A small company can buy an artificial-intelligence service in minutes. It can take much longer to answer the question European regulators now care about: what role is the company actually playing?
That distinction matters because the European Union's AI Act does not regulate every business in the same way. A firm may be a deployer using a third-party tool, a provider selling a system under its own name, an importer bringing a product into the EU, or a distributor making it available. The label on the software subscription is less important than the activity the business performs.
The regulation entered into force on 1 August 2024 and became broadly applicable on 2 August 2026. The European Commission and national authorities have now begun enforcement, including transparency requirements for certain AI-generated or manipulated content. An amendment that entered into force on 27 July 2026 changed part of the timetable: rules for high-risk systems in specified sensitive uses are scheduled for 2 December 2027, while those embedded in regulated products are scheduled for 2 August 2028.
That extension is not a general pause. Prohibited practices and AI-literacy duties have applied since February 2025, rules for general-purpose AI models began applying in August 2025, and other provisions—including specified transparency duties—apply from August 2026. A company that treats the later high-risk dates as permission to ignore AI governance is reading the calendar too narrowly.
The law can reach a supplier outside Europe
The Act covers providers placing AI systems or general-purpose AI models on the EU market, deployers located in the EU, and certain providers or deployers outside the EU when the system's output is used in the Union. A software developer in Canada, a recruitment platform in Singapore or a connected-product manufacturer in Australia may therefore need to examine the Act before accepting European customers.
There is no useful shortcut based only on company size. The regulation includes proportionate measures and simplified requirements for smaller enterprises in some areas, but an SME is not automatically outside scope. Nor does the phrase “powered by AI” decide the risk category. Classification turns on the system, its intended purpose and the context in which it is marketed or used.
Begin with an inventory, not a certificate
The practical starting point is a register of real AI use. It should identify the tool, supplier, business owner, intended purpose, people affected, data used, important outputs, human review and countries where the output is used. Include features embedded in ordinary software: applicant ranking, fraud scoring, call summaries, customer chat, image generation, pricing recommendations and workplace monitoring can otherwise disappear inside departmental budgets.
The inventory should distinguish experimentation from production. A staff member testing a public chatbot to rewrite marketing copy creates different issues from a system that recommends whether a person receives a job interview or credit. Both need rules; they do not need identical controls.
Next, record the company's role for each system. A business using an unchanged vendor product will commonly be a deployer. But a company that substantially modifies a system, changes its intended purpose or markets it under its own trade mark may acquire provider obligations. Contracts cannot reliably transfer away a role created by the facts.
Transparency is already a customer-experience issue
Article 50 addresses particular transparency situations. The Commission says obligations applying from 2 August 2026 include rules for providers and deployers of certain generative or interactive systems, such as informing people when they interact with an AI system unless that fact is obvious, and labelling specified deepfakes and certain AI-generated public-interest text. The detailed exceptions matter, so a generic “AI used” footer is not a substitute for analysing the actual output.
For a small publisher, agency or e-commerce brand, this is an editorial workflow problem as much as a legal one. Teams need a way to preserve provenance, approve disclosure wording and stop synthetic media from being published without review. The Commission's voluntary Code of Practice on AI-generated-content transparency can help organisations understand marking and labelling, but using a code does not remove responsibility for the underlying rule.
Ask vendors questions a sales page cannot answer
A vendor's claim of being “AI Act ready” is not an operating file. Buyers should ask for the system's intended purpose, model and version information, known limitations, data-handling terms, logging and retention options, security controls, human-oversight features, incident contacts and notice of material changes. If the product influences a sensitive decision, the buyer also needs to know whether the vendor's documentation supports the buyer's own obligations.
The contract should match the sales geography. A non-EU vendor serving EU customers may need an authorised representative or other arrangements depending on its role. An EU reseller should understand whether it is acting as importer or distributor. A business incorporating a model into its own service should map which evidence comes from the upstream provider and which evidence it must create itself.
AI literacy should be visible in the work
The AI-literacy obligation has applied since 2 February 2025. For an SME, useful evidence is not necessarily a long classroom course. Training should match the people, system and risk: staff should know when an output may be wrong, what confidential or personal information may not be entered, when disclosure is required, who can override a recommendation and where to report an incident.
A one-page procedure, attendance record and tested escalation route can be more credible than a generic certificate if they change behaviour. The business should revisit training after a system update, a new use case or a near miss. Governance that remains in a policy folder while employees improvise with live customer data is not governance in practice.
A workable 30-day file
During the next month, a small firm can create a defensible baseline without pretending the legal analysis is finished. Name one accountable owner; complete the AI inventory; pause any unknown or unjustified use; classify the company's role; flag employment, credit, education, biometrics, essential services and safety-related applications for specialist review; update public disclosures where required; and collect vendor evidence in one controlled location.
The team should also decide how it will respond when a model changes, produces harmful output or stops working. Record who can disable the system, how affected customers or workers can reach a person, which logs must be retained and when legal, security or privacy advisers must be involved. This work helps even where a particular use ultimately falls outside the Act, because it reduces vendor dependence and unexplained automated decisions.
The deadline moved for some systems, not for responsible management
The AI Omnibus gives businesses more time before specified high-risk requirements take effect, largely to align implementation with guidance and standards. It does not convert 2026 into a waiting year. Enforcement powers, transparency duties, existing prohibitions, AI literacy and general-purpose-model rules are part of the present landscape.
For SMEs, the sensible response is neither panic nor a badge-buying exercise. It is to turn AI from an invisible feature into an owned business process. Know what the system does, whose decision it influences, where its output travels and what evidence the company can produce. That is the point at which regulation becomes manageable—and the point at which customers can decide whether the technology deserves their trust.
Frequently asked questions
Does the EU AI Act apply to small businesses outside the EU?
It can. The Act covers certain providers and deployers outside the EU when they place covered systems or models on the EU market or when the output produced by the system is used in the EU. Scope depends on the business's role and the specific use.
Did every EU AI Act requirement start on 2 August 2026?
No. Prohibited practices and AI-literacy duties began applying in February 2025, while general-purpose AI obligations began in August 2025. Specified high-risk requirements now have later dates in December 2027 and August 2028.
Is an SME automatically exempt from the EU AI Act?
No. The law includes proportionate and simplified measures in some areas, but company size alone does not remove an organisation from scope.
What should a small business do first?
Create an inventory of AI systems, identify the supplier and business owner, document the intended use and affected people, determine the company's regulatory role, and flag sensitive applications for specialist review.
Explore More
Read the official AI Act timeline →Check which provisions apply now and which high-risk requirements take effect in 2027 or 2028.Use the EU AI Act Service Desk →Consult official information and tools for understanding roles, scope and obligations.Review the transparency guidance →Examine the Commission's current guidance for providers and deployers handling specified AI-generated content.Research sources
- European Commission — AI Act regulatory framework and application timeline
- European Commission — Enforcement of AI Act rules from 2 August 2026
- EUR-Lex — Consolidated Regulation (EU) 2024/1689 as amended on 27 July 2026
- EUR-Lex — Regulation (EU) 2026/1744 simplifying AI Act implementation
- European Commission — Transparency Code for AI-generated content
- European Commission — Guidelines for providers and deployers of high-risk AI systems
Comments
Join the discussion. Please keep comments respectful and relevant to the article.
← Back to home



No comments yet. Be the first to comment.