Skip to content
Back to blog
· Ulysse Trin

EU AI Act for SMEs: What Applies From August 2026

If your company uses ChatGPT, an AI-powered CRM, a chatbot on your website, or an automated CV screening tool, the EU AI Act may create obligations for your organization. The regulation became generally applicable on August 2, 2026, while several provisions started earlier and some high-risk rules follow a later timetable.

Most small and medium businesses we talk to fall into one of two camps: those who have never heard of it, and those who assume it only applies to big tech companies. Both assumptions are risky. The AI Act applies according to the organization’s role and the system’s use and risk level, not simply the size of the business.

This is an operational playbook, not another deadline recap. It explains how to identify your role, classify each use, question suppliers and assemble the evidence an SME should be able to produce. For a concise account of what changed on the August 2026 application date, read the separate AI Act deadline update.

The SME answer in one paragraph: inventory every AI-enabled system, record its purpose, supplier, data and affected people, identify whether you are a provider or deployer, then classify the use by risk. Address prohibited practices and Article 50 transparency immediately. Build evidence now for any high-risk use, even though the AI Omnibus moved the main Annex III rules to 2 December 2027 and product-embedded rules to 2 August 2028.

The AI Act in brief

The EU AI Act (Regulation 2024/1689) is the world’s first comprehensive legal framework for artificial intelligence. Adopted in 2024, it is being phased in between 2025 and 2027.

Its core principle is a risk-based classification. The higher the potential impact of an AI system on people’s fundamental rights, health, or safety, the stricter the obligations. This is a pragmatic approach: a spell checker and an automated hiring tool are not treated the same way.

Four risk levels

Unacceptable risk: banned outright. This includes subliminal manipulation, social scoring by public authorities, emotion recognition in workplaces and schools (with narrow exceptions), real-time biometric identification in public spaces, and untargeted facial image scraping. These have been prohibited since February 2025.

High risk: allowed but heavily regulated. AI systems that significantly affect people’s lives fall here. The regulation lists eight domains in Annex III: biometrics, critical infrastructure, education, employment and HR, access to essential services (credit scoring, insurance), law enforcement, migration, and administration of justice. For most SMEs, the relevant ones are automated CV screening, employee performance evaluation, and client creditworthiness scoring.

Limited risk: transparency obligations. Systems that interact with people must disclose their nature. A chatbot must tell users they are talking to an AI. AI-generated content (text, images, video) must be identifiable as such, particularly deepfakes.

Minimal risk: no specific obligations. The vast majority of everyday AI tools (translation, spell checking, search, content drafting assistants) fall here. No legal requirements, though the regulation encourages voluntary codes of conduct.

Are you affected?

Almost certainly yes, if you use any AI tool professionally. The key question is your role.

Provider vs. deployer

The AI Act distinguishes four roles: provider, deployer, importer, and distributor. The one that matters for most SMEs is deployer: you use AI systems developed by someone else in a professional context.

You are a deployer if you use ChatGPT or Claude to draft communications, run a CRM with predictive scoring, deploy a chatbot through a SaaS platform, or use HR software with automated screening. The overwhelming majority of European SMEs are deployers.

You are a provider if you develop an AI system and place it on the market, for example building a custom chatbot product for your clients or creating a scoring tool you sell as a service.

One important nuance: a deployer can become a provider by substantially modifying the intended purpose of a system. Using a product recommendation engine to assess creditworthiness, for instance, would shift your role, and your obligations.

The deployer misconception

Many businesses assume that being “just a user” means they have no obligations. This is incorrect. Deployers have real operational responsibilities, especially when the AI system impacts employees or customers. The obligations are lighter than those of providers, but they exist and are enforceable.

Concrete obligations for deployers

What the AI Act actually requires depends on the risk level of the systems you use.

Obligations that apply to everyone

AI literacy. The original Article 4 duty applied from February 2025. The AI Omnibus, which entered into force on July 27, 2026, replaced that company-level obligation with non-binding encouragement and gave the Commission and Member States a stronger role in promoting AI literacy. Training still remains one of the clearest ways to demonstrate competent oversight, reduce misuse and prepare teams for regulated workflows, but this guide does not present it as a standalone binding duty after the Omnibus change.

Banned practices check. Verify that none of your tools fall into the prohibited category. The most common risk area for SMEs is emotion analysis in video recruitment interviews.

Transparency obligations (limited-risk systems)

If you run a chatbot on your website, add a visible notice: “You are chatting with an AI assistant.” If you publish AI-generated content, label it accordingly. These are straightforward to implement and should be addressed now if they are not already.

High-risk obligations (the heavy lift)

If you use AI systems classified as high risk (automated hiring tools, credit scoring, performance evaluation), the requirements are significantly more demanding:

  • Human oversight. You must maintain meaningful human control, including the ability to override or stop the system.
  • Risk management. Document the risks associated with the system and the measures you have taken to mitigate them.
  • Data governance. Understand what data the system uses, its origin, quality, and potential biases.
  • Logging and traceability. Keep records of how the system operates and the decisions it produces.
  • Incident reporting. Establish a procedure to report serious incidents involving high-risk AI systems.
  • Registration. Ensure high-risk systems are registered in the EU database.

The timeline

Not everything kicks in at once. Here are the dates that matter.

DateWhat appliesWho is concerned
Feb 2, 2025Banned AI practices prohibited; original AI literacy duty starts applyingEveryone using AI systems
Aug 2, 2025Rules for general-purpose AI models (GPAI)Foundation model providers
Jul 27, 2026AI Omnibus enters into force, simplifying duties and extending the high-risk timetableProviders and deployers
Aug 2, 2026General application of the Act, including Article 50 transparency duties; Commission enforcement of GPAI-provider obligations beginsProviders and deployers in scope
Dec 2, 2027High-risk rules for Annex III use cases under the revised timetableProviders and deployers of those high-risk systems
Aug 2, 2028High-risk AI embedded in regulated productsProduct manufacturers

The ban on unacceptable practices has applied since February 2025. The Omnibus changed the treatment of AI literacy in July 2026, but not the operational value of giving staff enough competence to select, supervise and challenge AI systems.

The later dates for high-risk systems do not postpone the obligations already in force. Prohibited practices have applied since February 2025, while transparency duties for systems covered by Article 50 apply from August 2, 2026. Use the extra implementation time for high-risk systems to build evidence, governance and supplier controls rather than to delay the inventory.

Penalties

The regulation carries real financial consequences.

InfringementMaximum fine
Using a banned AI system35M EUR or 7% of global annual turnover
Non-compliance for a high-risk system15M EUR or 3% of global annual turnover
Failure to meet transparency obligations7.5M EUR or 1% of global annual turnover

For SMEs, fines are capped proportionally to revenue, so nobody is getting a 35-million-euro bill on a 2-million-euro turnover. But the reputational damage from a public enforcement action can be just as harmful as the fine itself. And national supervisory authorities across EU member states are currently standing up their enforcement structures.

6-step action plan

This plan is designed to produce an evidence pack, not merely a policy document. At the end, an SME should be able to show what it uses, why it uses it, who owns each decision and which controls are operating.

Step 1. Inventory your AI systems

More than half of organizations do not know what AI systems they are using. Start with a complete inventory.

For each tool, document: the tool name, provider, how it is used in your organization, what data it processes, who it affects (employees, clients, candidates), your role (provider or deployer), and the estimated risk level.

Where to look: SaaS subscriptions (check if “AI” or “machine learning” appears in the product description), plugins and extensions (Copilot in Office, Gemini in Workspace, coding assistants), business tools (CRM, HR, accounting, marketing, many now embed AI), and internal developments (scripts, automations, chatbots).

Step 2. Classify by risk level

For each system identified, determine the risk level using the four categories above. When in doubt, classify upward as a precaution.

Most SMEs find that the majority of their AI tools fall into the minimal-risk category. That is normal. The point of the inventory is to surface the one or two systems that might be high risk (an automated recruitment filter, a credit scoring module), because those carry the bulk of the obligations.

Step 3. Verify your suppliers

As a deployer, you must ensure your SaaS providers meet their own obligations. Request their AI Act documentation or roadmap. Verify that high-risk systems are registered in the EU database. Add AI Act clauses to your contracts (compliance, documentation, audit rights, incident notification). Keep evidence of your due diligence.

Use the same questions for every material supplier:

QuestionEvidence to retain
What is the system’s intended purpose and risk classification?Product documentation and supplier statement
Which data is processed, retained or reused for training?Data-processing terms and architecture note
Which human controls, logs and incident channels exist?Control description, log sample and escalation contact
Which model or feature changes can alter the risk profile?Release policy and notification clause

Step 4. Establish AI governance

Designate a person responsible for AI compliance. In smaller organizations, this could be the DPO (if you have one for GDPR), the IT security officer, a specialized legal counsel, or the CEO directly. What matters is that this person has a cross-functional view (IT, legal, and business operations) and direct access to leadership.

Assemble a project team that brings together IT, legal, HR, and the business units that use AI tools.

Step 5. Document everything

For high-risk systems, the documentation requirements are substantial: system description and intended use, risk assessment and mitigation measures, data sources and quality controls, human oversight procedures, logging and traceability mechanisms, and known performance limitations.

For limited-risk systems, documentation is lighter: visible transparency notices and a procedure for labeling AI-generated content.

If you are already GDPR-compliant, you have a significant head start here. Your processing register, impact assessments, and DPO documentation are directly reusable as a foundation. More on that below.

Step 6. Monitor and update

Compliance is not a one-time exercise. Set up regulatory monitoring (the text and its guidelines will evolve), an evaluation process for new AI tools before adoption, a periodic review of your AI inventory (quarterly is recommended), and an incident notification procedure for high-risk systems.

Minimum evidence pack for a small organization

Keep the first version deliberately small and usable:

  • one AI inventory with an owner and review date for each system;
  • one role and risk classification record per material use;
  • supplier terms, data-flow notes and due-diligence answers;
  • screenshots or copies of user-facing transparency notices;
  • the human oversight and incident escalation procedure;
  • training or competency records where relevant to safe operation;
  • a quarterly review log recording additions, removals and material changes.

AI Act and GDPR: how they interact

The GDPR governs personal data. The AI Act governs AI systems. The two frameworks do not replace each other. They stack.

When an AI system processes personal data (which is very common), both apply simultaneously. CV screening involves personal data and is a high-risk AI system. Client scoring involves personal data and is potentially high-risk. A chatbot that collects information involves personal data and triggers transparency obligations.

What your GDPR compliance already covers

If you are already GDPR-compliant, you have a head start. Your processing register can be extended into an AI inventory. Your data protection impact assessments (DPIAs) can be supplemented with AI-specific risk evaluations. Your DPO can lead the AI Act compliance effort. Your breach notification procedures can be expanded to cover AI incidents. Your existing documentation provides a solid foundation to build on.

This overlap is significant. GDPR-mature organizations will find the AI Act less burdensome than those starting from scratch on both fronts.

What happens next

The AI Act is no longer a future deadline. Several obligations are already enforceable and the regulation has been generally applicable since August 2, 2026. For SMEs, the good news is that most obligations are manageable when the systems, roles and risks are documented early.

Start with the inventory. That single step will tell you where you stand and what you need to prioritize. Everything else flows from there. If your inventory reveals no high-risk systems, your compliance path is mostly transparency notices and AI literacy training, achievable in weeks, not months. If it does reveal high-risk systems, you now know exactly where to focus.

The regulation will also continue to evolve. Implementing standards, sector-specific guidelines, and enforcement precedents will shape how the AI Act works in practice over the coming years. Maintaining a compliance process, rather than treating August 2026 as a one-off deadline, positions you well for what comes next.

We run hands-on training sessions that walk SME teams through the full compliance process, from inventory to documentation, using your actual AI systems as working material. If you would rather not figure this out alone, get in touch.

Sources


This guide is provided for informational purposes and does not constitute legal advice. For analysis specific to your situation, consult a qualified legal professional.


Need compliance guidance? First call is free →