AI compliance Munich

Use AI without losing control of data and accountability.

Cleero takes Munich businesses from initial AI Act orientation to a reliable AI register, clear ownership, practical actions and traceable evidence.

✓ AI register and data sources✓ AI Act role assessment✓ Internal AI policy✓ Training and ongoing control

From general AI assistants to specialist systems

The first gap is usually a lack of visibility.

Teams often use AI before purpose, data, providers, versions, approvals and changes are documented. Cleero creates transparency first and derives practical guardrails rather than blanket bans.

01

AI register

Document the system, provider, role, first use, version, purpose, changes, evidence and owner.

02

Privacy review

Assess legal basis, processing terms, transfers, training data, confidentiality and DPIA needs.

03

AI Act roles

Identify provider, deployer or other roles and the resulting duties.

04

Internal guardrails

Define approved tools, prohibited inputs, approvals, controls and training.

Turn official orientation into action

Orientation is the beginning. Cleero makes it actionable.

The Federal Network Agency’s free AI Compliance Compass provides an initial, non-binding orientation. Cleero does not duplicate it: we turn the outcome into an operating system of owners, actions, target dates and evidence.

Open the official compass ↗
  1. 01
    Orient

    Narrow down the system, role and possible risk level.

  2. 02
    Implement

    Assign owners, concrete checks and a realistic timeline.

  3. 03
    Evidence

    Bring versions, decisions, approvals and records together in the Evidence Pack.

Maintain a traceable history for existing AI

The tool alone is not enough. Its history matters.

A timeline assessment needs findable facts. Cleero records the information required for review instead of presenting an automatic legal conclusion.

01

Role and date

Provider, deployer or another role, plus placement on the market or putting into service.

02

System and version

Provider, product, current version and supporting version record.

03

Purpose over time

Compare the original and current intended purpose.

04

Changes from 2 August 2026

Record the date and describe design, functional and purpose changes factually.

05

Source and evidence

Link release notes, contracts, screenshots or change records.

06

Review status and owner

Open, no indication or individual legal review required.

The local AI register is now included in the Cleero app. Entries remain on the device and can be exported with the working file.

Open the AI register in the app →

Article 111(2) is a transition rule for certain high-risk AI systems placed on the market or put into service before 2 August 2026. It is not a general exemption for all existing AI. Article 5 and other applicable laws require separate assessment. Cleero does not automatically determine whether a change is significant.

New specialist module

Cleero reviews not only the AI tool, but also the provenance of its training data.

This becomes relevant for in-house training, fine-tuning, web scraping or acquired datasets. The main path remains deliberately lean for ordinary users of ready-made AI tools.

EDPB Guidelines 03/2026: consultation draft until 30 October 2026.
  1. 01
    Own model

    You train or optimise your own AI model.

  2. 02
    Web data

    You or a third party collect publicly accessible web data.

  3. 03
    External dataset

    You purchase or obtain pre-assembled training data.

Cleero 5

The Cleero AI compliance process

01

Inventory

Map actual systems and informal use cases.

02

Assessment

Determine roles, data flows, risks and transparency duties.

03

Implementation

Set actions, approvals, ownership and required evidence.

04

Routine

Track versions, purpose and functional changes and train teams.

Local context

Connect AI compliance with existing privacy work.

Cleero integrates AI governance with privacy processes instead of creating parallel lists and conflicting ownership. Individual legal questions are reviewed only under a separately agreed legal mandate.

A quick first assessmentArticle 50 quick check with full assessment ↗

Frequently asked questions

Clear answers.

May employees use ChatGPT and other AI tools?+

Not as a blanket yes or no. Purpose, input data, provider terms, transfers and internal approval all matter.

What belongs in an AI register?+

At minimum: system, provider, role, date placed in service, version, original and current purpose, changes, owner, data, approval, evidence and next review.

Does AI Act Article 50 apply to every business?+

No. Duties depend on role, system and use, including direct AI interaction, synthetic content, deepfakes and certain public-interest text.

When is the AI Data Sources Check relevant?+

Where you train or adapt your own model, collect publicly accessible web data yourself or through a third party, or obtain pre-assembled training datasets. It is not automatically needed for ordinary use of a ready-made AI tool.

Is AI compliance only a legal project?+

No. It needs legal, privacy, IT, security, business owners and management decisions.

This content provides general guidance. Legal advice and binding individual legal assessments are not Cleero services.

Your next clear step

Know where you stand. Then act with confidence.

Tell us briefly where you stand. We will be open about what matters and which next step makes sense.

Book a consultation