Compliance & Regulation

EU AI Act 2026: What Mid-Sized Companies Must Do Now

Practical guide for SMEs on implementing the EU AI Act. From risk classification to the AI competence obligation to the 90-day plan. With checklist, industry example, and concrete recommendations.

The EU AI Act is no longer a future topic. In force since August 2024, the central obligations for companies become binding from August 2026. The AI competence obligation under Article 4 has even been in effect since February 2025. Despite this, many mid-sized companies have not yet even conducted an inventory of their AI systems. The situation is intensifying: simultaneously, GDPR tightening and NIS-2 requirements are taking effect, massively increasing the compliance burden for SMEs without their own legal department. This guide shows step by step what needs to be done now.

The EU AI Act at a Glance—What Applies from When

The EU AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive AI law. It regulates how artificial intelligence may be developed and deployed in the EU—regardless of company size. This means: even a mechanical engineering company with 80 employees or a trade business with 15 staff is affected as soon as AI systems are used in business operations.

The legislator has provided for a phased introduction intended to give mid-sized companies planning certainty. In practice, however, the various deadlines mean that some obligations have already been missed.

Timeline Overview of Deadlines

  • Date · What Applies · Relevance for SMEs
  • August 2024 · EU AI Act enters into force · Preparation phase begins
  • February 2025 · AI competence obligation (Art. 4) and prohibition of certain AI practices · Already in effect—all employees working with AI must be trained
  • August 2025 · Transparency obligations for generative AI and chatbots · Labeling of AI interactions becomes mandatory
  • August 2026 · Central obligations for all AI risk levels become binding · Documentation, governance, and risk classification must be in place
  • December 2027 · Transition periods for high-risk AI systems end (postponed from August 2026) · High-risk compliance must be fully complete by this point at the latest

Important: the recent postponement of high-risk obligations to December 2027 provides more time for the most demanding conformity assessments but does not release companies from the obligation to begin preparations now. Experts warn of costs in the mid five-figure range for compliance preparation alone. NIS-2 compliance can initially require even six-figure amounts.

What many business owners overlook: the AI competence obligation has been in effect for over a year. Anyone with employees who work daily with ChatGPT, Copilot, or other AI tools without documented training having taken place has been in a compliance gap since February 2025.

Understanding and Applying Risk Classification

The EU AI Act follows a risk-based approach. Not every AI system is treated equally. The higher the risk to fundamental rights, health, or safety, the stricter the requirements. For mid-sized companies, correctly classifying their own AI applications is the most important first step.

The Four Risk Categories

1. Unacceptable Risk (Prohibited)

These AI systems may not be operated in the EU. They include social scoring, manipulative systems that subliminally influence human behavior, and uncontrolled real-time biometric remote identification in public spaces. For most mid-sized companies, this category is not relevant—but those experimenting with emotion recognition technology in the workplace should examine closely.

2. High Risk

This covers AI systems deployed in sensitive areas: automated personnel decisions, creditworthiness assessments, applicant screenings, or safety-relevant systems in production. Companies must demonstrate a complete risk management system for these systems, maintain technical documentation, ensure data quality, and provide human oversight.

3. Limited Risk (Transparency Obligation)

Chatbots, generative AI in customer contact, and systems capable of creating deepfakes fall into this category. The main obligation: users must be able to clearly recognize that they are interacting with an AI system. A notice such as “This chat is powered by an AI assistant” suffices in many cases.

4. Minimal Risk

Internal productivity tools, translation aids, text generators for internal purposes, or spam filters fall into this category. There are no specific AI Act obligations here—existing regulations such as GDPR and industry-specific rules continue to apply, of course.

Classifying Typical AI Applications in Mid-Sized Companies

The greatest uncertainty arises in practice with the question: which category does my specific use case fall into? Here is a guide:

  • AI Application · Typical Risk Level · Key Obligations
  • ChatGPT for internal text work · Minimal · GDPR for personal data
  • Chatbot on the company website · Limited · Transparency notice, escalation to human
  • AI-powered invoice processing (OCR) · Minimal to limited · GoBD compliance, traceability
  • RAG system with company knowledge · Minimal · Access control, GDPR-compliant data management
  • Automated applicant screening · High risk · Complete documentation, bias testing, human oversight
  • AI-based quality control in production · High risk (if safety-relevant) · Risk management system, technical documentation
  • Predictive maintenance · Minimal to limited · Depends on safety relevance
  • AI-powered customer classification · Limited to high risk · Depends on the impact of the decision

The decisive factor: as soon as an AI system makes autonomous decisions that directly affect people—whether in hiring, terminations, credit, or safety assessments—the risk level rises significantly. As long as the human makes the final decision and the AI only makes suggestions, the classification typically remains lower.

The AI Competence Obligation Under Article 4

Article 4 of the EU AI Act contains one of the most underestimated obligations: since February 2025, all persons who work professionally with AI systems must have sufficient AI competence. This affects not only IT specialists but every employee who uses AI tools in their daily work—from the sales representative who uses ChatGPT for proposal texts to the HR manager who operates AI-powered applicant management software.

What exactly counts as “sufficient AI competence” is deliberately defined broadly by the legislator:

  • Basic understanding: How do AI systems fundamentally work? What are language models, how are they trained?
  • Opportunities and limitations: What can AI accomplish, where are its weaknesses? Why do models hallucinate?
  • Risk awareness: Bias, data protection risks, dependencies on providers
  • Personal obligations: What may I input, what not? When must I verify an output?

What Are the Consequences of Violations?

The risk is real: unauthorized AI tools used in recruiting, for example, can be classified as illegal high-risk AI systems. Anyone who lets employees work with AI systems without training violates Article 4 and risks fines.

Practical Example: Mechanical Engineering Company in Franconia

A mid-sized mechanical engineering company from the Aschaffenburg region with 120 employees has been using various AI tools since late 2024: the sales department (8 people) uses ChatGPT for proposal texts and market analyses. The engineering department (22 people) works with an AI-powered CAD assistant. The HR department (3 people) has introduced an applicant management system with AI pre-screening.

The starting position in early 2026: no documented AI training, no AI inventory, no risk classification. The estimated costs for retroactive compliance: approximately 45,000 euros, distributed across external consulting (15,000 euros), training program (8,000 euros), technical adjustments to the applicant system (12,000 euros), and documentation effort (10,000 euros in internal personnel costs).

Had the company started back in summer 2024, the costs would have been approximately 40 percent lower according to industry experts—because documentation built from the start costs less than documentation built retroactively.

The advantage of early action is also evident in market positioning. As Dr. Till Klein emphasized at the AI Act Now Conference in Bonn in early March 2026: early conformity is not a cost factor but a competitive advantage. Trustworthy AI promotes adoption in the mid-market—customers and business partners demonstrably prefer companies that design their AI use transparently and in compliance with regulations.

Practical Checklist for SMEs

The following checklist organizes the necessary measures into three phases. The sequence is deliberate: first capture the current state, then build the governance structures, and finally address technical implementation.

Phase 1: Assessment (Week 1 to 4)

  • Measure · Responsible · Result · Priority
  • Create AI inventory: capture all deployed AI tools and systems · Management + IT · Complete list of all AI applications · Critical
  • Conduct risk classification: assign each inventory entry to a risk level · Management + department · Risk matrix with classification per system · Critical
  • Shadow AI audit: identify unauthorized AI tools · IT + department heads · Report on unauthorized AI use · High
  • GDPR interface analysis: where is personal data processed in AI systems? · Data protection officer · Overview of data flows · High
  • Capture existing training levels: who has what AI competence? · HR department · Competence matrix · Medium

Phase 2: Governance and Training (Week 5 to 8)

  • Measure · Responsible · Result · Priority
  • Create AI policy: internal policy for handling AI systems · Management · Documented AI policy · Critical
  • Develop training plan and conduct training (Art. 4) · HR department · Documented training records · Critical
  • Define responsibilities: who is the AI officer in the company? · Management · Named contact person · High
  • Define monitoring process: how is AI use continuously supervised? · IT + AI officer · Monitoring concept · High
  • Define reporting and escalation process for AI incidents · Management + IT · Documented process · Medium

Phase 3: Technical Implementation (Week 9 to 12)

  • Measure · Responsible · Result · Priority
  • Implement logging: log every AI interaction in a structured manner · IT · Functioning logging layer · High
  • Add transparency notices: label chatbots and AI interfaces · IT + department · Visible AI labeling · High
  • Review access controls: who may access which AI systems and data? · IT · Role-based access concept · High
  • Ensure data residency: sensitive data in EU or on-premise · IT · Documented data locations · Medium
  • Set up automated compliance checks · IT · Regular audit reports · Medium

The Three Regulatory Layers: EU AI Act, GDPR, and NIS-2

What particularly challenges the mid-market is the intersection of three regulatory frameworks that take effect simultaneously. According to the BCG AI Radar 2026, AI investment readiness in Germany stands at 52 percent—leading in the EU. Yet this investment readiness meets a regulatory density that overwhelms many SMEs.

  • Regulation · Core Focus · Relevance for AI
  • EU AI Act · AI-specific obligations (risk levels, documentation, transparency) · Direct—affects all AI systems
  • GDPR · Protection of personal data · Whenever AI processes personal data
  • NIS-2 · Cybersecurity and resilience · When AI systems are used in critical infrastructure or essential services

In practice, this means: an AI-powered personnel selection system must simultaneously meet the high-risk requirements of the AI Act, comply with GDPR requirements for automated decisions (Art. 22 GDPR), and—if the company falls under NIS-2—demonstrate cybersecurity requirements for the IT infrastructure.

Frequently Asked Questions

Do small companies also fall under the EU AI Act?

Yes. The EU AI Act applies regardless of company size. As soon as a company deploys or places AI systems on the market, it is affected. However, the regulation does provide certain relief for SMEs, such as simplified conformity assessments and access to regulatory sandboxes. The planned national AI Implementation Act (KI-MIG) is intended to define further SME-specific relief.

What does implementation realistically cost?

Costs depend heavily on the number and risk level of deployed AI systems. For a typical mid-sized company with three to five AI applications in the minimal and limited risk range, experts estimate 20,000 to 50,000 euros for initial compliance. For high-risk systems, the effort can be significantly higher. Important: these costs arise regardless—those who start later pay more because retroactive documentation and adjustment are more expensive than compliance-by-design.

Do all employees really need to be trained?

Yes—but with gradation. Article 4 requires that all persons who work with AI systems have sufficient AI competence. The competence level must match the respective role: a sales representative using ChatGPT for text work needs a different training level than a developer integrating AI models. Training must be documented.

What happens if employees use unauthorized AI tools?

Unauthorized AI tools—so-called shadow AI—are a significant compliance risk. If an employee uses an unauthorized AI tool in recruiting, for example, this can be classified as illegal operation of a high-risk AI system. Responsibility lies with the company, not the individual employee. This is why the combination of a clear AI policy, approved tool alternatives, and regular audits is critical.

What support is available for mid-sized companies?

Targeted funding programs now exist. The Bavarian AI Innovation Accelerator, celebrating its first anniversary in March 2026, specifically supports SMEs, start-ups, and the public sector with AI Act implementation. A research project from LMU Munich, TU Munich, and TU Nuremberg is developing legally robust recommendations specifically for mid-sized companies. Additionally, Mittelstand-Digital centers and chambers of commerce offer free initial consultations. Bavaria’s start-up ecosystems rank first through third according to the Financial Times ranking—SMEs can also leverage this infrastructure for collaborations and knowledge transfer.

References

Tags

  • SMEs
  • EU AI Act
  • AI Competence
  • AI Governance
  • Mid-Market

Back to the overview

Business Data Strategy for your company

From the target state to Delivery Supervision. We advise you and enable your organization.