AI for Business Institute

New EU AI Act: How Mid-Sized Businesses Are Scrambling to Achieve Compliance

Mid-sized European firms scramble to interpret and implement the EU AI Act, facing significant operational and financial hurdles.

The European Union's Artificial Intelligence Act, provisionally agreed upon in December 2023, is set to impose a comprehensive regulatory framework on AI systems. While large corporations often possess dedicated legal and compliance departments, mid-sized European businesses are now grappling with the significant challenge of adapting their AI deployments and development processes to meet these stringent new requirements. The Act categorises AI systems by risk level, with 'high-risk' applications facing the most rigorous obligations, including conformity assessments, risk management systems, and human oversight.

Understanding the Regulatory Landscape

Many mid-sized enterprises, particularly those innovating with AI in sectors like manufacturing, healthcare, and finance, are finding the sheer volume and technical detail of the Act daunting. Identifying which of their AI systems fall into the 'high-risk' category is a primary hurdle. This classification dictates the level of compliance required, impacting everything from data governance and cybersecurity to transparency and human oversight mechanisms. Companies are investing in legal counsel and specialised consultants to interpret the Act's nuances and assess their current AI portfolios.

Operationalising Compliance

Beyond legal interpretation, the operationalisation of compliance presents a significant challenge. Mid-sized firms typically operate with leaner resources than their larger counterparts. Implementing robust quality management systems, ensuring data traceability, conducting impact assessments, and establishing post-market monitoring for AI systems require substantial internal adjustments. Some businesses are exploring partnerships with AI governance platforms or consortiums to share best practices and resources, while others are upskilling existing staff in AI ethics and regulatory compliance.

Investment in Infrastructure and Training

The Act necessitates investment in new infrastructure and training. For instance, ensuring AI systems provide adequate logging capabilities for accountability and auditing purposes may require significant technical upgrades. Furthermore, staff across various departments, from AI developers to product managers, need training on the Act's requirements and their role in maintaining compliance. This often involves a cultural shift, embedding 'AI by design' principles from the outset of development rather than as an afterthought.

Strategic Adjustments and Future Outlook

Some mid-sized businesses are re-evaluating their AI strategies, prioritising lower-risk applications or seeking to modify high-risk systems to mitigate regulatory burdens. Others view compliance as a competitive advantage, aiming to build trust and demonstrate responsible AI deployment. The coming months will be critical as the Act moves towards full implementation, with companies racing to establish the necessary frameworks and processes to avoid penalties and maintain market access within the EU.

Briefing notes

Questions this story answers

01How does the EU AI Act categorise AI systems?

The EU AI Act categorises AI systems by risk level, with 'high-risk' applications facing the most stringent requirements, including conformity assessments, risk management systems, and human oversight. This classification determines the extent of compliance obligations.

02What are the main challenges for mid-sized businesses under the EU AI Act?

Mid-sized businesses are challenged by interpreting the Act's details, identifying high-risk AI systems, and operationalising compliance with leaner resources. They also face significant investment needs for new infrastructure and staff training.

03What strategies are mid-sized businesses employing to achieve compliance?

Companies are investing in legal counsel, specialised consultants, and partnerships with AI governance platforms. They are also upskilling staff, implementing new quality management systems, and embedding 'AI by design' principles.

04What specific requirements does the EU AI Act impose on AI systems?

The EU AI Act requires robust quality management systems, data traceability, impact assessments, post-market monitoring, and adequate logging capabilities for AI systems. It also mandates human oversight and transparency.

05What is the overall goal of the EU AI Act?

The Act aims to ensure AI systems are safe, transparent, non-discriminatory, and environmentally sound, fostering trust in AI while promoting innovation. It seeks to protect fundamental rights and establish a harmonised regulatory framework across the EU.

Put the intelligence into practice

Your next move

Turn responsible AI understanding into a recognised standard of capability.
For professionalsGet certified as an individualFor teams and enterprisesAccredit your organisation

Continue the brief