# AI Act: Underestimating compliance puts your SME at risk

> The AI Act regulation applies to any organization operating an artificial intelligence system, regardless of its size or business sector. Even an SME using standard software can be subject to these rules, with sanctions of up to 15 million euros or 3% of global turnover. Quickly assess your exposure.

- Tags: AI Act PME, conformité IA Europe PME, risques AI Act entreprises, obligations réglementaires IA PME, systèmes IA haut risque PME, diagnostic conformité AI Act, sanctions AI Act PME, outils IA cachés PME
- Main keyword: AI Act PME conformité

## Key points

- According to Eurostat 2024, 42% of European SMEs use AI without being aware of it.
- The AI Act is not based on company size but on the risk of the AI used.
- Tools such as CRMs with scoring, predictive accounting software, or recruitment ATS are concerned.
- Non-compliance with the regulation can lead to penalties of up to 15 million euros or 3% of global turnover.
- An express quiz allows you to identify in 2 minutes if your company is subject to the AI Act.
- The free compaia diagnostic offers an AI compliance check in less than 3 minutes.

## Introduction

Imagine receiving an official notification from the [AI Office](https://digital-strategy.ec.europa.eu/en/policies/european-approach-artificial-intelligence) signaling that your company is violating [Regulation (EU) 2024/1689](https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:32024R1689) on artificial intelligence. The reason? The use of a non-compliant AI system, integrated into a daily tool whose AI component you were unaware of. This scenario is not exceptional: according to [Eurostat (2024)](https://ec.europa.eu/eurostat/web/products-eurostat-news/-/ddn-20240515-1), 42% of European companies with more than 10 employees use at least one tool containing AI. Yet, many SME leaders still think that the AI Act does not concern them. This misconception is high-risk.

## Content

## Why thinking "this doesn't concern us" is a strategic error

The AI Act regulation entered into force in **August 2024** and its first requirements have been applicable since **February 2025**. Yet, according to [McKinsey 2025](https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai-in-2024), **68%** of SME executives underestimate the real impact of this text on their organization. Four misconceptions persist and can be costly: up to **15 million euros** or **3%** of global turnover, according to [Article 71](https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:32024R1689#art_71).

### Misconception #1: "Our company is too small to be targeted"

Many SME leaders imagine that only large corporations or tech players are concerned. In reality, size does not matter: it is the nature of the AI system and its risk level that take precedence. A micro-enterprise of 5 people using credit scoring is just as exposed as an international bank.

**Illustrations:**

- An online store with 3 employees adjusts its prices via a dynamic pricing tool using AI to analyze purchasing behaviors and predict trends. If this system strongly influences the prices of essential goods, it can be classified as "high risk" and subject the SME to strict obligations (documentation, risk assessment).
- An accounting firm of 10 people relies on AI-based cash flow forecasting software to anticipate financial difficulties. If this module guides major decisions (granting credit, payment deferrals), it may fall under the "high risk" category and require enhanced compliance.
- A real estate agency with 5 employees uses a CRM with AI scoring to estimate the probability of prospect purchases. If this scoring strongly influences commercial choices, the system may be considered "limited risk" and involve transparency obligations.

In all these cases, the size of the company does not change the application of the regulation. It is the use and risk level of the AI that determine the obligations. The sanctions themselves can jeopardize the very existence of the SME: up to 15 million euros or 3% of global turnover.

### Misconception #2: "We don't really use AI"

Many companies think they are not concerned because they have not developed AI in-house or do not use a chatbot. However, AI is often embedded in standard tools, without the user's knowledge. According to [Gartner 2024](https://www.gartner.com/en/newsroom/press-releases/2024-03-12-gartner-predicts-75-percent-of-enterprise-software-engineers-will-use-ai-coding-assistants-by-2028), **75%** of professional software will integrate some form of AI by **2028**, often invisibly.

**Frequent cases:**

- Accounting software with a cash flow forecasting module: AI analyzes past financial flows to anticipate difficulties. If this module guides financial decisions (credit, deferrals), it may be "high risk" and require strict compliance.
- A CRM with AI scoring: it estimates the probability of prospect conversion based on their history and interactions. If this scoring strongly guides commercial decisions, it may be "limited risk" and require transparency.
- An ATS (recruitment tool) with automatic CV sorting: AI analyzes and classifies applications. If the system rejects profiles without human intervention, it is "high risk" under the AI Act and requires detailed technical documentation and bias assessment.

In these situations, AI is used without the company being fully aware of it. And if these tools fall under "high risk," fines can climb up to 15 million euros or 3% of global turnover.

### Misconception #3: "My business sector is not concerned"

Some executives think that only technological or innovative sectors are targeted. This is false: the regulation applies to all fields as soon as an AI system is in place. An artisanal bakery using scheduling software with AI prediction or a recruitment agency using an automated ATS are just as concerned.

**Sector examples:**

- **Health**: a physiotherapy practice uses appointment management software with AI cancellation prediction. If this module influences scheduling, it may be "limited risk" and impose transparency obligations.
- **Retail**: a store adjusts its prices via an AI-based dynamic pricing tool. If this system strongly impacts the prices of essential products, it may be "high risk" and require strict compliance.
- **Construction**: an SME in the building sector uses project management software with AI delay prediction. If the module guides resource allocation or planning, it may fall under "high risk."
- **Catering**: a restaurant manages its inventory using an AI tool that anticipates sales. If this system drives purchasing, it may be "limited risk" and involve transparency obligations.

In all these cases, the sector matters little: it is the use of AI and its risk level that count. The sanctions remain identical: up to 15 million euros or 3% of global turnover.

### Misconception #4: "The AI Act only targets tech startups"

Many think that only companies developing AI are concerned. In reality, any company using an AI system, even one purchased, must comply with the regulation. An SME using purchased credit scoring is just as concerned as a startup developing its own model.

**Illustrations:**

- An electrician plans their interventions using AI software that predicts breakdowns. If this module influences prioritization, it may be "limited risk."
- A travel agency uses an AI recommendation engine to personalize destinations. If this system strongly guides customer choices, it may be "limited risk."
- A law firm uses AI legal research software to anticipate jurisprudential trends. If this module guides strategic decisions, it may be "high risk."

In these examples, these are not tech players, but the use of AI exposes them to the same obligations and sanctions.

## Quick test: is your company concerned by the AI Act?

Answer "yes" or "no" to the following questions. A single "yes" is enough to indicate that your company is likely concerned:

1. Do you use a tool that makes automated decisions based on data (e.g., CRM with scoring, automated recruitment, dynamic pricing)?
2. Do you have software that anticipates trends or behaviors (e.g., cash flow forecasting, predictive inventory management, scheduling with delay anticipation)?
3. Do you offer recommendations or personalized content via a tool (e.g., product suggestions, personalized training paths, HR with recommendations)?
4. Are some decision-making processes automated (e.g., recruitment automatically excluding candidates, credit scoring refusing requests, surveillance triggering alerts)?
5. Do you analyze images, videos, or voices to make decisions (e.g., facial recognition, medical image analysis, video surveillance with automatic detection)?

If you answered "yes" to at least one question, it is highly likely that the AI Act applies to your company. To precisely assess your exposure and obligations, use the [free compaia diagnostic](https://compaia.eu/diagnostic).

## What steps to take if your company is concerned?

Don't panic if you discover that the AI Act concerns you. Here are the steps to follow:

1. **Classify your AI systems**: identify whether they fall under "minimal risk," "limited risk," "high risk," or are prohibited. The [compaia diagnostic](https://compaia.eu/diagnostic) guides you through this classification.
2. **Determine your obligations** according to the risk level:
    - For minimal risk: no specific requirements, but documenting the use of AI is recommended.
    - For limited risk: obligation to inform users that they are interacting with an AI system.
    - For high risk: strict obligations, including technical documentation, risk assessment, AI governance, and declaration to competent authorities.
3. **Compile the required documentation** for high-risk systems, in accordance with [Annex IV](https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:32024R1689#annex_IV):
    - Description of the AI system and its purposes
    - Information on training data
    - Risk assessment and mitigation measures
    - Governance and monitoring procedures
4. **Implement AI governance**: designate an AI compliance officer and establish regular control and monitoring processes.
5. **Declare your high-risk AI systems** to competent authorities, such as the [AI Office](https://digital-strategy.ec.europa.eu/en/policies/ai-office).

To simplify these steps, [compaia](https://compaia.eu/assistant-vocal-ai-act) offers a complete platform:

- Quick classification of your AI systems via the [free diagnostic](https://compaia.eu/diagnostic)
- Automatic generation of technical documentation compliant with Annex IV
- Personalized support to structure AI governance
- Export of documentation in professional PDF, ready for an audit

## Calendar of main AI Act obligations

- **August 2024**: entry into force of the regulation
- **February 2025**: first applicable requirements
- **November 2, 2026**: transparency and watermarking obligations for generative AI ([Article 50](https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:32024R1689#art_71))
- **December 2, 2027**: obligations for high-risk AI listed in [Annex III](https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:32024R1689#annex_IV)
- **August 2, 2028**: obligations for AI integrated into regulated products

## Conclusion: the AI Act, constraint or lever for your SME?

The AI Act regulation is not just a restrictive text. It also represents an opportunity for SMEs wishing to distinguish themselves, build trust with their customers, and anticipate technological developments. Becoming compliant means:

- Protecting yourself against fines of up to 15 million euros or 3% of global turnover
- Reassuring your customers about the responsible and transparent management of AI
- Anticipating the generalization of AI in all sectors
- Accessing new markets where AI Act compliance is becoming a prerequisite

Rather than thinking "this doesn't concern us," ask yourself: "What if the AI Act was an opportunity for my company?" To find out, start with the [free compaia diagnostic](https://compaia.eu/diagnostic). In three minutes, you will know if your company is concerned and what actions to take.

> "Complying with the AI Act is investing in the sustainability of your company. You avoid sanctions, inspire confidence in your customers, and prepare for the future of responsible AI."
>
> - [compaia glossary](https://compaia.eu/glossaire)

## Official source
- [Source](https://www.aiacto.eu/fr/blog/ai-act-ca-ne-nous-concerne-pas-phrase-dangereuse-pme)
