If you use an AI system in your professional activity, even a simple chatbot, the AI Act applies to you. The European regulation on artificial intelligence covers any organisation, business, nonprofit or public body that supplies, imports, distributes or deploys AI within the European Union. So the real question is not whether you are affected, but in what capacity and with which obligations.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
If you use an AI system in your professional activity, even a simple chatbot, the AI Act applies to you. The European regulation on artificial intelligence covers any organisation, business, nonprofit or public body that supplies, imports, distributes or deploys AI within the European Union. So the real question is not whether you are affected, but in what capacity and with which obligations.
That distinction changes everything. A software vendor building AI and a small business using ChatGPT to draft sales proposals do not carry the same responsibilities. This article breaks down the categories of operators, the territorial scope, the risk levels, and the actual timeline of obligations, which was significantly reshaped in the summer of 2026. For the full compliance picture, read our AI Act compliance guide for SMEs and nonprofits.
Any organisation that supplies, imports, distributes or deploys an AI system on the European market is affected, regardless of its size. Regulation (EU) 2024/1689 provides no general exemption for micro-businesses, SMEs or nonprofits. According to the French Directorate-General for Enterprise, the rules cover entities established in the Union as well as those located outside it, whenever their products or outputs are used within European territory.
In practice, three profiles come up most often among the organisations we work with. First, the vendor or agency that builds and sells a solution embedding AI. Second, the company that integrates an existing AI tool (a chatbot, a recommendation engine, a CV-screening tool) into its internal processes. Third, the nonprofit or local authority that uses generative AI tools daily, often without having formalised that usage.
The regulation governs the placing on the market, the putting into service and the use of AI systems. Strictly personal uses outside a professional setting, as well as scientific research, fall outside the text under certain conditions set out in Article 2.
The AI Act defines several roles, and your obligations depend directly on the one you hold. Article 3 of the regulation distinguishes four main categories of operators, plus the authorised representative for actors outside the EU.
| Role | Definition | Concrete example |
|---|---|---|
| Provider | Develops an AI system, or has it developed, then places it on the market under its own name | A SaaS vendor selling customer-scoring software |
| Deployer | Uses an AI system under its own authority in a professional context | An SME using an AI tool to shortlist candidates |
| Importer | Places on the EU market an AI system from a provider established outside the EU | A French distributor of a US solution |
| Distributor | Makes an AI system available on the market without being its provider or importer | A marketplace reselling AI tools |
Most SMEs and nonprofits are deployers. That is good news: the heaviest obligations (technical documentation, CE marking, risk management) fall first on providers, especially those of high-risk systems. Be careful, though: a deployer can shift into provider status if it substantially modifies a system or places it back on the market under its own name.
The AI Act has extraterritorial reach: it applies even to operators based outside Europe. Article 2 covers three situations. First, providers that place an AI system on the Union market, wherever they are established. Second, deployers whose registered office or location is in the Union. Third, providers and deployers located in a third country, when the output produced by the system is used within the Union.
This logic is close to that of the GDPR. A company that uses, from France, an AI tool hosted in the United States remains subject to the regulation for that use. The large international providers (language models, generative AI) are therefore covered as soon as their services are accessible on the European market.
The AI Act does not treat every system the same way: it applies a risk-based approach. The higher the potential impact on health, safety or fundamental rights, the stricter the obligations. The table below summarises the four categories.
| Risk level | What the regulation says | Examples |
|---|---|---|
| Unacceptable | Prohibited | Social scoring, real-time remote biometric identification in public spaces, manipulation exploiting vulnerabilities |
| High | Strict obligations (risk management, documentation, human oversight) | CV-screening AI, exam grading, credit scoring, biometrics |
| Limited | Transparency obligation | Chatbots, generative AI that must flag content as artificial |
| Minimal | No specific obligation | Spam filters, basic recommendation AI |
For most SMEs, everyday uses fall under limited or minimal risk. The point to watch concerns human resources and access to credit, which slide easily into high risk. If you automate a decision that affects employment or access to an essential service, the question deserves serious review. Our AI Act checklist for SMEs helps frame that assessment.
Since 2 February 2025, every provider and deployer must ensure a sufficient level of AI literacy among its staff. This is the most immediate obligation, and the one most often overlooked. Article 4 requires making sure that the people who use or supervise AI systems have the skills needed to understand their capabilities, limits and risks.
This obligation does not depend on the system's risk level. It applies as soon as AI is used in a professional context. A nonprofit using a generative AI tool for its communications is affected just as much as a large group. The regulation sets no imposed format: what matters is being able to demonstrate that your teams have been made aware and trained in a way suited to their real usage.
This is precisely the entry point we handle most often. To gauge its scope, read our dedicated analysis of Article 4 and the training obligation, as well as our guide to AI training in the workplace.
The AI Act timeline was amended in the summer of 2026: some high-risk obligations, originally due on 2 August 2026, have been postponed. This is a point many articles have not yet absorbed. On 29 June 2026, the Council of the European Union gave its final green light to the "Digital Omnibus" (the Omnibus VII package), which pushes back the application of the rules on high-risk systems.
Here is the consolidated timeline, as it appears in the official European texts.
| Date | What applies |
|---|---|
| 1 August 2024 | Regulation enters into force |
| 2 February 2025 | Ban on unacceptable practices; AI literacy obligation (Article 4) |
| 2 August 2025 | Rules for general-purpose AI models (GPAI); governance; designation of national authorities |
| 2 December 2026 | New deadline for transparency solutions on generated content (grace period cut from 6 to 3 months) |
| 2 August 2027 | Regulatory sandboxes; rules for high-risk AI embedded in regulated products |
| 2 December 2027 | Application of rules for stand-alone high-risk AI systems (Annex III) |
| 2 August 2028 | Application for high-risk systems embedded in products (Annex I) |
The reason for the delay is technical: the harmonised standards needed to bring high-risk systems into compliance were not ready for the original deadline. The Digital Omnibus now links the application of these rules to the availability of support tools. This postponement does not affect obligations already in force, in particular AI literacy and the ban on unacceptable practices, which remain fully applicable. The timeline for penalties and transparency, for its part, stays largely unchanged at 2 August 2026.
Failure to comply with the AI Act exposes you to fines that rank among the highest in European law. Article 99 sets three ceilings. Using a prohibited practice can cost up to 35 million euros or 7% of total worldwide annual turnover, whichever is higher. Breaching other obligations (high-risk systems, transparency) can reach 15 million euros or 3% of turnover. Supplying incorrect information to authorities is capped at 7.5 million euros or 1%.
The regulation provides for adjustment for SMEs and start-ups: for them, the applicable ceiling is the lower of the two amounts, percentage or absolute value. This flexibility does not remove the need to comply, but it limits the financial exposure of small organisations. To dig deeper, read our article on AI Act penalties.
Is my nonprofit really affected by the AI Act? Yes, as soon as it uses an AI system as part of its activity. The regulation makes no exception for the nonprofit sector. In practice, a nonprofit deployer is mainly concerned by the AI literacy obligation of Article 4.
I only use ChatGPT or a chatbot. Do I have obligations? You are a deployer of a limited-risk AI system. Your main obligations are transparency, informing the user that they are interacting with an AI or that the content is generated, and AI literacy for your teams.
Am I a provider if I configure an existing AI tool? In principle, no. You remain a deployer as long as you do not substantially modify the system or place it back on the market under your own name. Very heavy fine-tuning can, however, shift you into provider status.
Do high-risk obligations apply on 2 August 2026? No, not anymore since the Digital Omnibus adopted on 29 June 2026. The rules for stand-alone high-risk systems are postponed to 2 December 2027, and those embedded in products to 2 August 2028.
Does a non-EU company escape the regulation? No, if its system is placed on the Union market or if the output produced is used there. The scope is extraterritorial, on a model close to the GDPR.
How do I know whether my use counts as high risk? You have to examine the purpose of the system. Uses in recruitment, assessment, access to credit or essential services are the most likely to be classified as high risk. A scope audit lets you decide on a case-by-case basis.
GrowthPerf is a Qualiopi-certified training provider specialised in AI, no-code and automation for SMEs and nonprofits in the Paris region. Our approach to the AI Act always starts the same way: mapping your real usage to determine your status (provider or deployer) and the risk level of each system. That diagnostic drives the compliance effort, not the other way around.
We then handle the most immediate obligation, the AI literacy of Article 4, through training tailored to your concrete usage and eligible for OPCO funding. The goal is not to tick a box, but to make your teams autonomous and clear-eyed about AI.
To place your organisation within the scope of the AI Act and prioritise your actions, book a free 30-minute scope audit. You will leave with a clear reading of your status, your obligations and the timeline that actually applies to you.