AI Act·

EU AI Act – What German SMEs must document for Microsoft Copilot by 2 August 2026

On 2 August 2026 the EU AI Act's GPAI obligations kick in. What SMEs must now document for Microsoft Copilot and which sovereign alternatives hold up.

EU AI Act – What German SMEs must document for Microsoft Copilot by 2 August 2026

In five weeks – on 2 August 2026 – the EU AI Act's obligations for general-purpose AI models (GPAI) enter into force. Despite the Digital Omnibus postponing other deadlines, this date holds, as do the Article 50 transparency duties. For every German SME that uses Microsoft Copilot, ChatGPT Enterprise, or Claude in day-to-day office work, the implication is clear: by the end of July an auditable file must exist. Otherwise, fines of up to EUR 15 million or three percent of annual turnover – whichever is higher – become a live risk.

We work through the situation at the end of June 2026 without drama: what the deadline really covers, why Microsoft Copilot falls directly into scope, which documents must be on hand now, and where sovereign alternatives can measurably reduce the compliance burden.

What the EU AI Act demands from 2 August 2026

The EU AI Act has been in force since 1 August 2024 but takes effect in stages. GPAI – a model trained so generally that it is usable across many tasks, exactly the model type behind Copilot, ChatGPT, and Claude. Providers of such models acquire four main duties from 2 August 2026: technical documentation, information for downstream providers, a training-data summary, and a copyright policy.

For an SME that only uses Copilot rather than training it, the duties are lighter – but they are not zero. Article 50 transparency requires that end users be able to recognise that they are interacting with an AI system or that a piece of content is AI-generated. Synthetic audio, image, video, and text must be marked. The Article 4 AI-literacy duty has applied since 2 February 2025 anyway: anyone in the company working with AI must be demonstrably trained.

The Digital Omnibus, adopted by the European Parliament on 16 June 2026, shifts the obligations for high-risk AI under Annex III to 2 December 2027 and for embedded AI under Annex I to 2 August 2028. GPAI and transparency duties remain untouched.

Why Microsoft Copilot is in scope directly

Microsoft Copilot is technically based on Azure-OpenAI models – the GPT-4 family – and those fall under the GPAI definition. For its EU-market variant Microsoft itself publishes a Model Card and an AI Transparency Note. That covers Microsoft's provider duties, not the user duties of the deploying SME.

Three duties stay with the company that licenses Copilot:

  • Risk classification per use case. Copilot in Outlook is limited risk. Copilot for candidate pre-screening becomes high-risk under Annex III.
  • Transparency to data subjects. Whoever sends an AI-generated email reply must make this recognisable in context.
  • Oversight and intervention. A person must be able to override any Copilot output before it becomes binding.

Combine the Copilot risk classification with the Flex Routing outside the EU Data Boundary documented in April 2026 and you reach a double compliance gap: data-protection on one side, AI Act on the other. That is why BSI and supervisory authorities continue to handle Copilot restrictively in public administration – see also NIS2 and GDPR – the Microsoft paradox.

The four-block documentation – what belongs in the file

German supervisory practice condenses the AI Act user duty into four building blocks:

  1. Use-case inventory with risk classification per case.
  2. Data-category inventory – which personal and material data each case processes.
  3. Oversight concept – who reviews Copilot outputs and how deeply.
  4. Training and conformity records – attendance lists, audit logs, annual review.

A 50-person SME realistically needs ten to fifteen working days for this four-block file, if the inventories cannot already be derived from the GDPR records of processing activities and BSI IT-Grundschutz. If they can be derived, the effort shrinks to one week. The HowTo section below maps the pragmatic path.

Special case: schools and public sector

For schools and public bodies the picture is tighter. The German Data Protection Conference continues to classify Microsoft 365 in schools without additional measures as not legally compliant – the North Rhine-Westphalia commissioner confirmed this again in spring 2026. Adding the AI Act dimension via Copilot multiplies the risk. Concretely: a school authority deploying Copilot in administration potentially processes Article 9 GDPR special-category data – health, religion – via a GPAI model.

Public bodies are also subject to the Cloud and AI Development Act, which since 3 June 2026 prescribes sovereignty tiers for contracting authorities. Microsoft Copilot reaches CADA tier 1 in its EU-standard configuration. Tier 3 requires European ownership and is structurally unattainable with Copilot. Schools and municipal administrations that tender for CADA tier 3 must therefore switch to sovereign LLM endpoints.

Sovereign alternatives that reduce user duties

Anyone using the 2 August 2026 deadline to reorder their AI portfolio has three realistic sovereign options in summer 2026:

  • Aleph Alpha Luminous – German provider, hosted in Heidelberg. EU ownership, no US sub-processor. Suitable for administrative and contract text.
  • Mistral Large 2 – French provider, hosted at OVHcloud or STACKIT. Comparable quality to GPT-4, much stricter data residency.
  • EuroLLM – open-weight model from TU Munich and the Mistral consortium, self-hostable on Hetzner or via a managed hoster. Noticeably cheaper than closed-source models but higher configuration effort.

Combined with a sovereign office stack – see Microsoft Teams alternative – Element/Matrix or the openDesk components – the AI Act user duty falls back to what is strictly necessary. The four-block file still has to be kept, but risk classification routinely lands in "limited risk" and the sovereignty discussion disappears entirely.

We help SMEs, school authorities, and public bodies make exactly this reordering – from use-case inventory through to productive migration. Get in touch if the file should be in place by the end of July, and see /en/alternativen for the European LLM and office building blocks we operate.

In ten days to an AI-Act-ready Copilot file

The HowTo section in the frontmatter of this post lists a concrete ten-day path. Starting on 1 July 2026 gets the file in place by 15 July with two weeks of buffer until the deadline. Starting at the end of July is too late. The Article 4 training duty is the bottleneck because it needs a dated attendance list that cannot be backdated.

Bottom line

2 August 2026 is not a doomsday but it is not free either. Whoever uses Microsoft Copilot needs a four-block documentation, a transparency practice, and a training record. Whoever is already considering sovereign alternatives – because of CADA, DORA, school-authority oversight, or simply a sovereignty strategy – now has the right occasion to reorder for the next five weeks. Both paths are doable. Both want a decision now.