If you run a small or mid-sized business and the phrase "EU AI Act" has been sitting in your inbox unread, you are not alone — and you are not late. The headline date is 2 August 2026, when the regulation becomes fully applicable. This article is a plain-language orientation: what the law is, what is already in force, what an SME using an off-the-shelf AI assistant actually needs to think about, and how to treat the deadline as a reason to act rather than a reason to wait.
One disclaimer up front, in plain English: this is orientation, not legal advice. Every business is different, and where the stakes are high you should talk to a qualified advisor. The goal here is to replace vague dread with a clear picture.
The timeline, without the jargon
The EU AI Act did not appear overnight, and it does not arrive all at once. It phases in:
- August 2024 — the Act entered into force. The clock started.
- August 2025 — obligations for general-purpose AI (GPAI) models went live. These mostly land on the companies that build foundation models, not the SMEs that use them.
- 2 August 2026 — the Act becomes fully applicable. This is the date most businesses should anchor to.
- Into 2027 — some high-risk duties under Annex III phase in later, buying more time for the most heavily regulated use cases.
The EU AI Act does not replace the GDPR / DSGVO — it sits alongside it. Data-protection law still governs how you collect and process personal data; the AI Act adds a layer about how AI systems themselves are built, labelled, and overseen. If you already take DSGVO seriously, you have a head start.
The risk-based tiers, at a glance
The Act sorts AI systems by how much they can harm people, and regulates accordingly. Four broad tiers:
- Prohibited — uses considered an unacceptable risk (for example, certain forms of social scoring or manipulative systems). These are simply off the table.
- High-risk — systems used in sensitive contexts such as hiring, credit, or critical infrastructure. These carry the heaviest obligations: documentation, risk management, human oversight, logging. This is the tier whose duties phase in into 2027.
- Limited risk — systems that interact with people, like a customer-facing chatbot. The main obligation here is transparency: people should know they are talking to an AI.
- Minimal risk — the vast majority of everyday tools, where the Act imposes little to nothing.
For most SMEs, the honest answer is that a customer-support assistant or an internal knowledge helper falls into the limited-risk band. That is a relief — but "limited" is not "nothing." Transparency, data handling, and being able to show how the system behaves still matter.
What a typical SME actually needs to think about
Suppose you adopt an off-the-shelf AI assistant to answer customer questions or help your team find information. You are not training a foundation model; you are a deployer. Three practical concerns dominate.
1. Transparency
If a person is interacting with an AI, they should know it. For a public-facing agent this is straightforward — say so. Beyond the legal point, it is also good practice: customers trust a business that is upfront about how it answers them. (See how a closed cloud assistant compares with a sovereign one on the compare page.)
2. Data protection, alongside DSGVO
The single biggest question is: where does your data go? Most mainstream assistants send your prompts — and whatever knowledge you feed them — to a foreign cloud for processing. That raises DSGVO questions about transfers and processing, and it widens your exposure. The cleanest answer is to keep the model and the knowledge under your own control, a topic we cover in sovereign AI explained. If nothing leaves the building, an entire category of compliance risk simply does not arise.
3. Governance and an audit trail
You should be able to answer, in plain terms: what can this system see, what can it say, and can I prove it? That means knowing what knowledge an assistant draws on, controlling what a customer-facing agent is ever allowed to reveal, and keeping a record you can point to if asked. An audit trail is not bureaucracy for its own sake — it is the evidence that turns "we think we're compliant" into "here is how we know."
The real barrier is not the law — it's the uncertainty
Here is the most telling fact in this whole conversation. Across German businesses, legal uncertainty is the number-one cited barrier to adopting AI — roughly 53%. Not cost. Not skills. Uncertainty.
That uncertainty has consequences. Around 41% of German firms use AI in 2026 — about double the 2025 figure — yet roughly 43% of the mid-market still has no concrete AI plan. The market is splitting into businesses that found a way to move and businesses frozen by the fear of getting it wrong.
The deadline is real, but the paralysis is optional. The companies pulling ahead are not the ones with the biggest legal teams; they are the ones who chose tools where compliance is built in rather than bolted on afterwards.
Turning a deadline into a reason to act
This is exactly the gap Wegenty was built to close. The idea is simple: make the sovereign, governed path the default, so that an SME can adopt AI without an engineer — because a trusted local consultant runs it for them.
A few design choices do the heavy lifting:
- It runs locally. One locally-hosted model serves your knowledge bases. Your data stays in the building, which neutralises a large share of the DSGVO and transfer questions before they start.
- It is governed by architecture. Your internal knowledge base is the superset; the public customer agent is a governed projection of it — never the reverse. Sensitivity labels and per-base policy decide what a customer can ever see. Default-private, by design.
- It improves safely. When the agent is unsure, it escalates to a human, and that answer is captured back into the knowledge base via the correction loop. The system gets better without anyone hand-feeding it your secrets.
- It carries a compliance layer. The one closed component, Cloud Shield, is a compliance umbrella: live regulatory posture, an audit trail, and certification support under DSGVO and the EU AI Act. Everything else is open source, so you are never locked in — a stance we unpack in the product is governance and open core, sovereign by default.
In other words, the features that make Wegenty pleasant to use — local hosting, the projection boundary, the correction loop — are the same features that answer the compliance questions above. You can see how the pieces fit together on the platform page, and if you advise SMEs for a living, our consultant model is built precisely so the relationship — and the compliance work — stays with someone the customer already trusts.
A short, calm checklist
You do not need a legal department to make progress before August. You need orientation and a few good decisions:
- Inventory your AI use. List where AI already touches your business, even informally.
- Find your tier. For most SMEs the customer-facing pieces are limited-risk; sanity-check anything near hiring, credit, or safety.
- Follow the data. Ask every tool where prompts and knowledge go. Prefer ones that keep it local.
- Be transparent. Tell people when they are talking to an AI.
- Keep a record. Choose tools that give you an audit trail instead of making you build one.
Compliance is not the price of using AI. Done right, it is the reason your customers trust the AI you use.
The 2 August 2026 deadline is not a wall to brace against — it is a prompt to choose well. If you would like to see a governed, sovereign assistant answer real questions with nothing leaving the building, try the live demo or book a walkthrough. And if you are weighing what a deployment would cost, our pricing overview lays out the tiers in plain terms.