EU AI Act Law & Compliance

AI and the law from August 2026: what really matters for the Mittelstand

Markus Dieing 17 July 2026 8 min read

In a nutshell

  • From 2 August 2026, only a few obligations of the EU AI Act become enforceable. For a typical mid-sized company, most of the rest is noise.
  • Two things genuinely matter: the AI literacy obligation (Article 4) and the transparency obligations for chatbots and AI-generated content.
  • The dreaded high-risk obligations have been postponed. They only apply from December 2027 or August 2028.
  • For SMEs, the lower of the two fine ceilings applies. The headline millions hit corporations, not the 120-employee company.
  • More tangible than half the AI Act: the new product liability for software and AI (to be transposed into German law by December 2026).

The EU AI Act is once again causing a lot of unease, because terms like million-euro fines, high-risk and conformity assessment are buzzing through every article. For the average company, however, most of this is noise, because only a few obligations actually apply, and they do so from 2 August 2026. Anyone who knows them can deal with the topic in one or two days and doesn't need to freeze in shock.

This overview therefore sorts out what matters and what doesn't. It is no substitute for legal advice, but it helps you ask the right questions.

The literacy obligation: employees must understand the AI they work with

This is the point that affects almost every company. In Article 4, the AI Act requires companies that use AI to take appropriate measures to build the AI literacy of the employees who work with these systems. This requirement has already applied since February 2025. What's new is twofold: authorities can enforce the obligation from 2 August 2026, and the EU has recently even eased it with the Digital Omnibus. What is required is no longer a guarantee of a particular level of competence, but merely evidence that appropriate measures have been taken. The legislator thereby confirms what was the sensible path anyway: not a major project, but a fitting qualification.

The decisive word here is use, because a company doesn't have to develop AI to be affected. It is enough that employees use Microsoft Copilot, ChatGPT or an AI feature in their industry software, and the obligation already exists.

The legislator deliberately left what appropriate means open, and this openness leads in practice to two opposite mistakes: one is to ignore the topic, the other is to turn it into a major project with an external certificate for every employee. In our view, neither achieves the goal, because what is required is a qualification that matches actual usage, is role-specific and is repeated. Someone who merely summarises texts with Copilot needs less than someone who processes customer data through an AI system. There is no obligation to obtain a certificate, but companies must be able to demonstrate that they have taken action. A documented internal qualification measure that explains which systems run in-house, what they can do, where the risks lie and which data must not be entered already fulfils the core of the obligation.

One detail is often blurred in the debate: the law formulates a qualification obligation, not a training obligation. It prescribes neither a particular format nor a certificate, so the path to building competence remains freely selectable. Whether competence is built through a standardised online course, a trainer-led on-site session or a combination of both is left to the company, and which path is right depends on your own goal. Anyone who primarily wants to fulfil the obligation and bring employees to a solid baseline is well served by a standardised training process, because it is efficient, documentable and scalable. Anyone who sees AI as a real productivity lever and wants not just to inform employees but to motivate and genuinely enable them should rely on an experienced, suitably qualified trainer who tailors the session to the company's actual workflows. The difference shows less in the compliance folder than in everyday work afterwards: in one case employees know what they must not do, in the other they also know what they can achieve.

How we help: For exactly this role-specific enablement we run AI workshops directly at your company, tailored to your actual workflows and documentable as a qualification measure.

Our take: this obligation doesn't directly lead to less bureaucracy. But rather than complaining about it, it's worth focusing on the positive aspects. And those inevitably lie in qualifying and guiding employees in handling a future technology. Because the greatest damage caused by AI in a business doesn't come from missing certificates, but from employees who enter confidential data into a freely accessible tool because no one explained to them why that's a problem.

The internal AI policy: not explicitly required, but hard to do without

The AI Act does not require a dedicated AI policy in its wording. In practice, though, there is hardly a way around it, because somewhere it must be set down which tools are permitted in the company, for which purposes they may be used, with which data they may work and where the limits lie. The policy is at the same time the natural evidence document towards authorities, customers and insurers, as well as the foundation on which every qualification measure builds, because without it you're training into a void.

Here a critical observation from practice is worthwhile. In many companies internal policies already exist that simply prohibit the use of AI, which at first glance looks like the safe option, because forbidden is forbidden. In reality, the opposite often emerges: employees use AI anyway, just under the radar and, in the worst case, through private, free accounts. This creates a double danger. First, no one in the company knows which data is entered into which tool, while the employees themselves, lacking qualification, cannot even know which data they may, can and should enter. Second, precisely the data that should be protected leaks away unseen, and with free versions, the inputs are, depending on the provider, even used to train the models. A prohibition on paper therefore doesn't protect; it merely shifts the risk to where no one can see or steer it any more.

A prohibition on paper doesn't protect. It merely shifts the risk to where no one can see it any more.

The obvious question is therefore not how to suppress AI use as effectively as possible, but whether it isn't fundamentally more sensible to qualify employees and at the same time give them the right, enterprise-grade tools, that is, AI access where data protection and data use are contractually regulated. Anyone who combines both, a clear policy and trained employees with clean tools, not only fulfils the obligation under Article 4 but also solves the actual problem: the shadow usage that prohibitions create in the first place.

The prohibitions: certain AI applications are banned outright

The AI Act prohibits certain practices entirely and backs them with the harshest fine ceiling of up to €35 million or 7 percent of annual turnover. That sounds dramatic but rarely affects a manufacturing company, because the prohibitions cover, among other things, social scoring, manipulative systems and the recognition of emotions in the workplace and in educational settings.

One point deserves a brief look nonetheless: this very ban on emotion recognition in the workplace. If a tool promises to analyse the mood or attention of employees via camera or voice, steer clear of it. Beyond that, this area is simply not a topic for most companies.

The transparency obligations: make it clear when AI is involved

From 2 August 2026 it also applies that a chatbot must be labelled as AI, so that users can tell they are communicating with a machine and not a human. AI-generated content, whether text, image, audio or video, must also be recognisable as such. This affects every company that runs a chatbot on its website or publishes AI-generated content.

The effort involved is manageable, but the obligation is easily overlooked because it sounds so trivial. At its core, a notice on the chatbot and an honest labelling of AI content are enough. One relief is also worth mentioning: for AI-generated texts that are reviewed in substance by a human before publication and for which a person bears editorial responsibility, the labelling obligation does not apply. So anyone who uses AI as a writing tool with genuine editing afterwards doesn't have to label every blog post.

The all-clear: the dreaded high-risk obligations come later

This is where the biggest misunderstanding lies. Public debate is dominated by the high-risk obligations with their elaborate conformity assessment, risk management and extensive documentation. But precisely these obligations have been postponed: with the so-called Digital Omnibus, which the EU adopted at the end of June 2026, the high-risk obligations under Annex III only apply from 2 December 2027, and those for safety-relevant products under Annex I only from August 2028.

For most manufacturing companies this area is rarely relevant anyway, because high-risk applications include things like automated candidate selection, credit scoring or AI in critical infrastructure. One point nonetheless deserves attention for the future: anyone who integrates AI into their own machines or safety-relevant components and places them on the market may fall into the high-risk category for products. That is a topic for product planning in 2027 and 2028, not for next month, but it should be kept in view.

The postponement is a genuine relief, but no reason to set the topic aside entirely. Because anyone who already knows today that they are moving towards high-risk gains preparation time with the additional runway, and no excuse.

General-purpose AI models: obligations for providers, not users

The large language models on which tools like Copilot or ChatGPT are based carry their own obligations. These, however, are directed at the model providers, Microsoft, OpenAI and others, and not at the companies that use them. From 2 August 2026 the EU can enforce these obligations with fines, which for users means above all one thing: the providers are now themselves responsible, which tends to bring more transparency and documentation on their side. No obligation of their own arises from this for the user.

Who supervises this in Germany and what a fine means for a mid-sized business

Germany has regulated the implementation with its own law, which the Bundestag passed in June 2026. According to it, the central point of contact and market surveillance authority will be the Federal Network Agency (Bundesnetzagentur), which also serves as the coordination body for a uniform interpretation, while the Federal Office for Information Security handles the cybersecurity of high-risk AI.

With the fines there is a detail that is decisive for the Mittelstand and usually gets lost in the panic debate: the quoted ceilings of up to €35 million or 7 percent of turnover are intended for large corporations. For small and medium-sized enterprises, the regulation expressly provides that the lower of the two values applies in each case, not the higher. That significantly relativises the intimidating figures: a fine remains unpleasant, but the headline millions don't hit the company with 120 employees.

The blind spot: what's coming beyond the AI Act

The AI Act is not the only body of rules relevant to AI, and two further points are even more tangible for a manufacturing company.

1. The new product liability

The revised EU Product Liability Directive must be transposed into German law by December 2026. What's new about it is that software and AI expressly count as products. So anyone who places a product with software or AI on the market will in future be liable, regardless of fault, for damage caused by defects, and expressly also for defects that only arise through the continued learning of an AI system. For mechanical and plant engineering, this is more relevant than half the AI Act. The originally planned separate AI Liability Directive was, incidentally, withdrawn, so it comes down to product liability and general law.

2. Co-determination

Companies with a works council should be aware that the introduction of AI systems is, as a rule, subject to co-determination, and the works council may even bring in an AI expert to assess it. That's no reason not to introduce AI, but it is a reason to involve the works council early rather than late. And of course the General Data Protection Regulation continues to apply: any AI that processes personal data needs a legal basis and, depending on the case, a data protection impact assessment. That's not new, but the use of AI often makes it acute for the first time.

All deadlines at a glance

AI literacy (Art. 4)

From 2 August 2026  ·  affects almost every company

Transparency obligations

From 2 August 2026  ·  for chatbots / AI content

High-risk obligations

Only from Dec 2027 / Aug 2028  ·  rare

New product liability

By Dec 2026  ·  high for product makers

What this concretely means by August

Anyone who wants to be on the safe side by summer doesn't need major projects, but five manageable steps:

  1. Get an overview. Which AI tools are actually used in-house, officially and unofficially?
  2. Set up an AI policy. It governs permitted use in a practical way, rather than banning it wholesale.
  3. Qualify your employees. Documented and tailored to the tools in use.
  4. Label. Identify chatbots and published AI content for what they are.
  5. Check the prohibitions. Briefly clarify whether any application in use falls under the prohibited practices. Rarely the case, but quickly settled.

The high-risk and product liability topics, by contrast, belong on the agenda for 2027, not in the rush of the coming weeks.

Our take stays sober: for the typical mid-sized business, the AI Act is neither a reason to panic nor a reason to do nothing. The expensive penalty is unlikely, and the real danger lies in the wrong reaction. Anyone who freezes in shock gives away productivity; anyone who charges in blindly risks avoidable mistakes. As so often, the right path lies in between: handle the few obligations that genuinely apply cleanly, and don't let the rest slow you down.

About the author: Markus Dieing is managing director at SimplifieD Solutions GmbH and an expert in business and processes. With his team he supports mid-sized companies in mechanical engineering, construction and manufacturing in adopting AI and automation solutions, with more than 30 successfully delivered projects. This article is no substitute for legal advice.

What does the AI Act mean for your company?

In a free 30-minute discovery call, we clarify which of the new obligations actually affect you, and what a practical AI policy and AI qualification could look like for you. Pragmatic, confidential and with no commitment.

100%

Free

30 min

Discovery call

€0

No commitment

Book a discovery call
Reviews & ratings for SimplifieD Solutions GmbH Top service provider 2026 - SimplifieD Solutions GmbH