Skip to main content

Executive guide · 8 min read

AI Act for SMEs, what affects you and when

Regulation EU 2024/1689 enters into force in stages until 2027. Most SMEs still don't know if it applies to them, at what level, or what to do. This guide clarifies it with plain language, real examples, and an actionable roadmap.

Important: This guide is educational synthesis and orientative. It does NOT constitute legal advice or binding conformity assessment. For specific cases, always refer to a specialised law firm.

What is the AI Act and who does it apply to

The AI Act (Regulation EU 2024/1689) is the world's first comprehensive regulation on artificial intelligence. It was adopted in July 2024 and applies progressively until August 2026.

It applies to any company that develops, commercialises or uses AI systems within the European Union, including non-EU providers if their AI output is used inside the EU. Company size doesn't matter: a 20-employee SME is equally obligated as a multinational.

What changes by size and sector is the *level* of obligations: prohibited practices are forbidden for everyone; strict obligations only apply to AI systems classified as high-risk; most everyday uses (chatbots, ChatGPT) only have transparency obligations.

The 4 risk levels

The AI Act classifies systems by risk level. Knowing where you stand is the first step.

Level 1 · Prohibited

Prohibited practices (Art. 5)

AI systems banned for being incompatible with fundamental rights. Cannot be commercialised or used in the EU under any circumstance.

Examples: Mass facial recognition in public spaces, social scoring, emotion inference at the workplace, subliminal manipulation.

Level 2 · High risk

High-risk systems (Annex III)

Systems that significantly affect fundamental rights or safety. Permitted but with strict obligations: risk management, technical documentation, human oversight, CE marking.

Examples: AI for personnel selection, credit scoring, medical diagnosis, student assessment, critical infrastructure management.

Level 3 · Limited risk

Transparency obligations

Systems with low risk but requiring users to know they're interacting with AI or seeing artificially generated content.

Examples: Customer service chatbots, image generators, deepfakes (labelled), conversational assistants.

Level 4 · Minimal risk

No specific obligations

The majority of everyday AI uses. No binding obligations, but voluntary good practices are recommended.

Examples: Spam filters, product recommendations, search engines, automatic translation, grammar correction.

Application timeline 2024-2027

The AI Act doesn't apply all at once. It has a staged 3-year calendar.

  1. August 2024

    Formal entry into force

    The regulation is officially in force in the EU Official Journal, but most obligations don't yet apply, the transition period begins.

  2. February 2025

    Prohibited practices + AI literacy

    Art. 5 prohibitions apply, along with the obligation to ensure AI literacy for all personnel using AI systems (Art. 4).

  3. August 2025

    General-purpose AI obligations (GPAI)

    Providers of large models (GPT, Claude, Gemini, etc.) face specific transparency, documentation and systemic risk assessment requirements.

  4. August 2026

    AI Act fully applicable

    All high-risk system obligations are enforceable: risk management, technical documentation, human oversight, cybersecurity, logging.

  5. February 2027

    CE marking mandatory

    All high-risk AI systems sold in the EU must carry the CE mark and have an EU declaration of conformity.

What applies to your sector

Five typical SME cases and how the AI Act affects them.

HR consultancy / agency

High risk (Annex III, point 4)

If you use AI to filter CVs, evaluate candidates, decide promotions or terminations, your system is high-risk. You must ensure absence of discriminatory biases, transparency in automated decisions, and effective human oversight. Enforceable from August 2026.

Private medical centre

High risk (Annex III, point 9)

If you use AI for diagnosis, clinical decision support or triage, high risk. In addition to the AI Act, the Medical Device Regulation (MDR) applies. Specific CE certification and system registration required.

Tax firm or financial advisor

High risk (Annex III, point 5)

If you do credit scoring or automated solvency assessments, high risk. Decisions must include intelligible explanations to the client (right not to be subject to purely automated decisions, also GDPR).

Training academy or institution

High risk (Annex III, point 3)

If you use AI to evaluate students, decide admissions or detect cheating, high risk. You must ensure the AI doesn't introduce biases against vulnerable groups and allows human review.

Marketing agency

Limited or minimal risk

Typical uses (ChatGPT for copy, image generators, predictive campaign analysis) are limited or minimal risk. Required: label deepfakes/generated content, comply with GDPR for client data, train the team in AI literacy.

Roadmap to compliance

Five practical steps to start today.

1

1. Inventory

Identify all AI systems your company uses or offers, including those embedded in third-party tools.

2

2. Classify

Determine each system's risk level according to Annex III and Art. 5. Document the classification.

3

3. Document

For high-risk systems, prepare technical documentation, automatic logs, and risk management procedures.

4

4. Train

Ensure staff AI literacy (mandatory from Feb 2025). Formal courses or internal sessions both work.

5

5. Govern

Designate an AI compliance lead, set up periodic reviews, and cooperate with authorities if needed.

Want to know exactly what applies to you?

Take the interactive 5-minute diagnostic or talk to IAescola about your specific case.