Germany’s Mittelstand — the roughly 3.5 million small and medium-sized enterprises that form the backbone of the German economy — is not the obvious protagonist in a story about EU AI regulation. These are the family-owned precision engineering firms in Baden-Württemberg, the specialist chemical manufacturers in the Ruhr, the machine tool companies in Bavaria with 200 employees and 60-year histories. They are not AI companies. They’re using AI, increasingly, but AI is a tool for them the way CAD software or ERP systems are tools — instrumental to the business, not the business itself.

The EU AI Act has encountered this population of users with consequences that nobody in Brussels, when designing the regulation, appears to have specifically modeled.

The issue is scope. The Act doesn’t only govern AI companies. It governs AI deployers — companies that use AI systems in their business operations. A Mittelstand manufacturer using AI for quality control inspection on an assembly line is deploying AI in what may be a high-risk application (if the manufacturing process is safety-critical or if the AI’s outputs determine whether workers are exposed to hazardous conditions). A logistics company using AI for route optimization and driver performance monitoring may be deploying high-risk AI under the employment provisions. A precision components supplier using AI-assisted design tools that recommend specifications to engineers may be deploying high-risk AI if those recommendations are for use in aircraft or medical devices.

None of these companies built the AI. They bought it. Under the Act, they’re still deployers with obligations.

Who’s a Deployer Under the Act

The EU AI Act’s definition of “deployer” is intentionally broad: any natural or legal person who uses an AI system under their authority (except for personal, non-professional use). This covers essentially every business in Europe that uses AI in any professional context.

Deployer obligations for high-risk AI are meaningful. Deployers must conduct a fundamental rights impact assessment for certain high-risk systems. They must implement human oversight measures adequate to the system’s risks. They must ensure their employees have adequate training on the AI system they’re using. They must report to the provider if they discover unexpected risks. They must keep logs of operations.

For a company like SAP or Siemens — whose entire business involves technology and whose compliance infrastructure is mature — these obligations are manageable extensions of existing processes. For a 150-employee machine tool manufacturer in Esslingen with an IT department of three people, they represent genuinely novel obligations requiring expertise the company doesn’t have.

The Mittelstand’s typical approach to software is purchase and deployment: buy the ERP, implement with a systems integrator, run it until it breaks or the vendor forces an upgrade. This approach doesn’t include ongoing oversight of the software’s compliance with evolving AI regulations. It doesn’t include fundamental rights impact assessments. It doesn’t include AI-specific employee training documentation.

The VDMA — Germany’s mechanical engineering industry association, representing approximately 3,200 Mittelstand manufacturers — published a survey in June 2026 finding that 67 percent of responding members believed they had AI systems in use that might be high-risk under the Act, but only 12 percent had conducted a formal classification assessment. The gap between deployment and compliance awareness is enormous.

What the Compliance Actually Involves

A typical Mittelstand company deploying industrial AI might have three to five AI applications: a quality control vision system, a predictive maintenance tool, an ERP-integrated demand forecasting model, and perhaps an AI-assisted design tool. Running through whether each of these is high-risk, conducting impact assessments, implementing logging and oversight, and documenting employee training — this is probably 100 to 150 hours of professional work per AI system, at consulting rates around €150 to €250 per hour.

For five AI systems, that’s roughly €75,000 to €190,000 in one-time compliance costs. Then €15,000 to €30,000 annually in ongoing compliance maintenance.

For a €20 million revenue manufacturer operating at typical industrial margins of 6 to 8 percent — that’s €1.2 to €1.6 million in annual operating profit — these numbers are significant. Not existential, but meaningful. A company operating at these margins doesn’t have €100,000 to spend on AI compliance without feeling it somewhere else.

The impact is compounded by the compliance market’s current structure. The consulting practices equipped to help Mittelstand companies with EU AI Act compliance are predominantly the large professional services firms whose minimum engagement sizes start at €50,000. They’re not structured to help a 150-person manufacturer conduct a focused €15,000 compliance assessment. The boutique consulting firms and legal practices that serve the Mittelstand in other compliance domains — tax, employment, environmental — largely don’t yet have AI Act expertise.

This gap is being addressed, slowly. Several German chambers of commerce have stood up AI Act guidance services for members. The German Federal Ministry for Economic Affairs published a practical Mittelstand compliance guide in May 2026. The BSW (Bundesverband Steuerberatung und Wirtschaftsprüfung, the German accountant and tax advisor association) is training members on basic AI Act compliance assessments. These are genuine efforts at making compliance accessible. They’re also six to twelve months behind where the Mittelstand is in terms of actual AI deployment and regulatory obligation.

The Industrial AI Investment Question

The Mittelstand’s compliance challenges have an investment dimension that connects to Germany’s broader industrial competitiveness concerns.

Industrial AI — computer vision for quality inspection, predictive maintenance, process optimization, automated materials handling — is the category of AI with perhaps the clearest near-term economic return. The productivity gains are measurable, the ROI is documented, and the technology is mature enough that deployment risk is manageable. German manufacturers were among the early adopters of industrial AI precisely because they’re sophisticated enough to evaluate it and disciplined enough to implement it carefully.

The EU AI Act hasn’t stopped industrial AI investment in Germany. But it has changed the calculation, particularly for quality control and process monitoring AI that might be classified as high-risk in safety-critical manufacturing contexts. The VDMA survey found that 41 percent of members had delayed or deferred an industrial AI investment in the past six months specifically due to AI Act compliance uncertainty.

Meanwhile, industrial AI investment in the US continues at pace, and Chinese industrial AI — developed and deployed domestically under China’s national AI strategy with minimal regulatory friction — is advancing rapidly. The Fraunhofer Institute’s June 2026 analysis of global industrial AI patent filings showed Germany’s share declining from 12 percent in 2021 to 8 percent in 2025. The US share held stable. China’s share increased from 34 to 41 percent.

There are many reasons for this trend that have nothing to do with the EU AI Act. German industrial R&D investment has been under structural pressure for years. The relationship between compliance overhead and innovation output is not linear or simple. But the regulation is adding cost and uncertainty to an investment decision that European industrial policy desperately wants companies to make.

What Would Actually Help

German Mittelstand companies are not asking for less regulation. The VDMA’s position — representing a broad cross-section of manufacturers who buy AI, not just the ones building it — is not anti-regulation. Their public statements support the AI Act’s goals. What they’re asking for is more accessible implementation guidance, a simplified assessment pathway for standard industrial AI applications (as opposed to the full conformity assessment track), and more time to implement obligations that they’re only now understanding they have.

The EU AI Office’s regulatory sandbox program — which allows companies to test high-risk AI under regulatory supervision without full conformity assessment — is in theory available to deployers as well as providers. In practice, the sandbox program has been used almost entirely by AI developers, not industrial deployers. The application process is complex, the eligibility criteria favor innovation over compliance clarification, and the program doesn’t serve companies that simply need to know whether their existing machine vision system is compliant.

A more useful intervention would be sector-specific standard contracts between AI providers and industrial deployers that clearly allocate compliance obligations, pre-negotiated with the national AI authority. This is being discussed in Germany. It hasn’t happened. The interval between discussion and implementation is where Mittelstand companies are currently living — knowing they have obligations they can’t fully meet, waiting for guidance that hasn’t fully arrived.

The AI Provider Responsibility Gap

One of the less discussed aspects of the Mittelstand’s AI Act exposure is that it exists partly because AI providers — the companies selling AI tools to Mittelstand manufacturers — have been slow to provide adequate compliance support to their industrial customers.

Under the Act, providers of high-risk AI systems have obligations to provide deployers with the information necessary for compliance. This includes instructions for use, technical specifications, and documentation adequate for the deployer to understand the system and implement required oversight. In principle, a Mittelstand manufacturer buying an industrial AI vision system should receive, from the provider, the core documentation needed to meet their deployer obligations.

In practice, most industrial AI vendors were not prepared for this in early 2026. Their products were designed for industrial utility, not regulatory compliance. Their documentation covered technical specifications, installation procedures, and maintenance — not EU AI Act conformity assessment packages. Some are retroactively preparing this documentation for existing customers. Many are including AI Act compliance packages in new contracts at additional cost.

The VDMA estimates that approximately 30 percent of AI vendors selling to German Mittelstand companies have proactively provided EU AI Act deployer support documentation to existing customers. The other 70 percent have not. This means the compliance gap isn’t just a Mittelstand failure to understand their obligations — it’s partly a provider failure to supply the information the law requires them to supply.

This should, in theory, generate enforcement attention: AI providers who fail to supply adequate deployer documentation are non-compliant with their own obligations under the Act. Whether national competent authorities will prioritize this issue is unclear. The German Federal AI Office has, to date, focused its limited resources on the highest-profile deployment risks rather than on provider documentation compliance. The gap between what the Act requires providers to give deployers and what providers are actually giving them remains wide. That gap is where most of Germany’s manufacturing AI compliance problems actually live.

Get the best of Think Different in your inbox

One email a month: new articles, reviews and the upcoming live webinar + free recording. No spam, unsubscribe anytime.