0
Innovativer Roboter assistiert bei IT-Service-Management in moderner Büroumgebung.
KI-Wissen

KI-Compliance für KMU: Was ist wirklich Pflicht?

For most SMEs, the EU AI Act is mandatory — but not every AI application triggers the same requirements. Which rules apply in practice depends on the type of AI system your company uses or develops and which risk class that system falls into. This article answers the most important questions that SMEs face when getting started with AI compliance.

Which SMEs are covered by the EU AI Act?

In principle, the EU AI Act applies to all companies that deploy, develop, or place AI systems on the EU market, regardless of their size. Small and medium-sized enterprises are also covered as soon as they operate or offer AI systems. There is no exemption for SMEs, but there are simplified obligations for certain risk classes.

The EU AI Act distinguishes between providers (companies that develop or place AI systems on the market) and deployers (companies that use AI systems within their own operations). Most SMEs fall into the deployer category, because they use ready-made AI tools from third-party vendors — for example, for customer service, personnel selection, or document analysis.

Also relevant: the EU AI Act does not only apply to self-developed AI. If you deploy an AI application from an external provider productively within your own company, you take on deployer obligations. SMEs should therefore check, for every AI solution they use, which risk class it falls into.

What do high-risk AI systems mean for small businesses?

High-risk AI systems are those deployed in sensitive areas that can have significant effects on fundamental rights, safety, or health. SMEs that operate such systems face considerably stricter obligations than companies that only use AI with minimal risk.

The EU AI Act lists in Annex III specific areas of use that are classified as high-risk. These include, among others:

  • AI-assisted personnel decisions (recruiting, performance evaluation)
  • AI in credit lending or creditworthiness assessment
  • AI in safety-critical infrastructure
  • Biometric identification systems
  • AI in education for the assessment of learners

For SMEs, this means: if you use an AI tool for the automated pre-selection of job applications, for example, you are most likely operating a high-risk AI system. The associated obligations are extensive and require active AI risk management.

What specific compliance obligations apply, and from when?

The EU AI Act comes into force in stages. Prohibitions on certain AI practices have applied since February 2025, obligations for high-risk AI systems take effect from August 2026, and rules for general-purpose AI models (GPAI) have already applied since August 2025. SMEs must act now, not only once deadlines expire.

The most important obligations for deployers of high-risk AI systems at a glance:

  • Ensuring operation in accordance with the provider’s instructions for use
  • Implementing human oversight mechanisms
  • Continuous monitoring and reporting of serious incidents to authorities
  • Six-month retention of automated logs (log files)
  • Data protection impact assessment pursuant to Art. 35 GDPR
  • Duty to inform affected individuals about automated decisions

For AI systems with minimal risk — such as simple chatbots or recommendation algorithms — there are no mandatory additional requirements. However, the obligation to ensure AI competence (Art. 4 AI Act) remains in place for all companies, regardless of risk class.

How do the obligations differ for AI providers and AI deployers?

AI providers develop or market AI systems and bear primary responsibility for technical conformity, documentation, and certification. AI deployers use ready-made systems within their own company and are primarily responsible for safe, purpose-compliant operation and human oversight. The obligations differ, but both roles are binding.

For SMEs as deployers, the core obligations are:

  • Using the AI system only for its intended purpose
  • Ensuring and documenting human oversight
  • Equipping employees with the necessary AI competencies
  • Reporting incidents and risks to the provider and, where applicable, to authorities

For SMEs as providers — that is, companies that develop their own AI products — considerably more extensive obligations apply: technical documentation, conformity assessment procedures, CE marking, and registration in the EU database. In practice, these requirements primarily affect software companies and AI startups.

Many SMEs underestimate that they can act in both roles simultaneously — for example, when they integrate a purchased AI model into their own product. In this case, combined obligations from both categories apply.

What penalties do SMEs face for violations of AI regulations?

The fines under the EU AI Act are substantial: violations of prohibited AI practices can result in fines of up to 35 million euros or 7 percent of global annual turnover. Violations of obligations for high-risk AI systems can be sanctioned with up to 15 million euros or 3 percent of annual turnover. Proportionate sanctions generally apply to SMEs.

In addition to fines under the EU AI Act, SMEs face further legal consequences from related areas of law:

  • GDPR: Up to 4 percent of global annual turnover for data protection violations in the AI context (Art. 83 GDPR)
  • Competition law: Warnings from competitors or associations for misleading use of AI under the UWG
  • Employment law: Liability for discriminatory AI decisions in the HR area under the AGG
  • Reputational damage: Loss of trust among customers and business partners due to publicly known violations

For SMEs, this means: compliance is not only a legal obligation but also an economic safeguard. Investing early in AI compliance training helps you avoid costly remediation and liability risks.

How can SMEs practically prepare for AI compliance?

SMEs prepare most effectively for AI compliance by first taking an inventory of all AI systems in use, determining their risk class, and then implementing the applicable obligations in a structured way. A step-by-step approach is more realistic and sustainable than trying to address everything at once.

A proven way to get started with AI compliance follows these steps:

  1. Create an AI inventory: Record all AI systems and tools in use, including embedded AI in standard software
  2. Carry out risk classification: Check for each system whether it is to be classified as high-risk, limited risk, or minimal risk
  3. Define responsibilities: Establish clear accountability for monitoring, reporting obligations, and documentation
  4. Build AI competence: Train employees so that they can use AI systems safely and in compliance with the law (obligation under Art. 4 AI Act)
  5. Set up processes and documentation: Retain log files, establish monitoring routines, and put incident reporting processes in place

If you want to build a structured AI management system beyond this, ISO 42001 provides a recognised international framework. The standard defines requirements for an AI management system and helps SMEs anchor governance, risk management, and compliance systematically.

How mITSM supports SMEs in building AI compliance

We at mITSM offer practical training courses and certifications that prepare SMEs specifically for the requirements of the EU AI Act and related regulatory frameworks. Our trainers are certified experts who know AI compliance not only from theory but from daily practice.

Our offering for SMEs includes, among other things:

  • AI compliance training for employees and managers that fulfils the obligations under Art. 4 AI Act
  • AI manager and AI compliance officer training with recognised certifications via ICO-Cert
  • ISO 42001 training for building a structured AI management system
  • In-house training delivered as a standardised format directly at your location
  • Courses as in-person training, online live training, or e-learning, depending on your needs

Whether you are just starting out with AI compliance as an SME or want to qualify specific employees for deployer obligations: we support you with the right course format. Discover our complete training offering on AI topics and get in touch with us if you have questions about content or formats.

Dieser Inhalt wurde mithilfe von KI erstellt und kann Fehler enthalten.

+49 89 - 44 44 31 88 0 Chat starten
4.9
Basierend auf 126 Rezensionen