Starting August 2, 2026, all SMEs using or developing AI systems must comply with the AI Act. This involves identifying their AI tools, assessing risks, meeting transparency obligations, and supervising AI usage, under penalty of financial sanctions.
In brief
- From August 2, 2026, SMEs must apply the obligations of the AI Act for all their high-risk AI systems and comply with transparency rules, whether they are users or developers.
August 2, 2026, marks the full entry into force of the European AI Act for high-risk artificial intelligence systems, as well as for transparency requirements. Contrary to popular belief, SMEs are not excluded: whether they develop or operate AI solutions, they must comply. This guide details the concrete steps to take to anticipate this regulatory obligation.
Why does the AI Act apply to SMEs too?
The AI Act (EU Regulation 2024/1689) is often associated with tech giants, but it applies to all economic actors, including small and medium-sized enterprises. Many SMEs underestimate the impact of this text, wrongly believing they are not targeted or that they still have time. However, ignoring these obligations could lead to major financial consequences.
The text enters into force for high-risk AI systems and transparency requirements on August 2, 2026. An SME that uses, for example, HR software integrating AI, a credit scoring tool, a customer service chatbot, or an automated recruitment system is considered a "deployer" under the regulation. The obligations therefore apply in full.
Understanding roles: provider or deployer?
The AI Act distinguishes between two main functions:
- **Provider**: A company that develops and places an AI system on the market.
- **Deployer**: An organization that uses an AI system in the course of its professional activity.
Most SMEs are deployers: they have not developed the AI model themselves but have subscribed to a SaaS, integrated an API, or added an AI module to their CRM. This does not exempt them from complying with the regulation. Article 26 specifies the obligations of this role.
Some SMEs are also providers, particularly if they develop and market software integrating AI. In this case, the requirements are heavier: technical documentation compliant with Annex IV, CE marking, and registration in the European database. This article primarily targets SME deployers.
1. Map all your AI systems
The first step toward compliance is to establish a precise inventory of all AI systems used in the company. It is impossible to be compliant with what you do not know!
Here are the main types of tools to identify:
- HR management software using sorting or evaluation algorithms (recruitment, performance)
- Customer relationship solutions integrating chatbots or generative AI
- Financial analysis or credit scoring systems
- Surveillance or employee activity analysis tools
- Any SaaS solution that mentions "AI," "machine learning," or "predictive" in its documentation
For each tool, note the following: provider name, purpose of the AI, types of data processed, and categories of affected persons.
2. Assess the risk level of each system
After listing your tools, it is essential to classify them according to the risk categories defined by the AI Act:
- **Unacceptable risk** (prohibited): generalized social scoring, subliminal manipulation, certain biometric uses
- **High risk** (Annex III): AI used for recruitment, HR management, access to essential services, or education
- **Limited risk**: chatbots, generative AI, deepfakes — transparency obligations (Article 50)
- **Minimal risk**: spam filters, content recommendations — no specific obligation
This classification determines the intensity of the measures to be implemented. For example, an automated CV screening tool falls under "high risk" (Annex III, section 4) and implies reinforced requirements.
3. Comply with deployer obligations for high-risk AI
If some of your systems are classified as high risk, Article 26 imposes several obligations on you:
- **Effective human oversight**: any important decision made by the AI must be reviewable, contestable, or correctable by a competent person, with real and not symbolic control.
- **Log archiving**: keep the logs generated by the AI system to ensure traceability, in accordance with the law, in the event of an audit or dispute.
- **Compliance with provider instructions**: only use the system within the framework provided by the supplier. If restrictions appear in the documentation, they must be followed to the letter.
- **Informing affected persons**: any person affected by a decision resulting from a high-risk AI system must be informed (see Article 50 and Article 26(6)).
- **Fundamental rights impact assessment** (Article 27): this analysis is mandatory for public actors and certain essential service operators. Check if your sector is concerned.
4. Ensure transparency for other AI systems
Even if none of your tools are high-risk, Article 50 imposes transparency obligations on all AI systems that interact with humans or produce content:
- A **chatbot** must clearly signal to the user that it is an AI.
- A **content generator** (text, image, video) must indicate that the production is generated by an AI.
- Any **voice synthesis** imitating a human voice must be explicitly signaled.
These rules apply from August 2, 2026, regardless of the system's risk level. Many SMEs still underestimate this requirement, which is nevertheless unavoidable.
5. Collaborate with your SaaS providers
As a deployer, it is your responsibility to verify the compliance of the tools you use. Here are the essential questions to ask your providers:
- Is the system considered high-risk under the AI Act?
- Do you have technical documentation compliant with Annex IV?
- What training data was used and how is it documented?
- What human oversight mechanisms are provided for clients?
- Are you registered in the European database for high-risk systems?
If a provider cannot answer these questions, they represent a non-compliance risk for your company. It is crucial to formalize these points in your contracts.
Sanctions for non-compliance
The AI Act's sanction regime is progressive and applies to all actors, including SMEs:
- Up to 35 million euros or 7% of global turnover for prohibited practices (Article 99(1))
- Up to 15 million euros or 3% of global turnover for non-compliance of high-risk systems
- Up to 7.5 million euros or 1% of global turnover for providing inaccurate information to authorities
Supervisory authorities must take into account the size and resources of SMEs in the application of sanctions, but no exemption is provided. Proportionality applies, but the obligation remains.
How to start the compliance process?
Good news: you do not need an internal legal department to get started. Here are three key actions to launch your compliance:
1. **Inventory**: list all your SaaS tools and check for AI features.
2. **Classification**: assess the risk level of each tool by referring to Annex III.
3. **Documentation**: start recording your decisions, supervision processes, and exchanges with your providers.
These steps can be completed in a few days and form the basis of a solid compliance file. In the event of an audit, they demonstrate your proactive approach before the August 2, 2026 deadline.
To simplify the process, the compaia AI Act diagnostic offers step-by-step guidance to classify your systems and automatically generate the first elements of your compliance file, adapted to your profile as a deployer or provider.