Regfortis

EU AI Act compliance for SMEs: obligations, key dates and what to do now.

European SMEs using AI tools now have active legal obligations under the EU AI Act — including staff AI literacy (Article 4) and user transparency (Article 50), both in force from 2 August 2026. Find out exactly which requirements apply to your business and how to prepare with our free 5-minute assessment.

Updated for Regulation (EU) 2026/1744 — Annex III high-risk obligations now apply from 2 December 2027

What the EU AI Act means for SME deployers

While the heaviest regulatory burden falls on developers of AI models, companies that simply use AI tools — called "deployers" — also have legal obligations under the AI Act.

Depending on how you use AI, you may need to take measures to support AI literacy (Article 4), disclose AI interactions to users (Article 50), and — for organisations using Annex III high-risk systems — meet the full Article 26 deployer duties from December 2027.

For the exact regulatory texts these obligations come from, see our

regulatory sources

Common SME AI tools covered

  • Generative tools (ChatGPT, Microsoft Copilot, Google Gemini)
  • Recruitment and HR screening tools
  • Customer-facing chatbots and virtual assistants
  • Automated email and content generation
  • Data analytics and business intelligence

What our assessment covers

AI Tool Usage & Literacy (Article 4)

Evaluating whether your organisation takes proportionate measures to support AI literacy among staff. In force from 2 August 2026.

Risk Classification (Annex III)

Identifying if your systems may fall into Annex III high-risk categories. Full compliance obligations apply from 2 December 2027.

Governance & Vendor Management (Article 26)

Reviewing governance structures and vendor oversight. Mandatory for Annex III systems from 2 December 2027; good practice now.

Transparency Obligations (Article 50)

Assessing AI interaction disclosures to users and synthetic media labelling. In force from 2 August 2026.

Prohibited Practices (Article 5)

Flagging AI uses that may be prohibited now or from 2 December 2026 under the amended Article 5, requiring immediate or advance review.

Three steps to compliance readiness

From your first question to documented readiness — three straightforward steps.

Step 1 — Free

Take the free assessment

Answer questions about your business and AI tool usage. About 5 minutes. No account required.

Step 2 — Free

Receive immediate findings

Get a readiness profile instantly — which obligations apply, where your gaps are, and which actions to prioritise.

Step 3 — Optional

Optionally get documentation

Purchase generic templates from €99 or a personalised pack from €299 — one-time, no subscription. Many organisations use the free findings alone.

EU AI Act compliance timeline

Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 · Last reviewed 14 August 2026

In force

In force now

Upcoming

Act entered into force

Article 5 prohibited practices applied

Including emotion recognition in workplaces, biometric categorisation by protected attributes, subliminal manipulation, social scoring, and real-time biometric ID in public spaces.

General-purpose AI model (GPAI) provider obligations

Applies to providers of GPAI models. Most SMEs are users of GPAI-based products, not GPAI providers.

Article 4 (AI literacy) and Article 50 (transparency) in force

Article 4: deployers must take measures to support AI literacy among staff. Article 50: users must be told when interacting with AI; synthetic media must be labelled.

New Article 5 prohibitions (Regulation (EU) 2026/1744)

Art. 5(1)(ba): prohibition on AI generating non-consensual intimate synthetic imagery. Art. 5(1)(bb): prohibition on AI generating child sexual abuse material.

Annex III high-risk system obligations (Chapter III, Sections 1–3)

Amended from 2 Aug 2026 by Regulation (EU) 2026/1744. Includes Article 26 deployer duties for high-risk AI: conformity verification, human oversight, record-keeping, incident reporting.

Annex I regulated-product high-risk obligations

Applies to AI integrated into regulated products (medical devices, machinery, vehicles, aviation). Specialist advice required for these sectors.

Frequently asked questions about the EU AI Act

Does the EU AI Act apply to my business if I only use AI tools, not develop them?

Yes. Companies that deploy AI systems built by others — known as "deployers" — have obligations under the EU AI Act. These include taking measures to support AI literacy among staff (Article 4, in force from 2 August 2026), informing users when they interact with AI systems (Article 50, in force from 2 August 2026), and preparing for the Annex III high-risk deployer obligations under Article 26, which apply from 2 December 2027. The scope of obligations depends on which AI tools you use and for what purpose.

What is a "high-risk" AI system under the EU AI Act?

High-risk AI systems are those listed in Annex III of the Act. They include AI used in recruitment and HR decisions (such as CV screening), critical infrastructure management, education and vocational training assessments, access to essential services (credit, insurance), law enforcement, and biometric identification. The full compliance obligations for Annex III systems — including conformity assessment, EU database registration, and the Article 26 deployer duties — apply from 2 December 2027. This date was amended from the original 2 August 2026 by Regulation (EU) 2026/1744.

What are the key compliance dates under the EU AI Act?

The Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024. Key dates: Article 5 prohibited practices applied from 2 February 2025 (and remain in force). General-purpose AI model provider obligations applied from 2 August 2025. Article 4 (AI literacy measures) and Article 50 (transparency) apply from 2 August 2026. Two new Article 5 prohibitions added by Regulation (EU) 2026/1744 apply from 2 December 2026. The full Annex III high-risk system obligations (Chapter III) apply from 2 December 2027 — amended by Regulation (EU) 2026/1744 from the original August 2026 date. Annex I regulated-product high-risk systems apply from 2 August 2028.

What does "AI literacy" mean under Article 4 of the EU AI Act?

Article 4 (as amended by Regulation (EU) 2026/1744) requires providers and deployers to take measures to support the development of sufficient AI literacy skills among their staff and others dealing with AI on their behalf. The obligation is proportionate — the level of literacy support required scales with the role and the risk level of the AI systems involved. No specific training certification, course duration, or minimum qualification level is mandated. Documented guidance, training records, and staff briefings are practical ways to demonstrate compliance. This obligation applies from 2 August 2026.

What are the prohibited AI practices under Article 5?

Article 5 prohibits certain AI uses entirely. Original prohibitions (in force 2 February 2025) include: AI that manipulates behaviour through subliminal or deceptive techniques; exploitation of vulnerabilities of specific groups; real-time remote biometric identification in public spaces (with narrow law-enforcement exceptions); social scoring by public authorities; emotion recognition in workplaces or educational institutions (with limited exceptions); and AI that infers protected characteristics from biometric data. Regulation (EU) 2026/1744 added two new prohibitions applying from 2 December 2026: Article 5(1)(ba) prohibiting AI that generates non-consensual intimate synthetic imagery of real individuals, and Article 5(1)(bb) prohibiting AI that generates child sexual abuse material. This assessment screens for certain Article 5 risks but does not constitute exhaustive legal clearance for every prohibition.

What does Article 50 require regarding transparency?

Article 50 requires deployers to disclose to users when they are interacting with an AI system (Article 50(1)) — for example via chatbots or virtual assistants — unless this is obvious from context. AI-generated or significantly AI-modified images, audio, and video must be labelled as such in a machine-readable format (Article 50(4)). These obligations apply from 2 August 2026. Pre-existing systems in use before that date should have reached compliance promptly. There is a limited transitional accommodation for certain pre-existing synthetic content systems under the amended regulation.

Explore EU AI Act guides for SMEs

In-depth articles on each part of the Act — practical steps, official EUR-Lex citations, and FAQs drawn from real SME questions. All reviewed against Regulation (EU) 2026/1744.

EU AI Act for SMEs

Scope, roles and the full obligation map for businesses using AI

Compliance Checklist

Prioritised action list organised by deadline — act now, prepare next

Key Dates 2024–2028

Every application date including the Omnibus amendments

Article 4 — AI Literacy

What "sufficient AI literacy" means and how to document it

Article 50 — Transparency

When to disclose AI interaction and how to label synthetic content

Annex III — High-Risk AI

All eight high-risk categories and the December 2027 deployer duties

Ready to find out where you stand?

Takes about 5 minutes. No commitment required. The assessment is free.

Start your free assessment

Optional documentation packs are shown above.

Review what's included

Assessment results are informational only and do not constitute legal advice.

See Disclaimer.

Primary legal sources