✨ New — try Standpoint free for 14 days: full access to all 15 frameworks. A card is required, but you won’t be charged. Start your free trial →
Standpointby AI Service Pro
Security Intelligence / EU AI Act
Guide

EU AI Act for SMEs: What Actually Applies in 2026

M
Mohammad
Founder, AI Service Pro · 11 min read

Most of what you'll read about the EU AI Act and small businesses is out of date. It tells you that on August 2, 2026, the bulk of the regulation lands on you. That was the original plan. It is not what happened.

In May 2026, EU legislators agreed the Digital Omnibus on AI. The European Parliament formally endorsed it on June 16, 2026, and the Council gave final sign-off on June 29, 2026 (Consilium, White & Case). It postponed the heaviest obligations by more than a year — and left a smaller set of rules exactly where they were.

Here is the short version for a company under 750 people.

The Standpoint definition: For most SMEs, the EU AI Act in 2026 is not a compliance project. It is a disclosure project — tell people when they're talking to a machine, and mark what a machine made. The heavy engineering obligations only bite if your AI makes consequential decisions about people, and those are now a 2027 problem.

Does the EU AI Act apply to my small company?

Probably yes — but far more lightly than you think. The Act applies to any organisation that develops, places on the market, or uses an AI system in the EU, regardless of headcount. There is no small-business exemption from scope.

What size does change is which obligations attach and how hard they are to satisfy. The Act's duties are tiered by the risk of the system, not the size of the company — and most SME AI use (a support chatbot, a CRM with lead scoring, an AI writing tool, a coding assistant) sits in the two lightest tiers.

Does it apply if I'm a US company with no EU office?

Yes, if your AI system is put on the EU market or its output is used in the EU. A US SaaS company with paying customers in Berlin is in scope. Physical presence is irrelevant; so is where your servers are.

What changed in the Digital Omnibus — and is it final?

It's law. Parliament endorsed the simplification package on June 16, 2026; the Council gave its final green light on June 29, 2026; and it was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744, entering into force on 27 July 2026. The dates below are the ones now in force, not a proposal (Gibson Dunn).

Three changes matter to an SME:

  1. High-risk obligations were postponed. Stand-alone Annex III high-risk systems (hiring, credit, education, essential services, and similar) moved from August 2, 2026 → December 2, 2027. AI embedded in regulated products (Annex I) moved to August 2, 2028 (DLA Piper).
  2. Transparency obligations did not move. Article 50 still applies from August 2, 2026.
  3. The SME simplified regime was extended to "small mid-caps." More on that below.

What actually takes effect on August 2, 2026?

Article 50 transparency — and that's the part you have to handle this summer. From that date:

  • Deployers must disclose when a person is interacting with an AI system (unless it's obvious).
  • Content that is artificially generated or manipulated must be disclosed, including deepfakes.
  • Providers of generative AI must mark outputs in a machine-readable way so systems downstream can detect them.

One concession: generative systems already on the market before August 2, 2026 get until December 2, 2026 to meet the machine-readable marking requirement in Article 50(2).

GPAI (general-purpose AI model) obligations and the associated Code of Practice also continue on their existing track — relevant to you mainly as a customer of model providers, not as an obligation you carry.

Translation for a 30-person SaaS company: if you have an AI chat widget, label it. If you publish AI-generated copy or images, disclose it. If your product generates content for customers, look at machine-readable marking. That is the August work.

What moved to 2027 and 2028?

Obligation setOld dateNew date
High-risk, stand-alone (Annex III)Aug 2, 2026Dec 2, 2027
High-risk, embedded in regulated products (Annex I)Aug 2, 2027Aug 2, 2028
Article 50 transparencyAug 2, 2026Unchanged — Aug 2, 2026

If someone tells you your hiring tool needs a full conformity assessment by August, they are working from the old text.

Am I a "provider" or a "deployer"?

Provider = you develop an AI system and put it on the market under your name. If you built the AI feature in your SaaS product, you're a provider of that system.

Deployer = you use an AI system under your own authority in your business — the CRM with lead scoring, the AI notetaker, the résumé screener you bought.

Most SMEs are both: a provider of the AI in their product, and a deployer of the AI tools they bought. Provider duties are heavier. Deployer duties, even for high-risk systems, are lighter but real: human oversight, use in line with the provider's instructions, monitoring, and incident reporting.

Do this first: write down every AI-touching system in the business, and next to each one write "we built it" or "we bought it." That single column decides most of your obligations.

Is my AI system high-risk? (Almost certainly not.)

The Act sorts systems into four tiers: prohibited, high-risk, limited/transparency-risk, and minimal risk.

High-risk means the AI makes or materially informs a consequential decision about a person — employment, creditworthiness, education access, essential public or private services, law enforcement, biometrics, critical infrastructure.

Is a chatbot high-risk?

No. This is the most common error in the SME guides currently ranking on Google. A customer-support chatbot and a deepfake are transparency-tier — the obligation is to tell people, under Article 50. They are not high-risk, and they do not trigger conformity assessments, technical files, or EU-database registration.

Where SMEs do stumble into high-risk: AI résumé screening and candidate ranking. Employment is Annex III. If you use an AI hiring tool, you are a deployer of a high-risk system — and your deadline is now December 2, 2027, not this August.

What is the SME simplified regime — and do I qualify?

The Act always carried SME concessions. The Omnibus extended them to a new category, the small mid-cap (SMC): a company that exceeds the SME thresholds but has fewer than 750 employees and turnover ≤ €150 million (or a balance-sheet total ≤ €129 million) (Orrick, Mishcon de Reya).

If you're under those thresholds and you ever do land in high-risk territory, you get:

  • Simplified technical-documentation templates that notified bodies must accept.
  • Proportionate quality-management expectations instead of the full-fat version.
  • Priority access to regulatory sandboxes — supervised environments to test AI outside the normal regulatory structure. SMEs and startups get priority and free access; an EU-level sandbox is being created.
  • Tailored penalty caps.

What are the penalties — and are they lower for SMEs?

The headline numbers: up to €35 million or 7% of global annual turnover for prohibited practices, and up to €15 million or 3% for high-risk non-compliance. For SMEs and startups, the cap is the lower of the fixed amount or the percentage — the opposite of the "whichever is higher" rule that applies to large companies. Enforcement is also explicitly required to be proportionate to the size and resources of the organisation.

That's a real concession. It is not an exemption.

What should an SME actually do before August 2, 2026?

A founder-sized list. None of this needs a consultant:

  1. Inventory every AI system you build or buy. One row each: name, "built or bought," what decision it touches, whether EU users see it.
  2. Flag anything that talks to a person — chat widget, voice agent, AI email replies. Those need a disclosure.
  3. Flag anything that generates content — text, images, audio, video. Those need disclosure and, if you're the provider, machine-readable marking.
  4. Flag anything that decides about a person — hiring, credit, access. That's your future high-risk work. Diarise December 2, 2027; don't panic in July 2026.
  5. Write the disclosures. "You're chatting with an AI assistant." "Parts of this content were AI-generated." Put them where a user actually sees them, not in a footer.
  6. Keep a one-page record of what you decided and why. When a customer's security questionnaire asks about AI governance — and it will — this is the document you send.
  7. Check your vendors. If you're a deployer of someone else's AI, their compliance posture becomes your problem. Ask for it in writing.

How much does EU AI Act compliance cost an SME?

For a company whose AI is transparency-tier, the honest answer is: mostly staff time, not cash. The work is inventory, labelling, and documentation. Costs escalate only if you're a provider of a high-risk system — and that timeline is now 2027, which gives you a budgeting cycle you didn't have in May.

Do I need ISO 42001 to comply with the EU AI Act?

No. ISO/IEC 42001 is an AI management-system standard; the EU AI Act is law. They are not the same thing and one does not certify the other. That said, an ISO 42001-style management system is a very efficient way to produce the governance evidence the Act (and your enterprise customers) will ask for. Many SMEs will do it because buyers ask, not because Brussels does.

The one-sentence version

If you're an SME: label your AI, disclose your AI-generated content, inventory everything, and put December 2, 2027 in the calendar for anything that decides about a human being.

FAQ

Does the EU AI Act apply to small businesses?

Yes. There is no size exemption from scope. But most SME AI use falls into the transparency or minimal-risk tiers, where the obligation is disclosure rather than engineering. Size affects the concessions you get (simplified documentation, sandbox access, lower penalty caps), not whether the law reaches you.

What EU AI Act obligations apply on August 2, 2026?

Article 50 transparency obligations: disclose when a user is interacting with an AI system, disclose artificially generated or manipulated content including deepfakes, and — for providers of generative AI — mark outputs in a machine-readable way. Generative systems already on the market get until December 2, 2026 for the machine-readable marking requirement.

Were the EU AI Act high-risk rules really delayed?

Yes. Under the Digital Omnibus, stand-alone Annex III high-risk obligations move to December 2, 2027, and high-risk AI embedded in regulated products (Annex I) moves to August 2, 2028. Parliament endorsed the package on June 16, 2026 and the Council on June 29, 2026.

Is a customer-support chatbot a high-risk AI system?

No. Chatbots are transparency-tier under Article 50 — you must tell users they're interacting with AI. High-risk is reserved for systems making consequential decisions about people, such as hiring, credit, education access, and essential services.

What is a "small mid-cap" under the AI Act?

A company that exceeds the SME thresholds but has fewer than 750 employees and turnover of €150 million or less (or a balance sheet total of €129 million or less). The Digital Omnibus extended the AI Act's SME simplifications — simplified technical documentation, proportionate quality-management expectations, priority sandbox access, tailored penalty caps — to this category.

See where you stand — free
2-minute check · no card · runs in your browser
Run your free check →
Newsletter
Practical AI-governance & security tips, monthly

No fluff, no fear-selling. Unsubscribe anytime.

// Keep reading