically high-risk. Under Article 6(3), a listed system is not considered high-risk where it does not pose a significant risk of harm, for example because it performs only a narrow procedural task, improves the result of a previously completed human activity or performs a preparatory task. A tool that merely converts incoming CVs into a standard format may fall within that exception. A tool that ranks candidates generally will not. A system that profiles natural persons is always considered high-risk. A provider relying on the exception must document its assessment and, as Regulation (EU) 2026/1744 confirms, register the system.[1][16]

Data protection must be designed into the workflow 

The GDPR applies whenever the workflow processes personal data, even if the AI system is not high-risk under the AI Act. The data controller must identify a lawful basis under Article 6, comply with purpose limitation and data minimisation under Article 5, provide the information required by Articles 13 or 14, and implement data protection by design under Article 25. Special-category data require an Article 9 exception in addition to an Article 6 basis. Employee consent is often unsuitable because the imbalance in the employment relationship may prevent it from being freely given.[3] 

The European Commission has proposed amendments to the GDPR as part of its wider Digital Omnibus package, including on the processing of personal data for the development of AI. That proposal was still under negotiation at the time of writing, and companies should plan on the basis of the GDPR as it currently stands. 

A customer-support example shows why labels such as “enterprise version” or “data not used for training” are not a complete answer. If the assistant receives chat histories, order data and complaints, the company must still decide which fields are necessary, how long prompts and outputs are kept, who can access them, where subprocessors operate, and whether data leaves the European Economic Area. Enforcement is not theoretical as in December 2024, the Italian data protection authority fined OpenAI EUR 15 million, finding, among other things, that personal data had been used to train ChatGPT without an adequate legal basis and that transparency obligations towards users had not been met. The case concerned a model provider, but the same principles of lawful basis and transparency apply to every company that feeds personal data into an AI workflow.[17] 

A data protection impact assessment is required before processing that is likely to result in a high risk to individuals, including certain systematic evaluations based on automated processing. The assessment should describe the full workflow rather than the model in isolation. It should cover data sources, output recipients, error and bias risks, security, human review, retention, rights handling and foreseeable misuse. The European Data Protection Board has also cautioned that an AI model is not automatically anonymous. Anonymity requires a case-specific assessment of whether people can be identified from the model or their data extracted through queries.[3][4][16] 

Article 22 restricts decisions based solely on automated processing that have legal or similarly significant effects. A nominal human approval step does not help if the reviewer routinely accepts the score, lacks the underlying information or has no authority to change the result. Where Article 22 applies, an exception must exist and safeguards include human intervention, the opportunity to express a view and the ability to contest the decision. In Dun & Bradstreet Austria, Case C-203/22, the Court of Justice confirmed that meaningful information about the logic must enable the individual to understand and challenge the automated decision. Trade-secret claims do not justify a refusal to explain it.[3][5] 

National courts apply the same standard to algorithmic management. In April 2023, the Amsterdam Court of Appeal held that a ride-hailing platform’s decisions to deactivate drivers’ accounts for alleged fraud were based solely on automated processing, because the platform had not shown that the involvement of its review team was much more than a purely symbolic act. The platform was ordered to provide the drivers with information enabling them to understand and verify the basis of the decisions.[17] 

Security measures under Article 32 must cover the AI-specific attack surface, including prompt injection, unintended retrieval from connected databases, excessive permissions and leakage through logs. Estonian Data Protection Inspectorate guidance also advises against entering personal data, credentials, client materials, contracts, intellectual property or other confidential work information into publicly available AI services. An internal rule should turn that warning into concrete choices about approved accounts, permitted data and escalation.[6] 

Intellectual property, confidentiality and output ownership 

Input and output require separate analysis.  

Before employees upload text, code, images, recordings or databases, the company should confirm that its licence or other legal basis permits the intended use.  

Estonia’s Copyright Act implements the EU text-and-data-mining exceptions in sections 19.1 and 19.2. Commercial mining may cover reproductions of lawfully accessible works unless the rightsholder has expressly reserved the use, including by machine-readable means for online content. The exception is not a general licence to ignore access restrictions, retain copies indefinitely or reproduce protected expression in outputs. It is mainly relevant where a company trains or fine-tunes models, not as a justification.[7][8] 

Providers of general-purpose AI models must maintain a policy to comply with EU copyright law and publish a sufficiently detailed summary of training content under Article 53 of the AI Act. Those provider duties help downstream due diligence, but they do not guarantee that every generated output is cleared for every commercial use. Procurement should therefore ask how the vendor handles rights reservations, memorisation claims, takedowns, output similarity and indemnities.[1] 

Courts are beginning to test these questions, for example, in GEMA v OpenAI, the Munich Regional Court held at first instance in November 2025 that song lyrics memorised by a language model, and reproduced in its outputs in response to simple prompts, infringed the rightsholders’ reproduction rights, and that the text-and-data-mining exception did not cover that memorisation. Outside the EU, the High Court of England and Wales in Getty Images v Stability AI reached a narrower result on the facts, rejecting the argument that the trained model was itself an infringing copy. The case law is unsettled, which is why contractual allocation of risk and output review remain important.[17]

Ownership of output is a different issue.  

Under sections 4 and 28 of the Estonian Copyright Act, a protected work must be the author’s own intellectual creation and the author is a natural person. A company should not assume that an output generated with minimal human creative control carries copyright. Protection is more plausible where a person makes identifiable free and creative choices through selection, arrangement and substantial editing, but the assessment remains fact-specific. Therefore it is advised to keep drafts and revision history for valuable content. For employee-created works, section 32 contains rules on the transfer or licensing of economic rights to the employer within the purpose and scope of the employee’s duties, contracts should address any gaps.[7] 

Courts elsewhere have taken the same approach to authorship. In 2023, the Municipal Court in Prague held that an image generated by an AI tool from a user’s text prompt was not protected by copyright because it had not been created by a natural person.[17] 

Generated code, images and documents should also be checked. A coding assistant may be useful, but the code might useful function The practical control is not a promise that the model never copies. It is a review process combining source and licence scanning, technical testing, provenance records and a clear rule about when specialist review is required. 

Confidentiality deserves the same attention. Under section 5 of Estonia’s Restriction of Unfair Competition and Protection of Business Secrets Act, information qualifies as a business secret only if it is secret, has commercial value because it is secret and has been subject to reasonable measures to keep it secret. Uploading a pricing model or unreleased product design to an unapproved AI service may undermine that last element. In 2023, Samsung Electronics restricted employees’ use of generative AI services after engineers reportedly entered confidential source code and internal meeting notes into a public chatbot. Reasonable measures include approved enterprise accounts, access limits, contractual confidentiality, restricted vendor reuse, short retention, deletion rights, audit evidence and employee instructions that distinguish acceptable from prohibited inputs.[9]

Employment matters cannot be delegated to AI 

Estonian employment law applies before the AI Act’s high-risk employment provisions take effect. Section 28(2)(11) of the Employment Contracts Act requires the employer to respect employee privacy and verify performance without violating fundamental rights. AI monitoring therefore needs a defined purpose, a lawful basis, necessity and proportionality.10] For example, software that records keystrokes, captures periodic screenshots and generates an AI “productivity score” for each employee is difficult to reconcile with these principles unless the employer can show a specific, legitimate purpose that less intrusive means could not achieve, and has informed employees in advance. Recruitment and management systems also create discrimination risk. 

Consider a CV-ranking tool that scores candidates and recommends whom to interview. It is listed as high-risk employment AI under Annex III, although the core AI Act obligations for that category are postponed to 2 December 2027. Today, the employer must still satisfy the GDPR and employment law rules. A recruiter who sees only the score and almost always follows it is unlikely to provide meaningful human review. 

AI can also change work organisation. An Estonian employer with at least 30 employees must inform and consult under sections 17 to 21 of the Employees’ Trustee Act about planned decisions likely to cause substantial changes in work organisation or employment relationships. Consultation should take place while alternatives can still influence the decision. Separately, Article 26(7) of the AI Act will require employers to inform workers’ representatives and affected workers before deploying a high-risk workplace system when that provision becomes applicable.[1][11] 

Training and contractual change must be planned as well. Section 28(2)(5) of the Employment Contracts Act requires employer-funded training needed to develop professional knowledge and skills in the employer’s interests. Material changes to agreed duties require agreement under section 12.

Contracts, customer communications and liability 

The vendor contract is where most of these requirements become enforceable. Standard terms for AI services are frequently drafted for the vendor’s benefit: they may permit unilateral changes to models and features, reserve broad rights to use customer data for service improvement, disclaim responsibility for the accuracy of output and cap liability at a few months’ fees. A company cannot always negotiate a bespoke agreement with a global provider, but it can choose between service tiers, configure data-use settings, obtain the vendor’s data processing agreement and security documentation, and decline tools whose terms are incompatible with its obligations to its own clients. 

Where output will be used commercially, the scope of any intellectual property indemnity deserves close reading. Indemnities offered by major providers typically apply only to specified paid services and are conditional on the customer keeping the provider’s safety filters enabled and not deliberately prompting for infringing material. Those conditions should be reflected in internal usage rules, otherwise, the indemnity may not respond when it is needed. 

A business also answers for what its AI tells customers. In Moffatt v Air Canada (2024), a Canadian case held the airline liable after its website chatbot incorrectly told a customer that a bereavement discount could be claimed retrospectively, and rejected the argument that the chatbot was responsible for its own statements. Under Estonian law, the analysis would turn on the pre-contractual duties and contract rules of the Law of Obligations Act and on the prohibition of misleading commercial practices in consumer protection law. That a chatbot generated the statement is not in itself a defence.  A retail chatbot that tells a consumer that sale items cannot be returned, contrary to the statutory 14-day right of withdrawal for distance contracts, exposes the business both to the customer’s claim and to supervisory action.[17] 

Sector-specific rules may add further requirements. Financial entities subject to the Digital Operational Resilience Act (DORA) must manage AI vendors as ICT third-party service providers, including through the contractual provisions that DORA prescribes. Professional firms bound by confidentiality duties must ensure that client information is processed only in ways their professional rules permit.[18]

A hypothetical example 

The following hypothetical example shows how the analysis differs across tools within a single business. A Tallinn-based online retailer with 80 employees plans to introduce three AI tools in the autumn of 2026. 

1. A customer-service chatbot 

The retailer licenses a chatbot built on a vendor’s general-purpose model and configures it with its own product. In most configurations of this kind, the retailer is a deployer. If it instead develops its own system on top of the model and puts it into service under its own name, it may become the provider of that system. The chatbot is not high-risk. Under Article of the AI Act 50, customers must be able to tell that they are interacting with an AI system, so the retailer should confirm that the system discloses this and should not give the bot a human persona. Under the GDPR, the retailer needs a data processing agreement, defined retention periods for chat logs, a review of international transfers and an updated privacy notice. Under consumer law, it must ensure that answers on delivery, warranty and withdrawal rights are accurate, and it should offer a clear route to a human agent. 

2. Generative tools for marketing 

The marketing team uses a text-and-image generator for product descriptions and campaign visuals. The principal issues are intellectual property and consumer protection rather than the AI Act. Output produced with minimal human input may not attract copyright, so the retailer cannot assume that it can prevent competitors from reusing or copying it. Images must be checked for recognisable third-party works, trademarks and real people. If a campaign shows realistic people, places or events that could falsely appear authentic, Article 50(4) requires disclosure. Independently of the AI Act, product visuals must not mislead consumers about the goods themselves. Employees should not upload unreleased product designs or supplier pricing to tools that are not approved for confidential data. 

3. CV screening 

HR proposes a tool that scores applicants and recommends a shortlist. This is a high-risk use under Annex III of the AI Act, with the core deployer obligations applying from 2 December 2027. Today, the retailer must still identify a lawful basis, inform applicants, assess whether the process amounts to a solely automated decision under Article 22, and comply with the employment laws and equal treatment legislation. A data protection impact assessment will usually be required. As an employer with more than 30 employees, it should also consider whether the change triggers information and consultation duties. The contract should require the vendor to provide instructions for use, evidence of bias testing and log retention, and to commit to meeting the Annex III requirements.

Compliance as a source of product value 

For companies that develop or sell AI-enabled products, a significant part of a product’s value now lies in demonstrable legal compliance, not merely in a system that works. A technically impressive tool that cannot show how it handles personal data, how its outputs are controlled and how it will meet the AI Act requirements is increasingly difficult to sell, finance or integrate into a customer’s operations. 

The same applies in transactions. Investors and acquirers of technology companies increasingly examine how training data was obtained, whether licences and rights reservations were respected, whether data processing agreements are in place and whether the product can meet forthcoming AI Act obligations. Gaps discovered at that stage tend to reduce valuations, lead to specific indemnities or delay closing. Compliance built in from the outset, by contrast, is an asset that can be documented and presented to customers and investors.  

On the other hand, the same goes for the vendors. 


 

IN PRACTICE

Consider an Estonian start-up that sells an AI-based candidate-screening tool to Nordic employers. Its customers will need a data processing agreement, instructions for use, log retention, evidence of bias testing and, from December 2027, a completed conformity assessment and CE marking. A competitor that can supply this documentation from the first sales meeting is better placed to succeed in procurement processes than a technically comparable product without it.


Practical implementation sequence 

  1. Create an AI register. Record each use case, owner, system and model version, vendor, intended purpose, affected people, data categories, integrations and output recipients. Include informal pilots and employee-installed tools. For most small and medium-sized companies, a well-maintained spreadsheet is sufficient.
  2. Classify the legal role and risk. Decide whether the company is a deployer, provider or both; screen for prohibited practices, Article 50 transparency and Annex I or III high-risk use. Record the current and future application dates.
  3. Map data before procurement. Identify lawful bases, special-category data, retention, access, subprocessors and international transfers.
  4. Negotiate for evidence. Require security and privacy documentation, change notices, audit support, deletion, incident cooperation, service continuity, copyright information and workable exit rights. Allocate responsibility for notices and rights requests.
  5. Design genuine human control. Name reviewers with the competence, information, time and authority to disagree. Define which outputs may be used directly, which require verification and which may never determine a decision alone.
  6. Protect confidential inputs and outputs. Use approved accounts and technical restrictions. Set rules for personal data, source code, client material and business secrets. Retain records for valuable or externally published output.
  7. Involve employees early. Inform and consult where required, update work-organisation rules, explain monitoring and appeals, provide role-specific training.
  8. Monitor changes. AI services change through new models, integrations and default settings. Reassess classification, accuracy, bias, security and contracts after material changes and on a scheduled basis. Keep training records, assessments, review logs and vendor documentation so that compliance can be demonstrated to supervisory authorities, clients and auditors.
Frequently asked questions 

Do we need a formal AI policy? 

No Estonian statute requires a document with that title. However, the AI literacy duty, the GDPR accountability principle and the need to demonstrate reasonable measures to protect business secrets are difficult to satisfy without written rules. For most companies, a short acceptable-use policy supported by the AI register described above is proportionate. 

May our employees use free public chatbots for work? 

That is a business decision, but it should be an informed one. Free consumer versions often allow the provider to use inputs to improve its services and offer limited contractual protection. We advise against entering personal data or confidential information into publicly available AI services. Many companies therefore permit only approved business accounts for work involving such information. 

If we build on a major provider’s model, are we the provider? 

Often, yes, in respect of the AI system you build, if you place it on the market or put it into service under your own name. The model developer remains responsible for its obligations as a provider of a general-purpose AI model, including making technical information available to downstream providers. Your contract should secure the information you need to meet your own obligations. 

Must all AI-generated content be labelled? 

No. Article 50 targets specific situations: direct interaction with AI systems, deepfakes, and AI-generated or manipulated text published to inform the public on matters of public interest, subject to exceptions such as human review and editorial responsibility. Internal drafts and AI-assisted text that a person has reviewed and taken responsibility for do not generally require a label, although consumer protection and advertising rules may independently require transparency. 

Does choosing an EU-hosted vendor solve GDPR compliance? 

It helps with international transfers, but only if support, maintenance and subprocessing also remain within the EEA. Hosting location does not address lawful basis, transparency, minimisation, retention or data subjects’ rights, all of which remain the company’s responsibility as controller. 

Does the postponement mean we can wait until 2027? 

The current AI Act, the GDPR, employment and other rules already apply, and procurement cycles mean that tools selected now will be in use when the high-risk obligations apply. Contract terms and technical choices made in 2026 will largely determine how costly compliance is in December 2027. 

Conclusion 

The legal work around AI implementation is manageable when it follows the actual workflow. An accurate inventory, clear purpose, controlled data flow, meaningful human review, and evidence from the vendor solve more problems than a broad policy written afterwards.  

The immediate priorities are the duties already in force under the AI Act, full GDPR compliance, protection of intellectual property and confidential information, and lawful treatment of applicants and employees. The postponed high-risk rules should shape contracts and system design now, because the systems bought in 2026 are likely to remain in use when those duties apply. For companies that build and use AI products, the same work is also a commercial asset. The ability to demonstrate compliance increasingly determines whether a product can be sold, financed or acquired. 

How Magnusson can help 

Magnusson’s Tallinn office advises companies on AI implementation across corporate, intellectual property, data protection, employment and technology contracting matters. Our work includes AI inventories and risk classification, data protection impact assessments, negotiation of AI vendor agreements, internal AI policies and training, and cross-border matters.

Selected legal sources 

[1] Regulation (EU) 2024/1689, consolidated version of 27 July 2026, in particular Articles 3–5, 6, 25–27, 50, 53, 99 and 113 and Annex III; as amended by Regulation (EU) 2026/1744. Official source 

[2] European Commission, AI Act implementation timeline and enforcement framework, updated for the 2026 Digital Omnibus. Official source 

[3] Regulation (EU) 2016/679, in particular Articles 5, 6, 9, 13–15, 22, 25, 28, 32, 35 and 44–49. Official source 

[4] European Data Protection Board, Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models. Official source 

[5] Court of Justice of the European Union, judgment of 27 February 2025, Case C-203/22, Dun & Bradstreet Austria, ECLI:EU:C:2025:117. Official source 

[6] Estonian Data Protection Inspectorate, guidance on AI, awareness and individual rights, including confidential and personal information in public AI services. Official source 

[7] Estonian Copyright Act, in particular sections 4, 19.1, 19.2, 28 and 32. The Estonian text is authoritative. Official source 

[8] Directive (EU) 2019/790, in particular Articles 3 and 4 on text and data mining. Official source 

[9] Estonian Restriction of Unfair Competition and Protection of Business Secrets Act, in particular section 5. The Estonian text is authoritative. Official source 

[10] Estonian Employment Contracts Act, in particular sections 11, 12, 28 and 89. The Estonian text is authoritative. Official source 

[11] Estonian Employees’ Trustee Act, in particular sections 17–21. The Estonian text is authoritative. Official source 

[12] Estonian Equal Treatment Act, in particular sections 1–3 and 12, and Gender Equality Act, section 6. The Estonian texts are authoritative. Official source and Gender Equality Act 

[13] European Commission, Guidelines on the definition of an artificial intelligence system established by Regulation (EU) 2024/1689 (February 2025); Guidelines on prohibited artificial intelligence practices established by Regulation (EU) 2024/1689 (February 2025).  

[14] Directive (EU) 2024/2853 of 23 October 2024 on liability for defective products.  

[15] Consumer Protection and Technical Regulatory Authority (TTJA), “Tehisintellektisüsteemid” (AI systems), last updated 10 September 2026. Official source 

[16] Regulation (EU) 2026/1744 of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI), OJ L, 24 July 2026. Official source 

[17] Cases and decisions referred to: Landgericht München I, judgment of 11 November 2025, 42 O 14139/24 (GEMA v OpenAI, first instance); High Court of England and Wales, Getty Images v Stability AI (November 2025); Gerechtshof Amsterdam, judgment of 4 April 2023, ECLI:NL:GHAMS:2023:796 (Uber drivers); Městský soud v Praze (Municipal Court in Prague), case 10 C 13/2023; US Court of Appeals for the D.C. Circuit, Thaler v Perlmutter, 18 March 2025; Civil Resolution Tribunal of British Columbia, Moffatt v Air Canada, 2024 BCCRT 149; Garante per la protezione dei dati personali, sanction against OpenAI announced on 20 December 2024.  

[18] Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA), in particular Articles 28–30. 

Contact me and learn more