The EU AI Act: A Plain-Language Compliance Guide for European SMEs

Paulo Rodrigues10 min read

The EU AI Act: A Plain-Language Compliance Guide for European SMEs

You run a small European business. You use AI — maybe a chatbot on your site, a copilot in your code editor, an AI feature buried inside software you already pay for. And somewhere you have read that the EU AI Act can fine companies up to €35 million. That number is real. It is also almost certainly not about you.

This is a plain-language guide to what the EU AI Act actually requires of a small or medium business. Not the lawyer's version — the operator's version: what it is, which parts apply to you, the deadlines that matter, and a concrete list of what to do. Every date, article, and figure below is taken from the regulation itself or from official EU sources, and I have listed them so you can check.

This is educational content, not legal advice. It is written for founders and operators, not lawyers, and it deliberately simplifies. It is also a fast-moving area — the timeline was amended in July 2026 and is still settling. For decisions with real exposure, get advice from a qualified professional and verify the current text.

Correction, 24 July 2026. When this guide was published on 22 July it said the Digital Omnibus deferral of the high-risk deadlines had been agreed but not yet published in the Official Journal, and that the original 2 August 2026 date therefore remained the binding one. That was accurate when written and is no longer. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 (OJ L, 2026/1744), with entry into force on 27 July 2026. The high-risk dates are 2 December 2027 (Annex III, standalone) and 2 August 2028 (Annex I, embedded in regulated products). Nothing changed for the Article 50 transparency obligations or for the Act's general date of application — both still apply from 2 August 2026. Check us rather than trust us: CELEX 32026R1744 · ELI http://data.europa.eu/eli/reg/2026/1744/oj.

Correction, 28 July 2026. A second pass against the primary sources found two errors and two gaps in the guide below. (1) The Annex I baseline was wrong. This guide said three times that the Annex I high-risk deadline had been postponed from 2 August 2026. It never sat on that date. Under the original Article 113, third paragraph, point (c) of Regulation (EU) 2024/1689, Article 6(1) and Annex I applied from 2 August 2027, and Regulation (EU) 2026/1744 moved that to 2 August 2028. Annex I therefore gained one year, not two. The Annex III limb is different and really did move from 2 August 2026 to 2 December 2027. The two must not be merged. (2) The Article 4 AI literacy duty was presented as unchanged. Regulation (EU) 2026/1744 replaced Article 4 with effect from 27 July 2026 and made the provider and deployer duty less demanding: they must now "take measures to support the development of AI literacy of their staff", where previously they had to "take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff", and the new text adds that the obligation "does not require providers or deployers to guarantee any specific level of AI literacy of any individual". Only that company-facing duty in Article 4(1) was softened; the replacement also adds new paragraphs 2 and 3, which create duties for the Commission and the Member States, not for companies. The duty still exists and still applies from 2 February 2025. (3) The deferral has an exception that was missing here. It covers Chapter III, Sections 1 to 3, with the exception of Article 6(5). That exception is a duty on the Commission to issue guidelines, not a new obligation on your business. (4) Two new prohibited practices were missing. The same act added points (ba) (non-consensual intimate imagery) and (bb) (AI-generated child sexual abuse material) to the first subparagraph of Article 5(1), with interpretive paragraphs 5(1a) and 5(1b). They apply from 2 December 2026, not from February 2025 like the rest of the Article 5 list. Source: Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July 2026 and in force on 27 July 2026, CELEX 32026R1744.

What the EU AI Act actually is

The EU AI Act is Regulation (EU) 2024/1689, the world's first comprehensive law on artificial intelligence. It entered into force on 1 August 2024 and applies across all 27 EU member states. Like the GDPR before it, it reaches beyond Europe: it can apply to a company anywhere if its AI system's output is used in the EU.

The core idea is simple and worth holding onto, because it dissolves most of the panic: the Act is risk-based. It does not regulate "AI" as one thing. It sorts AI uses into tiers and applies heavier rules only where the risk to people is higher. The vast majority of everyday business AI sits at the bottom of that pyramid, where the rules are light.

The four risk tiers

The Act sorts AI into four levels of risk.

1. Unacceptable risk — banned outright. A short, defined list in Article 5 of AI practices considered a clear threat to people's safety and rights. These are prohibited entirely. They include:

  • Manipulative or deceptive techniques that materially distort behaviour and cause harm
  • Exploiting vulnerabilities of age, disability, or a specific social or economic situation
  • Social scoring — evaluating people based on social behaviour, leading to unfair treatment
  • Building or expanding facial-recognition databases through untargeted scraping of faces from the internet or CCTV
  • Emotion recognition in the workplace and in education (with narrow medical/safety exceptions)
  • Biometric categorisation to infer sensitive traits like race, political opinion, or sexual orientation

Most small businesses will never touch these — but the emotion-recognition ban is one to know if you have ever been pitched software that claims to read employees' or students' moods.

Two further prohibitions were added in 2026, and they bite later than the rest. Regulation (EU) 2026/1744 inserted two new points into the first subparagraph of Article 5(1), together with interpretive paragraphs 5(1a) and 5(1b):

  • Point (ba): non-consensual intimate imagery
  • Point (bb): AI-generated child sexual abuse material

Be precise about the timing here, because it differs from every other entry on this list. These two have been in the legal text since 27 July 2026, when Regulation (EU) 2026/1744 entered into force, but they do not bind until 2 December 2026. Everything else in Article 5 has been binding since 2 February 2025.

2. High risk — allowed, but with strict obligations. AI used in areas that can seriously affect health, safety, or fundamental rights. This is where the real compliance burden lives — risk management, documentation, human oversight, conformity assessment. The Annex III use cases most relevant to an SME are:

  • Recruitment and employment — filtering job applications, evaluating candidates, decisions on promotion or task allocation
  • Creditworthiness and credit scoring of individuals (fraud detection is carved out)
  • Access to essential services and benefits — eligibility decisions for healthcare or welfare
  • Education — admissions, grading, and exam monitoring

If your business uses AI for hiring or lending decisions about people, this tier is the one to take seriously.

3. Limited risk — transparency only. AI that interacts with people or generates content. No conformity assessment; the duty is to be honest that AI is involved. This is the tier most SMEs will actually land in, and it is covered by Article 50 (below).

4. Minimal risk — no new rules. Everything else: spam filters, recommendation engines, AI in video games, most productivity tools. Official EU guidance is explicit that the vast majority of AI systems in use fall here. Nothing new is required.

The deadlines that actually matter

The Act does not switch on all at once. It phases in, and — importantly — two of the phases are already in force. Here is the timeline set by Article 113 of the regulation, with the 2026 amendment noted.

DateWhat appliesStatus
1 Aug 2024Regulation enters into forceDone
2 Feb 2025Prohibited practices banned; AI literacy obligation begins (Article 4, replaced and softened 27 Jul 2026)In force now
2 Aug 2025Governance rules, GPAI model obligations, and the penalty regimeIn force now
2 Aug 2026Transparency obligations (Article 50) applyUpcoming
2 Dec 2026Two new prohibited practices in Article 5 begin to bind, points (ba) and (bb)Added by Reg. (EU) 2026/1744, in the text since 27 Jul 2026
2 Dec 2027High-risk systems under Annex III (standalone), postponed from 2 Aug 2026Set by Reg. (EU) 2026/1744, published 24 Jul 2026, in force 27 Jul 2026
2 Aug 2028High-risk AI inside regulated products (Annex I), postponed from 2 Aug 2027, never from 2 Aug 2026Set by Reg. (EU) 2026/1744, published 24 Jul 2026, in force 27 Jul 2026

Three things to take from this table.

First, the parts already in force are the parts that apply to most small businesses. The prohibitions, and the obligation that people using AI have a basic understanding of it, have been binding since February 2025. You do not have until 2027 to think about those.

Second, the high-risk deadlines moved, and as of July 2026 the change is law. The two limbs did not move from the same starting point, and this is where most summaries go wrong. Standalone high-risk systems (Annex III) were due on 2 August 2026 and are now due on 2 December 2027. High-risk AI embedded in regulated products (Annex I) was never due in 2026 at all: under the original Article 113, third paragraph, point (c) of Regulation (EU) 2024/1689, Article 6(1) and Annex I applied from 2 August 2027, and they now apply from 2 August 2028. Annex I gained one year; Annex III gained rather more. Both dates come from the package known as the Digital Omnibus on AI (proposed by the Commission on 19 November 2025; adopted by the European Parliament on 16 June 2026 and given the Council's final green light on 29 June 2026), published in the EU's Official Journal as Regulation (EU) 2026/1744 on 24 July 2026 (OJ L, 2026/1744), with entry into force on 27 July 2026. Those are the dates to plan around.

Note carefully what did not move. The Act's general date of application is still 2 August 2026, and the Article 50 transparency obligations still apply from that date. The postponement reaches only the high-risk regime in Chapter III, Sections 1 to 3, and even there it carves out Article 6(5), which is not deferred. That exception is not a new obligation landing on you: Article 6(5) requires the Commission to issue guidelines on classifying high-risk systems, so it simply keeps its own schedule. Conflating the postponement with the general date of application is the easiest mistake to make here, and it is the expensive one: it would tell you that nothing happens in August 2026, when in fact the disclosure rules that touch most small businesses start exactly then.

Third, the AI literacy duty was softened, and most summaries have not caught up. Article 4 still exists and still applies from 2 February 2025. What changed is how demanding it is. Regulation (EU) 2026/1744 replaced Article 4 with effect from 27 July 2026: providers and deployers must now "take measures to support the development of AI literacy of their staff", where before they had to "take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff". The new text adds, expressly, that the obligation "does not require providers or deployers to guarantee any specific level of AI literacy of any individual". Read that narrowly. Only the company-facing duty in Article 4(1) was relaxed; the replacement also adds new paragraphs 2 and 3, and those create duties for the Commission and the Member States, not for you. The practical advice further down does not change: train your people, and write down that you did.

This is also exactly the kind of detail that goes stale — this very section said "agreed but not yet published" until 24 July 2026 — so verify the current status before you plan around it. The primary sources: CELEX 32026R1744, ELI http://data.europa.eu/eli/reg/2026/1744/oj, amending Article 113 of Regulation (EU) 2024/1689.

The transparency rules — the ones most SMEs will meet (Article 50)

If any part of the Act touches your business directly, this is probably it. Article 50 applies from 2 August 2026 and requires disclosure in a few specific situations, regardless of risk tier:

  • Chatbots and AI assistants: if people interact directly with an AI system, they must be told they are dealing with AI (unless it is obvious).
  • AI-generated content: the outputs of generative AI must be marked as artificially generated in a machine-readable way. (For systems already placed on the market before 2 August 2026, the same Digital Omnibus package allows until 2 December 2026 to meet this marking obligation — Article 111(4) of the AI Act, added by Regulation (EU) 2026/1744. Systems placed on the market from 2 August 2026 onward have no such grace period.)
  • Deepfakes: if you publish AI-generated or manipulated image, audio, or video that resembles real people, places, or events, you must disclose that it is artificial — even if there was no intent to deceive.
  • AI-generated text on matters of public interest: must be disclosed as AI-generated when published to inform the public.

For most SMEs this is very manageable: label your chatbot as a bot, and be honest when you publish something an AI made. That is the spirit of the rule.

General-purpose AI (GPAI): mostly not your problem

You will hear a lot about GPAI obligations. For a typical SME, the reassuring news is that these obligations sit with the model providers — the companies that build large general-purpose models — not with you as a user of those models. Providers must supply technical documentation, respect copyright rules, and publish a summary of training content. A model is presumed to have high-impact capabilities — "systemic risk" — when the compute used to train it exceeds 10²⁵ floating-point operations (Article 51), but that is a rebuttable presumption, not an automatic bright line. Such models carry extra duties.

Your practical takeaway: you are almost never the "provider" here. Just keep a record of which AI tools and models you rely on, so you can point to the provider's documentation if asked.

The penalties — and the protection for small companies

The fines are real, and they are tiered by how serious the breach is (Article 99):

  • Prohibited practices (the Article 5 list): up to €35 million or 7% of total worldwide annual turnover, whichever is higher.
  • Other obligations (high-risk duties, transparency, etc.): up to €15 million or 3%, whichever is higher.
  • Supplying incorrect or misleading information to authorities: up to €7.5 million or 1%, whichever is higher.

Now the part written specifically for you. For SMEs and start-ups, the Act flips the calculation: the fine is the amount or the percentage, whichever is lower — the opposite of the "whichever is higher" rule that applies to large companies. A small firm's exposure is capped by its size, not multiplied by it. The €35 million headline is a ceiling for corporations, not a threat aimed at a five-person business.

What an SME actually has to do — a checklist

Here is the practical, do-this-today version.

  1. Inventory your AI. List every AI system you use or build, including AI features baked into software you already pay for. You cannot classify what you have not written down.
  2. Classify each by risk tier. Most will be minimal or limited. Flag anything touching recruitment, lending, education assessment, or essential services (potential high-risk), and anything resembling the prohibited list.
  3. Stop anything prohibited. Check your tools against the Article 5 list. The common trap for a normal business is emotion-recognition software aimed at employees.
  4. Do AI literacy properly. Anyone using AI in your business should understand, at a basic level, what it can and cannot do. This has been required since February 2025, and Article 4 was replaced on 27 July 2026 with a lighter duty: you must support the development of AI literacy, not guarantee a specific level in any individual. A short internal briefing and a written note that you did it still goes a long way.
  5. Plan your transparency disclosures. From August 2026: label chatbots as AI, and mark or disclose AI-generated content. Decide now how you will do it.
  6. Keep a paper trail. Note which AI tools you use, what for, and who is responsible. Documentation is most of what "governance" means for a small company.
  7. Mind your data (GDPR overlaps here). Do not feed personal data into tools that ship it to places you do not control. The AI Act and the GDPR reinforce each other; solving one often helps the other.
  8. Assign an owner. One person accountable for AI decisions. It does not need to be a new hire — it needs to be a named human.
  9. Get real advice if you are near high-risk. If your AI makes or heavily informs decisions about hiring, credit, or access to services, this is where professional help pays for itself.

Where our approach fits — honestly

We build self-hosted, privacy-first AI, so it would be easy to claim self-hosting makes you AI-Act compliant. It does not, and I would rather say so plainly. The Act regulates what an AI system does and how risky its use is — not where it runs. Hosting a model in Frankfurt instead of Virginia exempts you from nothing.

What ownership genuinely helps with is everything around the obligations:

  • Transparency and documentation are far easier when you can actually see what your system does. A self-hosted stack you understand is one you can accurately describe, log, and disclose — which is most of what Article 50 and the record-keeping duties ask for.
  • Data control overlaps with the GDPR. Keeping personal data on infrastructure you own, instead of shipping it to a third-party model, shrinks your GDPR surface. That is not an AI Act exemption, but AI use tends to expand your data exposure, and owning the path is the cleanest way to keep it contained. We wrote about that discipline in how to make a local model cite only sources it actually read and what our €107 infrastructure looks like.
  • AI literacy becomes real, not performative, when your team runs the stack rather than renting a black box.

The honest summary: self-hosting is not a compliance shortcut. It is a way to make the compliance you owe anyway easier to prove — and to keep your data where the GDPR wants it.

The takeaway

For most European SMEs the EU AI Act is far less frightening than the €35 million headline suggests. You are very likely in the minimal- or limited-risk tier, where the duties are: do not use prohibited AI, make sure your people understand the AI they use, and be honest when AI is involved. The prohibitions and the literacy rule are already in force, with two further prohibitions joining them on 2 December 2026; transparency arrives in August 2026; and the heavy high-risk obligations are years out, pushed to December 2027 (Annex III) and August 2028 (Annex I) by an amendment published in July 2026.

Do the boring, cheap work now — inventory, classify, document, disclose — and the Act becomes what it was designed to be: a floor under responsible AI use, not a trap. And if your business genuinely sits near a high-risk use like hiring or lending, that is the signal to bring in someone who does this for a living.

A final reminder: this guide is educational and simplified, the law is being actively amended, and nothing here is legal advice. Verify every date and requirement against the current regulation or a qualified adviser before you act on it.

Frequently Asked Questions

Does the EU AI Act apply to my small business if I just use ChatGPT or a chatbot?

Almost certainly, but lightly. Most small businesses using off-the-shelf AI fall into the minimal-risk or limited-risk (transparency) tiers, where there is no conformity assessment and no registration. Your real duties are three: do not use any AI on the prohibited list (Article 5), make sure staff who use AI have a basic understanding of it (the AI literacy obligation in Article 4, in force since 2 February 2025, and softened by Regulation (EU) 2026/1744 with effect from 27 July 2026: you must support the development of AI literacy, not guarantee any specific level in any individual), and disclose AI where transparency rules require it, for example telling people they are talking to a chatbot, and labelling AI-generated content (Article 50). You do not need a high-risk compliance programme unless your AI is used for something like recruitment, credit scoring, or another Annex III use case.

What are the deadlines I actually have to worry about?

Two dates have already passed and are enforceable now: 2 February 2025 (prohibited practices banned, AI literacy required) and 2 August 2025 (governance rules, general-purpose AI model obligations, and the penalty regime). The transparency obligations under Article 50 apply from 2 August 2026. The heavy high-risk obligations moved in July 2026, but the two limbs did not start from the same date. Standalone high-risk systems (Annex III) were due 2 August 2026 and are now due 2 December 2027. AI built into regulated products (Annex I) was never due in 2026: under the original Article 113, third paragraph, point (c) it applied from 2 August 2027, and it now applies from 2 August 2028, a gain of one year rather than two. Both dates were set by the package known as the 'Digital Omnibus on AI', published in the Official Journal as Regulation (EU) 2026/1744 on 24 July 2026 (OJ L, 2026/1744), with entry into force on 27 July 2026. Two new prohibited practices were added to Article 5 by the same act and apply from 2 December 2026. Those are the dates to plan around. Note what did not change: the Article 50 transparency obligations, and the Act's general date of application, still land on 2 August 2026. This area moves, so verify the current status before relying on any of it (CELEX 32026R1744).

Does self-hosting AI in the EU make me AI-Act compliant?

No, and it is important to be honest about this. The AI Act regulates what an AI system does and how risky its use is — not where it is hosted. Self-hosting does not exempt you from anything. What it does do is make the other obligations easier to meet: you can actually see what your system does, keep the logs and documentation that transparency and record-keeping require, and avoid shipping personal data to third-party models (which is a GDPR win, not an AI Act exemption). Ownership helps you comply; it is not compliance by itself.

Ready to automate your business?

We build AI tools and automation systems for European SMEs — from rapid MVPs to production systems, always GDPR-compliant.

it's human stuff

Weekly AI insights for European SMEs. No hype, just what works.

Keep Reading