← Back to overview

Which AI risk category applies to your SME?

The EU AI Act sorts every AI use case into one of four risk categories. Here's how to find yours and what it requires.

Which AI risk category applies to your SME?

Every AI use case an SME runs falls into one of four EU AI Act risk categories — unacceptable, high, limited (transparency), or minimal. Most SME tools land in the bottom two, but "minimal" still isn't "no obligations", and getting the classification wrong is the single most common AI Act mistake among smaller companies.

Short answer in 3 minutes: not sure whether the AI Act, NIS2 or the GDPR applies to you? Take the free AI Compliance & Risk Scan — you'll see your exposure per obligation immediately, with an honest report. No sales pitch.

The four risk categories

The AI Act classifies every AI system by the risk it poses to people's rights and safety:

What the Digital Omnibus changed

Under the Digital Omnibus, obligations for high-risk AI systems were pushed back to 2 December 2027, giving SMEs more runway to prepare. That delay does not touch Article 4 (AI literacy) or Article 50 (transparency for chatbots and generated content) — both have been in force since 2 August 2026, regardless of company size.

What this means in practice

A few concrete steps cover most of the obligations that actually apply to SMEs:

For the full timeline of what's active and what's coming, see our AI Act delay explainer.

Key takeaway

Classifying your AI use case correctly is the first real step toward AI Act compliance — and for most SMEs it takes an afternoon, not a project. Want to know exactly where your applications stand? Sign up for our free compliance scan and get a clear picture of your current status.

Schedule a compliance conversation