Many German companies are underestimating the current situation: while the deadline for high-risk AI systems has been pushed back to December 2027, enforcement measures for General Purpose AI (GPAI) have been active since August 2, 2026. The European AI Office can now request documentation from providers, evaluate models, and order recalls. Violations carry fines of up to €15 million or 3% of global turnover.
The essentials
- GPAI rules have been in effect since August 2, 2026 – the postponement applies only to high-risk systems
- 35% of German companies identify machine identity management as their biggest AI security gap (Keeper Security study 2026)
- Code of Practice requires technical safeguards: centralized credential management, time-limited access, audit-proof logging
- December 2027 is the new deadline for high-risk systems – but measures already in effect must be implemented by then
The Digital Omnibus postpones, but not everything
The Digital Omnibus, which stakeholders provisionally agreed on in early 2026, does bring relief – but only for part of the requirements. Classification and conformity assessment of high-risk systems is pushed to December 2027. This gives organizations more planning time. However, this postponement does not change measures that are already in effect: the voluntary GPAI Code of Practice is already binding for providers wanting to demonstrate compliance.
The Code of Practice's chapter on Safety and Security is clearer than many political discussions: it's not about policy papers, but about Access Governance – the technical protection of model weights, defense against insider threats, and strict access control.
Machine identities: The underestimated vulnerability
This is where the real problem lies: every training cluster, every fine-tuning pipeline, and every inference endpoint brings machine identities that require credentials. These are typically provisioned faster than they can be properly managed.
A Keeper Security study shows that 35% of German companies already identify machine identity management as one of their biggest AI security gaps – a figure above the global average. This is no accident: German companies often operate complex AI infrastructures with many decentralized access points.
To meet Code of Practice security expectations, organizations must implement three things:
| Measure | Requirement |
|---|---|
| Centralized management | Infrastructure credentials stored in a central vault |
| Just-in-time access | Time-limited permissions instead of permanent access |
| Logging | Audit-proof documentation of all privileged sessions |
What this means for you
Anyone waiting now, thinking the 2027 deadline is sufficient, is confusing two different things: the postponement for high-risk systems and already active GPAI requirements. Companies that secure their infrastructure credentials today and implement Access Governance are laying the groundwork for required compliance proof – and avoiding costly fixes later. For German mid-market companies, this means concretely: if you train or deploy AI models, you should now inventory your machine identities and manage them centrally. This is not optional – it's part of the rules already in effect.
Sources
Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.




