Since 2 August 2026, the AI Act has applied in full to transparency and enforcement, but the heavy obligations covering high-risk systems have been pushed back to December 2027. For a small business using ChatGPT, a chatbot or a no-code tool, the real work amounts to half a day.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
Since 2 August 2026, the AI Act has applied in full to transparency and enforcement, but the heavy obligations covering high-risk systems have been pushed back to December 2027. For a small business using ChatGPT, a chatbot or a no-code tool, the real work amounts to half a day.
The confusion comes from the pile of content published before summer 2026, which still dates high-risk obligations to 2 August 2026 and sells a hard training requirement backed by a 15 million euro fine. The Digital Omnibus on AI, in force since 27 July 2026, changed both. This article separates what binds you today from what can wait. For the full framework, including non-profits, the AI Act compliance guide for SMEs and non-profits is the starting point.
Only three blocks are applicable and enforceable in September 2026: prohibited practices, Article 50 transparency, and the rules on general-purpose AI models. Everything else either has a future date or targets operators you probably are not.
Here is the consolidated timeline published by the European Commission on its AI Act Service Desk portal, as amended by the Digital Omnibus on AI:
| Date | What applies | Relevant if |
|---|---|---|
| 2 February 2025 | Prohibited practices (Article 5), definitions, AI literacy (Article 4) | Always |
| 2 August 2025 | General-purpose AI models, national governance | You train or distribute a model |
| 2 August 2026 | Transparency (Article 50), enforcement and penalties begin | You expose AI to customers, staff or visitors |
| 2 December 2026 | New prohibitions (non-consensual sexual deepfakes, child sexual abuse material) and end of the grace period on machine marking of generated content | You supply a generative system placed on the market before August 2026 |
| 2 December 2027 | Stand-alone high-risk systems, Annex III | Recruitment, credit scoring, education, critical infrastructure |
| 2 August 2028 | High-risk AI embedded in regulated products, Annex I | Medical devices, machinery, toys |
The article-by-article breakdown is covered in the complete AI Act timeline from 2024 to 2030. The takeaway: if your company runs AI-assisted recruitment, your deadline is 2 December 2027, not summer 2026. That changes the order of priorities, not the direction of travel.
In nearly every case a small or mid-sized business is a deployer, not a provider, and the heavy obligations sit with its vendor. A deployer uses an AI system under its own authority in a professional context. A provider develops the system and places it on the market under its own name.
The trap lies elsewhere: a deployer becomes a provider in four specific situations. It puts its own brand on the system, it substantially modifies it, it changes the intended purpose, or it plugs an existing system into a high-risk use case.
This is where no-code projects create exposure. A company that assembles a CV screening AI agent on top of an off-the-shelf LLM, with its own scoring rules and its own commercial name, is no longer treated by the regulation as a simple API user. It ticks two of the four boxes: modified purpose and Annex III use. From December 2027 it will owe technical documentation, a conformity assessment and registration in the EU database.
The sorting rule we apply during audits: as long as you use a SaaS tool as-is, with its original parameters, you remain a deployer. The moment you build something you sell or present as your own, ask the provider question. The detailed scope of the regulation walks through each case.
The vast majority of small-business AI usage falls under limited or minimal risk, where the only real constraint is disclosure. Classifying your tools takes an hour if you start from your software subscription list.
One common case is often misjudged: ChatGPT used internally to draft a quote or rewrite an email is minimal risk. The same content published on your site, or sent to a client as a generated image, moves into Article 50 territory.
Article 50 requires you to inform people that they are interacting with an AI, or that content was AI-generated, unless it is obvious to a reasonably well-informed observer. This is the only obligation that genuinely reaches every small business since 2 August 2026.
Three situations come up constantly:
On top of this sits the machine-marking obligation, which falls on the model provider rather than the deployer, with a transitional deadline of 2 December 2026 for systems already on the market before August 2026. You do not have to implement that marking yourself. Drafting your disclosures is covered step by step in the article on the AI information notice.
Article 4 on AI literacy still exists, but the AI Omnibus turned the "sufficient level" requirement on companies into a non-binding incentive, with the Commission and Member States taking the lead on promotion. In other words, there is no dedicated fine for a training gap.
This is a point where we deliberately break with the dominant line in our own industry. Many training providers still sell the AI Act as a hard obligation backed by a 15 million euro fine. That was already debatable before the Omnibus; it has been wrong since July 2026.
Two caveats still hold. First, a training obligation survives for deployers of high-risk systems, through Article 26 and its requirement of effective human oversight: you cannot meaningfully supervise a system you do not understand. Second, supervision by national market surveillance authorities started on 2 August 2026, under a proportionate regime.
Our position: train because teams produce mediocre output and take confidentiality risks without a framework, not because a regulator is waving a stick. The full analysis is in AI Act Article 4: is AI training mandatory.
For an SME or start-up, the fine is capped at the lower of the turnover percentage and the fixed amount, whereas the rule is the opposite for large companies. That is Article 99(6), and it is probably the least reported provision in the whole regulation.
| Breach | General cap | SME cap |
|---|---|---|
| Prohibited practice (Article 5) | EUR 35M or 7% of global turnover, whichever is higher | Whichever is lower |
| Other operator obligations | EUR 15M or 3% of global turnover, whichever is higher | Whichever is lower |
| Inaccurate information to authorities | EUR 7.5M or 1% of global turnover, whichever is higher | Whichever is lower |
For a company with EUR 2 million in turnover, a breach of operator obligations is therefore capped at EUR 60,000, not EUR 15 million. The amount is still a deterrent, but the headline figure quoted in most articles does not match your situation. The full penalty schedule is covered in the article on AI Act penalties in 2026.
The regulation includes a set of measures aimed specifically at SMEs and start-ups that most guides skip entirely. They do not remove obligations; they cut the cost of meeting them.
Article 62 requires Member States to give SMEs established in the Union priority access to regulatory sandboxes, to run awareness and training activities tailored to their needs, and to open dedicated advisory channels. It also provides that conformity assessment fees be reduced proportionately to company size. Each Member State should have at least one sandbox operational by 2 August 2027.
SMEs may also supply the Annex IV technical documentation in simplified form, using a template the Commission must produce for small and micro-enterprises, a template notified bodies are required to accept. Article 63 adds derogations on the quality management system for micro-enterprises.
These provisions only matter once you become a provider of a high-risk system. They are worth knowing before abandoning a project over compliance cost.
For a company under 250 employees running no high-risk system, compliance is half a day of work, not a quarterly project.
Two limits worth keeping in mind. This method is not enough if you use AI in recruitment, employee evaluation or financial scoring: the December 2027 deadline then requires a real conformity assessment, which takes months to prepare. And it does not address personal data, governed by the GDPR, which applies alongside the AI Act rather than instead of it: the topic is covered in AI Act vs GDPR.
Is a five-person business using ChatGPT covered by the AI Act? Yes, but only lightly. Internal use of ChatGPT to draft or rewrite is minimal risk and carries no specific obligation. Obligations appear as soon as AI output is exposed to third parties, for instance through a chatbot or a published generated image.
Do I have to declare my AI systems to a national authority? No, except for providers of high-risk systems, who will have to register in the EU database from December 2027. A deployer has no prior declaration to make.
Has the obligation to train teams on AI disappeared? It has been softened. The AI Omnibus, in force since 27 July 2026, replaced the binding Article 4 requirement with an incentive. Training remains required in practice for deployers of high-risk systems, under the human oversight duty in Article 26.
My vendor built a custom AI tool for me: who is responsible? It depends on the name the tool operates under and the degree of customisation. If it carries your brand or you changed its purpose, you risk being classified as a provider. This should be settled contractually, ideally before development starts.
What budget should a small business plan for AI Act compliance? For a company with no high-risk use case, the cost is mostly internal time, in the range of half a day to a day. The expensive items appear later: conformity assessment if you become a provider of a high-risk system, and technical documentation. The regulation does provide for conformity assessment fees to be reduced proportionately for SMEs.
Do non-profits face the same rules? Yes. The regulation reasons by role, provider or deployer, not by legal status. A non-profit deploying a chatbot on its website has the same transparency obligations as a commercial company.
What happens if I do nothing before an inspection? National market surveillance authorities have been exercising their powers since 2 August 2026, under a graduated regime that favours formal notice before penalties. A missing chatbot disclosure takes minutes to fix; a complete absence of mapping is much harder to correct under deadline.
We are neither lawyers nor a compliance firm. We work on what compliance implies on the tools side and the people side: mapping actual AI usage, including what management does not know about, fixing transparency notices on interfaces, and training teams to work within a defined frame.
Our AI onboarding programme for companies includes a regulatory framing module, and the Operational AI for SMEs course covers confidentiality and traceability through concrete cases. GrowthPerf is Qualiopi-certified, which unlocks French OPCO funding.
If you want to know where you stand first, the free 30-minute audit sorts what binds you today from what can wait until December 2027. The AI Act compliance guide for SMEs and non-profits remains the reference for going deeper on any point raised here.