Technical Guide

The EU AI Act for the Mittelstand: What Changes and What to Do

A practical, non-legal guide to the EU AI Act for mid-market companies. Understand the risk tiers, find where your AI sits, and get a concrete action list.

July 22, 202616 min readOronts Engineering Team

You Are Probably Already In Scope

Let me be direct: if your company uses AI in any customer-facing or decision-making process, the EU AI Act applies to you, and it does not care that you are a mid-market company rather than a tech giant. The good news is that most Mittelstand AI use falls into the lighter tiers, and the obligations there are manageable. The bad news is that "we did not know" is not a defense, and retrofitting compliance after you have shipped is far more expensive than building it in.

This is not a legal analysis, and it is not a substitute for your lawyer. It is a practical guide for a business owner or manager who needs to understand where their AI sits, what that means, and what to actually do about it, in plain terms. The Act works on a risk-based logic, and once you see which tier your use falls into, the path becomes clear.

The EU AI Act is not a reason to avoid AI. It is a set of guardrails that, handled early, are a normal design constraint. Handled late, they are a rebuild. The difference is entirely timing.

We build AI systems that are compliant by design, and we handle this in our own products, Exfinity and OGuardAI. This guide is the practical version. For the detailed regulatory analysis, see our EU AI Act omnibus guide, and for the data-protection overlap, our GDPR and AI guide.

Who Cares About What

RoleThe real questionWhat good looks like
Managing directorAre we exposed, and what do we do?A clear tier and an action list
Data protection officerHow does this overlap with GDPR?One coherent compliance approach
OperationsWhat changes in how we work?Transparency and oversight, documented
IT leadWhat do we build or change?Concrete controls, not a policy PDF
LegalIs our position defensible?Documented classification and controls

The Risk Tiers, in Plain Terms

The whole Act turns on one idea: the higher the risk your AI poses, the more you have to do. There are four tiers, and knowing yours tells you almost everything.

TierWhat it meansTypical Mittelstand example
ProhibitedBanned outrightSocial scoring, manipulative systems
High riskStrict obligationsHiring decisions, credit scoring, safety
Limited riskTransparency dutiesChatbots, AI-generated content
Minimal riskEssentially freeSpam filters, internal tooling

Most mid-market AI, a support chatbot, a content assistant, a product-data tool, sits in limited or minimal risk, where the obligations are light. The tier that catches people out is high risk, which includes AI used in hiring, creditworthiness, and certain safety functions. If your AI makes or materially influences those decisions, you have real obligations. If it does not, you are in the lighter tiers. Our AI governance guide covers how to structure the controls either way.

Find Where Your AI Sits

Before anything else, classify each AI use you have. This is the single most valuable hour you will spend, because it turns a vague worry into a specific, bounded task.

Does the AI make or heavily influence a decision about
  a person's job, credit, safety, or essential services?
        │ yes                              │ no
        ▼                                  ▼
   HIGH RISK                        Does the user interact with
   (real obligations)               AI or see AI-generated content?
                                          │ yes            │ no
                                          ▼                ▼
                                   LIMITED RISK       MINIMAL RISK
                                   (transparency)     (light)

Write down each AI use, run it through this, and record the result. That record is the start of your compliance file, and it is what you show if anyone asks. Most companies find that everything they run is limited or minimal, and the one thing that might be high risk is a hiring or scoring tool they can then handle deliberately.

Limited Risk: The Transparency Duties

If you run a chatbot or generate content with AI, and most Mittelstand companies do, you are in limited risk, and the core duty is transparency. People must know when they are interacting with AI or seeing AI-generated content.

In practice this is a small set of concrete controls.

  1. Disclose the AI. A clear notice before someone chats with an AI assistant, in the languages you serve.
  2. Label AI-generated content. Mark content a model produced, where a person would reasonably want to know.
  3. Keep a human reachable. A path to a person, not a dead end in a bot.

This is exactly what we build into our own platforms: an AI disclosure notice before a chat, in every supported language, and AI-generated suggestions marked for human approval. It is a design detail, not a burden. Our human-in-the-loop guide covers keeping a person in the flow.

High Risk: When You Have Real Obligations

If any of your AI genuinely falls into high risk, hiring, credit, safety, essential services, the obligations are more serious, and you should handle them deliberately with legal support. In broad terms they include risk management, data governance, documentation, human oversight, transparency to affected people, and record-keeping.

The practical takeaway for a mid-market company: high-risk AI is a deliberate decision, not something you drift into. If a tool influences those decisions, either build the obligations in from the start, or design the system so a human makes the actual decision and the AI only assists, which changes the risk picture. Our AI decision traceability guide covers the documentation and oversight machinery.

A Worked Example: Classifying Three Common Uses

Classification sounds abstract until you do it, so run three typical Mittelstand AI uses through the logic.

A customer-support chatbot on your website. It answers questions and hands off to a human when unsure. It does not decide anything about a person's job, credit, or safety, but users interact with it. That is limited risk. Action: add a clear AI disclosure before the chat and keep a path to a human. Cheap, done.

An AI tool that drafts product descriptions. It generates content that a person reviews before publishing. No decision about anyone, but it produces AI content. Limited risk, and the content should be labeled where a reader would reasonably want to know. Cheap, done.

A tool that screens job applicants and ranks them. This influences a hiring decision about a person. That is high risk, with real obligations around documentation, human oversight, and transparency to the affected applicants. Action: either build those obligations in deliberately with legal support, or redesign so a human makes the actual decision and the tool only surfaces information, which changes the risk picture.

Support chatbot     ── limited  ── disclose AI, human fallback
Content drafting    ── limited  ── label AI content, human review
Applicant screening ── HIGH     ── obligations, or redesign to assist only

Most companies run the first two and, once classified, handle them in an afternoon. The third is the one to catch and treat with care. The value of writing this down is that a vague "are we compliant" becomes a short, specific list, and that list is your defense if anyone asks.

The GDPR Overlap: One Approach, Not Two

The EU AI Act does not replace the GDPR, it sits alongside it, and most of your AI touches personal data, so you are handling both. The efficient move is to treat them as one coherent approach rather than two separate projects.

The overlap is large and works in your favor. Protecting personal data at the boundary, keeping an audit trail, honoring erasure, keeping a human accountable, these serve both regimes at once. Protecting personal data so it never reaches a model in raw form, as our PII-safe RAG guide describes, is a GDPR control and an AI Act data-governance control simultaneously. Our GDPR and AI guide covers the combined approach, and our trust and GDPR pages show how we handle it in delivery.

The Action List

Here is what to actually do, in order.

  1. Classify every AI use. Run each through the risk decision above and write down the result.
  2. Handle limited risk cheaply. Add AI disclosure and content labeling where people interact with AI.
  3. Flag anything high risk. If a tool influences hiring, credit, or safety, treat it deliberately with legal support.
  4. Merge with GDPR. Build data protection, audit, and human oversight once, for both regimes.
  5. Keep the file. Your classifications, controls, and decisions are your defense. Write them down.

This is a manageable list, and handled early it is cheap. Our consulting and custom software teams build compliant-by-design systems and can run this classification with you. Start at contact or get a scoped quote.

Common Ways This Goes Wrong

  1. Assuming it does not apply. It applies to users, not just builders. Classify your uses.
  2. Retrofitting after launch. Late compliance is a rebuild. Build it in from the start.
  3. Treating GDPR and the AI Act separately. They overlap heavily. Handle them once, together.
  4. Drifting into high risk. Hiring and scoring tools carry real duties. Enter that tier deliberately.
  5. No documentation. Your classification file is your defense. Keep it.

Who Builds This

Oronts is a founder-led software company in Munich. Refaat Al Ktifan, our founder and solution architect, leads a senior team that builds AI systems compliant by design for the German and European market. We handle the AI Act and GDPR overlap in our own products, Exfinity and OGuardAI, and we build the same discipline into client systems. We help you classify your AI, add the right controls, and keep the file that defends you. See our services, solutions, and trust pages. This guide is practical guidance, not legal advice, so pair it with your own counsel.

Takeaways

  • The EU AI Act applies to companies that use AI, not just build it, and mid-market firms are in scope.
  • The Act is risk-based. Classify each AI use and the obligations become clear.
  • Most Mittelstand AI is limited or minimal risk, where the duties are light and manageable.
  • High risk, hiring, credit, safety, is a deliberate decision with real obligations. Do not drift into it.
  • Handle the AI Act and GDPR as one coherent approach, built in early, not retrofitted.

The companies that will struggle with the AI Act are the ones that ignore it until an audit. The ones that classify their AI now and build the light controls in will find it is a normal design constraint, not a wall.

Not sure where your AI sits under the Act? Tell us what you run. Start at contact or get a scoped quote.

Topics covered

EU AI ActMittelstandAI complianceAI regulationrisk classificationAI governanceGDPRtransparency obligationshigh-risk AIAI Act checklist

Building something like this?

We design and ship production systems like the one in this guide. Talk to the engineers who wrote it, no sales pitch.

Start a conversation