top of page
Donau City DC Tower,  Wien in Austria

COMPLIANCE AUSTRIA

Compliance Austria.
Enforces at runtime.

In Austria, too, the EU AI Act applies directly – complemented by GDPR, the Austrian Data Protection Act and the AI service desk as the national point of contact. EVEDY enforces these requirements where AI actually works: at runtime.

CLEAR CONTROL. SECURE REGULATIONS

The regulatory landscape for AI in Austria

No separate Austrian 'AI act', but directly applicable EU law plus national supervisory structures and sector expectations.

Regulation

What it requires

How EVEDY enforces it

EU AI Act

In force since 08/2024; duties phasing in through 2027

Risk-based duties: prohibited practices, AI literacy (Art. 4), transparency, logging, human oversight and robustness – strictest for high-risk systems.

End-to-end logging of every interaction, policies per risk class, human-oversight escalation, evidence documentation for conformity assessments.

GDPR & DSG

EU General Data Protection Regulation and the Austrian Data Protection Act

Lawful bases, data minimisation, individual rights, limits on automated individual decisions (Art. 22 GDPR); supervised by the Data Protection Authority.

Automatic PII redaction in prompts and responses, access control via your IAM, marked automated decisions, complete logging.

AI service desk & national supervision

AI service desk at RTR; market surveillance structures being established

Coordination and information duties; enterprises must be able to evidence the compliant use of their AI systems.

Tamper-evident audit trails per regulation – defensible evidence for authority requests and audits.

FMA expectations

Financial sector: expectations of the Financial Market Authority

Governance and risk management for AI use in banks, insurers and investment firms; clear accountability and controls.

A central control plane across all models and agents, testing and evaluation of every version, continuous monitoring of non-deterministic behaviour.

ISO/IEC 42001 & internal policies

AI management standard and your own directives

A systematic AI management system: roles, processes, continuous improvement – plus your enterprise AI policies.

Enterprise policies are stored as machine-enforceable rules and applied automatically to every AI interaction – not just documented.

As of August 2026. This overview does not constitute legal advice.

THE DIFFERENCE

From written policy to runtime enforcement

Most enterprises have AI policies. Very few can prove they are followed. EVEDY closes exactly that gap.

1

Capture the rules

Legal requirements and internal policies are modelled as machine-readable policies – synchronised from your GRC platform if you wish.

2

Enforce at runtime

Every request to a model or agent passes through EVEDY. Violations are blocked, corrected or escalated – in real time, not after the fact.

3

Prove compliance

Audit trails per user, per agent and per regulation give internal audit, the board and regulators defensible evidence at any time.

bottom of page