The EU AI Act: A Plain-Language Compliance Guide for European SMEs

Paulo Rodrigues10 min read

The EU AI Act: A Plain-Language Compliance Guide for European SMEs

You run a small European business. You use AI — maybe a chatbot on your site, a copilot in your code editor, an AI feature buried inside software you already pay for. And somewhere you have read that the EU AI Act can fine companies up to €35 million. That number is real. It is also almost certainly not about you.

This is a plain-language guide to what the EU AI Act actually requires of a small or medium business. Not the lawyer's version — the operator's version: what it is, which parts apply to you, the deadlines that matter, and a concrete list of what to do. Every date, article, and figure below is taken from the regulation itself or from official EU sources, and I have listed them so you can check.

This is educational content, not legal advice. It is written for founders and operators, not lawyers, and it deliberately simplifies. It is also a fast-moving area — a 2026 amendment to the timeline has been agreed but is not yet in force, so it is still settling. For decisions with real exposure, get advice from a qualified professional and verify the current text.

What the EU AI Act actually is

The EU AI Act is Regulation (EU) 2024/1689, the world's first comprehensive law on artificial intelligence. It entered into force on 1 August 2024 and applies across all 27 EU member states. Like the GDPR before it, it reaches beyond Europe: it can apply to a company anywhere if its AI system's output is used in the EU.

The core idea is simple and worth holding onto, because it dissolves most of the panic: the Act is risk-based. It does not regulate "AI" as one thing. It sorts AI uses into tiers and applies heavier rules only where the risk to people is higher. The vast majority of everyday business AI sits at the bottom of that pyramid, where the rules are light.

The four risk tiers

The Act sorts AI into four levels of risk.

1. Unacceptable risk — banned outright. A short, defined list (eight categories in Article 5) of AI practices considered a clear threat to people's safety and rights. These are prohibited entirely. They include:

  • Manipulative or deceptive techniques that materially distort behaviour and cause harm
  • Exploiting vulnerabilities of age, disability, or a specific social or economic situation
  • Social scoring — evaluating people based on social behaviour, leading to unfair treatment
  • Building or expanding facial-recognition databases through untargeted scraping of faces from the internet or CCTV
  • Emotion recognition in the workplace and in education (with narrow medical/safety exceptions)
  • Biometric categorisation to infer sensitive traits like race, political opinion, or sexual orientation

Most small businesses will never touch these — but the emotion-recognition ban is one to know if you have ever been pitched software that claims to read employees' or students' moods.

2. High risk — allowed, but with strict obligations. AI used in areas that can seriously affect health, safety, or fundamental rights. This is where the real compliance burden lives — risk management, documentation, human oversight, conformity assessment. The Annex III use cases most relevant to an SME are:

  • Recruitment and employment — filtering job applications, evaluating candidates, decisions on promotion or task allocation
  • Creditworthiness and credit scoring of individuals (fraud detection is carved out)
  • Access to essential services and benefits — eligibility decisions for healthcare or welfare
  • Education — admissions, grading, and exam monitoring

If your business uses AI for hiring or lending decisions about people, this tier is the one to take seriously.

3. Limited risk — transparency only. AI that interacts with people or generates content. No conformity assessment; the duty is to be honest that AI is involved. This is the tier most SMEs will actually land in, and it is covered by Article 50 (below).

4. Minimal risk — no new rules. Everything else: spam filters, recommendation engines, AI in video games, most productivity tools. Official EU guidance is explicit that the vast majority of AI systems in use fall here. Nothing new is required.

The deadlines that actually matter

The Act does not switch on all at once. It phases in, and — importantly — two of the phases are already in force. Here is the timeline set by Article 113 of the regulation, with the 2026 amendment noted.

DateWhat appliesStatus
1 Aug 2024Regulation enters into forceDone
2 Feb 2025Prohibited practices banned; AI literacy obligation beginsIn force now
2 Aug 2025Governance rules, GPAI model obligations, and the penalty regimeIn force now
2 Aug 2026Transparency obligations (Article 50) applyUpcoming
2 Dec 2027High-risk systems under Annex III (standalone) — proposed deferralAgreed, not yet in force
2 Aug 2028High-risk AI inside regulated products (Annex I) — proposed deferralAgreed, not yet in force

Two things to take from this table.

First, the parts already in force are the parts that apply to most small businesses. The prohibitions, and the obligation that people using AI have a basic understanding of it, have been binding since February 2025. You do not have until 2027 to think about those.

Second, the high-risk deadlines are set to move — but the change is not yet law. The heavy obligations were originally due on 2 August 2026. In 2026 the EU's co-legislators agreed a package known as the Digital Omnibus (proposed by the Commission on 19 November 2025; adopted by the European Parliament on 16 June 2026 and given the Council's final green light on 29 June 2026) that would postpone them — standalone high-risk systems to 2 December 2027, and AI embedded in regulated products to 2 August 2028. But agreed is not the same as in force: as of this writing the package has not yet been published in the EU's Official Journal, and until it is, the original 2 August 2026 date remains the legally binding one. This is exactly the kind of detail that goes stale: treat the later dates as agreed-but-pending, not carved in stone, and verify the current status before you plan around them.

The transparency rules — the ones most SMEs will meet (Article 50)

If any part of the Act touches your business directly, this is probably it. Article 50 applies from 2 August 2026 and requires disclosure in a few specific situations, regardless of risk tier:

  • Chatbots and AI assistants: if people interact directly with an AI system, they must be told they are dealing with AI (unless it is obvious).
  • AI-generated content: the outputs of generative AI must be marked as artificially generated in a machine-readable way. (A short grace period to 2 December 2026 for this marking obligation is part of the same Digital Omnibus package described above — agreed but not yet in force, so treat it as provisional.)
  • Deepfakes: if you publish AI-generated or manipulated image, audio, or video that resembles real people, places, or events, you must disclose that it is artificial — even if there was no intent to deceive.
  • AI-generated text on matters of public interest: must be disclosed as AI-generated when published to inform the public.

For most SMEs this is very manageable: label your chatbot as a bot, and be honest when you publish something an AI made. That is the spirit of the rule.

General-purpose AI (GPAI): mostly not your problem

You will hear a lot about GPAI obligations. For a typical SME, the reassuring news is that these obligations sit with the model providers — the companies that build large general-purpose models — not with you as a user of those models. Providers must supply technical documentation, respect copyright rules, and publish a summary of training content. A model is presumed to have high-impact capabilities — "systemic risk" — when the compute used to train it exceeds 10²⁵ floating-point operations (Article 51), but that is a rebuttable presumption, not an automatic bright line. Such models carry extra duties.

Your practical takeaway: you are almost never the "provider" here. Just keep a record of which AI tools and models you rely on, so you can point to the provider's documentation if asked.

The penalties — and the protection for small companies

The fines are real, and they are tiered by how serious the breach is (Article 99):

  • Prohibited practices (the Article 5 list): up to €35 million or 7% of total worldwide annual turnover, whichever is higher.
  • Other obligations (high-risk duties, transparency, etc.): up to €15 million or 3%, whichever is higher.
  • Supplying incorrect or misleading information to authorities: up to €7.5 million or 1%, whichever is higher.

Now the part written specifically for you. For SMEs and start-ups, the Act flips the calculation: the fine is the amount or the percentage, whichever is lower — the opposite of the "whichever is higher" rule that applies to large companies. A small firm's exposure is capped by its size, not multiplied by it. The €35 million headline is a ceiling for corporations, not a threat aimed at a five-person business.

What an SME actually has to do — a checklist

Here is the practical, do-this-today version.

  1. Inventory your AI. List every AI system you use or build, including AI features baked into software you already pay for. You cannot classify what you have not written down.
  2. Classify each by risk tier. Most will be minimal or limited. Flag anything touching recruitment, lending, education assessment, or essential services (potential high-risk), and anything resembling the prohibited list.
  3. Stop anything prohibited. Check your tools against the Article 5 list. The common trap for a normal business is emotion-recognition software aimed at employees.
  4. Do AI literacy properly. Anyone using AI in your business should understand, at a basic level, what it can and cannot do. This has been required since February 2025 — a short internal briefing and a written note that you did it goes a long way.
  5. Plan your transparency disclosures. From August 2026: label chatbots as AI, and mark or disclose AI-generated content. Decide now how you will do it.
  6. Keep a paper trail. Note which AI tools you use, what for, and who is responsible. Documentation is most of what "governance" means for a small company.
  7. Mind your data (GDPR overlaps here). Do not feed personal data into tools that ship it to places you do not control. The AI Act and the GDPR reinforce each other; solving one often helps the other.
  8. Assign an owner. One person accountable for AI decisions. It does not need to be a new hire — it needs to be a named human.
  9. Get real advice if you are near high-risk. If your AI makes or heavily informs decisions about hiring, credit, or access to services, this is where professional help pays for itself.

Where our approach fits — honestly

We build self-hosted, privacy-first AI, so it would be easy to claim self-hosting makes you AI-Act compliant. It does not, and I would rather say so plainly. The Act regulates what an AI system does and how risky its use is — not where it runs. Hosting a model in Frankfurt instead of Virginia exempts you from nothing.

What ownership genuinely helps with is everything around the obligations:

  • Transparency and documentation are far easier when you can actually see what your system does. A self-hosted stack you understand is one you can accurately describe, log, and disclose — which is most of what Article 50 and the record-keeping duties ask for.
  • Data control overlaps with the GDPR. Keeping personal data on infrastructure you own, instead of shipping it to a third-party model, shrinks your GDPR surface. That is not an AI Act exemption, but AI use tends to expand your data exposure, and owning the path is the cleanest way to keep it contained. We wrote about that discipline in how to make a local model cite only sources it actually read and what our €107 infrastructure looks like.
  • AI literacy becomes real, not performative, when your team runs the stack rather than renting a black box.

The honest summary: self-hosting is not a compliance shortcut. It is a way to make the compliance you owe anyway easier to prove — and to keep your data where the GDPR wants it.

The takeaway

For most European SMEs the EU AI Act is far less frightening than the €35 million headline suggests. You are very likely in the minimal- or limited-risk tier, where the duties are: do not use prohibited AI, make sure your people understand the AI they use, and be honest when AI is involved. The prohibitions and the literacy rule are already in force; transparency arrives in August 2026; the heavy high-risk obligations are years out, and a 2026 package (agreed but not yet in force) would push them further still.

Do the boring, cheap work now — inventory, classify, document, disclose — and the Act becomes what it was designed to be: a floor under responsible AI use, not a trap. And if your business genuinely sits near a high-risk use like hiring or lending, that is the signal to bring in someone who does this for a living.

A final reminder: this guide is educational and simplified, the law is being actively amended, and nothing here is legal advice. Verify every date and requirement against the current regulation or a qualified adviser before you act on it.

Frequently Asked Questions

Does the EU AI Act apply to my small business if I just use ChatGPT or a chatbot?

Almost certainly, but lightly. Most small businesses using off-the-shelf AI fall into the minimal-risk or limited-risk (transparency) tiers, where there is no conformity assessment and no registration. Your real duties are three: do not use any AI on the prohibited list (Article 5), make sure staff who use AI have a basic understanding of it (the AI literacy obligation, in force since 2 February 2025), and disclose AI where transparency rules require it — for example telling people they are talking to a chatbot, and labelling AI-generated content (Article 50). You do not need a high-risk compliance programme unless your AI is used for something like recruitment, credit scoring, or another Annex III use case.

What are the deadlines I actually have to worry about?

Two dates have already passed and are enforceable now: 2 February 2025 (prohibited practices banned, AI literacy required) and 2 August 2025 (governance rules, general-purpose AI model obligations, and the penalty regime). The transparency obligations under Article 50 apply from 2 August 2026. The heavy high-risk obligations were originally due 2 August 2026. In 2026 the EU's co-legislators agreed a package (the 'Digital Omnibus') that would postpone them — standalone high-risk systems (Annex III) to 2 December 2027, and AI built into regulated products (Annex I) to 2 August 2028. Both chambers have adopted it (Parliament on 16 June 2026, Council on 29 June 2026), but as of this writing it has not yet been published in the EU's Official Journal, so it is not yet in force. Until it is, the original dates remain the legally binding ones. Treat the deferrals as agreed-but-pending and verify the current status before relying on them.

Does self-hosting AI in the EU make me AI-Act compliant?

No, and it is important to be honest about this. The AI Act regulates what an AI system does and how risky its use is — not where it is hosted. Self-hosting does not exempt you from anything. What it does do is make the other obligations easier to meet: you can actually see what your system does, keep the logs and documentation that transparency and record-keeping require, and avoid shipping personal data to third-party models (which is a GDPR win, not an AI Act exemption). Ownership helps you comply; it is not compliance by itself.

Ready to automate your business?

We build AI tools and automation systems for European SMEs — from rapid MVPs to production systems, always GDPR-compliant.

it's human stuff

Weekly AI insights for European SMEs. No hype, just what works.

Keep Reading