AI and automation

AI Act for Companies: How Regulation Can Become a Competitive Advantage

The AI Act is often reduced to labeling requirements and fines. What is crucial is something else: companies must make AI manageable. This can turn regulation into a trust and competitive advantage.

As of August 2, 2026, further key requirements of the European AI Act apply. The public discussion mainly focuses on labeling obligations, potential fines, and new restrictions.

That falls short.

The AI Act does not require every use of artificial intelligence to be publicly visible. Rather, it forces companies to differentiate more precisely: Which AI is used for what? What impact can it have? Which results require review? Who bears responsibility? And where must people be able to recognize that they are confronted with an AI system or with artificially generated content?

These questions create work at first. At the same time, however, they create something that is necessary for the productive use of AI anyway: clarity.

Precisely therein lies the strategic opportunity.

Note: This article is a strategic and organizational classification. It does not constitute legal advice and does not replace the review of concrete AI usage by a specialized law firm, a data protection officer, or other competent expert bodies.

The labeling requirement is not the core of the AI Act

The transparency obligations under Article 50 of the AI Act have been in effect since August 2, 2026.

From this, the shortened statement is occasionally derived that in future practically everything created with the help of artificial intelligence must be labeled: texts, images, advertisements, subtitles, or social media posts.

The regulation does not go that far.

The AI Act distinguishes between different situations.

For example, people should generally be able to recognize when they are directly communicating with an AI system. This applies to certain chatbots, AI agents, or voice assistants, for instance.

Artificially generated or manipulated images, audio, or video content may also require visible labeling if they depict existing persons, objects, places, or events in such a way that the content may falsely appear authentic or true.

Special transparency requirements also apply to published AI-generated or manipulated texts on matters of public interest.

At the same time, the regulation contains important distinctions.

A text that has undergone substantial human review or editorial control, and for which a person or organization assumes editorial responsibility, does not need to be labeled solely because generative AI was involved in its creation.

Even a purely assistive AI function for routine editing does not automatically make content subject to labeling requirements.

The crucial point is therefore not:

Was AI used anywhere?

But rather:

What function did the AI have, what impact does the result have, and what responsibility was organized around it?

Blanket labeling does not yet create responsibility

A notice like "created with AI" can create transparency. However, it does not solve any of the fundamental quality problems.

A labeled text can be factually incorrect.

A labeled image can be misleading.

An unshielded chatbot can output inappropriate information.

An AI system can be used transparently and still process personal data inappropriately.

Conversely, a work process intensively supported by AI can be technically very robust if sources, rules, review, and responsibility are cleanly organized.

Therefore, it would be a mistake to reduce the AI Act to labels.

For companies, the relevant work begins one level earlier.

AI adoption is growing faster than its organizational integration

Artificial intelligence is no longer a fringe topic in companies.

After a Bitkom survey from March 2026 41 percent of surveyed German companies with 20 or more employees were already using AI. Another 48 percent were planning or discussing its use.

This shifts the question of leadership.

As long as individual employees occasionally experiment with a new tool, many decisions can remain informal.

However, as soon as AI is regularly used for texts, research, translations, data analysis, customer communication, software development, knowledge search, or process automation, an operational system emerges.

Then the question "Which tool are we using?" is no longer sufficient.

Companies need to know:

  • which AI systems are actually deployed,
  • for which tasks they are used,
  • what information is processed in the process,
  • which results remain internal or have external effects,
  • when a human review is necessary,
  • who approves results,
  • which cases are intentionally not automated,
  • how errors and changes are detected.

These questions arise regardless of whether a law requires them.

The AI Act merely makes it more visible that the use of AI without organizational responsibility is not sustainable in the long run.

The parallel to the GDPR is not perfect, but instructive

The discussion is reminiscent of the introduction of the General Data Protection Regulation.

Even back then, a significant portion of public perception initially focused on effort, warnings, consents, privacy policies, and potential fines.

That was not unfounded. Regulation creates effort.

At the same time, a more fundamental development was initiated: companies had to understand more precisely which personal data they process, why they need it, who is allowed to access it, and what responsibility arises from it.

Today, data protection issues are naturally part of many digital projects.

Not every company has developed better processes as a result. Not every cookie banner builds trust. And the GDPR has not automatically become a competitive advantage either.

But a professional company can hardly afford to treat data protection as a purely downstream formality anymore.

A similar development is emerging with the AI Act.

The use of artificial intelligence will not be judged solely on whether something works technically. Increasingly, the deciding factor will be whether companies can explain how and under what conditions it works.

Trust is not created through regulation alone

Regulation does not automatically create a competitive advantage.

A company does not become better just because it maintains an AI register or employees have completed training.

The advantage arises from the capabilities built through serious implementation.

Clear use cases

“We use AI in marketing” is not a sufficient description.

A concrete use case is, for example:

A language model supports the editorial team in structuring and initially formulating specialist articles based on defined sources. Before publication, facts, sources, argumentation, and formulations are technically reviewed and editorially approved.

This makes the task, limit, and responsibility visible.

Suitable data and knowledge sources

An AI system can only work with the information available to it.

Companies must therefore distinguish between:

  • public information,
  • internal working documents,
  • confidential company data,
  • personal data,
  • binding sources,
  • historical documents,
  • unchecked information.

The question of data quality is thus directly linked to the question of result quality.

Appropriate human review

Not every AI output requires the same level of control.

An internal draft for a headline has different consequences than binding customer information, a legal statement, or an automated decision.

Verification should therefore be guided by impact, consequences of errors, and reversibility.

The existing classification “Why human review remains part of every robust AI process” describes this check not as a formal nod, but as a defined process function.

People need to know what to check, on what basis to decide, and when to stop or escalate a process.

Named Responsibility

AI can formulate recommendations, summarize information, and prepare actions.

It cannot assume entrepreneurial responsibility.

Therefore, for every relevant use case, it must remain traceable:

  • Who is responsible for the business purpose?
  • Who is responsible for data and sources?
  • Who checks the result?
  • Who is allowed to approve?
  • Who reacts to errors?
  • Who decides on changes?

The more outwardly impactful an AI system is or the more independently it performs actions, the more important this separation becomes.

AI Competence

The AI Act also addresses the competence of the people who use AI systems.

This is not about every employee having to become an AI specialist.

An appropriate understanding of the system actually used and its context of use is relevant.

Anyone working with generative AI should know, for example:

  • that persuasive language is no guarantee of factual correctness,
  • that sources can be invented or wrongly attributed,
  • which data may not be entered,
  • when results need to be checked,
  • what approval rules apply,
  • where the limits of the system lie.

AI competence is therefore not an abstract technological qualification.

It is operational competence.

The competitive advantage lies in mastery

The AI Act does not automatically make European companies more innovative.

It can even create additional effort and slow down projects if implemented unclearly.

Nevertheless, regulation can create a competitive advantage.

Not because regulation in itself is valuable, but because professional AI use requires capabilities that simultaneously build trust.

A company that masters its use of AI can explain to customers, partners, and employees:

  • what AI is used for,
  • where consciously not,
  • what data is used,
  • which results are checked,
  • who bears responsibility,
  • how errors are handled.

This capability becomes particularly relevant in the B2B environment.

There, it is not solely a matter of whether a provider produces content faster or automates more processes.

The crucial factor is whether clients can rely on confidential information being protected, statements being technically verified, and automated processes remaining controllable.

The actual competition is therefore not:

Companies with AI vs. companies without AI.

It increasingly states:

controlled AI use versus uncontrolled AI usage.

What this concretely means for marketing and communication

Particularly in marketing, the current discussion easily leads to overreactions.

A company does not have to proactively label every text as AI-generated just because ChatGPT, Copilot, or another language model assisted with structure, formulation, or revision.

Even automatic translations, standard processing, text optimization, or technical assistance functions do not automatically trigger a visible labeling requirement.

The situation is different when the type of AI application becomes essential for the user's perception.

Direct AI communication

If a human communicates directly with an AI system and this is not obvious anyway, they must fundamentally be informed about it.

This concerns, for example, a corresponding customer service chatbot or an AI voice agent.

Meaningful transparency is then not somewhere in the imprint:

Our company uses artificial intelligence.

Information belongs at the actual point of contact.

Realistically generated or manipulated content

An artificially generated image does not automatically have to be labeled as an AI image.

The question becomes relevant in particular when a real person, an existing place, object, or event is portrayed in such a way that viewers might consider the content to be authentic or true.

A synthetic speaker who appears like a real person, a manipulated real event, or a deceptively real artificial testimonial must therefore be treated differently than an obviously illustrative graphic.

Texts on matters of public interest

Differentiation is also necessary here.

For published AI-generated or manipulated texts that serve to inform the public about matters of public interest, the AI Act provides for a labeling obligation.

However, a significant exception exists where substantial human review or editorial control has taken place and editorial responsibility is assumed.

This is crucial for technical communication.

Human review does not mean spell checking here.

It means that a professionally qualified person actually assesses content, statements, facts, and sources, and can change or reject the text.

This makes editorial quality regulatory relevant.

Not everything needs more bureaucracy

The new requirements should not result in a knee-jerk large-scale project.

A medium-sized company does not necessarily need an extensive AI management system immediately.

The appropriate scope depends on which systems are used and what impact their use has.

For a company that primarily uses generative AI for internal drafts, a manageable structure may suffice:

  • List of approved systems,
  • permissible and impermissible data,
  • named use cases,
  • simple checking rules,
  • responsible persons,
  • documented AI instruction.

A company with automated customer decisions, sensitive data, or highly integrated AI agents requires considerably more.

Governance should therefore be proportional.

Too little structure creates risks.

Too much structure can unnecessarily block innovation.

The task is to adapt the control effort to the actual impact.

First step: Make your own AI usage visible

Many companies know which major AI tools have been officially introduced.

It is often less clear where AI is actually used in everyday work.

It is now found not only in standalone chat applications, but also in:

  • Office software,
  • translation services,
  • Image editing,
  • Marketing platforms,
  • CRM systems,
  • development tools,
  • Analytical applications,
  • Video platforms,
  • Search and knowledge systems.

A robust AI governance therefore does not start with a long guideline.

It begins with an inventory.

AI usage inventory for SMEs

A AI usage inventory for SMEs available.

The template captures not only product names but concrete use cases:

  • AI system and provider,
  • Task and affected process,
  • Users and responsible parties,
  • used data,
  • personal or confidential information,
  • Output and possible follow-up action,
  • external effect,
  • direct interaction with people,
  • necessary human review,
  • Release,
  • need for transparency or labeling,
  • internal risk classification,
  • open measures,
  • next review.

The inventory is supplemented by a review and release log as well as a compact quick check for new use cases.

Working template · XLSX

AI usage inventory for SMEs

Record systems, use cases, data, review, approval, and next check in a shared working basis.

Download AI usage inventory

The template is deliberately not an „AI Act Register“. There is no blanket legal obligation to keep exactly this document. The internal risk assessment also does not replace a legal classification according to the AI Act.

The inventory creates something more fundamental:

a common working basis for departments, management, data protection, and technical implementation.

What companies should not do

Label every AI use case by default

Over-labeling does not automatically create more transparency.

If every AI-assisted text, every translation, and every image edit receives the same notice, the labeling loses its significance where it is actually important for perception.

Leave AI use completely invisible

The counter-model is just as problematic.

An AI agent should not appear as a human employee. A realistically manipulated depiction should not be understood as an authentic recording. Transparency is necessary where it enables an informed assessment.

Confusing compliance with a disclaimer

A notice under content does not replace the verification of data, sources, systems, or responsibilities.

Compliance happens within the process.

Writing a policy that no one can apply

A twenty-page AI guideline is of little help if employees still don't know whether they are allowed to upload a customer file to a specific system.

Good rules are concrete enough to enable decision-making in everyday work.

Inventing the legal classification yourself

Internal traffic lights and risk classes can help with prioritization.

However, they should not be confused with the legal classification of the AI Act.

Expert review remains necessary for legally significant use cases.

Regulation can become quality architecture

The interesting effect of the AI Act therefore lies less in individual labelling obligations.

It lies in the fact that companies are forced to make their handling of artificial intelligence more explicit.

What could previously happen informally increasingly requires:

  • Limitation,
  • responsibility,
  • Review,
  • Competence,
  • Traceability.

These elements initially appear to require additional effort.

When properly implemented, however, they improve precisely the factors that are necessary for productive AI even without regulation.

A model delivers better results when the task is clearer.

Automation becomes more stable when the process is understood.

A technical text becomes more reliable when sources and verification are regulated.

An agent becomes more controllable when rights and exceptions are defined.

An organization becomes more capable of learning when errors are documented.

This allows operational quality to emerge from regulatory work.

Perspective from practice

Digital projects often show the same pattern.

The technical capability is available faster than the organizational clarity.

A new tool can be activated within a few minutes. The more difficult decision is whether and for what purpose it should be meaningfully deployed.

That is precisely why I do not primarily consider the AI Act to be an innovation brake.

Nor is it a guarantee of quality.

It sets a framework that forces companies to answer questions that must be answered anyway in professional digital work.

It was similar with data protection.

Not every data protection requirement has created a better website. But companies had to learn to understand data processing as a responsible component of digital processes.

The next comparable leadership task now arises with the use of AI.

Having as little AI as possible is not the goal.

The goal is not to use as much AI as possible.

Controlled AI is the goal.

Consequences for companies

The AI Act should neither be downplayed nor dramatized.

The new requirements are real. Individual use cases can trigger significant legal and organizational requirements.

For a large part of everyday AI support, however, there is no reason to treat every use as problematic across the board.

Companies should systematically differentiate instead:

  1. Which AI is actually used?
  2. What task does it fulfill?
  3. What data and sources are used?
  4. What impact does the result have?
  5. What human review is necessary?
  6. Who bears responsibility?
  7. What level of transparency is required in the specific case?
  8. What needs to be documented and regularly reviewed?

Those who can answer these questions not only meet regulatory requirements better.

It builds a capability that will be crucial for the coming years:

to be able to use artificial intelligence productively without relinquishing control over quality, knowledge, and responsibility.

This is not a restriction of innovation.

It is their professionalization.

Subject-matter connection

Develop AI application from individual use to a manageable system

The AI Act does not answer the strategic question of which AI applications are actually sensible for a company.

This decision begins earlier.

The existing insight “What companies need to clarify before AI automation” assigns task, data, roles, approval, risk, and success criterion for it.

“Why human review remains part of every robust AI process” deepens the role of human approval and exception handling.

The contribution "AI deployment requires roles, rules, and responsibilities" brings these levels together into an organizational governance model.

If existing AI use is first to be comprehensively categorized, prioritized, and linked with the remaining digital structures, the SDC-Discovery a common decision-making basis before further systems, automations, or guidelines are established.

Structurally review AI and automation foundations

Sources and factual basis (6)
  1. European Union, "Regulation (EU) 2024/1689 on artificial intelligence", consolidated version dated 27 July 2026. Open source
  2. European Commission, „Guidelines on transparency obligations for providers and deployers of AI systems“, July 2026. Open source
  3. European Commission, „Transparency obligations under Article 50 of the AI Act. Questions & Answers“, July 2026. Open source
  4. European Commission, "Code of Practice on Transparency of AI-generated Content", 2026. Open source
  5. European Commission, „AI Literacy. Questions & Answers“, 2026. Open source
  6. Bitkom, „Digitalization of the Economy. Almost every company is dealing with AI“, March 11, 2026. Open source
Göke Frerichs, digital strategist and Smart Digital Creative
Author

About Göke Frerichs

Göke Frerichs has been combining digital strategy, communication, technology, and implementation since 1999. As a digital strategist and Smart Digital Creative, he supports owner-managed B2B companies in developing clear and reliable digital systems from individual measures. His perspective is based on many years of consulting and implementation experience in the DACH region and North America.

More about Göke Frerichs
SDC-Discovery

Classify AI usage and responsibilities

Individual tools become a reliable system when use cases, data, review, and responsibility are considered together.

View SDC Discovery