If your company uses ChatGPT, an AI-powered CRM, a chatbot on your website, or an automated CV screening tool, the EU AI Act may create obligations for your organization. The regulation became generally applicable on August 2, 2026, while several provisions started earlier and some high-risk rules follow a later timetable.
Most small and medium businesses we talk to fall into one of two camps: those who have never heard of it, and those who assume it only applies to big tech companies. Both assumptions are risky. The AI Act applies according to the organization’s role and the system’s use and risk level, not simply the size of the business.
This is an operational playbook, not another deadline recap. It explains how to identify your role, classify each use, question suppliers and assemble the evidence an SME should be able to produce. For a concise account of what changed on the August 2026 application date, read the separate AI Act deadline update.
The SME answer in one paragraph: inventory every AI-enabled system, record its purpose, supplier, data and affected people, identify whether you are a provider or deployer, then classify the use by risk. Address prohibited practices and Article 50 transparency immediately. Build evidence now for any high-risk use, even though the AI Omnibus moved the main Annex III rules to 2 December 2027 and product-embedded rules to 2 August 2028.
The AI Act in brief
The EU AI Act (Regulation 2024/1689) is the world’s first comprehensive legal framework for artificial intelligence. Adopted in 2024, it is being phased in between 2025 and 2027.
Its core principle is a risk-based classification. The higher the potential impact of an AI system on people’s fundamental rights, health, or safety, the stricter the obligations. This is a pragmatic approach: a spell checker and an automated hiring tool are not treated the same way.
Four risk levels
Unacceptable risk: banned outright. This includes subliminal manipulation, social scoring by public authorities, emotion recognition in workplaces and schools (with narrow exceptions), real-time biometric identification in public spaces, and untargeted facial image scraping. These have been prohibited since February 2025.
High risk: allowed but heavily regulated. AI systems that significantly affect people’s lives fall here. The regulation lists eight domains in Annex III: biometrics, critical infrastructure, education, employment and HR, access to essential services (credit scoring, insurance), law enforcement, migration, and administration of justice. For most SMEs, the relevant ones are automated CV screening, employee performance evaluation, and client creditworthiness scoring.
Limited risk: transparency obligations. Systems that interact with people must disclose their nature. A chatbot must tell users they are talking to an AI. AI-generated content (text, images, video) must be identifiable as such, particularly deepfakes.
Minimal risk: no specific obligations. The vast majority of everyday AI tools (translation, spell checking, search, content drafting assistants) fall here. No legal requirements, though the regulation encourages voluntary codes of conduct.
Are you affected?
Almost certainly yes, if you use any AI tool professionally. The key question is your role.
Provider vs. deployer
The AI Act distinguishes four roles: provider, deployer, importer, and distributor. The one that matters for most SMEs is deployer: you use AI systems developed by someone else in a professional context.
You are a deployer if you use ChatGPT or Claude to draft communications, run a CRM with predictive scoring, deploy a chatbot through a SaaS platform, or use HR software with automated screening. The overwhelming majority of European SMEs are deployers.
You are a provider if you develop an AI system and place it on the market, for example building a custom chatbot product for your clients or creating a scoring tool you sell as a service.
One important nuance: a deployer can become a provider by substantially modifying the intended purpose of a system. Using a product recommendation engine to assess creditworthiness, for instance, would shift your role, and your obligations.
The deployer misconception
Many businesses assume that being “just a user” means they have no obligations. This is incorrect. Deployers have real operational responsibilities, especially when the AI system impacts employees or customers. The obligations are lighter than those of providers, but they exist and are enforceable.
Concrete obligations for deployers
What the AI Act actually requires depends on the risk level of the systems you use.
Obligations that apply to everyone
AI literacy. The original Article 4 duty applied from February 2025. The AI Omnibus, which entered into force on July 27, 2026, replaced that company-level obligation with non-binding encouragement and gave the Commission and Member States a stronger role in promoting AI literacy. Training still remains one of the clearest ways to demonstrate competent oversight, reduce misuse and prepare teams for regulated workflows, but this guide does not present it as a standalone binding duty after the Omnibus change.
Banned practices check. Verify that none of your tools fall into the prohibited category. The most common risk area for SMEs is emotion analysis in video recruitment interviews.
Transparency obligations (limited-risk systems)
If you run a chatbot on your website, add a visible notice: “You are chatting with an AI assistant.” If you publish AI-generated content, label it accordingly. These are straightforward to implement and should be addressed now if they are not already.
High-risk obligations (the heavy lift)
If you use AI systems classified as high risk (automated hiring tools, credit scoring, performance evaluation), the requirements are significantly more demanding:
- Human oversight. You must maintain meaningful human control, including the ability to override or stop the system.
- Risk management. Document the risks associated with the system and the measures you have taken to mitigate them.
- Data governance. Understand what data the system uses, its origin, quality, and potential biases.
- Logging and traceability. Keep records of how the system operates and the decisions it produces.
- Incident reporting. Establish a procedure to report serious incidents involving high-risk AI systems.
- Registration. Ensure high-risk systems are registered in the EU database.
The timeline
Not everything kicks in at once. Here are the dates that matter.
| Date | What applies | Who is concerned |
|---|---|---|
| Feb 2, 2025 | Banned AI practices prohibited; original AI literacy duty starts applying | Everyone using AI systems |
| Aug 2, 2025 | Rules for general-purpose AI models (GPAI) | Foundation model providers |
| Jul 27, 2026 | AI Omnibus enters into force, simplifying duties and extending the high-risk timetable | Providers and deployers |
| Aug 2, 2026 | General application of the Act, including Article 50 transparency duties; Commission enforcement of GPAI-provider obligations begins | Providers and deployers in scope |
| Dec 2, 2027 | High-risk rules for Annex III use cases under the revised timetable | Providers and deployers of those high-risk systems |
| Aug 2, 2028 | High-risk AI embedded in regulated products | Product manufacturers |
The ban on unacceptable practices has applied since February 2025. The Omnibus changed the treatment of AI literacy in July 2026, but not the operational value of giving staff enough competence to select, supervise and challenge AI systems.
The later dates for high-risk systems do not postpone the obligations already in force. Prohibited practices have applied since February 2025, while transparency duties for systems covered by Article 50 apply from August 2, 2026. Use the extra implementation time for high-risk systems to build evidence, governance and supplier controls rather than to delay the inventory.
Penalties
The regulation carries real financial consequences.
| Infringement | Maximum fine |
|---|---|
| Using a banned AI system | 35M EUR or 7% of global annual turnover |
| Non-compliance for a high-risk system | 15M EUR or 3% of global annual turnover |
| Failure to meet transparency obligations | 7.5M EUR or 1% of global annual turnover |
For SMEs, fines are capped proportionally to revenue, so nobody is getting a 35-million-euro bill on a 2-million-euro turnover. But the reputational damage from a public enforcement action can be just as harmful as the fine itself. And national supervisory authorities across EU member states are currently standing up their enforcement structures.
6-step action plan
This plan is designed to produce an evidence pack, not merely a policy document. At the end, an SME should be able to show what it uses, why it uses it, who owns each decision and which controls are operating.
Step 1. Inventory your AI systems
More than half of organizations do not know what AI systems they are using. Start with a complete inventory.
For each tool, document: the tool name, provider, how it is used in your organization, what data it processes, who it affects (employees, clients, candidates), your role (provider or deployer), and the estimated risk level.
Where to look: SaaS subscriptions (check if “AI” or “machine learning” appears in the product description), plugins and extensions (Copilot in Office, Gemini in Workspace, coding assistants), business tools (CRM, HR, accounting, marketing, many now embed AI), and internal developments (scripts, automations, chatbots).
Step 2. Classify by risk level
For each system identified, determine the risk level using the four categories above. When in doubt, classify upward as a precaution.
Most SMEs find that the majority of their AI tools fall into the minimal-risk category. That is normal. The point of the inventory is to surface the one or two systems that might be high risk (an automated recruitment filter, a credit scoring module), because those carry the bulk of the obligations.
Step 3. Verify your suppliers
As a deployer, you must ensure your SaaS providers meet their own obligations. Request their AI Act documentation or roadmap. Verify that high-risk systems are registered in the EU database. Add AI Act clauses to your contracts (compliance, documentation, audit rights, incident notification). Keep evidence of your due diligence.
Use the same questions for every material supplier:
| Question | Evidence to retain |
|---|---|
| What is the system’s intended purpose and risk classification? | Product documentation and supplier statement |
| Which data is processed, retained or reused for training? | Data-processing terms and architecture note |
| Which human controls, logs and incident channels exist? | Control description, log sample and escalation contact |
| Which model or feature changes can alter the risk profile? | Release policy and notification clause |
Step 4. Establish AI governance
Designate a person responsible for AI compliance. In smaller organizations, this could be the DPO (if you have one for GDPR), the IT security officer, a specialized legal counsel, or the CEO directly. What matters is that this person has a cross-functional view (IT, legal, and business operations) and direct access to leadership.
Assemble a project team that brings together IT, legal, HR, and the business units that use AI tools.
Step 5. Document everything
For high-risk systems, the documentation requirements are substantial: system description and intended use, risk assessment and mitigation measures, data sources and quality controls, human oversight procedures, logging and traceability mechanisms, and known performance limitations.
For limited-risk systems, documentation is lighter: visible transparency notices and a procedure for labeling AI-generated content.
If you are already GDPR-compliant, you have a significant head start here. Your processing register, impact assessments, and DPO documentation are directly reusable as a foundation. More on that below.
Step 6. Monitor and update
Compliance is not a one-time exercise. Set up regulatory monitoring (the text and its guidelines will evolve), an evaluation process for new AI tools before adoption, a periodic review of your AI inventory (quarterly is recommended), and an incident notification procedure for high-risk systems.
Minimum evidence pack for a small organization
Keep the first version deliberately small and usable:
- one AI inventory with an owner and review date for each system;
- one role and risk classification record per material use;
- supplier terms, data-flow notes and due-diligence answers;
- screenshots or copies of user-facing transparency notices;
- the human oversight and incident escalation procedure;
- training or competency records where relevant to safe operation;
- a quarterly review log recording additions, removals and material changes.
AI Act and GDPR: how they interact
The GDPR governs personal data. The AI Act governs AI systems. The two frameworks do not replace each other. They stack.
When an AI system processes personal data (which is very common), both apply simultaneously. CV screening involves personal data and is a high-risk AI system. Client scoring involves personal data and is potentially high-risk. A chatbot that collects information involves personal data and triggers transparency obligations.
What your GDPR compliance already covers
If you are already GDPR-compliant, you have a head start. Your processing register can be extended into an AI inventory. Your data protection impact assessments (DPIAs) can be supplemented with AI-specific risk evaluations. Your DPO can lead the AI Act compliance effort. Your breach notification procedures can be expanded to cover AI incidents. Your existing documentation provides a solid foundation to build on.
This overlap is significant. GDPR-mature organizations will find the AI Act less burdensome than those starting from scratch on both fronts.
What happens next
The AI Act is no longer a future deadline. Several obligations are already enforceable and the regulation has been generally applicable since August 2, 2026. For SMEs, the good news is that most obligations are manageable when the systems, roles and risks are documented early.
Start with the inventory. That single step will tell you where you stand and what you need to prioritize. Everything else flows from there. If your inventory reveals no high-risk systems, your compliance path is mostly transparency notices and AI literacy training, achievable in weeks, not months. If it does reveal high-risk systems, you now know exactly where to focus.
The regulation will also continue to evolve. Implementing standards, sector-specific guidelines, and enforcement precedents will shape how the AI Act works in practice over the coming years. Maintaining a compliance process, rather than treating August 2026 as a one-off deadline, positions you well for what comes next.
We run hands-on training sessions that walk SME teams through the full compliance process, from inventory to documentation, using your actual AI systems as working material. If you would rather not figure this out alone, get in touch.
Sources
- Regulation (EU) 2024/1689 : official text
- AI Act : European Commission
- AI Act implementation timeline : European Commission
- Article 50 transparency guidance : European Commission
- AI Omnibus enters into force : European Commission
- Guide AI Act : CNIL
This guide is provided for informational purposes and does not constitute legal advice. For analysis specific to your situation, consult a qualified legal professional.
Need compliance guidance? First call is free →