What does the EU AI Act require of small businesses?

Most SMEs are covered by the EU AI Act because they use AI, not because they build it. If your staff use ChatGPT, Microsoft Copilot, Google Gemini, or AI features built into everyday business software, your business is a deployer under the regulation.

The obligation that follows for almost every SME is AI literacy. The Act asks businesses to take measures supporting AI literacy among the staff who use AI on their behalf — proportionate to those staff’s technical knowledge, experience, and how the systems are used — and to be able to show it.

There is no minimum employee count, no revenue threshold, and no exemption for smaller organisations. A four-person consultancy using ChatGPT carries the same obligation as a 400-person firm using the same tool. What differs is what a proportionate response looks like, not whether the obligation applies.

Who the EU AI Act applies to

The Act divides responsibility between providers — organisations that develop AI systems or place them on the EU market — and deployers, which is anyone using an AI system under their own authority in a professional capacity. Provider obligations are extensive and technical; deployer obligations, for the systems most SMEs use, are considerably lighter. The vast majority of European SMEs are deployers only.

Three points catch businesses out. Buying software does not transfer the obligation — using a compliant tool does not make your business compliant, because the deployer obligation attaches to your use of the system, not to the system itself. There is no size threshold below which the AI literacy obligation stops applying. And it reaches beyond the EU: under Article 2(1)(c), the regulation applies to providers and deployers established outside the EU where the output produced by the AI system is used within the EU. A UK, Swiss, or US business whose AI-assisted outputs reach EU customers can be in scope regardless of where it is established.

Which obligations actually apply to your business

Not every part of the Act is relevant to every business. For a typical SME using off-the-shelf AI tools, the picture is narrower than the regulation’s length suggests.

AI literacy applies to virtually all SMEs using AI. It has been in force since 2 February 2025, with enforcement by national authorities from 2 August 2026, and is the obligation most SMEs need to address. Transparency obligations apply where you use AI to interact with people or generate content: individuals must be told when they are dealing with an AI system unless it is obvious, and certain AI-generated or manipulated content must be disclosed as such. These apply from 2 August 2026. High-risk obligations catch most SMEs only rarely, but are worth checking — the Act designates certain uses as high-risk, including AI used in recruitment and employee evaluation, access to education, and creditworthiness assessment. General-purpose AI model obligations attach to organisations that develop and place foundation models on the market, not to businesses using them, so they do not apply to most SMEs.

The dates that matter

The AI literacy obligation has applied since 2 February 2025. National authority enforcement powers, along with the transparency obligations, take effect from 2 August 2026 — the one genuine deadline on the horizon for most SMEs.

High-risk obligations have a longer runway than the rest of the Act. Under the AI Omnibus — now signed law, in force since July 2026 — the obligations for standalone Annex III systems are deferred to 2 December 2027, and to 2 August 2028 for AI embedded in products already covered by EU product-safety legislation. For the small number of SMEs whose use falls into a high-risk category, those are the dates that apply.

Last reviewed: 27 July 2026

What do you actually need to do?

The EU AI Act does not hand you a list of documents to produce. It sets an obligation and leaves implementation to each business, proportionate to size and context. That flexibility is genuinely helpful, and it is also why so many SMEs are unsure whether what they have done is enough.

The practical answer is that there is a clear difference between activity that resembles compliance and evidence that would survive scrutiny. A completed training course is activity. A record showing which AI tools your business uses, what your policy on their use is, which staff have been trained on what, and when that was last reviewed — that is evidence.

That difference becomes concrete the moment someone asks. For most businesses, the person who asks first is not a regulator but a customer: enterprise buyers and public sector bodies increasingly want suppliers to evidence their AI governance, often as a routine line in a vendor questionnaire alongside GDPR and information security. A business that can answer clears it in a day; a business that cannot delays the deal or loses it.

If you use AI to screen or shortlist job applicants, it is worth checking whether you fall into the high-risk category — the obligations there go beyond AI literacy.

Applicability

Does the EU AI Act apply to small businesses?

Why using AI tools puts your business in scope, what the deployer obligation actually asks of you, and why proportionality changes how you comply rather than whether you must.

Read the full guide →

UK Businesses

Does the EU AI Act apply to UK businesses?

How the Act reaches businesses established outside the EU, what the output-based test in Article 2(1)(c) means in practice, and how to work out whether your business meets it.

Read the full guide →

US Businesses

Does the EU AI Act apply to US businesses?

Why a US business with no EU office can still be in scope, what the output-based test in Article 2(1)(c) means in practice, and how it mirrors the GDPR reach US companies already know.

Read the full guide →

Documentation

What documentation does the EU AI Act require?

What the Act asks for, what it deliberately leaves open, and what separates documentation that would hold up under scrutiny from paperwork that would not.

Read the full guide →

Compliance

EU AI Act compliance checklist for SMEs

A step-by-step walkthrough of what to have in place, in what order, with what evidence behind each item.

View the checklist →

AI Tools Register

What is an AI tools register — and do I need one?

What belongs in a register, why it is the first thing to build, and how it underpins every other document you will need.

Read the full guide →

Get it done, and keep it done.

Generate your EU AI Act compliance documentation from your business’s actual AI use, then keep it current as your tools, your team and the rules change. Compliance is not a document you file once — it is a position you maintain.

Get started