AI & Analytics Legends The knowledge platform for SAP Analytics
Concept card

EU AI Act + Schrems-II for Joule Deployments

EU AI Act + Schrems-II for Joule Deployments — Analytics Legends section illustration for the SAP Analytics knowledge base (concepts, studies, Academy)

As of 2026-09-27

What is EU AI Act + Schrems-II for Joule Deployments?

A Joule deployment in the EU is governed by two separate regimes: the AI Act (high-risk duties now from 2 Dec 2027 for Annex III after the Digital Omnibus) and GDPR transfer rules (Schrems II; the EU-US Data Privacy Framework upheld by the General Court on 3 Sep 2025, appeal pending) — each needs its own decision.

A Joule rollout in the EU has to clear two different legal tests that are easy to confuse. The first is the EU AI Act (Regulation (EU) 2024/1689): does the configured Joule scenario fall into a risk tier with obligations, and who — SAP or the customer — carries them? The second is the GDPR's regime for international transfers, shaped by the Court of Justice's Schrems II judgment (Case C-311/18, 16 July 2020): when personal data reaches a model endpoint or support process outside the EEA, is there a valid transfer mechanism? A scenario can pass one test and fail the other. The architect's job is to answer both before the first sprint, and to design so that the answers can change without a rebuild.

Test 1 — the AI Act, after the Omnibus

The AI Act was amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026). High-risk requirements now apply from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems, instead of 2 December 2027 and 2 August 2027. Other obligations already apply: the Article 5 prohibitions and Article 4 AI-literacy measures since 2 February 2025, GPAI-provider obligations since 2 August 2025, and Article 50 transparency since 2 August 2026 — telling users they are interacting with an AI system is a live obligation for a Joule assistant today.

Why it matters

  • Two regimes, two decisions: the AI Act tier (high-risk from 2 Dec 2027 for Annex III) and the GDPR transfer basis are assessed separately — passing one says nothing about the other.
  • Employment AI is explicitly Annex III (point 4): a Joule agent that ranks applicants or proposes performance measures is high-risk once it materially shapes the decision.
  • The EU-US Data Privacy Framework survived annulment at first instance (T-553/23, 3 Sep 2025) but an appeal is reported pending — design for a switchable transfer basis.

Key points

  • AI Act as amended by Regulation (EU) 2026/1744: high-risk duties from 2 Dec 2027 (Annex III) and 2 Aug 2028 (Annex I); Art. 50 transparency already applies since 2 Aug 2026.
  • Joule triggers: Annex III point 4 (recruitment, promotion, termination, task allocation, performance monitoring) and point 5 (consumer credit scoring, life/health insurance pricing).
  • Art. 6(3) can take an Annex III system out of high-risk (narrow/preparatory task, no profiling) — only with a documented assessment.
  • Customers building agents in Joule Studio or repurposing SAP features can become providers (Art. 25); deployers keep Art. 26 duties incl. informing workers' representatives.
  • Transfers: Schrems II (C-311/18, 2020) → Data Privacy Framework (Decision (EU) 2023/1795) upheld by the General Court on 3 Sep 2025 (T-553/23); appeal reported (C-703/25 P).
  • Model choice drives residency: check SAP Note 3437766 and sovereign-cloud flags; Mistral AI and Cohere are SAP's announced sovereign model options.

Terms used on this page

EU AI Act (Regulation (EU) 2024/1689)
Risk-based EU regulation for AI systems and GPAI models, in force since 1 Aug 2024; amended by the Digital Omnibus (Regulation (EU) 2026/1744) in July 2026.
Schrems II
CJEU judgment C-311/18 of 16 July 2020 that invalidated the EU-US Privacy Shield and required case-by-case assessment of transfers under standard contractual clauses.
EU-US Data Privacy Framework
Adequacy decision (EU) 2023/1795 of 10 July 2023 for transfers to certified US organisations; action for annulment dismissed by the General Court on 3 Sep 2025 (T-553/23).
Article 26 deployer duties
Use per instructions, competent human oversight, monitoring, log retention, and informing workers' representatives before deploying high-risk AI at the workplace.
Transfer impact assessment
Documented assessment, required after Schrems II when relying on standard contractual clauses, of whether the destination country's law undermines the safeguards.

Sources

  1. EUR-Lex — Regulation (EU) 2024/1689 (AI Act)
  2. EUR-Lex — Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ L 24.7.2026
  3. EUR-Lex — CJEU Case C-311/18 (Schrems II), 16 July 2020
  4. CJEU press release No 106/25 — General Court dismisses action against the EU-US data transfer framework (T-553/23), 3 Sep 2025
  5. IAPP — General Court upholds EU-US Data Privacy Framework (secondary; appeal status)
  6. SAP News — SAP unveils the Autonomous Enterprise (Sapphire 2026; Mistral AI and Cohere sovereign model options)
  7. SAP AI Core — product guide PDF incl. What's New (generative AI hub models, sovereign-cloud flags), 2026-09-04
  8. AI Act Article 99 — penalties (reading aid)
  9. SAP News Center — AI agents work at scale: AI Governance Assistant, EU AI Act + NIST classification (22 Sep 2026)
  10. SAP Help Portal — generative AI hub model access and providers
  11. LeanIX — SAP LeanIX announces launch of AI Agent Hub (4 Nov 2025)
  12. Microsoft Learn — OpenAI as a subprocessor in Microsoft Fabric
  13. SAP News Center — secure AI agents: SAP and NVIDIA co-define enterprise-grade agent execution (12 May 2026)

Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.

Open in the app →