Most small and medium-sized enterprises (SMEs) I talk to have 1 of 2 wrong beliefs about the EU AI Act: either that it does not touch them because they only use ChatGPT and a few AI features in their software, or that a €35 million fine is waiting for them on 2 August 2026. Neither is true, and the second one changed again this summer when the Digital Omnibus on AI was adopted.
I run +10 SaaS and AI companies from Barcelona with customers in 20+ countries, so I had to work out what the regulation actually requires of a normal company. Here it is, in plain language: who the Act applies to, the timeline as it stands on 18 September 2026, what the Omnibus moved, which risk category your uses fall into, what you must do now, and what the fines really look like for an SME.
Key takeaways
- The EU AI Act applies to any company that uses or sells AI systems in the EU, but for an SME that only uses AI tools the current duties are AI literacy for staff and transparency towards people, not the heavy high-risk paperwork.
- Prohibited practices and the AI literacy duty have applied since 2 February 2025, general-purpose AI model rules since 2 August 2025, and the transparency rules of Article 50 since 2 August 2026.
- The Digital Omnibus on AI, in force since 27 July 2026, moved the high-risk obligations from 2 August 2026 to 2 December 2027 for stand-alone systems and to 2 August 2028 for AI embedded in regulated products.
- Fines reach €35 million or 7% of turnover for banned practices, but for SMEs Article 99 applies whichever of the fixed amount or the percentage is lower, so a €5 million company faces a €350,000 ceiling on the top tier.
Does the EU AI Act apply to my SME?
Yes, if you place an AI system on the EU market or use one in your business in the EU, but what you must do depends on your role and on the risk level of each use, and for most SMEs the role is deployer, not provider.
The Act uses 2 main roles. A provider develops an AI system or model and puts it on the market under its own name. A deployer uses an AI system under its own authority for professional purposes. If your team uses Claude, ChatGPT, Gemini or Copilot to write, code, analyse and answer customers, you are a deployer of general-purpose systems. If you build a product with AI features and sell it, you are a provider for that product, and if that feature is high risk, the heavy obligations follow.
Size does not exempt you. The Act has SME provisions, mainly lighter fines and simplified documentation, but the rules apply to a 5-person agency in Girona as much as to a bank. What changes with size is the proportion, not the principle.
What is the EU AI Act timeline as of September 2026?
As of 18 September 2026 the bans, the AI literacy duty, the general-purpose AI model rules and the transparency rules are already in force, while the high-risk obligations have been postponed to December 2027 and August 2028.
This is the timeline published by the European Commission's AI Act Service Desk, updated for the Digital Omnibus on AI. I keep it pinned in every board folder.
- 1 August 2024: the AI Act enters into force.
- 2 February 2025: general provisions, the AI literacy duty (Article 4) and the prohibited practices (Article 5) apply.
- 2 August 2025: obligations for general-purpose AI model providers, governance structures, national authorities and penalty rules apply.
- 2 August 2026: the majority of the Act applies, including the transparency obligations of Article 50, and national enforcement starts.
- 2 December 2026: new prohibitions on nudifier apps and AI generating child abuse material, and the deadline for the watermarking grace period on systems already on the market.
- 2 August 2027: each member state must have at least 1 AI regulatory sandbox; general-purpose models placed on the market before August 2025 must comply.
- 2 December 2027: rules for stand-alone high-risk systems listed in Annex III apply.
- 2 August 2028: rules for high-risk AI embedded in regulated products under Annex I apply.
What did the Digital Omnibus change in 2026?
The Digital Omnibus on AI postponed the high-risk obligations by 16 and 24 months, gave a short grace period for watermarking AI-generated content, and softened the AI literacy duty from ensuring a level of literacy to supporting its development.
The European Commission proposed the Omnibus on 19 November 2025 because the technical standards companies need to comply with the high-risk rules were not ready. According to Freshfields and DLA Piper, the European Parliament endorsed the agreement on 16 June 2026, the Council gave its final approval on 29 June 2026, the text was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.
The substance, according to those same analyses: Annex III high-risk systems now apply from 2 December 2027; Annex I systems embedded in regulated products from 2 August 2028; the Article 50 duty to mark AI-generated content gets a grace period until 2 December 2026 for systems already on the market, while the duty to tell people they are talking to an AI stayed on 2 August 2026. For an SME the message is: you gained time on high-risk paperwork, you gained nothing on transparency.
What are the risk categories and where does a normal SME sit?
The Act sorts AI uses into 4 levels, prohibited, high risk, limited risk with transparency duties, and minimal risk, and a normal SME using AI tools sits almost entirely in the last 2 unless it uses AI to decide about people.
Prohibited practices, banned since February 2025, include manipulative systems that cause harm, social scoring by public authorities, untargeted scraping of faces for recognition databases and emotion recognition at work or school. No normal company does these on purpose, but check what your vendors' tools do with employee data.
High risk is the category that creates real work: AI used to recruit, evaluate or monitor workers, to score creditworthiness, to grade students, or as a safety component of a regulated product. If you deploy one of these, from December 2027 you must use it according to the provider's instructions, keep human oversight, keep logs, inform affected workers and, in some cases, run a fundamental rights impact assessment. Limited risk covers chatbots, AI-generated content and deepfakes: you must tell people. Everything else, from spam filters to code assistants, is minimal risk with no specific obligation beyond the literacy duty.
What must an SME using AI tools actually do now?
In September 2026 an SME that uses AI tools must do 5 things: train its staff, tell people when they interact with AI or AI-generated content, inventory its AI uses, check whether any use is high risk, and choose vendors that can document their systems.
This is the checklist I apply in my companies. None of it requires a lawyer to start, although one should review it once you find a high-risk use.
- AI literacy: give every employee who uses AI a short, documented training on what the tools do, their limits and your internal rules; a training record is your best evidence.
- Transparency: label customer-facing chatbots as AI, disclose AI-generated images, audio and video, and label deepfakes clearly, as Article 50 requires since 2 August 2026.
- Inventory: keep a simple register of every AI system in use, who owns it internally, what data it touches and what decisions it influences.
- Risk check: flag any use that touches hiring, promotion, monitoring, credit, insurance pricing or education, and start preparing the deployer duties due on 2 December 2027.
- Vendors: ask providers for their AI Act documentation, their data handling terms and whether their general-purpose models comply with the August 2025 obligations.
- Data protection: the AI Act does not replace the GDPR (General Data Protection Regulation), so keep running data protection impact assessments where personal data is involved.
What are the penalties for SMEs under the AI Act?
The AI Act sets 3 fine tiers, up to €35 million or 7% of worldwide turnover for prohibited practices, €15 million or 3% for most other breaches and €7.5 million or 1% for supplying incorrect information, and for SMEs and start-ups Article 99 applies whichever of the 2 figures is lower.
That last sentence is the one most articles skip. For large companies the higher amount applies. For an SME the ceiling is the lower one, so a company with €5 million in turnover faces a maximum of €350,000 for the worst tier and €150,000 for the middle tier, not €35 million. Article 99 also says fines must take into account the interests of SMEs, including start-ups, and their economic viability.
Enforcement is national and started on 2 August 2026, so the authority that knocks will be your member state's market surveillance authority, in Spain the Agencia Española de Supervisión de la Inteligencia Artificial. I expect the first years to focus on prohibited practices and missing transparency, the cheapest things to get right. Ignoring the Act is a risk; being paralysed by it is a bigger one.
For a normal SME the EU AI Act in September 2026 is a manageable list: train your people, be transparent about AI, know what you use, and treat any AI that decides about people as a project with a December 2027 deadline. The Digital Omnibus bought time for the heavy part and changed nothing for the everyday part. In my companies we did the inventory and the training first, because they cost days, not months, and they are what a regulator, a customer or an investor will ask to see. Do the same, and revisit the list before December 2026 and December 2027.
Frequently asked questions
- Did the EU AI Act high-risk rules apply on 2 August 2026?
- No. The Digital Omnibus on AI, in force since 27 July 2026, postponed the high-risk obligations to 2 December 2027 for stand-alone Annex III systems and to 2 August 2028 for AI embedded in regulated products. The transparency rules of Article 50 did apply on 2 August 2026 as planned.
- My company only uses ChatGPT and Copilot. What do I have to do?
- You are a deployer of general-purpose AI systems. Your current duties are to support AI literacy among staff, to tell people when they interact with an AI system or AI-generated content, and to check that none of your uses falls into a high-risk category such as recruitment or worker monitoring. Keep an inventory and a training record as evidence.
- What is the maximum fine for an SME under the AI Act?
- For SMEs and start-ups, Article 99 applies the lower of the fixed amount and the percentage of turnover. On the top tier of €35 million or 7%, a company with €5 million in turnover faces a maximum of €350,000. The middle tier is €15 million or 3%, and the tier for incorrect information is €7.5 million or 1%.
Sources
- 01European Commission AI Act Service Desk: Timeline of the implementation of the EU AI Act
- 02Freshfields: EU AI Act unpacked #34: The final Digital Omnibus on AI
- 03DLA Piper: The Digital AI Omnibus: deferral of high-risk AI obligations under the AI Act (update)
- 04EU Artificial Intelligence Act: Article 99: Penalties
- 05EU Artificial Intelligence Act: Article 50: Transparency obligations for providers and deployers of certain AI systems
- 06EU Artificial Intelligence Act: Article 4: AI literacy