AI Strategy 31 August 2026 7 min read

EU AI Act: what SMEs must do now (2026 guide)

Gary Bramnik
Gary Bramnik
Directeur IA externalisé
Share
EU AI Act: what SMEs must do now (2026 guide)

On August 2, 2026, without much fanfare, the most binding part of the European regulation on artificial intelligence came into force.

If your SME uses AI to sort CVs, score customers, or run an agent that talks to your prospects, this date concerns you. And if you think "this is for big tech", keep reading: most of the obligations that hit an SME have been in effect since February 2025.

I translated the essentials into business language. Four risk levels, two obligations that apply to every company, three situations where an SME genuinely falls inside scope.

The four risk levels in two minutes

The AI Act does not regulate "AI" as a block. It classifies every use by the danger it poses:

Official badge of the EU AI Act, dark theme version

  1. Unacceptable risk: banned. Social scoring, subliminal manipulation, exploiting vulnerabilities linked to age or disability. No exceptions, not even for small companies.
  2. High risk: allowed but regulated. The bulk of the text. Recruitment, education, credit scoring, critical infrastructure. Allowed, with heavy obligations.
  3. Limited risk: transparency duty. You must disclose that it is AI. Chatbots and deepfakes live here.
  4. Minimal risk: nothing at all. Anti-spam filters, video games, most office uses. Not regulated.

The question that matters is not "do I use AI?". It is: "what risk level are my uses at?".

What is outright banned

The list of prohibited practices deserves a close read, because some commercial tools flirt with the line:

  • Scoring people by their social behaviour (the Chinese social credit model).
  • Manipulative or subliminal techniques that distort decisions.
  • Exploiting vulnerabilities: age, disability, socio-economic situation.
  • Inferring emotions at work and in education. Read that line again. Some HR software sells exactly that.
  • Biometric categorisation of people (sexual orientation, opinions, religion).
  • Predicting criminality based on profiling alone.
  • Building face databases by massively scraping the web.

Sanctions go up to €35 million or 7% of global revenue for these practices. For most other breaches: €15 million or 3%.

An SME will never face such amounts, let's be serious about it. But banned means banned: if a tool you bought infers your employees' emotions, switch it off, full stop.

High risk: where an SME genuinely falls in

Annex III lists the use cases classified as high risk. Three directly concern SMEs:

1. Recruitment

Any AI system that sorts applications, filters CVs, evaluates candidates, decides promotions, or monitors performance. If your recruiting software automatically scores profiles, you are in that box. Since August 2, 2026.

The heaviest obligations sit with providers (technical documentation, data governance, logging, robustness). But you, the deployer, are not exempt: effective human oversight, informing people, using systems per their instructions.

The practical rule: AI can pre-select, a human must decide. If nobody reviews automatic rejections at your company, you are off track.

2. Financial scoring

Creditworthiness assessment, life or health insurance pricing. Relevant if you grant payment terms or operate near those areas.

3. Access to essential services

Less common for a classic SME, but worth knowing if you operate in vocational training (education is also in Annex III).

The two obligations that hit EVERY SME

Mandatory AI literacy since February 2025

This is Article 4, and it is probably your biggest blind spot. Every provider OR deployer of an AI system must ensure its staff has sufficient AI literacy to understand its limits and use it properly.

Eighteen months ago already. Yet in most SMEs I visit, everyone copies customer data into public AI tools with no framework, no rules, no training.

No certified course is required: demonstrable literacy is. A team given clear rules, trained on your real tools and processes, checks the box. A team left on its own does not.

Transparency for agents and content

Also in force since August 2, 2026: your prospects have the right to know they are talking to an AI, and generated content (images, voice, synthetic text) must be identifiable as such.

For an SME running a voice agent or a sales chatbot: a simple mention ("virtual assistant") is enough, but it must exist. Same for AI-generated brand videos.

Diagram of the AI Act risk pyramid: banned uses at the top, high-risk systems regulated since August 2026, transparency duties for chatbots and deepfakes, minimal risk unregulated, with application dates from February 2025 to August 2027


The deadline table

DateWhat appliesStatus
February 2025Prohibited practices + AI literacy duty (Article 4)In force
August 2025General-purpose AI models (GPAI): provider documentation and transparencyIn force
August 2026High-risk systems (Annex III) + chatbot/deepfake transparencyJust entered
August 2027High risk built into regulated products (Annex I)Upcoming

My take: no panic, but no improvisation either

Let's be honest: if you use Claude to write emails and run a standard CRM, the AI Act barely changes your daily routine. Minimal risk is unregulated, and that covers most office uses.

But three signals should trigger action now:

  1. Your recruitment tool sorts CVs on its own and nobody reviews the rejections.
  2. Your teams have been using public AI tools for over a year with no rule and no training.
  3. An agent talks to your customers without announcing it is an AI.

None of these requires a six-month compliance project. They require one decision, one written rule, and half a day of clean-up.

And there is a positive angle: Article 4 forces training, yet real AI adoption in SMEs hits exactly that wall. Compliance and performance call for the same action: teams trained on real files, not a generic slideshow. That is exactly the principle of the micro-trainings built into Externalised AI Leadership (Direction IA Externalisée): every month, the team learns on the processes it already runs.

How to get compliant this week

  1. List all your AI uses. Purchased tools, deployed agents, team habits. One sheet, one row per use. No inventory, no compliance.
  2. Check the banned list against your HR tools. Emotion detection, personality scoring? If yes, disable and document.
  3. Identify whether you are high risk. Automatic CV sorting or customer scoring: ask your provider for written deployment instructions (they must supply them).
  4. Put the human back in the loop. Any automated decision affecting a person (candidate, customer) must be reviewed and appealable.
  5. Add the AI disclosure where missing. Chatbot, voice agent, generated content: one line suffices.
  6. Frame the training (Article 4). One session on your real use cases beats generic e-learning that never gets finished. And if you want someone to handle it end to end, let's talk: the free 45-minute audit also maps your risks.

Conclusion

The AI Act is not an administrative monster designed to suffocate SMEs. It is a net: ban what harms, regulate what can hurt, leave the rest alone.

Most SMEs are already in the green without knowing it. A few are in the red without knowing it.

The difference between the two is half a day of inventory.

🎁 First day included (€990 value) for qualified profiles

Take action: your Express AI Audit (45 min)

45 minutes with an AI expert to evaluate your operations, identify productivity gains and map your first high-ROI AI agents.

Designed for SME leaders (10 to 100 staff) · No commitment · 100% IP ownership

B2B AI Implementation

Deploy AI Agents in your SME with an External CAIO

Get an outsourced AI Director 1 to 10 days per month to audit, automate your workflows and train your teams.

Book 45-min AI Audit →
AI French Touch Digest

Stay ahead of AI Innovations

Every week, get a curated selection of our latest articles, case studies, and actionable AI insights directly in your inbox. No spam, 100% value.

100% Free • Désinscription en 1-click • Privacy Policy