EU AI Act + Schrems-II for Joule Deployments
As of 2026-09-27
What is EU AI Act + Schrems-II for Joule Deployments?
A Joule deployment in the EU is governed by two separate regimes: the AI Act (high-risk duties now from 2 Dec 2027 for Annex III after the Digital Omnibus) and GDPR transfer rules (Schrems II; the EU-US Data Privacy Framework upheld by the General Court on 3 Sep 2025, appeal pending) — each needs its own decision.
A Joule rollout in the EU has to clear two different legal tests that are easy to confuse. The first is the EU AI Act (Regulation (EU) 2024/1689): does the configured Joule scenario fall into a risk tier with obligations, and who — SAP or the customer — carries them? The second is the GDPR's regime for international transfers, shaped by the Court of Justice's Schrems II judgment (Case C-311/18, 16 July 2020): when personal data reaches a model endpoint or support process outside the EEA, is there a valid transfer mechanism? A scenario can pass one test and fail the other. The architect's job is to answer both before the first sprint, and to design so that the answers can change without a rebuild.
Test 1 — the AI Act, after the Omnibus
The AI Act was amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026). High-risk requirements now apply from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems, instead of 2 December 2027 and 2 August 2027. Other obligations already apply: the Article 5 prohibitions and Article 4 AI-literacy measures since 2 February 2025, GPAI-provider obligations since 2 August 2025, and Article 50 transparency since 2 August 2026 — telling users they are interacting with an AI system is a live obligation for a Joule assistant today.
Why it matters
- Two regimes, two decisions: the AI Act tier (high-risk from 2 Dec 2027 for Annex III) and the GDPR transfer basis are assessed separately — passing one says nothing about the other.
- Employment AI is explicitly Annex III (point 4): a Joule agent that ranks applicants or proposes performance measures is high-risk once it materially shapes the decision.
- The EU-US Data Privacy Framework survived annulment at first instance (T-553/23, 3 Sep 2025) but an appeal is reported pending — design for a switchable transfer basis.
Key points
- AI Act as amended by Regulation (EU) 2026/1744: high-risk duties from 2 Dec 2027 (Annex III) and 2 Aug 2028 (Annex I); Art. 50 transparency already applies since 2 Aug 2026.
- Joule triggers: Annex III point 4 (recruitment, promotion, termination, task allocation, performance monitoring) and point 5 (consumer credit scoring, life/health insurance pricing).
- Art. 6(3) can take an Annex III system out of high-risk (narrow/preparatory task, no profiling) — only with a documented assessment.
- Customers building agents in Joule Studio or repurposing SAP features can become providers (Art. 25); deployers keep Art. 26 duties incl. informing workers' representatives.
- Transfers: Schrems II (C-311/18, 2020) → Data Privacy Framework (Decision (EU) 2023/1795) upheld by the General Court on 3 Sep 2025 (T-553/23); appeal reported (C-703/25 P).
- Model choice drives residency: check SAP Note 3437766 and sovereign-cloud flags; Mistral AI and Cohere are SAP's announced sovereign model options.
Terms used on this page
- EU AI Act (Regulation (EU) 2024/1689)
- Risk-based EU regulation for AI systems and GPAI models, in force since 1 Aug 2024; amended by the Digital Omnibus (Regulation (EU) 2026/1744) in July 2026.
- Schrems II
- CJEU judgment C-311/18 of 16 July 2020 that invalidated the EU-US Privacy Shield and required case-by-case assessment of transfers under standard contractual clauses.
- EU-US Data Privacy Framework
- Adequacy decision (EU) 2023/1795 of 10 July 2023 for transfers to certified US organisations; action for annulment dismissed by the General Court on 3 Sep 2025 (T-553/23).
- Article 26 deployer duties
- Use per instructions, competent human oversight, monitoring, log retention, and informing workers' representatives before deploying high-risk AI at the workplace.
- Transfer impact assessment
- Documented assessment, required after Schrems II when relying on standard contractual clauses, of whether the destination country's law undermines the safeguards.
Sources
- EUR-Lex — Regulation (EU) 2024/1689 (AI Act)
- EUR-Lex — Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ L 24.7.2026
- EUR-Lex — CJEU Case C-311/18 (Schrems II), 16 July 2020
- CJEU press release No 106/25 — General Court dismisses action against the EU-US data transfer framework (T-553/23), 3 Sep 2025
- IAPP — General Court upholds EU-US Data Privacy Framework (secondary; appeal status)
- SAP News — SAP unveils the Autonomous Enterprise (Sapphire 2026; Mistral AI and Cohere sovereign model options)
- SAP AI Core — product guide PDF incl. What's New (generative AI hub models, sovereign-cloud flags), 2026-09-04
- AI Act Article 99 — penalties (reading aid)
- SAP News Center — AI agents work at scale: AI Governance Assistant, EU AI Act + NIST classification (22 Sep 2026)
- SAP Help Portal — generative AI hub model access and providers
- LeanIX — SAP LeanIX announces launch of AI Agent Hub (4 Nov 2025)
- Microsoft Learn — OpenAI as a subprocessor in Microsoft Fabric
- SAP News Center — secure AI agents: SAP and NVIDIA co-define enterprise-grade agent execution (12 May 2026)
Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.
Guides that answer with this page
These guides cite this page as one of the sources their answer rests on.