EU-Regulierung

EU AI Act 2025: What the August Implementation Means for European SMEs

General AI models are subject to new obligations – Is your company ready for EU AI Act compliance? Organizations using ChatGPT, Copilot, Claude, or Gemini face penalties of up to €35 million or 7% of global annual revenue.

Sarah Mueller
Sarah Mueller
Senior Compliance Beraterin
September 18, 2025
3 min read
KI Standard

Phase 2: In effect since August 2, 2025

The Phase 2 obligations of the EU AI Act came into force on August 2, 2025, and create significant compliance requirements for European SMEs using AI systems. Most SMEs are not yet aware of these requirements.

Critical Warning

Organizations using ChatGPT, Copilot, Claude or Gemini face penalties of €35 million or 7% of global annual revenue – whichever amount is higher.

Two primary requirements

1. Transparency obligations for GPAI providers

  • Technical Documentation on Training Processes and Model Limitations
  • Disclosure of Training Data Summaries for Identifying Potential Biases
  • Documentation of Copyright Compliance Procedures
  • Publication of contact information for regulatory inquiries

2. Reporting and Risk Obligations

Organizations that deploy AI models with systemic risk must notify EU authorities.

Three practical scenarios

Scenario 1: Customer Service Chatbots

Requires disclosure to customers, documentation practices and governance structures with human oversight protocols.

Scenario 2: Recruiting-AI (High-risk)

Requires risk assessments, mandatory human review of decisions, candidate transparency, and detailed audit trails with decision justifications.

Scenario 3: Business Analytics (lower risk)

Requires system documentation, understanding of training data and human verification before implementation.

Compliance Schedule

  • By December 2025: Inventory of all AI systems including users, applications, and risk classifications
  • By February 2026: Establish governance structure, appoint AI officer, develop usage guidelines
  • By March 2026: Conduct team training, create documentation
  • Ongoing: Document all systems, identify risks, record compliance measures

Penalty structure

  • Prohibited practices: €35 million or 7% of global annual turnover
  • High-risk systems non-compliance: €15 million or 3% of annual turnover
  • Transparency violations: €7.5 million or 1% of annual turnover

Example: An SME with €10 million revenue risks €100,000 minimum penalties for 1% violations.

Conclusion

The regulation promotes transparent, secure and ethical AI implementation. Responsible SMEs that adequately document their practices will have minimal compliance challenges. Non-compliance results from the failure to document systems and address inherent risks such as discrimination or data protection violations.

#
Share:

About the Author

Sarah Mueller
Sarah Mueller
Senior Compliance Beraterin

Senior Compliance Beraterin mit Fokus auf ISO-Zertifizierungen und EU-Regulierung.

Related Articles

Die Zukunft der Zertifizierung

Many SMEs in Austria, Switzerland, Spain, France, and Italy think: "This doesn't affect us – we don't have 1,000 employees." But while direct applicability may be limited, the indirect effects are almost universal.

Nov 28, 2025