🇩🇪
EU AI Act – Compliance requirements for companies 2026

EU AI Act: What companies 2026 need to know and implement

EU AI Act • 4 May 2026

As of: 23 June 2026 · Reading time: 7 min

Teilen:

Key takeaways

  • The EU AI Act has been in force since August 2024 and applies gradually until 2027.
  • What does this specifically mean for medium-sized companies that have AI deployed or developed?
  • This article explains schedule, risk classes and duties without German authorities.

The EU AI Act has been in force since August 2024 and applies gradually until 2027. What does this specifically mean for medium-sized companies that have AI deployed or developed? This article explains schedule, risk classes and duties without German authorities.

Digitalization is not an IT project—it is a business strategy.

Björn Groenewold, Managing Director, Groenewold IT Solutions

EU AI Act (Regulation (EU) 2024/1689) is the world's first complete legal regulation of artificial intelligence. It applies directly to all EU Member States – without a national implementing law.

Since August 2024, it intervenes gradually for most companies until August 2026 or 2027.

This article explains without German authorities what the AI Act means for German mid-sized businesses – whether as AI users, clients or developers.

Timetable: When does what apply?

Short: **The EU AI Act has been in force since August 2024 and applies gradually until 2027.

**The EU AI Act has been in force since August 2024 and applies gradually until 2027.

As a basis for decision to EU AI Act: What companies need to know and implement 2026 now are suitable cost calculator: AI development and explore solutions.

Time What is valid
August 2024 AI Act entered into force
February 2025 Prohibitions for unacceptable AI systems apply
August 2025 Obligations for GPAI models (large AI models such as GPT-4) apply
August 2026 Main part of the obligations for high-risk AI systems
August 2027 Obligations for existing high-risk systems (resistance rule expires)

Important: Anyone who is planning or commissioning a new AI system today should already design AI-act-compliant – even if the duties formally only reach 2026. Retrospective adjustments are significantly more expensive.

The Risk Class Model: Four Steps

Short: The AI Act classified AI systems according to their risk.

The AI Act classified AI systems according to their risk. The classification determines which duties apply.

Inacceptable risk – prohibited: Certain AI applications are completely prohibited:

  • Biometric real-time monitoring in public space (with close exceptions)
  • Social scoring by government agencies
  • manipulation of people by unconscious influence
  • emotional recognition at work or in educational institutions (with exceptions)

High risk – strict requirements: AI systems that can have significant impact on people. These include:

  • AI in recruitment procedures and personnel management
  • AI in credit and credit assessment
  • AI in medical diagnostics and treatment systems
  • AI in critical infrastructure (energy, water, transport)
  • AI in law enforcement and justice
  • Biometric identification and categorization

Delimited risk – transparency obligations:

  • Chatbots and AI avatars: Users must be informed that they interact with AI
  • Deepfakes and AI-generated content: labelling requirement
  • Recommendation systems with specific effects

**Minimal risk – no specific duties:**AI-assisted spam filters, AI in video games, simple AI-assisted search – no AI-act-specific requirements apply here.

Does this affect your operation?

Short: The first question: What role do you take in the AI Act?

The first question: What role do you take in the AI Act?

Provider: You develop an AI system and bring it to the market. Counts the highest responsibilities, in particular for high-risk systems.

Protector (Deployer): You use an AI system that has developed another. If limited own duties are required, but must ensure that the provider is AI-act-compliant.

Importeur / Dealer: Distributes AI systems from third countries in the EU. Takes responsibility for compliance of the product.

User: Individuals and companies using AI tools (e.g. ChatGPT for internal purposes). Mostly minimal duties.

for mid-sized businesses: You are operator – They buy or license AI systems and use them in operation.

And you can be orders – They commission individual AI solutions at an agency, then become the provider in fact.

Obligations for high-risk AI as Operator

Short: If you use a high-risk AI system (e.

If you use a high-risk AI system (e.g. AI-based personnel selection, automated credit decisions):

  • establish risk management system** for the AI system
  • Ensure human supervision: people must be able to monitor, understand and oversteer decisions of the system.
  • Protocoling: Operation must be sufficiently logged to be comprehensible afterwards
  • Check input data: Ensure relevance and representativeness of input data
  • Technical documentation
  • Reporting of serious incidents to the competent authority

Obligations for AI projects as client/provider

Short: If you are commissioning individual AI software and will use these third parties (e.

If you are commissioning individual AI software and will use these third parties (e.g. an AI tool for your customers), you will carry supplier obligations for high-risk systems:

  • Conformity assessment before market launch
  • Technical documentation according to Annex IV of the AI Act
  • CE marking (for high risk systems)
  • **EU Declaration of Conformity **
  • Registration in the EU database system
  • Current post-market monitoring
  • Safety updates and quality management system

When ordering an AI agency: In the contract, it should be clear who is responsible for compliance. Unclear responsibilities are the most common problem with AI-act-relevant projects.

What to do now is: Pragmatic steps

Short: **Step 1: inventory of the AI systems used.

**Step 1: inventory of the AI systems used. **What AI systems are used in the company?

These include not only products marketed explicitly as AI, but also AI functions in ERP, CRM, HR software, recruiting platforms and marketing tools.

**Step 2: Determine risk class. ** For each identified system: Is it unacceptable (forbidden)? High risk? Limited risk? Minimum risk?

**Step 3: Interval analysis against duties. ** What requirements apply to the identified systems – and which of them are already fulfilled?

**Step 4: Suggest suppliers. ** Are the AI-act-compliant providers used? Are there any conformity documentation? For high risk: CE marking available?

**Step 5: Designing new projects AI-Act-first. ** Anyone who starts an AI project today should plan compliance from the outset – not as a follow-up. Our team integrates AI-Act requirements directly into architecture and documentation in the AI development for companies.

What is the threat of violations?

The AI Act provides for staggered fines:

Violation Maximum fine
Use of prohibited AI systems 35 million € or 7% of global annual turnover
Violation of high risk 15 million € or 3 % of global annual turnover
Wrong information to authorities 7.5 million € or 1% of global annual turnover

Reduced fines are provided for SMEs – concrete guidelines of the EU authorities are still pending.

The market surveillance authorities in Germany are expected to be the Federal Network Agency (for GPAI) and the national authorities (for sector-specific systems).

Conclusion

Short: The EU AI Act is complex – but no insurmountable hurdle for mid-sized businesses.

The EU AI Act is complex – but no insurmountable hurdle for mid-sized businesses.

Anyone who is now structuring: inventory, risk classification, gap analysis, contractual security for AI assignments – is well positioned.

Those who wait until the authorities become active have less time and more effort.

Please contact us if you need support in the AIAct classification of your AI projects or in the EU AI Act conform AI development.

Frequently Asked Questions (FAQ)

Does the AI Act also apply to AI tools we use internally (e.g. ChatGPT for employees)?

For purely internal use by employees, only the transparency obligations (users know that they use AI) and, if necessary, restrictions on certain high-risk applications apply.

GDPR requirements for data transfer to external models remain unaffected.

What about AI functions already included in our existing software?Stock systems have time to adapt by August 2027. New systems must be compliant from August 2026. Important: If a stock system is significantly changed, it can be classified as a new system.

Should we inform our employees about AI use?

Basically yes – especially when AI is used in personal decisions (performance assessment, monitoring). This also applies to co-determination rights of the works council.

Where can I read the full text of the EU AI Act?

The official text is available in the Official Journal of the EU (EUR-Lex). The EU Commission also provides guidelines and FAQs on the AI Act website, which are continuously updated.


Learn more:

EU AI Act Consulting – technical and organizational compliance support for your company: risk classification, documentation obligations and AI governance. Artificial Intelligence

Next consultation appointment →

Short: The following independent references complement the classification on the topics of this Article:

The following independent references complement the classification on the topics of this Article:

"Mobile apps need not only UX but also clear offline and security concepts; otherwise, trust and acceptance in the area suffers."

— *Björn Groenewold, Managing Director, Groenewold IT Solutions *

About the author

Björn Groenewold
Björn Groenewold(Dipl.-Inf.)

Managing Director of Groenewold IT Solutions GmbH and Hyperspace GmbH

Since 2009 Björn Groenewold has been developing software solutions for the mid-market. He is Managing Director of Groenewold IT Solutions GmbH (founded 2012) and Hyperspace GmbH. As founder of Groenewold IT Solutions he has successfully supported more than 250 projects – from legacy modernisation to AI integration.

Software ArchitectureAI IntegrationLegacy ModernisationProject Management

Blog recommendations

Related articles

These posts might also interest you.

Free download

Checklist: 10 questions before software development

Key points before you start: budget, timeline, and requirements.

Get the checklist in a consultation

Relevant next steps

Related services & solutions

Based on this article's topic, these pages are often the most useful next steps.

Related services

Related solutions

More on this topic

More on EU AI Act and next steps

This article is in the EU AI Act topic. In our blog overview you will find all articles; under category EU AI Act more posts on this subject.

For topics like EU AI Act we offer matching services – from app development and AI integration to legacy modernisation and maintenance. We describe typical use cases under solutions. Our cost calculators give initial estimates. Key terms are in the IT glossary. Books and long-form guides appear on the publications page; deeper articles live under topics.

If you have questions about this article or want a non-binding discussion about your project, you can book a consultation or reach us via contact. We usually respond within one working day.

Next Step

Questions about this topic? We're happy to help.

Our experts are available for in-depth conversations – practical and without obligation.

30 min strategy call – 100% free & non-binding