Regfortis
EU AI Act for SMEs: what applies now, what's coming, and how to comply
If your business uses any AI-powered tool — a chatbot, CV screening software, credit risk model, or automated content generator — you already have active legal obligations under the EU AI Act. This guide explains what applies to SMEs, when, and what to do about it.
Last regulatory review: 14 August 2026 · Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744
Does the EU AI Act apply to my SME?
Yes — if your business operates in the EU, sells to EU customers, or uses AI systems that affect people in the EU, the Act applies to you regardless of your size. The Act distinguishes between two roles:
Provider
A business that develops and places an AI system on the market — an AI software company, for example. Providers face the heaviest obligations, including conformity assessments and EU database registration for high-risk AI.
Deployer
A business that uses an AI system built by someone else in a professional context. Most SMEs are deployers. Deployers have real obligations too — AI literacy, transparency, and (for high-risk AI from December 2027) formal deployer duties under Article 26.
Being a deployer does not mean you can ignore the Act. Articles 4 and 50 apply equally to providers and deployers from 2 August 2026, and the prohibition on harmful AI practices (Article 5) has applied to everyone since 2 February 2025.
Obligations already in force
Three sets of obligations are active today. If you use any AI tools in your business, you need to address these now.
Article 4 — AI literacy
In force: 2 August 2026
Requires deployers and providers to take proportionate measures to ensure their staff and others dealing with AI systems on their behalf have "sufficient AI literacy." This does not mandate any specific certification or training format — but it does require deliberate action: mapping which staff interact with AI, providing appropriate guidance, and keeping records.
Read the full guide
Article 50 — Transparency
In force: 2 August 2026
Requires deployers of AI systems that interact with natural persons to tell users they are dealing with an AI — unless this is obvious from context. It also requires appropriate technical measures to label AI-generated synthetic content (images, audio, video, text) so it can be identified as machine-generated.
Read the full guide
Article 5 — Prohibited practices
In force: 2 February 2025
Bans specific uses of AI outright: subliminal manipulation, exploiting vulnerabilities of protected groups, social scoring by public authorities, most uses of real-time remote biometric identification in public spaces, biometric categorisation to infer sensitive attributes, emotion inference in workplaces and schools, and AI-assisted predictive policing based solely on profiling.
Read the full guide
Check what applies to your business
The free Regfortis assessment covers Articles 4, 5, 50 and the Annex III high-risk categories. It takes about 5 minutes and gives you a prioritised action list.
Start free AI Act assessment
What's coming: Annex III high-risk AI obligations (December 2027)
Deadline amended by Regulation (EU) 2026/1744. The original August 2026 date for Chapter III (Annex III) high-risk obligations was moved to 2 December 2027. SMEs using high-risk AI systems now have more time to prepare — but preparation should start now.
Annex III lists eight categories of AI use-cases that attract the heaviest compliance burden: biometric identification, critical infrastructure, education, employment (including CV screening), essential services such as credit and insurance, law enforcement, migration, and administration of justice.
If your business uses AI in any of these areas, the full Chapter III deployer obligations — including fundamental rights impact assessments, EU AI database registration, and formal human oversight measures under Article 26 — will apply from 2 December 2027.
Read the Annex III high-risk AI guide
Explore the full EU AI Act guide for SMEs
Each page below covers one part of the Act in depth, with practical steps for SMEs and direct links to the official regulatory text.
EU AI Act Compliance Checklist for SMEs
Action list
EU AI Act Key Dates and Deadlines 2024–2028
Timeline
Article 4: AI Literacy Requirements for Employers
In force now
Article 50: AI Transparency Requirements
In force now
Article 5: Prohibited AI Practices
In force now
Annex III: High-Risk AI Systems Guide for SMEs
Dec 2027
AI System Inventory Guide and Template
Best practice
Official regulatory sources
- Regulation (EU) 2024/1689 — EU AI Act (EUR-Lex)
- Regulation (EU) 2026/1744 — Official sources
- European Commission — Official sources
- Regfortis regulatory source annotations — all articles mapped to assessment questions
This guide is for informational purposes only. It does not constitute legal advice and should not be treated as a compliance certificate or regulatory opinion. Consult qualified legal counsel for advice specific to your organisation.