Executive guide · 8 min read
AI Act for SMEs, what affects you and when
Regulation EU 2024/1689 enters into force in stages until 2027. Most SMEs still don't know if it applies to them, at what level, or what to do. This guide clarifies it with plain language, real examples, and an actionable roadmap.
Important: This guide is educational synthesis and orientative. It does NOT constitute legal advice or binding conformity assessment. For specific cases, always refer to a specialised law firm.
What is the AI Act and who does it apply to
The AI Act (Regulation EU 2024/1689) is the world's first comprehensive regulation on artificial intelligence. It was adopted in July 2024 and applies progressively until August 2026.
It applies to any company that develops, commercialises or uses AI systems within the European Union, including non-EU providers if their AI output is used inside the EU. Company size doesn't matter: a 20-employee SME is equally obligated as a multinational.
What changes by size and sector is the *level* of obligations: prohibited practices are forbidden for everyone; strict obligations only apply to AI systems classified as high-risk; most everyday uses (chatbots, ChatGPT) only have transparency obligations.
The 4 risk levels
The AI Act classifies systems by risk level. Knowing where you stand is the first step.
Level 1 · Prohibited
Prohibited practices (Art. 5)
AI systems banned for being incompatible with fundamental rights. Cannot be commercialised or used in the EU under any circumstance.
Examples: Mass facial recognition in public spaces, social scoring, emotion inference at the workplace, subliminal manipulation.
Level 2 · High risk
High-risk systems (Annex III)
Systems that significantly affect fundamental rights or safety. Permitted but with strict obligations: risk management, technical documentation, human oversight, CE marking.
Examples: AI for personnel selection, credit scoring, medical diagnosis, student assessment, critical infrastructure management.
Level 3 · Limited risk
Transparency obligations
Systems with low risk but requiring users to know they're interacting with AI or seeing artificially generated content.
Examples: Customer service chatbots, image generators, deepfakes (labelled), conversational assistants.
Level 4 · Minimal risk
No specific obligations
The majority of everyday AI uses. No binding obligations, but voluntary good practices are recommended.
Examples: Spam filters, product recommendations, search engines, automatic translation, grammar correction.
Application timeline 2024-2027
The AI Act doesn't apply all at once. It has a staged 3-year calendar.
August 2024
Formal entry into force
The regulation is officially in force in the EU Official Journal, but most obligations don't yet apply, the transition period begins.
February 2025
Prohibited practices + AI literacy
Art. 5 prohibitions apply, along with the obligation to ensure AI literacy for all personnel using AI systems (Art. 4).
August 2025
General-purpose AI obligations (GPAI)
Providers of large models (GPT, Claude, Gemini, etc.) face specific transparency, documentation and systemic risk assessment requirements.
August 2026
AI Act fully applicable
All high-risk system obligations are enforceable: risk management, technical documentation, human oversight, cybersecurity, logging.
February 2027
CE marking mandatory
All high-risk AI systems sold in the EU must carry the CE mark and have an EU declaration of conformity.
What applies to your sector
Five typical SME cases and how the AI Act affects them.
HR consultancy / agency
High risk (Annex III, point 4)
If you use AI to filter CVs, evaluate candidates, decide promotions or terminations, your system is high-risk. You must ensure absence of discriminatory biases, transparency in automated decisions, and effective human oversight. Enforceable from August 2026.
Private medical centre
High risk (Annex III, point 9)
If you use AI for diagnosis, clinical decision support or triage, high risk. In addition to the AI Act, the Medical Device Regulation (MDR) applies. Specific CE certification and system registration required.
Tax firm or financial advisor
High risk (Annex III, point 5)
If you do credit scoring or automated solvency assessments, high risk. Decisions must include intelligible explanations to the client (right not to be subject to purely automated decisions, also GDPR).
Training academy or institution
High risk (Annex III, point 3)
If you use AI to evaluate students, decide admissions or detect cheating, high risk. You must ensure the AI doesn't introduce biases against vulnerable groups and allows human review.
Marketing agency
Limited or minimal risk
Typical uses (ChatGPT for copy, image generators, predictive campaign analysis) are limited or minimal risk. Required: label deepfakes/generated content, comply with GDPR for client data, train the team in AI literacy.
Roadmap to compliance
Five practical steps to start today.
1. Inventory
Identify all AI systems your company uses or offers, including those embedded in third-party tools.
2. Classify
Determine each system's risk level according to Annex III and Art. 5. Document the classification.
3. Document
For high-risk systems, prepare technical documentation, automatic logs, and risk management procedures.
4. Train
Ensure staff AI literacy (mandatory from Feb 2025). Formal courses or internal sessions both work.
5. Govern
Designate an AI compliance lead, set up periodic reviews, and cooperate with authorities if needed.
Want to know exactly what applies to you?
Take the interactive 5-minute diagnostic or talk to IAescola about your specific case.