How does the EU AI Act affect small businesses?

AI regulation: the EU AI Act

For most small businesses, the EU AI Act is not a blanket licensing or audit regime. A typical SME using third party AI tools is usually a deployer, not a provider. That means the main duties already live are AI literacy and avoiding prohibited uses. From 2 August 2026, some transparency rules arrive for specific systems. The heavier high-risk duties matter only if your use case is genuinely in scope, and their next dates depend on whether the adopted AI Omnibus has entered into force.

What this means

If you run a 20 person firm and use AI for drafting, customer support, search, analytics or internal productivity, the Act is narrower than many sales decks suggest. It does not automatically force you into conformity assessments, CE marking, EU database registration or a full compliance programme just because your team uses a popular AI tool.

The first distinction is between a provider and a deployer. A provider places an AI system on the market or puts it into service under its own name or trade mark. A deployer uses an AI system under its authority. Most small firms buying software are deployers. That matters because many of the Act's heavier obligations sit with providers, or only apply where a system is actually high-risk.

As at 21 July 2026, the law in force is still Regulation (EU) 2024/1689. The separate AI Omnibus has completed the legislative procedure, was signed on 8 July 2026, but was still awaiting Official Journal publication when checked for this article. So the current law's dates formally still stand until that publication happens, even though the adopted Omnibus text is highly relevant for planning.

Why it matters

This matters because small firms are vulnerable to two opposite mistakes. One is scare marketing: being told the Act already requires every business using generative AI to register systems, hire specialists, or stop using mainstream tools. The other is complacency: assuming the Act is only for big labs and regulated industries. Neither is right.

For a typical SME, the practical stakes are more specific. You need staff who can use AI with enough judgement to spot basic risks, limits and misuse. You need a simple banned-practices screen so that a marketing team, HR team or product team does not wander into prohibited territory. If you run public facing chatbots, AI avatars, deepfake style content, or AI generated public interest text, transparency duties are close at hand. If you use AI in hiring, credit, insurance, essential services or other Annex III areas, you need to know whether you are actually in high-risk territory, and whether the applicable start date is still the current law's formal date or has been moved by the Omnibus once it is published.

How it works

Who this page is about

A 20 person company will almost always fall inside the SME bracket. Under the EU's standard SME definition, an SME has fewer than 250 employees and annual turnover of no more than EUR 50 million, or an annual balance sheet total of no more than EUR 43 million. A small enterprise is narrower again: fewer than 50 employees and turnover or balance sheet total of no more than EUR 10 million.

The adopted AI Omnibus also introduces a new "small mid-cap enterprise" concept into the AI Act by cross referring to the 2025 Commission recommendation. That category sits above SMEs and below large firms: fewer than 750 employees, and turnover of no more than EUR 150 million or balance sheet total of no more than EUR 129 million, while not already qualifying as an SME. As at 21 July 2026, that concept is relevant for planning but not yet in force because the Omnibus was still awaiting publication.

For this page, "small business" mainly means a typical SME that deploys AI systems bought from others, rather than developing or placing its own AI systems on the EU market under its own name. That is the most common real world posture for smaller firms, and it is the posture that most often gets misdescribed.

What applies to a typical small deployer now

Two things already matter now.

First, Article 4 AI literacy has applied since 2 February 2025. The obligation is not a demand for certificates, external audits or a mandatory AI officer. The Commission's Q and A says there is no need for a certificate, no specific governance structure is mandated, and there is no obligation to formally measure staff knowledge. But firms do need proportionate measures so staff and other people acting on the firm's behalf can use AI systems with a sufficient level of understanding. The AI Office's current approach is flexible and context based. Internal records of training, guidance or briefings are sensible because they show you took the duty seriously.

Second, Article 5 prohibited practices has also applied since 2 February 2025. For most SMEs this is less about exotic edge cases and more about hygiene. You should be able to say, in plain language, that your business is not deploying AI in ways the Act flatly bans, and that your procurement and acceptable-use controls are designed to stop that happening. For most small firms, that means a short red flag review before launching a new use case, especially in sensitive areas involving manipulation, exploitation, social scoring, prohibited biometric uses or other clearly banned practices.

That is why a small deployer "doing AI" is not compliance-free today. But it is also why the correct response is proportionate governance, not panic.

What formally arrives on 2 August 2026 under the law currently in force

Under the AI Act as currently in force, 2 August 2026 is the next major date for most businesses.

The most visible change for ordinary deployers is Article 50 transparency. These rules apply only to certain systems and use cases, not to every AI output in every workflow. In broad terms: * If your AI system interacts directly with natural persons, such as a chatbot, AI agent or avatar, people must be told they are interacting with AI unless that is obvious from the context. * If you deploy emotion recognition or biometric categorisation systems, affected people must be informed. * If you deploy systems that create or manipulate deepfakes, or publish certain AI generated or AI manipulated text on matters of public interest without human review or editorial control, labelling duties can apply. * For providers of systems generating synthetic audio, image, video or text, machine readable marking obligations under Article 50(2) also become relevant.

The Commission adopted Article 50 transparency guidelines on 20 July 2026 and published supporting FAQ material and quick facts immediately afterwards. That is important for SMEs because this is one of the few parts of the Act that can affect very ordinary public facing AI use.

Under the current law, 2 August 2026 is also the general application date for most of the remaining provisions that have not yet started, unless a later special date applies. That includes the practical machinery around market surveillance, innovation support tools, and the Article 6(3) filter and Article 49(2) registration mechanics. Formally, that means that if the law remained unchanged through 2 August 2026, standalone Annex III high-risk duties would also become live then, while product safety route systems under Article 6(1) keep their separate later date under the current law.

What the adopted Omnibus would change once it is published

This is the key dual-track issue.

When this article was checked on 21 July 2026, the European Parliament procedure file still showed the AI Omnibus as completed and awaiting publication in the Official Journal. The signed final act text exists, but there was no final regulation number or Official Journal citation to rely on yet. That means the current law's dates still formally stand for now.

Once the Omnibus is published and enters into force, several planning assumptions change.

What does not move: * Article 4 AI literacy is not postponed. * The Article 5 prohibitions that already apply are not postponed. * GPAI model rules do not move. * Article 50 as a whole does not shift away from 2 August 2026.

What does change: * New prohibitions are added for AI systems that generate or manipulate non-consensual intimate material and child sexual abuse material. Those new prohibition points apply from 2 December 2026, not immediately. * Providers of synthetic-content systems already placed on the market before 2 August 2026 get until 2 December 2026 to comply with Article 50(2). * The Omnibus moves most Chapter III standalone high-risk obligations for Annex III systems to 2 December 2027. * It moves the Annex I embedded product high-risk route to 2 August 2028. * It moves the national sandbox deadline to 2 August 2027. * Articles 102 to 110 apply from the Omnibus entry into force date.

For SMEs, the main practical consequence is simple: if the Omnibus enters into force before 2 August 2026, Article 50 still arrives on schedule, but the broad fear that every Annex III use case suddenly triggers full high-risk duties in August 2026 becomes much less accurate. If publication does not happen before then, the current law's formal position still governs until it does.

Which reliefs and support measures matter for smaller firms

The Act already contains some proportionality tools, and the Omnibus broadens several of them.

Under the current law: * Article 11 already allows SMEs, including start-ups, to provide Annex IV technical documentation in a simplified manner, using the Commission's simplified form where they choose that route. * Article 62 requires support measures for SMEs, including priority access to AI regulatory sandboxes, tailored training and awareness activity, communication channels, help with participation in standardisation, reduced conformity-assessment fees, and Commission templates and information tools. * Article 63 currently allows only microenterprises, not all SMEs, to comply with certain quality-management-system elements in a simplified manner, and only if they do not have partner or linked enterprises within the SME recommendation meaning. * Article 99 already contains the lower-of fine rule for SMEs, including start-ups: the maximum fine is the lower of the percentage cap or the fixed euro amount.

Under the adopted Omnibus, once in force: * the Article 11 simplified technical documentation route is extended to small mid-caps as well as SMEs; * the Article 63 quality-management simplification is extended from microenterprises to SMEs, including start-ups, subject to the linked-enterprise condition in the text; * sandbox priority access and related support are extended to small mid-caps too; * the penalties article is adjusted so the interests and economic viability of SMEs, start-ups and small mid-caps are expressly taken into account, and small mid-caps get a lower-of rule for the relevant fine bands.

There is also a practical support pipeline, not just statutory relief. The Commission launched the AI Act Service Desk and Single Information Platform in 2025. It has also been building a guidance pipeline that includes high-risk classification guidance, high-risk requirement guidance, value-chain guidance, substantial-modification guidance, reporting guidance, a voluntary post-market monitoring template, and guidance on simplified quality-management elements for SMEs and small mid-caps. As of 21 July 2026, the transparency guidelines were final, while the high-risk classification guidance was still in draft and open to consultation until 23 July 2026.

A practical checklist for a 20-person firm

What you should do now: * Make a short inventory of every AI system your business uses, including public facing tools, hiring tools and vendor supplied systems. * Mark your role for each tool: deployer, provider, importer, distributor, or more than one. * Run a banned-practices check against Article 5 before approving a new use case. * Put in place simple AI literacy measures for staff and contractors who actually use AI systems on the firm's behalf. Keep an internal record. * Identify any public facing chatbot, AI avatar, synthetic-content workflow, deepfake-style use, emotion-recognition feature, biometric categorisation use, or public-interest publishing workflow that could trigger Article 50 from 2 August 2026. * If a use case touches hiring, worker management, credit, insurance, essential services, migration, justice, elections, or similar Annex III areas, do a proper high-risk scoping review instead of guessing. * Review vendor contracts so you can tell whether you are merely deploying a tool or are rebranding, substantially modifying, or otherwise stepping into provider responsibilities. * Put a diary note on the AI Omnibus publication event, because that one publication changes the Chapter III timetable.

What you can usually ignore for now: * GPAI provider obligations, unless you actually place a general-purpose AI model on the market. * Notified-body rules, unless you are in the conformity-assessment chain. * CE marking and the full provider stack for high-risk AI, unless you really are placing an in-scope high-risk system on the market. * EU database registration, unless you are in the limited provider situations that trigger it. * Sandbox mechanics, unless you are actively developing or testing an AI system that would benefit from one.

That is the right middle position between exaggeration and shrugging the issue off.

Examples

Example 1: Staff use ChatGPT or a similar tool to write marketing copy or translate text. The Commission's AI literacy Q and A treats this as in scope for Article 4. That means the company should not assume "general productivity AI" is outside the Act. What it needs is proportionate literacy, for example reminding staff about hallucinations, verification, confidentiality and the limits of the tool. It does not mean the firm suddenly becomes a high-risk AI provider.

Example 2: A small firm puts an AI chatbot or avatar on its website for customer support. Under Article 50, from 2 August 2026 the relevant provider obligations include informing people that they are interacting with AI, unless this is already obvious. That is a very different compliance task from a conformity assessment. For many SMEs, a clear interface notice and sensible process design will matter more than anything in Chapter III.

Example 3: An SME buys a recruitment tool that analyses and filters job applications or evaluates candidates. Annex III expressly treats recruitment and selection uses as a high-risk area. Under the law currently in force, that creates a formal August 2026 issue. But if the adopted Omnibus is published before then, the standalone Annex III timetable moves to 2 December 2027. So this is exactly the kind of use case where a founder should not rely on generic claims that "all high-risk rules were delayed" or that "none of this matters until 2027". The correct answer depends on publication status and on whether the use case is truly in scope.

Common misunderstandings

"Every small company using AI has to register systems with the EU this summer." No. A typical SME using third party tools is usually a deployer. Registration duties are not a universal requirement for ordinary deployers.

"The AI Omnibus has already moved all the important dates." No. As checked on 21 July 2026, it had been adopted and signed but was still awaiting Official Journal publication. Until entry into force, the current law's dates formally still apply.

"Small firms are exempt because the Act is really for big tech." No. Article 4 AI literacy and Article 5 prohibited-practices rules already apply to small firms that professionally use AI. Size changes proportionality, not scope.

"Our team just needs a PDF policy to satisfy AI literacy." Usually not. The Commission's current guidance is flexible, but it expects measures that actually fit the systems used, the staff involved and the risks. A written policy alone may be too thin if employees are using AI in meaningful workflows.

"If we touch hiring, the Omnibus means we can ignore the issue until late 2027." Not automatically. The current law still formally points to the earlier date unless and until the Omnibus enters into force. And even if the date moves, classification work, vendor review and governance should start well before the deadline.

Risks and boundaries

This article is about the regulatory position of smaller firms under the EU AI Act. It is not legal advice, it is not a substitute for classifying a specific system, and it is not a design blueprint for your governance programme.

Three boundaries matter.

First, the provider versus deployer line can blur. If you substantially modify a system, fine tune and place it on the market under your own name, white-label it, or otherwise take on provider functions, your obligations can expand quickly. Many "we only use the tool" assumptions break down at that point.

Second, high-risk classification is more technical than most summaries admit. Annex III labels only certain use cases as high-risk, and Article 6(3) provides a filter for some systems that do not pose a significant risk of harm to health, safety or fundamental rights. The Commission's classification guidance is meant to help here, but as at 21 July 2026 the relevant high-risk guidance was still in draft and under consultation until 23 July 2026.

Third, publication status genuinely matters right now. Some official implementation pages already explain the adopted Omnibus timetable for planning purposes. But the formal legal position still depends on Official Journal publication and entry into force. As at 21 July 2026, the safest formulation is this: current-law dates still stand formally, while the adopted Omnibus text is the best guide to the near-term changes that are likely to take effect once publication occurs.

What to do next

Treat this as a targeted operating issue, not a civilisation-level event.

Start with a 60 minute review of your actual AI use cases. Identify which are internal productivity tools, which are public facing, and which touch sensitive decisions about people. Assign an owner for each. For most small firms, that one exercise will separate the real compliance work from the noise.

Then do three practical things.

First, put AI literacy on a real footing. Give staff short, role-based guidance and training that reflects the systems they use. Keep a record.

Second, create a simple approval gate for new AI use cases. The gate should ask: are we the provider or just the deployer; could Article 5 be implicated; could Article 50 apply from 2 August 2026; and does this touch Annex III high-risk areas such as recruitment or essential services?

Third, plan on the dual track. Prepare for Article 50 on 2 August 2026 if you have in-scope transparency uses. At the same time, watch the Official Journal status of the AI Omnibus, because that publication event will determine whether your high-risk planning should be anchored to the current law's formal date or to the adopted later dates.

If you need a practical support route, use the Commission's AI Act Service Desk, the Single Information Platform and the official Compliance Checker before turning to vendor interpretations.

FAQs

We are a small UK or US company selling into the EU. Does this still matter?

Potentially yes. The Act reaches providers outside the EU where the system's output is used in the EU, and deployers using systems in the EU are also in scope.

If we only use third party AI tools, are we outside the Act?

No. You are usually a deployer rather than a provider, which often means a lighter obligation set, but not no obligations. AI literacy already applies, prohibited practices already apply, and Article 50 can apply from 2 August 2026 for certain uses.

Do we need an AI officer, certificates or a formal exam for staff?

Not as a general rule. The Commission's current Article 4 guidance says there is no need for certificates, no mandated AI governance structure, and no duty to formally measure staff knowledge. But you still need proportionate literacy measures.

Are all recruitment tools automatically high-risk?

Not every tool in the broad HR area is automatically caught, but AI systems intended for recruitment or selection of natural persons, including filtering applications and evaluating candidates, sit squarely in an Annex III high-risk area. Classification should be checked carefully.

Do small companies get any fine relief?

Yes. The current Act already contains a lower-of fine rule for SMEs, including start-ups, in Article 99. The adopted Omnibus would extend a similar lower-of approach to the new small mid-cap category for the relevant fine bands once it enters into force.

Has the Omnibus already delayed the August 2026 date?

Not yet, as checked for this article on 21 July 2026. It had been adopted and signed, but was still awaiting Official Journal publication. Until it enters into force, the current law's dates formally still stand.

What is the one thing most SMEs should not do?

Do not assume that "using ordinary AI tools" means you have no duties, and do not assume that every AI use puts you into the Act's heaviest category. Most small firms need focused basics, not full-scale overreaction.

Sources