Practical guide
EU AI Act for Small Businesses: What Applies Now
A practical guide to EU AI Act scope, risk classification, current deadlines, and the first actions an SME should take when it uses AI.
Key takeaways
- The EU AI Act entered into force in 2024, but its duties apply in stages. Prohibited-practice rules have applied since 2 February 2025, and Article 50 transparency duties since 2 August 2026.
- Most obligations for Annex III high-risk systems now apply from 2 December 2027. Annex I high-risk obligations follow on 2 August 2028.
- Your legal role and intended use matter. Buying an AI tool does not automatically make every use high-risk, and serving an EU customer does not automatically make a non-EU business a deployer.
- Recruitment, worker management, creditworthiness, and some essential-service uses need careful Annex III analysis. Article 6(3) contains limited exceptions, but profiling of people remains high-risk.
- Start with an AI inventory, then record scope, role, intended purpose, risk classification, and applicable date for each system.
The EU AI Act is not one deadline and it does not classify an entire business as “high-risk.” It regulates particular AI systems and practices, with obligations that depend on where the system is used, your role, and its intended purpose.
For a small business, the useful question is not “Do we use AI?” It is: “What role do we have for this system, what do we use it for, and which rules apply now?”
Is your business in scope?
Article 2 of Regulation (EU) 2024/1689 covers, among others:
- providers that place an AI system or general-purpose AI model on the EU market, even when established outside the EU;
- deployers established or located in the EU; and
- providers and deployers outside the EU where the output produced by the system is used in the EU.
A provider develops or markets a system under its name. A deployer uses one under its authority in a professional activity.
An EU-based company using an AI recruitment tool will usually be a deployer. A company outside the EU needs a closer scope analysis: having EU customers alone is not the statutory test. For example, output from a system used to make decisions in the EU may bring the use into scope, but a general marketing tool used wholly outside the EU is not automatically covered merely because an EU resident sees the result.
Changing or rebranding a system can alter your role, so do not rely only on the vendor's description.
The dates SMEs need to know
The Act entered into force on 1 August 2024, but application is phased. Following Regulation (EU) 2026/1744, the practical timeline is:
| Date | What applies | |---|---| | 2 February 2025 | Article 5 prohibited practices and Article 4 AI-literacy duties | | 2 August 2026 | Article 50 transparency obligations and most other generally applicable provisions | | 2 December 2027 | Chapter III, Sections 1–3 for Annex III high-risk systems | | 2 August 2028 | Chapter III, Sections 1–3 for Annex I high-risk systems |
A recruitment system may need classification now, and GDPR or employment law may already apply, while the main AI Act duties for an Annex III system generally begin on 2 December 2027. Inventory and procurement work still take time.
A practical four-part classification
The familiar “four risk tiers” are a useful working model, although the Act does not present every system as a simple four-level score.
1. Prohibited practices
Article 5 prohibits specific practices, not AI generally. SME-relevant examples can include emotion inference in workplaces, except for narrow medical or safety reasons; certain manipulative or exploitative practices; and prohibited forms of social scoring.
These rules already apply. If a tool may infer emotion from employee video, voice, or messages, pause the use and obtain specialist advice rather than treating it as an ordinary HR feature.
2. Potentially high-risk systems
Article 6 and Annex III identify uses that may be high-risk. Common SME examples include AI intended to:
- recruit or select candidates, place targeted job advertisements, filter applications, or evaluate candidates;
- make decisions affecting work relationships, promotion, termination, task allocation, or worker monitoring;
- assess creditworthiness, except for fraud detection; or
- evaluate access to certain essential private or public services.
The intended purpose and how you actually deploy the tool control the analysis. A recruitment platform is not high-risk in every configuration, and a general-purpose chatbot does not become high-risk merely because HR owns the subscription.
Article 6(3) can exclude some Annex III systems that perform narrow procedural, preparatory, or pattern-detection tasks and do not pose a significant risk of harm. That exception is fact-specific, must be documented by the provider, and does not apply where the system profiles natural persons.
3. Article 50 transparency uses
Article 50 duties apply to particular functions, regardless of a general “limited-risk” label. Since 2 August 2026:
- providers must generally design systems intended to interact directly with people so those people are informed they are interacting with AI, unless that is obvious;
- deployers of emotion-recognition or biometric-categorisation systems must inform exposed people, subject to the Act's exceptions; and
- deployers must disclose deepfakes and certain AI-generated or manipulated text published to inform the public on matters of public interest.
The Act does not require a blanket label on every piece of AI-assisted business writing. For customer chatbots, coordinate with the provider and put a clear disclosure at or before the first interaction.
4. Other AI systems
Many internal drafting, summarisation, spam-filtering, and productivity uses fall outside those categories. Other law still applies: personal data can trigger GDPR, and confidential or inaccurate output creates ordinary business risk.
What to do first
1. Build an inventory
Include standalone tools and AI embedded in software you already use: applicant tracking, CRM scoring, helpdesk routing, transcription, accounting, and workplace monitoring. The AI Governance Checklist provides a broader inventory process.
For each system, record the owner, vendor, users, data entered, output, affected people, and business decision it supports.
2. Record scope and role
Record why the system is or is not in EU scope, your role, and where its output is used.
3. Test the intended use
Classify the particular use, not the product name. Test Article 5, Article 6, Annex I, Annex III, and Article 50. Ask for the vendor's reasoning, but record your own deployment. Put that check into your AI tool approval process.
4. Act according to the result and date
- Possible prohibited practice: stop and escalate now.
- Article 50 use: implement the relevant disclosure now; the AI disclosure guide explains the operational choice separately from jurisdiction-specific law.
- Potential Annex III high-risk use: document the classification, check the Article 6(3) analysis, obtain provider evidence, and plan for the 2 December 2027 duties.
- Other use: record why it falls outside those categories and review when the vendor or purpose changes.
5. Run the GDPR analysis separately
Where personal data is involved, record the processing and lawful basis, review processor terms, and assess whether a Data Protection Impact Assessment is required. EU GDPR Article 22 may apply to solely automated decisions with legal or similarly significant effects. AI Act classification does not replace that analysis.
A small-business example
Consider a 20-person consultancy:
| Use | Initial screen | Immediate action | |---|---|---| | ChatGPT drafts internal meeting summaries | Other AI use; GDPR may apply if prompts contain personal data | Set input rules and record the vendor review | | Applicant tool ranks CVs for a hiring shortlist | Potential Annex III employment use | Confirm intended purpose, provider classification, Article 6(3) position, and meaningful human oversight | | Website support chatbot | Article 50 interaction duty may apply | Confirm the provider feature and display a clear first-interaction notice | | Tool claims to infer employee emotion from calls | Potential Article 5 prohibition | Stop and obtain specialist advice |
The table is a screening result, not a final legal classification. The facts of the deployment decide the outcome.
Where to start
The EU AI Act Risk Classification Worksheet records scope, role, prohibited-practice screening, Annex III classification, the Article 6(3) test, Article 50 duties, and the applicable date. The EU Pro Pack also includes a GDPR AI Data Processing Register and DPIA Trigger Checklist for the separate data-protection analysis.
If you first need a jurisdiction-neutral inventory and internal rules, the AI Governance Starter Pack provides the foundation. You can also use the free AI Risk Checklist for an operational risk screen; it is not an EU AI Act classification.
This article describes the EU AI Act and related GDPR issues in plain language for SME owners. It is not legal advice, a conformity assessment, or a guarantee of compliance. Scope and obligations depend on the system, role, intended purpose, sector, location, and facts. Obtain qualified advice for a potentially prohibited or high-risk use.