All articles
Regulations & StandardsJune 3, 2026 · 2 min read · SafeAI for Business

EU AI Act Compliance for SMEs: The Complete 2026 Guide

Regulation (EU) 2024/1689 is rolling out in phases through 2027. This guide translates the risk tiers, deadlines, and SME duties into plain English.

The EU AI Act — Regulation (EU) 2024/1689 — is the world's first comprehensive AI law. It entered into force on 1 August 2024 and applies in phases through 2027. It reaches any business whose AI systems are placed on the EU market or whose outputs are used in the EU — including non-EU SMEs.

The risk pyramid

  • Unacceptable risk — banned (since 2 February 2025). Social scoring, exploitative manipulation, untargeted facial-image scraping, emotion recognition at work and school (with narrow exceptions), and more.
  • High risk — heavily regulated. AI used in employment and worker management, credit scoring, essential services, education, critical infrastructure, law enforcement, and as safety components of regulated products.
  • Limited risk — transparency duties. Chatbots must disclose they are AI; deepfakes and AI-generated content must be labeled.
  • Minimal risk — no new duties. Spam filters, game AI, most productivity uses.

The timeline that matters

  • 2 Feb 2025 — bans apply, plus the AI-literacy duty (Art. 4): staff using AI must be adequately trained.
  • 2 Aug 2025 — rules for general-purpose AI models take effect.
  • 2 Aug 2026 — the bulk applies, including most high-risk obligations.
  • 2 Aug 2027 — final phase-in for high-risk AI embedded in regulated products.

What SMEs typically are: deployers

Most SMEs don't build AI; they deploy it. Deployer duties for high-risk systems include using the system per the provider's instructions, ensuring human oversight by trained people, monitoring for problems, keeping logs, and — where you're an employer — informing workers when high-risk AI is used on them. If you use AI for hiring or performance evaluation, assume high-risk duties apply to you.

Two duties almost everyone already has

  • AI literacy. Anyone in your business who operates AI must understand its capabilities and limits. A short training plus written usage rules covers this.
  • Transparency. If customers chat with a bot or see AI-generated content from you, say so.

Penalties scale to the offense: up to €35M or 7% of worldwide turnover for banned practices. SMEs get proportionality — fines are capped at the lower of the percentages or fixed amounts — but "small" does not mean exempt.

Your compliance path

  • Inventory AI uses; classify each against the risk tiers.
  • Kill anything close to the banned list immediately.
  • For high-risk deployments: implement human oversight, logging, and vendor documentation now — before August 2026.
  • Train staff and update customer-facing disclosures.
  • Watch for the harmonized standards and SME sandboxes each member state must provide — they exist to make this cheaper for you.
Disclaimer: This article is educational guidance, not legal advice. Regulations change and apply differently by jurisdiction and sector — confirm decisions with qualified counsel.