EU AI Act Compliance
AI Act Compliance for the German Mittelstand: What Actually Changes
If your Mittelstand company deploys AI in hiring, customer service, or operations, the EU AI Act creates concrete obligations that start in 2025. Here is what changes, what stays the same, and what to do next.
The Deadline Is Already Here for Some of You
AI Act compliance for the German Mittelstand is not a 2027 problem. The prohibition on unacceptable-risk AI systems under Article 5 has applied since 2 February 2025. General-purpose AI literacy obligations under Article 4 became enforceable on the same date. If your Familienbetrieb uses AI tools for recruitment screening, employee monitoring, or automated customer decisions, you are already in scope.
The good news: most Mittelstand companies do not build AI systems. They buy them from vendors and deploy them internally. That puts you in the deployer category under the Act, which carries a different and generally lighter set of obligations than those imposed on providers. But lighter does not mean zero.
Who Enforces the AI Act in Germany?
Germany has not yet published its final designation of the national competent authority, but the regulatory picture is becoming clear. The Bundesnetzagentur (BNetzA) is expected to take the lead coordinating role for AI Act market surveillance, building on its existing mandate under the Digital Markets Act. Sector-specific authorities will run parallel: the Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin) for AI in financial services, the Bundesamt für Sicherheit in der Informationstechnik (BSI) for cybersecurity-related AI applications, and the Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI) alongside 16 state-level Datenschutzbehörden for anything touching personal data.
That last point matters enormously for the Mittelstand. Germany's privacy enforcement structure means your AI deployment can simultaneously attract scrutiny from the BNetzA under the AI Act and from your Landesdatenschutzbehörde under the DSGVO (GDPR). The two frameworks overlap wherever AI processes personal data, which is most of the time.
The DSGVO Interaction You Cannot Ignore
The Bundesdatenschutzgesetz (BDSG) supplements the GDPR in Germany with stricter rules in several areas relevant to AI. Section 26 BDSG governs employee data processing, and it sets a higher bar for consent than the base GDPR standard. If you deploy an AI system that monitors employee productivity, routes customer service tickets, or scores job applicants, you are almost certainly processing employee personal data under both Section 26 BDSG and the AI Act simultaneously.
Under Article 26 of the AI Act, deployers of high-risk AI systems must:
- Conduct a Fundamental Rights Impact Assessment (FRIA) before deployment
- Assign a human to review and override AI outputs in HR and recruitment contexts
- Keep logs of system operation for at least six months
- Inform affected employees or individuals that an AI system is making or influencing decisions about them
The FRIA overlaps significantly with a GDPR Data Protection Impact Assessment (DPIA). Germany's data protection authorities have signalled that running both assessments as a combined document is acceptable, which saves Mittelstand companies meaningful time. Check guidance from your Landesdatenschutzbehörde, several of which have already published AI-specific DPIA templates.
One uniquely German wrinkle: Betriebsrat co-determination rights. Under the Betriebsverfassungsgesetz, works councils have statutory consultation rights when employers introduce technical systems capable of monitoring employee behaviour. AI tools often qualify. Before you deploy any AI system touching employee data, involve your Betriebsrat early. Their consent or agreement is not optional, and a failure here can halt a deployment entirely.
Which AI Systems Are High-Risk for the Mittelstand?
Annex III of the AI Act lists the high-risk categories. For a typical German SME, the three most relevant are:
Recruitment and HR management. AI systems that sort CVs, rank candidates, make or influence hiring decisions, or monitor employee performance fall under Annex III, point 4. This includes widely used SaaS HR tools. If you are using an applicant tracking system with built-in AI scoring, check with your vendor whether they have completed a conformity assessment.
Credit and insurance scoring. Mittelstand companies in leasing, factoring, or trade credit that use AI to assess customer creditworthiness fall under Annex III, point 5(b). BaFin oversight adds a second layer here.
Safety components in manufacturing. Germany's industrial SME backbone includes Maschinenbau companies using AI for quality control or predictive maintenance. Where the AI output affects product safety under EU product legislation, it may qualify as high-risk under Annex III, point 2.
If your system appears on this list, the compliance checklist under Article 27 applies: you need the provider's technical documentation, you need to run the FRIA, you need human oversight procedures documented in writing, and you need staff trained on the system's limitations.
Article 4 Literacy: Practical for 50-Person Companies
Article 4 requires deployers to ensure staff who work with AI systems have sufficient AI literacy. This does not mean every employee needs a machine learning certificate. The obligation is proportionate to company size and to the role each person plays.
For a 50-person Mittelstand company, proportionate compliance looks like this:
- All staff who interact with AI outputs receive a 60-to-90-minute awareness session covering what the tool does, what it cannot do, and how to escalate concerns.
- HR managers and team leads who rely on AI recommendations for hiring or performance reviews receive a deeper session on how to apply human judgment before acting on AI output.
- The compliance or HR officer maintains a simple log: who was trained, on which system, on what date.
Keep the training records for at least four years. Article 99 sets maximum fines at €15 million or 3% of global annual turnover for deployer violations. A missing training record in an audit is an avoidable risk.
The German Data Protection Officer Angle
Many Mittelstand companies are already required to appoint a Datenschutzbeauftragter (DSB) under Section 38 BDSG, which lowers the threshold for mandatory appointment compared to the base GDPR: companies with 20 or more people regularly processing personal data need a DSB. That is most of you reading this.
Your DSB should now be part of every AI system procurement decision. Their role under the combined DSGVO and AI Act framework includes reviewing vendor contracts for the clauses required by Article 26 of the AI Act, checking that the provider has supplied the relevant technical documentation, and flagging systems that require a DPIA. If your DSB has not yet been briefed on the AI Act, schedule that conversation this quarter.
Procurement: The Contractual Obligation You Might Be Missing
When you buy a high-risk AI system, the provider must give you certain information: the intended purpose, the performance metrics, the known limitations, and the technical documentation. Article 26 requires deployers to use AI systems only in accordance with that intended purpose.
In practice, this means your vendor contracts need an AI Act clause. It should specify that the provider will supply updated documentation when the system changes materially, that they will notify you of incidents, and that they carry the conformity assessment obligations on their side. Most standard SaaS contracts from 2023 and earlier do not contain these clauses. Add them at next renewal. If a vendor refuses, that refusal is itself a compliance signal worth taking seriously.
One Action to Take This Week
Pull a list of every AI tool your company currently pays for or uses internally. Mark each one: does it touch employee data, candidate data, or customer creditworthiness decisions? That simple inventory is the starting point for everything else: the FRIA, the vendor review, the literacy training plan, the Betriebsrat consultation.
You do not need a large compliance team to do this. You need a structured process and a clear picture of what you have deployed.
Run the free 2-minute compliance check at comply.khairos.ai to see which of your AI systems are likely in scope under the EU AI Act and where your most urgent gaps are.
# Need help getting compliant?
The free 2-minute compliance check shows you exactly where your gaps are. No email gate to see your score.
Start the free check →