From AI Experimentation to Operational Readiness Transparency, Cyber Resilience and Investment for SMEs
In recent years, artificial intelligence, connected equipment and Industry 4.0 have primarily been presented as opportunities to improve productivity. In August 2026, however, the technological transition is entering a new phase: some requirements are already applicable, others will take effect within weeks, and access to funding increasingly depends on a company’s technological and organisational readiness.
The new transparency requirements under the European Artificial Intelligence Act became applicable on 2 August. From 11 September, manufacturers of products with digital elements will be required to report actively exploited vulnerabilities and severe incidents under the Cyber Resilience Act.
At the same time, the European Union has launched a call to establish up to seven AI gigafactories, while a new fund for strategic technologies and defence is being prepared in Bulgaria. The budget of the Industry 4.0 funding procedure has been increased, enabling another 286 companies to receive support. Funding for implementing innovations also remains available to some businesses operating in territories covered by Local Action Groups.
The overall direction is clear: technological investment can no longer be considered separately from transparency, cybersecurity, data governance and evidence of practical results.
Transparency in the use of AI is now a current obligation
The new transparency requirements under the European Artificial Intelligence Act became applicable on 2 August 2026. The European Commission and the competent national authorities are also beginning more active enforcement of the Regulation. The information was published by the European Commission on 31 July.
The new rules apply to specific categories of systems and content. The main requirements include:
- users must be informed when they are interacting with a chatbot or another AI system rather than a person;
- images, audio and video constituting so-called deepfake content must be disclosed;
- content generated or manipulated using AI must contain appropriate machine-readable markings;
- individuals must be informed when emotion-recognition or biometric-categorisation systems are being used;
- AI-generated text concerning matters of public interest must be disclosed when published without human review or editorial responsibility.
This does not mean that every use of artificial intelligence necessarily requires a visible label. The relevant factors include the type of system, the company’s role, the intended purpose of the content, and whether genuine human and editorial oversight is in place.
For most SMEs, the first necessary step is a brief internal review of their public-facing AI applications:
- Does the company’s website feature a chatbot or automated virtual assistant?
- Is AI used to create or substantially modify images, video or audio?
- Is automatically generated content published without being reviewed by a specifically designated person?
- Are systems used to analyse faces, voices, emotions or biometric characteristics?
- Does the provider of the AI system supply the necessary machine-readable markings and compliance information?
- Can the company demonstrate who reviewed and approved the published content?
A practical approach is to introduce a concise policy defining permitted AI applications, the required level of human review, and the cases in which a disclosure must be added. In this way, transparency becomes part of the company’s normal processes for publishing content, serving customers and approving materials.
Cyber resilience is moving from a general principle to specific reporting obligations
The next important deadline is 11 September 2026. From that date, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents affecting the security of their products.
An early warning must be submitted within 24 hours of becoming aware of the incident, followed by a full notification within 72 hours. In the case of an actively exploited vulnerability, a final report must also be submitted no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, the final report must be submitted within one month. Reporting will take place through a single European reporting platform. The European Commission has published an overview of the reporting mechanism and applicable deadlines.
The principal requirements of the Cyber Resilience Act will apply in full from 11 December 2027, but the reporting obligations begin earlier.
On 27 July, the Commission published new practical guidance covering:
- which products and related services fall within the scope of the Regulation;
- what constitutes a substantial modification of an existing product;
- how the support period should be determined;
- how risk assessment and reporting obligations should be fulfilled;
- how remote data-processing solutions and open-source software are treated.
The guidance includes 67 practical examples and has been developed with particular attention to the position of micro, small and medium-sized enterprises. Although it is not legally binding, it provides an important basis for preparation. The full document and its annexes are available on the European Commission’s portal.
These requirements do not apply exclusively to conventional software companies. Their scope may include businesses that market under their own name:
- connected machinery and industrial equipment;
- controllers, sensors and Internet of Things devices;
- embedded software;
- mobile or web applications connected to a physical product;
- remote monitoring and control systems;
- specialised digital solutions integrated into customers’ equipment.
A company that merely uses such a product will not generally have the same reporting obligations as its manufacturer. It should nevertheless know which supplier is responsible for security, how vulnerabilities should be reported, and how it will receive updates and corrective measures.
Before 11 September, potentially affected manufacturers should appoint a responsible person, establish a channel for receiving vulnerability reports, and document a procedure for determining whether an individual case must be reported. With a 24-hour deadline, these responsibilities cannot be clarified only after an incident has occurred.
AI gigafactories represent an infrastructure opportunity, not a conventional grant scheme
On 30 July, the European Union launched a call to establish up to seven AI gigafactories. The initiative is expected to mobilise more than €30 billion in investment, comprising up to €10 billion in European and national public funding and at least €20 billion in private capital.
The gigafactories will combine specialised AI processors, cloud technologies, software, high-speed connectivity and energy-efficient data centres. Their purpose is to provide European infrastructure for training, adapting and deploying advanced AI models. The deadline for the call is 12 November 2026. The European Commission has presented the main parameters of the initiative.
This is not a standard funding procedure through which an individual SME can apply to purchase software or computer equipment. The principal applicants will be large industrial and infrastructure consortia.
Opportunities for small and medium-sized enterprises are more likely to emerge in two areas.
The first is future access to infrastructure for training, running and adapting AI models. This could be important for companies developing solutions for industry, logistics, healthcare, energy, cybersecurity or large-scale data analysis.
The second area is participation in supply chains. Building such centres will require:
- energy and electrical infrastructure;
- cooling and energy-management systems;
- data centres and specialised equipment;
- communications connectivity;
- cybersecurity;
- industrial automation;
- engineering, construction and maintenance services;
- software integration and data management.
For companies in the Ruse region, a more realistic approach would be to identify a specific technological, manufacturing or engineering capability that could be offered to operators and partners participating in future consortia.
Bulgaria is preparing capital for strategic technologies
On 27 July, Bulgaria’s Fund of Funds launched a procedure to select a financial intermediary to manage the new Strategic Technologies and Defence Fund.
The planned public funding amounts to €30.3 million, to which the selected fund manager must add at least 10% in private co-financing. The maximum investment in a single company will be €5 million, with approximately 15 companies expected to receive support. The investment period will continue until the end of 2030.
The fund will target early-stage and growth-stage companies developing:
- digital and deep technologies;
- clean and resource-efficient technologies;
- biotechnology;
- defence technologies and industrial capacity;
- dual-use products and services.
The parameters of the instrument have been published by the Fund of Funds.
An important distinction must be made: the current procedure is intended to select a fund manager and is not a direct application process for companies. Access to investment will begin after the intermediary has been selected and the instrument has been established.
Companies that could potentially fall within the fund’s scope can use this period to prepare:
- a clear description of the technology and its strategic application;
- evidence of technological maturity;
- information about intellectual property;
- a market strategy and potential customers;
- a financial model and the required investment;
- a plan for the use of the funding;
- information about the management team and partnerships;
- an assessment of any applicable restrictions concerning dual-use products.
Equity financing differs from grant funding. The investor will consider not only eligible expenditure but also the company’s growth potential, competitive advantage and realistic prospects of generating a return.
Additional funding for Industry 4.0 does not represent a new application round
The Ministry of Innovation and Growth has provided slightly more than €71 million in additional funding under the procedure for introducing Industry 4.0 technologies. This will enable another 286 small and medium-sized enterprises to receive support.
The total budget of the measure has now reached more than €125 million, while the number of supported companies has increased to 512. A total of 742 project proposals were submitted. The figures have been published by the Ministry of Innovation and Growth.
The increase in the budget does not constitute a new call for project proposals. It is intended to finance additional applicants that have already been evaluated.
The results nevertheless demonstrate strong demand for artificial intelligence, cloud technologies, the Industrial Internet of Things, digital twins, data analytics, automation and cybersecurity solutions.
For the companies receiving support, the next challenge will be successful implementation. The purchase of equipment or software should be accompanied by:
- integration with existing processes;
- clearly defined data ownership and quality standards;
- employee training;
- access management;
- cybersecurity and backup arrangements;
- measurement of productivity before and after the investment;
- a plan for maintenance and further development after the project has ended.
Companies that have not received funding should not abandon the investment case they have already prepared. It can be adapted for a future procedure, financial instrument, leasing arrangement or phased investment using the company’s own resources.
Local funding for innovation requires careful verification of eligibility
The first application period under the procedure “Implementation of Innovations in SMEs in the Territories of Local Action Groups” remains open until 16:30 on 14 September 2026.
The budget is almost €20 million. Grant funding for an individual project ranges from €15,000 to €102,500, with a maximum aid intensity of up to 75% of eligible expenditure.
Funding is available for machinery, equipment, software, patents, utility models, industrial designs and licences required to implement a new or improved product or business process. The conditions and deadlines have been published by the Ministry.
The procedure is not available to all SMEs. Applicants must be located in the territory of a Local Action Group with approved complementary funding under the programme. Territorial and other eligibility conditions must therefore be verified before the project is developed.
Given the approaching deadline, companies that have not yet identified a specific innovation, obtained a technical quotation or secured their co-financing should realistically assess whether they can prepare a high-quality proposal in time. A second application period is scheduled from 14 January to 15 March 2027.
An improved business climate does not eliminate weak industrial demand
Data from Bulgaria’s National Statistical Institute for July show that the overall business climate indicator increased by 0.7 percentage points, from 16.1% to 16.8%. In industry, the indicator rose by 1.1 percentage points to 17.2%.
Behind the overall improvement, however, are more cautious operational signals. Industrial companies report a decline in new orders over the previous three months, while expectations for production activity remain unfavourable. Average capacity utilisation has fallen by 2.4 percentage points since April, reaching 72.9%. The principal constraints continue to be the uncertain economic environment and labour shortages. The full results have been published by the National Statistical Institute.
This combination calls for a more selective approach to technological investment. Before launching a project, a company should answer four questions:
- What specific production, market or organisational problem will the investment solve?
- What measurable effect is expected in terms of costs, capacity, quality, delivery times or sales?
- Does the company have the people, data and processes required for implementation?
- Is the solution aligned with the requirements for transparency, cybersecurity and information protection?
At a time of weaker order volumes, technology should improve the resilience and efficiency of the business rather than merely add another complex asset.
A practical 90-day framework for SMEs
Companies can structure their preparations around six actions:
- Create an inventory of the AI systems being used. Document the purpose, provider, data used, public interaction and responsible person for each solution.
- Review public-facing AI content. Examine chatbots and automatically generated text, images, video and audio, and introduce the necessary disclosures and human oversight.
- Determine whether you offer products with digital elements. If you manufacture connected equipment, software or embedded systems, assess your role and obligations under the Cyber Resilience Act.
- Establish a procedure for vulnerabilities and incidents. Define a reporting channel, responsible persons, a method for assessing individual cases, and arrangements for meeting the 24-hour and 72-hour deadlines.
- Classify your investment project according to its stage of development. Determine whether it is suitable for grant funding, equity investment, a bank loan, leasing or participation in a larger technology consortium.
- Connect the technology to a measurable business outcome. Establish baseline indicators for productivity, quality, energy consumption, delivery times, cyber risk and revenue, against which the impact of the investment can be evaluated.
Conclusion
August 2026 demonstrates that European technology policy is now operating simultaneously through regulation, infrastructure and funding.
AI transparency is already an applicable requirement. Reporting under the Cyber Resilience Act begins on 11 September. AI gigafactories are creating future infrastructure and new supply chains. Bulgarian financial instruments are directing capital towards Industry 4.0, innovation and strategic technologies.
The common denominator is operational readiness. Companies that understand the technologies they use, manage their data and vulnerabilities, maintain appropriate technical documentation and can demonstrate the impact of their investments will be better positioned both to comply with regulatory requirements and to access future funding.
The Ruse Chamber of Commerce and Industry publishes materials of this kind to support companies in the region in assessing new requirements, preparing investment projects and building technological partnerships.
If you would like to discuss the applicability of the AI transparency and cyber-resilience requirements, the preparation of an innovation project, or the positioning of your organisation within emerging technology value chains, please contact me at sminchev@rcci.bg or +359 895 890 123.
Note: This article was prepared with the assistance of generative artificial intelligence, which supported the structuring of the content, verification of sources and drafting process. The final text reflects the author’s expert contribution, ensuring its practical relevance. The information is current as of 3 August 2026 and does not constitute legal or financial advice.