As of: 23 June 2026 · Reading time: 7 min
Key takeaways
- The EU AI Act has been in force since August 2024 and applies gradually until 2027.
- What does this specifically mean for medium-sized companies that have AI deployed or developed?
- This article explains schedule, risk classes and duties without German authorities.
The EU AI Act has been in force since August 2024 and applies gradually until 2027. What does this specifically mean for medium-sized companies that have AI deployed or developed? This article explains schedule, risk classes and duties without German authorities.
“Digitalization is not an IT project—it is a business strategy.”
– Björn Groenewold, Managing Director, Groenewold IT Solutions
EU AI Act (Regulation (EU) 2024/1689) is the world's first complete legal regulation of artificial intelligence. It applies directly to all EU Member States – without a national implementing law.
Since August 2024, it intervenes gradually for most companies until August 2026 or 2027.
This article explains without German authorities what the AI Act means for German mid-sized businesses – whether as AI users, clients or developers.
Timetable: When does what apply?
Short: **The EU AI Act has been in force since August 2024 and applies gradually until 2027.
**The EU AI Act has been in force since August 2024 and applies gradually until 2027.
As a basis for decision to EU AI Act: What companies need to know and implement 2026 now are suitable cost calculator: AI development and explore solutions.
| Time | What is valid |
|---|---|
| August 2024 | AI Act entered into force |
| February 2025 | Prohibitions for unacceptable AI systems apply |
| August 2025 | Obligations for GPAI models (large AI models such as GPT-4) apply |
| August 2026 | Main part of the obligations for high-risk AI systems |
| August 2027 | Obligations for existing high-risk systems (resistance rule expires) |
Important: Anyone who is planning or commissioning a new AI system today should already design AI-act-compliant – even if the duties formally only reach 2026. Retrospective adjustments are significantly more expensive.
The Risk Class Model: Four Steps
Short: The AI Act classified AI systems according to their risk.
The AI Act classified AI systems according to their risk. The classification determines which duties apply.
Inacceptable risk – prohibited: Certain AI applications are completely prohibited:
- Biometric real-time monitoring in public space (with close exceptions)
- Social scoring by government agencies
- manipulation of people by unconscious influence
- emotional recognition at work or in educational institutions (with exceptions)
High risk – strict requirements: AI systems that can have significant impact on people. These include:
- AI in recruitment procedures and personnel management
- AI in credit and credit assessment
- AI in medical diagnostics and treatment systems
- AI in critical infrastructure (energy, water, transport)
- AI in law enforcement and justice
- Biometric identification and categorization
Delimited risk – transparency obligations:
- Chatbots and AI avatars: Users must be informed that they interact with AI
- Deepfakes and AI-generated content: labelling requirement
- Recommendation systems with specific effects
**Minimal risk – no specific duties:**AI-assisted spam filters, AI in video games, simple AI-assisted search – no AI-act-specific requirements apply here.
Does this affect your operation?
Short: The first question: What role do you take in the AI Act?
The first question: What role do you take in the AI Act?
Provider: You develop an AI system and bring it to the market. Counts the highest responsibilities, in particular for high-risk systems.
Protector (Deployer): You use an AI system that has developed another. If limited own duties are required, but must ensure that the provider is AI-act-compliant.
Importeur / Dealer: Distributes AI systems from third countries in the EU. Takes responsibility for compliance of the product.
User: Individuals and companies using AI tools (e.g. ChatGPT for internal purposes). Mostly minimal duties.
for mid-sized businesses: You are operator – They buy or license AI systems and use them in operation.
And you can be orders – They commission individual AI solutions at an agency, then become the provider in fact.
Obligations for high-risk AI as Operator
Short: If you use a high-risk AI system (e.
If you use a high-risk AI system (e.g. AI-based personnel selection, automated credit decisions):
- establish risk management system** for the AI system
- Ensure human supervision: people must be able to monitor, understand and oversteer decisions of the system.
- Protocoling: Operation must be sufficiently logged to be comprehensible afterwards
- Check input data: Ensure relevance and representativeness of input data
- Technical documentation
- Reporting of serious incidents to the competent authority
Obligations for AI projects as client/provider
Short: If you are commissioning individual AI software and will use these third parties (e.
If you are commissioning individual AI software and will use these third parties (e.g. an AI tool for your customers), you will carry supplier obligations for high-risk systems:
- Conformity assessment before market launch
- Technical documentation according to Annex IV of the AI Act
- CE marking (for high risk systems)
- **EU Declaration of Conformity **
- Registration in the EU database system
- Current post-market monitoring
- Safety updates and quality management system
When ordering an AI agency: In the contract, it should be clear who is responsible for compliance. Unclear responsibilities are the most common problem with AI-act-relevant projects.
What to do now is: Pragmatic steps
Short: **Step 1: inventory of the AI systems used.
**Step 1: inventory of the AI systems used. **What AI systems are used in the company?
These include not only products marketed explicitly as AI, but also AI functions in ERP, CRM, HR software, recruiting platforms and marketing tools.
**Step 2: Determine risk class. ** For each identified system: Is it unacceptable (forbidden)? High risk? Limited risk? Minimum risk?
**Step 3: Interval analysis against duties. ** What requirements apply to the identified systems – and which of them are already fulfilled?
**Step 4: Suggest suppliers. ** Are the AI-act-compliant providers used? Are there any conformity documentation? For high risk: CE marking available?
**Step 5: Designing new projects AI-Act-first. ** Anyone who starts an AI project today should plan compliance from the outset – not as a follow-up. Our team integrates AI-Act requirements directly into architecture and documentation in the AI development for companies.
What is the threat of violations?
The AI Act provides for staggered fines:
| Violation | Maximum fine |
|---|---|
| Use of prohibited AI systems | 35 million € or 7% of global annual turnover |
| Violation of high risk | 15 million € or 3 % of global annual turnover |
| Wrong information to authorities | 7.5 million € or 1% of global annual turnover |
Reduced fines are provided for SMEs – concrete guidelines of the EU authorities are still pending.
The market surveillance authorities in Germany are expected to be the Federal Network Agency (for GPAI) and the national authorities (for sector-specific systems).
Conclusion
Short: The EU AI Act is complex – but no insurmountable hurdle for mid-sized businesses.
The EU AI Act is complex – but no insurmountable hurdle for mid-sized businesses.
Anyone who is now structuring: inventory, risk classification, gap analysis, contractual security for AI assignments – is well positioned.
Those who wait until the authorities become active have less time and more effort.
Please contact us if you need support in the AIAct classification of your AI projects or in the EU AI Act conform AI development.
Frequently Asked Questions (FAQ)
Does the AI Act also apply to AI tools we use internally (e.g. ChatGPT for employees)?
For purely internal use by employees, only the transparency obligations (users know that they use AI) and, if necessary, restrictions on certain high-risk applications apply.
GDPR requirements for data transfer to external models remain unaffected.
What about AI functions already included in our existing software?Stock systems have time to adapt by August 2027. New systems must be compliant from August 2026. Important: If a stock system is significantly changed, it can be classified as a new system.
Should we inform our employees about AI use?
Basically yes – especially when AI is used in personal decisions (performance assessment, monitoring). This also applies to co-determination rights of the works council.
Where can I read the full text of the EU AI Act?
The official text is available in the Official Journal of the EU (EUR-Lex). The EU Commission also provides guidelines and FAQs on the AI Act website, which are continuously updated.
Learn more:
EU AI Act Consulting – technical and organizational compliance support for your company: risk classification, documentation obligations and AI governance. Artificial Intelligence
Next consultation appointment →
Technical sources and further links
Short: The following independent references complement the classification on the topics of this Article:
The following independent references complement the classification on the topics of this Article:
- Bitkom – Digital Economy Association
- BSI – Federal Office for Information Security
- European Commission – Digital Strategy
- MDN Web Docs (Mozilla)
- W3C – World Wide Web Consortium
"Mobile apps need not only UX but also clear offline and security concepts; otherwise, trust and acceptance in the area suffers."
— *Björn Groenewold, Managing Director, Groenewold IT Solutions *
About the author

Managing Director of Groenewold IT Solutions GmbH and Hyperspace GmbH
Since 2009 Björn Groenewold has been developing software solutions for the mid-market. He is Managing Director of Groenewold IT Solutions GmbH (founded 2012) and Hyperspace GmbH. As founder of Groenewold IT Solutions he has successfully supported more than 250 projects – from legacy modernisation to AI integration.
Blog recommendations
Related articles
These posts might also interest you.

High-Risk AI under the EU AI Act: How to Classify Your Systems Correctly
Whether an AI system qualifies as high-risk under the EU AI Act determines your compliance scope. This guide explains classification with practical examples.

EU AI Act Compliance Checklist for mid-sized businesses
A structured checklist that enables medium-sized companies to systematically build up their EU AI Act compliance – from stocktaking to risk classification to ongoing governance.

Successful funding applications for software development: Best Practices
Innovation is the key to success in the dynamic world of information technology. But especially for small and medium-sized enterprises (SMEs) the financing of ambitious...
Free download
Checklist: 10 questions before software development
Key points before you start: budget, timeline, and requirements.
Get the checklist in a consultationRelevant next steps
Related services & solutions
Based on this article's topic, these pages are often the most useful next steps.
Related services
Related solutions
Cost calculators
More on EU AI Act and next steps
This article is in the EU AI Act topic. In our blog overview you will find all articles; under category EU AI Act more posts on this subject.
For topics like EU AI Act we offer matching services – from app development and AI integration to legacy modernisation and maintenance. We describe typical use cases under solutions. Our cost calculators give initial estimates. Key terms are in the IT glossary. Books and long-form guides appear on the publications page; deeper articles live under topics.
If you have questions about this article or want a non-binding discussion about your project, you can book a consultation or reach us via contact. We usually respond within one working day.
