AI Helpdesk

Frequently Asked Questions About AI

AI offers great potential—for businesses as well as for public sector organizations. Yet many SMEs and PSOs face the same questions: What exactly can AI do for my business or my organization? How do I go about implementing it? And what does the EU AI Act mean for me?

The EDIH-AICS AI Helpdesk answers the most frequently asked questions on these topics—in a neutral, easy-to-understand way that requires no prior knowledge.

General

What is EDIH-AICS, and who is behind it?

The EDIH-AICS (European Digital Innovation Hub Artificial Intelligence & Cybersecurity) is an EU-cofunded hub that supports SMEs, public institutions, and research organizations in the secure and responsible use of artificial intelligence and cybersecurity solutions.

The hub brings together expertise from universities, research institutes, the private sector, and public administration, and offers impartial access to technology, knowledge, and funding.

Last update on 24.06.2026 by Samira Dahl.

What specific services does EDIH-AICS offer?

Many basic services—including initial consultations, orientation sessions, and select workshops—are free or heavily subsidized for SMEs and public institutions, as the hub is co-financed by EU and national funds.

For more extensive projects, customized pilot implementations, or longer-term support programs, participants may be required to cover a partial amount of the costs. The exact terms will be discussed transparently during the initial consultation.

Last update on 24.06.2026 by Samira Dahl.

How can my organization benefit from EDIH-AICS?

Getting started is easy:

  • Contact us via the web form or by email
  • Free initial consultation to assess your needs (approx. 60 minutes)
  • Recommendations for suitable services and funding opportunities
  • Support for pilot projects, training, or networking
  • We work with organizations of all sizes—from 5-person businesses to federal agencies.

Last update on 24.06.2026 by Samira Dahl.

Artificial Intelligence

Where can I get help with implementing AI in a company?

Where to start when using AI-based solutions naturally depends very much on one’s level of experience. In general, however, a phased approach has proven effective—one in which you don’t tackle the full complexity of a potential solution right away, but instead proceed step by step. The EDIH-AICS “test-before-invest” program is well-suited for this. Through it, an SME can work with experts from the EDIH-AICS community to explore a potential AI application step by step. During an “Inspiration Tour,” exemplary solutions can be presented in detail (such as at the FZI House of Living Labs, SmartEast, the Karlsruhe Research Factory, or the KIT Energy Lab) and then adapted to the specific challenges of an SME in initial feasibility experiments.

Ultimately, a well-thought-out and methodical approach will be essential. Further information can be found here.

Last update on 01.07.2026 by Samira Dahl.

What should I keep in mind when designing AI applications in my organization?

A key factor in the successful implementation of AI systems in organizations is the principles of human-centered design:

  • Participatory AI design is crucial for tailoring the solution to the needs of users and other stakeholders.
  • AI solutions often act as a black box. Transparency and explainability are therefore important principles of trustworthy design.
  • Depending on the quality of the training data and potential implicit biases, AI systems can produce unfair results. Fairness and equity are therefore important fundamental
  • principles for preventing people from losing trust in an AI system.
  • Users should be able to monitor and correct AI decision recommendations, as AI systems can make suboptimal decisions. Decision-making authority and responsibility should therefore always remain with humans.

The following points should be considered before introducing AI into an organization:

  • IT infrastructure
  • Data availability and data quality
  • Employee expertise
  • Organizational structure and organizational adaptation

Last update on 01.07.2026 by Samira Dahl.

How can I ensure that AI does not share sensitive data?

The key is to ensure a contractual and technical separation between data processing and model training:

  • Choose providers who provide a written guarantee that input data will not be used for model training
  • Consider on-premises or private cloud options for data requiring special protection
  • Implement internal guidelines specifying which data may be entered into AI tools
  • Pseudonymize or anonymize data wherever possible

Last update on 01.07.2026 by Samira Dahl.

Which AI applications are particularly relevant for public administration?

Government agencies benefit most from AI in the following areas:

  • Document processing: automatic classification, extraction, and forwarding of applications
  • Citizen services: AI-powered information systems and chatbots for standard inquiries
  • Fraud detection: pattern recognition for benefit fraud or suspicious transactions
  • Language processing: automatic transcription and translation

According to the EU AI Act, decisions with legal consequences (notices, rejections) may not be made fully automatically by AI—human oversight is mandatory.

Last update on 01.07.2026 by Samira Dahl.

As an SME, how do I get started with AI without my own IT staff?

The best way to get started is with preconfigured AI services that don’t require your own infrastructure. Start with a narrowly defined use case—such as automated document processing or customer communication.

  • Take advantage of free trial periods before investing in licenses
  • Involve employees early on to promote acceptance
  • Define quality criteria: When is the AI result good enough?
  • EDIH-AICS offers initial AI assessments specifically for SMEs without an IT department

Last update on 01.07.2026 by Samira Dahl.

Cybersecurity

What should we do if our organization falls victim to a cyberattack?

Follow a clear step-by-step plan:

  • Immediate action: Disconnect affected systems from the network (do not shut them down)
  • Notify the IT emergency contact or external service provider
  • Contact the BSI reporting center (mandatory for KRITIS and NIS2-regulated entities)
  • Notify the data protection authority if personal data is affected (72-hour deadline under the GDPR)
  • File a criminal complaint with the cybercrime division of the relevant State Criminal Police Office (LKA)

Keep printed copies of emergency contacts stored separately from IT systems—in an emergency, these may not be accessible.

Last update on 29.06.2026 by Samira Dahl.

What are the minimum IT security requirements for a government agency?

Public institutions are subject to different framework requirements depending on their level and size:

  • BSI IT-Grundschutz: mandatory for federal agencies; recommended for state and local governments
  • NIS2 Directive (transposed into national law as of October 2024): applies to public administrations above certain thresholds
  • Minimum technical measures: MFA, patch management, encrypted communication, regular backups
  • Organizational measures: emergency plan, security officer, awareness training

The EDIH-AICS offers free security assessments for public institutions. Please feel free to contact us.

.

Last update on 29.06.2026 by Samira Dahl.

What are the most pressing cyber risks for small and medium-sized enterprises?

According to the BSI situation report, these are the most common attack vectors for SMEs:

  • Ransomware: Data encryption accompanied by a ransom demand — often delivered via email attachments
  • Phishing: Deceptively authentic emails designed to trick users into revealing login credentials or making payments
  • Unpatched software: known vulnerabilities that were not patched in a timely manner
  • Weak or reused passwords without multi-factor authentication

Over 80% of all attacks exploit human error as a point of entry. Employee training is often more effective than individual technical measures.

Last update on 29.06.2026 by Samira Dahl.

Cross-cutting themes

What funding is available for AI and cybersecurity projects?

There are various EU and national funding programs:

  • DIGITAL Europe Program (DIGITAL): Digitalization, AI, cybersecurity — accessible through EDIHs, among other channels
  • Horizon Europe: Research and innovation projects, including for SMEs through the EIC and KDT JU
  • Federal funding programs: Central Innovation Program for SMEs (ZIM), AI transfer projects of the BMBF
  • State programs: Different digitization funding options depending on the federal state

The EDIH-AICS provides free advice on suitable funding programs: You can find further initial information in our Investment Guidelines or from our AI funding superhero, Edda.

Last update on 29.06.2026 by Samira Dahl.

Can we use AI tools in a way that complies with the GDPR?

Yes, subject to the following conditions:

  • Enter into a Data Processing Agreement (DPA) with the AI provider in accordance with Article 28 of the GDPR
  • Ensure that data processing takes place within the EU/EEA or in an appropriate third country
  • Document the use of AI in the record of processing activities
  • Inform data subjects in the privacy policy

Conduct a data protection impact assessment (DPIA) if necessary.

Last update on 29.06.2026 by Samira Dahl.

How is AI changing the cyber threat landscape?

AI acts as an amplifier on both sides:

  • Attackers use AI to create more credible phishing emails (no more spelling mistakes), convincing deepfakes, and automated vulnerability scanning
  • Defenders benefit from AI-powered anomaly detection, faster threat analysis, and automated responses

Train employees to check senders and communication patterns—not just content. Classic telltale signs like spelling errors are absent in AI-generated attacks.

Last update on 29.06.2026 by Samira Dahl.

EU AI Act

What penalties apply for violations of the EU AI Act?

The EU AI Act provides for substantial fines, scaled according to the severity of the violation:

  • Up to €35 million or 7% of global annual revenue for prohibited AI practices
  • Up to €15 million or 3% for violations of other obligations
  • Up to €7.5 million or 1.5% for providing false information to authorities

For SMEs and startups, the competent authorities may impose lower fines on a case-by-case basis.

Supervisory authorities will be designated in each Member State. In Germany, the jurisdiction is still being clarified—the BSI is likely to play a central role.

Last update on 29.06.2026 by Samira Dahl.

When will the provisions of the EU AI Act take effect?

The AI Act will come into effect in phases:

  • February 2025: Prohibitions on unacceptable risks take effect
  • August 2025: Regulations for general-purpose AI models (GPAI, e.g., large language models)
  • August 2026: Full applicability of all regulations, including high-risk AI
  • August 2027: Transition periods for certain high-risk AI systems expire

Take action now: EDIH-AICS supports you in achieving AI Act compliance.

Last update on 01.07.2026 by Samira Dahl.

What are my obligations as the operator of a high-risk AI system?

Operators (so-called “deployers”) of high-risk AI systems must:

  • Review and retain the provider’s technical documentation and declaration of conformityUse systems only in accordance with their intended purpose
  • Ensure human oversight—AI decisions must be verifiable and revisable
  • Conduct a data protection impact assessment (DPIA) if personal data is processed
  • Inform data subjects about the use of AI
  • Report incidents and malfunctions to the provider and, if necessary, to the supervisory authority

There are no general exemptions for SMEs and public institutions—but simplified procedures do apply for certain conformity assessments.

Last update on 01.07.2026 by Samira Dahl.

What risk classes does the EU AI Act define?

The AI Act classifies AI systems according to their risk potential:

  • Prohibited: Social scoring by government agencies, mass biometric surveillance, and manipulative systems that exploit human weaknesses
  • High-risk AI in critical infrastructure, education, human resources, law enforcement, immigration, the judiciary, and the allocation of social benefits — strict requirements, conformity assessment, registration
  • Limited Risk: Chatbots, deepfake generators — transparency requirements toward users
  • Minimal Risk: Spam filters, AI in games — no additional requirements

Which category applies to your AI application? You can find more detailed information and an initial classification of your AI application at the Federal Network Agency’s AI Service Desk.

Last update on 01.07.2026 by Samira Dahl.

What is the EU AI Act, and who does it affect?

The EU AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive regulatory framework for artificial intelligence. It has been in effect since August 2024 and will become fully applicable in phases by August 2026.

It applies to all organizations that develop, distribute, or use AI systems in the EU—regardless of whether they are based in the EU:

  • SMEs that use or develop AI applications
  • Public authorities that use AI for decision-making
  • Research institutions (with exceptions for pure research)

Even those who merely purchase and use AI software (without developing it) may fall under the AI Act as “operators” and must comply with the relevant obligations.

Last update on 01.07.2026 by Samira Dahl.

You still have a question?

Feel free to contact us!

The personal data you provide will be stored exclusively for the purpose of responding to your inquiry. Further information can be found in our privacy policy.