The EU AI Act in practice: what SMEs should really have in place by August 2026
The EU AI Act has become less a legal text than a sales argument. We regularly receive screenshots of emails recommending that mid sized companies launch a six figure compliance project because they use a transcription tool. In almost every case we have seen, that was wildly overblown. At the same time there is a core of obligations you really should have handled, and it is surprisingly small.
One important update first: with the so-called Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026), the EU has postponed the deadlines for high-risk AI. The obligations for standalone Annex III high-risk systems, which include automated candidate screening or performance assessment, now apply only from 2 December 2027. The transparency obligations under Article 50, meaning the notice when people interact with AI or conversations are processed, still apply unchanged from 2 August 2026. For most SMEs that merely deploy AI, this changes little in practice; it mainly buys some extra time on the more sensitive use cases.
The first step is the role question. Almost every SME is a deployer, not a provider (the roles are defined in Article 3 of the AI Act). You do not build an AI system, you use one. That distinction determines most of your obligations and is regularly blurred in consulting offers. Provider duties such as technical documentation (Article 11), conformity assessment (Article 43) and CE marking (Article 48) sit with your software supplier. Check that in the contract, not in the marketing material.
The second step is classifying your use cases, not your tools. The same tool can be harmless or sensitive depending on what you use it for. Meeting minutes for a project team are uncritical. The same technology used to automatically evaluate job interviews or assess employee performance sits in a very different category. So write down use cases, not product names.
The third step is AI literacy (Article 4). This duty is the most overlooked and the easiest to satisfy. Since the Digital Omnibus it is phrased a little more softly, companies should support AI literacy rather than strictly ensure it, which changes nothing about the practical approach. What is required is that the people working with the systems understand what the system does, where its limits are and when they need to intervene. A two hour session with real examples from your own company, a short handout and an attendance list do the job. What matters is evidence, not volume.
The fourth step is transparency (Article 50). If conversations are recorded or processed, participants need to know. That is required by data protection law anyway and is culturally the decisive point in practice. We recommend a standard sentence at the start of every meeting and a works agreement clarifying that recordings are not used for performance monitoring. Without that commitment nobody on the works council will follow you, with it things usually move surprisingly fast.
The fifth step is human oversight, concretely rather than conceptually (for high-risk systems, Article 14 requires exactly this). It is not enough to write in a policy that humans have the final say. You need a named person per use case, a defined review interval and a documented way to report errors. Why we treat human in the loop as a founding principle is described separately. In many companies this is the only real effort involved, and it pays off regardless of any regulation.
What can you ignore?
You do not need a certified AI management system to use a documentation tool. You do not need a risk analysis for every chatbot an employee once tried. And you do not need external certification if you only operate low risk systems. What you need is a current list of your use cases, clear responsibilities and evidence of training and oversight.
A realistic roadmap for a company with 50 to 500 employees fits into three meetings. In the first you collect every AI application actually in use, including the unofficial ones, and there are usually more than management assumes. In the second you assign an owner and a risk assessment to each use case. In the third you define training, transparency notices and review intervals. After that the whole topic lives in a document of a few pages and needs an annual update.
The real benefit of this exercise, by the way, is rarely compliance. It is that you finally have a complete picture of where AI is actually used in your company. In most cases that list is the best basis for the next investment decision you have to make anyway. How to turn it into a workable framework is covered in our article on responsible AI in practice, with more reading in the topic hub AI for mid sized companies.
Sources
Frequently asked questions
Which EU AI Act obligations apply to SMEs?+
Companies with 50 to 500 employees typically face deployer duties: a current list of use cases, a risk classification per case, AI literacy for users, transparency towards affected people and named human oversight.
Does an SME need certification for AI applications?+
Usually not. If you only operate low risk systems you need evidence of training, ownership and oversight rather than a certified AI management system.
How much effort does implementation take?+
Realistically three meetings: collect the use cases, assign owners and risk levels, define training, transparency notices and review intervals. After that the topic lives in a document of a few pages updated annually.
Related articles
In a 30 minute conversation we'll discuss how and why RECO can grow your business now and into the future. Schedule a meeting now.
