Back to Insights
AI Act ·14 August 2026 ·11 min read

The EU AI Act for SMEs: what do you need to have in place right now?

Since 2 August 2026, the AI Act's transparency rules apply and enforcement has begun. The high-risk system rules have been postponed to 2027/2028, but AI literacy, banned practices and chatbot transparency already apply. A practical overview for SMEs — not legal advice.

Since 2 August 2026, a large part of the EU AI Act is in force — and being enforced. In practice that means: if you publish a chatbot, an AI assistant, or AI-generated content, you must inform your users about it, and the European Commission can now fine you for not doing so. The rules for high-risk AI systems, meanwhile, have been postponed this year — to December 2027 and August 2028. What you need to have in place right now is smaller than many SMEs assume, but it's not nothing: AI literacy among staff, avoiding banned practices, and transparency toward users.

This article lays out the timeline as it stands today, after the changes the EU made in 2026 through the so-called Digital Omnibus. It is not legal advice — the AI Act is complex enough that the precise classification of your AI application always deserves individual assessment. What you will get is a concrete picture of what already applies, what's still coming, and where the simplified regime for smaller companies sits.

The timeline so far

The AI Act entered into force on 1 August 2024, but its obligations have rolled out in phases since then. On 2 February 2025, the general provisions took effect: the definitions, the AI literacy obligation for staff (Article 4), and the ban on a set of AI practices (Article 5) — think social scoring and manipulative techniques that undermine people's behaviour without their awareness. On 2 August 2025, the rules for providers of general-purpose AI models (the large language models themselves) followed, and member states had to designate their supervisory authorities.

2 August 2026 — twelve days before this article's publication date — is when most of the remaining rules took effect and enforcement began for what already applied: general-purpose AI, banned practices, transparency and AI literacy. This is the moment the AI Act shifted from "law on paper" to "can actually get you fined" for most businesses.

What applies as of 2 August 2026: Article 50

The transparency obligations under Article 50 were not postponed and have applied in full since 2 August 2026. They come down to five requirements. Providers of chatbots and AI assistants must ensure users know they're communicating with AI, unless that's already obvious from the context. Providers of generative AI must mark AI-generated audio, image, video and text as machine-readable artificial content. Anyone deploying emotion recognition or biometric categorisation must inform the people involved. Anyone publishing deepfakes must make clear that the material was artificially generated or manipulated — with an exception for evidently creative, satirical or artistic work. And anyone publishing AI-generated text to inform the public on matters of public interest must disclose that, unless the text underwent human editorial review and carries editorial responsibility.

For an SME running a customer-service chatbot, or using AI to draft website copy, this is the obligation that becomes relevant first: a visible notice that the user is dealing with an AI system, and no hidden AI content presented as purely human work.

What's still postponed: high-risk AI

The most far-reaching part of the law — the requirements for high-risk AI systems under Annex III, such as AI used for recruitment, credit scoring, or access to essential services — was originally also set to take effect on 2 August 2026. Through the Digital Omnibus, finally approved by the Council of the EU on 29 June 2026, that date has been pushed to 2 December 2027: a sixteen-month extension. For high-risk AI embedded in regulated products (Annex I, think medical devices and machinery), the extension runs twelve months, to 2 August 2028.

Important: this is a delay, not a cancellation. And two other dates were not moved. On 2 December 2026, new bans take effect for AI generating non-consensual sexual deepfakes or child sexual abuse material, alongside a transition deadline for certain providers of synthetic-content systems already on the market before 2 August 2026. And on 2 August 2027, every member state must have at least one AI regulatory sandbox operational.

The new "small mid-cap" category

The Digital Omnibus also introduced a new company category between SME and large enterprise: the small mid-cap, defined as a company with fewer than 750 employees and less than €150 million in annual turnover. Companies in this category — and SMEs below it — gain access to simplified compliance documentation, targeted guidance, priority access to regulatory sandboxes, and in some cases lower fine ceilings. The obligations themselves don't disappear, but the administrative burden of meeting them shrinks as your company gets smaller.

What this means for an SME today

1. Make sure your staff is AI-literate. Article 4 requires providers and deployers of AI systems to have sufficient understanding of how those systems work, what their limitations are, and what risks they carry — proportionate to the context of use. That doesn't have to mean a weeks-long course, just demonstrable awareness among the people operating the AI day to day.

2. Check whether anything you do falls under banned practices. For most SME applications this is unlikely, but subliminal manipulation techniques, exploiting the vulnerabilities of specific groups, and certain forms of biometric categorisation have been on the ban list since February 2025.

3. Make AI use visible to your users. A chatbot that doesn't identify itself as AI, or a blog post that's entirely AI-generated without any disclosure, now falls under an enforceable transparency duty as of 2 August 2026.

4. Track whether your application might later become high-risk. Even though the deadline has moved to December 2027, the classification of your AI system doesn't change with the delay. Anyone using AI for, say, candidate screening or credit scoring would do well to inventory now whether that system falls under Annex III, so 2027 doesn't arrive as a surprise.

How this relates to the GDPR

The AI Act doesn't replace the GDPR — it sits on top of it. If your AI application processes personal data, both frameworks apply at once: the GDPR governs the processing of the data, the AI Act governs the system itself. We wrote a fuller guide on AI and the GDPR, including when a DPIA is required — a question that, for high-risk AI under the AI Act, often coincides with a GDPR obligation.

Frequently asked questions

Does this apply even if I only use off-the-shelf AI tools, like ChatGPT or a chatbot plugin? Yes. The obligations target both whoever provides the system and whoever deploys it ("deployer"). If you use an off-the-shelf tool to talk to customers, you're responsible for transparency toward your own users, even if the underlying technology comes from someone else.

Is there already enforcement in the Netherlands? The AI Act is an EU regulation with direct effect, but actual enforcement runs through nationally designated supervisory authorities. Exactly which authority that is in the Netherlands, and how actively it enforces, changes over time — check with a legal adviser or current government guidance if you're unsure.

Do I need to keep an AI register? For high-risk systems, some form of registration and documentation becomes mandatory once Annex III applies. For other AI applications, keeping your own overview of which AI systems you use, for what, and with what risks isn't a legal requirement yet, but it's practical preparation for both the AI Act and the GDPR.

Conclusion

As of 2 August 2026, the AI Act went from an announcement to an enforceable law — just not in the form many SMEs expected: the heavy high-risk obligations have been pushed to 2027 and 2028, while AI literacy, the ban on certain practices, and transparency toward users already apply and are already being enforced. For most smaller businesses, this year's task is manageable: make sure your AI is visible as AI, keep your staff informed, and track whether your application will later fall under the stricter rules. This article is meant to explain, not to advise — always get your situation checked by a lawyer before drawing conclusions about what specifically applies to your business.

Technology, not legal advice

Want your AI system's technical footprint clearly documented?

We build and document AI systems so the technical side — what the system does, with what data, with what controls — is clear on the table. Legal review we leave to your adviser; we make sure they're not working in the dark.