Every regulation arrives with a chorus of "it is the next GDPR." Sometimes the chorus is right; often it is exhausting. The EU AI Act is genuinely consequential for German Mittelstand companies, but only if you understand which parts apply to you, which apply to your vendors, and which apply only to a much narrower category than the headlines suggest. This is a sober read for mid-market IT and compliance leaders in 2026.
The shape of the regulation, in one paragraph
The AI Act takes a risk-based approach. Most AI uses are unregulated. A specific category of high-risk uses — defined by sector and use case rather than by technology — carry significant obligations around documentation, data governance, human oversight, accuracy testing and post-market monitoring. A narrow set of uses is outright prohibited. Foundation-model providers carry their own obligations as providers. Most enterprises will land in one of two roles: deployer (using an AI system someone else built) or, less often, provider (offering an AI system to others).
What "high-risk" actually covers for Mittelstand companies
The high-risk list is finite. The categories most likely to be relevant for German mid-market enterprises:
- Employment and HR. AI used in recruitment, candidate evaluation, performance management or termination decisions.
- Access to essential services. Credit scoring, insurance underwriting, eligibility decisions for utilities or healthcare.
- Education and vocational training. Admission decisions, assessment, monitoring.
- Critical infrastructure. AI components in operational safety of water, gas, electricity, transport.
- Law enforcement and migration. Less commonly relevant for the typical Mittelstand IT department, but worth knowing about.
A pragmatic test: if your AI system is making a meaningful decision about a person — hiring, firing, lending, insuring — assume high-risk and plan accordingly. If your AI system is automating an internal workflow (invoice classification, document routing, internal search), the regulatory burden is much lighter.
What "general purpose AI" obligations look like as a deployer
Most Mittelstand uses of AI involve calling someone else's foundation model — OpenAI, Anthropic, Google, Mistral, Aleph Alpha, or whichever provider you settled on. The provider carries the bulk of the technical compliance burden. As a deployer you still have responsibilities, primarily around:
- Knowing what AI systems you are using — an inventory you can produce on request.
- Transparency to affected people when AI is making or substantially influencing a decision about them.
- Logging and audit trails proportionate to risk.
- Human oversight arrangements where high-risk uses are involved.
These are not exotic requirements. For most Mittelstand companies, they amount to writing things down that you probably already do informally.
Where the AI Act is genuinely different from GDPR
Two structural differences are worth grasping before you let the comparison run away with you.
Risk-based instead of universal. GDPR applies to all personal data. The AI Act's heavy obligations apply only to defined risk categories. The compliance footprint is narrower; the depth in those categories is sometimes greater.
Provider-heavy. Much of the technical burden falls on whoever built the AI system, not whoever uses it. For a deployer, this means the vendor evaluation phase is where most of the work happens — picking a provider who can supply the documentation, conformity assessments and ongoing reporting you need.
The AI Act is not GDPR in scope. It is GDPR in seriousness for the narrow set of uses it actually targets. Read the use-case list before estimating the budget.
What to do this quarter
For a typical German Mittelstand company with two or three AI projects in flight, a realistic plan:
- Inventory. List every AI use in the organisation, including the shadow uses (the team using ChatGPT for first-draft contracts; the marketing tool with AI features no one noticed when it was procured).
- Classify. Tag each entry against the high-risk list. The triage is usually quick: most internal-productivity uses are low-risk; HR-adjacent and customer-decision uses need closer attention.
- Talk to providers. For each AI system, request documentation that demonstrates the provider is meeting their AI Act obligations. Treat absent documentation as a red flag.
- Establish a register. A simple internal register of AI systems, with owner, risk category, documentation references and human-oversight arrangement. This is the artefact regulators will ask to see.
- Update procurement. Add AI Act questions to your standard vendor due diligence. Future procurements get easier when the questions are standard.
What is on the horizon but not yet binding
Phasing matters. Several provisions come into force on a staggered schedule. The headline-grabbing prohibitions on certain uses are largely in force; the heavier obligations on high-risk systems and on general-purpose AI providers phase in over the following 18 to 36 months from the Act's entry into force. As of 2026 you can plan calmly; you cannot legitimately ignore it.
For Mittelstand companies, the practical horizon to watch is when your specific high-risk obligations bite. If you are not in one of the listed high-risk sectors, the AI Act in 2026 is mostly about inventory, transparency, and vendor management.
The trap to avoid
The biggest mistake in 2026 is the same mistake many companies made with GDPR in 2018: treating it as an IT problem instead of an organisational one. The AI Act is a governance regulation as much as a technical one. The work is partly compliance-team work, partly procurement work, partly an HR conversation about what your hiring tool is actually doing. IT supports all of these, but no IT team can carry the whole load alone.
Set up the working group early. Loop in legal, HR, procurement and the relevant business owners. Make the AI register an organisational artefact, not a technical one. The Mittelstand companies that do this in 2026 will spend a quiet 2027 watching their less-organised peers scramble.
Why this is worth getting right
The AI Act is the first credible governance regime for AI in any major economy. Whatever its rough edges, it shapes how DACH enterprises will buy, build and operate AI for the rest of the decade. The Mittelstand companies that engage with it as a normal part of governance, rather than an annoyance, end up with better AI systems — more transparent, more auditable, more defensible. That is not a compliance victory. That is just how serious adoption looks.
