EU AI Act: what SMEs must do now (2026 guide)

On August 2, 2026, without much fanfare, the most binding part of the European regulation on artificial intelligence came into force.
If your SME uses AI to sort CVs, score customers, or run an agent that talks to your prospects, this date concerns you. And if you think "this is for big tech", keep reading: most of the obligations that hit an SME have been in effect since February 2025.
I translated the essentials into business language. Four risk levels, two obligations that apply to every company, three situations where an SME genuinely falls inside scope.
The four risk levels in two minutes
The AI Act does not regulate "AI" as a block. It classifies every use by the danger it poses:

- Unacceptable risk: banned. Social scoring, subliminal manipulation, exploiting vulnerabilities linked to age or disability. No exceptions, not even for small companies.
- High risk: allowed but regulated. The bulk of the text. Recruitment, education, credit scoring, critical infrastructure. Allowed, with heavy obligations.
- Limited risk: transparency duty. You must disclose that it is AI. Chatbots and deepfakes live here.
- Minimal risk: nothing at all. Anti-spam filters, video games, most office uses. Not regulated.
The question that matters is not "do I use AI?". It is: "what risk level are my uses at?".
What is outright banned
The list of prohibited practices deserves a close read, because some commercial tools flirt with the line:
- Scoring people by their social behaviour (the Chinese social credit model).
- Manipulative or subliminal techniques that distort decisions.
- Exploiting vulnerabilities: age, disability, socio-economic situation.
- Inferring emotions at work and in education. Read that line again. Some HR software sells exactly that.
- Biometric categorisation of people (sexual orientation, opinions, religion).
- Predicting criminality based on profiling alone.
- Building face databases by massively scraping the web.
Sanctions go up to €35 million or 7% of global revenue for these practices. For most other breaches: €15 million or 3%.
An SME will never face such amounts, let's be serious about it. But banned means banned: if a tool you bought infers your employees' emotions, switch it off, full stop.
High risk: where an SME genuinely falls in
Annex III lists the use cases classified as high risk. Three directly concern SMEs:
1. Recruitment
Any AI system that sorts applications, filters CVs, evaluates candidates, decides promotions, or monitors performance. If your recruiting software automatically scores profiles, you are in that box. Since August 2, 2026.
The heaviest obligations sit with providers (technical documentation, data governance, logging, robustness). But you, the deployer, are not exempt: effective human oversight, informing people, using systems per their instructions.
The practical rule: AI can pre-select, a human must decide. If nobody reviews automatic rejections at your company, you are off track.
2. Financial scoring
Creditworthiness assessment, life or health insurance pricing. Relevant if you grant payment terms or operate near those areas.
3. Access to essential services
Less common for a classic SME, but worth knowing if you operate in vocational training (education is also in Annex III).
The two obligations that hit EVERY SME
Mandatory AI literacy since February 2025
This is Article 4, and it is probably your biggest blind spot. Every provider OR deployer of an AI system must ensure its staff has sufficient AI literacy to understand its limits and use it properly.
Eighteen months ago already. Yet in most SMEs I visit, everyone copies customer data into public AI tools with no framework, no rules, no training.
No certified course is required: demonstrable literacy is. A team given clear rules, trained on your real tools and processes, checks the box. A team left on its own does not.
Transparency for agents and content
Also in force since August 2, 2026: your prospects have the right to know they are talking to an AI, and generated content (images, voice, synthetic text) must be identifiable as such.
For an SME running a voice agent or a sales chatbot: a simple mention ("virtual assistant") is enough, but it must exist. Same for AI-generated brand videos.
The deadline table
| Date | What applies | Status |
|---|---|---|
| February 2025 | Prohibited practices + AI literacy duty (Article 4) | In force |
| August 2025 | General-purpose AI models (GPAI): provider documentation and transparency | In force |
| August 2026 | High-risk systems (Annex III) + chatbot/deepfake transparency | Just entered |
| August 2027 | High risk built into regulated products (Annex I) | Upcoming |
My take: no panic, but no improvisation either
Let's be honest: if you use Claude to write emails and run a standard CRM, the AI Act barely changes your daily routine. Minimal risk is unregulated, and that covers most office uses.
But three signals should trigger action now:
- Your recruitment tool sorts CVs on its own and nobody reviews the rejections.
- Your teams have been using public AI tools for over a year with no rule and no training.
- An agent talks to your customers without announcing it is an AI.
None of these requires a six-month compliance project. They require one decision, one written rule, and half a day of clean-up.
And there is a positive angle: Article 4 forces training, yet real AI adoption in SMEs hits exactly that wall. Compliance and performance call for the same action: teams trained on real files, not a generic slideshow. That is exactly the principle of the micro-trainings built into Externalised AI Leadership (Direction IA Externalisée): every month, the team learns on the processes it already runs.
How to get compliant this week
- List all your AI uses. Purchased tools, deployed agents, team habits. One sheet, one row per use. No inventory, no compliance.
- Check the banned list against your HR tools. Emotion detection, personality scoring? If yes, disable and document.
- Identify whether you are high risk. Automatic CV sorting or customer scoring: ask your provider for written deployment instructions (they must supply them).
- Put the human back in the loop. Any automated decision affecting a person (candidate, customer) must be reviewed and appealable.
- Add the AI disclosure where missing. Chatbot, voice agent, generated content: one line suffices.
- Frame the training (Article 4). One session on your real use cases beats generic e-learning that never gets finished. And if you want someone to handle it end to end, let's talk: the free 45-minute audit also maps your risks.
Conclusion
The AI Act is not an administrative monster designed to suffocate SMEs. It is a net: ban what harms, regulate what can hurt, leave the rest alone.
Most SMEs are already in the green without knowing it. A few are in the red without knowing it.
The difference between the two is half a day of inventory.
See also the AI glossary
Take action: your Express AI Audit (45 min)
45 minutes with an AI expert to evaluate your operations, identify productivity gains and map your first high-ROI AI agents.
Designed for SME leaders (10 to 100 staff) · No commitment · 100% IP ownership
Deploy AI Agents in your SME with an External CAIO
Get an outsourced AI Director 1 to 10 days per month to audit, automate your workflows and train your teams.
Stay ahead of AI Innovations
Every week, get a curated selection of our latest articles, case studies, and actionable AI insights directly in your inbox. No spam, 100% value.
Fractional AI Director locations


