EU AI Act Compliance for SMEs: What to Handle Now

qw
vc
mshm
Trending AI Topics
July 27, 2026
Cinematic image of a glowing shield with a luminous checkmark, surrounded by calendar fragments, symbolizing EU AI Act compliance.

The EU AI Act has applied since 1 August 2024, but rolls out in phases: prohibited practices and AI literacy became mandatory on 2 February 2025, GPAI rules on 2 August 2025, and from 2 August 2026 regulators can start enforcing. For SMEs, this means the priority now is to inventory which AI you use, classify the risk, and document governance before the high-risk obligations follow in 2027.

Last updated: 2026-07-27

Summary

 

  • Parts of the EU AI Act already apply: prohibited practices and AI literacy since 2 February 2025, GPAI rules since 2 August 2025.
  • From 2 August 2026, regulators can enforce the law and the transparency rules take effect.
  • High-risk obligations have been delayed to 2 December 2027, via the Digital Omnibus agreement of 7 May 2026.
  • Four steps are enough to get started: inventory, classify, set up governance, choose an EU-compliant AI stack.
  • In the Netherlands, the Autoriteit Persoonsgegevens and the Rijksinspectie Digitale Infrastructuur provide oversight.

 

The EU AI Act has applied since 1 August 2024, but rolls out in phases: prohibited practices and AI literacy became mandatory on 2 February 2025, GPAI rules on 2 August 2025, and from 2 August 2026 regulators can start enforcing. For SMEs, this means the priority now is to inventory which AI you use, classify the risk, and document governance before the high-risk obligations follow in 2027.

 

 

What Is the EU AI Act, and Why Act Now

 

The EU AI Act, formally Regulation (EU) 2024/1689, is the first broad European law regulating the use of artificial intelligence. The regulation entered into force on 1 August 2024, but applies in phases: not every obligation kicked in on that date.

That phased rollout is exactly why many SME leadership teams feel confused right now. You hear about 'the AI law' in the news, but no one explains which part of it already applies to your business today.

The core idea is simple. If you deploy AI, you are a provider or a deployer under the law, and both roles carry obligations. That applies to a chatbot on your website just as much as to a small piece of automation, or to the digital workforce you use for customer contact.

For SMEs, this is not some distant, abstract issue. You are probably already using AI: a language model for text, a tool for CV screening, a chatbot for support. Every one of those applications falls under the regulation, even if you built nothing yourself and simply use an existing tool.

There is also a practical reason to start now rather than after the first round of enforcement. You can build an AI file at a calm pace, with time to ask suppliers questions and revisit choices. Wait until a regulator comes knocking, and you end up working under time pressure on something that never needed to be rushed.

 

 

The Enforcement Timeline: Which Obligations Already Apply

 

The EU AI Act rolls out in phases, each with a fixed date on which a new block of obligations kicks in. Three dates determine what you need to handle already: 2 February 2025, 2 August 2025, and 2 August 2026.

Since 2 February 2025, the eight prohibited AI practices from Article 5 have been in force, together with the AI literacy obligation from Article 4 (Regulation (EU) 2024/1689, 2024). Since 2 August 2025, the governance rules and the obligations for providers of general-purpose AI models have applied, such as the language models behind ChatGPT, Copilot, and Claude.

From 2 August 2026, national regulators gain enforcement powers and the transparency obligation from Article 50 takes effect. That is also the date on which most fining powers become active (European Commission, 2026).

 

Already mandatory: since February and August 2025

 

  • Prohibited practices (Art. 5): social scoring, manipulative AI, and untargeted scraping for facial recognition are no longer allowed, since 2 February 2025
  • AI literacy (Art. 4) and GPAI governance: staff must have basic knowledge of the AI they use, and providers of AI models must supply documentation, since 2 August 2025

 

New from 2 August 2026

 

  • Transparency obligation (Art. 50): a chatbot must identify itself as an AI system, and AI-generated content must be recognisable as such
  • Enforcement: national regulators gain the power to fine violations of Article 4 and Article 5

 

Delayed: high-risk systems (Annex III)

 

  • Originally: the heaviest obligations for high-risk AI systems, think CV screening or credit scoring, were due to take effect on 2 August 2026
  • After the Digital Omnibus agreement of 7 May 2026: that date has shifted to 2 December 2027, and to 2 August 2028 for AI embedded in products such as lifts or toys (European Commission, 2026)

 

Horizontal timeline with four highlighted years for the phased rollout of the EU AI Act.
The EU AI Act rolls out in four clear steps, from 2024 to 2027.

 

For SMEs, this is no reason to sit back. Enforcement of Article 4 and 5 starts in full in August 2026, and it affects virtually every business that uses AI (EU Artificial Intelligence Act, Implementation Timeline, 2026).

 

 

GDPR or EU AI Act: Which Law Covers What

 

The GDPR and the EU AI Act are two separate laws that can apply at the same time. The GDPR regulates personal data, the EU AI Act regulates the AI system itself. If you use AI to process personal data, both laws apply side by side, and neither one replaces the other (DLA Piper, 2024).

The two laws overlap on points such as risk assessment and human oversight, but the instruments are not interchangeable. A GDPR Data Protection Impact Assessment (DPIA) does not replace a Fundamental Rights Impact Assessment (FRIA) under the EU AI Act, and vice versa (IAPP, 2026).

 

GDPR (General Data Protection Regulation)

 

  • Scope: personal data, regardless of whether AI is involved
  • Main instrument: the DPIA (Data Protection Impact Assessment) for high-risk processing

 

EU AI Act

 

  • Scope: the AI system itself, even when no personal data is involved
  • Main instrument: risk classification, and for high-risk systems, a FRIA (Fundamental Rights Impact Assessment)

 

In practice, this means a GDPR check does not automatically cover your EU AI Act homework too. If you only have the GDPR in order, you are still missing the risk classification and the governance requirements of the AI law.

If you already keep a processing register under the GDPR, that is actually a good starting point. Add, per processing activity, whether AI is involved and what risk level that AI application carries, and your GDPR register naturally grows into a foundation for your EU AI Act file.

 

 

Four Steps to Get Your AI Use in Order Now

 

You don't need a legal department to start today. Four steps take you from ad hoc AI use to a file that demonstrably holds up.

 

Step 1: inventory which AI systems you already use

 

Make a list: which tool, for what purpose, and who in your organisation works with it. That's less work than it sounds, because most AI is already baked into software you buy: a CRM with AI scoring, a chatbot plugin, a small piece of agentic AI that processes invoices or follows up leads on its own.

Ask your suppliers too. Since 2 August 2025, providers of general-purpose AI models must be able to show documentation, and you simply request that from your account manager.

 

Step 2: classify the risk of each AI system

 

The EU AI Act has four risk classes: unacceptable (prohibited), high risk, limited risk, and minimal risk. Most SME applications, such as internal text generation or a spam filter, fall into the lowest class.

Pay close attention when AI helps decide about people: recruitment and selection, credit scoring, or staff assessment. Those applications fall into the high-risk class more quickly and require a heavier file.

 

Four numbered steps for EU AI Act compliance: inventory, classify, governance, and EU stack.
Four steps bring your AI use into order.

 

Step 3: set up governance and responsibilities

 

Appoint someone to keep the AI file up to date. That doesn't need to be a full-time role: at many SMEs, this sits with the same person who already oversees GDPR compliance.

Document how human-in-the-loop works for each system: who checks the output, and who steps in when an AI system proposes a decision that's wrong. Governance is not an extra layer of bureaucracy, it's the proof that you are in control. If no one is watching this overview, a Fractional Chief AI Officer is one way to fill that role temporarily without creating a new full-time position.

In the Netherlands, the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority) and the Rijksinspectie Digitale Infrastructuur are proposed as coordinating regulators under the Dutch Implementation Act for the AI Regulation (Rijksoverheid, 2026). Until that act is passed, the Autoriteit Persoonsgegevens already acts as the de facto coordinating regulator (Autoriteit Persoonsgegevens, 2025).

 

Step 4: choose an EU-compliant, GDPR-compliant AI stack

 

The systems you set up from scratch, you can get right from day one. Choose AI suppliers that host in the EU, that offer a clear data processing agreement, and that don't train on your data without consent.

That's also the starting point for our own AI Bedrijfsbrein: one connected AI system instead of separate tools you have to check one by one.

 

 

Checklist: What to Handle This Month

 

Overview is nice, action is better. The breakdown below helps you separate what you can do this week from what needs more time.

 

This week

 

  • Start the inventory: a spreadsheet with tool, purpose, and owner for each AI system
  • Appoint an owner: someone who keeps the file up to date and can answer questions from suppliers or regulators

 

This month

 

  • Classify each system: unacceptable, high risk, limited risk, or minimal risk
  • Request documentation from suppliers: especially from providers of general-purpose AI models

 

This quarter

 

  • Document human-in-the-loop: describe, per high-risk system, who checks the output
  • Review your AI stack: replace tools without EU hosting or without a clear data processing agreement

 

Three ascending platforms with glowing checkmarks, symbolizing progress on the EU AI Act checklist.
From this week to this quarter: small steps that add up.

 

None of these steps is a year-long project. Most SMEs have the inventory and classification wrapped up within a day of focused work, the rest is a matter of keeping at it.

 

 

What a First-Mover Advantage Gets You

 

Most SMEs wait until a fine or an audit forces them to react. Whoever gets their house in order now won't need to rush once regulators actually start enforcing.

That's more than risk management. Clients and partners increasingly ask how you handle AI and data, especially in sectors like real estate, accounting, and construction, where trust is the basis of the relationship.

A demonstrable AI readiness is then a concrete sales argument, not just a compliance checkbox. You can show that you know which AI you use, why, and how you keep it under control.

 

One bright glowing node ahead of a row of dimmer nodes, symbolizing a first-mover advantage in EU AI Act compliance.
Whoever leads now won't need to rush later.

 

If you want to take that step now instead of after the first round of enforcement, arranging EU AI Act compliance is exactly the moment where you still have influence today over how that process unfolds.

Companies that handle this now usually don't do it out of fear of a fine. They do it because a clear AI file also brings internal peace of mind: everyone knows which tools are allowed, who oversees them, and why.

 

 

Frequently Asked Questions

 

What exactly is the EU AI Act?

 

The EU AI Act (Regulation (EU) 2024/1689) is the European law that regulates the use and development of artificial intelligence based on risk. It bans a small number of AI applications, sets strict requirements for high-risk systems, and requires transparency for chatbots and AI-generated content. The law entered into force on 1 August 2024 and has applied in phases ever since.

 

Does the EU AI Act also apply to small businesses (SMEs)?

 

Yes, the law makes no exception for company size: as soon as you use or offer an AI system, you fall under the regulation. What does change for SMEs are the fine caps: under Article 99(6), a small business pays the lower of the fixed cap or the revenue percentage, not the higher amount that applies to large companies. An SME with 2 million euros in revenue therefore risks a maximum of 7% of that revenue for the most severe violation, not tens of millions.

 

When do the EU AI Act's obligations take effect?

 

In phases: prohibited practices and AI literacy since 2 February 2025, governance rules and GPAI obligations since 2 August 2025, and transparency plus enforcement powers from 2 August 2026. The heaviest obligations for high-risk systems have been shifted to 2 December 2027 via the Digital Omnibus agreement of 7 May 2026.

 

What is the difference between the GDPR and the EU AI Act?

 

The GDPR governs how you handle personal data, whether or not AI is involved. The EU AI Act governs the AI system itself, even when no personal data is involved. If you use AI to process personal data, both laws apply at the same time, and neither replaces the other.

 

Which AI applications are classified as high risk?

 

Applications that help decide about people: recruitment and selection, credit scoring, access to essential services, and AI in critical infrastructure or education. These systems fall under Annex III of the regulation and require a conformity assessment, technical documentation, and human oversight.

 

What happens if you don't comply with the EU AI Act on time?

 

From 2 August 2026, national regulators, in the Netherlands the Autoriteit Persoonsgegevens and the Rijksinspectie Digitale Infrastructuur, can investigate complaints and impose fines. For most violations, SMEs pay the lower of a fixed cap or a revenue percentage. In practice, regulators are expected to start with questions and a period to fix things before fining a company that can demonstrably show it's working on compliance.

 

How do you start an AI risk assessment?

 

Start with a complete inventory of the AI systems you use, including AI features hidden inside existing software. Assess, for each system, whether it helps decide about people and which of the four risk classes it falls into. Record that classification, even if the outcome is minimal risk, because that is your proof that you went through the process.

 

What does an EU-hosted AI stack mean for compliance?

 

An EU-hosted stack keeps your data within European jurisdiction and makes it easier to comply with both the GDPR and the EU AI Act. When choosing suppliers, look for a clear data processing agreement, no training on your data without consent, and documentation you can produce immediately during an audit.

 

 

Want to get EU AI Act compliance sorted in your organisation?

 

If you wait until enforcement begins, you'll be scrambling for time you can easily spare today. We'll check together where you stand now and what to tackle first.

Check your EU AI Act readiness with us

Read more articles

From insight to impact.
We translate AI oportunities into practical profit for your business.
z
z
z
z
i
i
z
z