[{"data":1,"prerenderedAt":422},["ShallowReactive",2],{"navigation-docs_en":3,"/en/blog/eu-ai-act-microsoft-copilot-smes-august-2026-posts_en":51,"/en/blog/eu-ai-act-microsoft-copilot-smes-august-2026-surround-posts_en":411},[4],{"title":5,"path":6,"stem":7,"children":8,"page":25},"En","/en","en",[9],{"title":10,"path":11,"stem":12,"children":13,"page":25},"Docs","/en/docs","en/1.docs",[14,26],{"title":15,"path":16,"stem":17,"children":18,"icon":25},"Getting Started","/en/docs/getting-started","en/1.docs/1.getting-started/1.index",[19,21],{"title":20,"path":16,"stem":17,"children":-1},"Introduction",{"title":22,"path":23,"stem":24,"children":-1},"Migration Roadmap","/en/docs/getting-started/migration-fahrplan","en/1.docs/1.getting-started/2.migration-fahrplan",false,{"title":27,"path":28,"stem":29,"children":30,"page":25},"Technologies","/en/docs/technologies","en/1.docs/2.technologies",[31,35,39,43,47],{"title":32,"path":33,"stem":34,"children":-1},"Nextcloud","/en/docs/technologies/nextcloud","en/1.docs/2.technologies/1.nextcloud",{"title":36,"path":37,"stem":38,"children":-1},"Matrix / Element","/en/docs/technologies/matrix","en/1.docs/2.technologies/2.matrix",{"title":40,"path":41,"stem":42,"children":-1},"ONLYOFFICE","/en/docs/technologies/onlyoffice","en/1.docs/2.technologies/3.onlyoffice",{"title":44,"path":45,"stem":46,"children":-1},"Ubuntu Linux","/en/docs/technologies/ubuntu","en/1.docs/2.technologies/4.ubuntu",{"title":48,"path":49,"stem":50,"children":-1},"Keycloak","/en/docs/technologies/keycloak","en/1.docs/2.technologies/5.keycloak",{"id":52,"title":53,"authors":54,"badge":60,"body":62,"date":355,"description":356,"extension":357,"faq":358,"howto":374,"image":403,"meta":405,"navigation":406,"path":407,"seo":408,"stem":409,"__hash__":410},"posts_en/en/3.blog/18.eu-ai-act-microsoft-copilot-smes-august-2026.md","EU AI Act – What German SMEs must document for Microsoft Copilot by 2 August 2026",[55],{"name":56,"to":57,"avatar":58},"europioneer Team","/",{"src":59},"/favicon.svg",{"label":61},"AI Act",{"type":63,"value":64,"toc":344},"minimark",[65,69,102,105,110,117,128,139,143,162,165,187,201,205,208,235,247,251,262,274,278,281,301,309,321,325,328,332],[66,67,53],"h1",{"id":68},"eu-ai-act-what-german-smes-must-document-for-microsoft-copilot-by-2-august-2026",[70,71,72,73,77,78,81,82,85,86,89,90,93,94,97,98,101],"p",{},"In ",[74,75,76],"strong",{},"five weeks"," – on ",[74,79,80],{},"2 August 2026"," – the ",[74,83,84],{},"EU AI Act","'s obligations for ",[74,87,88],{},"general-purpose AI models (GPAI)"," enter into force. Despite the Digital Omnibus postponing other deadlines, this date holds, as do the ",[74,91,92],{},"Article 50 transparency duties",". For every German SME that uses ",[74,95,96],{},"Microsoft Copilot",", ChatGPT Enterprise, or Claude in day-to-day office work, the implication is clear: by the end of July an auditable file must exist. Otherwise, fines of up to ",[74,99,100],{},"EUR 15 million or three percent of annual turnover"," – whichever is higher – become a live risk.",[70,103,104],{},"We work through the situation at the end of June 2026 without drama: what the deadline really covers, why Microsoft Copilot falls directly into scope, which documents must be on hand now, and where sovereign alternatives can measurably reduce the compliance burden.",[106,107,109],"h2",{"id":108},"what-the-eu-ai-act-demands-from-2-august-2026","What the EU AI Act demands from 2 August 2026",[70,111,112,113,116],{},"The EU AI Act has been in force since 1 August 2024 but takes effect in stages. ",[74,114,115],{},"GPAI"," – a model trained so generally that it is usable across many tasks, exactly the model type behind Copilot, ChatGPT, and Claude. Providers of such models acquire four main duties from 2 August 2026: technical documentation, information for downstream providers, a training-data summary, and a copyright policy.",[70,118,119,120,123,124,127],{},"For an SME that only uses Copilot rather than training it, the duties are lighter – but they are not zero. ",[74,121,122],{},"Article 50 transparency"," requires that end users be able to recognise that they are interacting with an AI system or that a piece of content is AI-generated. Synthetic audio, image, video, and text must be marked. The ",[74,125,126],{},"Article 4 AI-literacy duty"," has applied since 2 February 2025 anyway: anyone in the company working with AI must be demonstrably trained.",[70,129,130,131,134,135,138],{},"The Digital Omnibus, adopted by the European Parliament on ",[74,132,133],{},"16 June 2026",", shifts the obligations for ",[74,136,137],{},"high-risk AI under Annex III to 2 December 2027"," and for embedded AI under Annex I to 2 August 2028. GPAI and transparency duties remain untouched.",[106,140,142],{"id":141},"why-microsoft-copilot-is-in-scope-directly","Why Microsoft Copilot is in scope directly",[70,144,145,146,149,150,153,154,157,158,161],{},"Microsoft Copilot is technically based on Azure-OpenAI models – the GPT-4 family – and those fall under the GPAI definition. For its EU-market variant Microsoft itself publishes a ",[74,147,148],{},"Model Card"," and an ",[74,151,152],{},"AI Transparency Note",". That covers ",[74,155,156],{},"Microsoft's"," provider duties, not the ",[74,159,160],{},"user duties"," of the deploying SME.",[70,163,164],{},"Three duties stay with the company that licenses Copilot:",[166,167,168,175,181],"ul",{},[169,170,171,174],"li",{},[74,172,173],{},"Risk classification per use case."," Copilot in Outlook is limited risk. Copilot for candidate pre-screening becomes high-risk under Annex III.",[169,176,177,180],{},[74,178,179],{},"Transparency to data subjects."," Whoever sends an AI-generated email reply must make this recognisable in context.",[169,182,183,186],{},[74,184,185],{},"Oversight and intervention."," A person must be able to override any Copilot output before it becomes binding.",[70,188,189,190,195,196,200],{},"Combine the Copilot risk classification with the ",[191,192,194],"a",{"href":193},"/en/blog/microsoft-copilot-flex-routing","Flex Routing outside the EU Data Boundary"," documented in April 2026 and you reach a double compliance gap: data-protection on one side, AI Act on the other. That is why BSI and supervisory authorities continue to handle Copilot restrictively in public administration – see also ",[191,197,199],{"href":198},"/en/blog/nis2-gdpr-microsoft-paradox","NIS2 and GDPR – the Microsoft paradox",".",[106,202,204],{"id":203},"the-four-block-documentation-what-belongs-in-the-file","The four-block documentation – what belongs in the file",[70,206,207],{},"German supervisory practice condenses the AI Act user duty into four building blocks:",[209,210,211,217,223,229],"ol",{},[169,212,213,216],{},[74,214,215],{},"Use-case inventory"," with risk classification per case.",[169,218,219,222],{},[74,220,221],{},"Data-category inventory"," – which personal and material data each case processes.",[169,224,225,228],{},[74,226,227],{},"Oversight concept"," – who reviews Copilot outputs and how deeply.",[169,230,231,234],{},[74,232,233],{},"Training and conformity records"," – attendance lists, audit logs, annual review.",[70,236,237,238,241,242,246],{},"A 50-person SME realistically needs ",[74,239,240],{},"ten to fifteen working days"," for this four-block file, if the inventories cannot already be derived from the GDPR records of processing activities and ",[191,243,245],{"href":244},"/en/blog/bsi-it-grundschutz-microsoft-365","BSI IT-Grundschutz",". If they can be derived, the effort shrinks to one week. The HowTo section below maps the pragmatic path.",[106,248,250],{"id":249},"special-case-schools-and-public-sector","Special case: schools and public sector",[70,252,253,254,257,258,261],{},"For ",[74,255,256],{},"schools and public bodies"," the picture is tighter. The German Data Protection Conference continues to classify ",[74,259,260],{},"Microsoft 365 in schools"," without additional measures as not legally compliant – the North Rhine-Westphalia commissioner confirmed this again in spring 2026. Adding the AI Act dimension via Copilot multiplies the risk. Concretely: a school authority deploying Copilot in administration potentially processes Article 9 GDPR special-category data – health, religion – via a GPAI model.",[70,263,264,265,269,270,273],{},"Public bodies are also subject to the ",[191,266,268],{"href":267},"/en/blog/cada-eu-tech-sovereignty-package-public-sector-2026","Cloud and AI Development Act",", which since 3 June 2026 prescribes sovereignty tiers for contracting authorities. Microsoft Copilot reaches ",[74,271,272],{},"CADA tier 1"," in its EU-standard configuration. Tier 3 requires European ownership and is structurally unattainable with Copilot. Schools and municipal administrations that tender for CADA tier 3 must therefore switch to sovereign LLM endpoints.",[106,275,277],{"id":276},"sovereign-alternatives-that-reduce-user-duties","Sovereign alternatives that reduce user duties",[70,279,280],{},"Anyone using the 2 August 2026 deadline to reorder their AI portfolio has three realistic sovereign options in summer 2026:",[166,282,283,289,295],{},[169,284,285,288],{},[74,286,287],{},"Aleph Alpha Luminous"," – German provider, hosted in Heidelberg. EU ownership, no US sub-processor. Suitable for administrative and contract text.",[169,290,291,294],{},[74,292,293],{},"Mistral Large 2"," – French provider, hosted at OVHcloud or STACKIT. Comparable quality to GPT-4, much stricter data residency.",[169,296,297,300],{},[74,298,299],{},"EuroLLM"," – open-weight model from TU Munich and the Mistral consortium, self-hostable on Hetzner or via a managed hoster. Noticeably cheaper than closed-source models but higher configuration effort.",[70,302,303,304,308],{},"Combined with a sovereign office stack – see ",[191,305,307],{"href":306},"/en/blog/microsoft-teams-alternative","Microsoft Teams alternative – Element/Matrix"," or the openDesk components – the AI Act user duty falls back to what is strictly necessary. The four-block file still has to be kept, but risk classification routinely lands in \"limited risk\" and the sovereignty discussion disappears entirely.",[70,310,311,312,316,317,320],{},"We help SMEs, school authorities, and public bodies make exactly this reordering – from use-case inventory through to productive migration. ",[191,313,315],{"href":314},"/en/contact","Get in touch"," if the file should be in place by the end of July, and see ",[191,318,319],{"href":319},"/en/alternativen"," for the European LLM and office building blocks we operate.",[106,322,324],{"id":323},"in-ten-days-to-an-ai-act-ready-copilot-file","In ten days to an AI-Act-ready Copilot file",[70,326,327],{},"The HowTo section in the frontmatter of this post lists a concrete ten-day path. Starting on 1 July 2026 gets the file in place by 15 July with two weeks of buffer until the deadline. Starting at the end of July is too late. The Article 4 training duty is the bottleneck because it needs a dated attendance list that cannot be backdated.",[106,329,331],{"id":330},"bottom-line","Bottom line",[70,333,334,335,338,339,343],{},"2 August 2026 is not a doomsday but it is not free either. Whoever uses Microsoft Copilot needs a four-block documentation, a transparency practice, and a training record. Whoever is already considering sovereign alternatives – because of ",[191,336,337],{"href":267},"CADA",", ",[191,340,342],{"href":341},"/en/blog/dora-microsoft-365-exit-strategy-banks-2026","DORA",", school-authority oversight, or simply a sovereignty strategy – now has the right occasion to reorder for the next five weeks. Both paths are doable. Both want a decision now.",{"title":345,"searchDepth":346,"depth":346,"links":347},"",2,[348,349,350,351,352,353,354],{"id":108,"depth":346,"text":109},{"id":141,"depth":346,"text":142},{"id":203,"depth":346,"text":204},{"id":249,"depth":346,"text":250},{"id":276,"depth":346,"text":277},{"id":323,"depth":346,"text":324},{"id":330,"depth":346,"text":331},"2026-06-30T00:00:00.000Z","On 2 August 2026 the EU AI Act's GPAI obligations kick in. What SMEs must now document for Microsoft Copilot and which sovereign alternatives hold up.","md",[359,362,365,368,371],{"q":360,"a":361},"What concretely happens on 2 August 2026 under the EU AI Act?","On 2 August 2026 the obligations for general-purpose AI models (GPAI) and the transparency duties of Article 50 of the EU AI Act enter into force. GPAI models are universal AI systems such as GPT-4, Claude, or the Azure-OpenAI models behind Microsoft Copilot. Providers of such models must hold technical documentation, a training-data summary, and a copyright policy from that date. Companies that integrate these models into their own workflows fall under Article 50 and must transparently inform end users that they are interacting with an AI system or that content is AI-generated.",{"q":363,"a":364},"Wasn't 2 August 2026 postponed by the Digital Omnibus?","No. The Digital Omnibus, politically agreed in May 2026 and adopted by the European Parliament on 16 June 2026, shifts the obligations for high-risk AI under Annex III to 2 December 2027 and for embedded AI under Annex I to 2 August 2028. GPAI obligations and the Article 50 transparency duties remain at 2 August 2026 unchanged. The AI-literacy duty under Article 4 has applied since 2 February 2025 anyway and was also not postponed.",{"q":366,"a":367},"Does Microsoft Copilot in a German SME automatically count as high-risk?","Not per se. Copilot as a generic office tool is by default \"limited risk\" and therefore only subject to transparency duties. The deployment context determines the classification. As soon as Copilot is embedded into a high-risk workflow – candidate pre-screening, employee evaluation, credit-worthiness assessment, or procurement preparation in public administration – the entire use case becomes high-risk, and the stricter Annex III duties apply from 2 December 2027. For Copilot in general office use, the four-block documentation is usually sufficient.",{"q":369,"a":370},"What penalties apply for breaches of the GPAI obligations?","The EU regulation provides for fines up to EUR 15 million or three percent of worldwide group turnover – whichever is higher. For most German SMEs the three-percent threshold is the binding one. The Federal Network Agency and the BSI are jointly the competent authorities in Germany. Enforcement targets the GPAI provider first – Microsoft, OpenAI, Anthropic – but the deploying SME is itself liable for its own transparency and documentation duties.",{"q":372,"a":373},"Does the existing Microsoft Data Processing Agreement cover the AI Act duties?","No. The DPA covers GDPR aspects, not AI Act duties. Microsoft does publish an AI Transparency Note for Copilot and provides a GPAI model summary, but the duty to maintain an internal risk classification per use case, a data-category inventory, an oversight concept, and conformity records sits with the deploying company. This four-block documentation is non-delegable.",{"name":375,"description":376,"totalTime":377,"steps":378},"From zero to AI-Act-ready Copilot file in ten days","A pragmatic path for a 30- to 250-person SME to reach 2 August 2026 without enforcement risk.","P10D",[379,382,385,388,391,394,397,400],{"name":380,"text":381},"Inventory the use cases","On days 1 and 2 build a simple table that records every Copilot use in the company by use case, data category, and end user. Typical cases are Outlook reply suggestions, Word summaries, Teams meeting notes, Excel analysis, SharePoint search. Each case gets an ID and an owner.",{"name":383,"text":384},"Classify the risk per use case","On day 3 sort each use case into AI Act risk classes – limited, high, minimal. Candidate sorting or performance review is high-risk; general writing assistance is limited risk. The classification decides which obligations apply. The table is the primary evidence in an audit.",{"name":386,"text":387},"Build the data-category inventory","On day 4 document which data categories Copilot processes per use case – personal data, trade secrets, health data, or special categories under Article 9 GDPR. With Article 9 data, Copilot is effectively only usable with tenant isolation and Customer Lockbox – otherwise abstention is the clean choice.",{"name":389,"text":390},"Install transparency notices","On days 5 and 6 ensure that end users and external recipients can recognise when content is AI-generated or AI-assisted. This applies to outbound email as well as proposals, reports, and automated customer replies. A standard footer, a privacy-notice supplement, and a short company-wide email cover most use cases.",{"name":392,"text":393},"Document the oversight concept","On day 7 write a two-page oversight concept. Who reviews Copilot outputs in which workflows? For recruiting, four-eyes mandatory. For office use, employee responsibility with managerial spot checks. The concept is signed off by management and reviewed annually.",{"name":395,"text":396},"Evidence the workforce training","On day 8 satisfy the AI-literacy duty under Article 4 of the EU AI Act. A 45-minute online course per employee is sufficient in an SME context. The dated attendance list matters, because it is what an audit will request. Content-wise, fundamentals on hallucination, data protection, and risk awareness are enough.",{"name":398,"text":399},"Record a sovereign fallback option","On day 9 embed in your strategy when the company falls back to a sovereign LLM endpoint – Aleph Alpha, Mistral, EuroLLM at a European provider. Concretely for contract-law workflows, administrative procedures, and personnel decisions. The fallback clause is relevant when a contracting authority demands CADA sovereignty tier 3.",{"name":401,"text":402},"Close and file the audit binder","On day 10 merge the table, the data-category inventory, the oversight concept, the training attendance list, the transparency notices, and the fallback strategy into a single PDF binder. File it under a clear version ID in your DMS. In an authority request or audit, this binder is exactly what is requested – no more, no less.",{"src":404},"https://images.unsplash.com/photo-1620712943543-bcc4688e7485?w=1200&q=80",{},true,"/en/blog/eu-ai-act-microsoft-copilot-smes-august-2026",{"title":53,"description":356},"en/3.blog/18.eu-ai-act-microsoft-copilot-smes-august-2026","j3UBPNZPC6Z3Ndn19Ysm081yFr3MZZw7nUVZJNeDk0o",[412,417],{"title":413,"path":414,"stem":415,"description":416,"children":-1},"Operation Sovereignty – What the Bundestag's Microsoft Exit Teaches SMEs, Schools and Public Bodies","/en/blog/bundestag-operation-sovereignty-microsoft-exit-2026","en/3.blog/17.bundestag-operation-sovereignty-microsoft-exit-2026","In May 2026 the German Bundestag approved an IT strategy to exit Microsoft 365. Five pillars, the Phoenix Suite, Wire – what SMEs can copy from it now.",{"title":418,"path":419,"stem":420,"description":421,"children":-1},"Cyber Resilience Act – What German SMEs and public bodies must demand from Microsoft and their software suppliers from 11 September 2026","/en/blog/cyber-resilience-act-september-2026-microsoft-smes-public-sector","en/3.blog/19.cyber-resilience-act-september-2026-microsoft-smes-public-sector","On 11 September 2026 the CRA reporting obligations kick in. What German SMEs, school authorities, and public bodies must now lock into contracts and where Microsoft cannot structurally deliver.",1784618209835]