Skip to content
NewSecurity Audit for AI-Built Apps. Fixed scope, clear report
GeekTech
AI Governance

EU AI Act: What SMBs Actually Need to Know

A practical guide to the EU AI Act for small and mid-sized companies: which rules apply to you, what to do first, and what you can safely deprioritize.

Updated 6 min read

GeekTech Engineering Team18 years building and securing software

The EU AI Act is long, and most coverage of it is written for large enterprises and AI model developers. If you run a small or mid-sized company that uses AI tools, or builds modest AI features into its product, much of it won't apply to you. Some of it will.

This guide focuses on what matters for SMBs: the categories that decide your obligations, the rules already in force, the use cases that need care, and a practical plan for the first 90 days. It's general information, not legal advice. For decisions with legal consequences, involve your counsel.

The Act in one paragraph

The AI Act (Regulation (EU) 2024/1689) regulates AI systems according to risk. A small set of practices is prohibited outright. "High-risk" systems, such as AI used in hiring, credit decisions, education or critical infrastructure, carry substantial obligations. Some systems carry transparency obligations, like telling people when they're talking to a chatbot. Everything else, which covers most business use of AI, has few specific obligations beyond general good practice. It applies to companies outside the EU too, if their AI systems are used in the EU.

Are you a provider or a deployer?

This distinction shapes almost everything:

  • Provider: you develop an AI system, or have one developed, and put it on the market under your name. If you build an AI feature into a product you sell, you may be a provider of that system.
  • Deployer: you use an AI system in your business under your own authority. A company using an AI tool to screen support tickets is a deployer.

Most SMBs are deployers of several AI tools, and some are also providers of an AI feature in their own product. Obligations for deployers are generally lighter.

Be aware that the roles can shift. Under the Act, a deployer can take on provider obligations for a high-risk system, for example by putting its own name on it or by substantially modifying it. If you customize a vendor's system for a high-risk purpose, check which role you end up in.

What applies to most SMBs

AI literacy

Companies that provide or deploy AI systems must take measures to ensure a sufficient level of AI literacy among staff who operate or use them. This has applied since February 2025. In practice: people using AI tools at work should understand what those tools can and can't do, and the risks involved. Training proportionate to how staff use AI is a reasonable way to meet it.

Proportionate is the key word. A sales team using an AI writing assistant needs a short session on accuracy, confidentiality and review. A team operating an AI system that affects customers needs more depth. Keep a record of who was trained and on what.

Prohibited practices

Also in force since February 2025. The prohibited list includes manipulative techniques that cause significant harm, social scoring, and emotion recognition in the workplace (with narrow exceptions). Few SMBs are anywhere near these, but it's worth confirming no tool you use does something on the list. Emotion recognition is the one most likely to appear unexpectedly, for example as a "sentiment" or "engagement" feature in a call-center or video-meeting tool applied to employees.

Transparency obligations

If you run a chatbot or AI assistant that interacts with people, they generally need to be told they're interacting with AI unless it's obvious. AI-generated content such as synthetic images, audio or video may need to be marked. These obligations are among those scheduled to apply from August 2026.

The practical fix is usually small: a clear label on the chat widget, a line in the first message, and a process for marking generated media used in public content.

High-risk use cases

This is where the heavy obligations sit, and where you need to be careful. If you use or build AI for things like recruitment and candidate screening, employee performance evaluation, creditworthiness assessment or access to essential services, check whether it falls into the high-risk categories. Deployers of high-risk systems have obligations around human oversight, monitoring, logging and, in some cases, impact assessments.

The Commission has proposed changes that could adjust some high-risk timelines, so check the current status before planning around specific dates.

Common SMB scenarios

Most companies recognize themselves in one or more of these:

ScenarioLikely categoryWhat to do
Staff use AI assistants for writing, research and codeMinimal riskAI literacy, acceptable-use policy, data rules
A chatbot answers customer questions on your websiteTransparencyTell users it's AI; offer a route to a human
AI ranks or filters job applicantsLikely high-riskHuman oversight, vendor documentation, legal review
Your SaaS product includes an AI summarization featureUsually minimal, you may be a providerDocument the system; check transparency duties
Marketing publishes AI-generated images or videoTransparencyMark generated content where required

The categories in this table are typical, not guaranteed. The classification depends on what the system is used for, not on the technology, so the same tool can fall into different categories in different companies.

A practical first 90 days

StepWhat to doOutput
1Inventory the AI tools in use, including unofficial ones staff use on their ownA list of tools, owners and purposes
2Classify each use: prohibited, high-risk, transparency, or minimalA simple risk register
3Write an AI acceptable-use policyOne or two pages staff actually read
4Run AI literacy training proportionate to useTraining records
5Add AI disclosure to chatbots and assistantsUpdated interfaces
6Review vendors for data handling and model training termsVendor notes and contract updates

Step 1 usually produces surprises. Staff adopt AI tools faster than policy can follow, and "shadow AI" (tools used without approval, often on personal accounts) is where most unmanaged risk sits.

A short anonymous survey works well for the inventory: "Which AI tools do you use for work, and for what?" People answer more honestly when the goal is visibility, not enforcement.

Questions to ask your AI vendors

Most SMBs will meet their obligations largely through the tools they buy. For each vendor that touches customer, employee or confidential data, ask:

  1. Where is our data processed and stored, and which subprocessors are involved?
  2. Is our data used to train or improve models, and can we opt out?
  3. How long are prompts, files and outputs retained?
  4. Is the product intended for any high-risk use, and what documentation do you provide for it?
  5. What logging and human-oversight features are available?
  6. How will you notify us of significant changes to the model or the product?

Keep the answers with the contract. If a regulator, auditor or enterprise customer asks how you manage AI risk, this file is a large part of the answer.

Don't forget GDPR

For most SMBs, GDPR remains the bigger day-to-day compliance question. If personal data goes into an AI tool, all the usual questions apply: legal basis, data minimization, processor agreements, international transfers and data subject rights. The AI Act adds to GDPR; it doesn't replace it.

A good test for any AI tool: do you know where the data goes, whether it's used to train models, and how long it's kept?

What about penalties?

The Act sets maximum fines in tiers: the highest for prohibited practices, lower tiers for other breaches and for supplying incorrect information to authorities. For SMEs and startups, the cap is the lower of the fixed amount and the percentage of turnover, rather than the higher. That's a meaningful difference, but it doesn't make compliance optional, and for most companies the reputational and contractual consequences arrive sooner than a fine.

What you can deprioritize

Unless you develop general-purpose AI models, the obligations for general-purpose AI model providers aren't yours. If your AI use is limited to productivity tools and low-risk features, you don't need a large compliance program. Proportionate, documented good practice is the goal.

Document as you go

Regulators and customers both look for evidence, not intentions. A dated inventory, a policy, training records and vendor answers show a reasonable, proportionate approach.

The short version

Know what AI you use. Classify it. Train your people. Tell users when they're talking to AI. Be careful around anything touching hiring, credit or access to services. Ask your vendors the right questions and keep the answers. Keep GDPR in view. That covers most of what the AI Act asks of a typical SMB.

Insights

Related insights

More on AI Governance →
  • AI Governance

    How to Write a Company AI Use Policy

    A practical structure for an AI acceptable-use policy that staff will read: approved tools, data rules, review duties, disclosure and new-tool requests.

    5 min read

  • AI Engineering

    When Does a Company Need a Fractional AI CTO?

    What a fractional AI CTO does, the signs you need one, how it compares with hiring or consultants, and how to set up the engagement so it delivers.

    5 min read

  • AI Engineering

    RAG vs Fine-Tuning: How to Choose

    When retrieval-augmented generation is the right approach, when fine-tuning earns its cost, and why most business AI features should start with neither.

    6 min read

Get practical AI insights, monthly

AI security, automation and governance, written by engineers. No spam, unsubscribe any time.

Book a free 30-min call