What is the EU AI Act? A plain-English guide for SMEs
Published June 9, 2026 · 5 min read
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive law on artificial intelligence. It took a risk-based approach: the more risk an AI system poses to health, safety, or fundamental rights, the more obligations apply. It entered into force in August 2024 and rolls out in stages.
The four risk tiers
- Prohibited (Article 5) — banned uses such as social scoring and untargeted facial-image scraping. In force since 2 February 2025.
- High-risk (Annex III / Annex I) — e.g. recruitment, credit scoring, and medical devices. The heaviest obligation set.
- Limited risk (Article 50) — chatbots and generative AI, subject to transparency and labelling.
- Minimal risk — everything else; no mandatory obligations.
Does the EU AI Act apply to my business?
Most SMEs are in one of three situations: you provide an AI system (you build or rebrand one), you deploy one (you use a third-party system in your operations), or you sit somewhere in the supply chain. Obligations follow the role you play and the system's risk tier — not your company size. For a first read in two minutes, run the free Risk Checker; for the full analysis, see whether the Act applies to your business.
High-risk AI systems (Annex III)
High-risk is where most of the compliance work concentrates: risk management, data governance, technical documentation, record-keeping, human oversight, accuracy, and conformity assessment for providers. Annex III lists the use-cases — employment, credit scoring, education, essential services, and certain biometric and infrastructure uses. Full breakdown: high-risk systems explained (Annex III).
Annex IV: the technical documentation file
Providers of high-risk systems must compile and maintain Annex IV technical documentation — a structured file covering the system's purpose, data, development, risk management and performance, available to authorities on request. What goes in it: the Annex IV file explained.
General-purpose AI (GPAI)
Building or fine-tuning general-purpose models triggers a separate set of obligations — technical documentation, transparency to downstream providers, a copyright policy, and more for models with systemic risk. Details: GPAI model obligations (Articles 53 & 55).
Key dates
Prohibited practices apply since February 2025 and GPAI model obligations since August 2025. Following the Digital Omnibus on AI, the high-risk obligations apply from 2 December 2027 (stand-alone, Annex III) and 2 August 2028 (embedded in products, Annex I) — settled by Regulation (EU) 2026/1744, in force since 27 July 2026. Transparency obligations apply from 2 August 2026.
Penalties
Non-compliance can cost up to €35 million or 7% of global annual turnover for prohibited practices, with lower (but still significant) ceilings for other breaches.
What SMEs should do
Start by classifying each AI system you build or use. If you are high-risk, the documentation and conformity work takes months — begin early. Try our free EU AI Act Risk Checker, browse compliance by use case, or see pricing.
FAQ
Is the EU AI Act only for big tech?
No. It applies by role and risk tier, not company size — many SMEs are deployers of high-risk AI, for example HR screening tools.
Has the deadline been cancelled?
No. Some high-risk timing was adjusted by the Digital Omnibus, but the obligations remain. See the new deadlines explained.
Do I need Annex IV documentation?
If you provide a high-risk system, generally yes. If you only deploy one, your obligations differ — use, oversight and record-keeping. Scope your situation first.
Where do I start?
Inventory your AI systems, then run the free Risk Checker for a first risk read in two minutes.