Complete Guide Regulation (EU) 2024/1689 ⚠ August 2, 2026 Deadline

EU AI Act Compliance for Small & Mid-Market Businesses

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI law. It applies to any company whose AI systems affect EU residents — regardless of where you are incorporated. Most SMBs fall into the "deployer" category with lighter obligations than AI developers, but lighter is not zero. The August 2, 2026 enforcement deadline is real, and fines start at €7.5 million.

Create a workspace → Guided intake → See a Sample Plan

12 questions · 5 minutes · Instant score · No account required

TL;DR — The Three Things You Must Know
Scope & Applicability

Are you affected? Providers vs. Deployers explained

The EU AI Act distinguishes two primary roles. Your role determines what you must do — and the difference is significant.

Role 1

Provider

Develops an AI system and places it on the market — either commercially or as a free tool. Responsible for training the model, ensuring technical compliance, conformity assessments, and EU database registration for high-risk systems.

Who this is: OpenAI, Microsoft Copilot, Workday, any SaaS company building AI-powered products for others to use.
Role 2 — Most SMBs

Deployer

Uses an AI system in a professional context to serve end users or support internal decisions. You bought or subscribed to an AI tool and use it in your operations. Deployers have lighter obligations than providers — but significantly more than zero for high-risk systems.

Who this is: A law firm using AI to review contracts. A financial advisor using AI-generated client reports. An HR team using CV-screening software. A retailer using a customer chatbot.

The EU AI Act's geographic scope follows the AI system's output, not the company's location. Source: artificialintelligenceact.eu, Article 2. If your AI tool affects EU residents — via marketing, employment, lending, or any other application — the Act applies to you even if your company is based in the US, UK, Canada, or anywhere else outside the EU.

Use these questions to confirm whether you're in scope:

01

Do you use any AI tools in your business operations?

This includes generative AI writing tools, AI-powered CRMs, chatbots, CV-screening software, scheduling AI, analytics platforms with AI features, or any product where AI makes or supports decisions. If your vendor uses AI under the hood, you are still a deployer of that AI.

Yes → Proceed to Question 2
02

Does the output of that AI touch EU residents?

Do EU-based employees, customers, job applicants, or users experience the AI system's decisions or outputs — directly or indirectly? If you sell into Europe, hire from Europe, or have operations there, the answer is almost certainly yes.

Yes → You are subject to the EU AI Act as a deployer
03

Do you build AI systems and sell them to others?

If you are developing AI models, fine-tuning foundation models, or embedding AI into a product you sell to business customers, you are also a provider with additional obligations on top of deployer duties.

Yes → Provider obligations apply. Seek specialist legal counsel.

For the rest of this guide, we focus on deployer obligations — which is where the vast majority of SMBs sit.

Risk Classification

The four risk tiers — with concrete SMB examples

The EU AI Act uses a four-tier risk hierarchy. Your compliance workload is almost entirely determined by where your AI tools land on this scale. Over-classifying wastes months of effort. Under-classifying creates enforcement risk. Get this right first.

Tier 1 — Prohibited (Banned Since Feb 2, 2025)

Stop using it. Now. Enforcement is already active.

These practices are categorically banned under Article 5. No exceptions for SMBs. The prohibition is not a future risk — it has been in force since February 2, 2025. If you are using any of these, the only compliant action is immediate cessation.

SMB-relevant examples AI systems that use subliminal or manipulative techniques to influence vulnerable users · Real-time biometric identification in publicly accessible spaces · Emotion recognition systems in workplaces or educational settings · AI that exploits age, disability, or social situations to manipulate behavior · Social scoring systems that rank individuals based on behavior in unrelated contexts
Tier 2 — High-Risk (August 2, 2026 Deadline)

Full compliance required. This is the category most SMBs underestimate.

Defined in Article 6 and Annex III of Regulation (EU) 2024/1689. High-risk AI is any system used in a domain where errors or biases can significantly harm people's rights, health, safety, or livelihood. As a deployer, you must ensure the vendor has completed conformity assessment, you must implement human oversight, maintain documentation, and conduct your own risk management — even if you're just a customer of the AI tool, not its developer.

Common SMB high-risk systems CV screening and candidate ranking AI (Annex III, employment) · Employee performance monitoring and scheduling AI · Credit decision support tools for lending or insurance · AI that determines access to essential public services · Healthcare diagnostic AI or clinical decision support · Biometric categorization systems (beyond prohibited tier) · AI systems embedded in safety components of regulated products
Tier 3 — Limited Risk (Transparency Required)

Disclose AI interaction. Lightweight but legally mandatory.

Limited-risk systems carry transparency obligations under Articles 50–52. Users must be told they are interacting with AI. AI-generated content must be labeled. These are not extensive compliance programs — but failure to disclose is still a violation subject to the €7.5M/1% penalty tier.

Common SMB limited-risk systems Customer service chatbots (must disclose AI at session start) · AI-generated marketing emails, blog posts, or social content (must be labeled) · Voice assistants and phone bots · AI-generated product descriptions or legal summaries presented to users · Deepfake-like synthetic media tools
Tier 4 — Minimal Risk (AI Literacy Training Only)

The good news: most AI is here. Train your staff and document it.

The EU Commission estimates over 85% of AI systems fall into this category. Minimal-risk AI carries one primary obligation: Article 4 requires that organizations ensure anyone using AI systems has sufficient AI literacy — documented training on how the AI works, its limitations, and accountability protocols. No conformity assessment, no database registration, no technical documentation required.

Common SMB minimal-risk systems Sales pipeline AI (lead scoring, deal forecasting) · Email spam filters · Recommendation engines (products, content) · CRM AI features · Internal document summarization · Grammar and writing assistance tools · Scheduling optimization AI (not employment-decision AI) · Pricing AI (with non-discrimination monitoring as best practice)
Deployer Obligations

High-risk AI: what SMB deployers must actually do

If any of your AI tools are high-risk (hiring, credit, healthcare, performance monitoring), these are your specific obligations as a deployer under Articles 26–29 of the EU AI Act. These apply even when you didn't build the AI — you just use it.

📋

Risk Management System

You must implement and maintain a documented risk management system for each high-risk AI system you deploy. This is an ongoing process, not a one-time audit.

  • Identify reasonably foreseeable risks the AI system poses
  • Document risk assessment methodology and outcomes
  • Define mitigation measures and residual risk acceptance
  • Assign internal ownership for the risk management process
  • Review annually or when the system changes materially
👁

Human Oversight

Every high-risk AI decision must include meaningful human oversight. Rubber-stamp review does not qualify — oversight must be genuine and documented.

  • Define the human oversight role and decision authority for each AI workflow
  • Train the designated reviewer on the AI system's limitations and failure modes
  • Build override mechanisms into the workflow — AI output is a recommendation, not a final decision
  • Log all human review actions and final decisions separately from AI outputs
  • Prohibit fully automated final decisions in high-risk contexts
📁

Technical Documentation

You must obtain and retain technical documentation from your AI vendor for each high-risk system you use. If your vendor cannot provide this, you cannot legally deploy the system.

  • Request the EU Declaration of Conformity from your vendor
  • Obtain technical documentation as required under Article 11
  • Verify the vendor has registered the system in the EU AI Act database
  • Retain copies for a minimum of 10 years (or as specified by sectoral law)
  • Update documentation when vendor releases material updates to the system
📣

Transparency to Affected Persons

Individuals subject to high-risk AI decisions — job applicants, loan applicants, insurance applicants — must be informed that AI is involved. This is a standalone obligation, not just GDPR.

  • Disclose AI use in hiring processes to all applicants before screening begins
  • Explain what data the AI uses and how decisions are influenced
  • Provide a mechanism for applicants to request human review of AI-influenced decisions
  • Document all disclosure communications and consent records
  • Update privacy policies and job application forms before August 2, 2026
📊

Logging & Post-Market Monitoring

High-risk AI systems must have logging enabled and deployers must monitor performance and bias over time. Enforcement authorities may request logs during investigations.

  • Confirm your vendor enables automatic logging of AI system inputs and outputs
  • Retain logs for the period specified by applicable national authority guidelines
  • Implement bias monitoring: review outcomes quarterly for demographic disparities
  • Report incidents involving discrimination or material errors to legal counsel immediately
  • Maintain a log of all AI-influenced decisions in high-risk categories
🎓

AI Literacy Training (All SMBs)

Article 4 applies to all AI users, not just high-risk deployments. Every employee using AI must have documented, certifiable AI literacy training before August 2, 2026.

  • Audit which staff members use AI tools (including embedded AI in software)
  • Select an EU-recognized training program (EU Digital Academy, FUNDAE, or equivalent)
  • Complete training for all current staff and document completion
  • Establish 30-day onboarding training requirement for new hires
  • Retain certificates and training records for a minimum of 3 years
Enforcement Timeline

Key dates for SMB deployers

The EU AI Act has a phased rollout from 2024 to 2027. Here is every date that matters for a typical SMB deployer, with current status as of May 2026.

August 1, 2024 — Passed

EU AI Act Enters Into Force

Regulation (EU) 2024/1689 was published in the Official Journal of the European Union and entered into force 20 days later. The 36-month full implementation clock started here.

February 2, 2025 — Already Enforceable

Prohibited AI Banned — Chapter II Enforcement Active

Six months after entry into force, the prohibitions under Article 5 became law. Real-time biometric ID in public spaces, social scoring systems, emotion recognition in the workplace, and subliminal manipulation of vulnerable groups are illegal across all EU member states. Enforcement is active.

August 2, 2025 — Passed

GPAI Model Obligations Apply

Rules for General-Purpose AI (GPAI) models — covering foundation model providers like OpenAI, Mistral, and Anthropic — took effect. Businesses using GPAI-powered tools benefit from providers' compliance but remain responsible for their own deployer obligations.

NOW
Now → July 2026

AI Inventory, Classification, and Training Window

The action window for SMBs to complete AI system inventories, classify each tool by risk tier, document human oversight processes, and complete Article 4 AI literacy training for all staff. Most organizations underestimate this phase — 10+ tools is common once embedded AI in existing software is counted. Start this week.

AUG
August 2, 2026 — Hard Deadline

High-Risk AI Full Compliance Required

The primary enforcement date for high-risk AI systems. By this date, deployers must have: risk management systems documented, technical documentation obtained from vendors, human oversight workflows operational, transparency disclosures to affected persons implemented, logging enabled, and staff AI literacy training complete with records retained. National market surveillance authorities (MSAs) in each EU member state begin active enforcement from this date.

Dec
December 2, 2026

AI-Generated Content Machine-Readable Labeling

Machine-readable watermarking or labeling requirements for AI-generated images, audio, and video become mandatory. Marketing and content teams must have a labeling workflow and metadata tagging process in place.

Aug
August 2, 2027

Legacy & Embedded AI Systems Deadline

AI systems that were already on the market before the EU AI Act entered into force — including AI embedded in products regulated under other EU sectoral laws (medical devices, machinery, vehicles) — must achieve full compliance by this date. If you use legacy AI products from regulated industries, mark this date now.

Financial Exposure

Penalty structure — what the fines actually look like

The EU AI Act fine structure is more aggressive than GDPR for the highest violations. For SMBs, note that the law applies the higher of the fixed amount or the percentage of global annual turnover. A company with €5M revenue faces maximum fines of €15M for high-risk violations — the percentage floor doesn't help you if you're small.

Violation Category Maximum Fine Basis Typical SMB Trigger
Prohibited AI practices (Article 5) €35M or 7% Whichever is higher, of global annual turnover Using workplace emotion recognition; real-time biometric surveillance; social scoring
High-risk AI violations (Articles 9–29) €15M or 3% Whichever is higher, of global annual turnover No human oversight on hiring AI; no risk management documentation; no technical documentation from vendor
Transparency violations (Article 50) €15M or 3% Whichever is higher, of global annual turnover Chatbot not disclosing it's AI; AI content not labeled
Providing false/incomplete information to authorities €7.5M or 1% Whichever is higher, of global annual turnover Responding inaccurately to market surveillance authority investigations
Failing to cooperate with MSA investigations €7.5M or 1% Whichever is higher, of global annual turnover Refusing document access; not responding to authority requests

Source: Articles 99–101, Regulation (EU) 2024/1689. Penalties are set by national market surveillance authorities; enforcement intensity will vary by member state. For SMBs, €7.5M is the practical minimum across all violation categories. See the EU AI Act Portal for official text.

How GovernIQ Helps

From this guide to a compliance plan in under an hour

Reading the regulation is the first step. Knowing where your specific AI tools fall, what your gaps are, and getting a written compliance plan is the second. GovernIQ automates the gap analysis.

01

12-Question Assessment

Covers AI tool inventory, data handling practices, employee training status, and policy governance. Takes 5 minutes. Generates a 0–100 compliance score and identifies up to 8 specific policy gaps.

Take the Assessment →
02

Sample Compliance Plan

See a real example of the personalized Compliance Action Plan output for a fictional financial advisory firm. Understand exactly what you'll get before you buy.

View Sample Plan →
03

Personalized Action Plan

After a $299 one-time purchase, receive a full Compliance Action Plan specific to your company's AI stack, gaps, and risk level — with actionable items, policy templates, and a 90-day remediation roadmap.

See Pricing →
Frequently Asked Questions

EU AI Act SMB compliance — the questions we hear most

Does the EU AI Act apply to small businesses outside the EU?
Yes. The EU AI Act has extraterritorial reach. If your AI system's output is used in the EU — even if your company is based in the US, UK, or anywhere else — you are subject to the Act as a deployer or provider. The test is where the output affects EU residents, not where you are incorporated. Article 2 of Regulation (EU) 2024/1689 is explicit on this point.
What is the difference between a 'provider' and a 'deployer' under the EU AI Act?
A provider develops and places an AI system on the market — think OpenAI, Microsoft, or any vendor building AI products. A deployer uses an AI system in a professional context to serve end users or make decisions. Most SMBs are deployers: they buy or subscribe to AI tools and use them in their business operations. Deployers have lighter obligations than providers for most categories, but still face significant compliance duties for high-risk AI systems.
When does EU AI Act enforcement begin for high-risk AI?
August 2, 2026. That is the enforcement date for high-risk AI systems under Article 6 and Annex III of Regulation (EU) 2024/1689. Prohibited AI practices were already banned on February 2, 2025. GPAI model rules applied from August 2, 2025. The August 2, 2026 deadline is the major one for most businesses — it covers hiring AI, credit AI, healthcare AI, and any system in the Annex III high-risk categories.
What counts as 'high-risk' AI for an SMB?
High-risk AI is defined in Annex III of the EU AI Act. For SMBs, the most common categories are: AI used in recruitment or HR decisions (CV screening, candidate ranking, performance monitoring), AI used in credit assessment or lending decisions, AI used in access to essential services (insurance, public benefits), and AI used in educational or vocational training assessment. If your hiring tools, credit tools, or HR monitoring tools use AI to influence outcomes, they are likely high-risk.
What are the penalties for violating the EU AI Act?
Penalties are tiered by violation type. Using prohibited AI: up to €35 million or 7% of global annual turnover, whichever is higher. Violations related to high-risk AI or transparency obligations: up to €15 million or 3% of global annual turnover. Providing false information to authorities: up to €7.5 million or 1% of global annual turnover. For SMBs, the turnover-based floor is often the higher figure — meaning the penalty is not reduced because you're small.
Does the EU AI Act apply to AI embedded in software I buy?
Yes, if you deploy that software in a way that uses the AI component. A CRM with embedded lead-scoring AI, a payroll system with scheduling AI, or HR software with performance-rating AI — if those AI features influence decisions that fall into Annex III categories, you as the deployer carry compliance obligations even though the vendor built the model. You must obtain technical documentation from the vendor and cannot legally rely on the assumption that "the vendor handles it."
What is AI literacy training under Article 4?
Article 4 requires organizations to ensure their staff and anyone using AI systems on their behalf have sufficient AI literacy — documented training on how AI works, its limitations, bias risks, and accountability. Training completion must be documented and records retained. Free options include EU Digital Academy courses and FUNDAE (for Spanish companies). Self-study without certification does not generally satisfy the documentation requirement for regulatory purposes.
Do chatbots trigger EU AI Act obligations?
Yes. Customer service chatbots fall under 'limited risk' in the EU AI Act. They require transparency: users must be informed they are interacting with an AI at the start of each conversation. This is a lightweight obligation but still legally required under Article 50. If the chatbot also makes or influences decisions in an Annex III category (for example, insurance eligibility or loan pre-qualification), the high-risk rules apply instead — and the obligations become much more extensive.
What documentation records do SMB deployers need to keep?
For high-risk AI: technical documentation from the vendor (EU Declaration of Conformity, technical specifications), records of the conformity assessment, risk management documentation, and human oversight procedures. Minimum retention is 10 years for some categories. For all AI: AI literacy training records for staff. For limited-risk chatbots: records of disclosure mechanisms (screenshots, UX documentation). Build your document management system now — enforcement agencies audit documentation, not just system behavior.
How do I verify that my vendor's AI is compliant?
Request the EU Declaration of Conformity and technical documentation under Article 13. Reputable vendors selling into the EU should have these documents ready before the August 2026 enforcement date. For high-risk systems, the provider is required to register in the EU AI Act database — expected to open before August 2026 at artificialintelligenceact.eu. If a vendor cannot provide documentation, you cannot legally deploy the system for high-risk use cases.
Is the EU AI Act the same as GDPR?
No. GDPR governs personal data processing. The EU AI Act governs the development and use of AI systems specifically — it is AI-specific regulation, not data regulation. They overlap significantly: many AI systems process personal data, triggering both laws simultaneously. But the EU AI Act adds requirements GDPR does not cover — risk classification, technical documentation, human oversight, conformity assessment, EU database registration, and the AI literacy obligation. If you operate in the EU, you need both frameworks in place.
📋
Free Tool — No signup required
Need a policy before August 2? Get a customized AI Acceptable Use Policy in 60 seconds.
Named approved/restricted tools, high-risk AI checklist, AI literacy requirements — generated for your organization.
Build Your Policy Free →

Find out exactly where you stand — in 5 minutes.

The GovernIQ assessment identifies which of your AI tools are high-risk, which gaps you have against the EU AI Act, and exactly what to fix before August 2. Free. No account required.

Create a workspace → Guided intake → See a Sample Report

Free assessment · Personalized Compliance Action Plan $299 · No subscription