Key Findings:
The EU AI Act for SMEs is already partially in force. Prohibitions have been in effect since February 2025, but the main high-risk rules were delayed – after the Digital Omnibus they now land on December 2, 2027 (Annex III systems) and August 2, 2028 (Annex I embedded systems), not August 2026.
Your first compliance decision is whether you are a provider (you build or brand the AI) or a user (you professionally use AI systems from others). The duty sets differ significantly.
The Digital Omnibus on AI – provisionally agreed May 7, 2026, formally adopted by the Council on June 29, 2026, and in force since July 27, 2026 – delayed the main high-risk deadlines by roughly 16 months and added SME simplifications. It changed nothing about the prohibitions or transparency obligations for general-purpose AI.
Penalty caps reach 35 million euros or 7% of global annual turnover for the most severe violations under Article 99, with reduced caps for SMEs. Reduced does not mean symbolic.
Close documentation gaps in your single high-risk system on a limited budget first. Broad compliance theater across all tools costs more and protects less.
Most SME owners I speak with in September 2026 fall into two camps. The first assumes the EU AI Act was delayed and they will deal with it next year. The second falls into quiet panic because a consultant just made a five-figure retainer offer for a chatbot and a resume screener. Both pictures are wrong – but for opposite reasons than you might expect. The AI Act is not on ice, but the timeline has actually shifted: the Digital Omnibus finalized in July 2026 delayed the main high-risk deadlines to December 2027 and August 2028. That is real breathing room, not myth – but prohibitions and transparency obligations never shifted, and "we have more time" is not the same as "we can ignore this." This post goes through what applies now, what actually changed this year, and where to spend limited budget addressing real risks instead of paperwork for its own sake.
The EU AI Act in Simple Terms for SMEs
Regulation (EU) 2024/1689 is the world's first comprehensive AI law. It regulates AI systems by risk category, not by company size. Small and medium enterprises have the same core obligations as large corporations when operating the same system category – penalty caps and some procedural burdens are the only things that get lighter.
Provider vs. User: The Distinction That Changes Everything
A provider is any organization that develops or has developed an AI system and places it on the EU market under its own name. Users are something different: you use an AI system in a professional context, not for personal, non-professional use.
The two roles lead to very different duties. Providers are responsible for technical documentation, conformity assessment, and CE marking. Users are on the operational side – correct system use, monitoring, keeping logs, ensuring human oversight, and notifying affected people when an AI-driven specific decision is made.
The practical test for an SME is short. Did you build or brand this AI? You're a provider. Are you simply using another company's tool in your business? User. Buy a CV screening SaaS and use it as sold, and you're a user. Take an open-source model, fine-tune it with your candidate data, give it your brand, and you become a provider with the full documentation duty set.
Why Size Affects Penalty Caps but Not Rules
Article 99 of the EU AI Act as published in the Official Journal sets penalty caps up to 35 million euros or 7% of global annual turnover for violations of prohibited AI, whichever is higher. SMEs and start-ups get the lower of the two amounts instead. That limits risk meaningfully. It creates no exemption. A ten-person recruitment firm operating an automated resume screener has the same high-risk duty set as a Fortune 500 staffing platform, just with a smaller penalty cap.
According to statements from the EU Council and European Parliament press office, the Digital Omnibus shifted certain high-risk implementation deadlines, streamlined some documentation obligations for SMEs, and left prohibitions and transparency obligations for general-purpose AI unchanged. That last point matters. If you assumed the shift covers everything, it did not.
Risk Categories: Where Your AI Tools Actually Land
Four risk bands: prohibited, high-risk, limited risk, and minimal risk. Where a system lands determines the rules, not who made it.
Prohibited practices have been in effect across the union since February 2, 2025. These include social scoring by public authorities, real-time remote biometric identification in public space by law enforcement (with narrow exceptions), indiscriminate scraping of facial images for recognition databases, and manipulative AI that exploits vulnerabilities. Most SMEs will never deal with these categories. Any tool with behavioral profiling, biometric matching, or workplace emotion recognition should still be checked against the EU AI Office guidelines.
High-risk AI systems are where most SME compliance work will ultimately concentrate – but the clock on this just shifted. Annex III of the Act lists the affected sectors: hiring and employee management, access to essential private and public services (including credit scoring), education, safety components of regulated products, migration and border control, and administration of justice. If you use AI to assess job applicants, decide who gets a loan, or embed AI in a machine that already has CE marking, you definitely fall within scope – you now just have until December 2, 2027 (for standalone Annex III systems) or August 2, 2028 (for AI embedded in regulated products under Annex I, such as machines or medical devices) to be ready, not August 2026.
Limited-risk systems carry only transparency obligations. Chatbots must disclose they are AI. Deepfakes and synthetic media need labeling – this deadline also shifted under the Omnibus, from August to December 2, 2026. Emotion recognition systems in the workplace trigger disclosure obligations to affected employees.
Minimal-risk systems cover spam filters, AI in video games, inventory forecasting, and the vast majority of ordinary business software. No specific AI Act obligations apply except voluntary codes of conduct.
A quick example: You run a photo studio and use generative fill-in in Adobe? Minimal risk. You use an AI resume screener to rank candidates for interview? You are a user of a high-risk system, and the following rules are yours.
EU AI Act Compliance Obligations 2026 for High-Risk Systems
For high-risk AI systems, the Act sets a defined duty set that came into force for most obligations on August 2, 2026, with staggered dates for systems embedded in regulated products. Chapter III of the Official Journal is the authoritative source.
Providers must establish a risk management system running across the entire lifecycle – documented risk identification, risk mitigation, and residual risk analysis, updated whenever the system changes materially. Data governance rules require training, validation, and test datasets to be relevant, adequately representative, and as far as feasible error-free. Technical documentation must be comprehensive enough for a national authority to audit the system on request.
Users get a narrower but real duty set. You must use the system according to the provider's instructions. You must assign human oversight to a competent, trained, and authorized person who can intervene. Auto-generated logs must be kept where the system creates them. In some cases you must conduct a fundamental rights impact assessment before deploying the system, especially in the public sector and for credit and insurance use cases.
What Meaningful Human Oversight Actually Means
Regulators are not looking for a person to rubber-stamp AI outputs. They want documented evidence that a named person understands the system's outputs, can override them, and decide not to use the system in a given case. In practice that means a written oversight procedure, a job description for the oversight owner, training materials, and audit logs showing when overrides were exercised. A single Google Doc kept current beats a polished folder that has not been opened since deployment.
CE Marking and EU Database Registration
Providers of high-risk AI systems must affix a CE mark and register the system in the EU AI database managed by the Commission before placing it on the market. Users of public high-risk AI systems must also register their use in the database, though private users generally do not.
What the 2026 Digital Omnibus Actually Changed
The Omnibus package went through a longer path than a single announcement: provisional political agreement May 7, 2026, European Parliament approval June 16, 2026, final green light from Council June 29, 2026, Official Journal publication July 24, 2026, and entry into force July 27, 2026. It was consistently presented as a competitiveness measure, not a rollback. Four shifts matter for SMEs.
Deadlines shifted by more than a "minor adjustment" Standalone high-risk systems under Annex III now have until December 2, 2027 – a 16-month shift from the original August 2, 2026 date. High-risk AI embedded in regulated products under Annex I gets until August 2, 2028. Watermarking and synthetic content disclosure obligations shifted from August to December 2, 2026. GPAI transparency obligations were not delayed and continue to apply from August 2025 for new models and August 2027 for existing ones, exactly as in the original text.
New prohibitions were added, not just delays. The Omnibus introduced new prohibitions on non-consensual AI-generated intimate imagery and child sexual abuse material – additions to Article 5, not weakening.
SME-specific simplifications. The amended text introduced lighter technical documentation templates for micro and small enterprises, allowed simplified conformity assessment routes where a harmonized standard exists, and confirmed priority access for SMEs to national regulatory sandboxes.
What did not change. Prohibitions remained in force from February 2025. GPAI model transparency obligations, including training content summaries, remained on track. Article 99 penalty caps were not reduced.
The trap for SMEs is treating the Omnibus as a blanket grace period. It is not. If your business operates a scoped high-risk system, your core obligations are live and your penalties are real. What changes is the amount of paperwork needed to demonstrate compliance, not whether compliance is required.
For teams weighing whether to build compliance internally or bring in outside help, the same tradeoffs that apply to broader AI adoption apply – cost, vendor selection, and compliance scope are covered in more detail in our guide to selecting and budgeting an AI agency in Germany.
A Practical Priority List for SMEs Right Now
Skip the generic seven-step checklist. Use a triage approach instead: identify what you have, classify each item, and spend budget where risk actually concentrates.
Build your AI inventory first. List every AI-touching tool your business uses, including embedded features in common SaaS. Note the vendor, business function, and who in your organization owns it. Based on our own client intake across mid-market firms in 2026, most SMEs discover between 15 and 40 tools when they do this properly, from Microsoft 365 Copilot to niche recruitment plugins that no one really remembers procuring.
Classify each tool with two questions:
What risk band does it fall into: prohibited, high-risk, limited, or minimal?
For this system, are we a provider, a user, or an importer?
Any tool that ranks or orders people (candidates, applicants, students, customers for essential services) is high-risk. A forward-facing chatbot is limited risk. Accounting AI is minimal risk. Fine-tune or brand a model and you become a provider, even if you started as a customer.
Once you know what you have and what role you play, the paperwork question shifts from theoretical to concrete. That's when documentation earns its value.
Build the documentation foundation. For high-risk deployments you will eventually need a written oversight procedure, an incident log, a data steward note describing what data the system uses and how it was checked, and the provider's instructions to use in the file. With the timeline now extended to December 2027, there's no reason to rush these into a polished folder – but there's also no reason to wait until 2027 to start the shared folder and template.
Name an accountability owner and record the appointment in writing. In a ten-person SME this is often the operations manager or CTO. In a larger firm it could be the data protection officer expanding their scope. The role does not require a lawyer, but it requires someone who can read guidance and act.
EU AI Act SME Penalties and Enforcement: Budget Triage
Article 99 sets three penalty caps. For SMEs and start-ups, the Act applies the lower of the two amounts in each row, instead of the higher.
Violation Type | Standard Maximum | Applies to SMEs as |
Prohibited AI Practices | 35 million euros or 7% of global turnover | Lower of both |
High-Risk Non-Compliance | 15 million euros or 3% of global turnover | Lower of both |
False or Misleading Information to Authorities | 7.5 million euros or 1% of global turnover | Lower of both |
Even the reduced cap sets SME risk for serious violations in the six or seven-figure range. Enforcement runs through national competent authorities designated by each member state. The EU AI Office implementation page publishes updated guidance and coordinates across member states.
Where to Spend Limited Budget
Have 10,000 euros to spend on EU AI Act compliance over the next quarter? Do not spread it evenly across every tool. Concentrate on one thing: your single high-risk system. For most SMEs that means one of these:
An automated hiring or resume-screening tool
An AI credit or affordability assessment tool used in lending or insurance broking
An AI safety component in a physical product you manufacture
A general-purpose AI model you fine-tune and give to customers
Close documentation gaps there first. Write the oversight procedure, capture the logs, request the provider's technical file in writing, and document the risk assessment. Real protection beats a flat compliance-theater pass across 30 tools that are minimal-risk anyway.
Official help is available and free. National regulatory sandboxes let SMEs test high-risk AI before market entry under supervised conditions, and every member state is required to operate at least one. The EU AI Office publishes documentation templates that SMEs can adapt directly. If you bring in outside help, structure the engagement around specific artifacts (technical file, oversight procedure, FRIA) instead of open-ended consulting.
Three Steps to Take This Week
If you close this article and want visible progress by Friday:
Conduct the AI inventory. Ask every department head to list every tool using AI, including features in familiar SaaS. Capture everything before you filter.
Flag the high-risk candidates. Any tool that ranks, scores, or makes decisions about people probably falls under Annex III. Star these on your list.
Name an owner and give them an hour a week. The AI Act is not a one-time project. Continuous ownership beats a one-time audit that is outdated in six months.
Want a structured way to work through this with your team? Our practice helps SMEs build practical AI governance without overshooting. Book an initial conversation to walk through your inventory and sort the top three risks.
Related Service: AI Agency
Frequently Asked Questions
Does the EU AI Act apply to US companies?
Yes, if a US company places an AI system on the EU market, offers services with AI output to EU users, or its AI output is used in the EU. The Act follows the same extraterritorial logic as GDPR. A US SaaS provider selling a resume screener to a German recruiter is a provider under the Act and typically must appoint an authorized EU representative.
Was the EU Artificial Intelligence Act passed?
Yes. It was adopted in 2024 and published as Regulation (EU) 2024/1689 in the Official Journal on July 12, 2024. Prohibitions came into force February 2, 2025. GPAI transparency rules came into force August 2, 2025. High-risk obligations, originally set for August 2, 2026, were shifted by the Digital Omnibus (in force since July 27, 2026) to December 2, 2027 for standalone Annex III systems and August 2, 2028 for Annex I embedded systems.
Are SMEs exempt from the EU AI Act?
No. The Act applies by system category, not company size. What SMEs get are lighter procedural burdens, reduced penalty caps under Article 99, lighter technical documentation templates, and priority access to national regulatory sandboxes. Core obligations are unchanged.
What are the key changes in EU AI regulations for 2026?
Digital Omnibus on AI, in force since July 27, 2026, shifted the main high-risk compliance deadlines roughly 16 months (to December 2027 and August 2028, depending on system type), shifted the watermarking/synthetic content deadline to December 2, 2026, added new prohibitions on AI-generated intimate imagery and CSAM, introduced formal SME and small mid-cap definitions with documentation and sandbox simplifications, and weakened the Article 4 AI literature obligation. It did not change the already-in-force prohibitions, the GPAI transparency obligations, or the Article 99 penalty caps.
What is the practical difference between a provider and a user?
A provider builds or places an AI system on the market under their name and owns technical documentation, conformity assessment, and CE marking. A user professionally uses another organization's AI system and owns operational obligations: correct use, human oversight, logging, and in some cases a fundamental rights impact assessment. Most SMEs are users for tools they buy and providers for anything they build, fine-tune, or brand.
Where do I find official EU guidance?
The EU AI Office legal framework page is the primary information source. It publishes implementation guidance and documentation templates, and coordinates with national authorities. The full legal text is in the Official Journal.
This article reflects the state of regulatory deadlines as of September 2026. The "Digital Omnibus" package was formally adopted and published only weeks before this article was written – so always check current deadlines on the official EU AI Office and Bundesnetzagentur pages before making compliance decisions, and take advice from a qualified specialist specific to your business.