All articles

AI & Automation

AI Act for SMEs: What You Actually Need to Do When Using AI

A practical overview for small and mid-sized companies that use AI tools or build AI into their processes: roles, risk classes, AI literacy, transparency and the deadlines after the 2026 Digital Omnibus.

Why the AI Act matters even if you only use AI

Many small and mid-sized companies assume the EU AI Act is a topic for large tech companies that build models. In practice, it also applies to organisations that use AI systems in their own business. The regulation calls them deployers, and that is the role most SMEs have when they use AI for support, documents, marketing or internal workflows.

The good news: for typical business use, the obligations are manageable. The AI Act is risk-based. Most everyday applications fall into categories with few or no specific duties. What matters is knowing which category your use cases fall into, and noticing early when a project moves into a stricter one. The regulation can also reach companies outside the EU, for example in Switzerland, when they place AI systems on the EU market or when the output of their AI is used in the EU.

Provider or deployer: know your role

A provider develops an AI system or has it developed and places it on the market or puts it into service under its own name. A deployer uses an AI system under its own authority in a professional context. A company that uses an AI writing tool or a standard support chatbot is a deployer. A company that builds its own AI system and offers it to customers under its brand is a provider.

The line can shift. If you put your own name or trademark on a high-risk AI system, substantially modify it, or change its intended purpose so that it becomes high-risk, you can take on provider obligations. That is worth checking before an internal tool is turned into a product or offered to customers.

Risk classes in practice

The AI Act sorts AI uses into four broad groups. For most SMEs, the important task is to make sure no use case falls into the first group and to recognise the second one early.

High-risk does not mean that AI is used in an important process. It refers to specific areas listed in the regulation, such as AI used to screen job applications, evaluate employees, assess creditworthiness of individuals or decide on access to education. A helpdesk assistant or a document classifier for invoices is usually not high-risk.

  • Prohibited practices: for example social scoring, manipulative techniques that cause significant harm, or emotion recognition in the workplace and in education outside medical or safety reasons. These have been banned since 2 February 2025.
  • High-risk systems: specific use cases in areas such as employment, credit, education or critical infrastructure, with strict requirements for providers and deployers.
  • Transparency obligations: for example chatbots, synthetic content and deepfakes, where people must know that AI is involved.
  • Minimal risk: most other applications, such as spam filters, translation aids or internal drafting tools, without specific AI Act duties.

AI literacy: what the softened duty still requires

Article 4 on AI literacy has applied since 2 February 2025 and affects every provider and deployer, regardless of risk class. The Digital Omnibus on AI, Regulation (EU) 2026/1744, softened its wording in July 2026: companies must now take measures to support the AI literacy of their staff and of other people who operate or use AI systems on their behalf. They do not have to guarantee a specific level of literacy for each individual.

Softer wording does not mean no obligation. In practice, it is sensible to document what you do: a short internal guideline on approved AI tools, briefings for the teams that use them, clear rules on which data may be entered, and named contacts for questions. For SMEs, this can be lean, but it should exist and be traceable.

Transparency since August 2026

The transparency obligations in Article 50 have applied since 2 August 2026. Providers must design chatbots so that people know they are interacting with AI, and generative systems must mark synthetic content in a machine-readable way. Providers of generative systems that were already on the market before that date have until 2 December 2026 for the marking. Deployers must disclose deepfakes and inform people when emotion recognition or biometric categorisation is used on them.

If an SME builds its own chatbot or content tool on top of a model API and offers it to customers, it can be the provider of that system and responsible for the disclosure. How to turn these requirements into clear interface states, labels and review workflows is covered in our article on AI Act transparency for web apps.

The timeline after the Digital Omnibus

The Digital Omnibus entered into force on 27 July 2026 and replaced the original high-risk deadlines with fixed calendar dates. That gives companies more time for high-risk use cases, but no reason to wait: the earlier obligations already apply, and national supervision has started. In Germany, the Bundesnetzagentur has been the central market surveillance authority for the AI Act since 2 August 2026, while sector regulators such as BaFin keep their responsibilities.

Fines are graded. Prohibited practices can lead to fines of up to 35 million euros or 7 percent of worldwide annual turnover, and most other violations up to 15 million euros or 3 percent. For SMEs, the lower of the two amounts applies, but even that is far more than the cost of a clean setup.

  • Since 2 February 2025: prohibited practices and AI literacy.
  • Since 2 August 2025: obligations for providers of general-purpose AI models.
  • Since 2 August 2026: transparency obligations under Article 50 and national supervision.
  • 2 December 2027: high-risk obligations for stand-alone systems listed in Annex III, such as hiring or credit scoring.
  • 2 August 2028: high-risk obligations for AI in products covered by EU product law listed in Annex I, such as medical devices or machinery.

A practical checklist for SMEs

For most small and mid-sized companies, AI Act readiness comes down to a short, repeatable routine. It works best when it is part of how new AI tools and AI projects are introduced, not a one-off audit.

When AI is built into your own products or processes, these questions belong in the design from the start: which role you have, which data the system uses, where people review results and what is logged. That is how EDS Labs plans AI integrations, as technical and organisational guidance. This article is not legal advice. For binding assessments of specific cases, involve legal counsel or your data protection officer.

  • List the AI tools and AI features in use, including those inside existing software.
  • Note for each use case whether you are deployer or provider.
  • Check that no use case falls under the prohibited practices.
  • Flag use cases in sensitive areas such as hiring, employee evaluation or credit early.
  • Document AI literacy measures: guidelines, briefings, approved tools and data rules.
  • Plan transparency: AI disclosure for chatbots, labels for synthetic content where required.
  • Review the list whenever a new AI tool or AI project is introduced.