News
12 min read

EU AI Act for mid-sized companies: which obligations really apply

Understand your real obligations under the EU AI Act Regulation 2024/1689, from Article 4 AI literacy to deployer duties and staggered timelines.

A managing director of a mid-sized company reviews a document on Regulation (EU) 2024/1689 on a tablet at their desk
A managing director of a mid-sized company reviews a document on Regulation (EU) 2024/1689 on a tablet at their desk

Understanding your role: deployer vs provider under Regulation 2024/1689

To navigate Regulation (EU) 2024/1689 effectively, you must first determine your exact regulatory role. The EU AI Act distinguishes sharply between developers who create AI systems and organizations that integrate third-party tools into their operations. For most managing directors and technical leads in German mid-sized companies, understanding this distinction is reassuring: the heavy administrative burden falls primarily on developers, while everyday corporate users face far lighter operational requirements.

RoleDefinition under Article 3Primary Compliance Scope
Provider (Anbieter)Develops an AI system or has it developed to place on the market under its own brand.Comprehensive technical documentation, conformity assessments, and quality management systems.
Deployer (Betreiber)Uses an AI system under its authority for professional activities (unless for purely personal use).Ensuring AI literacy, following usage instructions, monitoring operation, and maintaining human oversight.

If your company subscribes to commercial software like Microsoft 365 Copilot, integrates cloud-based analytics, or uses SaaS tools with built-in AI capabilities, you act as a deployer. Much like the shared responsibility model in cloud computing, your obligations center on governance, proper usage, and staff oversight rather than software certification. You are only reclassified as a provider if you heavily modify high-risk software or rebrand a third-party AI tool as your own proprietary system.

Recognizing that you are a deployer removes much of the anxiety surrounding the EU AI Act. Instead of conducting costly conformity assessments or building complex technical files, your primary task is establishing basic internal governance, ensuring staff AI literacy, and adhering to the manufacturer's intended usage guidelines.

The four risk tiers: why most Mittelstand AI is not high risk

Regulation (EU) 2024/1689 structures European artificial intelligence governance around a clear, four-tiered risk pyramid[2]. For managing directors and technical executives in mid-sized businesses, categorizing your company's software footprint is the essential first step. The framework divides applications into prohibited practices, high-risk systems, specific transparency risks, and minimal or low-risk tools. While legal headlines frequently emphasize complex certification burdens for high-risk software, the operational reality for the vast majority of Mittelstand deployers is significantly lighter.

Risk CategoryRegulatory DefinitionCommon Mittelstand Use CaseOperational Impact
ProhibitedUnacceptable threat to fundamental human rights, such as social scoring or manipulative systemsWorkplace emotion recognition or untargeted facial scrapingBanned outright under EU law
High RiskSignificant risk to safety, fundamental rights, critical infrastructure, HR, or creditAutomated CV filtering for recruitment or AI credit scoringStrict conformity assessments and documentation
Specific TransparencySystems interacting directly with natural persons or generating synthetic contentCustomer support chatbots and AI marketing copy generatorsMandatory disclosure to users under Article 50
Minimal / Low RiskStandard operational software, productivity enhancements, and routine analyticsInternal knowledge search, translation tools, and code assistantsNo mandatory technical requirements under the Act

In practice, everyday commercial applications such as spam filters, predictive maintenance algorithms, internal search tools, and routine operational analytics sit firmly in the minimal risk tier. Unless you deploy specialized AI tools to automate employee recruitment or perform credit scoring, your core systems will not trigger high-risk regulatory obligations. Even deployers using customer-facing chatbots face simple obligations: informing users that they are communicating with an AI system. Aligning these deployment practices with solid cybersecurity and basic governance keeps your business fully compliant without stalling digital innovation.

Article 4 AI literacy: the mandatory requirement active since February 2025

While headlines often focus on complex high-risk AI certifications, the EU AI Act introduces immediate compliance requirements that apply across the board. Under Article 4 of Regulation (EU) 2024/1689, which became legally binding on February 2, 2025, all providers and deployers of AI systems are required to ensure their personnel attain an adequate level of AI literacy[3]. For mid-sized companies using standard productivity tools, generative assistants, or SaaS software with embedded AI, this obligation applies directly. Managing directors must actively foster staff competence relative to employees' technical background, role responsibilities, and operational context.

Practical steps to implement workforce AI literacy

Achieving compliance under Article 4 does not require formal university certifications or complex engineering credentials. Instead, European regulators expect practical, role-specific measures that help employees understand how AI systems process data, where output risks lie, and how to verify automated results safely.

  • Audit existing AI deployment: Create a comprehensive inventory of all AI-enabled tools used across departments, including writing assistants, customer support chat tools, and automated data processing modules.
  • Deliver role-tailored instruction: Provide targeted training suited to specific staff functions, ensuring technical teams understand model limits while administrative staff learn core data confidentiality rules.
  • Establish clear usage boundaries: Define written policies regarding acceptable use cases, prohibiting staff from entering sensitive company data or personal customer information into unsecured public models.
  • Document completion and policies: Maintain centralized logs of attendance, training materials, and employee acknowledgments to serve as verifiable audit proof.

Treating AI literacy as an ongoing operational habit rather than a single HR checkbox ensures long-term protection against regulatory risks. When integrated alongside overall IT security oversight, structured training empowers your team to leverage modern AI tools efficiently while remaining fully compliant with EU legal duties[4].

Specific deployer duties for high-risk AI systems

While the vast majority of software applications used in German mid-sized businesses fall into the low-risk category, deploying a high-risk AI system (such as automated candidate screening in HR, employee evaluation tools, or AI-driven credit scoring engines) triggers specific legal duties under Article 26 of Regulation (EU) 2024/1689[5]. As a deployer, you are not required to conduct the complex technical certifications expected of software developers. However, management remains directly responsible for how the system is operated, monitored, and controlled within daily operations.

  • Human oversight implementation: Assign qualified, properly trained personnel with explicit authority to review system outputs, identify potential bias, and override or halt automated decisions when necessary.
  • Adherence to operating instructions and data quality: Use the system strictly according to the provider's technical documentation, and ensure that internal input data under your control is accurate and representative.
  • Log retention and auditability: Automatically store operational system logs for a minimum of six months, or longer if required by applicable sector regulations, to maintain a clear audit trail.
  • Worker and staff transparency: Inform affected employees and workplace representatives before introducing high-risk AI systems into human resources or workforce management processes.
  • Operational monitoring and incident reporting: Continuously monitor system performance during routine use, suspending operations and notifying the vendor immediately if safety risks or malfunctions arise.

For managing directors and IT decision-makers, fulfilling these obligations does not require building an elaborate administrative apparatus from scratch. Instead, deployer compliance should be integrated into existing operational workflows alongside overall cyber risks management. Documenting human oversight roles, maintaining strict log retention routines, and enforcing clear operational guidelines ensures that high-risk tools are deployed safely, legally, and without unnecessary operational burden.

The implementation timeline: key application dates through 2027

Regulation (EU) 2024/1689 does not enforce all regulatory requirements overnight[2]. Instead, European lawmakers created a phased implementation schedule spanning 36 months from the law's official entry into force. For mid-sized enterprises across Germany, understanding this multi-stage roadmap is crucial for structuring an effective compliance strategy without overallocating administrative resources. While complex certification and monitoring duties for high-risk systems take effect in later years, specific baseline obligations apply much earlier in the regulatory transition period.

  • 1 August 2024: Regulation (EU) 2024/1689 formally entered into force across all EU member states.
  • 2 February 2025 (6 months): the general provisions (Chapter I), the prohibitions on unacceptable AI practices (Chapter II) and the Article 4 AI literacy obligation became applicable.
  • 2 August 2025 (12 months): the rules for providers of general-purpose AI models (GPAI) applied, alongside the governance structures and the penalty framework.
  • Later deadlines for high-risk AI: in the following years the core requirements for high-risk AI systems under Annex III take effect, including risk assessments and logging duties for deployers.
  • Full conformity for embedded systems: binding compliance for high-risk AI systems built into products already covered by EU product legislation follows last.

For managing directors and IT leads, this phased approach provides valuable time to align operational processes. Your company does not need an immediate overhaul of standard administrative software, as typical business applications remain in low-risk categories. However, delaying internal review until the 2026 high-risk deadline is a critical oversight. Just as proactive IT security management minimizes operational risk, leadership must begin inventorying active AI software and implementing basic workforce literacy measures today to satisfy early statutory milestones.

Pragmatic AI governance: steps for mid-sized companies without a SOC

Establishing pragmatic AI governance does not require a dedicated Security Operations Center or an enterprise compliance department. For mid-sized organizations, compliance under Regulation (EU) 2024/1689 is primarily an exercise in operational hygiene: identifying shadow AI tools, setting baseline workplace guidelines, and verifying vendor claims. When managing directors and technical leads treat IT security as an executive responsibility, fulfilling deployer duties integrates seamlessly into routine IT administration.

A four-step framework for internal oversight

  • Audit shadow AI and build an asset register: Document every SaaS application, productivity extension, and internal script incorporating machine learning models. Record what data types pass through each tool and identify the primary business owner.
  • Enforce acceptable usage guidelines: Define explicit boundary rules for staff. Specify which tools are approved, strictly prohibit pasting customer data or proprietary source code into public generative models, and record training completion.
  • Scrutinize third-party vendor claims: Request documented evidence from software providers regarding their AI Act risk classification, training data lineage, and compliance statements before renewing subscriptions.
  • Integrate AI monitoring into core IT operations: Leverage existing endpoint management and software distribution processes to audit executable applications, ensuring unauthorized generative tools cannot bypass network perimeter controls.

By establishing this structured approach, you maintain full control over corporate data flows and AI adoption. Rather than incurring heavy legal consulting fees or building complex monitoring infrastructure, your technical team delivers demonstrable regulatory alignment through existing operational channels.

Navigating Regulation (EU) 2024/1689 requires a highly pragmatic perspective tailored to German mid-sized companies. For managing directors and technical leaders in the Mittelstand, the EU AI Act does not demand a costly organizational overhaul or complex compliance certifications. Because typical mid-market organizations integrate existing commercial software rather than build proprietary foundation models, their primary legal classification is that of an AI deployer rather than an AI provider.

  • Focus on AI literacy: Establish basic workforce competence under Article 4, which applies directly as of 2 February 2025.
  • Proportionate risk classification: Recognize that everyday administrative, analytical, and productivity tools fall under minimal or low risk.
  • Targeted high-risk evaluation: Limit intensive compliance efforts to specific high-risk deployments, such as AI-driven recruitment or biometric evaluation.
  • Governance alignment: Integrate AI oversight into existing operational processes and executive IT security oversight.

This professional assessment provides operational orientation to help executive teams establish balanced governance without falling into regulatory paralysis or vendor-driven alarmism. It translates complex statutory requirements into actionable priorities for mid-market decision-makers. However, because specific deployment contexts and vendor contracts can introduce nuanced legal liabilities, this guide serves as strategic guidance rather than formal legal advice. Executives should review high-risk deployments with specialized counsel when necessary.

By focusing immediate efforts on workforce training and maintaining an accurate inventory of active AI applications, mid-sized businesses can satisfy regulatory expectations efficiently while continuing to leverage modern technology safely.

Frequently asked questions

Does the EU AI Act apply to mid-sized companies using off-the-shelf AI software?

Yes, Regulation (EU) 2024/1689 applies to deployers using AI tools in professional activities. However, for standard off-the-shelf tools with minimal risk, your primary immediate obligation is ensuring staff AI literacy under Article 4.

What is the difference between an AI provider and an AI deployer under Regulation 2024/1689?

A provider develops or customizes an AI system to place it on the market under its own name. A deployer uses an AI system under its authority in professional operations. Most mid-sized companies act strictly as deployers.

What does Article 4 AI literacy require mid-sized companies to do?

Article 4 mandates that deployers take measures to ensure a sufficient level of AI literacy among their staff. Measures must consider employees' technical knowledge, experience, role, and the context in which AI tools are used.

When did the EU AI Act requirements start applying?

The AI Act entered into force on August 1, 2024. Prohibited AI practices and Article 4 AI literacy applied from February 2, 2025. General rules for high-risk AI systems apply from August 2, 2026.

Are standard HR or recruitment tools considered high-risk AI systems?

AI systems used in recruitment, employee evaluation, or task allocation are classified as high-risk under Annex III. Deployers using these tools must maintain human oversight, log operations, and follow provider instructions starting August 2026.

Does EU AI Act compliance require purchasing specific security software?

No provision in Regulation (EU) 2024/1689 requires purchasing specific cybersecurity software. Compliance relies on clear operational policies, asset registers, employee training, and risk-appropriate governance.

Sources

  1. artificialintelligenceact.eu
  2. digital-strategy.ec.europa.eu
  3. artificialintelligenceact.eu
  4. clearyiptechinsights.com
  5. ai-act-service-desk.ec.europa.eu

Where does your company stand?

30 minutes, free, no commitment. We show you where you stand.