The EU AI Act for Mid-Sized Businesses: Obligations, Deadlines, Approach

12.06.2026 ·

The EU AI Act is in force, and the first obligations already apply. Many mid-sized companies nevertheless do not know whether and how they are affected. The information landscape offers little help. On one side are advisory offerings that work with drastic penalty scenarios. On the other, the assumption persists that the law concerns only the big tech corporations anyway. Both are misleading. This guide sets out what the EU AI Act actually means for mid-sized businesses: which risk classes exist, which deadlines apply, what the training obligation under Article 4 requires, and which steps you should take now with a reasonable level of effort.

What the EU AI Act regulates – and what it does not

The EU AI Act (Regulation (EU) 2024/1689) is the first comprehensive law regulating artificial intelligence. It entered into force on 1 August 2024 and, as an EU regulation, applies directly in all Member States. A national transposition law, as required for directives, is not necessary, even though Germany still regulates the supervisory structures at national level.

The central idea: it is not the technology that is regulated, but its intended purpose. The AI Act follows a risk-based approach. The higher the risk an AI application poses to health, safety or fundamental rights, the stricter the obligations. The corollary is that the vast majority of AI use in mid-sized businesses (text assistants, translation, research, code support) is subject to only minor obligations or none at all.

What the AI Act does not regulate: it is not a data protection law. The GDPR continues to apply in parallel and independently. Anyone feeding personal data into AI tools must observe both sets of rules.

The four risk classes explained clearly

Unacceptable risk: prohibited

Article 5 prohibits certain AI practices entirely, since 2 February 2025. These include, among others, social scoring (the evaluation of individuals based on their social behaviour with detrimental consequences), manipulative techniques that subliminally push people towards harmful behaviour, and, with narrow exceptions, emotion recognition in the workplace and in educational institutions. For most mid-sized companies, this category is quickly checked. Anyone who does not use such systems is finished here. The most likely stumbling block is emotion recognition, which may be included as a feature in some HR or call-centre tools.

High risk: strictly regulated

High-risk AI systems are permitted but subject to extensive requirements: risk management, data quality, documentation, human oversight, accuracy and robustness. Which systems count as high-risk is listed in Annex III of the regulation. The most relevant for mid-sized businesses are:

  • Employment and personnel management: AI for pre-selecting applicants, for allocating tasks, or for assessing the performance and behaviour of employees
  • Creditworthiness: AI-assisted credit scoring of natural persons
  • Education: AI for assessing learning outcomes or admission decisions
  • Critical infrastructure: AI as a safety component, for example in energy or water supply

Important: an HR tool with an AI feature does not automatically make you a strictly regulated provider. Anyone who merely deploys a purchased high-risk system is a deployer, with considerably leaner obligations (more on this below).

Limited risk: transparency obligations

Certain AI applications are subject to transparency obligations under Article 50. The most important cases: chatbots must identify themselves as AI where this is not obvious to users. AI-generated or manipulated image, audio and video content (deepfakes) must be labelled as such. Anyone operating a customer-service chatbot or publishing AI-generated content should address this labelling cleanly and early. The effort involved is minimal.

Minimal risk: no specific obligations

Everything that falls into none of the categories above (spam filters, spell checking, most internal productivity applications) is subject to no specific obligations under the AI Act. Based on our reading of the market, this is where the bulk of the AI currently used in mid-sized businesses ends up.

Provider or deployer? Your role is decisive

The AI Act distinguishes between providers, i.e. those who develop an AI system or place it on the market under their own name, and deployers, i.e. those who use an AI system under their own responsibility in a professional capacity. The heavy obligations of high-risk regulation fall primarily on providers. Deployers must essentially use the system as intended in accordance with the manufacturer’s instructions, ensure human oversight, and report relevant incidents.

One point deserves attention. Anyone who substantially modifies a purchased AI system, or offers it as a high-risk system under their own brand, may legally slip into the provider role, with all the associated obligations. Anyone who does not merely use AI systems but builds them into their own products or agent solutions should examine this distinction before launch, not after.

The deadlines at a glance

The AI Act applies in stages. The most important dates:

Date What applies from then
2 February 2025 Prohibitions under Art. 5; obligation regarding AI literacy under Art. 4
2 August 2025 Rules for general-purpose AI models (GPAI); governance and penalty provisions
2 August 2026 Transparency obligations under Art. 50 (labelling of AI chatbots and AI-generated content)
2 December 2027 High-risk obligations for standalone systems under Annex III (postponed from the original 2 August 2026)
2 August 2028 High-risk obligations for AI in already regulated products under Annex I, e.g. machinery or medical devices (postponed from 2 August 2027)

A note on the current state of play: on 7 May 2026, the Council and Parliament reached a provisional agreement, as part of what is known as the Digital Omnibus, to extend the high-risk deadlines. The Annex III obligations thereby move from August 2026 to December 2027. Formal adoption and publication in the Official Journal were still pending at the time of writing, but are expected before August 2026. What already applies remains unaffected: the prohibitions under Article 5 and the AI literacy obligation under Article 4. Anyone who might be affected should check the current state of play before making important decisions and should not rely on obligations being dropped altogether.

The training obligation under Article 4

Article 4 is the obligation that affects practically every company using AI, regardless of risk class. The wording requires providers and deployers to “take measures to ensure, to their best extent”, that their staff have a sufficient level of AI literacy. What is meant are the skills and understanding needed to use AI systems competently and to be aware of the opportunities and risks.

What the law does not prescribe: a specific form of training, a number of hours, a certificate or an examination. The requirement is context-dependent. It is determined by prior technical knowledge, role and intended purpose. A specialist who occasionally uses a text assistant needs a different level than a team operating a high-risk system.

Article 4 can be implemented pragmatically in three steps: first, record who in the company uses which AI systems and for what; second, conduct role-based training, fundamentals for all users, in greater depth for those responsible; third, document the measures, because if in doubt you must be able to show that you have taken action. Structured AI workshops cover this need and incidentally achieve what compliance alone does not: employees who use AI productively and safely.

Penalties: what the law says

The AI Act provides for fines, graduated according to the severity of the infringement. The maximum ceilings under Article 99 reach up to 35 million euros or 7 percent of worldwide annual turnover for prohibited practices; for most other infringements they are lower. For SMEs, the lower of the two amounts applies in each case. These are upper limits, not standard amounts. Actual fines are determined on a case-by-case basis. An established enforcement practice does not yet exist. Anyone who documents systematically and acts transparently today will be better positioned in any conceivable review than someone who waits.

What you should do now: five steps

  • 1. Create an AI inventory. Record all AI systems in the company, including the tools used unofficially by individual teams (“shadow AI”). Without a complete picture, any risk assessment is piecemeal.
  • 2. Assign risk classes. Examine each system: does it fall under a prohibition pursuant to Art. 5? Under a high-risk use case pursuant to Annex III? Under transparency obligations? Most of it usually ends up at “minimal risk”, but the result belongs in documentation.
  • 3. Clarify roles. Are you only a deployer, or do you develop or integrate AI in such a way that you become a provider? This question determines the scope of your obligations.
  • 4. Implement Article 4. Plan, conduct and document role-based AI training. This obligation already applies.
  • 5. Anchor responsibility. Appoint a responsible person or a small committee for AI governance, i.e. the internal rules, responsibilities and processes for the use of AI. For the initial assessment and the setup of lean structures, this need not be a full-time position. An experienced AI governance consultant on a project basis is often the more economical route for mid-sized businesses.

Conclusion: take obligations seriously, dose the effort correctly

The EU AI Act is no reason for mid-sized businesses to panic, but it is also not a topic to sit out. Two obligations already apply to practically every company using AI: not to use prohibited practices, and to ensure the AI literacy of employees. The strict high-risk requirements affect only a small share of companies, and mostly in the leaner deployer role. The pragmatic route: build an AI inventory now, assign risk classes, implement training under Article 4, and designate responsibility. This covers the obligations currently in force and lays the foundation for everything else. Unclear terms from GPAI to deployer are explained in our AI glossary; for structured implementation in the company, an AI governance consultant or a compact AI workshop is the sensible first step.

Does the EU AI Act also apply to small and medium-sized enterprises?
Yes. The EU AI Act has no general exemption for SMEs. What matters is not the size of the company, but which AI systems are used and in what role – as a provider or as a deployer. For most mid-sized companies that merely use AI tools, the obligations are manageable, but not zero.
What exactly does the training obligation under Article 4 require?
Article 4 obliges providers and deployers of AI systems to ensure that their staff have sufficient AI literacy. The obligation has applied since 2 February 2025. The law does not prescribe a specific form of training or a certificate – the effort must match the deployment context and the prior knowledge of the employees.
Is using ChatGPT or Microsoft Copilot in the company a high-risk case?
As a rule, no. The typical office use of generative AI usually falls within the minimal or limited risk range. It only becomes high-risk when AI is used in sensitive application areas under Annex III – for example, for pre-selecting applicants, assessing the performance of employees, or credit-scoring.
What should a mid-sized company do first?
Create an AI inventory: which AI systems are in use, including unofficially used tools? Then assign each system to a risk class, rule out prohibited practices, and implement the training obligation under Article 4. These steps are feasible with manageable effort and cover the obligations already in force.

Looking for the right AI specialist?

Tell us about your project — within one business day you’ll get an honest assessment of role, day rate and availability.

Request experts