Skip to content
Back to blog
Compliance11 min read

EU AI Act Compliance for Small Business: A Plain-Language Guide (2026)

The EU AI Act's main obligations take effect in August 2026. A plain-language guide to what small businesses need to do, what carries real risk, and what can safely wait.

March 18, 2026
EU flag beside legal documents on a desk, illustrating EU AI Act compliance for small business

TL;DR: The EU AI Act's main obligations take effect in August 2026. For most small businesses the practical impact is limited, though not zero. This guide covers which provisions apply to typical SMB operations, what you need to document, what the penalties are, and where it is safe to wait. Plain English, written for people who run businesses rather than compliance teams.


The EU AI Act is the first law to regulate AI across the board. It entered into force in August 2024, and its obligations are rolling out in phases through 2026 and 2027. If your business operates in the EU, or sells to EU customers, parts of it apply to you.

Most of the coverage focuses on large enterprises and AI developers. Very little is written for the operations manager at a 50-person company who uses a few AI tools and wants to know what they actually have to do.

This guide fills that gap. It is written for small business operators.

Important disclaimer: This is educational content, not legal advice. For specific compliance questions affecting your business, consult a qualified legal professional familiar with AI regulation.

First: what the AI Act actually regulates

The AI Act is a risk-based framework. It regulates AI systems by the risk they pose, not by the technology they use. That matters, because it means:

  1. Most AI tools used by small businesses fall into low-risk or minimal-risk categories with minimal obligations.
  2. A small number of AI applications carry significant obligations regardless of company size.
  3. "We are a small company" is not a compliance exemption.

The Act sorts AI systems into four tiers:

Risk TierWhat It CoversYour Obligations
Unacceptable (banned)Social scoring, subliminal manipulation, real-time biometric surveillanceProhibited entirely
High riskHiring, credit scoring, healthcare, critical infrastructureConformity assessments, documentation, human oversight, registration
Limited riskChatbots, deepfakesTransparency: users must know they interact with AI
Minimal riskSpam filters, recommendations, most business automationNone under the Act

For most small businesses using AI on internal work like document processing, email drafting, scheduling, and reporting, you sit in the minimal risk tier with no specific obligations under the Act.

When it gets more complicated: are you a deployer?

The Act separates providers (companies that build AI systems) from deployers (companies that use them). Most small businesses are deployers.

As a deployer your obligations are lighter than a provider's, but they are real. Under the high-risk provisions, deployers must:

  • Use AI systems in line with the provider's instructions
  • Keep human oversight over AI decisions
  • Keep logs of high-risk AI system use
  • Report serious incidents to the relevant national authority

When does this apply to you? When you deploy an AI system that counts as high-risk. For small businesses, the high-risk categories that come up most often are:

  • Recruitment and HR: AI tools that screen CVs, schedule interviews, or evaluate candidates
  • Credit and financial assessment: AI tools that help judge the creditworthiness of clients or partners
  • Customer profiling: AI used to make consequential decisions about individual customers

If you use AI-assisted hiring, credit scoring, or automated customer profiling, check whether those tools are high-risk under the Act and whether your provider has done the required conformity assessments.

The transparency obligations that affect everyone

Even minimal-risk AI carries transparency obligations once it interacts with people:

Chatbots and AI assistants: If a chatbot on your site talks to customers, those customers have to be told they are dealing with an AI. It does not need to be in large letters, but it does need to be clear and shown before the conversation starts.

AI-generated content: Deepfakes and AI-generated synthetic media must be labelled. This covers marketing content, not only news media.

Emotion recognition: If you use systems that read emotional states (now common in customer-experience platforms), you have to disclose it.

For most SMBs the practical step is simple: label any customer-facing AI clearly as AI-assisted or AI-generated.

The August 2026 milestone

Two sets of obligations become fully enforceable in August 2026:

  1. Prohibited AI practices. The ban on unacceptable-risk systems takes full effect. Most businesses are nowhere near this line. Still, it is worth checking whether any tool you use makes fully automated decisions about individuals in ways they cannot contest.

  2. General-purpose AI model obligations. If you call large foundation models directly through an API in customer-facing products, the Act's GPAI provisions apply. They cover technical documentation, transparency about training data, and copyright compliance.

If you reach those models through a third-party platform instead, such as a no-code tool or a SaaS product, the platform provider carries these obligations rather than you.

A practical compliance checklist for SMBs

Here is what a small business should actually do.

Do now:

  • Audit which AI tools you currently use and which risk category each falls into
  • Make sure any customer-facing chatbots are labelled as AI
  • Ask your HR software vendor whether their AI features meet the Act's high-risk HR provisions
  • Keep a simple log of the AI systems running in your business (tool name, use case, decision type)

Review by August 2026:

  • If you use AI in hiring, credit assessment, or customer profiling: confirm provider compliance and put human oversight in place
  • If you call AI through an API for customer-facing features: confirm your provider meets the GPAI obligations
  • Give one person ownership of AI compliance. It does not have to be a dedicated role, but someone should have oversight.

Can wait:

  • A full AI governance policy (required only for high-risk deployers and providers)
  • External audits (required only for high-risk AI systems)
  • Employee AI training programmes (useful, but not yet mandatory for low-risk deployers)

What the penalties look like

Enforcement sits with national authorities (in Poland: UODO; in Germany: BfDI; in the UK: the ICO since Brexit). The fines under the Act:

  • Banned (prohibited) practices: up to €35 million or 7% of annual global turnover
  • High-risk non-compliance: up to €15 million or 3% of turnover
  • Giving incorrect information to authorities: up to €7.5 million or 1.5% of turnover

These ceilings are aimed at large companies. The regulation tells enforcement authorities to weigh company size and treat SMBs proportionately. Being small is not immunity, though. It counts as a mitigating factor, nothing more.

The practical read for most small businesses

If you run a service business and use AI for internal work such as drafting documents, processing data, summarising information, and automating reports, your obligations under the Act are minimal today:

  1. Do not run any AI that makes fully automated decisions about individuals without human review
  2. Label any customer-facing AI
  3. Keep a simple record of which AI tools you use and why
  4. Make sure any AI-assisted HR tools come from providers who have completed compliance assessments

That is a morning's work, not a compliance programme.

If you use AI in hiring, credit decisions, or customer profiling, or if you build and sell AI-powered products, your obligations are heavier and deserve proper legal advice.

Where this fits with what we do

Compliance is one of the six areas we work across at Runproven AI, alongside AI products, automation, infrastructure, reliability, and content. It is not a side note for us. When we built dopomo.pl, our own multilingual AI assistant for migrants in Poland, we ran a formal EU AI Act assessment (it came out as not high-risk), completed a DPIA, kept records of processing, and built in an in-chat AI disclosure plus data-subject rights including erasure. We held that work to the same standard we apply to client projects.

The rules in this area shift every few months, and keeping up with them is part of what an ongoing AI partner does. If you want to know exactly where your current AI stack sits under the Act, and what you specifically need to do before August 2026, an advisory session gives you a clear, practical picture. You can also book a call to talk it through.


Related reading: What Is Agentic AI and Why It Matters for Business | Fractional Chief AI Officer: What It Is and Who Needs One

We use cookieless analytics by default. With your consent we also load advertising cookies (Google Ads, LinkedIn, Meta) for conversion measurement. You can change your mind at any time. Learn more in our Privacy Policy