EU AI Act under criticism: practical check for South Tyrolean SMEs
This article was translated from German with the assistance of AI.
- Most of the EU AI Act has applied since 2 August 2026. AI literacy has been mandatory since February 2025, and transparency rules have applied since August 2026.
- High-risk rules for employment, credit and critical infrastructure now apply from December 2027 or August 2028, depending on the system.
- Users of standard software can still have obligations as deployers. Their role, intended use and risk class determine what is required.
Most of the EU AI Act has applied since 2 August 2026. For companies, the relevant question is no longer whether to address it, but which obligations apply to their specific role and use case. Most everyday AI tools are not high-risk, yet requirements for AI literacy and, in certain cases, transparency already apply.
A proportionate approach makes sense for South Tyrolean SMEs. An internal writing assistant, a customer chatbot and AI-supported applicant screening do not belong in the same category. The intended use, affected people and the company's role as provider or deployer determine the effort required.
Risk: The “compliance trap” for SMEs
The main practical difficulty is correct classification. A hotel chatbot must generally make clear that people are interacting with a machine. An applicant-screening system may instead be high-risk and trigger much broader requirements. Those high-risk rules were postponed to 2 December 2027, or 2 August 2028 for AI embedded in regulated products.
The frequently quoted maximum fine of 35 million euros or seven percent of worldwide annual turnover concerns prohibited AI practices. Other provider and deployer obligations have different ceilings. For SMEs, the lower of the percentage and fixed amount applies, so a single headline figure without context is misleading.
Opportunity: “Made in Europe” as a seal of quality
Data protection, traceable decisions and clear responsibility are genuine quality signals in sensitive industries. Companies that document applications, train employees and define human approval points build trust with customers and their own teams. For particularly sensitive information, local AI can be a controllable alternative to the cloud.
The 3 most important to-dos for South Tyrolean entrepreneurs
These three steps create a reliable foundation:
- 1. Build an inventory: Record systems, intended purposes, data types, responsible people and affected groups. Include integrated AI functions in HR, CRM and marketing software.
- 2. Clarify roles and duties: Determine whether you are a provider, deployer, importer or distributor. Even when using Microsoft Copilot or other standard software, deployer duties may remain, such as human oversight, logging or informing affected people.
- 3. Implement current obligations: Provide appropriate AI literacy, disclose direct chatbot interactions and assess critical uses such as applicant screening, creditworthiness or infrastructure separately.
Conclusion: The AI Act is manageable when companies do not treat every application alike. Start with an inventory, role clarification and obligations already in force. Then assess individual high-risk uses in detail.
Updated 21 August 2026. The European Commission's official AI Act information is authoritative. This article is not legal advice.
Describe your situation to us in a free initial consultation. You get an honest assessment of whether and how AI helps you.
Free initial consultation