KlarComply
Language:DEENNL
HomeKnowledge › The AI Act for SMEs

EU AI Act for SMEs: the plan without a consulting project

Most writing about the AI Act was produced for large corporations. This was not. It assumes you have between ten and two hundred and fifty people, that you use AI rather than build it, and that you have very little time. It also assumes you may not be in the EU at all — which, as it turns out, changes less than you would hope.

Are you even in scope?

Very probably yes — but almost certainly less heavily than you fear. The regulation has no headcount threshold and no turnover threshold. It distinguishes by role and by risk, not by size.

Your role decides most of it. A company that only uses AI tools is a deployer, and the catalogue of duties for deployers is short. You become a provider, with substantially more obligations, only when you place a system on the market or put it into service under your own name or trade mark, or when you substantially modify one or change its intended purpose — putting a branded chatbot on your website is the classic example.

If you are not in the EU: read Article 2 first

This is the part that catches English-speaking readers, and it is worth more than a footnote. Article 2 defines the scope by effect. It covers:

The third limb is the one that surprises people. It does not ask where your servers are, where your company is registered, or whether you have any EU entity. It asks where the output lands.

Three concrete cases

Conversely, a purely domestic US business whose AI output never reaches the EU is not brought into scope by this regulation. Being honest about that boundary matters as much as being honest about the reach.

There is one further asymmetry worth knowing. Providers outside the EU that place systems on the EU market must appoint an authorised representative established in the Union under Article 22 — and Article 22 is in the penalty catalogue. Deployers do not carry that duty. If you are unsure which side of the provider/deployer line you sit on, that question is worth resolving before anything else.

The deadlines — as they stand after the Digital Omnibus

The Digital Omnibus was finally adopted on 29 June 2026 and entered into force in July 2026. It is applicable law, not an announcement, and the postponements in it are real.

DateWhat applies
2 Feb 2025Prohibited practices (Art. 5) · AI literacy obligation (Art. 4)
2 Aug 2025Obligations for general-purpose AI models, governance, national penalty regimes
2 Aug 2026Transparency obligations (Art. 50) · national market surveillance operational
2 Dec 2026Art. 50(2) extends to systems already on the market · further prohibitions take effect
9 Dec 2026Transposition deadline of the new EU Product Liability Directive (EU) 2024/2853 — software and AI count as products
2 Dec 2027High-risk obligations for standalone systems — postponed
2 Aug 2028High-risk obligations for AI embedded in regulated products — postponed

The short version: if you build high-risk AI, you have gained time. If you merely use AI, your dates have already passed.

The date that is quietly the more important one

9 December 2026 is the transposition deadline for Directive (EU) 2024/2853 on liability for defective products. It brings software and AI systems within the definition of a product, extends the notion of damage to include destruction or corruption of data, and eases the burden of proof for claimants in technically complex cases.

That is a civil liability regime, not a regulatory one — it does not depend on an authority noticing you. It depends on someone suffering damage and bringing a claim. For a company deploying AI in customer-facing processes, that is a more probable route to a bad afternoon than a market surveillance inspection.

What deployers actually have to do

  1. Support AI literacy (Art. 4) — basic training for everyone who uses AI, documented. No separate fine attaches to this one; see our page on Article 4 for why that matters and why you should do it anyway.
  2. Provide transparency (Art. 50) — label chatbots, label photorealistic AI images, set a human approval step for published text. This one is fined. Free labels are on our AI labels page.
  3. Avoid prohibited practices (Art. 5) — for smaller companies the relevant one is emotion inference in the workplace, which is prohibited outright and is occasionally sold as an HR analytics feature.
  4. Keep an overview — an AI inventory, without which none of the above can be evidenced.
  5. Follow the provider's instructions for use (Art. 26, where high-risk systems are involved) and assign human oversight to someone with the competence and authority to exercise it.

Everything beyond that — conformity assessment, technical documentation, registration in the EU database, post-market monitoring — concerns providers and high-risk systems. That is a small minority of mid-sized companies, and it is worth checking whether you are in it rather than assuming either way.

The two situations where an SME does land in the high-risk regime

Of the eight areas in Annex III, only two come up regularly for smaller companies:

If you deploy something in either area: document it, escalate it to management, and take legal advice. The December 2027 deadline buys you time to comply, not time to work out whether you are in scope. The classification should be on paper now.

Who enforces this, and how does it actually go?

Enforcement sits with the national market surveillance authorities designated by each member state, coordinated at Union level by the European AI Office and the AI Board. Which authority that is varies by country — some have handed it to their telecoms or data protection regulator, others created something new. If you sell into several member states, you may deal with more than one.

The Commission also runs an AI Act Service Desk as a single entry point for questions, aimed particularly at SMEs, alongside the regulatory sandboxes that each member state was required to establish.

Realistically, authorities do not open with fines. They open with a request for information and an order to remedy. A company that can produce its inventory, its policy and its training records at that point is through the process.

And the more frequent trigger is not a regulator at all. It is a supplier questionnaire from a business customer. The five questions on those have become remarkably standardised: your register of AI systems, your internal policy, your training status, your named responsible person, and whether you deploy any high-risk systems. That is the deadline that turns out to be real, and it arrives without warning.

The effort, quantified honestly

For a company of around fifty people that uses AI rather than builds it:

That is the realistic envelope. Anyone trying to sell you a six-figure consulting project is describing a different size of company — one with a legal department, a model risk function and an obligation to answer to a supervisory board. If that is you, this page is not the right one.

If it is not, the free quick check takes two minutes and tells you which of the ten points you have already covered. Where the gaps warrant more than a checklist, the compliance kit supplies the register, the policy template and the training material as a package.

Frequently asked questions

Does the AI Act apply to small companies?

Yes. There is no headcount or turnover threshold. The regulation distinguishes by role and risk, not by size. For companies that only use AI, however, the catalogue of duties is short.

Does the EU AI Act apply to companies outside the EU?

It can. Article 2 covers providers placing AI systems on the EU market irrespective of establishment, deployers located in the Union, and providers and deployers in third countries where the output produced by the AI system is used in the Union. A UK, US or Swiss firm whose AI output reaches people in the EU is in scope for that activity.

What is the difference between a provider and a deployer?

Deployers use an AI system in a professional capacity — that covers most companies. Providers develop a system or place it on the market under their own name. A company that offers a bought-in system under its own brand, substantially modifies it, or changes its intended purpose becomes a provider in law.

Were the deadlines postponed?

Partly. The Digital Omnibus moved the high-risk obligations to December 2027 and August 2028. The date of 2 August 2026 for the transparency obligations and the start of market surveillance was left unchanged.

Do we need an AI officer?

No such appointment is required by law, unlike the data protection officer under the GDPR. In practice it has become standard, because the duties fall on the company and without a named person nobody discharges them. It is also the first question on most supplier questionnaires.

How much time does implementation take?

For a company of around fifty people: half a day to a day for initial set-up, roughly thirty minutes of training per person, and two to six hours a month on an ongoing basis.

What changes on 9 December 2026?

That is the transposition deadline for the new EU Product Liability Directive (EU) 2024/2853, under which software and AI systems count as products. It is a civil liability regime: it eases the burden of proof for claimants and extends damage to include corruption of data. It does not depend on a regulator taking an interest.

Where does your company stand?

The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.

Start the quick check — free
Read on AI literacy obligation → Building an AI inventory → Labelling AI content (Art. 50) → Writing an AI policy →
Sources:
Regulation (EU) 2024/1689 — official consolidated text, EUR-Lex
Article 2 EU AI Act — scope
Article 26 EU AI Act — obligations of deployers
Article 99 EU AI Act — penalties
European Commission — regulatory framework for AI
European Commission — AI Act Service Desk
Directive (EU) 2024/2853 — liability for defective products
Reviewed on 2 August 2026 · Reflects the Digital Omnibus · This article is general information and not legal advice.
Legal notice·Privacy·Terms·[email protected]