
Last updated: 2026-07-27
The EU AI Act has applied since 1 August 2024, but rolls out in phases: prohibited practices and AI literacy became mandatory on 2 February 2025, GPAI rules on 2 August 2025, and from 2 August 2026 regulators can start enforcing. For SMEs, this means the priority now is to inventory which AI you use, classify the risk, and document governance before the high-risk obligations follow in 2027.
The EU AI Act, formally Regulation (EU) 2024/1689, is the first broad European law regulating the use of artificial intelligence. The regulation entered into force on 1 August 2024, but applies in phases: not every obligation kicked in on that date.
That phased rollout is exactly why many SME leadership teams feel confused right now. You hear about 'the AI law' in the news, but no one explains which part of it already applies to your business today.
The core idea is simple. If you deploy AI, you are a provider or a deployer under the law, and both roles carry obligations. That applies to a chatbot on your website just as much as to a small piece of automation, or to the digital workforce you use for customer contact.
For SMEs, this is not some distant, abstract issue. You are probably already using AI: a language model for text, a tool for CV screening, a chatbot for support. Every one of those applications falls under the regulation, even if you built nothing yourself and simply use an existing tool.
There is also a practical reason to start now rather than after the first round of enforcement. You can build an AI file at a calm pace, with time to ask suppliers questions and revisit choices. Wait until a regulator comes knocking, and you end up working under time pressure on something that never needed to be rushed.
The EU AI Act rolls out in phases, each with a fixed date on which a new block of obligations kicks in. Three dates determine what you need to handle already: 2 February 2025, 2 August 2025, and 2 August 2026.
Since 2 February 2025, the eight prohibited AI practices from Article 5 have been in force, together with the AI literacy obligation from Article 4 (Regulation (EU) 2024/1689, 2024). Since 2 August 2025, the governance rules and the obligations for providers of general-purpose AI models have applied, such as the language models behind ChatGPT, Copilot, and Claude.
From 2 August 2026, national regulators gain enforcement powers and the transparency obligation from Article 50 takes effect. That is also the date on which most fining powers become active (European Commission, 2026).

For SMEs, this is no reason to sit back. Enforcement of Article 4 and 5 starts in full in August 2026, and it affects virtually every business that uses AI (EU Artificial Intelligence Act, Implementation Timeline, 2026).
The GDPR and the EU AI Act are two separate laws that can apply at the same time. The GDPR regulates personal data, the EU AI Act regulates the AI system itself. If you use AI to process personal data, both laws apply side by side, and neither one replaces the other (DLA Piper, 2024).
The two laws overlap on points such as risk assessment and human oversight, but the instruments are not interchangeable. A GDPR Data Protection Impact Assessment (DPIA) does not replace a Fundamental Rights Impact Assessment (FRIA) under the EU AI Act, and vice versa (IAPP, 2026).
In practice, this means a GDPR check does not automatically cover your EU AI Act homework too. If you only have the GDPR in order, you are still missing the risk classification and the governance requirements of the AI law.
If you already keep a processing register under the GDPR, that is actually a good starting point. Add, per processing activity, whether AI is involved and what risk level that AI application carries, and your GDPR register naturally grows into a foundation for your EU AI Act file.
You don't need a legal department to start today. Four steps take you from ad hoc AI use to a file that demonstrably holds up.
Make a list: which tool, for what purpose, and who in your organisation works with it. That's less work than it sounds, because most AI is already baked into software you buy: a CRM with AI scoring, a chatbot plugin, a small piece of agentic AI that processes invoices or follows up leads on its own.
Ask your suppliers too. Since 2 August 2025, providers of general-purpose AI models must be able to show documentation, and you simply request that from your account manager.
The EU AI Act has four risk classes: unacceptable (prohibited), high risk, limited risk, and minimal risk. Most SME applications, such as internal text generation or a spam filter, fall into the lowest class.
Pay close attention when AI helps decide about people: recruitment and selection, credit scoring, or staff assessment. Those applications fall into the high-risk class more quickly and require a heavier file.

Appoint someone to keep the AI file up to date. That doesn't need to be a full-time role: at many SMEs, this sits with the same person who already oversees GDPR compliance.
Document how human-in-the-loop works for each system: who checks the output, and who steps in when an AI system proposes a decision that's wrong. Governance is not an extra layer of bureaucracy, it's the proof that you are in control. If no one is watching this overview, a Fractional Chief AI Officer is one way to fill that role temporarily without creating a new full-time position.
In the Netherlands, the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority) and the Rijksinspectie Digitale Infrastructuur are proposed as coordinating regulators under the Dutch Implementation Act for the AI Regulation (Rijksoverheid, 2026). Until that act is passed, the Autoriteit Persoonsgegevens already acts as the de facto coordinating regulator (Autoriteit Persoonsgegevens, 2025).
The systems you set up from scratch, you can get right from day one. Choose AI suppliers that host in the EU, that offer a clear data processing agreement, and that don't train on your data without consent.
That's also the starting point for our own AI Bedrijfsbrein: one connected AI system instead of separate tools you have to check one by one.
Overview is nice, action is better. The breakdown below helps you separate what you can do this week from what needs more time.

None of these steps is a year-long project. Most SMEs have the inventory and classification wrapped up within a day of focused work, the rest is a matter of keeping at it.
Most SMEs wait until a fine or an audit forces them to react. Whoever gets their house in order now won't need to rush once regulators actually start enforcing.
That's more than risk management. Clients and partners increasingly ask how you handle AI and data, especially in sectors like real estate, accounting, and construction, where trust is the basis of the relationship.
A demonstrable AI readiness is then a concrete sales argument, not just a compliance checkbox. You can show that you know which AI you use, why, and how you keep it under control.

If you want to take that step now instead of after the first round of enforcement, arranging EU AI Act compliance is exactly the moment where you still have influence today over how that process unfolds.
Companies that handle this now usually don't do it out of fear of a fine. They do it because a clear AI file also brings internal peace of mind: everyone knows which tools are allowed, who oversees them, and why.
The EU AI Act (Regulation (EU) 2024/1689) is the European law that regulates the use and development of artificial intelligence based on risk. It bans a small number of AI applications, sets strict requirements for high-risk systems, and requires transparency for chatbots and AI-generated content. The law entered into force on 1 August 2024 and has applied in phases ever since.
Yes, the law makes no exception for company size: as soon as you use or offer an AI system, you fall under the regulation. What does change for SMEs are the fine caps: under Article 99(6), a small business pays the lower of the fixed cap or the revenue percentage, not the higher amount that applies to large companies. An SME with 2 million euros in revenue therefore risks a maximum of 7% of that revenue for the most severe violation, not tens of millions.
In phases: prohibited practices and AI literacy since 2 February 2025, governance rules and GPAI obligations since 2 August 2025, and transparency plus enforcement powers from 2 August 2026. The heaviest obligations for high-risk systems have been shifted to 2 December 2027 via the Digital Omnibus agreement of 7 May 2026.
The GDPR governs how you handle personal data, whether or not AI is involved. The EU AI Act governs the AI system itself, even when no personal data is involved. If you use AI to process personal data, both laws apply at the same time, and neither replaces the other.
Applications that help decide about people: recruitment and selection, credit scoring, access to essential services, and AI in critical infrastructure or education. These systems fall under Annex III of the regulation and require a conformity assessment, technical documentation, and human oversight.
From 2 August 2026, national regulators, in the Netherlands the Autoriteit Persoonsgegevens and the Rijksinspectie Digitale Infrastructuur, can investigate complaints and impose fines. For most violations, SMEs pay the lower of a fixed cap or a revenue percentage. In practice, regulators are expected to start with questions and a period to fix things before fining a company that can demonstrably show it's working on compliance.
Start with a complete inventory of the AI systems you use, including AI features hidden inside existing software. Assess, for each system, whether it helps decide about people and which of the four risk classes it falls into. Record that classification, even if the outcome is minimal risk, because that is your proof that you went through the process.
An EU-hosted stack keeps your data within European jurisdiction and makes it easier to comply with both the GDPR and the EU AI Act. When choosing suppliers, look for a clear data processing agreement, no training on your data without consent, and documentation you can produce immediately during an audit.
If you wait until enforcement begins, you'll be scrambling for time you can easily spare today. We'll check together where you stand now and what to tackle first.