EU AI Act 2026: The Guide for SMEs | Adaptive Operations

Since February 2025, the first provisions of the EU AI Act have been in effect. Additional obligations followed in August 2025, and by August 2026, the majority of the regulation will be enforced - including significant fines. This doesn't just affect the big tech companies. It affects you if your company uses AI systems. And yes, ChatGPT in customer service or an AI tool in accounting counts.
I've spoken with dozens of mid-sized business owners about this topic in recent months. The results are sobering: most know there's "something about AI regulation" out there. Very few know exactly what's coming. And almost nobody has a concrete plan for dealing with it.
That needs to change. And now - not in six months.
What the EU AI Act Actually Is
The EU AI Act is the world's first comprehensive AI regulation. Similar to the GDPR a few years ago, it establishes a regulatory framework that applies to anyone who develops, distributes, or deploys AI systems in the EU. And just like with the GDPR, smaller companies are massively underestimating what this means for their daily operations.
The basic idea is a risk-based approach: the higher the risk an AI system poses to fundamental rights and safety, the stricter the requirements. That sounds reasonable at first. In practice, however, it means you as a company first need to understand which of your AI applications fall into which risk category - and what follows from that.
The Risk Categories - Simply Explained
The EU AI Act divides AI systems into four risk levels. Here's what each concretely means:
Unacceptable Risk (Prohibited)
Certain AI applications are simply banned. These include:
- Social scoring by authorities (as in China)
- Real-time biometric surveillance in public spaces (with narrow exceptions for law enforcement)
- AI systems that manipulatively influence human behavior
- Emotion recognition in the workplace and educational institutions
For most SMEs, this category is largely irrelevant - but check anyway whether you're inadvertently straying into this territory. Some analytics tools that track employee behavior can be borderline.
High Risk
This is the category that brings the most obligations and affects many companies without them realizing it. High-risk AI systems include:
- AI in personnel recruitment and evaluation (application screening, performance assessment)
- AI in creditworthiness assessment and insurance
- AI in critical infrastructure (energy, water, transportation)
- AI in education (grading exams, access decisions)
- AI in law enforcement and border control
- AI in medical diagnostics
If you use an AI tool that automatically pre-sorts applications or prepares credit decisions, you're in the high-risk category. That means: extensive documentation obligations, risk management, human oversight, transparency toward affected individuals, and regular reviews.
Limited Risk (Transparency Obligations)
This is primarily about chatbots, deepfakes, and generative AI. The obligation: you must disclose that an AI system is in use. If your customer speaks with a chatbot, they must know they're talking to a machine. If you publish AI-generated content, it must be labeled as such.
This affects practically every company that uses chatbots, AI-powered text generation, or image generation.
Minimal Risk
Simple AI applications like spam filters, recommendation systems in online shops, or AI-powered search functions fall under minimal risk and are largely unregulated. You don't need to do anything special here - but showing transparency never hurts.
What the AI Act Concretely Requires of You
Now it gets practical. Depending on the risk category, you need to do the following:
For High-Risk Systems
-
Establish a risk management system. You need a documented process that identifies, assesses, and mitigates the risks of your AI system. It doesn't need to be a monstrous framework, but it must exist and be verifiable.
-
Ensure data governance. The training and input data of your AI system must meet certain quality criteria. You must document where the data comes from and how you ensure it isn't discriminatory or flawed.
-
Create technical documentation. A comprehensive description of your AI system: what does it do, how does it work, what data does it use, what risks exist, what measures have you taken?
-
Logging and traceability. Your system must be able to log its decisions so they can be reviewed after the fact.
-
Ensure human oversight. There must always be a human who monitors the system and can intervene if needed. Fully autonomous decisions in high-risk areas are not permitted.
-
Transparency toward affected individuals. People affected by an AI decision (applicants, borrowers, etc.) must be informed about it.
-
Registration in the EU database. High-risk systems must be registered in a public EU database.
For Transparency-Required Systems
- Users must know they're interacting with an AI system
- AI-generated content must be labeled as such
- For deepfakes: clear labeling as artificially generated
For Providers of General Purpose AI (GPAI)
If you use models like GPT, Claude, or Mistral in your products, there are specific obligations here too. You must document which model you use and ensure you meet transparency requirements. The main burden falls on the model providers, but as a "deployer" you share responsibility.
The Timeline - What Applies When
The tricky part of the EU AI Act is the staggered timeline. Not everything takes effect on the same date:
- Since February 2025: Prohibitions on AI systems with unacceptable risk are already in effect.
- Since August 2025: Governance rules and obligations for GPAI providers are in force.
- From August 2026: The majority of the regulation will be enforced, including all obligations for high-risk systems.
- From August 2027: Additional obligations for certain high-risk systems in the area of critical infrastructure.
This means: depending on the category, you still have a few months to just over a year. But anyone who's only starting to think about it now will find it very tight.
What Happens If You Do Nothing
The fines are tiered and, like the GDPR, oriented toward revenue:
- Prohibited AI practices: Up to 35 million euros or 7 percent of global annual revenue
- Violations of high-risk obligations: Up to 15 million euros or 3 percent of revenue
- False information to authorities: Up to 7.5 million euros or 1.5 percent of revenue
There are reduced fine caps for SMEs - but "reduced" doesn't mean "painless." And beyond financial penalties, there are reputational damages and, in the worst case, prohibition from continuing to operate certain AI systems.
My advice: don't treat this as a compliance topic you can push to 2027. Treat it like the GDPR in 2018 - those who were late paid the price.
Your 7-Step Plan for the EU AI Act
Here's a pragmatic roadmap that works for mid-sized companies without requiring an army of lawyers.
Step 1: Create an AI Inventory
Take stock of all AI systems in your company. And I mean truly all of them - including the ones employees use on their own (shadow AI). Create a list including:
- Name of the tool or system
- Purpose and affected individuals
- Type of data processed
- Provider and contractual basis
You'll be surprised how many AI systems are already in use that you didn't know about.
Step 2: Assign Risk Categories
Go through your list and assign each system to a risk category. When in doubt, classify one level higher - that's cheaper than one level too low.
Step 3: Conduct a Gap Analysis
Compare the current state with the AI Act requirements. Where is documentation missing? Where is human oversight missing? Where is transparency toward affected individuals missing?
Step 4: Clarify Responsibilities
Determine who in the company is responsible for AI Act compliance. This could be the data protection officer (a natural fit given the significant overlap with GDPR), or it could be a dedicated role. The important thing is that it doesn't hang in the air.
Step 5: Build Documentation
Start with high-risk systems and work your way down. Technical documentation is the most labor-intensive part - but also the most valuable because it forces you to truly understand your AI systems.
Step 6: Implement Processes
Set up the required processes: risk management, human oversight, monitoring, complaint management. It doesn't need to be perfect - it needs to exist and function.
Step 7: Training and Awareness
All employees who work with AI systems need a basic understanding of compliance requirements. Not at the legal detail level, but enough to know what they may do, what they may not, and who to contact with questions.
Three Mistakes You Should Avoid
Mistake 1: Wait and hope. The GDPR showed: those who hope the regulation won't be enforced strictly are wrong. Supervisory authorities have learned from the GDPR introduction and will strike faster with the AI Act.
Mistake 2: Solve it solely with the legal department. The AI Act is not a purely legal topic. It requires technical understanding, organizational changes, and collaboration between IT, business units, and legal. If you leave it only to the lawyers, you get paper - but not real compliance.
Mistake 3: Ban every AI tool. Some companies respond to uncertainty with a total ban. That's counterproductive: you lose productivity advantages, encourage shadow AI, and end up without compliance anyway because your employees continue using the tools secretly.
Conclusion
The EU AI Act is not a recommendation, not a guideline, and not a nice-to-have. It's binding law with hard enforcement mechanisms and significant fines. For SMEs, the good news is: the vast majority of obligations are manageable - if you start now.
The biggest mistake you can make is to wait. Not because the fine notices are coming tomorrow, but because building compliance takes time. Documentation doesn't write itself overnight, processes need to be established, employees need to be trained.
Start today. Create your AI inventory, assign risk categories, identify the biggest gaps. The rest follows step by step.
Companies that see the AI Act as an opportunity - as a reason to professionalize their AI use and make it responsible - will ultimately be better positioned than those who only do the minimum to avoid penalties.
FAQ
Does the EU AI Act also apply to companies that only use AI and don't develop it themselves? Yes, absolutely. The AI Act distinguishes between providers who develop AI systems and deployers who use them. Both have obligations - though different ones. If you use ChatGPT, an AI recruiting tool, or automated credit scoring, you're a deployer and must fulfill the corresponding obligations.
We're a small company with 30 employees - does this even affect us? Yes, company size fundamentally doesn't matter. What's relevant is whether and how you use AI systems. There are some concessions for SMEs on fines and certain documentation requirements - but you're not exempt from basic obligations. The question isn't whether, but to what extent the Act affects you.
Where can I find support without spending a fortune on consultants? Chambers of commerce are increasingly offering information events and initial consultations. The EU Commission has published guidelines specifically tailored to SMEs. Industry associations also provide orientation guides. Start with these free resources and only bring in external help for the points where you're truly stuck.
How does the AI Act relate to the GDPR - do I need to be compliant with both? The two regulations complement each other but also overlap significantly. If you're already GDPR-compliant, you have a solid foundation: records of processing activities, data protection impact assessments, data subject rights - much of this transfers to AI Act requirements. You're not starting from zero. But there are also new obligations that go beyond the GDPR, particularly for high-risk systems.
What about AI tools we only use internally - does the AI Act apply there too? Yes. The AI Act doesn't distinguish based on whether you use an AI system internally or externally. If you use an AI tool that automatically evaluates applications - even only internally for your own positions - that falls under the high-risk category. What matters is the application and the risk to affected individuals, not whether the system is visible externally.

Mario Lohe
General Manager with 15+ years of experience in business operations, agile transformation, and AI enablement. Former Director of Operations at Havas Creative Group, Head of Operations at Audiencly. Certified: CSPO, CSM, ISO 31000, Systemic Coach (DCA).
Verwandte Artikel

Ops Trends 2026: What Stays After the Hype? | Adaptive Operations
Five operations trends for 2026 put to the reality test: from AI-augmented decisions to platform engineering. What works, what's hot air? Read now.

AI Agents for SMEs: Hype or Real Opportunity? | Adaptive Operations
AI agents in SMEs: where they really work, what they cost, and when deployment pays off. Practical analysis for HR, finance, marketing, and operations. Read the analysis now.

No AI Team? Why AI Literacy for Everyone Is Better | Adaptive Operations
Why a dedicated AI team is often the wrong approach — and how to build AI literacy across your company. With a 5-step plan and practical examples. Read the guide now.

