Guide · Last reviewed 26 August 2026
The EU AI Act for SMEs: what small companies actually have to do
SMEs are fully in scope of the EU AI Act, but with proportionate treatment: fines are capped at the lower of the percentage or fixed amount (Article 99(6), extended to small mid-caps by Regulation (EU) 2026/1744), and SME providers may use simplified Annex IV technical documentation. In 2026 the binding duties for most SMEs are Article 5 screening, Article 4 AI literacy measures and the Article 50 transparency rules; high-risk obligations start 2 December 2027.
Last reviewed: 26 August 2026 · Primary source: Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.
Yes, the AI Act applies to you — but less than the headlines suggest
There is no SME exemption from the AI Act: if your staff use AI tools professionally, you are a deployer; if you build AI into a product you sell, you are a provider — company size does not change the role (Articles 3(3)-(4)). What size does change is proportionality: fine caps, simplified documentation, priority access to regulatory sandboxes, and — since the Digital Omnibus — extension of several reliefs to the new small mid-cap category.
The other good news is scope. The heavy obligations attach to high-risk systems, and most SMEs neither provide nor deploy any. A typical small company using generative AI tools, a website chatbot and some AI features inside SaaS products faces a compliance workload measured in days, not months. The workload only grows if you build AI products, or use AI in Annex III areas such as recruitment or credit decisions — then the high-risk regime is your problem from 2 December 2027.
What is binding for SMEs right now (August 2026)
Three obligations apply today to essentially every company using AI:
- Article 5 — prohibited practices (since 2 February 2025): screen your AI uses against the banned list; note the additional CSAM/NCII prohibitions from 2 December 2026. For most SMEs the result is a documented 'nothing prohibited'.
- Article 4 — AI literacy (since 2 February 2025): take measures that support the development of sufficient AI literacy among staff using AI on your behalf. Post-Omnibus, this is explicitly a measures obligation — no guaranteed competence level per person, and formal training is one option, not the only one. A short policy, role-appropriate guidance and a record of what you did will carry you. See Article 4 explained.
- Article 50 — transparency (since 2 August 2026): if you provide a chatbot or generative system, design in AI disclosure (50(1)) and machine-readable marking of synthetic output (50(2) — grace to 2 December 2026 for systems on the market before 2 August 2026; no SME exemption, though cost and state of the art may be considered). If you merely use third-party tools, your duty is the deployer layer: disclose deepfakes and AI-generated public-interest text (50(4)) and inform people about emotion recognition or biometric categorisation (50(3)).
Work through all of it in order with the compliance checklist.
The SME reliefs, precisely
Fine cap (Article 99(6)): the AI Act's maximum fines are €35 million or 7% of worldwide turnover (prohibitions), €15 million or 3% (most obligations) and €7.5 million or 1% (incorrect information). For most undertakings the applicable ceiling is whichever is higher; for SMEs and start-ups it is whichever is lower — for a small company, the percentage of turnover, not the eight-figure sum. The Omnibus extended this proportionate treatment to small mid-caps (SMCs).
Who counts: SME status follows Recommendation 2003/361/EC (below 250 employees and turnover/balance-sheet ceilings). The SMC category comes from Commission Recommendation (EU) 2025/1099 of 21 May 2025 — enterprises below roughly 750 employees within defined financial ceilings. Keep the two definitions separate when you claim relief.
Simplified documentation: SME providers of high-risk systems may supply the Annex IV technical documentation in the simplified form provided for small companies (Article 11) — same information obligations in substance, lighter format.
Also for SMEs: priority, cost-free access to regulatory sandboxes (Article 62) and proportionate quality-management implementation. None of this touches liability: reliefs shrink penalties and paperwork, not obligations.
Realistic effort for a typical SME
For a company of 10-100 people using off-the-shelf AI tools and providing none:
- AI inventory: half a day to a day — list the tools, owners, data and purposes.
- Role mapping and Article 5 screen: a few hours — you will almost certainly be a deployer throughout, with no prohibited practices.
- Article 4 measures: one to two days to adopt a policy, brief staff and set up records.
- Article 50 check: an hour per system to confirm which duties are the vendor's (marking) and which are yours (disclosure).
- Vendor due diligence: an hour per new AI tool with a standing questionnaire.
- Ongoing: keep the inventory current, screen new tools at intake, diarise 2 December 2026 (new prohibitions, end of marking grace) and 2 December 2027 (Annex III) in a compliance calendar.
If you provide an AI system, add the provider transparency work now, and — if the system is plausibly Annex III — start the high-risk workstream in 2026, because risk management, data governance, Annex IV documentation and conformity assessment realistically take 12-18 months.
Common myths, corrected
'The AI Act doesn't apply to small companies.' False — roles, not size, decide. The reliefs are proportionate penalties and paperwork, not exemption.
'We must send everyone to certified AI training.' False. Article 4 (as amended) requires measures supporting AI literacy; it never mandated certified courses, prescribed no cadence, and post-Omnibus explicitly guarantees no individual competence level.
'Using ChatGPT makes us a provider with marking duties.' False. Using a third-party tool makes you a deployer; the Article 50(2) marking duty stays with the tool's provider. Your duty is disclosure under Article 50(4) where it applies. But putting your own brand on an AI system is a different story — see the white-label trap.
'Everything hits in 2026.' False. High-risk obligations start 2 December 2027 (Annex III) and 2 August 2028 (Annex I). What binds SMEs in 2026 is the short list above.
'Fines of €35 million could kill us.' Misleading. For SMEs, start-ups and small mid-caps each fine is capped at the lower of the percentage or the fixed amount (Article 99(6)) — proportionate to your turnover, though real enough to take seriously.
Related reading
- AI System Inventory template
- AI Literacy Policy template
- Internal AI-Use Policy template
- Prohibited-Practices Screening template
- Vendor Due-Diligence Questionnaire template
- Compliance Calendar template
- The EU AI Act, explained
- Compliance checklist
- Provider vs deployer
- The Digital Omnibus 2026
- Fines & the SME cap
- AI literacy (Article 4)
- Timeline & deadlines
Frequently asked
Is there an SME exemption from the EU AI Act?+
No. SMEs have proportionate treatment — fines capped at the lower of the percentage or fixed amount (Article 99(6)), simplified Annex IV documentation for providers, sandbox access — but the obligations themselves apply regardless of company size.
What must a small company do before the end of 2026?+
Inventory AI use, confirm no Article 5 prohibited practices (including the new CSAM/NCII prohibitions from 2 December 2026), take Article 4 AI literacy measures, and implement the Article 50 transparency duties matching your role. Providers of generative systems on the market before 2 August 2026 must meet the Article 50(2) marking duty by 2 December 2026.
What is a small mid-cap and why does it matter?+
A small mid-cap (SMC) is an enterprise below roughly 750 employees within turnover and balance-sheet ceilings defined in Commission Recommendation (EU) 2025/1099. Since the Digital Omnibus (Regulation (EU) 2026/1744), SMCs benefit from the proportionate 'lower of' fine treatment previously reserved for SMEs and start-ups.
Do we need a lawyer or consultant to comply?+
For the 2026 deployer duties, generally no — the obligations are operational (inventory, screening, policy, disclosures) and can be implemented with good templates. Legal advice becomes valuable when your role is unclear, when you provide AI systems, or when a system may be Annex III high-risk.