The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityThe EU AI Act, Regulation 2024/1689, applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you have been required to train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect. This guide covers the real timeline, updated after the digital omnibus package adopted in June 2026, and a 6 step roadmap to get compliant without overspending.
Much of what was published in 2024 and 2025 announced that the "high risk" obligations would fully apply on 2 August 2026. That is no longer accurate: the digital omnibus package voted by the European Parliament and approved by the Council in late June 2026 shifted part of the timeline. What remains true, and what too many companies ignore: several obligations are already in force today, including the duty to train your teams in AI, and the penalty regime does activate on 2 August 2026.
Any organisation that develops, sells or simply uses an AI system in the European Union falls within the scope of the AI Act, whatever its size: SME, micro-business, nonprofit or large group. Regulation 2024/1689, published in the Official Journal of the EU on 12 July 2024 and in force since 1 August 2024, is the world's first comprehensive legal framework for artificial intelligence. Contrary to a persistent misconception, it does not target software vendors only.
The text distinguishes several roles, and yours determines your obligations:
For a typical SME, the most common scenario is simple: you are a deployer of mainstream generative AI systems. Your obligations are then limited but real: train your teams, inform the people who interact with the AI, and check that none of your uses falls into the prohibited or high risk categories. A nonprofit that uses AI to screen volunteer applications or support vulnerable people has more questions to ask itself than a firm drafting meeting notes with an LLM.
The regulation also applies to organisations established outside the EU whenever the output produced by the AI system is used within the Union. A Swiss or British service provider serving French clients is therefore covered.
The original AI Act timeline was amended in June 2026 by the digital omnibus package: the "high risk" obligations are postponed to late 2027 and 2028, but everything else applies as planned. This is the single largest source of confusion, including in the trade press. Here are the deadlines as they stand in July 2026:
In practice, for an SME that uses AI, two dates matter: today (Articles 4 and 5, already applicable) and 2 August 2026 (transparency and penalties). The postponement of high risk to December 2027 is breathing room for the companies concerned, not an exemption: high risk compliance projects take time, and 17 months go by quickly.
One caveat: this timeline results from a text adopted in late June 2026. If your last briefing predates the summer, have it refreshed before setting your compliance budget.
The AI Act places every AI use into one of four risk levels, and your obligations flow directly from that classification, not from the size of your company. The same tool can sit at different levels depending on use: an LLM drafting your newsletters is minimal risk; the same LLM used to shortlist CVs becomes high risk.
| Risk level | Concrete examples | Your obligations | Deadline |
|---|---|---|---|
| Unacceptable (prohibited) | Social scoring, manipulation exploiting vulnerability, emotion recognition at work | Stop the practice, no exceptions | Already in force (2 February 2025) |
| High risk | CV screening, credit scoring, algorithmic task allocation, assessing learners | Risk management, human oversight, logs, documentation | 2 December 2027 (Annex III) |
| Transparency risk | Customer chatbots, generated content (text, images, deepfakes), conversational agents | Inform people, mark generated content | 2 August 2026 |
| Minimal risk | Writing assistance, translation, spam filters, proofreading, brainstorming | Nothing specific beyond Article 4 | Not applicable |
In our AI audit work with SMEs around Paris, the split is almost always the same: 80 to 90 percent of uses are minimal risk, a few fall under transparency (a website chatbot, generated visuals for social media), and one or two HR uses deserve a proper high risk analysis. The classic trap: the candidate "matching" module switched on by default in an HR tool, which nobody had identified as AI.
Since 2 February 2025, your organisation must ensure a sufficient level of AI literacy for anyone using AI systems on its behalf: that is Article 4, and the omnibus neither postponed nor softened it. This AI literacy duty applies to providers and deployers alike, so to the 12 person SME where three people use ChatGPT as much as to an industrial group.
The text does not impose a single format: the training level must fit the technical context, the teams' experience and the actual uses. For a team using generative AI for office work, a structured one day awareness programme covers the essentials: how models work and where they fail, hallucinations and output checking, confidential data, internal usage rules. We covered the topic in detail in our article on Article 4 and the training obligation, and the practical side in what the August 2026 deadline changes for SMEs.
An often overlooked point: evidence. In a dispute or an inspection, the burden is on you to show your teams were trained. Keep the programmes, attendance sheets and training certificates. Training delivered by a Qualiopi certified provider has a double advantage here: the documentary evidence comes built in, and in France the cost can be covered by your OPCO, as explained in our guide to OPCO funding.
Article 5 outright prohibits certain practices since the same date: social scoring, exploiting the vulnerabilities of fragile groups, inferring emotions in the workplace or in education (outside medical or safety reasons), and certain forms of biometric identification. Most SMEs are not concerned, but check the side features of your tools: a video conferencing product that claims to analyse participants' "emotional engagement" in meetings would take you into prohibited territory.
From 2 August 2026, you must clearly inform anyone who interacts with an AI or views AI generated content, and national authorities can impose penalties. That is the real shift of summer 2026 for SMEs and nonprofits.
Article 50 sets four main transparency obligations:
That last point deserves attention from any organisation that publishes content: genuine human review, with an identified editorial owner, places you within the exception. A fully automated blog with no human control does not.
On penalties, Article 99 sets three ceilings: up to 35 million euros or 7 percent of worldwide annual turnover for prohibited practices; up to 15 million euros or 3 percent for most other breaches; up to 7.5 million euros or 1 percent for supplying incorrect information to authorities. For SMEs and startups, the regulation explicitly retains the lower of the two ceilings, and authorities must take the company's size and economic viability into account. We covered the mechanics in our article on what non compliant companies risk.
Neither drama nor complacency is warranted. Nobody will shut down your SME on 3 August 2026. The real risk sits elsewhere: a dismissed employee invoking a non compliant AI assisted decision before an employment tribunal, a lost tender because you could not document compliance, a large client demanding contractual guarantees. AI Act compliance is becoming a supplier selection criterion, just as the GDPR did after 2018.
If you use AI to recruit, assess, score or assign people, you probably fall under the high risk category of Annex III, whose obligations will apply on 2 December 2027. The postponement decided in June 2026 buys you time; it does not change the scope.
The most frequent high risk cases in SMEs and nonprofits:
For these uses, the deployer will notably have to ensure effective human oversight (the AI proposes, a human decides and can override), use relevant input data, keep the system logs, inform the people concerned and report serious incidents to the provider. Providers carry most of the load: documented risk management, data governance, technical documentation, registration in the European database.
Our practical recommendation: do not launch a theoretical high risk programme. Start by mapping your actual uses (most SMEs discover 2 to 3 times more AI uses than they expected), classify each use across the four levels, and focus the effort on the few genuinely high risk ones. If an HR module tips you into high risk for marginal benefit, the most rational decision is sometimes to switch it off.
An SME or nonprofit can reach solid compliance in 4 to 8 weeks of distributed work, without hiring or blowing up its budget. Here is the sequence we apply with our clients:
For nonprofits the approach is identical but the funding differs: see our dedicated article on AI training for nonprofits. And for a condensed overview, our AI Act compliance checklist for SMEs turns these steps into an actionable list.
Yes, as a deployer. Your obligations remain light: train the users (Article 4, already in force), respect transparency if you publish generated content without human review, and check that no use falls under the prohibited practices. No technical file or European registration for this profile.
Partially. The digital omnibus adopted in June 2026 postpones the high risk obligations of Annex III to 2 December 2027 and those of Annex I to 2 August 2028. Everything else follows the original timeline: Articles 4 and 5 have applied since February 2025, and Article 50 transparency plus the penalty regime apply from 2 August 2026.
Ceilings go up to 35 million euros or 7 percent of worldwide turnover for prohibited practices, and 15 million euros or 3 percent for other breaches. For SMEs the regulation retains the lower of the two amounts and requires authorities to consider economic viability. The most likely short term risk is indirect: employment litigation, lost tenders, contractual demands from large clients.
National market surveillance authorities designated by each member state, coordinated at European level by the Commission's AI Office. In France the setup relies on existing sector regulators, with the CNIL remaining competent whenever personal data is processed. These authorities can impose penalties from 2 August 2026.
The GDPR protects personal data; the AI Act regulates AI systems themselves, including when no personal data is processed. The two stack: an HR tool analysing CVs must comply with the GDPR for candidate data and with the AI Act for the algorithmic logic. A shared governance (single register, common lead) avoids doing the work twice.
No, but it is the foundation. Training covers Article 4 and enables the rest: trained teams apply transparency, spot risky uses and feed your mapping. You still need the transparency fixes, an internal AI policy and, where relevant, the high risk workstream.
Not in substance: the regulation targets organisations, not legal forms. A nonprofit employer has the same obligations as an SME. Two specifics though: social sector uses (supporting vulnerable people, prioritising aid) can qualify as high risk, and in France training funding goes through Uniformation rather than a standard OPCO.
GrowthPerf is a Qualiopi certified training provider specialised in AI, no-code and automation for SMEs and nonprofits. On the AI Act, our approach is deliberately pragmatic:
Want to know where you stand? Book a free 30 minute AI Act compliance audit: we review your uses, identify the top 2 or 3 actions and the right funding setup. No commitment, no 40 page report, just a clear assessment.
Written by Romain Bellaïche, founder of GrowthPerf, a Qualiopi certified training provider specialised in AI, no-code and automation for SMEs and nonprofits. Official sources: EU Regulation 2024/1689 on artificial intelligence (AI Act), in particular Articles 4, 5, 50 and 99 and Annex III; the digital omnibus package adopted by the European Parliament and the Council in June 2026; European Commission (AI Office).