EU AI Act for SMEs: What Austrian Companies Must Do
EU AI Act for Austrian SMEs: which obligations apply, what changed on 2 August 2026, whether you need a KI-Beauftragter and three steps to take now.
The EU AI Act applies to every company that uses AI, not only to tech firms. For most Austrian SMEs the obligations are manageable: know which AI tools you use and what they decide, make sure the people using them understand them, and tell people when they are dealing with an AI or certain AI-generated content. Under the Act's timetable, the transparency rules apply from 2 August 2026, so now is the time to get organised.
Does the EU AI Act apply to my small business?
Yes, as soon as you use AI in your business. The Act distinguishes between providers, who develop AI systems, and deployers, who use them. Most SMEs are deployers: they use chatbots, AI writing tools, AI features in their CRM or automated email assistants. Deployers have fewer obligations than providers, but not none.
The Act sorts AI use by risk:
- Prohibited practices, such as manipulative techniques or social scoring, are banned outright.
- High-risk systems, for example AI used in recruitment, credit scoring or with biometric data, come with strict requirements.
- Limited risk, such as chatbots and generative AI, mainly brings transparency duties.
- Minimal risk, for example spam filters or internal drafting aids, brings no specific new obligations.
Most SME use cases fall into the limited or minimal risk categories. For small companies, the real risk is less the regulation itself than not knowing where their own tools fall.
What applies since 2 August 2026?
Under the Act's timetable, the transparency obligations apply from 2 August 2026. In practice this means:
- Chatbots and AI assistants that talk to customers must make clear that the person is interacting with an AI, unless that is obvious.
- Deepfakes, meaning realistic AI-generated or manipulated images, audio or video, must be labelled as such.
- AI-generated text published to inform the public on matters of public interest must be disclosed, unless a human has reviewed it and holds editorial responsibility.
- Providers of generative AI must mark synthetic output in a machine-readable way. That is mainly the vendor's job, but check that your tools do it.
The original timetable also set August 2026 for most high-risk obligations. The EU has since discussed adjusting parts of that timetable, so if any of your use cases could be high-risk, check the current status.
Do I need a KI-Beauftragter (AI officer)?
The AI Act does not require a formally appointed AI officer. What it does require is AI literacy: companies must make sure that staff who operate or use AI systems understand them well enough for their role. This obligation already applies.
Appointing a KI-Beauftragter is simply the most practical way to organise that. One person keeps the list of AI tools in use, trains colleagues, sets the internal rules and answers questions. In a small company, that can be the owner or an office manager with the right training. Peter Sigmond, who runs PPY Solutions, is a certified KI-Beauftragter and helps companies set up exactly this.
What should an SME do now?
Three steps cover most of the work:
- Audit: list every AI tool you use and which decisions it influences, including AI features hidden inside software you already have.
- Document: map your AI workflows and data flows. Who uses what, with which data, and who reviews the output?
- Classify: check whether any use case touches high-risk areas such as recruitment, credit or biometrics. If it does, get specific advice.
Then add the visible measures: a notice on your website chatbot, a label on AI-generated images where it is required, and a short internal AI policy.
How do we build compliance into our own systems?
We treat compliance as good housekeeping rather than an afterthought. Every action our AI agents take is logged in a persistent knowledge vault, so we can trace who or what did what, and when. Customer-facing agents are kept strictly separate from internal processing agents, and high-stakes actions need a human click. When an agent is not confident enough to act, it escalates to a person instead of guessing.
Much of this is not mandatory for low-risk systems. But it makes systems more transparent and easier to debug, and it helps when a customer or an authority asks questions.
FAQ
Does using ChatGPT in the office fall under the AI Act?
Using a general-purpose AI tool internally is usually minimal or limited risk. The main duties are AI literacy for staff and data protection: don't put personal or confidential data into public tools without a proper contract.
Do I have to label every AI-generated marketing text?
Not automatically. The disclosure duty targets chatbots, deepfakes and AI-generated text published to inform the public on matters of public interest without human editorial review. Marketing copy that a person reviews and publishes is generally not covered, although transparency rarely hurts.
Where can Austrian companies find official information?
The Austrian regulator RTR runs an AI service desk (KI-Servicestelle) with information for companies. For your specific situation, an AI audit clarifies which tools you use and where you stand.
This article is general information, not legal advice.
Tags:
Related Posts
Ready to automate?
Let's talk about how we can help you.
Book a Call