The EU AI Act for SMEs: What You Need to Know
The AI Act is not just for tech companies and multinationals — as an SME that uses AI tools, you are already subject to new obligations.
Updated: July 2026
Revised after the Digital Omnibus agreement. On 19 November 2025 the European Commission proposed a 'Digital Omnibus on AI'; the European Parliament voted in favour on 16 June 2026 and the Council gave its final green light on 29 June 2026. The deal postpones the heaviest high-risk obligations to late 2027 — but, crucially, for most businesses the AI Act is not delayed: the transparency obligations (Article 50) and the enforcement of general-purpose AI models still apply from 2 August 2026, and the AI-literacy obligation has applied since February 2025. The timeline below has been updated accordingly.
What Is the AI Act?
The AI Act (officially: EU Regulation 2024/1689) is the first comprehensive European law regulating the use of artificial intelligence. The regulation entered into force on 1 August 2024 and — like the GDPR — applies directly in all EU member states without requiring national transposition.
Its aim is twofold: to protect citizens from high-risk AI applications, while leaving room for innovation through a clear and predictable framework. To achieve this, the legislator chose a risk-based approach: the higher the potential risk, the heavier the obligations.
The AI Act takes effect in phases. Not all obligations apply immediately — some are already active, while others will become binding during 2025, 2026, 2027, and 2028. That makes it straightforward to look at what is already in play and what is coming, step by step.
Disclaimer: this article provides an informational overview and does not constitute legal advice. For guidance on how the AI Act applies to your specific situation, consult a lawyer or compliance specialist.
The Risk-Based Approach: Four Tiers
The AI Act classifies AI systems into four risk categories. Which category applies determines which obligations you face. Here is a concise overview.
Prohibited AI Practices
Certain AI applications are outright banned in the EU — systems that pose an unacceptable threat to fundamental rights or human dignity.
- Social scoring systems operated by public authorities based on behaviour.
- Real-time remote biometric identification in publicly accessible spaces (with narrow exceptions for law enforcement).
- AI that manipulates behaviour subconsciously or exploits vulnerable groups.
- Untargeted scraping of facial images to build recognition databases.
High-Risk AI Systems
High-risk systems are permitted, but carry heavy requirements: conformity assessment, registration in an EU database, technical documentation, a risk-management system, and mandatory human oversight. This applies to AI used in sectors such as medical devices, biometric identification, critical infrastructure, education, and HR.
- Recruitment screening and CV evaluation via AI.
- AI systems used in credit scoring or insurance underwriting.
- AI in courts, border control, or policing.
- Medical diagnosis or treatment support systems.
Limited Risk: Transparency Obligations
AI systems in this tier face lighter obligations, primarily around transparency. Users must know they are interacting with AI.
- Chatbots and virtual assistants: disclose that the user is talking to AI.
- Deepfake images or videos: label them as AI-generated.
- Emotion-recognition systems: inform the people concerned.
Minimal Risk
The vast majority of AI applications fall here: spam filters, AI-powered search, product recommendations, grammar tools. No specific AI Act obligations apply, though other laws (GDPR, sector regulation) continue to apply.
What Is Already in Effect — and What Is Coming?
The AI Act has a phased implementation schedule. Here is the timeline at a glance — including the postponement introduced by the Digital Omnibus.
Since February 2025: Prohibited Practices and AI Literacy
Since 2 February 2025, the prohibited AI practices are enforceable. Anyone using or offering a banned application risks a sanction. At the same time, Article 4 of the AI Act already applies: the AI-literacy obligation.
Article 4 requires organisations — both providers and deployers of AI systems — to ensure that staff who work with AI have sufficient knowledge and skills to understand AI systems and use them responsibly. The law does not prescribe a specific certificate, but 'adequate AI literacy' must be demonstrable. An internal AI policy backed by training is the practical way to meet this requirement.
2 August 2026: Transparency, General-Purpose AI Models, and Oversight
On 2 August 2026 a significant part of the AI Act becomes genuinely enforceable — and this was not postponed by the Digital Omnibus. From that date the transparency obligations under Article 50 apply: you must let users know when they are interacting with AI and label AI-generated content (such as deepfakes) as such. A transitional deadline of 2 December 2026 applies to the technical watermarking requirement.
At the same time, regulators gain teeth: enforcement and the power to impose fines on providers of general-purpose AI (GPAI) models come into force, with fines of up to 15 million euros or 3% of worldwide annual turnover. National market-surveillance authorities also activate from this date. For most SMEs this mainly means one thing: make sure your AI chatbot and any AI-generated content are clearly recognisable.
Postponed to Late 2027 and 2028: The High-Risk Obligations
This is the biggest change introduced by the Digital Omnibus. The heavy obligations for high-risk AI systems were originally due to apply from 2 August 2026, but have been postponed. Standalone high-risk systems (Annex III — think of AI for recruitment screening, credit assessment, or education) now only need to meet the requirements from 2 December 2027.
For high-risk AI embedded in regulated products (Annex I — for example machinery or medical devices), the deadline moves to 2 August 2028. The postponement gives providers and regulators more time to finalise the accompanying standards and conformity assessments. Treat it as breathing room, not cancellation — and it mainly affects providers, not the average SME user.
What Does the AI Act Mean in Practice for Your SME?
I often hear directors assume the AI Act only applies to tech companies or large platforms. That is a misconception. The AI Act applies to everyone who provides or uses AI systems in the EU — including an SME that uses ChatGPT, Copilot, or an AI recruitment tool.
The good news: most SMEs are deployers (users) of AI systems, not providers (developers). That means a lighter regime. And most tools you use day-to-day — text generators, AI-powered search, email assistants — fall into the limited or minimal risk categories. The heavy high-risk obligations rarely apply directly to most SMEs.
What does apply:
- Prohibited practices: check whether you use AI anywhere for social scoring, manipulative systems, or real-time biometric identification. Probably not — but be certain.
- AI-literacy obligation (Art. 4): ensure staff who work with AI understand the basics. This is already in force.
- Transparency for chatbots: if you have an AI chatbot on your website, this must be visible to users.
- High-risk check: do you use AI for recruitment screening, credit assessment, or medical support? Stricter requirements apply — potentially handled via the provider who carries out the conformity assessment.
- Supplier check: if you procure high-risk AI, the provider must supply conformity documentation. Ask for it.
A Practical Action Plan to Become Compliant
You do not need to have everything in order all at once. Here is a workable sequence I recommend.
- Step 1 — Take stock of your AI use: which tools are in use, by whom, and for what purposes? This gives you an AI inventory that also serves as the foundation for your AI policy.
- Step 2 — Determine the risk category for each application: use the four tiers as your guide. Most tools are minimal or limited risk. Note the exceptions.
- Step 3 — Address AI literacy: Article 4 is already in force. Run an awareness session, put an internal AI policy in place, and designate a point of contact.
- Step 4 — Check suppliers for high-risk AI: ask your AI vendors whether their systems are classified as high-risk and what conformity documentation is available.
- Step 5 — Draft an AI policy: document which tools are approved, how personal data is handled, and how human oversight is organised. Align this with your GDPR policy.
- Step 6 — Schedule an annual review: the AI Act evolves and implementing acts will follow. Set a recurring moment each year to test your compliance.
Common Misconceptions About the AI Act
Quite a few misunderstandings are circulating about the AI Act. The ones I encounter most often:
- "The AI Act only kicks in a few years from now." Incorrect: the prohibited practices and the AI-literacy obligation have been in force since February 2025, and the transparency obligations and oversight of general-purpose AI models follow on 2 August 2026. Only the heavy high-risk obligations have been postponed — to late 2027 — via the Digital Omnibus.
- "We don't build AI ourselves, so it doesn't affect us." Incorrect: the law also applies to deployers — companies that use AI systems built by third parties.
- "Only tech companies need to do something." Incorrect: the AI Act cuts across every sector. An HR system, a credit check tool, or an AI chatbot on your website can already bring you into scope.
- "We'll wait for our supplier to sort it out." Partly true for conformity documentation — but the AI-literacy obligation and the ban on prohibited practices rest with you as the user.
- "Fines are only for large companies." The AI Act sets graduated fines based on the infringement, not exclusively on company size — though regulators are likely to enforce proportionately.
- "Using ChatGPT is high risk." No: a text generator is minimal or limited risk. High risk is context-dependent — it is about the purpose for which you deploy AI, not the tool itself.
Key takeaways
- The AI Act (EU 2024/1689) has been in force since August 2024 and is being phased in; under the Digital Omnibus agreement (2026), the high-risk obligations move to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
- Prohibited AI practices and the AI-literacy obligation (Art. 4) have been in force since February 2025.
- On 2 August 2026 the transparency obligation (Art. 50) and enforcement of general-purpose AI (GPAI) models do take effect — that part was not postponed.
- Most SMEs are deployers of limited or minimal risk AI — the heavy high-risk obligations rarely apply to them directly.
- The AI-literacy obligation is already in force: make sure staff who work with AI understand the basics.
- Start with an AI inventory, determine the risk category of your applications, and put an internal AI policy in place.
Tackle Your AI Strategy and Governance Together?
In the boardroom workshop, we spend one day building a concrete AI strategy for your organisation — including the conditions, roles, and first steps for working AI governance aligned with the AI Act.
View the Boardroom Workshop