- 📅 2 August 2026 activated Article 50 transparency rules and regulator enforcement powers, while full Annex III high-risk obligations no longer start until 2 December 2027.
- 📊 17% of EU small enterprises used AI in 2025, so the compliance question now reaches ordinary businesses, not only model developers and large technology firms.
- 🏢 Provider versus deployer status matters more than headcount: rebranding, substantial modification, or changing an AI system’s purpose can shift a business into provider duties.
- 🛡️ SMEs receive a crucial penalty safeguard: Article 99 applies the lower of the fixed fine ceiling or turnover percentage, alongside simplified documentation and sandbox support.
- ✅ A practical first month should produce an AI register, role classification, prohibited-use check, Article 50 review, AI literacy record, data safeguards, and vendor evidence file.
I would not treat the EU AI Act for small business as a 2027 problem: the heaviest high-risk obligations were postponed, but several rules that affect ordinary firms are already live and enforceable. As of 28 August 2026, a small company using AI for marketing, customer support, analysis, recruitment, or internal productivity needs to separate what applies now from what applies later, then document that judgement rather than buy a generic compliance package.
That distinction matters because small-business adoption is no longer marginal. Eurostat reports that 17.0% of EU small enterprises used AI technologies in 2025, compared with 30.4% of medium enterprises and 55.0% of large enterprises. Among small enterprises that considered AI but did not adopt it, 54.8% cited lack of clarity about legal consequences and 52.5% cited data-protection or privacy concerns. The regulatory uncertainty is therefore an operating constraint, not an abstract legal debate (Eurostat, 2026).
The post-Omnibus timeline also changed the centre of gravity. Article 50 transparency obligations apply from 2 August 2026, Article 4 AI literacy has applied since February 2025 and is now subject to national supervision, while the core Annex III high-risk regime was moved to 2 December 2027 and product-embedded Annex I high-risk duties to 2 August 2028 (European Commission, 2026a; European Parliament & Council, 2024/2026).
For a lean business, the sensible response is a small control system: know which AI is in use, know whether you are a provider or deployer, block prohibited practices, train people to recognise tool-specific risk, check transparency duties, keep personal data under GDPR controls, and obtain evidence from vendors. This guide builds that system without pretending every SME needs an enterprise governance department.
EU AI Act for Small Business: What Applies Now
The first compliance decision is temporal. Regulation (EU) 2024/1689 became generally applicable on 2 August 2026, but the amended Article 113 now staggers important parts of the regime. This means a small firm should not use a single checklist marked simply ‘AI Act compliant’. It needs a date-sensitive register that distinguishes current duties, future high-risk duties, and obligations that belong mainly to the vendor rather than the customer.
The rules already relevant to many ordinary businesses include Article 4 AI literacy, the prohibited-practice regime, and Article 50 transparency. National market surveillance authorities can supervise Article 4 and Article 50, while the Commission’s AI Office has its own role for general-purpose AI and certain systems built on such models. If your team uses a commercial assistant to draft sales copy, summarise calls, analyse spreadsheets, or help with coding, that use is not automatically high-risk. It still belongs in your inventory because literacy, data protection, contractual limits, and some transparency duties can apply.
This is why older coverage needs to be read with dates attached. Our earlier EU AI Act deadline reporting captured the pre-Omnibus expectation that high-risk requirements would arrive in August 2026. The final 2026 amendment changed that timetable before the original date arrived. A good compliance file should record the source and date behind every deadline because this law has already demonstrated that implementation sequencing can move.
“a clear, risk-based and durable framework for trustworthy AI”
Henna Virkkunen, Executive Vice-President, European Commission, 31 July 2026
Henna Virkkunen, the European Commission Executive Vice-President responsible for technology policy, presented the Act on 31 July 2026 as a framework intended to combine legal certainty with public protection. For a small business, the risk-based design is the operative point. The fastest route to over-compliance is to copy a multinational control framework without first classifying the actual use cases on your own systems.
The 2026 Timeline Changed, Not the Whole Law
The AI Omnibus did not cancel the AI Act. It redistributed when specific obligations become enforceable and added targeted simplifications. The consolidated Article 113 says the core high-risk requirements in Chapter III Sections 1 to 3 apply from 2 December 2027 for Annex III systems and from 2 August 2028 for high-risk systems tied to regulated products in Annex I. Article 50, by contrast, applies now. Certain new prohibited practices added by the 2026 amendment begin on 2 December 2026 (European Parliament & Council, 2024/2026; European Commission, 2026b).
| Date | What Applies | Small-Business Implication | Status |
| 2 February 2025 | Article 4 AI literacy and original Chapter II prohibitions | Training and prohibited-use screening should already exist | Live |
| 2 August 2025 | GPAI, governance and selected enforcement provisions | Mainly relevant to model providers and governance ecosystem | Live |
| 27 July 2026 | Regulation (EU) 2026/1744 entered into force | Omnibus amendments changed deadlines and SME simplifications | Live |
| 2 August 2026 | General AI Act application, Article 50 transparency and broader enforcement powers | Immediate review of transparency, roles and evidence | Live |
| 2 December 2026 | Certain new prohibited practices and legacy-system Article 50(2) marking deadline | Check affected content systems and new Article 5 prohibitions | Upcoming |
| 2 December 2027 | Annex III high-risk Chapter III Sections 1 to 3 | Hiring and other Annex III workflows need full readiness | Future |
| 2 August 2028 | Annex I product-related high-risk Chapter III Sections 1 to 3 | Regulated-product providers receive a longer runway | Future |
The practical consequence is a two-speed programme. During 2026, most small firms should prioritise visible, current duties and create the evidence they will later reuse for higher-risk governance. Firms that recruit at scale, provide essential services, sell regulated products, or build AI into customer-facing products should also map future high-risk exposure now, because the lead time for data controls, vendor evidence, human oversight, logging, and contracting is measured in months rather than days.
The broader 2026 AI regulation landscape is also worth keeping in view. The AI Act sits beside GDPR, consumer protection, employment law, product safety, cybersecurity obligations, and sector rules. A postponed AI Act deadline does not postpone those other duties. This is especially relevant when a tool uses personal data or influences decisions about workers and customers.
Start With Your Legal Role, Not Your Headcount
Small-business owners often ask whether an SME exemption exists. The better question is what role the firm plays for each AI system. The Act distinguishes providers, deployers, importers, distributors, product manufacturers, and actors in the general-purpose AI value chain. An organisation that simply uses a third-party system under the provider’s intended purpose is usually a deployer. A business that develops and markets a system under its own name is normally a provider. The duties can be very different.
Article 25 contains the most important role-drift trap. For high-risk AI, a deployer, importer, distributor, or other third party can become the provider if it puts its own name or trademark on the system, makes a substantial modification while it remains high-risk, or changes the intended purpose of a non-high-risk system so that it becomes high-risk. The legal consequence is larger than a branding detail because provider obligations include the high-risk compliance architecture in Article 16 and related provisions (AI Act Service Desk, Article 25).
That makes white-labelling and repurposing governance decisions. A recruitment consultancy, for example, should not assume that adding its brand to a high-risk screening system is legally neutral. A software agency that takes a general assistant and repurposes it into a system used for an Annex III decision should obtain advice before deployment. Our analysis of AI governance as an operating problem reaches the same organisational conclusion: who owns a system and who can change its purpose must be explicit.
| Scenario | Likely Role | Duty Level | Key Action |
| Staff use a third-party writing assistant for approved drafting | Deployer | Usually lower-risk use | Inventory, literacy, GDPR/data controls, output review |
| Business sells its own AI service under its brand | Provider | Provider duties depend on system classification | Document intended purpose and applicable provider obligations |
| Business rebrands an existing high-risk system | Provider under Article 25 | High-risk provider stack when applicable | Obtain documentation and assess conformity responsibilities |
| Business materially modifies a high-risk system | Potential provider under Article 25 | High-risk provider stack when applicable | Document modification and seek specialist assessment |
| Business repurposes a non-high-risk system into an Annex III use | Potential provider under Article 25 | High-risk provider stack when applicable | Stop and classify before deployment |
For each entry in the AI register, record the vendor, intended purpose, users, affected people, data categories, whether the business modifies the system, and the firm’s role. That one row often resolves more ambiguity than a long policy statement.
EU AI Act for Small Business Role Test
Use a role test before a risk test. Ask who designed the system, whose name appears on it, whether your business changes the model or workflow materially, whether you alter its intended purpose, and whether the resulting use falls into a high-risk category. The answer is system-specific. The same company can be a deployer for a writing assistant and a provider for a separately branded AI service it sells to clients.
Most Everyday AI Use Is Lower Risk, but Context Decides
For many SMEs, everyday generative AI sits outside the Act’s high-risk categories. Drafting an internal email, brainstorming a campaign, summarising public research, preparing a first-pass product description, or generating code suggestions is not high-risk merely because the tool is powerful. Risk classification turns on the use and context, not on whether the product is called generative AI, a copilot, or an agent.
The boundary becomes more serious when an AI system materially affects access to employment, education, certain essential services, law enforcement, migration, justice, or other Annex III areas. A hiring workflow illustrates the difference. Asking an assistant to rewrite a vacancy description is different from using AI to rank candidates. The latter can fall into the high-risk framework depending on the precise function and classification rules. Even before the delayed high-risk obligations apply, GDPR, discrimination law, employment rules, and contractual duties can constrain the processing.
The most useful purchasing discipline is therefore to keep the tool stack small and the use cases named. Our small-business AI stack guide argues for choosing tools around governed workflows rather than collecting subscriptions. The legal version of that principle is equally practical: approve a specific purpose, data type, and user group for each tool. Do not approve a brand in the abstract.
Eurostat’s 2025 data adds a useful caution. Among small enterprises that had considered AI, lack of relevant expertise was the most common barrier, cited by 70.9%. Legal clarity and privacy concerns followed close behind. That combination explains why a narrow approved-use catalogue often works better than a fifty-page policy. It gives staff enough specificity to act while creating obvious escalation points for sensitive uses (Eurostat, 2026).
AI Literacy Is Already a Live Duty
Article 4 is the rule most likely to surprise a small business because it is broad, already applicable, and deliberately flexible. The Commission’s updated Q&A says providers and deployers must take measures to support AI literacy for staff and other people using AI systems on their behalf. The 2026 amendment removed the idea that a particular ‘sufficient’ level must be guaranteed, but it did not remove the obligation itself (European Commission, 2026c).
The same Q&A gives a highly practical example: a company whose employees use ChatGPT for advertising text or translation still needs to address risks such as hallucination. It also says there is no mandatory certificate, no prescribed one-size-fits-all course, and no requirement to create an AI officer or governance board merely to satisfy Article 4. Internal records of training or guidance can form part of the evidence.
For a ten-person business, that suggests a role-based programme rather than an annual compliance theatre. Everyone who uses approved AI should understand what systems the company permits, what data may be entered, how to verify outputs, when disclosure may be needed, and when to escalate. Staff using AI for finance, hiring, health-related services, customer decisions, or public-interest content need deeper scenario training. Contractors acting under the business’s responsibility may also need appropriate literacy measures.
The gap is operational as much as educational. The enterprise AI control gap reported elsewhere on this site shows what happens when adoption outpaces governance. A small company can prevent the same pattern cheaply by combining a one-page acceptable-use standard, short scenario training, and a record showing who completed it.
The Commission points SMEs towards more than 200 European Digital Innovation Hubs, with nine in ten already providing AI-focused services, and notes that the AI Skills Academy began operating on 1 May 2026. Those support channels are useful because Article 4 is context-specific by design, not because a particular external certificate is legally required.
Article 50 Transparency: What Small Firms Must Actually Label
Article 50 is now one of the most concrete parts of the regime. The first mistake is to assume every obligation belongs to the company buying an AI tool. Article 50(1), for example, is framed as a provider duty: providers of systems that directly interact with people must design them so people are informed they are interacting with AI unless that fact is obvious. A small business deploying a third-party chatbot should still verify that the vendor supports compliant disclosure, but it should not casually describe the provider’s design obligation as its own primary statutory duty (European Commission, 2026d).
Deployers have direct duties in other cases. A deployer of an emotion-recognition or biometric-categorisation system must inform exposed people about its operation. A deployer publishing a deepfake must provide a clear human-perceivable disclosure, not merely rely on the provider’s machine-readable marking. A deployer publishing AI-generated or manipulated text to inform the public on a matter of public interest must label it unless the text has undergone substantive human review or editorial control with legal responsibility for publication.
| Use Case | Primary Legal Actor | Transparency Rule | SME Action |
| Direct AI interaction such as a chatbot | Provider for Article 50(1) | System designed to inform users unless AI interaction is obvious | Contract-check vendor design and test the live experience |
| Synthetic text, image, audio or video generation | Provider for Article 50(2) | Machine-readable marking and detectability, subject to scope and exemptions | Request documentation if deploying the tool |
| Emotion recognition or biometric categorisation | Deployer for Article 50(3) | Inform exposed natural persons | Treat as sensitive and obtain specialist review |
| Deepfake publication | Deployer for Article 50(4) | Clear human-perceivable disclosure | Add visible or audible label at first exposure |
| AI text on a matter of public interest | Deployer for Article 50(4) | Label unless qualifying substantive human review/editorial control applies | Keep editorial review and responsibility evidence |
That last exception is narrower than a proofreading pass. The Commission says spell-checking or grammatical correction is not enough. A real reviewer must examine the substance, and editorial control means authority to approve, change, or reject content on substantive grounds. This distinction matters for agencies, publishers, advisers, and professional firms producing public-facing material.
Customer service creates another practical interface. A business procuring an agent should ask whether the product clearly discloses AI interaction, how it preserves that disclosure across channels, and whether humans can take over. Our customer-service AI agent test shows why governance and escalation should be part of procurement rather than added after launch.
For systems placed on the market before 2 August 2026, the limited grace period in Article 50 concerns the provider’s machine-readable marking duty under Article 50(2), which moves to 2 December 2026 for those legacy systems. It is not a general Article 50 holiday (European Commission, 2026d).
High-Risk AI Is Delayed, but Preparation Still Matters
The postponement gives SMEs time, not immunity. Annex III high-risk requirements in the affected Chapter III sections now apply from 2 December 2027, while the comparable duties for Annex I product-related high-risk systems begin on 2 August 2028. The Commission linked the delay to the availability of standards, guidance, and implementation infrastructure needed for effective compliance (European Commission, 2026a).
For a deployer of a future high-risk system, Article 26 is the operational centre. It addresses use according to instructions, competent human oversight, the relevance of input data that the deployer controls, monitoring, incident escalation, retention of automatically generated logs under the deployer’s control for at least six months where applicable, and workplace notification in specified circumstances. The exact obligations should be checked against the consolidated text when the delayed provisions become applicable because guidance and standards are still developing.
For a provider, the stack is heavier: risk management, data governance, technical documentation, record-keeping, transparency information, human oversight design, accuracy, robustness, cybersecurity, quality management, conformity work, registration, and post-market responsibilities. SMEs benefit from simplified paths in parts of this framework, but simplification is not exemption.
This is also where product choice affects future workload. Our Copilot and ChatGPT business guide treats enterprise governance as a core selection factor because permissions, auditability, data boundaries, and admin controls vary by environment. A business expecting to place AI into a consequential workflow should collect vendor documentation now, while it still has time to replace a tool that cannot provide the evidence needed later.
“Europe can lead on AI safety without adding additional burden to its companies.”
Cecilia Bonefeld-Dahl, Director General, DIGITALEUROPE, 7 May 2026
Cecilia Bonefeld-Dahl, Director General of DIGITALEUROPE, welcomed the May 2026 simplification agreement while continuing to press for lower administrative burden. The final SME test will be whether the simplified compliance mechanisms make that balance real in day-to-day implementation.
GDPR Still Governs the Data Before the AI Act Does
An AI Act classification does not answer the data-protection question. If a small firm puts personal data into an AI system, the GDPR analysis still needs a lawful basis, purpose limitation, data minimisation, security, retention logic, processor or controller allocation, international-transfer analysis where relevant, and safeguards around automated decisions. The fact that an AI use is ‘minimal risk’ under the AI Act does not make personal-data processing lawful under GDPR.
This is especially important for generative AI because staff can turn a low-risk tool into a high-privacy workflow simply by pasting customer records, HR material, legal correspondence, health information, or commercially sensitive files into it. The control should therefore sit before the prompt. Define which data classes are allowed, which need an approved enterprise environment, and which must never be entered without specialist review.
A useful data workflow begins with source authority. The business should identify where the authoritative record lives, minimise the extract, remove identifiers where possible, send only the fields needed for the task, and reconcile the output back to the source. Our controlled AI data-analysis workflow explains why verification of totals, schema, assumptions, and calculations matters even when the legal risk category is low.
The EDPB’s 2026-2027 work programme explicitly includes joint guidance on the interplay between the AI Act and GDPR. Until that work is complete, SMEs should resist the temptation to merge the two regimes into one fuzzy ‘AI privacy’ checklist. Keep the legal questions distinct and connect them through the AI register. One row can carry both an AI Act role and risk classification and a separate GDPR note on lawful basis, data categories, processor terms, transfer mechanism, retention, and data-subject impact.
This separation also improves procurement. A vendor statement that its product ‘supports EU AI Act compliance’ does not answer whether your particular processing has a lawful GDPR basis, and a data-processing agreement does not answer whether the product satisfies Article 50.
Build a Small-Business AI Register Before Buying Compliance Software
The highest-return control for most SMEs is a spreadsheet, not a platform. An AI register creates one factual source for compliance decisions and stops shadow use from disappearing into browser tabs. Start with every AI-enabled service the company knows it uses, including features inside software already licensed. Then add owner, vendor, purpose, user group, affected people, input data, output destination, legal role, risk class, Article 50 relevance, GDPR status, human review, vendor evidence, and review date.
The register should be use-case based. ‘Microsoft 365’ or ‘ChatGPT’ is too broad because the same product can support harmless drafting and a much more sensitive workflow. Create separate rows when purpose, data, affected people, or decision impact changes. That allows a business to approve an assistant for meeting summaries while blocking it from candidate scoring without creating contradictory policy language.
A lightweight traffic-light system can help. Green means approved low-impact use with ordinary verification. Amber means personal data, public publication, customer interaction, employment, financial consequence, sensitive sector, or significant automation, so a named reviewer must approve conditions. Red means a prohibited practice, an unapproved high-risk use, or a data category the company has barred from the tool. The labels are an internal control device, not statutory AI Act categories.
Do not confuse inventory with surveillance of staff. The purpose is to know what systems act on the business’s behalf and what controls follow. A quarterly review is usually more valuable than attempting to log every prompt. It catches vendor feature changes, new integrations, changed purposes, and systems that have become business-critical.
This register also creates information gain for future audits. When a regulator, client, insurer, or enterprise customer asks how the company governs AI, the business can show dates, owners, decisions, and evidence rather than reconstructing usage from memory.
Vendor Contracts and Evidence Are the Hidden Compliance Layer
A small business cannot document what a vendor refuses to explain. Procurement should therefore ask for evidence that maps to the intended use rather than accept a broad marketing statement. For a routine assistant, that may mean current terms, privacy and security documentation, data-use controls, retention choices, administrator features, and information about Article 50 support. For a system heading towards a high-risk use, the evidence set becomes substantially deeper.
Start with intended purpose. Article 25 makes changes of purpose legally important, so contract and product documentation should describe what the system is designed to do and what uses the provider excludes. Then record whether your configuration changes that purpose. If the supplier markets a product for drafting but the customer rebuilds it into a decision engine, the customer’s compliance posture cannot be inferred from the supplier’s original label.
Next, ask who supplies the evidence your role requires. A deployer may need instructions for use, logging information, human-oversight guidance, incident routes, and information necessary to operate safely. A provider integrating third-party components may require deeper technical cooperation. Article 25 specifically contemplates written arrangements between high-risk providers and third-party suppliers for necessary information, technical access, and assistance, subject to intellectual-property and confidentiality protections.
Microsoft’s current EU AI Act Trust Center is an example of a vendor publishing central compliance material, but the existence of a trust page is not proof that a customer’s use case complies. The procurement file should connect each vendor document to an internal decision. What data is allowed? Who can enable integrations? Which output requires review? What happens if the vendor changes a feature? Who receives incident notices?
This is why vendor governance should be versioned. Save the date, document title, or screenshot reference behind important decisions. If a feature changes six months later, the business can identify whether it needs a new legal or security assessment instead of treating the original approval as permanent.
Penalties, SME Relief, and What Proportionate Really Means
The headline fines are large, but the SME calculation contains a detail that is frequently omitted. Article 99 sets general ceilings of up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3% for specified operator and transparency obligations, and up to EUR 7.5 million or 1% for supplying incorrect, incomplete, or misleading information to authorities or notified bodies. For SMEs, including start-ups, the fine is capped at the lower of the relevant fixed amount or turnover percentage, not the higher (AI Act Service Desk, Article 99).
| Breach | General Ceiling | SME Rule | Practical Note |
| Article 5 prohibited practices | EUR 35m or 7% worldwide annual turnover, whichever is higher | Lower of fixed amount or percentage | Screen red-line uses before procurement or deployment |
| Specified operator duties and Article 50 | EUR 15m or 3% worldwide annual turnover, whichever is higher | Lower of fixed amount or percentage | Current Article 50 exposure can be relevant in 2026 |
| Incorrect, incomplete or misleading information to authorities/notified bodies | EUR 7.5m or 1% worldwide annual turnover, whichever is higher | Lower of fixed amount or percentage | Keep source-backed records and correct errors promptly |
That does not make non-compliance cheap. National authorities also have enforcement measures beyond the maximum fine, and the Act requires sanctions to be effective, proportionate, and dissuasive. Business impact can include remediation, product restrictions, procurement consequences, customer trust, and the cost of investigating incidents. A small company’s best defence is not to calculate a theoretical fine but to show a reasonable, risk-based control trail.
SMEs also receive affirmative support. Article 62 requires Member States to provide qualifying SMEs with priority access to regulatory sandboxes, tailored awareness and training, channels for implementation advice, and support for participation in standardisation. Conformity-assessment fees must take SME interests into account. The AI Act Service Desk further describes simplified technical documentation and simplified quality-management mechanisms for SME providers of high-risk AI systems, plus free access to regulatory sandboxes where applicable.
The 2026 Omnibus broadened some simplifications beyond SMEs to small mid-caps and clarified additional implementation mechanisms. That is important because proportionate compliance should change the form of evidence, not the truth of the underlying risk. A two-page record can be proportionate if it captures the system, decision, risk, owner, control, and source. A one-hundred-page template copied from a large enterprise can still be poor evidence if nobody uses it.
Brando Benifei, MEP and co-rapporteur of the original Act, highlighted fragmentation across implementation and enforcement at a June 2026 Brussels roundtable. SMEs operating across several Member States should therefore track the competent national authority and local guidance, not only the EU-level text.
“challenging the fragmentation we have in the implementation and enforcement”
Brando Benifei, MEP and EU AI Act co-rapporteur, Thomson Reuters Foundation roundtable, 23 June 2026
A 30-Day Compliance Plan for a Small Team
A small business can build a defensible baseline in a month without pretending to finish every future high-risk obligation. The aim is to establish ownership, evidence, and escalation. The plan below assumes the company mainly deploys third-party tools. A business developing or selling AI systems, operating in a regulated sector, or using AI for consequential decisions should obtain specialist legal and technical advice earlier.
Days 1 to 5: appoint one operational owner and create the AI register. Interview team leads, review procurement and browser-approved tools, and capture AI features embedded in existing SaaS products. Record use case, vendor, role, data, affected people, human review, and business owner. Do not wait for perfect completeness before moving on.
Days 6 to 10: run a prohibited-practice and high-risk screen. Remove or escalate any use involving manipulation, prohibited biometric practices, social scoring, or other Article 5 concerns. Flag employment, education, essential-service, regulated-product, and similarly consequential uses for specialist classification. Record that Annex III deadlines are delayed but do not use the delay as approval to ignore GDPR or sector law.
Days 11 to 15: complete the Article 50 review. Identify customer-facing AI, synthetic media, deepfake risks, public-interest text, and any emotion-recognition or biometric-categorisation systems. Allocate the provider versus deployer responsibility and test what the user actually sees. Capture screenshots or configuration evidence where disclosure matters.
Days 16 to 20: deliver role-based AI literacy. Cover approved tools, hallucination, confidentiality, personal data, verification, disclosure, human escalation, and restricted use. Keep a dated attendance or acknowledgement record. Give high-impact teams additional scenarios rather than forcing the same module on everyone.
Days 21 to 25: review vendor and data controls. Save current terms and compliance documentation, check retention and training-data settings, identify subprocessors or transfers where relevant, and make sure administrators can restrict integrations. For sensitive workflows, document the authoritative source and human reviewer.
Days 26 to 30: hold a short management review. Approve green uses, assign actions to amber uses, suspend red uses, and set the next review date. Thomson Reuters Foundation data presented by Katie Fowler, Director of Responsible Business, showed materially stronger governance indicators among companies referencing the Act. The useful lesson for an SME is that a small control cycle works only when it produces decisions, not when it produces policy files.
“by a wide margin”
Katie Fowler, Director of Responsible Business, Thomson Reuters Foundation, 23 June 2026
Our Editorial Verification Process
This explainer was verified against the consolidated text of Regulation (EU) 2024/1689 as amended on 27 July 2026, Regulation (EU) 2026/1744, the European Commission’s current AI Act and enforcement pages, the Commission’s updated Article 4 AI literacy Q&A, the July 2026 Article 50 transparency Q&A and guidance, the AI Act Service Desk provisions on Articles 25, 62 and 99, Eurostat’s 2026 publication on enterprise AI adoption, and 2026 stakeholder material from the Thomson Reuters Foundation and DIGITALEUROPE. The legal timeline is stated as of 28 August 2026.
The article uses a role-first methodology because legal duties differ materially between provider and deployer. We cross-checked the dates for Article 50 and the delayed Chapter III high-risk requirements against the consolidated Article 113 and the Commission’s enforcement page. We treated Eurostat’s 17.0%, 30.4%, and 55.0% figures as adoption rates for small, medium, and large EU enterprises in 2025, using Eurostat’s enterprise-size definitions rather than generalising them to every microbusiness.
Internal-link verification had a technical limitation: the site’s XML sitemap endpoint did not return parseable sitemap content through the available browsing interface during research. To avoid fabricating links, the eight internal destinations in this document were selected only from live, indexed Perplexity AI Magazine article pages found in current web search and each was used once in a contextually relevant body section.
This is an explainer and compliance-planning article, not a software product review. A complete software feature inventory, API integration list, or pricing matrix is therefore not applicable to the search intent. Where a vendor resource is mentioned, such as Microsoft’s EU AI Act Trust Center, it is used as an example of compliance documentation rather than as a purchase recommendation or pricing claim.
This article was researched and drafted with AI assistance and reviewed by the Awais Khalid editorial desk at Perplexity AI Magazine. All data, citations, pricing figures, and named quotes have been independently verified against primary sources before publication.
Pre-publication control: the final human editorial desk must complete and evidence the stated review before publication. The WordPress publishing team should also perform the brief’s separate back-button and hidden-content checks on the live page, because those technical tests cannot be established from a pre-publication Word document.
Conclusion
The EU AI Act is now real compliance infrastructure for small businesses, but it does not require every SME to behave like a model developer. The most useful 2026 response is to separate current obligations from delayed high-risk duties and then build evidence around the systems actually in use.
For most ordinary deployers, the immediate work is concrete: keep an AI register, screen prohibited uses, support AI literacy, understand Article 50 transparency, maintain GDPR discipline, document human review, and hold vendors to the evidence required for the intended purpose. Firms building, rebranding, substantially modifying, or repurposing AI need an earlier and deeper role analysis because Article 25 can move responsibilities upstream.
The Omnibus bought time for the most complex high-risk requirements. It did not turn August 2026 into a compliance-free period. The open questions are now practical ones: how national authorities will enforce proportionately, how forthcoming standards will settle high-risk implementation, how the Commission and EDPB will clarify the AI Act-GDPR boundary, and whether SME simplifications reduce real administrative cost.
A small business that can show what it uses, why it uses it, who is responsible, which rules apply, and what evidence supports that decision is in a stronger position than one with a polished policy but no operational record.
FAQs
Does the EU AI Act apply to small businesses?
Yes. The Act can apply to SMEs and start-ups when they provide, deploy, import, distribute, or otherwise operate AI systems within its scope. Company size changes some support measures, simplified compliance routes, and penalty calculations, but it is not a blanket exemption. The role and use case come first.
What EU AI Act rules apply to SMEs in 2026?
As of 28 August 2026, relevant live rules include prohibited AI practices, Article 4 AI literacy, Article 50 transparency, governance and enforcement provisions, and rules affecting general-purpose AI providers. Core Annex III high-risk requirements are delayed to 2 December 2027, with Annex I product-related high-risk duties delayed to 2 August 2028.
Do small businesses need an AI officer?
Not merely to comply with Article 4. The European Commission says no specific governance structure, AI officer, or board is mandated for the AI literacy duty. A small firm should still assign an accountable owner so its inventory, training, transparency reviews, vendor evidence, and escalation process do not become orphaned tasks.
Do employees using ChatGPT need AI training?
The Commission says a company whose employees use ChatGPT for tasks such as advertising copy or translation should address specific risks such as hallucination. Article 4 does not prescribe a certificate or one mandatory training format. The appropriate literacy measures should reflect the users, system, purpose, and risk.
Must a small business label all AI-generated content?
No. Article 50 is use-specific. Providers have machine-readable marking duties for covered synthetic content, while deployers have direct labelling duties for deepfakes and certain AI-generated public-interest text. Substantive human review and editorial responsibility can remove the public-interest text labelling requirement in qualifying cases. Ordinary private drafts are not automatically subject to a label.
When do high-risk AI rules apply after the 2026 Omnibus?
The amended Article 113 sets 2 December 2027 for Chapter III Sections 1 to 3 as they apply to Annex III high-risk systems, except Article 6(5), and 2 August 2028 for high-risk AI systems linked to Annex I regulated products. Other AI Act obligations have different application dates.
What are the maximum AI Act fines for SMEs?
Article 99 includes ceilings of EUR 35 million or 7% for prohibited practices, EUR 15 million or 3% for specified operator and transparency breaches, and EUR 7.5 million or 1% for certain misleading information. For SMEs, the applicable ceiling is the lower of the relevant fixed amount or turnover percentage.
What should a small business do first for AI Act compliance?
Create a use-case-level AI register. Record the tool, owner, intended purpose, users, affected people, data, legal role, risk screen, transparency duty, human review, and vendor evidence. Then prioritise prohibited uses, Article 4 literacy, Article 50, GDPR controls, and sensitive or future high-risk workflows.
References
European Commission. (2026a). AI Act: Regulatory framework for artificial intelligence.
European Commission. (2026b). The enforcement framework of the AI Act.
European Commission. (2026c). AI Literacy – Questions & Answers.
European Commission. (2026d). Transparency obligations under Article 50 of the AI Act.
Eurostat. (2026). The use of artificial intelligence technologies in the European Union.
Microsoft. (2026). EU AI Act Compliance, Microsoft Trust Center.