EU AI Act: what SMEs actually have to do in 2026
EU AI Act and SMEs: the 3 real obligations, the dated timeline (Feb 2025, Aug 2026), the risk levels and the penalties. Without the needless panic.
Flavien Bittar
June 29, 2026
EU AI Act: what SMEs actually have to do in 2026
For the vast majority of SMEs, the EU AI Act comes down to three obligations, not a multinational's compliance binder. One: train your teams to use AI properly (in force since February 2025). Two: tell your users when they are interacting with an AI (from August 2026). Three: comply with the GDPR, which already applies. The rest, the heavy "high-risk" compliance, only concerns companies that deploy specific systems, like automated CV screening or credit scoring.
I say this because the panic around the AI Act is wildly out of proportion for SMEs. People wave the penalty figure (up to €35 million) without saying who it applies to. The result: business owners postponing every AI project "because of the regulation," when their case falls under the lightest regime. Let us take it in order, with the real dates.
The real EU AI Act timeline
Regulation (EU) 2024/1689, its official name, entered into force on 1 August 2024. But it does not apply in one block. Its rollout is staggered over three years, and knowing the dates changes everything, because most of the deadlines that concern you are already past or close.
- 2 February 2025: ban on unacceptable-risk uses (social scoring, manipulation, certain biometric recognition) and start of the AI-literacy obligation. Since that date, you must ensure the people using AI in your company have a sufficient level of understanding.
- 2 August 2025: obligations for general-purpose AI models (the large models like GPT, Claude, Gemini), governance rules and the penalty framework.
- 2 August 2026: application of the bulk of the regulation, including transparency obligations and the rules for high-risk systems listed in Annex III. This is the deadline everyone talks about.
- 2 August 2027: obligations for high-risk systems embedded in already-regulated products (Annex I), with a longer transition.
Remember that February 2025 and August 2026 are your two dates. The first is behind you. The second is coming.
The four risk levels, and where your SME sits
The AI Act does not regulate "AI" as a block. It sorts systems by risk level, and the obligations depend entirely on that classification. This is the point media coverage flattens, and it is the most important one for you.
- Unacceptable risk: banned since February 2025. Social scoring, behavioural manipulation. No normal SME is here.
- High risk: systems that decide on sensitive matters. CV screening, creditworthiness assessment, access to education or essential services. Heavy obligations. We come back to this, because that is where your real exposure sits.
- Limited risk: chatbots, content generators, assistants. One real obligation: transparency. Tell the user they are talking to an AI.
- Minimal risk: everything else. Spam filters, suggestions, internal automations. No specific obligation under the AI Act.
Nearly all SMEs operate in the last two levels. A support chatbot, a writing assistant, an invoice automation: limited or minimal risk. Your obligations then fit on one page.
One last piece of vocabulary that changes your obligations: are you a provider or a deployer? The provider develops and puts an AI system on the market. The deployer uses it. Most SMEs are deployers, which lightens their obligations considerably: they do not have to produce a system's technical documentation, only to use it correctly and transparently. If you buy an AI tool rather than build it, you are almost always in this case.
What your SME actually has to do
Here are the four concrete moves, from the most urgent to the most context-dependent.
- AI literacy. The most overlooked obligation, and it is already in force. Your staff who use AI must know how to phrase their requests, check the outputs and spot errors. A short training and an internal note are enough to document the effort.
- Transparency. From August 2026, a user interacting with your chatbot must know they are talking to an AI. Generated content (images, synthetic text on matters of public interest) must be labelled as such. Technically trivial, just do not forget it.
- Human validation. For any high-stakes decision (HR, credit, contracts), keep a human in the loop. AI proposes, a human decides. It is a universal good practice, and an obligation as soon as you touch high risk.
- Data and IP protection. Check in your vendors' terms that your data is not used to train their public models, and keep these processing activities in your GDPR record. This part directly overlaps with GDPR compliance, covered in our guide on GDPR and data governance for SMEs.
Four points, half a day of scoping. Not a fifty-thousand-euro law firm.
The real question: are you affected by "high risk"
This is the one question that can flip your exposure entirely. If one of your AI systems qualifies as high risk under Annex III, you go from half a day of scoping to a genuine compliance project.
The most common Annex III cases in an SME:
- A tool that automatically screens or scores job applications.
- A system that assesses creditworthiness or decides on access to credit.
- A system used for access to essential services or to education.
If you are in one of these cases, the obligations step up: conformity assessment, technical documentation, reinforced human oversight, risk management, system registration. It is not out of reach, but it takes preparation and cannot be improvised in August 2026.
Most SMEs are not there. But those using an HR tool with automated CV screening are, sometimes without knowing it, because it is their vendor who embedded the AI. Hence the point of mapping your uses before concluding that "you are not affected."
The penalties, and why the figure going around misleads
Yes, the AI Act provides for hefty fines. Three levels:
- Up to €35 million or 7% of global turnover for prohibited uses.
- Up to €15 million or 3% for other breaches of the obligations.
- Up to €7.5 million or 1% for incorrect information supplied to the authorities.
The "€35 million" going around concerns prohibited practices, the ones no serious SME implements. And the regulation explicitly requires proportionate penalties, taking company size into account. A micro-business that forgot to label its chatbot does not face the same thing as a giant deploying a social-scoring system. Waving the figure without context is disinformation by omission.
Where to start, concretely
The right sequence has four steps, and you can launch it this week.
- Map your AI uses. List every AI tool in service, including those embedded in your business software (HR, accounting, CRM).
- Classify each by risk level. Minimal, limited, or high risk under Annex III.
- Handle limited and minimal first. Literacy, transparency, GDPR record. It is quick.
- Isolate the high risk, if any. And there, take the time to do things properly.
Scoping your AI compliance is not a brake on the project, it is what lets it go into production without being stopped by legal or by a large client now demanding an AI policy. It is the same reflex as integrating AI cleanly from the start, the logic we structure with the C.A.R.E. method.
If you want us to classify your AI uses and build your compliance scoping in one session, that is exactly what we do. Book a 30-minute discovery call. We will tell you honestly where you stand, and what you really have to do before August 2026.
FAQ
Frequently asked questions
What is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the first comprehensive European regulation on artificial intelligence, in force since 1 August 2024. It sorts AI systems by risk level (unacceptable, high, limited, minimal) and imposes obligations proportionate to that level. Prohibited uses have been banned since February 2025, and the bulk of the regulation applies from August 2026.
Does the EU AI Act apply to SMEs?
Yes, but in a very light form for most of them. An SME using a chatbot, a writing assistant or an automation falls under limited or minimal risk: its only real obligations are AI literacy (since February 2025) and transparency (from August 2026). Only SMEs deploying a high-risk system, such as automated CV screening or credit scoring, have heavy compliance to prepare.
What are the EU AI Act deadlines?
Four key dates. 2 February 2025: ban on unacceptable-risk uses and the AI-literacy obligation. 2 August 2025: obligations for general-purpose models and governance rules. 2 August 2026: application of the bulk of the regulation, transparency and Annex III high-risk systems. 2 August 2027: high risk embedded in already-regulated products. For an SME, the dates to remember are February 2025 and August 2026.
What is a high-risk AI system?
A high-risk system, under Annex III of the AI Act, is an AI that decides on matters sensitive to people: screening job applications, assessing creditworthiness or credit access, access to education or essential services. These systems require a conformity assessment, technical documentation, human oversight and risk management. Many SMEs are exposed to this without knowing it, through a business tool that has embedded this kind of automation.
What penalties apply for non-compliance with the AI Act?
The regulation provides for three levels of fines: up to €35 million or 7% of global turnover for prohibited uses, up to €15 million or 3% for other breaches, and up to €7.5 million or 1% for incorrect information supplied to the authorities. The €35 million figure concerns prohibited practices, which no normal SME implements. The regulation requires penalties proportionate to company size.
Ready to transform your digital ecosystem?
Discover how DigitalEasy helps SMEs navigate their digital transformation.
calendar_monthBook a Discovery Call