The EU AI Act, the European regulation on artificial intelligence, applies in stages: banned practices and the training obligation since February 2025, rules on general-purpose AI models since August 2025, and the bulk of the high-risk obligations between August 2026 and August 2027. For an SMB, the priority is not to document everything, but to know precisely which AI systems it uses or supplies, to check that no use is prohibited, and to prepare for the deadlines that actually apply to it.
A risk-based approach: four levels of requirements
The AI Act (Regulation EU 2024/1689, which entered into force on 1 August 2024) does not regulate the technology as such but its uses, classified by risk:
- Prohibited practices: generalised social scoring, manipulation exploiting people's vulnerabilities, emotion recognition in the workplace, certain forms of biometric identification. These are banned outright.
- High-risk systems: AI used for recruitment, employee evaluation, credit scoring, access to education or essential services, or embedded in regulated products. These carry heavy documentation, control and human-oversight obligations.
- Transparency obligations: chatbots, generated content and deepfakes must be disclosed as such to users.
- Minimal risk: the vast majority of uses (writing assistance, internal triage, office assistants) remain free, subject to existing law, starting with the GDPR.
On top of this come dedicated rules for general-purpose AI models (GPAI), which primarily affect the large model providers, not the SMBs that use them.
The timeline: what is already in force, what is coming
Since 2 February 2025: prohibitions and AI literacy
The prohibited practices are banned, and every organisation using AI must ensure a sufficient level of AI literacy among its staff (Article 4). In other words, training your employees is already a legal obligation, whatever your level of AI usage. In practice, a short awareness session plus targeted training for the teams that use AI daily is usually enough at this stage.
Since 2 August 2025: general-purpose AI models
Providers of large models must publish technical documentation, respect copyright and cooperate with the European AI Office. The direct impact on an SMB is limited, but the indirect impact is real: your AI tool vendors must now be able to provide you with this documentation.
2 August 2026: the bulk of the obligations
The regulation becomes applicable across the board: the full regime for high-risk systems listed in Annex III (HR, credit, education, essential services), the transparency obligations, the penalty regime and operational national supervisory authorities. This is the structuring deadline for most companies.
2 August 2027: regulated products and pre-existing models
High-risk systems embedded in products covered by sectoral regulation (medical devices, machinery, toys, vehicles) get one more year, as does the compliance of large models placed on the market before August 2025.
Note that timeline adjustments are regularly discussed in Brussels, including targeted postponements of certain high-risk obligations as part of the simplification agenda. Monitoring is necessary, but betting on a postponement to do nothing would be a mistake: the prohibitions and the training obligation already apply.
User or provider: what actually concerns your SMB
Your SMB uses AI systems (deployer)
This is the most common case. Your obligations: use the systems in line with their instructions, ensure appropriate human oversight, control the quality of the input data you manage, inform the people concerned (employees, candidates, customers) and report serious incidents. The number-one point of vigilance: AI applied to human resources, CV screening or evaluation, which is almost always classified as high-risk. Keep a simple register of these systems and of the checks you perform: it will be your first line of defence in an audit or a dispute.
Your SMB develops or embeds AI (provider)
If you place an AI system on the market, including one embedded in your software, and it qualifies as high-risk, you carry heavy obligations: risk management, data governance, technical documentation, CE marking, registration in the European database. Beware: heavily customising an existing system or selling it under your own brand can requalify you as a provider.
A pragmatic five-step action plan
- Inventory all AI uses, including those embedded in your SaaS tools and the unofficial uses within your teams.
- Classify each use: prohibited, high-risk, transparency, minimal risk. When in doubt, document your reasoning.
- Question your vendors: request their compliance documentation and add AI Act clauses to new contracts.
- Train your teams: general awareness for everyone, deeper training for those operating sensitive systems. This is already mandatory.
- Appoint an AI lead and organise regulatory monitoring: the framework is still moving, and so are your uses.
Penalties: dissuasive but proportionate
The ceilings are high: up to €35 million or 7 percent of worldwide turnover for prohibited practices, €15 million or 3 percent for other breaches. The regulation does, however, provide for proportionality for SMBs, and regulators will favour support and guidance first. The real short-term risk is commercial: your large enterprise customers already require compliance guarantees from their suppliers, and being able to show a documented, proportionate approach often makes the difference.
Complying with the AI Act looks a lot like what the GDPR was in 2018: a governance project more than a technical one. Running it with a partner who knows both the regulation and the reality of information systems helps avoid the two classic pitfalls: paralysing over-compliance and risky inaction.
