Does the EU AI Act apply to small businesses?
Yes. Regulation (EU) 2024/1689 applies by role and by risk, not by headcount or turnover, so a five-person company that uses an AI system in the EU is in scope exactly as a multinational is. What changes for an SME is the weight of the obligations: micro, small, and medium enterprises may use simplified technical documentation arrangements for high-risk systems, and Member States are required to give SMEs priority access to regulatory sandboxes.
In practice, most SMEs land in the lightest tier. They buy or subscribe to AI tools rather than build them, and those tools are usually not high-risk. The compliance work is then real but bounded: know what you use, confirm nothing is prohibited, meet transparency and literacy duties, and keep a record.
What are the first steps to comply with the EU AI Act?
The ordered sequence below works because each step depends on the one before it. Classification without an inventory is guesswork; documentation without classification documents the wrong things.
Step 1 — Build an AI inventory
List every system in the business that uses AI, including features embedded inside ordinary SaaS — the meeting summariser in the video tool, the ranking model in the recruitment platform, the fraud score in the payments provider. Shadow usage matters: staff pasting customer data into a public chatbot is an AI use of the business.
- System name and vendor, or "built in-house".
- Business purpose in one sentence, and who inside the company owns it.
- Whether it affects people outside the company (customers, applicants, employees).
- What data goes in, including whether personal data is involved.
- Whether outputs are acted on automatically or reviewed by a person.
Step 2 — Fix your role for each system
The Regulation assigns duties chiefly to providers (those who develop an AI system, or have one developed, and place it on the market or put it into service under their own name) and to deployers (those who use an AI system under their own authority in a professional capacity). Most SMEs are deployers. The role can flip: putting your own name or trade mark on a high-risk system supplied by someone else, or making a substantial modification to it, brings provider obligations with it.
Step 3 — Place each system in a risk tier
Work top-down. First check the prohibited practices in Art. 5 — for example social scoring, untargeted scraping of facial images to build recognition databases, and emotion inference in the workplace or in education, subject to narrow exceptions. These have been prohibited since 2 February 2025. Next check whether the system is high-risk: either as a safety component of a product already covered by EU product legislation, or because it falls within an Annex III use case such as employment and worker management, access to education, essential private and public services, or creditworthiness assessment. Anything left over is generally subject only to transparency duties, if any.
Step 4 — Map obligations, then document and monitor
Write the obligations against each system, assign an owner, and record the reasoning behind the classification. The reasoning is the artefact a market surveillance authority or a customer's procurement team will ask for, and it is the thing SMEs most often skip.
Which EU AI Act obligations apply to most SMEs?
For an SME that deploys a handful of non-high-risk tools, the recurring duties are short.
- AI literacy: ensuring staff who use or oversee AI systems have an adequate level of understanding, proportionate to their role and the context. This obligation has applied since 2 February 2025.
- No prohibited practices: a positive check that nothing in the inventory falls under Art. 5, re-run when tools change.
- Transparency under Art. 50: telling people they are interacting with an AI system where that is not obvious, and marking synthetic or manipulated content such as deepfakes.
- Following the provider's instructions for use, and using the system for its intended purpose rather than repurposing it into a different, riskier use.
- Basic governance: an inventory that is kept current, a named owner per system, and a route for staff to flag problems.
- •If one system does turn out to be high-risk — CV screening and candidate ranking is the common case for SMEs — the deployer obligations expand. They typically include assigning competent human oversight with the authority to intervene, ensuring input data is relevant for the intended purpose where the deployer controls it, retaining automatically generated logs for an appropriate period, informing workers and their representatives before putting the system into use in the workplace, and notifying the provider and the authorities if a serious incident or a risk to health, safety, or fundamental rights emerges.
What is genuinely out of scope for most SMEs
Reading the Regulation front to back makes it look enormous. Large parts of it will never touch a typical small business, and knowing which parts saves weeks.
- Provider obligations for high-risk systems — risk management systems, conformity assessment, CE marking, EU declarations of conformity, post-market monitoring plans — apply only if the SME actually develops or rebrands such a system.
- Obligations on providers of general-purpose AI models apply to those who train and place such models on the market, not to businesses that use them through an API or a subscription.
- Notified body procedures and registration in the EU database are provider- and, for certain public-sector deployers, deployer-specific; they do not attach to ordinary commercial use of a low-risk tool.
- Purely personal, non-professional use of AI by individuals is outside the Regulation, as is, subject to conditions, free and open-source software that is not high-risk and not placed on the market as such.
- Research and development activity prior to placing a system on the market is treated differently from deployment in production.
The honest summary for a typical SME: three or four obligations that apply always, one classification exercise that must be done properly, and a large body of law that applies to somebody else in the supply chain.
Dates to work backwards from
- 1 August 2024 — the Regulation entered into force.
- 2 February 2025 — prohibitions on unacceptable-risk practices and the AI literacy obligation began to apply.
- 2 August 2025 — obligations for providers of general-purpose AI models and the governance and penalties framework began to apply.
- 2 August 2026 — the general date of application, including the Annex III high-risk obligations and the Art. 50 transparency rules.
- 2 August 2027 — application for high-risk AI systems that are safety components of products covered by EU product legislation listed in Annex I.
An SME planning work in 2026 should treat 2 August 2026 as the hard edge for anything Annex III-adjacent, and treat the literacy and prohibited-practice checks as already due.
- •Inventory every AI system and AI feature in use, including embedded SaaS functionality and informal staff usage.
- •Record your role — provider or deployer — for each entry, and flag any tool you resell or white-label.
- •Screen every entry against the Art. 5 prohibited practices and record the outcome.
- •Screen every entry against the Annex III use cases and the product-safety route, and record the reasoning, not just the verdict.
- •Deliver proportionate AI literacy training to staff who use or oversee these systems, and keep evidence of who was trained and when.
- •Add AI transparency notices where users interact with a system or receive AI-generated content.
- •Read and retain each vendor's instructions for use, and note any way your actual use departs from the intended purpose.
- •Assign a named human overseer for anything high-risk, and confirm log retention with the vendor.
- •Diarise a review whenever a tool is added, a vendor ships a significant model change, or a use case expands.
- •Store the whole thing in one place so it can be produced on request by a customer, an auditor, or an authority.