---
title: "EU AI Act: what midsize companies need to do now"
description: "A practical guide for midsize companies to implementing the EU AI Act: from risk classification and AI literacy under Article 4 to a 90-day plan, with a checklist, an industry example, and concrete recommendations."
canonical: "https://simo-online.com/en/blog/eu-ai-act-mittelstand-praxisleitfaden-2026"
---

# EU AI Act: what midsize companies need to do now

A practical guide for midsize companies to implementing the EU AI Act: from risk classification and AI literacy under Article 4 to a 90-day plan, with a checklist, an industry example, and concrete recommendations.

- Author: SIMO GmbH
- Published: 2026-03-07
- Updated: 2026-10-07
- Topic: [Compliance & Regulation](https://simo-online.com/en/blog/topic/compliance-regulation)

The EU AI Act is no longer a future topic. It has been in force since August 2024; the AI literacy rule under Article 4 has applied since February 2025, and the transparency obligations under Article 50 since August 2026. Under Regulation (EU) 2026/1744, the high-risk obligations follow from December 2, 2027 (as of October 2026 · not legal advice). Even so, many midsize companies have not yet taken an inventory of their AI systems. GDPR requirements and NIS2 obligations apply at the same time, which significantly increases the compliance burden for companies without an in-house legal department. This guide shows, step by step, what to do now.

## The EU AI Act at a glance—what applies from when

The EU AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive AI law. It regulates how artificial intelligence may be developed and deployed in the EU—regardless of company size. This means: even a mechanical engineering company with 80 employees or a trade business with 15 staff is affected as soon as AI systems are used in business operations.

The legislator has provided for a phased introduction intended to give midsize companies planning certainty. In practice, however, the various deadlines mean that some obligations have already been missed.

## Timeline overview of deadlines

- Date: August 2024 | What Applies: EU AI Act enters into force | Relevance for midsize companies: Preparation phase begins
- Date: February 2025 | What applies: AI literacy rule (Art. 4) and prohibition of certain AI practices | Relevance for midsize companies: Already in effect; since July 2026, Article 4 requires measures that support staff AI literacy
- Date: August 2025 | What applies: Obligations for general-purpose AI models | Relevance for midsize companies: Mainly affects model providers; users check the information their providers supply
- Date: August 2026 | What applies: Transparency obligations under Article 50, such as disclosing an AI interaction and labeling AI-generated content | Relevance for midsize companies: Labeling is mandatory; for generative systems placed on the market before August 2026, Article 50(2) applies from December 2, 2026
- Date: December 2, 2027 | What applies: Obligations for high-risk AI systems under Annex III (postponed from August 2026 by Regulation (EU) 2026/1744); for systems under Annex I, August 2, 2028 applies | Relevance for midsize companies: High-risk compliance must be complete by this date at the latest

Important: the recent postponement of high-risk obligations to December 2027 provides more time for the most demanding conformity assessments but does not release companies from the obligation to begin preparations now. Experts warn of costs in the mid five-figure range for compliance preparation alone. NIS-2 compliance can initially require even six-figure amounts.

What many business owners overlook: Article 4 on AI literacy has applied since February 2025. Companies whose employees use ChatGPT, Copilot, or other AI tools every day without any AI literacy measures in place have a compliance gap.

## Understanding and applying risk classification

The EU AI Act follows a risk-based approach. Not every AI system is treated equally. The higher the risk to fundamental rights, health, or safety, the stricter the requirements. For midsize companies, correctly classifying their own AI applications is the most important first step.

## The four risk categories

1. Unacceptable Risk (Prohibited)

These AI systems may not be operated in the EU. They include social scoring, manipulative systems that subliminally influence human behavior, and uncontrolled real-time biometric remote identification in public spaces. For most midsize companies, this category is not relevant—but those experimenting with emotion recognition technology in the workplace should examine closely.

2. High Risk

This covers AI systems deployed in sensitive areas: automated personnel decisions, creditworthiness assessments, applicant screenings, or safety-relevant systems in production. Companies must demonstrate a complete risk management system for these systems, maintain technical documentation, ensure data quality, and provide human oversight.

3. Limited Risk (Transparency Obligation)

Chatbots, generative AI in customer contact, and systems capable of creating deepfakes fall into this category. The main obligation: users must be able to clearly recognize that they are interacting with an AI system. A notice such as “This chat is powered by an AI assistant” suffices in many cases.

4. Minimal Risk

Internal productivity tools, translation aids, text generators for internal purposes, or spam filters fall into this category. There are no specific AI Act obligations here—existing regulations such as GDPR and industry-specific rules continue to apply, of course.

## Classifying typical AI applications in midsize companies

The greatest uncertainty arises in practice with the question: which category does my specific use case fall into? Here is a guide:

- AI Application: ChatGPT for internal text work | Typical Risk Level: Minimal | Key Obligations: GDPR for personal data
- AI Application: Chatbot on the company website | Typical Risk Level: Limited | Key Obligations: Transparency notice, escalation to human
- AI Application: AI-powered invoice processing (OCR) | Typical Risk Level: Minimal to limited | Key Obligations: GoBD compliance, traceability
- AI Application: RAG system with company knowledge | Typical Risk Level: Minimal | Key Obligations: Access control, GDPR-compliant data management
- AI Application: Automated applicant screening | Typical Risk Level: High risk | Key Obligations: Complete documentation, bias testing, human oversight
- AI Application: AI-based quality control in production | Typical Risk Level: High risk (if safety-relevant) | Key Obligations: Risk management system, technical documentation
- AI Application: Predictive maintenance | Typical Risk Level: Minimal to limited | Key Obligations: Depends on safety relevance
- AI Application: AI-powered customer classification | Typical Risk Level: Limited to high risk | Key Obligations: Depends on the impact of the decision

The decisive factor: as soon as an AI system makes autonomous decisions that directly affect people—whether in hiring, terminations, credit, or safety assessments—the risk level rises significantly. As long as the human makes the final decision and the AI only makes suggestions, the classification typically remains lower.

## The AI literacy rule under Article 4

Article 4 of the EU AI Act contains one of the most underestimated obligations. It has applied since February 2025, and in amended form since July 2026: providers and deployers take measures that support the AI literacy of everyone who works with AI systems on their behalf (as of October 2026 · not legal advice). This affects not only IT specialists but every employee who uses AI tools at work, from the sales representative who uses ChatGPT for proposal texts to the HR manager who runs AI-assisted applicant management software.

The legislator deliberately defines what AI literacy includes in broad terms:

- Basic understanding: How do AI systems fundamentally work? What are language models, how are they trained?
- Opportunities and limitations: What can AI accomplish, where are its weaknesses? Why do models hallucinate?
- Risk awareness: Bias, data protection risks, dependencies on providers
- Personal obligations: What may I input, what not? When must I verify an output?

## What are the consequences of violations?

The risk is real: unapproved AI tools used in recruiting, for example, can count as high-risk AI systems without their obligations being met. Neither the EU AI Act nor the KI-MIG provides a separate fine for Article 4; but letting employees work with AI without AI literacy measures raises the risk of violating obligations that do carry fines.

## Practical example: mechanical engineering company in Franconia

A midsize mechanical engineering company from the Aschaffenburg region with 120 employees has been using various AI tools since late 2024: the sales department (8 people) uses ChatGPT for proposal texts and market analyses. The engineering department (22 people) works with an AI-powered CAD assistant. The HR department (3 people) has introduced an applicant management system with AI pre-screening.

The starting position in early 2026: no documented AI training, no AI inventory, no risk classification. The estimated costs for retroactive compliance: approximately €45,000, distributed across external consulting (€15,000), training program (€8,000), technical adjustments to the applicant system (€12,000), and documentation effort (€10,000 in internal personnel costs).

Had the company started back in summer 2024, the costs would have been approximately 40 percent lower according to industry experts—because documentation built from the start costs less than documentation built retroactively.

The advantage of early action is also evident in market positioning. As Dr. Till Klein emphasized at the AI Act Now Conference in Bonn in early March 2026: early conformity is not a cost factor but a competitive advantage. Trustworthy AI promotes adoption in the Mittelstand (privately held midsize companies)—customers and business partners demonstrably prefer companies that design their AI use transparently and in compliance with regulations.

## Practical checklist for midsize companies

The following checklist organizes the necessary measures into three phases. The sequence is deliberate: first capture the current state, then build the governance structures, and finally address technical implementation.

## Phase 1: assessment (week 1 to 4)

- Measure: Create AI inventory: capture all deployed AI tools and systems | Responsible: Management + IT | Result: Complete list of all AI applications | Priority: Critical
- Measure: Conduct risk classification: assign each inventory entry to a risk level | Responsible: Management + department | Result: Risk matrix with classification per system | Priority: Critical
- Measure: Shadow AI audit: identify unauthorized AI tools | Responsible: IT + department heads | Result: Report on unauthorized AI use | Priority: High
- Measure: GDPR interface analysis: where is personal data processed in AI systems? | Responsible: Data protection officer | Result: Overview of data flows | Priority: High
- Measure: Capture existing training levels: who has what AI competence? | Responsible: HR department | Result: Competence matrix | Priority: Medium

## Phase 2: governance and training (week 5 to 8)

- Measure: Create AI policy: internal policy for handling AI systems | Responsible: Management | Result: Documented AI policy | Priority: Critical
- Measure: Develop training plan and conduct training (Art. 4) | Responsible: HR department | Result: Documented training records | Priority: Critical
- Measure: Define responsibilities: who is the AI officer in the company? | Responsible: Management | Result: Named contact person | Priority: High
- Measure: Define monitoring process: how is AI use continuously supervised? | Responsible: IT + AI officer | Result: Monitoring concept | Priority: High
- Measure: Define reporting and escalation process for AI incidents | Responsible: Management + IT | Result: Documented process | Priority: Medium

## Phase 3: technical implementation (week 9 to 12)

- Measure: Implement logging: log every AI interaction in a structured manner | Responsible: IT | Result: Functioning logging layer | Priority: High
- Measure: Add transparency notices: label chatbots and AI interfaces | Responsible: IT + department | Result: Visible AI labeling | Priority: High
- Measure: Review access controls: who may access which AI systems and data? | Responsible: IT | Result: Role-based access concept | Priority: High
- Measure: Ensure data residency: sensitive data in EU or on-premise | Responsible: IT | Result: Documented data locations | Priority: Medium
- Measure: Set up automated compliance checks | Responsible: IT | Result: Regular audit reports | Priority: Medium

## The three regulatory layers: EU AI Act, GDPR, and NIS-2

What particularly challenges the Mittelstand is the intersection of three regulatory frameworks that take effect simultaneously. According to the BCG AI Radar 2026, AI investment readiness in Germany stands at 52 percent—leading in the EU. Yet this investment readiness meets a regulatory density that overwhelms many midsize companies.

- Regulation: EU AI Act | Core Focus: AI-specific obligations (risk levels, documentation, transparency) | Relevance for AI: Direct—affects all AI systems
- Regulation: GDPR | Core Focus: Protection of personal data | Relevance for AI: Whenever AI processes personal data
- Regulation: NIS-2 | Core Focus: Cybersecurity and resilience | Relevance for AI: When AI systems are used in critical infrastructure or essential services

In practice, this means: an AI-powered personnel selection system must simultaneously meet the high-risk requirements of the AI Act, comply with GDPR requirements for automated decisions (Art. 22 GDPR), and—if the company falls under NIS-2—demonstrate cybersecurity requirements for the IT infrastructure.

## Frequently asked questions

## Do small companies also fall under the EU AI Act?

Yes. The EU AI Act applies regardless of company size. As soon as a company deploys AI systems or places them on the market, it is affected. The regulation does provide certain relief for SMEs, such as simplified conformity assessments and access to regulatory sandboxes. Germany’s KI-MIG, in force since July 29, 2026, requires the Federal Network Agency to set up at least one AI regulatory sandbox and to support SMEs with information and advisory services.

## What does implementation realistically cost?

Costs depend heavily on the number and risk level of deployed AI systems. For a typical midsize company with three to five AI applications in the minimal and limited risk range, experts estimate €20,000 to €50,000 for initial compliance. For high-risk systems, the effort can be significantly higher. Important: these costs arise regardless—those who start later pay more because retroactive documentation and adjustment are more expensive than compliance-by-design.

## Do all employees really need to be trained?

Yes, but in a graduated way. Article 4 requires measures for everyone who works with AI systems on the company’s behalf. The measures must fit the role: a sales representative who uses ChatGPT for writing needs a different level of training than a developer who integrates AI models. Documented training is the simplest proof.

## What happens if employees use unauthorized AI tools?

Unauthorized AI tools—so-called shadow AI—are a significant compliance risk. If an employee uses an unauthorized AI tool in recruiting, for example, this can be classified as illegal operation of a high-risk AI system. Responsibility lies with the company, not the individual employee. This is why the combination of a clear AI policy, approved tool alternatives, and regular audits is critical.

## What support is available for midsize companies?

Targeted funding programs now exist. The Bavarian AI Innovation Accelerator, celebrating its first anniversary in March 2026, specifically supports midsize companies, start-ups, and the public sector with AI Act implementation. A research project from LMU Munich, TU Munich, and TU Nuremberg is developing legally robust recommendations specifically for midsize companies. Additionally, Mittelstand-Digital centers and chambers of commerce offer free initial consultations. Bavaria’s start-up ecosystems rank first through third according to the Financial Times ranking—midsize companies can also use this infrastructure for collaborations and knowledge transfer.

## References

- [Bavarian State Ministry for Digital Affairs: Bavaria’s AI Innovation Accelerator Celebrates First Anniversary (March 2026)](https://www.stmd.bayern.de/)
- [Xpert.Digital: EU AI Act—Pflichten, Risikoklassen und BCG AI Radar 2026 [in German]](https://xpert.digital/)
- [DAPD.de: EU AI Act verschiebt Pflichten für Hochrisiko-KI auf Dezember 2027 [in German]](https://www.dapd.de/)
- [der-windows-papst.de: AI Competence Obligation Since February 2025 (Art. 4 EU AI Act)](https://www.der-windows-papst.de/)
- [Dr. Till Klein / AI Act Now Conference Bonn: Trustworthy AI as Competitive Advantage (March 2026)](https://www.linkedin.com/)

Rendered version: https://simo-online.com/en/blog/eu-ai-act-mittelstand-praxisleitfaden-2026
