The EU AI Act has moved from theory into operations. For Berlin SMEs, the question is no longer whether regulation exists but whether the systems already in daily use can be documented, supervised, and defended.
Why smaller companies are still in scope
Many owners assume the AI Act mainly affects large model providers. That is too narrow. If your company uses AI for scoring, recommendations, document generation, customer interaction, or decision support, you may rely on systems that create compliance duties even if you never trained a model yourself.
Three immediate actions
- Create an inventory. List every AI-enabled workflow and tool in the company.
- Assess the role of each system. If it influences decisions about people, risk, or access, the compliance bar rises quickly.
- Document the operating model. Record inputs, outputs, responsible humans, fallback procedures, and vendor dependencies.
The strategic upside
Regulation is not only a burden. It raises the minimum bar for the market. Companies that understand their tooling and maintain proper oversight will look safer to clients, partners, and investors than competitors running unmanaged AI experiments across key workflows.
A pragmatic starting point
Most SMEs do not need a legal thesis first. They need a practical baseline: system inventory, basic risk classification, vendor documentation, human oversight rules, and a clear owner for each workflow. That turns a vague regulatory risk into work that can actually be planned and executed.