The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI law. It applies to any company whose AI systems affect EU residents — regardless of where you are incorporated. Most SMBs fall into the "deployer" category with lighter obligations than AI developers, but lighter is not zero. The August 2, 2026 enforcement deadline is real, and fines start at €7.5 million.
12 questions · 5 minutes · Instant score · No account required
The EU AI Act distinguishes two primary roles. Your role determines what you must do — and the difference is significant.
Develops an AI system and places it on the market — either commercially or as a free tool. Responsible for training the model, ensuring technical compliance, conformity assessments, and EU database registration for high-risk systems.
Uses an AI system in a professional context to serve end users or support internal decisions. You bought or subscribed to an AI tool and use it in your operations. Deployers have lighter obligations than providers — but significantly more than zero for high-risk systems.
The EU AI Act's geographic scope follows the AI system's output, not the company's location. Source: artificialintelligenceact.eu, Article 2. If your AI tool affects EU residents — via marketing, employment, lending, or any other application — the Act applies to you even if your company is based in the US, UK, Canada, or anywhere else outside the EU.
Use these questions to confirm whether you're in scope:
This includes generative AI writing tools, AI-powered CRMs, chatbots, CV-screening software, scheduling AI, analytics platforms with AI features, or any product where AI makes or supports decisions. If your vendor uses AI under the hood, you are still a deployer of that AI.
Yes → Proceed to Question 2Do EU-based employees, customers, job applicants, or users experience the AI system's decisions or outputs — directly or indirectly? If you sell into Europe, hire from Europe, or have operations there, the answer is almost certainly yes.
Yes → You are subject to the EU AI Act as a deployerIf you are developing AI models, fine-tuning foundation models, or embedding AI into a product you sell to business customers, you are also a provider with additional obligations on top of deployer duties.
Yes → Provider obligations apply. Seek specialist legal counsel.For the rest of this guide, we focus on deployer obligations — which is where the vast majority of SMBs sit.
The EU AI Act uses a four-tier risk hierarchy. Your compliance workload is almost entirely determined by where your AI tools land on this scale. Over-classifying wastes months of effort. Under-classifying creates enforcement risk. Get this right first.
These practices are categorically banned under Article 5. No exceptions for SMBs. The prohibition is not a future risk — it has been in force since February 2, 2025. If you are using any of these, the only compliant action is immediate cessation.
Defined in Article 6 and Annex III of Regulation (EU) 2024/1689. High-risk AI is any system used in a domain where errors or biases can significantly harm people's rights, health, safety, or livelihood. As a deployer, you must ensure the vendor has completed conformity assessment, you must implement human oversight, maintain documentation, and conduct your own risk management — even if you're just a customer of the AI tool, not its developer.
Limited-risk systems carry transparency obligations under Articles 50–52. Users must be told they are interacting with AI. AI-generated content must be labeled. These are not extensive compliance programs — but failure to disclose is still a violation subject to the €7.5M/1% penalty tier.
The EU Commission estimates over 85% of AI systems fall into this category. Minimal-risk AI carries one primary obligation: Article 4 requires that organizations ensure anyone using AI systems has sufficient AI literacy — documented training on how the AI works, its limitations, and accountability protocols. No conformity assessment, no database registration, no technical documentation required.
If any of your AI tools are high-risk (hiring, credit, healthcare, performance monitoring), these are your specific obligations as a deployer under Articles 26–29 of the EU AI Act. These apply even when you didn't build the AI — you just use it.
You must implement and maintain a documented risk management system for each high-risk AI system you deploy. This is an ongoing process, not a one-time audit.
Every high-risk AI decision must include meaningful human oversight. Rubber-stamp review does not qualify — oversight must be genuine and documented.
You must obtain and retain technical documentation from your AI vendor for each high-risk system you use. If your vendor cannot provide this, you cannot legally deploy the system.
Individuals subject to high-risk AI decisions — job applicants, loan applicants, insurance applicants — must be informed that AI is involved. This is a standalone obligation, not just GDPR.
High-risk AI systems must have logging enabled and deployers must monitor performance and bias over time. Enforcement authorities may request logs during investigations.
Article 4 applies to all AI users, not just high-risk deployments. Every employee using AI must have documented, certifiable AI literacy training before August 2, 2026.
The EU AI Act has a phased rollout from 2024 to 2027. Here is every date that matters for a typical SMB deployer, with current status as of May 2026.
Regulation (EU) 2024/1689 was published in the Official Journal of the European Union and entered into force 20 days later. The 36-month full implementation clock started here.
Six months after entry into force, the prohibitions under Article 5 became law. Real-time biometric ID in public spaces, social scoring systems, emotion recognition in the workplace, and subliminal manipulation of vulnerable groups are illegal across all EU member states. Enforcement is active.
Rules for General-Purpose AI (GPAI) models — covering foundation model providers like OpenAI, Mistral, and Anthropic — took effect. Businesses using GPAI-powered tools benefit from providers' compliance but remain responsible for their own deployer obligations.
The action window for SMBs to complete AI system inventories, classify each tool by risk tier, document human oversight processes, and complete Article 4 AI literacy training for all staff. Most organizations underestimate this phase — 10+ tools is common once embedded AI in existing software is counted. Start this week.
The primary enforcement date for high-risk AI systems. By this date, deployers must have: risk management systems documented, technical documentation obtained from vendors, human oversight workflows operational, transparency disclosures to affected persons implemented, logging enabled, and staff AI literacy training complete with records retained. National market surveillance authorities (MSAs) in each EU member state begin active enforcement from this date.
Machine-readable watermarking or labeling requirements for AI-generated images, audio, and video become mandatory. Marketing and content teams must have a labeling workflow and metadata tagging process in place.
AI systems that were already on the market before the EU AI Act entered into force — including AI embedded in products regulated under other EU sectoral laws (medical devices, machinery, vehicles) — must achieve full compliance by this date. If you use legacy AI products from regulated industries, mark this date now.
The EU AI Act fine structure is more aggressive than GDPR for the highest violations. For SMBs, note that the law applies the higher of the fixed amount or the percentage of global annual turnover. A company with €5M revenue faces maximum fines of €15M for high-risk violations — the percentage floor doesn't help you if you're small.
| Violation Category | Maximum Fine | Basis | Typical SMB Trigger |
|---|---|---|---|
| Prohibited AI practices (Article 5) | €35M or 7% | Whichever is higher, of global annual turnover | Using workplace emotion recognition; real-time biometric surveillance; social scoring |
| High-risk AI violations (Articles 9–29) | €15M or 3% | Whichever is higher, of global annual turnover | No human oversight on hiring AI; no risk management documentation; no technical documentation from vendor |
| Transparency violations (Article 50) | €15M or 3% | Whichever is higher, of global annual turnover | Chatbot not disclosing it's AI; AI content not labeled |
| Providing false/incomplete information to authorities | €7.5M or 1% | Whichever is higher, of global annual turnover | Responding inaccurately to market surveillance authority investigations |
| Failing to cooperate with MSA investigations | €7.5M or 1% | Whichever is higher, of global annual turnover | Refusing document access; not responding to authority requests |
Source: Articles 99–101, Regulation (EU) 2024/1689. Penalties are set by national market surveillance authorities; enforcement intensity will vary by member state. For SMBs, €7.5M is the practical minimum across all violation categories. See the EU AI Act Portal for official text.
Reading the regulation is the first step. Knowing where your specific AI tools fall, what your gaps are, and getting a written compliance plan is the second. GovernIQ automates the gap analysis.
Covers AI tool inventory, data handling practices, employee training status, and policy governance. Takes 5 minutes. Generates a 0–100 compliance score and identifies up to 8 specific policy gaps.
Take the Assessment →See a real example of the personalized Compliance Action Plan output for a fictional financial advisory firm. Understand exactly what you'll get before you buy.
View Sample Plan →After a $299 one-time purchase, receive a full Compliance Action Plan specific to your company's AI stack, gaps, and risk level — with actionable items, policy templates, and a 90-day remediation roadmap.
See Pricing →The GovernIQ assessment identifies which of your AI tools are high-risk, which gaps you have against the EU AI Act, and exactly what to fix before August 2. Free. No account required.
Free assessment · Personalized Compliance Action Plan $299 · No subscription