Skip to content
byte8
All articles
AI ActGDPRAI literacy

The EU AI Act for SMEs: what you need to arrange, and what you don't

The AI Act already applies. For most SMEs it comes down to four things: knowing which AI you use, AI literacy, transparency to customers and a human in control. The checklist, without panic.

Khalifa Hammami··4 min read

The European AI Regulation (AI Act) has been in force since 1 August 2024 and applies in phases. The obligations that touch SMEs now apply. The good news: for a company using AI for quotes, customer questions, administration or planning, the work is manageable. Below is what is expected of you, what is not, and how to get it in order in an afternoon.

The phases in one table

SinceWhat appliesDoes it touch SMEs?
2 February 2025Prohibited practices (such as social scoring and manipulation) and the duty of AI literacy (Article 4)Yes, literacy applies to everyone using AI
2 August 2025Rules for providers of general-purpose AI models, supervision and finesOnly if you provide models yourself
2 August 2026Transparency duties (Article 50) and most requirements for high-risk applicationsTransparency yes; high risk only for specific applications

One caveat: at the end of 2025 the European Commission proposed tying the start dates for high-risk applications to the availability of technical standards, with the end of 2027 as the new outer limit. Whether and how that becomes final depends on Parliament and Council. For the light rules it changes nothing.

First: which class does your use fall in?

The AI Act works with risk classes, and most SME applications sit at the bottom.

  • Prohibited. Social scoring, manipulation of vulnerable groups, emotion recognition in the workplace. You do not do this, and that stays so.
  • High risk. AI that decides or weighs in on recruitment, credit assessment, access to education or essential services, and AI in products with safety requirements. Here requirements apply to documentation, data quality, logging and human oversight.
  • Limited risk. Chatbots and agents that talk to people, and AI that creates text or images for the public. Here the rule is: be transparent.
  • Minimal risk. Everything below that: spam filters, an agent that sorts mail, a tool that prepares quotes for review.

An agent that stages quotes, retypes orders or answers customer questions sits in the last two classes. Those do not fall under the heavy requirements. Do take care if you use AI in job applications or in decisions about credit or access: then you are high risk.

The checklist for SMEs

1. Know which AI you use

Make a list: which tools and agents run, which data goes in, who uses them and for what. Do not forget the tools employees use on their own (shadow AI). Without that list you cannot arrange the rest.

2. Arrange AI literacy

Article 4 asks that the people using AI understand what it can and cannot do. It is an obligation of effort, not an exam. Per application a short explanation (what it does, where it can go wrong, what must not go in) and a few agreements, and a record that you did this. Half a day with the team, and you are there.

3. Be transparent

If a customer talks to an agent or chatbot, say it is AI. If you use AI-made text or images where it matters that a human did not make it, mark it. A line in your mail signature or a notice in the chat is enough.

4. Keep a human in control

For anything with consequences for a person (a rejection, a price agreement, a credit note) a human should take the decision or be able to reverse it. This is also how a good agent works: it stages, you approve.

5. The GDPR stays

The AI Act does not replace the GDPR. So: a processing agreement with your AI vendor, no personal data in public tools, preferably EU hosting, and knowing where your data goes.

What you do not need

  • No CE marking or conformity assessment for an agent that sorts mail or prepares quotes.
  • No registration in the European database, that is for high-risk systems.
  • No mandatory AI officer. Someone who keeps the overview, yes.
  • No stop on using AI. The law regulates; it only bans a short list.

And the fines?

The maximums are high: up to 35 million euros or 7 percent of global turnover for prohibited practices, and up to 15 million euros or 3 percent for other violations. For SMEs the lower of the two amounts always applies. Supervisors focus on the heavy classes; for a company that has the five points above in order, the risk is small.

How we build agents

Human in control, answers with a source, and data that stays within agreed limits: at byte8 that is not a compliance layer added afterwards but the way an agent is built. Want to know where AI pays back fastest in your business, and see right away how to arrange it properly? That is exactly what the AI Scan does in one afternoon.

Apply this to your business?

Tell us your idea and we will make it concrete.

Chat on WhatsApp