The EU AI Act for SMEs: What Really Applies to You in 2026
"Do we now have to do anything because of the EU AI Act?" – that is the question SMEs ask me most often at the moment. The honest answer: probably less than the panic headlines suggest, but not nothing. And what applies shifted once more in mid-2026.
The core principle: regulation by risk
The AI Act does not regulate "AI" wholesale, but by use case and risk. Simplified into four tiers:
- Prohibited practices (e.g. social scoring, manipulative systems) – banned.
- High-risk systems (e.g. AI in candidate selection, credit scoring, critical infrastructure) – strict obligations.
- Systems with a transparency duty (e.g. chatbots or deepfakes) – information and marking duties depending on role and use case.
- Minimal risk (the bulk of everyday AI) – essentially no special obligations.
For most SMEs the key insight is: you are usually not a provider of high-risk AI, but a deployer of standard tools such as ChatGPT and the like. The heaviest obligations therefore mostly do not fall on you – but a few light ones do. What this means in practice for continuing to use ChatGPT, Copilot & co. – and whether the AI Act bans them – is covered in the article Can we still use ChatGPT & Copilot at work?.
What changed in 2026: the Digital Omnibus
The original timeline set high-risk obligations for Annex III systems from 2 August 2026 and for high-risk systems in Annex I products from 2 August 2027. The simplification package proposed in November 2025, the "Digital Omnibus", was published as Regulation (EU) 2026/1744 in the EU Official Journal on 24 July 2026. It entered into force on 27 July 2026.
The new dates are therefore the legal timeline: 2 December 2027 for Annex III high-risk systems and 2 August 2028 for high-risk systems in Annex I products. The Commission's enforcement page, updated on 6 October 2026, also confirms these dates. Important: postponed means deferred, not abolished.
What still applies to you in 2026
AI literacy and transparency remain relevant – the specific duties depend on your role and use cases.
1. AI literacy (Art. 4) – already in force since February 2025
Art. 4 has applied since 2 February 2025 and was amended by the Omnibus. Providers and deployers must take measures to support AI literacy among their staff and others dealing with AI on their behalf. They must consider prior knowledge and the context of use; they do not have to guarantee a specific individual level of competence. For SMEs, a documented internal briefing on the tools in use, their limits and data handling can be a practical measure. It also helps avoid AI data breaches.
2. Transparency obligations (Art. 50) – applicable since 2 August 2026
Art. 50 does not impose blanket visible labelling of every piece of AI-generated material. Role and use case matter:
- Direct AI interaction (paragraph 1): Providers must ensure people are informed that they are interacting with AI, for example a chatbot, unless this is obvious in the circumstances.
- Synthetic content (paragraph 2): Providers of generative AI systems must mark audio, image, video and text outputs in a machine-readable format and make them detectable as artificially generated or manipulated, as far as technically feasible. Assistive standard editing and changes that do not substantially alter input data or their meaning are exempt. Systems placed on the market before 2 August 2026 have a transition period until 2 December 2026 under Art. 111(4) for this duty.
- Emotion recognition and biometric categorisation (paragraph 3): Deployers must inform the people exposed to these systems of their use.
- Deepfakes and public-interest texts (paragraph 4): Deployers must disclose artificial generation or manipulation of deepfake images, audio or video. For evidently artistic, creative, satirical or fictional works, an appropriate disclosure that does not hamper enjoyment of the work suffices. The disclosure duty for AI text applies when it is published to inform the public on matters of public interest; it does not apply where there is human review or editorial control and a natural or legal person holds editorial responsibility.
Art. 50 also contains specific exceptions for legally authorised law-enforcement purposes. Required information must be clear, distinguishable and accessible by the first interaction or exposure (paragraph 5).
Your pragmatic roadmap
- Rule out prohibited practices. Briefly check that none of your use cases falls into the prohibited category. For normal SME usage practically never an issue, but worth a tick.
- Clarify your role. Are you anywhere a provider or deployer of a high-risk system (e.g. AI in recruiting)? If so: prepare for 2 December 2027 for Annex III or 2 August 2028 for Annex I products.
- Support AI literacy. Take and document appropriate measures, such as a briefing based on your actual AI uses.
- Check and implement transparency. Review the duties applicable since 2 August 2026 by role and use case and add missing notices. Providers must also check machine-readable marking and, where relevant, the transition period until 2 December 2026.
- Keep an eye on data flows. The AI Act obligations and the GDPR interlock – where your data goes remains the central question.
In short
For a typical SME the EU AI Act is not a major project, but a handful of manageable tasks – above all AI competence in the team and a bit of transparency. The high-risk obligations apply from 2 December 2027 for Annex III and from 2 August 2028 for Annex I products. Those who set up the basics cleanly now will not have to retrofit hectically later. And if something does go wrong, the AI incident response kit helps with a quick assessment.
Note: Legal position checked on 7 October 2026 against the official EU sources linked above; the Commission's enforcement page was last updated on 6 October 2026. This article does not replace individual legal advice.