Last updated on 2 July 2026.

With the Digital Omnibus finally adopted on 29 June 2026, three deadlines matter for mid-sized companies. The EU AI Act's transparency obligations apply from 2 August 2026, watermarking for systems already on the market from 2 December 2026. High-risk obligations move to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). AI literacy and NIS2 already apply; if you've missed the German BSI registration, catch up now.

Executive Summary

Seven EU regulations are simultaneously active and enforceable in April 2026, each requiring operational responses from German SMEs. Germany's NIS2 implementation law took effect in December 2025 with no transition period, covering an estimated 29,500 organizationsMyBusinessFuture: NIS2-Umsetzung im Mittelstand 2026. The AI Act's AI literacy obligation has been live since February 2025, and from December 2026, manufacturers of software and AI products face liability under the revised Product Liability DirectiveBitkom Consult: Nächste Phase des EU AI Act ab August 2025A&O Shearman: Update Produkthaftungsrecht Deutschland März 2026. An integrated governance framework can reduce compliance effort by up to 60%, because six of the seven regulations share the same core requirementsEnactia: Compliance Triple Threat DORA NIS2 EU AI Act Overlap.

EU AI regulation for mid-sized companies 2026: status, deadlines, and penalties at a glance
RegulationStatus July 2026Next DeadlineMax Penalty
EU AI ActProhibitions + AI Literacy + GPAI in forceAug 2026: transparency obligations · Dec 2026: watermarking for existing systems · Dec 2027/Aug 2028: high-risk (Reg. (EU) 2026/1744)€35M / 7% revenue
NIS2 (Germany)Fully in force since 06.12.2025Registration deadline passed (Mar 2026)€10M / 2% revenue
DORAFully in force since 17.01.202531.12.2026: BAIT/VAIT supersededUp to 2% revenue (daily 1%)
CRAIn force since 10.12.2024Sep 2026: 24h vulnerability reporting€15M / 2.5% revenue
Product Liability (new)Directive in force since 08.12.2024, Bundestag 1st reading 04.03.202609.12.2026: Transposition deadline, software/AI = productCivil liability (no cap)
Data ActIn force since 12.09.2025Sep 2026: Access by DesignUp to €500K (DE)
GDPR + AIEDPB Opinion 28/2024, DSK RAG guidance2026: Coordinated enforcement on transparency€20M / 4% revenue

Status as of 24 July 2026: the Digital Omnibus has been adopted as Regulation (EU) 2026/1744 and was published in the EU Official Journal on 24 July 2026EUR-Lex: Verordnung (EU) 2026/1744 (Digital Omnibus on AI), Amtsblatt der EU vom 24.07.2026. Council (13 March) and Parliament (26 March, 569 to 45 votes) had both pushed for the high-risk postponement; the final text delivers exactly that: 2 December 2027 for Annex III, 2 August 2028 for Annex I.

Which regulations apply to your company?

Every CEO needs to know which of these regulations apply to their specific company. Three factors determine this: employee count, sector, and product portfolio.

Every company deploying AI systems must ensure AI literacy of its staff since February 2025 (Art. 4 AI Act)Bitkom Consult: Nächste Phase des EU AI Act ab August 2025. Prohibited practices apply regardless of company size. Any AI application processing personal data triggers GDPR obligations. The EDPB clarified in its Opinion 28/2024 that legitimate interest can serve as a legal basis for AI training but requires a three-part balancing testEDPB Opinion 28/2024: KI-Modelle und DSGVO.

Companies in NIS2 sectors (energy, transport, healthcare, digital infrastructure, manufacturing, food, chemicals, and 12 others) with more than 50 employees or €10 million revenue fall under Germany's NIS2 implementation lawMyBusinessFuture: NIS2-Umsetzung im Mittelstand 2026. The BSI registration portal has been live since January 2026; the deadline passed in March 2026. Managing directors bear personal liability under §38 BSIG with no option for contractual limitationSecjur: NIS2 Haftung Geschäftsführer §38 BSIG.

Manufacturers of products with digital elements (machinery, IoT devices, industrial software) are subject to the Cyber Resilience Act. From September 2026, actively exploited vulnerabilities must be reported within 24 hoursHogan Lovells: CRA Key 2026 Milestones. Full conformity with CE marking applies from December 2027. For connected products, the Data Act adds an "Access by Design" obligation from September 2026EU-Kommission: Data Act Policy. In the UK, the Product Security and Telecommunications Infrastructure Act has been in force since April 2024 with similar objectives, making CRA compliance a competitive advantage beyond EU borders.

The revised Product Liability Directive adds another layer: software and AI systems are now classified as "products" for liability purposes, with a transposition deadline of 9 December 2026A&O Shearman: Update Produkthaftungsrecht Deutschland März 2026. The German Bundestag held its first reading of the implementing legislation on 4 March 2026A&O Shearman: Update Produkthaftungsrecht Deutschland März 2026. Non-compliance with CRA or AI Act requirements can trigger a rebuttable presumption of product defectiveness in civil proceedings. Manufacturers who retain control over their product after placing it on the market (through updates, digital services, or connected components) can be held liable for defects that arise afterwardA&O Shearman: Update Produkthaftungsrecht Deutschland März 2026.

Financial sector firms and their IT suppliers fall under DORA, which has been fully applicable since January 2025. DORA is lex specialis to NIS2 and imposes stricter incident reporting: four hours after classification as severeBaFin: DORA Digital Operational Resilience Act. The BaFin is conducting systematic audits throughout 2026. SMEs are affected if they serve as critical ICT third-party providers to financial institutions.

Even companies below the formal thresholds face indirect pressure. NIS2-regulated customers increasingly require contractual cybersecurity assurances from their suppliersKopexa: NIS2 unterschätzte Pflicht für Mittelstand und Zulieferer.

Where do the requirements overlap?

Five requirement areas appear across virtually every regulation. Building them once in an integrated framework saves an estimated 60% of compliance effort compared to siloed projectsEnactia: Compliance Triple Threat DORA NIS2 EU AI Act Overlap.

Requirement matrix: where AI Act, NIS2, DORA, GDPR, and CRA overlap for mid-sized companies
RequirementAI ActNIS2DORAGDPRCRA
Risk ManagementAI risk classificationCyber risk analysisICT risk frameworkDPIAProduct security assessment
Incident ReportingSerious incidents24h / 72h / 1 month4h / 72h / 1 month72h (96h proposed)24h to ENISA
Supply ChainAI supplier assessmentArt. 21: Supply chain securityArt. 28: ICT third-partyProcessor managementComponent security
GovernanceHuman oversightPersonal director liabilityPersonal director liabilityDPODeclaration of conformity
DocumentationTechnical documentationRisk analysesInformation registerProcessing recordsSBOM + CE

A single risk register with regulation-specific categories serves all frameworks. One incident response process with differentiated reporting timelines replaces five parallel notification chains. A vendor assessment framework with regulation-specific add-on modules eliminates redundant supplier audits.

The Digital Omnibus proposes a unified EU reporting portal that automatically routes notifications to the relevant authoritiesEU-Parlament: Digital Omnibus on AI Legislative Train. Until that portal is operational, companies must build their own multi-regime notification logic. The revised Product Liability Directive adds further motivation: non-compliance with CRA or AI Act requirements can serve as evidence of product defectiveness in civil proceedingsA&O Shearman: Update Produkthaftungsrecht Deutschland März 2026.

Which certification delivers the most leverage?

ISO 27001:2022 covers 60 to 85% of NIS2 requirements and approximately 85% of DORA requirementsKopexa: NIS2 ISO 27001 Mapping. The remaining gaps are primarily sector-specific reporting timelines and technical penetration testing mandates. For a 100-person SME, certification typically costs between €50,000 and €100,000 (estimate) and takes six to twelve months.

For AI governance specifically, ISO 42001:2023 supports EU AI Act compliance for high-risk systems, though it does not guarantee conformity since legal requirements exceed any voluntary standardCloud Security Alliance: ISO 42001 und EU AI Act. The forthcoming harmonised standards from CEN-CENELEC JTC 21 are expected to reference ISO 42001 concepts.

Revised in October 2025, ISO 27701 is now a standalone management system, removing the previous ISO 27001 prerequisiteTekClarion: ISO 27701:2025 GDPR Compliance. It maps GDPR requirements directly and includes new annexes on AI-related data processing.

For the automotive supply chain, TISAX assessments cover NIS2 Art. 20 and Art. 21 requirements completely when all affected locations are within scopeENX Association: TISAX als Beitrag zur NIS-2 Cybersicherheit. Cloud service providers benefit from the BSI C5 attestation with 121 controlsBSI: C5 Cloud Computing Compliance Criteria Catalogue. In contrast, US-based frameworks like SOC 2 Type II provide reasonable overlap with ISO 27001 but do not map directly to NIS2 or AI Act requirements. For EU compliance, ISO-based certification is the more efficient path.

Certification priority for mid-sized companies: ISO standards by coverage and timeline
PriorityCertificationCoverageTimeline
1ISO 27001:2022NIS2 (60 to 85%), DORA (85%), AI Act (security), CRA (org)Start now, 6 to 12 months
2ISO 42001AI Act (high-risk), AI governanceFrom Q3 2026
3ISO 27701:2025GDPR, AI Act (privacy)From Q1 2027
4Sector-specific (TISAX/C5/B3S)Sector obligations + NIS2As needed

Will the Omnibus package shift the deadlines?

As of July 2026, the Digital Omnibus is done. After the failed trilogue on 28 April, the political deal landed on 7 MayRat der EU, Pressemitteilung 07.05.2026: Council and Parliament agree to simplify and streamline AI rules; Parliament approved on 16 JuneMorgan Lewis, EU Approves Delays and Other Amendments to Certain EU AI Act Obligations (Juni 2026, Parlamentsvotum 16.06. mit 423:57) and the Council gave its final green light on 29 JuneRat der EU, Pressemitteilung 29.06.2026: Council gives final green light (Omnibus VII / Digital Omnibus AI). The package is published as Regulation (EU) 2026/1744 in the EU Official Journal of 24 July 2026EUR-Lex: Verordnung (EU) 2026/1744 (Digital Omnibus on AI), Amtsblatt der EU vom 24.07.2026. High-risk deadlines are now fixed at 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Transparency obligations stay on 2 August 2026; watermarking for existing systems moves to 2 December 2026Gibson Dunn, EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes (Mai 2026). The AI literacy duty survives in softened formGibson Dunn, EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes (Mai 2026), and there's a new ban on AI generating non-consensual intimate imageryRat der EU, Pressemitteilung 29.06.2026: Council gives final green light (Omnibus VII / Digital Omnibus AI). On NIS2, the German registration duty stands unchangedSecjur, NIS2-Umsetzung Deutschland: Gesetz, Fristen und Schritte 2026 (Registrierungsfrist 06.03.2026 abgelaufen, Nachregistrierung möglich, fehlende Registrierung bußgeldbewehrt).

Two Omnibus packages affect SMEs. The Sustainability Omnibus has been adopted: Directive (EU) 2026/470 entered into force on 16 March 2026, raising CSRD reporting thresholds to 1,000 employees and €450 million revenuePwC Viewpoint: Omnibus Directive Finalised 2026. For the typical Mittelstand company, sustainability reporting obligations are effectively gone.

The Digital Omnibus has been adopted and published as Regulation (EU) 2026/1744 in the EU Official Journal on 24 July 2026EUR-Lex: Verordnung (EU) 2026/1744 (Digital Omnibus on AI), Amtsblatt der EU vom 24.07.2026. The high-risk deadlines are now final: 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Several of the Commission's simplification proposals were rolled back during the procedure: the AI literacy obligation survives with a lowered standardGibson Dunn, EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes (Mai 2026). A new prohibition covers AI systems that generate non-consensual sexual deepfakesRat der EU, Pressemitteilung 29.06.2026: Council gives final green light (Omnibus VII / Digital Omnibus AI). The labelling obligations for AI-generated content (Art. 50) apply from 2 August 2026; systems already on the market before that date must comply by 2 December 2026Gibson Dunn, EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes (Mai 2026). The DIHK position paper calls for unified definitions across all digital legislation and tiered certification optionsDIHK: Positionspapier Digital Simplification Package. For planning purposes this means: the new deadlines are legally settled. There is nothing left to wait for from Brussels.

What must CEOs do this week?

Block 90 minutes on Monday and open the BSI's applicability check at bsi.bund.de. The 15 questions determine whether NIS2 applies to your company. Write the result on a single page: affected sector yes/no, thresholds met yes/no, BSI registration completed yes/no. If you missed the March 2026 registration deadline, complete it in the same session. The BSI portal has been online since January 2026MyBusinessFuture: NIS2-Umsetzung im Mittelstand 2026. In the same sitting, assess whether the CRA or Data Act applies to your products.

Commission an ISO 27001 readiness assessment from an accredited provider, even if NIS2 does not formally apply to you. The assessment benchmarks your current posture against the standard and produces a gap analysis with a prioritised action list. Typical timeline to certification: six to twelve months. Investment for lower Mittelstand: from €50,000 (estimate). The readiness assessment itself costs between €3,000 and €8,000 (estimate) and takes two to four weeks.

Map every AI system in use across your company, from the customer service chatbot to AI-assisted applicant screening. Classify each according to the AI Act risk tiers: prohibited, high-risk, limited risk, minimal risk. Most office AI tools (Copilot, ChatGPT in a browser) fall under minimal risk. It gets critical with AI in HR processes, credit decisions, or biometric identification. Verify that your staff meets the Art. 4 AI literacy requirementBitkom Consult: Nächste Phase des EU AI Act ab August 2025. Bitkom provides free self-assessment guidesBitkom: AI Act kommt nach Deutschland. If you operate high-risk systems, begin documentation now. The architectural foundation for an audit-ready AI system is laid out in AI compliance architecture: three decisions. Waiting for the Omnibus to be formally adopted is a bet, not a strategy.

Our Take

Almost every managing director tells us the same thing: "We're handling NIS2 with the IT manager and sorting out the AI Act separately." It sounds reasonable. It is the most expensive approach. With one client of around 200 employees, we built a single risk register with five regulation-specific modules. The compliance workload roughly halved (estimate based on two comparable engagements).

Something that stuck with me since: across three other engagements, ISO 27001 certification ended up costing less than the legal fees that a penalty negotiation would have required.

Three deadlines converge in September 2026: CRA vulnerability reporting, Data Act Access by Design, AI Act transparency obligations. In December, the Product Liability Directive adds another. Companies without a functioning multi-regime incident response process by summer 2026 will spend the autumn in crisis mode.

To check which regulations apply specifically to your company and where you stand today, see the AI regulation check for SMEs.