[{"data":1,"prerenderedAt":830},["ShallowReactive",2],{"blog-works-council-ai-tools-austria-germany-en":3},{"slug":4,"published":5,"minutes":6,"category":7,"tags":8,"keywords":14,"about":23,"sources":36,"cover":78,"og":79,"expertise":80,"locales":81,"lang":82,"title":85,"description":86,"coverAlt":87,"metaTitle":88,"takeaways":89,"faq":95,"toc":108,"blocks":136,"others":523},"works-council-ai-tools-austria-germany","2026-10-02",11,"security",[9,10,11,12,13],"Works council","AI coding tools","Employee monitoring","GDPR","Co-determination",[15,16,17,18,19,20,21,22],"works council AI tools","AI coding tools works council","Betriebsrat KI Mitbestimmung","§ 87 BetrVG Überwachung","§ 96 ArbVG Kontrollmaßnahmen","AI usage logs employee monitoring","works agreement for AI tools","GDPR Article 88 employee data",[24,27,30,33],{"name":25,"url":26},"General Data Protection Regulation","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2016\u002F679\u002Foj\u002Feng",{"name":28,"url":29},"EU Artificial Intelligence Act (Regulation (EU) 2024\u002F1689)","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2024\u002F1689\u002Foj\u002Feng",{"name":31,"url":32},"Arbeitsverfassungsgesetz (Austrian Labour Constitution Act)","https:\u002F\u002Fwww.ris.bka.gv.at\u002FGeltendeFassung.wxe?Abfrage=Bundesnormen&Gesetzesnummer=10008329",{"name":34,"url":35},"Betriebsverfassungsgesetz (German Works Constitution Act), § 87","https:\u002F\u002Fwww.gesetze-im-internet.de\u002Fbetrvg\u002F__87.html",[37,39,41,44,47,49,52,54,57,60,63,66,69,72,75],{"title":38,"url":32},"Arbeitsverfassungsgesetz (ArbVG), §§ 96 and 96a, consolidated text of 10 October 2026, RIS",{"title":40,"url":35},"Betriebsverfassungsgesetz (BetrVG), § 87, gesetze-im-internet.de",{"title":42,"url":43},"Betriebsverfassungsgesetz (BetrVG), § 90, gesetze-im-internet.de","https:\u002F\u002Fwww.gesetze-im-internet.de\u002Fbetrvg\u002F__90.html",{"title":45,"url":46},"Bundesdatenschutzgesetz (BDSG), § 26, gesetze-im-internet.de","https:\u002F\u002Fwww.gesetze-im-internet.de\u002Fbdsg_2018\u002F__26.html",{"title":48,"url":26},"Regulation (EU) 2016\u002F679 (GDPR), EUR-Lex",{"title":50,"url":51},"GDPR Article 5(1)(e), storage limitation, gdpr-info.eu","https:\u002F\u002Fgdpr-info.eu\u002Fart-5-gdpr\u002F",{"title":53,"url":29},"Regulation (EU) 2024\u002F1689 (AI Act), EUR-Lex",{"title":55,"url":56},"Regulation (EU) 2026\u002F1744, EUR-Lex","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2026\u002F1744\u002Foj",{"title":58,"url":59},"AI Act Article 26, AI Act Explorer","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F26\u002F",{"title":61,"url":62},"AI Act Annex III, AI Act Explorer","https:\u002F\u002Fartificialintelligenceact.eu\u002Fannex\u002F3\u002F",{"title":64,"url":65},"BAG, 1 ABR 16\u002F23 (July 2024), headset system, gesetze.co","https:\u002F\u002Fgesetze.co\u002Furteile\u002F1_ABR_16-23",{"title":67,"url":68},"ArbG Hamburg, 24 BVGa 1\u002F24: law-firm summary by CMS","https:\u002F\u002Fcms.law\u002Fde\u002Fdeu\u002Flegal-updates\u002Fkein-mitbestimmungsrecht-des-betriebsrats-bei-chatgpt-co",{"title":70,"url":71},"ArbG Hamburg, 24 BVGa 1\u002F24: law-firm summary by Gleiss Lutz","https:\u002F\u002Fwww.gleisslutz.com\u002Fde\u002Fknow-how\u002Farbeitsgericht-hamburg-zu-chatgpt-kein-mitbestimmungsrecht-des-betriebsrats",{"title":73,"url":74},"Claude Code documentation: monitoring usage","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fmonitoring-usage",{"title":76,"url":77},"GitHub Docs: Copilot metrics data reference","https:\u002F\u002Fdocs.github.com\u002Fen\u002Fcopilot\u002Freference\u002Fmetrics-data","\u002Fimages\u002Fblog\u002Fworks-council-ai-tools-austria-germany\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fworks-council-ai-tools-austria-germany\u002Fog.jpg","ai-engineer",[82,83,84],"en","de","hu","AI coding tools and the works council: when usage logs count as monitoring","Usage logs can make an AI coding tool a monitoring system. What Austria (§ 96 ArbVG) and Germany (§ 87 BetrVG) require, and what to agree before rollout.","Cover art for works councils and AI tools: usage logs pass a consent gate before any developer seat is switched on.","AI coding tools and works councils · Balázs Csorba",[90,91,92,93,94],"A tool does not need to record conversations to count as monitoring. In Germany the test is whether it is objectively suitable to collect data on behaviour or performance.","Austria requires works council consent for control measures and technical systems that touch human dignity (§ 96(1) no. 3 ArbVG). Germany gives co-determination over equipment designed to monitor (§ 87(1) no. 6 BetrVG).","§ 90 BetrVG names the use of artificial intelligence in the employer's duty to inform and consult, so the works council hears about it early.","Law-firm summaries of the Hamburg labour court's 2024 ChatGPT order turn on private accounts the employer could not see. A managed rollout with admin logs is a different set of facts.","Sign the works agreement before the first seat is active, covering purpose, logged fields, access, retention, no performance use, training and review.",[96,99,102,105],{"q":97,"a":98},"Does an AI coding assistant need works council consent in Austria or Germany?","It can, depending on what the tool logs and who can see it. In Austria, § 96(1) no. 3 ArbVG makes control measures and technical systems that touch human dignity legally effective only with the works council's consent. In Germany, § 87(1) no. 6 BetrVG gives co-determination over equipment designed to monitor behaviour or performance. Have a lawyer classify your set-up before you switch on per-user logs.",{"q":100,"a":101},"Is individual employee consent enough under the GDPR?","I would not rely on it. § 26(2) BDSG asks decision-makers to weigh the employee's dependence on the employer when judging whether consent was freely given. Article 88 GDPR points to rules set by law or collective agreement, so put the rules into the works agreement.",{"q":103,"a":104},"What must a works agreement for AI tools cover?","The statutes give no template. Article 88(2) GDPR asks for suitable and specific measures, with particular regard to transparency and to monitoring systems at the workplace. I would cover purpose, logged fields, access, retention, a ban on performance use, training and a review date.",{"q":106,"a":107},"Does the EU AI Act apply to a coding tool?","Not automatically. The high-risk rules apply only if your use falls into an Annex III category, such as monitoring performance and behaviour. Regulation (EU) 2026\u002F1744 moves the Annex III application date to 2 December 2027. If a system is high-risk for your use, Article 26(7) requires telling workers' representatives and affected workers before first use.",[109,112,115,118,121,124,127,130,133],{"id":110,"title":111},"what-logs-reveal","What the logs reveal",{"id":113,"title":114},"austria-law","Austria: §§ 96 and 96a ArbVG",{"id":116,"title":117},"germany-law","Germany: §§ 87 and 90 BetrVG and § 26 BDSG",{"id":119,"title":120},"courts","What the courts have said so far",{"id":122,"title":123},"gdpr-ai-act","GDPR and the AI Act",{"id":125,"title":126},"works-agreement","What the works agreement should contain",{"id":128,"title":129},"rollout-timeline","A rollout timeline that fits the statutes",{"id":131,"title":132},"first-steps","What I would do first",{"id":134,"title":135},"sources","Sources",[137,141,144,151,154,157,176,195,204,207,208,211,214,217,220,221,224,227,230,231,234,237,240,243,244,247,250,253,256,259,262,301,302,305,345,348,350,353,354,357,422,429,435,436,451,474,475],{"type":138,"content":139},"paragraph",[140],"Rolling out an AI coding assistant to developers looks like a licence decision. In Austria and Germany it is also a works council question, and the trigger is often the admin console. The usage data that tools show administrators can say who used the tool, when and how often. That can be enough to make it a technical system capable of monitoring employees, whatever purpose the rollout slide gives. My answer is to involve the works council before the first seat is active, and to let the logs follow the agreement rather than the other way round.",{"type":138,"content":142},[143],"In Austria, consent is needed for certain measures to take legal effect. In Germany, co-determination covers the introduction and use of such equipment. Below I set out what the logs can show, what the statutes and the decisions I could check say, what a works agreement should cover, and a rollout timeline.",{"type":145,"variant":146,"title":147,"body":148},"callout","warn","This is not legal advice",[149],[150],"I am an engineer, not a lawyer, and nothing in this article is legal advice. I quote the statutes from the official texts I checked in October 2026. The court decisions come from the decision metadata or from law-firm write-ups. How any of this applies to your company, your works council and your vendor contract is a legal question. It can turn on facts, collective agreements and the country where people work. Involve an employment lawyer and your data protection officer before you switch on per-user logs.",{"type":152,"level":153,"id":110,"text":111},"heading",2,{"type":138,"content":155},[156],"Many coding tools now have an admin layer, and that layer is where the monitoring question starts. Here are two examples from documentation I opened in October 2026.",{"type":138,"content":158},[159,160,164,165,168,169,172,173,175],"GitHub's Copilot metrics give each user a ",{"tag":161,"children":162},"code",[163],"last_activity_at"," timestamp for their most recent Copilot interaction. The per-user record also carries the login, ",{"tag":161,"children":166},[167],"last_authenticated_at"," and ",{"tag":161,"children":170},[171],"last_surface_used",". The report refreshes every 30 minutes, although processing can take up to 24 hours. The data sits on a rolling 90-day window that cannot be changed, and after 90 days without activity, ",{"tag":161,"children":174},[163]," is null.",{"type":138,"content":177},[178,179,182,183,186,187,190,191,194],"Claude Code's monitoring setup, as Anthropic documents it, exports OpenTelemetry metrics and events. The telemetry carries an anonymous ",{"tag":161,"children":180},[181],"user.id",", the ",{"tag":161,"children":184},[185],"user.email"," when it is available, and the account UUID for signed-in users, which ",{"tag":161,"children":188},[189],"OTEL_METRICS_INCLUDE_ACCOUNT_UUID"," controls (default true). The prompt attribute is redacted unless ",{"tag":161,"children":192},[193],"OTEL_LOG_USER_PROMPTS"," is set to 1.",{"type":196,"attrs":197,"inner":201,"caption":202},"diagram",{"viewBox":198,"role":199,"aria-labelledby":200},"0 0 720 250","img","d1-wc-t d1-wc-d","\u003Ctitle id=\"d1-wc-t\">From usage log to works council duty\u003C\u002Ftitle>\u003Cdesc id=\"d1-wc-d\">Read left to right. The tool records use. If that use can be tied to a person, works council rights in Austria and Germany may apply, so consent or co-determination may be needed before rollout. If it cannot be tied to a person, the question stays open, because the BAG asks about suitability rather than identity.\u003C\u002Fdesc>\u003Ctext x=\"700\" y=\"22\" text-anchor=\"end\" class=\"d-label\">Read left to right\u003C\u002Ftext>\u003Crect x=\"20\" y=\"60\" width=\"190\" height=\"60\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"115\" y=\"85\" text-anchor=\"middle\" class=\"d-text\">Tool records use\u003C\u002Ftext>\u003Ctext x=\"115\" y=\"104\" text-anchor=\"middle\" class=\"d-small\">time, count, user ID\u003C\u002Ftext>\u003Cpath d=\"M210 90 H244\" class=\"d-line\" \u002F>\u003Cpath d=\"M252 90 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"260\" y=\"60\" width=\"190\" height=\"60\" rx=\"10\" class=\"d-gold\" \u002F>\u003Ctext x=\"355\" y=\"85\" text-anchor=\"middle\" class=\"d-text\">Tied to a person?\u003C\u002Ftext>\u003Ctext x=\"355\" y=\"104\" text-anchor=\"middle\" class=\"d-small\">user ID, login, email\u003C\u002Ftext>\u003Cpath d=\"M450 90 H484\" class=\"d-line-accent\" \u002F>\u003Cpath d=\"M492 90 l-9 -5 v10 z\" class=\"d-head-accent\" \u002F>\u003Ctext x=\"462\" y=\"82\" class=\"d-label\">yes\u003C\u002Ftext>\u003Crect x=\"500\" y=\"40\" width=\"200\" height=\"100\" rx=\"10\" class=\"d-accent\" \u002F>\u003Ctext x=\"600\" y=\"72\" text-anchor=\"middle\" class=\"d-text\">Works council rights\u003C\u002Ftext>\u003Ctext x=\"600\" y=\"92\" text-anchor=\"middle\" class=\"d-small\">may apply in AT and DE\u003C\u002Ftext>\u003Ctext x=\"600\" y=\"112\" text-anchor=\"middle\" class=\"d-small\">consent or co-determination\u003C\u002Ftext>\u003Cpath d=\"M355 120 V156\" class=\"d-line\" \u002F>\u003Cpath d=\"M355 164 l-5 -9 h10 z\" class=\"d-head\" \u002F>\u003Ctext x=\"365\" y=\"146\" class=\"d-label\">no\u003C\u002Ftext>\u003Crect x=\"260\" y=\"170\" width=\"190\" height=\"56\" rx=\"10\" class=\"d-mint\" \u002F>\u003Ctext x=\"355\" y=\"194\" text-anchor=\"middle\" class=\"d-text\">Check with counsel\u003C\u002Ftext>\u003Ctext x=\"355\" y=\"213\" text-anchor=\"middle\" class=\"d-small\">suitability, not identity\u003C\u002Ftext>",[203],"The first question is whether the tool can tie activity to a person. It is a practical screen, not the legal test, which asks whether the equipment is suitable for monitoring.",{"type":138,"content":205},[206],"That distinction matters. The legal tests below ask what a piece of equipment is suitable for, not what the employer plans to do with it. A dashboard that nobody opens today can still be a monitoring system.",{"type":152,"level":153,"id":113,"text":114},{"type":138,"content":209},[210],"Section 96(1) no. 3 of the Labour Constitution Act (ArbVG) makes certain employer measures legally effective only with the works council's consent. One of them is the introduction of control measures and technical systems for monitoring employees, insofar as these measures (systems) touch human dignity. The German wording is 'technischen Systemen zur Kontrolle der Arbeitnehmer, sofern diese Maßnahmen (Systeme) die Menschenwürde berühren'.",{"type":138,"content":212},[213],"Section 96(2) allows either party to end a works agreement on these matters in writing, at any time and without notice, unless the agreement sets its own term. The term is therefore part of the negotiation, not a formality.",{"type":138,"content":215},[216],"Section 96a covers systems that collect, process or transmit employees' personal data beyond general personal details and professional qualifications. No consent is needed where the use stays within what law, collective rules or the employment contract require. A second item covers systems for assessing employees, where the data collected is not justified by operational use.",{"type":138,"content":218},[219],"Under § 96a(2), a decision of the arbitration body (Schlichtungsstelle) can replace the works council's consent for these items. Section 96a(3) says these rules leave the consent rights under § 96 untouched. The text I checked gives the arbitration body no power over consent under § 96(1) no. 3, so I would treat a tool that touches human dignity as needing the works council's agreement. Confirm that reading with a lawyer.",{"type":152,"level":153,"id":116,"text":117},{"type":138,"content":222},[223],"Section 87(1) no. 6 of the Works Constitution Act (BetrVG) gives the works council co-determination over the introduction and use of technical equipment designed to monitor employees' behaviour or performance. If no agreement is reached, the conciliation committee (Einigungsstelle) decides, as § 87(2) provides.",{"type":138,"content":225},[226],"Section 90 is the information and consultation duty. The current text of § 90(1) no. 3 covers the planning of work procedures and workflows 'including the use of artificial intelligence' (einschließlich des Einsatzes von Künstlicher Intelligenz). The employer must inform the works council in good time and with the documents needed. Under § 90(2), the employer must also consult on the planned measures and their effects on how people work, early enough that the works council's proposals and concerns can still be considered.",{"type":138,"content":228},[229],"Data protection law applies alongside. Section 26 of the Federal Data Protection Act (BDSG) allows employee data to be processed for employment purposes where necessary, including for the rights and duties of employee representation under a law, a collective agreement or a works agreement. Section 26(4) allows processing on the basis of collective agreements, and the negotiating parties must observe Article 88(2) GDPR. Section 26(2) says that the employee's dependence on the employer must be considered when judging whether consent was freely given.",{"type":152,"level":153,"id":119,"text":120},{"type":138,"content":232},[233],"The Federal Labour Court (BAG) decided in July 2024, in case 1 ABR 16\u002F23, about a headset system that let managers listen in on staff calls. It held that the system was subject to co-determination under § 87(1) no. 6 BetrVG. The decision restates the test: equipment is designed to monitor if it is objectively suitable to collect or record information about behaviour or performance, and the employer's monitoring intent does not matter. Recording is not required; it is enough that the data is made available in a form that can be perceived. The local works council's appeal on points of law failed, because the group works council (Gesamtbetriebsrat) was the competent body.",{"type":138,"content":235},[236],"A labour court in Hamburg looked at AI tools in a different setting. In an interim order of 16 January 2024 (24 BVGa 1\u002F24), it rejected the group works council's applications, including one for a ban on AI use. The dispute centred on ChatGPT and similar tools. I have not read the order itself. What follows comes from two law-firm write-ups, by CMS and by Gleiss Lutz. According to them, the employer first blocked ChatGPT, then released it, encouraged its use and published guidelines asking staff to flag work results produced with AI. The tools were used through the browser, on employees' own accounts rather than on company hardware.",{"type":138,"content":238},[239],"According to the same write-ups, the court found no co-determination under § 87(1) nos. 1, 6 and 7 BetrVG. It treated the tools as work equipment. On no. 6, it reasoned that the employer had no access to the self-created accounts and did not know when, for how long or for what purpose staff used the tool. Telling staff to disclose AI use did not change that. An existing group works agreement already covered browser use. The summaries I read do not discuss company-managed accounts with admin logs, and that is the set-up this article is about.",{"type":138,"content":241},[242],"I would read the Hamburg order as a warning about facts, not as permission. Its reasoning rests on the employer having no access to the accounts. A managed rollout reverses those facts, and the BAG test asks what the equipment is suitable for, not what the employer does with it.",{"type":152,"level":153,"id":122,"text":123},{"type":138,"content":245},[246],"Article 88 of the GDPR allows member states or collective agreements to set more specific rules for employee data. Those rules must include suitable and specific measures to safeguard human dignity, legitimate interests and fundamental rights, with particular regard to transparency and to monitoring systems at the workplace. A works agreement is the natural place for those measures.",{"type":138,"content":248},[249],"The general principles still apply. Personal data must be collected for specified purposes and not used in a way that is incompatible with them (Article 5(1)(b), purpose limitation). It must be adequate, relevant and limited to what is necessary (Article 5(1)(c), data minimisation). It must not be kept longer than necessary (Article 5(1)(e), storage limitation). I would design the logs around those three rules, and let the agreement name each field, its purpose and its retention.",{"type":138,"content":251},[252],"Consent is a weak basis for monitoring at work. Section 26(2) BDSG asks decision-makers to weigh the employee's dependence on the employer when judging whether consent was freely given. Treat individual consent, if at all, as a supplement to the agreement.",{"type":138,"content":254},[255],"Article 35 requires a data protection impact assessment where processing is likely to result in a high risk. Its paragraph 3(a) names a systematic and extensive evaluation of personal aspects, based on automated processing including profiling, on which decisions with legal or similarly significant effects are based. A usage dashboard alone is not automatically in that category, but a performance score built on it may be. Ask your data protection officer to decide. I would do the assessment anyway, because it supplies the facts the agreement needs.",{"type":138,"content":257},[258],"The AI Act adds a second test. Annex III, point 4 covers AI used in employment. Point 4(b) covers AI intended to 'monitor and evaluate the performance and behaviour of persons in such relationships'. Annex III systems count as high-risk under Article 6(2). Article 6(3) can take a system out of that category where it does not pose a significant risk, including by not materially influencing decision-making. The AI Act asks about intended purpose, while the German courts ask about objective suitability, so the two tests do not map one-to-one.",{"type":138,"content":260},[261],"If a tool is high-risk for your use, an employer that deploys it must tell workers' representatives and the affected workers that they will be subject to the system, before it is first used at the workplace (Article 26(7)). That notice sits next to the works council duties above, not in place of them. Regulation (EU) 2026\u002F1744 moves the application date for Annex III high-risk obligations to 2 December 2027; recital 40 gives the original date as 2 August 2026. The same regulation replaces the AI literacy duty in Article 4 with a duty to take measures that support AI literacy, without guaranteeing any specific level for any individual. Check the dates on EUR-Lex before you plan around them.",{"type":263,"head":264,"rows":273},"table",[265,267,269,271],[266],"Question",[268],"Austria",[270],"Germany",[272],"EU: GDPR and AI Act",[274,283,292],[275,277,279,281],[276],"Trigger",[278],"Control measures and technical systems that touch human dignity (§ 96(1) no. 3 ArbVG)",[280],"Equipment designed to monitor behaviour or performance (§ 87(1) no. 6 BetrVG)",[282],"AI intended to monitor and evaluate performance and behaviour (Annex III, point 4(b))",[284,286,288,290],[285],"Works council role",[287],"Consent needed for legal effect; the arbitration body can replace only the § 96a consent",[289],"Co-determination; the conciliation committee decides without agreement (§ 87(2))",[291],"Information to workers' representatives before first use of a high-risk system (Art. 26(7))",[293,295,297,299],[294],"Written agreement",[296],"Works agreement; can be ended in writing at any time unless it sets a term (§ 96(2))",[298],"Works agreement; § 26(4) BDSG allows processing on the basis of collective agreements",[300],"GDPR Art. 88(2): rules need suitable and specific measures",{"type":152,"level":153,"id":125,"text":126},{"type":138,"content":303},[304],"The statutes name goals and procedures, not a template. Here is what I would put in, roughly in this order.",{"type":306,"ordered":307,"items":308},"list",false,[309,315,320,325,330,335,340],[310,314],{"tag":311,"children":312},"strong",[313],"Purpose."," One sentence per use: licence management, security, cost control. Anything outside the list needs a new agreement.",[316,319],{"tag":311,"children":317},[318],"Logged fields."," Name each field, for example seat activity dates and tool version. Name the fields that are never logged, such as prompt text and code content, unless a named purpose needs them.",[321,324],{"tag":311,"children":322},[323],"Access."," Which roles can see per-user data, who logs each access, and that managers get aggregated reports only.",[326,329],{"tag":311,"children":327},[328],"Retention."," A fixed period for each log, with automatic deletion. Do not inherit the vendor's window. GitHub's per-user activity data covers a rolling 90 days, so say what you keep beyond that, if anything.",[331,334],{"tag":311,"children":332},[333],"No performance use."," No appraisal, ranking, bonus or disciplinary use of tool data, and no AI-use score for individuals.",[336,339],{"tag":311,"children":337},[338],"Training."," AI literacy measures for everyone with a seat, in line with the duty to take measures under Article 4 as amended.",[341,344],{"tag":311,"children":342},[343],"Review and exit."," A review date, a right for the works council to see the configuration on request, and a deletion plan for when the tool is switched off.",{"type":138,"content":346},[347],"The telemetry switches are where the agreement becomes technical. This is a conservative setup for Claude Code, based on Anthropic's documentation, with prompt text left redacted:",{"type":161,"code":349},"# Telemetry on; prompt text stays redacted (the default)\nexport CLAUDE_CODE_ENABLE_TELEMETRY=1\nexport OTEL_METRICS_EXPORTER=otlp\nexport OTEL_LOGS_EXPORTER=otlp\nexport OTEL_EXPORTER_OTLP_PROTOCOL=grpc\nexport OTEL_EXPORTER_OTLP_ENDPOINT=http:\u002F\u002Flocalhost:4317  # your own collector\n# Leave this unset unless the agreement names a purpose:\n# export OTEL_LOG_USER_PROMPTS=1",{"type":138,"content":351},[352],"The switches are the easy part. The user identifiers still travel with the metrics, so the access rules matter as much as the configuration. Start with aggregated reporting, and switch per-user views on only once the agreement says who may see them.",{"type":152,"level":153,"id":128,"text":129},{"type":138,"content":355},[356],"The timing follows the statutes' own wording. Germany's § 90 asks for information in good time, with the documents needed. Austria's § 96 makes the measure legally effective only with consent. Germany's § 87 covers introduction and use. The weeks below are my planning suggestion, not a legal timetable.",{"type":263,"head":358,"rows":367},[359,361,363,365],[360],"Phase",[362],"Weeks",[364],"What happens",[366],"Gate",[368,377,386,395,404,413],[369,371,373,375],[370],"Map",[372],"1–2",[374],"List the logged fields per user and per team, and what the vendor sets by default. Draft the purpose list.",[376],"Field list approved internally",[378,380,382,384],[379],"Inform",[381],"2–4",[383],"Give the works council the field list, purposes and pilot plan in writing. Start the impact assessment with the data protection officer.",[385],"Works council has documents and time to respond",[387,389,391,393],[388],"Pilot",[390],"4–10",[392],"Volunteers only, aggregated reporting, no per-user dashboards. Anything that logs people needs the works council's agreement first.",[394],"Pilot data agreed with the works council",[396,398,400,402],[397],"Agree",[399],"10–12",[401],"Negotiate and sign the works agreement, including term, notice and review date. Austria: consent under § 96. Germany: works agreement or conciliation.",[403],"Signed works agreement",[405,407,409,411],[406],"Roll out",[408],"From week 12",[410],"Activate seats in waves, turn on only the telemetry the agreement names, and train every seat holder.",[412],"Access list and retention jobs running",[414,416,418,420],[415],"Review",[417],"Every 6 months",[419],"Check logs against the agreement and reopen it if the vendor changes its fields.",[421],"Review minutes on file",{"type":196,"attrs":423,"inner":426,"caption":427},{"viewBox":424,"role":199,"aria-labelledby":425},"0 0 720 170","d2-gate-t d2-gate-d","\u003Ctitle id=\"d2-gate-t\">Five steps with one gate before any seat is active\u003C\u002Ftitle>\u003Cdesc id=\"d2-gate-d\">Five boxes from left to right: map the logs, inform the works council, run an aggregated pilot, sign the works agreement as the gate, then activate seats in waves. Nothing after the gate starts until the agreement is signed.\u003C\u002Fdesc>\u003Ctext x=\"504\" y=\"56\" text-anchor=\"middle\" class=\"d-label\">gate\u003C\u002Ftext>\u003Crect x=\"12\" y=\"72\" width=\"120\" height=\"62\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"72\" y=\"97\" text-anchor=\"middle\" class=\"d-text\">Map logs\u003C\u002Ftext>\u003Ctext x=\"72\" y=\"117\" text-anchor=\"middle\" class=\"d-small\">fields and users\u003C\u002Ftext>\u003Cpath d=\"M134 103 H150\" class=\"d-line\" \u002F>\u003Cpath d=\"M154 103 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"156\" y=\"72\" width=\"120\" height=\"62\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"216\" y=\"97\" text-anchor=\"middle\" class=\"d-text\">Inform\u003C\u002Ftext>\u003Ctext x=\"216\" y=\"117\" text-anchor=\"middle\" class=\"d-small\">works council\u003C\u002Ftext>\u003Cpath d=\"M278 103 H294\" class=\"d-line\" \u002F>\u003Cpath d=\"M298 103 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"300\" y=\"72\" width=\"120\" height=\"62\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"360\" y=\"97\" text-anchor=\"middle\" class=\"d-text\">Pilot\u003C\u002Ftext>\u003Ctext x=\"360\" y=\"117\" text-anchor=\"middle\" class=\"d-small\">aggregated only\u003C\u002Ftext>\u003Cpath d=\"M422 103 H438\" class=\"d-line\" \u002F>\u003Cpath d=\"M442 103 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"444\" y=\"72\" width=\"120\" height=\"62\" rx=\"10\" class=\"d-accent\" \u002F>\u003Ctext x=\"504\" y=\"97\" text-anchor=\"middle\" class=\"d-text\">Sign\u003C\u002Ftext>\u003Ctext x=\"504\" y=\"117\" text-anchor=\"middle\" class=\"d-small\">works agreement\u003C\u002Ftext>\u003Cpath d=\"M566 103 H582\" class=\"d-line\" \u002F>\u003Cpath d=\"M586 103 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"588\" y=\"72\" width=\"120\" height=\"62\" rx=\"10\" class=\"d-mint\" \u002F>\u003Ctext x=\"648\" y=\"97\" text-anchor=\"middle\" class=\"d-text\">Activate\u003C\u002Ftext>\u003Ctext x=\"648\" y=\"117\" text-anchor=\"middle\" class=\"d-small\">seats in waves\u003C\u002Ftext>",[428],"The gate is the signature, not the pilot. Pilots use aggregated data, so the agreement is the first point where per-user views can switch on.",{"type":145,"variant":430,"title":431,"body":432},"tip","A pilot is not a loophole",[433],[434],"If the pilot logs per-user data, the works council conversation starts on day one, not in week twelve. Design the pilot around aggregated reporting, so nothing has to be unwound later.",{"type":152,"level":153,"id":131,"text":132},{"type":306,"ordered":437,"items":438},true,[439,441,443,445,447,449],[440],"Write down, per plan and per team, which admin fields and telemetry your tools expose, and their default retention.",[442],"Cut the purposes you do not need. Keep one sentence for each purpose you do.",[444],"Switch prompt text off, and decide whether account identifiers belong in metrics at all.",[446],"Brief the works council in writing and early, with the field list and a pilot plan. In Germany, § 90 requires timely information with documents. In Austria, start the § 96 consent conversation before anyone gets per-user access.",[448],"Ask an employment lawyer to classify the set-up under § 96 ArbVG, § 87 BetrVG and the AI Act, and ask your data protection officer about the impact assessment.",[450],"Draft the works agreement from the list above, and settle the term and review date in the first draft.",{"type":138,"content":452},[453,454,459,460,168,464,468,469,473],"For the data side of the same stack, see ",{"tag":455,"to":456,"children":457},"link","\u002Fblog\u002Fgdpr-llm-api-eu-data-residency",[458],"GDPR LLM data residency",", ",{"tag":455,"to":461,"children":462},"\u002Fblog\u002Fpii-redaction-llm-pipelines",[463],"PII redaction in LLM pipelines",{"tag":455,"to":465,"children":466},"\u002Fblog\u002Fagent-observability-opentelemetry",[467],"observability for LLM agents with OpenTelemetry",". For the AI Act timeline, see ",{"tag":455,"to":470,"children":471},"\u002Fblog\u002Feu-ai-act-gpai-high-risk-2026",[472],"EU AI Act beyond Article 50",".",{"type":152,"level":153,"id":134,"text":135},{"type":306,"ordered":437,"items":476},[477,481,484,487,490,493,496,499,502,505,508,511,514,517,520],[478],{"tag":479,"href":32,"children":480},"a",[38],[482],{"tag":479,"href":35,"children":483},[40],[485],{"tag":479,"href":43,"children":486},[42],[488],{"tag":479,"href":46,"children":489},[45],[491],{"tag":479,"href":26,"children":492},[48],[494],{"tag":479,"href":51,"children":495},[50],[497],{"tag":479,"href":29,"children":498},[53],[500],{"tag":479,"href":56,"children":501},[55],[503],{"tag":479,"href":59,"children":504},[58],[506],{"tag":479,"href":62,"children":507},[61],[509],{"tag":479,"href":65,"children":510},[64],[512],{"tag":479,"href":68,"children":513},[67],[515],{"tag":479,"href":71,"children":516},[70],[518],{"tag":479,"href":74,"children":519},[73],[521],{"tag":479,"href":77,"children":522},[76],[524,625,702,784],{"slug":525,"published":526,"minutes":6,"category":7,"tags":527,"keywords":533,"about":542,"sources":552,"cover":619,"og":620,"expertise":80,"locales":621,"lang":82,"title":622,"description":623,"coverAlt":624},"coding-agent-secrets-hygiene","2026-10-08",[528,529,530,531,532],"AI agents","Secrets management","Claude Code","Pre-commit scanning","CI security",[534,535,536,537,538,539,540,541],"coding agent secrets","keep secrets away from AI agents","Claude Code deny read .env","gitleaks pre-commit hook","GitHub push protection secrets","OIDC GitHub Actions short-lived credentials","rotate a leaked API key","MCP server token scope",[543,546,549],{"name":544,"url":545},"Principle of least privilege","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPrinciple_of_least_privilege",{"name":547,"url":548},"Model Context Protocol","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FModel_Context_Protocol",{"name":550,"url":551},"Git","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FGit",[553,556,559,562,565,568,571,574,577,580,583,586,589,592,595,598,601,604,607,610,613,616],{"title":554,"url":555},"Claude Code: permissions","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fpermissions",{"title":557,"url":558},"Claude Code: sandboxed Bash","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fsandboxing",{"title":560,"url":561},"Claude Code: hooks","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fhooks",{"title":563,"url":564},"Claude Code: data usage","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fdata-usage",{"title":566,"url":567},"Claude Code: settings","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fsettings",{"title":569,"url":570},"Claude Code: MCP servers","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fmcp",{"title":572,"url":573},"Codex: configuration reference","https:\u002F\u002Fdevelopers.openai.com\u002Fcodex\u002Fconfig-reference",{"title":575,"url":576},"Codex: agent approvals and security","https:\u002F\u002Flearn.chatgpt.com\u002Fdocs\u002Fagent-approvals-security",{"title":578,"url":579},"Codex: advanced configuration","https:\u002F\u002Flearn.chatgpt.com\u002Fdocs\u002Fconfig-file\u002Fconfig-advanced",{"title":581,"url":582},"GitHub: about push protection","https:\u002F\u002Fdocs.github.com\u002Fen\u002Fcode-security\u002Fsecret-scanning\u002Fintroduction\u002Fabout-push-protection",{"title":584,"url":585},"GitHub: security hardening with OIDC","https:\u002F\u002Fdocs.github.com\u002Fen\u002Factions\u002Fsecurity-for-github-actions\u002Fsecurity-hardening-your-deployments\u002Fabout-security-hardening-with-openid-connect",{"title":587,"url":588},"GitHub: OpenID Connect reference","https:\u002F\u002Fdocs.github.com\u002Fen\u002Factions\u002Freference\u002Fsecurity\u002Foidc",{"title":590,"url":591},"GitHub: using secrets in Actions","https:\u002F\u002Fdocs.github.com\u002Fen\u002Factions\u002Fsecurity-guides\u002Fusing-secrets-in-github-actions",{"title":593,"url":594},"GitHub: secure use reference","https:\u002F\u002Fdocs.github.com\u002Fen\u002Factions\u002Fsecurity-for-github-actions\u002Fsecurity-guides\u002Fsecurity-hardening-for-github-actions",{"title":596,"url":597},"GitHub: removing sensitive data","https:\u002F\u002Fdocs.github.com\u002Fen\u002Fauthentication\u002Fkeeping-your-account-and-data-secure\u002Fremoving-sensitive-data-from-a-repository",{"title":599,"url":600},"gitleaks: README and latest release","https:\u002F\u002Fgithub.com\u002Fgitleaks\u002Fgitleaks",{"title":602,"url":603},"TruffleHog: README","https:\u002F\u002Fgithub.com\u002Ftrufflesecurity\u002Ftrufflehog",{"title":605,"url":606},"detect-secrets: README and latest release","https:\u002F\u002Fgithub.com\u002FYelp\u002Fdetect-secrets",{"title":608,"url":609},"Model Context Protocol: security best practices","https:\u002F\u002Fmodelcontextprotocol.io\u002Fspecification\u002F2025-06-18\u002Fbasic\u002Fsecurity_best_practices",{"title":611,"url":612},"OWASP: Secrets Management Cheat Sheet","https:\u002F\u002Fcheatsheetseries.owasp.org\u002Fcheatsheets\u002FSecrets_Management_Cheat_Sheet.html",{"title":614,"url":615},"OWASP: LLM02 sensitive information disclosure","https:\u002F\u002Fgenai.owasp.org\u002Fllmrisk\u002Fllm022025-sensitive-information-disclosure\u002F",{"title":617,"url":618},"Git: git-add documentation","https:\u002F\u002Fgit-scm.com\u002Fdocs\u002Fgit-add","\u002Fimages\u002Fblog\u002Fcoding-agent-secrets-hygiene\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fcoding-agent-secrets-hygiene\u002Fog.jpg",[82,83,84],"Coding agents and secrets: keep keys out of context, logs and commits","How secrets leak through coding agents, and the controls that stop them: deny reads, a sandbox, pre-commit scans, push protection, OIDC and rotation.","Cover art for coding agents and secrets: a shield of six layered controls, from deny rules and a sandbox to rotation.",{"slug":626,"published":627,"minutes":628,"category":7,"tags":629,"keywords":634,"about":643,"sources":655,"cover":696,"og":697,"expertise":80,"locales":698,"lang":82,"title":699,"description":700,"coverAlt":701},"dpia-llm-feature-worked-example","2026-10-01",12,[630,12,631,632,633],"DPIA","LLM security","Data protection","AI Act",[635,636,637,638,639,640,641,642],"DPIA for LLM features","data protection impact assessment AI assistant","GDPR Article 35 AI","DSFA-V Austria AI","LLM customer support GDPR","prompt injection data leak GDPR","AI Act Article 50 chatbot","DPIA template LLM",[644,646,649,652],{"name":25,"url":645},"https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002F?uri=CELEX:32016R0679",{"name":647,"url":648},"WP29 guidelines on data protection impact assessment (WP248 rev.01)","https:\u002F\u002Fec.europa.eu\u002Fnewsroom\u002Farticle29\u002Fitems\u002F611236\u002Fen",{"name":650,"url":651},"OWASP LLM01:2025 Prompt Injection","https:\u002F\u002Fgenai.owasp.org\u002Fllmrisk\u002Fllm01-prompt-injection\u002F",{"name":653,"url":654},"Regulation (EU) 2024\u002F1689 (AI Act)","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2024\u002F1689\u002Foj",[656,657,659,662,665,668,671,674,677,680,682,684,687,690,693,694],{"title":48,"url":645},{"title":658,"url":648},"WP29 guidelines on DPIA, WP248 rev.01 (European Commission item page)",{"title":660,"url":661},"WP248 rev.01 PDF, adopted 4 April 2017 and revised 4 October 2017","https:\u002F\u002Fec.europa.eu\u002Fnewsroom\u002Fjust\u002Fdocument.cfm?doc_id=47711",{"title":663,"url":664},"EDPB Guidelines 07\u002F2020 on the concepts of controller and processor","https:\u002F\u002Fwww.edpb.europa.eu\u002Fsystem\u002Ffiles\u002F2023-10\u002Fedpb_guidelines_202007_controllerprocessor_final_en.pdf",{"title":666,"url":667},"EDPB Opinion 28\u002F2024 on AI models, adopted 17 December 2024","https:\u002F\u002Fwww.edpb.europa.eu\u002Fsystem\u002Ffiles\u002F2024-12\u002Fedpb_opinion_202428_ai-models_en.pdf",{"title":669,"url":670},"EDPB news release on Opinion 28\u002F2024","https:\u002F\u002Fwww.edpb.europa.eu\u002Fnews\u002Fedpb-opinion-on-ai-models-gdpr-principles-support-responsible-ai_en",{"title":672,"url":673},"EDPB, Report of the work undertaken by the ChatGPT Taskforce, 23 May 2024","https:\u002F\u002Fwww.edpb.europa.eu\u002Fsystem\u002Ffiles\u002F2024-05\u002Fedpb_20240523_report_chatgpt_taskforce_en.pdf",{"title":675,"url":676},"DSFA-V, BGBl. II Nr. 278\u002F2018 (RIS)","https:\u002F\u002Fwww.ris.bka.gv.at\u002Feli\u002Fbgbl\u002FII\u002F2018\u002F278",{"title":678,"url":679},"DSFA-AV, BGBl. II Nr. 108\u002F2018 (RIS)","https:\u002F\u002Fwww.ris.bka.gv.at\u002Feli\u002Fbgbl\u002FII\u002F2018\u002F108",{"title":681,"url":651},"OWASP Top 10 for LLM Applications 2025: LLM01 Prompt Injection",{"title":683,"url":615},"OWASP Top 10 for LLM Applications 2025: LLM02 Sensitive Information Disclosure",{"title":685,"url":686},"OpenAI, Data controls in the OpenAI platform","https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fyour-data",{"title":688,"url":689},"Commission Implementing Decision (EU) 2023\u002F1795 on the EU–US Data Privacy Framework","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdec_impl\u002F2023\u002F1795\u002Foj\u002Feng",{"title":691,"url":692},"CJEU, Case C-184\u002F20, OT v Vyriausioji tarnybinės etikos komisija","https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002F?uri=CELEX:62020CJ0184",{"title":53,"url":654},{"title":695,"url":56},"Regulation (EU) 2026\u002F1744 (Digital Omnibus on AI), EUR-Lex","\u002Fimages\u002Fblog\u002Fdpia-llm-feature-worked-example\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fdpia-llm-feature-worked-example\u002Fog.jpg",[82,83,84],"DPIA for an LLM support assistant: a worked example under GDPR Art. 35","A worked DPIA under GDPR Art. 35 for an AI assistant that drafts customer email replies from order data: when it is needed, the risks and owners.","Cover art for a DPIA of an LLM support assistant: a pipeline of six steps, from the high-risk test to the review date.",{"slug":703,"published":704,"minutes":628,"category":7,"tags":705,"keywords":710,"about":721,"sources":731,"cover":778,"og":779,"expertise":80,"locales":780,"lang":82,"title":781,"description":782,"coverAlt":783},"eu-ai-act-gpai-high-risk-2026","2026-09-24",[706,707,708,709],"EU AI Act","GPAI","High-risk AI","AI compliance",[711,712,713,714,715,716,717,718,719,720],"EU AI Act high-risk deadline","AI Act digital omnibus","AI Act GPAI obligations","AI Act provider vs deployer","EU AI Act 2 December 2027","GPAI code of practice","AI literacy Article 4","AI Act compliance checklist","AI Act OpenAI API provider deployer","AI Act mid-size company",[722,725,728],{"name":723,"url":724},"Artificial Intelligence Act","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FArtificial_Intelligence_Act",{"name":726,"url":727},"General-purpose artificial intelligence","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FFoundation_model",{"name":729,"url":730},"European Commission","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FEuropean_Commission",[732,733,734,737,740,743,746,749,752,755,757,760,763,766,769,772,775],{"title":53,"url":654},{"title":695,"url":56},{"title":735,"url":736},"AI Act Explorer: Digital Omnibus on AI, full amending text","https:\u002F\u002Fartificialintelligenceact.eu\u002Fai-act-explorer\u002Fdigital-omnibus\u002F",{"title":738,"url":739},"European Commission: AI Act regulatory framework and timeline","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fregulatory-framework-ai",{"title":741,"url":742},"European Commission: Guidelines for providers of general-purpose AI models","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fguidelines-gpai-providers",{"title":744,"url":745},"European Commission: Q&A on the guidelines for GPAI providers","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Ffaqs\u002Fguidelines-obligations-general-purpose-ai-providers",{"title":747,"url":748},"European Commission: The General-Purpose AI Code of Practice","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fcontents-code-gpai",{"title":750,"url":751},"European Commission: AI literacy Questions and Answers","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Ffaqs\u002Fai-literacy-questions-answers",{"title":753,"url":754},"AI Act Article 25: Responsibilities along the AI value chain","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F25\u002F",{"title":756,"url":59},"AI Act Article 26: Obligations of deployers of high-risk AI systems",{"title":758,"url":759},"AI Act Article 27: Fundamental rights impact assessment","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F27\u002F",{"title":761,"url":762},"AI Act Article 53: Obligations for providers of general-purpose AI models","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F53\u002F",{"title":764,"url":765},"AI Act Article 99: Penalties","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F99\u002F",{"title":767,"url":768},"AI Act Article 101: Fines for providers of general-purpose AI models","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F101\u002F",{"title":770,"url":771},"Gibson Dunn: EU AI Act Omnibus Agreement, postponed high-risk deadlines (27 May 2026)","https:\u002F\u002Fwww.gibsondunn.com\u002Feu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes\u002F",{"title":773,"url":774},"Orrick: EU AI Act Update, Digital Omnibus finalizes 8 compliance changes (29 July 2026)","https:\u002F\u002Fwww.orrick.com\u002Fen\u002FInsights\u002F2026\u002F07\u002FEU-AI-Act-Update-Digital-Omnibus-Finalizes-8-Compliance-Changes",{"title":776,"url":777},"K&L Gates: EU Digital Omnibus on AI enters into force (31 July 2026)","https:\u002F\u002Fwww.klgates.com\u002FEU-Digital-Omnibus-on-AI-Enters-Into-Force-7-31-2026","\u002Fimages\u002Fblog\u002Feu-ai-act-gpai-high-risk-2026\u002Fcover.webp","\u002Fimages\u002Fblog\u002Feu-ai-act-gpai-high-risk-2026\u002Fog.jpg",[82,83,84],"EU AI Act beyond Article 50: GPAI, high-risk dates and what to do now","The AI Act after the Digital Omnibus: GPAI duties, high-risk dates (2 Dec 2027 and 2 Aug 2028), provider vs deployer on OpenAI and Anthropic APIs, AI literacy.","Diagram: the AI Act timeline from February 2025 to August 2028, fanning out into GPAI duties, high-risk systems, provider and deployer roles and AI literacy.",{"slug":785,"published":786,"minutes":628,"category":7,"tags":787,"keywords":793,"about":802,"sources":809,"cover":824,"og":825,"expertise":80,"locales":826,"lang":82,"title":827,"description":828,"coverAlt":829},"eu-ai-act-article-50-developer-checklist","2026-09-22",[706,788,789,790,791,792],"Article 50","AI transparency","Digital Omnibus","AI literacy","Compliance",[706,794,795,796,797,798,799,800,717,801],"EU AI Act developers","Article 50 AI Act","AI transparency obligations","AI Act chatbot disclosure","Digital Omnibus AI Act","AI Act Article 50(2) watermarking","AI Act deepfake labelling","does the AI Act apply to my app",[803,804,806],{"name":723,"url":724},{"name":805,"url":56},"Regulation (EU) 2026\u002F1744",{"name":807,"url":808},"AI Act Explorer","https:\u002F\u002Fartificialintelligenceact.eu\u002Fai-act-explorer\u002F",[810,813,816,819,821],{"title":811,"url":812},"Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F50\u002F",{"title":814,"url":815},"Regulation (EU) 2026\u002F1744 (Digital Omnibus on AI), Official Journal, 24 Jul 2026","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2026\u002F1744\u002Foj\u002Feng",{"title":817,"url":818},"Faegre Drinker: Commission confirms Transparency Code of Practice as adequate and publishes final Article 50 Guidelines (30 Jul 2026)","https:\u002F\u002Fwww.faegredrinker.com\u002Fen\u002Finsights\u002Fpublications\u002F2026\u002F7\u002Feu-ai-act-commission-confirms-transparency-code-of-practice-as-adequate-and-publishes-final-version-of-its-guidelines-on-transparency-obligations",{"title":820,"url":771},"Gibson Dunn: EU AI Act Omnibus Agreement, postponed high-risk deadlines and other key changes (27 May 2026)",{"title":822,"url":823},"RTR KI-Servicestelle: AI Act (Austria)","https:\u002F\u002Fwww.rtr.at\u002Frtr\u002Fservice\u002Fki-servicestelle\u002Fai-act\u002F","\u002Fimages\u002Fblog\u002Feu-ai-act-article-50-developer-checklist\u002Fcover.webp","\u002Fimages\u002Fblog\u002Feu-ai-act-article-50-developer-checklist\u002Fog.jpg",[82,83,84],"EU AI Act Article 50: what developers must do from 2 August 2026","EU AI Act Article 50 transparency duties for developers: AI interaction disclosure, machine-readable marking, deepfakes, provider versus deployer and a checklist.","A six-step timeline from February 2025 to August 2028 covering the AI Act milestones, with the Article 50 step in August 2026 highlighted.",1791636875194]