Knowledge
The EU AI Act: What Does It Mean for Mid-Sized Companies?
The EU AI Act sorts AI into risk classes. For most applications in mid-sized companies — document processing, knowledge search, quote drafting — 'limited risk' applies: at its core, it must be recognisable that AI is involved. Only clearly defined practices are banned; strict obligations affect high-risk systems, for instance in hiring decisions or critical infrastructure.
- risk classes in the AI Act
- 4
- obligations in force
- 2026
- read
- 6 min
The risk classes
- Prohibited practices: e.g. social scoring, banned outright.
- High risk: areas such as critical infrastructure or certain HR decisions, with strict obligations.
- Limited risk: transparency obligations, such as labeling AI interaction or AI-generated content.
- Minimal risk: no special obligations.
What this means in practice
Typical use cases in mid-sized companies usually fall under 'limited risk'. The effort lies mainly in transparency and clean documentation. What matters is classifying your own use case correctly early on.
Timing
The AI Act takes effect in stages; individual obligations apply at different points in time. We check the deadlines that currently apply to your specific use case together with you.
FAQ
Frequently asked questions
Does the AI Act affect my SME?
If you use or offer AI, yes, but the scope of the obligations depends on the risk class. For many applications, only 'limited risk' applies.
What are the obligations for limited risk?
Essentially transparency: users should be able to recognize that they are interacting with AI or that content is AI-generated.
Who helps with the classification?
For the use cases we implement, we include an AI Act conformity check.