← Back to overview

EU AI Act: what should your SME do now?

Practical checklist for SMEs to comply with the EU AI Act: AI literacy, risk classification, transparency and compliance.

EU AI Act: what should your SME do now?

The EU AI Act is no longer a future concern. The law is in force, deadlines are active, and SMEs that use AI — which by now is most of them — fall under it too. Here's what to do now, in order of urgency.

Short answer in 3 minutes: not sure whether the AI Act, NIS2 or the GDPR applies to you? Take the free AI Compliance & Risk Scan — you'll see your exposure per obligation immediately, with an honest report. No sales pitch.

Quick recap: what is the EU AI Act?

A European law that classifies AI systems by risk (unacceptable, high, limited, minimal) and attaches obligations accordingly. The higher the risk, the more rules apply. Most SME use cases fall under "limited" or "minimal" — but that does not mean "no obligations".

The law rolls out in phases. The first obligations (a ban on unacceptable AI practices, AI literacy for staff) have been active since February 2025. Since 2 August 2026, the obligations for "high-risk" AI systems (Annex III) are also in force — the final phase, covering high-risk AI embedded in regulated products (Annex I), follows in August 2027.

Risk 1 — Ban on unacceptable AI

Banned since February 2025:

For most SMEs: not applicable. But check that none of your tools unintentionally fall into these categories — especially HR tech used for recruitment and performance analysis.

Risk 2 — AI literacy for staff (mandatory NOW)

Since February 2025 you're required to provide staff who use or deploy AI systems with "sufficient AI literacy". This applies to ALL companies that use AI, regardless of size.

What "sufficient" means depends on role and use case — but in practice: staff need to understand what the AI does, its limitations, and how to critically assess its output. An employee using ChatGPT in a spreadsheet falls under this too.

What you can do right now:

Risk 3 — High-risk AI (mandatory since August 2026)

High-risk is defined strictly: AI in recruitment and HR decisions, credit scoring, education assessment, critical infrastructure, legal decision-support, and similar. If you're active in any of these, since 2 August 2026 heavy obligations apply: risk analysis, data quality, human oversight, technical documentation, and registration in an EU database.

Most SME use cases do NOT fall in this category. But if you use AI for recruitment screening, loan assessment or medical diagnosis — you do, and those obligations are now actively enforceable, not future plans.

Risk 4 — Transparency for chatbots and generated content

If you use a chatbot, the user must know they're talking to AI. If you publish AI-generated content (images, video), it must be recognisable as such. Both are relatively simple to fix — a disclaimer under the chatbot, a watermark on the image.

The practical checklist for 2026

  1. Build an inventory: which AI systems do we use (in-house + purchased)?
  2. Classify risk: unacceptable / high-risk / limited / minimal
  3. Train staff on AI literacy (mandatory NOW)
  4. Document policy: GDPR + AI Act + internal guidelines in one document
  5. Appoint an AI owner (small company: a role; larger: a function)
  6. Run an annual review of AI use and risks

What we can do for you

Our Responsible AI service covers this end to end: inventory, risk classification, policy and training. For SMEs we keep it pragmatic — no 200-page compliance document, but a workable framework that fits your scale.

Key takeaway

The EU AI Act is not a reason to panic, but it is a reason to act. Starting with an AI inventory and staff training is the most important step — those two cover 80% of the obligations for most SMEs.

Get started

Want to be EU AI Act-ready in 4 weeks?
We run a complete inventory of your AI use, classify the risks, write tailored policy and train your team — including practical templates you can maintain yourself afterwards.

Schedule a compliance conversation