The EU AI Act represents a significantly larger regulatory risk for German companies than previously assumed. A new analysis shows: not only technology providers and AI developers must prepare for the new regulations, but all organizations that deploy AI systems – from HR systems to financial software.
Key Points
- The EU AI Act applies to all companies using AI systems, not just developers
- Particularly affected: organizations deploying standard software with integrated AI functions in areas such as biometrics, performance evaluation, and learning applications
- Erena Langley, Director of Regulatory Solutions at Navex, warns of massive compliance gaps in the German mid-market
- Missing technical standards and unclear regulatory responsibilities create significant uncertainty
The Biggest Misconception
The central problem lies in a widespread misunderstanding: many German companies believe the EU AI Act primarily affects technology corporations. In reality, the opposite is true.
The EU AI Act applies not only to artificial intelligence that companies develop themselves, but also to the use of enterprise software in which AI is integrated.
This is how Erena Langley from Navex explains it. The problem: AI has long since established itself in companies – but is often not perceived as a regulatory risk. In many cases, AI is not introduced as a standalone project, but supplements existing HR, legal, or financial systems with additional functions. Using third-party AI software also creates concrete documentation, control, and proof obligations.
Where It Falls Short: Standards and Authorities Missing
But internal shortcomings are not the only problem. Uncertainty is massively exacerbated by external factors:
| Obstacle | Status | Consequence |
|---|---|---|
| Technical Standards | Not yet published | Companies don't know how to demonstrate compliance |
| National Regulatory Responsibilities | Unclear | No German guidelines for interpretation and oversight |
| Deadlines | Partially postponed (Digital Omnibus) | Confusion about actual deadlines |
Langley warns clearly: "Companies are still waiting for European standardization organizations to publish the required compliance standards and for the German federal government to assign the Bundesnetzagentur and the German Accreditation Body with the corresponding tasks."
As long as this guidance is missing, uncertainty remains high. Many companies are waiting for national guidelines before they begin implementation – this is exactly where the core problem lies.
What German Companies Should Do Now
For decision-makers, this means: waiting for complete clarity is not a strategy. Langley emphasizes that companies must become aware of the actual scope of the EU AI Act to incorporate requirements into processes, responsibilities, and control mechanisms in time. This is especially true for the mid-market, which often operates with limited compliance resources.
Takeaway: The EU AI Act is becoming a central compliance challenge for German companies – not at some point in the future, but now. The combination of missing standards, unclear regulatory responsibilities, and partially postponed deadlines creates a vacuum that many companies underestimate. Those who establish protective measures early avoid fines and reputational damage later. At the same time, it is clear: without national guidelines and binding technical standards, it will remain difficult for many companies to demonstrate genuine compliance.
Sources
Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.




