EU AI Act Regulation (EU) 2024/1689 ⚠ August 2, 2026 Deadline

EU AI Act Compliance for SMBs —
What You Need Before August 2, 2026

Fines up to €35 million or 7% of global annual turnover. Most SMBs are "deployers" with lighter obligations than developers — but lighter isn't zero. You have 10 weeks to get ready.

Create a workspace → Guided intake → Colorado SB 205 →

12 questions · 5 minutes · Instant compliance score

€35M or 7% Prohibited AI violations Social scoring, biometric surveillance, manipulation of vulnerable groups
€15M or 3% High-risk AI violations Missing documentation, no human oversight, no conformity assessment
€7.5M or 1% Record-keeping violations Post-market monitoring failures or false information to authorities
Risk Classification

Four tiers. Which one applies to your AI?

The EU AI Act uses a tiered risk system. 85% of AI falls into "minimal risk" — but if your systems touch hiring, credit, or healthcare, you're in high-risk territory with full compliance obligations.

Tier 1 — Prohibited

Stop Using It Now

These systems were banned February 2, 2025. If you're using them, stop immediately — enforcement is already active.

Examples: Real-time biometric ID in public spaces · Government social scoring · Emotion recognition in the workplace · Subliminal manipulation of vulnerable groups
Tier 2 — High-Risk

Full Compliance by August 2

Systems that make or influence decisions in sensitive domains. Full documentation, risk assessment, conformity assessment, and EU database registration required.

Examples: Hiring/CV screening AI · Credit decision AI · Healthcare diagnostic AI · Employee performance monitoring · Essential services access
Tier 3 — Limited Risk

Transparency Disclosures Required

Systems that interact with users or generate content. You must clearly disclose that users are talking to AI or that content is AI-generated.

Examples: Customer service chatbots · AI-generated marketing content · Deep fake tools · AI writing assistants with customer-facing output
Tier 4 — Minimal Risk

AI Literacy Training Only

The vast majority of AI tools fall here. No specific AI Act obligations beyond documenting that your staff understands how AI works and its limitations.

Examples: Sales pipeline AI · Email spam filters · Recommendation engines · Internal document summarization · CRM AI features
Risk Decision Tree

Four questions to classify your AI

Work through these questions for each AI system you use. The first "yes" determines your compliance obligation — stop there.

01

Is the AI banned outright?

Does it perform real-time biometric ID in public spaces, social scoring, subliminal manipulation of vulnerable people, or emotion recognition in a workplace context?

Yes → Stop using it. Prohibited since Feb 2, 2025.
02

Does it make or influence decisions in a sensitive domain?

Does the system touch hiring, credit, education, healthcare, housing, law enforcement, insurance, or access to essential services?

Yes → High-risk. Full compliance required by Aug 2, 2026.
03

Is it a chatbot, deepfake tool, or AI-generated content system?

Does the system interact with users as if it were human, or produce AI-generated images, text, audio, or video for public consumption?

Yes → Limited-risk. Transparency disclosure required.
04

Everything else

Sales tools, spam filters, recommendation engines, internal productivity AI, scheduling tools — anything that doesn't touch a sensitive domain or interact with users as AI.

Minimal-risk. AI literacy training for staff — that's it.
Common Systems

Where common SMB AI tools fall

A quick-reference table for the most common AI tools SMBs use and their EU AI Act classification. Don't over-classify — that wastes months on documentation you don't need.

AI System Classification What You Need
Hiring/recruitment AI (CV screening, candidate ranking) High-Risk Full compliance: risk assessment, documentation, human oversight, conformity assessment, EU database registration
Employee performance monitoring / scheduling AI High-Risk Full compliance required — affects employment decisions
Credit / lending decision AI High-Risk Full compliance required
Customer service chatbot Limited-Risk Disclose that users are talking to AI at the start of the conversation
AI-generated marketing content Limited-Risk Label as "AI-generated" (machine-readable format required by Dec 2026)
Sales pipeline AI (lead scoring, opportunity ranking) Minimal-Risk AI literacy training for staff using the tool
Email spam filter Minimal-Risk AI literacy training only
Recommendation engine (products, content) Minimal-Risk AI literacy training only
Internal document summarization / AI copilot Minimal-Risk AI literacy training only
Pricing AI (dynamic pricing, cost calculation) Minimal-Risk AI literacy training; non-discrimination monitoring advised as best practice
Compliance Timeline

Key dates for SMB deployers

The AI Act has a phased rollout. Here's what matters for a typical SMB using (not building) AI systems.

Feb 2, 2025 — Already Enforced

Prohibited AI banned

Social scoring, real-time biometric surveillance, and subliminal manipulation systems were banned. Enforcement is active.

NOW
Now — July 1, 2026

AI system inventory & classification

List every AI tool in use, classify each by risk tier. Most SMBs discover 10+ tools including embedded AI in existing software. Don't over-classify.

Jul
July 15, 2026

AI literacy training complete

Article 4 requires documented proof that all staff using AI understand how it works, its limitations, and accountability. FUNDAE or EU Digital Academy certification counts — self-study does not.

AUG
August 2, 2026 — Enforcement Begins

High-risk AI compliance deadline

Full compliance required for high-risk systems: documented risk management policy, technical documentation, human oversight mechanisms, conformity assessment complete, and EU database registration.

Dec
December 2, 2026

AI-generated content labeling

Machine-readable labels required on AI-generated images, audio, and video. Marketing and content teams need a labeling workflow in place.

SMB Checklist

What most SMBs actually need to do

If your AI tools are minimal-risk (most are), your compliance footprint is small. Here's what each tier actually requires from an SMB deployer.

All SMBs — Regardless of Risk Tier

  • Complete an AI system inventory (list every tool in use)
  • Classify each tool by risk tier using the decision tree above
  • Document AI literacy training for all staff who use AI
  • Retain training certificates or completion records for 3+ years
  • Establish policy: new hires complete AI training within 30 days

💬 If You Use Chatbots or AI-Generated Content

  • Add clear AI disclosure at chatbot entry ("You're talking to an AI assistant")
  • Label AI-generated content as "AI-generated" in marketing materials
  • Complete GDPR DPIA if the chatbot processes personal data
  • Sign Data Processing Agreements with AI vendors
  • Document disclosure mechanisms (screenshots, UX flow)

⚠️ If You Use High-Risk AI (Hiring, Credit, Healthcare)

  • Create documented risk management policy (identify, assess, mitigate risks)
  • Collect technical documentation from your AI vendor
  • Build human oversight into every high-risk decision workflow
  • Complete conformity self-assessment and document results
  • Register the system in the EU AI Act database (portal opens before Aug 2)
  • Establish post-market monitoring for bias and performance drift

📋 Ongoing After August 2

  • Monitor national authority enforcement actions in your jurisdiction
  • Report discrimination incidents in high-risk systems to legal counsel
  • Update AI inventory when new tools are adopted (shadow AI risk)
  • Retain all compliance documentation for minimum 5 years
  • Review high-risk system performance and bias data annually

Find out which AI Act obligations apply to you.

The free 5-minute assessment identifies which of your AI systems are high-risk, what compliance gaps you have, and exactly what to fix before August 2.

Take the Free Assessment → See a Sample Plan

Free assessment · Compliance Action Plan $299 · No subscription