Meet the Authors

Key Takeaways What you need to know
  1. q.beyond launched "AI Act as a Service" on June 9, 2026, offering auditable risk classification for AI systems in production or planning.

  2. Most EU AI Act general requirements take binding effect in August 2026, with high-risk system obligations following in December 2027.

  3. The service is bookable directly online with a free tier for basic assessment; Antares Project GmbH is among the first customers to move it into production.

Cologne-based IT services firm q.beyond has released “AI Act as a Service,” a subscription offering that produces an auditable risk assessment of a company’s deployed and planned AI systems. The launch lands before the August 2026 date when most general requirements of the EU AI Act take binding effect on companies operating in the bloc.

The service addresses a gap q.beyond describes as common among its mid-market customers: enterprises are running “several thousand active AI users” and “several dozen large language models (LLMs) and agents” without a documented evaluation of how those systems map to the regulation’s risk tiers. Managers responsible for AI can use the tool to evaluate systems in use, obtain a risk assessment, and generate the supporting documentation and verification the Act requires.

What the Service Does

Customers can book the offering directly on q.beyond’s website without prior integration, according to the company. Pricing runs on a monthly subscription tied to the number of accounts covered, and a free version supports a basic assessment of AI Act requirements for a single application. The company positions the tool for CIOs, compliance managers, and CISOs.

Explore related questions

“Companies can start directly with AI Act as a Service and promptly obtain an auditable risk assessment,” said Dr. Daniel Taradzic, Chief AI Officer at q.beyond AG, in the announcement. Ingo List, Managing Director of Antares Project GmbH, said his firm had “several thousand active AI users but no assessment of the EU AI Act requirements” before adopting the service.

Why the Timing Matters

The EU AI Act classifies AI systems by risk level: unacceptable-risk uses such as social scoring are prohibited, high-risk systems face the most extensive regulation, limited-risk systems carry transparency duties, and minimal-risk applications are unregulated. Obligations fall primarily on providers of high-risk systems, but deployers—defined as natural or legal persons using AI in a professional capacity—also carry duties, and third-country providers are in scope when their output is used in the EU. Requirements are triggered by an application’s potential risk rather than a company’s size, meaning smaller firms can inherit high-risk obligations depending on the use case.

That distinction matters for the SME segment q.beyond primarily serves. The Act references SMEs 38 times and includes tailored measures such as priority sandbox access, proportional conformity assessment fees, simplified technical documentation forms, and dedicated communication channels. For downstream providers and deployers building applications on top of general-purpose AI models, the distinction between GPAI models and GPAI models with systemic risk does not determine their obligations—what matters is whether the intended use falls into a prohibited, high-risk, or transparency-triggering category.

Where the Offering Fits in Q.beyond’s Portfolio

q.beyond describes itself as an IT partner focused on European SMEs, with more than 1,000 specialists and operations centered on public and private clouds, Microsoft and SAP application operations, artificial intelligence, and IT security. The company runs proprietary certified AI data centers and maintains offices in Germany, Latvia, Spain, India, and the United States.

The AI Act service extends a portfolio that includes q.beyond’s Private Enterprise AI platform for processing sensitive corporate data and custom AI agents for retail, manufacturing, logistics, banking and insurance, healthcare, energy, and public sector customers, which q.beyond runs as managed services. The company frames regulatory clarity as the entry condition for the productivity gains those managed services are meant to deliver.

Practitioner Takeaway

For SAP customers running Microsoft- and SAP-based workloads through providers like q.beyond, the August 2026 milestone converts an internal AI inventory question into a documented compliance artifact.

High-risk classifications under Annex III cover use cases familiar to enterprise buyers—recruitment and workforce management, creditworthiness evaluation, and safety components in critical infrastructure among them—which means HR, finance, and operations deployments of generative AI can pull an organization into the Act’s most demanding tier.

A packaged assessment shortens the path from an untracked LLM footprint to the risk management system, technical documentation, and human oversight design the regulation expects from high-risk providers.

What This Means for SAPinsiders

  • Compliance becomes continuous portfolio management. Subscription delivery can turn AI Act review from a legal checkpoint into a recurring control tied to application growth. That pressures companies to centralize inventories, ownership, and renewal decisions before unmanaged tools outpace governance capacity.
  • Evidence becomes part of vendor selection. Providers that operate AI systems and generate their compliance records can offer customers a shorter path to defensible oversight. This model also concentrates operational knowledge and audit evidence with one supplier, increasing the importance of portability and independent verification.
  • Use-case governance moves ahead of procurement. Because classification follows intended use, companies must evaluate business purpose before approving platforms, models, or agents. The primary bottleneck therefore shifts from technical access to decision rights over which AI applications may enter production.

Events

29Oct
SAPinsider Summit New Orleans 2026New Orleans, Louisiana, United States
View All