The EU AI Act for SMEs: What Applies to You
Most of it does not apply to you. Almost every SME is a deployer rather than a provider, and the only date currently biting is the August 2026 transparency duty. What the tiers mean in business terms, where four common systems land, and the deadline that moved to December 2027.

Most of it doesn’t apply to you.
If you run a 50 to 500-person European company and you bought a chatbot, a document-processing tool, or an internal assistant, the EU AI Act for SMEs comes down to two obligations you already have and one you probably don’t. You are almost certainly a deployer, not a provider. Most of what you deploy is not high-risk. The heavy compliance machinery that fills the consulting decks, conformity assessments, technical files, registration in an EU database, attaches to a category most SMEs never touch. Knowing which side of that line you sit on takes about twenty minutes and saves a great deal of money.
The AI Act risk tiers, without the legal vocabulary
The Act sorts systems by what happens to a person when the system gets it wrong. Four bands. Prohibited covers things nobody reading this is building: social scoring by public authorities, manipulative systems that exploit vulnerability, untargeted scraping of facial images. Those have been banned since 2 February 2025. High-risk is the band that carries the real burden, and it is defined by use, not by technology: AI that decides who gets hired, who gets credit, who gets into a school, or that runs as a safety component in critical infrastructure. Limited risk covers systems people interact with directly, chatbots and generative tools, where the duty is disclosure rather than assessment. Minimal risk is everything else, which in practice is most business software, and carries no obligations at all.
The distinction that matters more than the tier is the role. A provider builds an AI system and puts it on the market under its own name. A deployer uses one under its own authority. If you bought a tool and configured it, you are a deployer, and deployer duties are a fraction of provider duties even inside the high-risk band. Buy a CV-screening product from a vendor and the vendor carries the conformity assessment; you carry human oversight, monitoring, and telling candidates the system is in use. Build that same screening tool yourself, or rebrand a vendor’s tool as your own, and you have become the provider. That is the line most people cross without noticing.
Deployer obligations and when each one bites
The AI Act does not land at once. It phases in, and one of the phases moved in 2026, which means a large amount of published guidance is now wrong. Here is the current state.
- 2 February 2025, prohibited practices. In force. Also an AI-literacy duty: staff who operate AI systems on your behalf need enough training to understand what the system does.
- 2 August 2025, general-purpose AI models. Obligations landed on the model makers, OpenAI, Google, Anthropic, Mistral, not on you. Relevant to you only as a question to ask a vendor.
- 2 August 2026, transparency (Article 50). Live now. Tell people when they are talking to an AI rather than a person. Mark synthetic audio, image, video and text as machine-generated. Disclose deepfakes. This is the one that touches ordinary SMEs, because it covers the customer-service bot you already run.
- 2 December 2026, marking grace period. Generative systems already on the market before August 2026 have until this date to meet the machine-readable marking requirement.
- 2 December 2027, stand-alone high-risk systems. This was 2 August 2026 until the Digital Omnibus deferred it by sixteen months. Parliament endorsed the change on 16 June 2026 by 423 votes to 57; the Council gave final approval on 29 June 2026. If a guide tells you high-risk obligations start in August 2026, it was written before that vote.
- 2 August 2028, AI embedded in regulated products. Machinery, medical devices, toys, anything already covered by EU product-safety law.
Read that list again with your own stack in mind and the practical conclusion is usually the same: the only date that currently constrains a typical SME is 2 August 2026, and the duty it imposes is disclosure. You have to say the quiet part out loud. That is a copy change and a config change, not a compliance programme.
Four systems SMEs actually run, sorted
Customer-service chatbot: limited risk. Disclosure only. The user has to know it is a machine. In practice that means a line in the opening message, not a legal notice. If it hands off to a human, say that too. Our own audits keep finding bots that hide the handover, which is a trust problem before it is an AI Act compliance problem.
Document processing: usually minimal risk. Extracting fields from invoices, classifying inbound post, summarising contracts for a human to review. No tier attaches as long as the output goes to a person who decides. The LexAlert build we shipped for a legal-monitoring team works exactly this way: the system reads and ranks legislative changes, and a lawyer decides what matters. You can see how that is structured in the LexAlert case study. Keep the human decision in the loop and the regulatory question mostly goes away.
CV screening: high-risk, and the one to be careful with. Employment is named in Annex III. If a system filters, ranks, or scores candidates, it is high-risk regardless of how simple the model is. A keyword filter with a threshold counts. You have until 2 December 2027, and as a deployer your duties are human oversight, keeping the logs, and informing candidates. This is the use case where we tell clients to get actual legal advice rather than take ours.
Internal assistant over company documents: minimal risk. Staff asking questions of a knowledge base sits outside the tiers. The real obligations here are GDPR ones, not AI Act ones, which is a distinction worth holding: most of what frightens people about deploying AI internally is data protection wearing a different hat. Our case studies are all in this shape, systems that inform a human rather than replace one.
Four things to write down this month
Whatever tier you land in, the work that gets expensive is reconstruction. Nobody remembers in 2027 which model version the vendor shipped in 2026, or who signed off on the prompt that went to customers. Four artefacts cover most of it, and a competent operations person can assemble them in an afternoon.
- A system inventory. One row per AI system: what it does, which vendor or model sits behind it, what data goes in, who in your company owns it. Most SMEs we audit cannot produce this, and half the value is discovering the two tools nobody knew were running.
- The human-oversight note. For each system, one sentence naming the person or role who reviews the output and what they can override. This is the single artefact that proves the point you will most need to prove.
- Vendor answers in writing. Ask each vendor whether they are the provider for AI Act purposes, where processing happens, and whether your data trains their models. Keep the reply. You are relying on their compliance, so you want it on the record.
- A dated change log. When you changed a prompt, swapped a model, or widened a system’s scope. Three lines per change is enough. Version drift is what makes an incident hard to explain a year later.
When this article stops being enough
You are probably fine if every AI system you run informs a human who then decides, you tell users when they are talking to a machine, and you are not touching hiring, credit, education, biometrics, or critical infrastructure. That describes most of the companies we audit. Write down what you deploy, what it does, and who reviews its output, and you have most of a compliance file for the cost of an afternoon. Doing it now costs nothing; reconstructing it in 2027 costs real money.
Stop relying on this article, and on us, in three situations. If your system makes or materially influences a decision about a person in one of the Annex III domains, get a lawyer. If you rebrand a vendor’s model as your own product, you may have become a provider, and that is a different regime. If you sell into a regulated product category, the 2028 date and your existing product-safety obligations interact in ways that need specialist advice. This is informational, not legal advice. We build systems and we read the regulation because we have to; we are not your counsel, and for high-risk cases you want one.
- Role beats tier. Almost every SME is a deployer rather than a provider, and deployer duties are a fraction of provider duties even inside the high-risk band.
- The only date currently constraining a typical SME is 2 August 2026, and the duty is disclosure: say when a user is talking to an AI, and mark generated content.
- High-risk obligations moved from 2 August 2026 to 2 December 2027 via the Digital Omnibus. Guidance published before June 2026 has the wrong date.
- Hiring is the trap. CV screening is high-risk however simple the model, and a keyword filter with a threshold counts.
- Keeping a human as the decider is the single design choice that removes most regulatory weight, and it usually produces a better system anyway.
Working out which EU AI Act obligations apply to your systems is an inventory problem before it is a legal one: what you run, what it decides, and who reviews it. That inventory is the first morning of an audit, and it is also the point where we tell some clients their AI plan is fine and needs no further spending. If you want the sequencing rather than the regulation, the AI readiness checklist covers what to have in place before you build anything at all. Which of your systems currently decides something about a person without one of your people reading the output?
Book your AI audit

