The EU AI Act is long, and most coverage of it is written for large enterprises and AI model developers. If you run a small or mid-sized company that uses AI tools, or builds modest AI features into its product, much of it won't apply to you. Some of it will.
This guide focuses on what matters for SMBs: the categories that decide your obligations, the rules already in force, the use cases that need care, and a practical plan for the first 90 days. It's general information, not legal advice. For decisions with legal consequences, involve your counsel.
The Act in one paragraph
The AI Act (Regulation (EU) 2024/1689) regulates AI systems according to risk. A small set of practices is prohibited outright. "High-risk" systems, such as AI used in hiring, credit decisions, education or critical infrastructure, carry substantial obligations. Some systems carry transparency obligations, like telling people when they're talking to a chatbot. Everything else, which covers most business use of AI, has few specific obligations beyond general good practice. It applies to companies outside the EU too, if their AI systems are used in the EU.
Are you a provider or a deployer?
This distinction shapes almost everything:
- Provider: you develop an AI system, or have one developed, and put it on the market under your name. If you build an AI feature into a product you sell, you may be a provider of that system.
- Deployer: you use an AI system in your business under your own authority. A company using an AI tool to screen support tickets is a deployer.
Most SMBs are deployers of several AI tools, and some are also providers of an AI feature in their own product. Obligations for deployers are generally lighter.
Be aware that the roles can shift. Under the Act, a deployer can take on provider obligations for a high-risk system, for example by putting its own name on it or by substantially modifying it. If you customize a vendor's system for a high-risk purpose, check which role you end up in.
What applies to most SMBs
AI literacy
Companies that provide or deploy AI systems must take measures to ensure a sufficient level of AI literacy among staff who operate or use them. This has applied since February 2025. In practice: people using AI tools at work should understand what those tools can and can't do, and the risks involved. Training proportionate to how staff use AI is a reasonable way to meet it.
Proportionate is the key word. A sales team using an AI writing assistant needs a short session on accuracy, confidentiality and review. A team operating an AI system that affects customers needs more depth. Keep a record of who was trained and on what.
Prohibited practices
Also in force since February 2025. The prohibited list includes manipulative techniques that cause significant harm, social scoring, and emotion recognition in the workplace (with narrow exceptions). Few SMBs are anywhere near these, but it's worth confirming no tool you use does something on the list. Emotion recognition is the one most likely to appear unexpectedly, for example as a "sentiment" or "engagement" feature in a call-center or video-meeting tool applied to employees.
Transparency obligations
If you run a chatbot or AI assistant that interacts with people, they generally need to be told they're interacting with AI unless it's obvious. AI-generated content such as synthetic images, audio or video may need to be marked. These obligations are among those scheduled to apply from August 2026.
The practical fix is usually small: a clear label on the chat widget, a line in the first message, and a process for marking generated media used in public content.
High-risk use cases
This is where the heavy obligations sit, and where you need to be careful. If you use or build AI for things like recruitment and candidate screening, employee performance evaluation, creditworthiness assessment or access to essential services, check whether it falls into the high-risk categories. Deployers of high-risk systems have obligations around human oversight, monitoring, logging and, in some cases, impact assessments.
The Commission has proposed changes that could adjust some high-risk timelines, so check the current status before planning around specific dates.
Common SMB scenarios
Most companies recognize themselves in one or more of these:
| Scenario | Likely category | What to do |
|---|---|---|
| Staff use AI assistants for writing, research and code | Minimal risk | AI literacy, acceptable-use policy, data rules |
| A chatbot answers customer questions on your website | Transparency | Tell users it's AI; offer a route to a human |
| AI ranks or filters job applicants | Likely high-risk | Human oversight, vendor documentation, legal review |
| Your SaaS product includes an AI summarization feature | Usually minimal, you may be a provider | Document the system; check transparency duties |
| Marketing publishes AI-generated images or video | Transparency | Mark generated content where required |
The categories in this table are typical, not guaranteed. The classification depends on what the system is used for, not on the technology, so the same tool can fall into different categories in different companies.
A practical first 90 days
| Step | What to do | Output |
|---|---|---|
| 1 | Inventory the AI tools in use, including unofficial ones staff use on their own | A list of tools, owners and purposes |
| 2 | Classify each use: prohibited, high-risk, transparency, or minimal | A simple risk register |
| 3 | Write an AI acceptable-use policy | One or two pages staff actually read |
| 4 | Run AI literacy training proportionate to use | Training records |
| 5 | Add AI disclosure to chatbots and assistants | Updated interfaces |
| 6 | Review vendors for data handling and model training terms | Vendor notes and contract updates |
Step 1 usually produces surprises. Staff adopt AI tools faster than policy can follow, and "shadow AI" (tools used without approval, often on personal accounts) is where most unmanaged risk sits.
A short anonymous survey works well for the inventory: "Which AI tools do you use for work, and for what?" People answer more honestly when the goal is visibility, not enforcement.
Questions to ask your AI vendors
Most SMBs will meet their obligations largely through the tools they buy. For each vendor that touches customer, employee or confidential data, ask:
- Where is our data processed and stored, and which subprocessors are involved?
- Is our data used to train or improve models, and can we opt out?
- How long are prompts, files and outputs retained?
- Is the product intended for any high-risk use, and what documentation do you provide for it?
- What logging and human-oversight features are available?
- How will you notify us of significant changes to the model or the product?
Keep the answers with the contract. If a regulator, auditor or enterprise customer asks how you manage AI risk, this file is a large part of the answer.
Don't forget GDPR
For most SMBs, GDPR remains the bigger day-to-day compliance question. If personal data goes into an AI tool, all the usual questions apply: legal basis, data minimization, processor agreements, international transfers and data subject rights. The AI Act adds to GDPR; it doesn't replace it.
A good test for any AI tool: do you know where the data goes, whether it's used to train models, and how long it's kept?
What about penalties?
The Act sets maximum fines in tiers: the highest for prohibited practices, lower tiers for other breaches and for supplying incorrect information to authorities. For SMEs and startups, the cap is the lower of the fixed amount and the percentage of turnover, rather than the higher. That's a meaningful difference, but it doesn't make compliance optional, and for most companies the reputational and contractual consequences arrive sooner than a fine.
What you can deprioritize
Unless you develop general-purpose AI models, the obligations for general-purpose AI model providers aren't yours. If your AI use is limited to productivity tools and low-risk features, you don't need a large compliance program. Proportionate, documented good practice is the goal.
Document as you go
Regulators and customers both look for evidence, not intentions. A dated inventory, a policy, training records and vendor answers show a reasonable, proportionate approach.
The short version
Know what AI you use. Classify it. Train your people. Tell users when they're talking to AI. Be careful around anything touching hiring, credit or access to services. Ask your vendors the right questions and keep the answers. Keep GDPR in view. That covers most of what the AI Act asks of a typical SMB.