Key insights: EU AI Act 2026: What Mid-Sized Companies Need to Know
EU AI Act for SMEs: risk classes, prohibited practices, high-risk uses, GPAI duties for providers/deployers, GDPR overlap and operational governance.
Read the German overview for full tables and operational guidance. For implementation support see AI training, Artificial Intelligence services and IT consulting.
Deployers: what to document
Maintain a lightweight decision log: model/version, purpose, data classes, human review points and incident contacts. Align prompts and tool permissions with HR/finance sensitivity — especially when outputs feed downstream systems.
Schedule a consultation to classify use cases and plan evidence packs.
About the author

Managing Director of Groenewold IT Solutions GmbH and Hyperspace GmbH
Since 2009 Björn Groenewold has been developing software solutions for the mid-market. He is Managing Director of Groenewold IT Solutions GmbH (founded 2012) and Hyperspace GmbH. As founder of Groenewold IT Solutions he has successfully supported more than 250 projects – from legacy modernisation to AI integration.
Frequently asked questions about EU AI Act 2026: What Mid-Sized Companies Need to Know
- Do we need a designated AI officer?
- There is no one-size-fits-all substitute for clear ownership: often a named lead with deputy suffices — aligned with your organisation. High-risk contexts require stronger QM-style evidence.
- How do we label AI-generated content?
- Where transparency duties apply, users should recognise AI — format depends on channel (UI hint, footer, voice disclosure). Internal guidelines prevent inconsistent practice.
- Must we log ChatGPT answers?
- For high-risk or decision-adjacent flows, document purpose, inputs and human review — technically via tickets or governance tools; avoid storing unnecessary personal data.
- What if our product is high-risk AI?
- Clarify provider vs deployer obligations, implement risk management and documentation — involve counsel; we supply architecture and logging foundations.
- How does the AI Act relate to GDPR?
- Both apply in parallel — AI Act focuses on risk/market rules; GDPR protects personal data; map data flows and legal bases jointly.
- When do GPAI duties affect us?
- Timelines are phased — confirm effective dates for your provider tier and model generation against the Official Journal text.
- What about open-source models?
- Roles and documentation duties still matter — open weights are not a free pass for high-risk deployment without governance.
- Which technical basics matter first?
- SSO/MFA for AI tools, secrets management, data classes for RAG, minimal logging and human escalation paths.
Topics & Topic Pages
Browse all expert topics by service in our Topics overview. For project-related consulting and our service portfolio, see Services. Key terms are explained in our IT Glossary.