EU AI Act Compliance for SMEs: The Complete 2026 Guide
Regulation (EU) 2024/1689 is rolling out in phases through 2027. This guide translates the risk tiers, deadlines, and SME duties into plain English.
The EU AI Act — Regulation (EU) 2024/1689 — is the world's first comprehensive AI law. It entered into force on 1 August 2024 and applies in phases through 2027. It reaches any business whose AI systems are placed on the EU market or whose outputs are used in the EU — including non-EU SMEs.
The risk pyramid
- Unacceptable risk — banned (since 2 February 2025). Social scoring, exploitative manipulation, untargeted facial-image scraping, emotion recognition at work and school (with narrow exceptions), and more.
- High risk — heavily regulated. AI used in employment and worker management, credit scoring, essential services, education, critical infrastructure, law enforcement, and as safety components of regulated products.
- Limited risk — transparency duties. Chatbots must disclose they are AI; deepfakes and AI-generated content must be labeled.
- Minimal risk — no new duties. Spam filters, game AI, most productivity uses.
The timeline that matters
- 2 Feb 2025 — bans apply, plus the AI-literacy duty (Art. 4): staff using AI must be adequately trained.
- 2 Aug 2025 — rules for general-purpose AI models take effect.
- 2 Aug 2026 — the bulk applies, including most high-risk obligations.
- 2 Aug 2027 — final phase-in for high-risk AI embedded in regulated products.
What SMEs typically are: deployers
Most SMEs don't build AI; they deploy it. Deployer duties for high-risk systems include using the system per the provider's instructions, ensuring human oversight by trained people, monitoring for problems, keeping logs, and — where you're an employer — informing workers when high-risk AI is used on them. If you use AI for hiring or performance evaluation, assume high-risk duties apply to you.
Two duties almost everyone already has
- AI literacy. Anyone in your business who operates AI must understand its capabilities and limits. A short training plus written usage rules covers this.
- Transparency. If customers chat with a bot or see AI-generated content from you, say so.
Penalties scale to the offense: up to €35M or 7% of worldwide turnover for banned practices. SMEs get proportionality — fines are capped at the lower of the percentages or fixed amounts — but "small" does not mean exempt.
Your compliance path
- Inventory AI uses; classify each against the risk tiers.
- Kill anything close to the banned list immediately.
- For high-risk deployments: implement human oversight, logging, and vendor documentation now — before August 2026.
- Train staff and update customer-facing disclosures.
- Watch for the harmonized standards and SME sandboxes each member state must provide — they exist to make this cheaper for you.