AI & Automation

EU AI Act & AI Governance for Mid-Sized Companies

The EU AI Act is in force — and it applies not only to companies that build AI but to everyone who uses it. For mid-sized companies this mainly means: knowing which AI is in the house, classifying it correctly, enabling employees, and documenting both together with GDPR. We put that into a form that works in daily practice.

More services

Regulation (EU) 2024/1689 has been in force since 1 August 2024 and applies in stages. Since 2 February 2025 prohibited practices are banned and the AI literacy obligation under Article 4 applies: anyone operating AI systems must ensure that the staff involved understand how they work and where their limits are. Since 2 August 2025 the rules for general-purpose AI models and the governance and penalty framework apply; since 2 August 2026 the regulation is in principle fully applicable. The deadlines for high-risk systems have been adjusted several times during the legislative process — which dates apply to you specifically is something we check case by case against the current state of the law.

For most mid-sized companies the good news is: what you actually use rarely falls into the high-risk category. A Copilot in Microsoft 365, a chatbot on the website or text classification in the inbox are typically low-risk systems or systems with transparency obligations. It becomes critical where AI decides about people — in recruiting, credit scoring or performance assessment. These are exactly the cases you need to know about before someone introduces them without consultation.

We therefore work from reality rather than from the legal text: first an inventory of what is actually in use — including the tools business units run without IT approval. Then classification per system by risk class and role, combined with the data protection view: which data flows where, on what legal basis, under which data processing agreement. From this we build a lean set of rules, an understandable usage policy for employees, and training that genuinely satisfies the literacy obligation rather than just ticking it off.

Concrete deliverables

AI inventory including unofficially used tools
Risk classification per system under the AI Act
Integration with GDPR: data flows, legal bases, processing agreements
Usage policy for employees in plain language
Training to satisfy the AI literacy obligation (Art. 4)
Documentation that stands up to an audit
Use cases

What this looks like in practice.

// 01

De-risking a Copilot rollout

Clarify before rollout which data Copilot can see, who is allowed to do what, and how it is documented.

// 02

Surfacing shadow AI

Record which AI tools business units already use — then bring them into order instead of banning them.

// 03

Meeting the literacy obligation

Hands-on training for employees who actually work with AI, with evidence for your documentation.

How we proceed

Step by step.

1

Inventory: which AI is actually in use?

2

Classification by risk class and role

3

Policy, documentation and processing agreements

4

Training and regular review

We advise on technical and organisational matters and do not replace legal advice. The AI Act deadlines — particularly for high-risk systems — have been adjusted several times; we check the state applicable to you case by case and work with your legal advisers where needed.

FAQ

Frequently asked questions.

Still have open questions? We're happy to clarify them in an initial call.

Does the AI Act even affect us? We don't build AI.
Yes. The regulation distinguishes between providers and deployers — anyone using AI systems in their own company is a deployer and has obligations of their own. The most practically relevant one applies regardless of company size: the AI literacy obligation under Article 4. The scope of the remaining duties depends on the risk class of the systems in use.
What happens in the event of a breach?
The regulation provides for tiered fines, at the top end up to €35 million or 7% of global annual turnover for prohibited practices. For small and medium-sized enterprises the lower of the two amounts applies. In practice, though, the more likely damage is a different one: missing evidence towards customers, auditors or the data protection authority.
How much effort is this for a company with 50 employees?
Manageable, provided you set it up properly once. Inventory and classification are usually done in a few sessions, because the number of systems actually in use is smaller than expected. The recurring effort is then limited to a periodic review and training for new employees.

Let's talk about your project.

Free initial consultation, 30–45 minutes, remote. An honest assessment — even if the answer is that you don't actually need it.