This is a practical overview, not legal advice. It helps you find the parts of the AI Act that deserve a closer look.
1. What the EU AI Act is
The EU AI Act is a law about artificial intelligence. It applies different rules to different uses of AI. The bigger the possible harm, the stricter the rules.
Some uses are banned. Some are classed as high-risk. Some need a clear label or notice. Most everyday AI uses have no special product rules, but other duties can still apply. AI literacy is one example.
The Act does not treat a spam filter, a recruitment tool, and a medical AI system in the same way. Start with what the tool does and who could be affected.
2. Who it affects
The Act affects companies that build, sell, import, distribute, or use AI systems in the EU. It can also reach companies outside the EU when an AI system's output is used in the EU.
You do not need to be an AI company. If your team uses ChatGPT, Microsoft Copilot, an AI recruitment tool, or AI inside another business product, the Act may still matter to you.
The exact duties depend on your role and how you use the system. A small company using an off-the-shelf tool has a different job from a company selling its own AI product.
3. Main implementation dates
The AI Act started in stages. The Digital Omnibus entered into force on 27 July 2026 and moved several dates. These are the main dates SMEs should know as of 31 July 2026:
| Date | What happened |
|---|---|
| 1 August 2024 | The AI Act entered into force. |
| 2 February 2025 | Most prohibited AI practices and the AI literacy rules started to apply. |
| 2 August 2025 | Governance rules and obligations for general-purpose AI models started to apply. |
| 27 July 2026 | The Digital Omnibus entered into force. It changed Article 4, added new prohibited uses, and moved the high-risk dates. |
| 2 August 2026 | Most of the Act starts to apply, including the transparency rules. The AI Office and national authorities begin enforcement. |
| 2 December 2026 | New prohibitions on certain non-consensual intimate and child sexual abuse material start to apply. This is also the marking deadline for generative AI systems placed on the market or put into service before 2 August 2026. |
| 2 August 2027 | General-purpose AI models placed on the market before 2 August 2025 must comply with the relevant GPAI rules. |
| 2 December 2027 | High-risk rules start for listed uses such as recruitment, education, and access to essential services. |
| 2 August 2028 | High-risk rules start for AI used as a safety component in regulated products. |
4. Are you a provider or a deployer?
These words appear throughout the Act. The difference is easier to understand with a simple example.
Provider
You develop an AI system and sell it or offer it under your company name. You can also become a provider by making a major change to someone else's system or putting your brand on it.
Deployer
You use an AI system as part of your work. An SME using an AI tool for writing, coding, recruitment, or customer service is usually a deployer.
One company can be both. You might use Copilot as a deployer and also sell your own AI feature as a provider. Check each system separately.
5. The rules that matter most
Start by checking whether your AI use is prohibited, high-risk, or covered by a transparency rule.
Prohibited uses
The Act bans specific harmful uses. Examples include some forms of social scoring, manipulation of vulnerable people, and untargeted scraping of facial images. Most bans have applied since February 2025.
High-risk uses
AI used for recruitment, worker management, education, credit, critical infrastructure, or regulated products can be high-risk. The classification depends on the exact purpose and exceptions in the Act.
Transparency rules
People may need to know when they are talking to AI. Providers may need to mark generated content. Deployers may need to label deepfakes and certain public-interest text. These rules start on 2 August 2026.
There is one narrow transition period. Providers of generative AI systems placed on the market or put into service before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty in Article 50(2).
High-risk systems come with more work. Providers generally need risk controls, documentation, testing, logging, and human oversight. Deployers generally need to follow the instructions, monitor the system, keep human oversight, and act when they find a problem.
Do not classify a system from its marketing name. Look at what it actually does, why you use it, and which decisions it affects.
6. Article 4 and AI literacy
Article 4 has applied since 2 February 2025. It says providers and deployers must take measures to support AI literacy among staff and other people who operate or use AI on their behalf.
National market surveillance authorities begin supervising and enforcing Article 4 from 2 August 2026.
In practical terms, people should understand the tools they use, what those tools can and cannot do, and the risks in their own work. A developer, a recruiter, and a marketing writer do not need exactly the same training.
The amended Article 4 no longer sets a specific "sufficient level" of AI literacy. The obligation itself remains. Match your approach to your role, the system, and the risks involved.
Read the full guide: EU AI Act Article 4 for SMEs.
7. Practical first steps for SMEs
- List your AI tools. Include free tools, paid tools, and AI features inside other software.
- Write down how each tool is used. The purpose matters more than the product name.
- Check your role. Are you using the system, providing it, or doing both?
- Screen the risky uses first. Look for prohibited uses, high-risk decisions, and transparency duties.
- Set simple rules. Cover approved tools, sensitive data, human review, and who handles problems.
- Train the people using AI. Keep the training short, relevant, and matched to their work.
- Keep a record. Save what you checked, what you decided, and who completed the training.
- Review when something changes. Check again when you add a tool or use it for a new purpose.
Start with the tools people already use. You can improve the process later. A short written inventory is better than a large compliance plan that never gets finished.
9. Primary sources and disclaimer
- Regulation (EU) 2024/1689 on EUR-Lex
- Regulation (EU) 2026/1744 amending the AI Act
- European Commission overview of the AI Act
- European Commission AI literacy questions and answers
- European Commission transparency guidelines
- European Commission enforcement update, 31 July 2026
This page gives general information about the EU AI Act. It cannot tell you how the law applies to your specific system or business. If the answer could affect people's rights, safety, or access to work or services, ask a qualified lawyer or compliance specialist to review it.