The basics
What is the EU AI Act and who does it apply to?
Short answer
For now, the EU AI Act for SMEs boils down to two tasks: train your team and tell people when they are talking to an AI. The EU AI Act is Regulation (EU) 2024/1689, the European regulation on artificial intelligence, which regulates AI by level of risk. If your agent decides on employment or credit, more controls apply from 2 December 2027. The GDPR still applies.
To understand what the EU AI Act is and who it applies to, think in terms of uses, not technology. The Artificial Intelligence Act applies to anyone who develops AI systems and anyone who uses them professionally in the EU, even if the business is based outside the EU (a UK company whose AI output is used in the EU, for instance). It doesn’t regulate ‘AI’ in the abstract: it regulates specific uses, and the more harm a use can do to people, the more obligations it carries.
So who does the EU AI Act apply to, and for which obligations? That depends on two roles defined in Article 3:
- Provider (Art. 3(3)): anyone who develops an AI system, or has one developed, and places it on the market or puts it into service under their own name or trademark. Providers carry most of the technical obligations.
- Deployer (Art. 3(4)): anyone who uses an AI system under their authority in the course of a professional activity. This is the typical role of an SME that subscribes to a chatbot, uses ChatGPT or integrates a third party’s agent.
Who does the EU AI Act apply to when the agent is custom-built?
Disclaimer
Timeline
EU AI Act timeline: what applies now and what has been delayed
The EU AI Act timeline is staggered: the Regulation entered into force on 1 August 2024, but it applies in phases. As of October 2026, the prohibitions, AI literacy, the rules for general-purpose AI models and the transparency obligations already apply; the high-risk rules have been postponed to December 2027 and August 2028. In practice, the timeline of the EU AI Act for SMEs makes one thing clear: what is urgent today is transparency and training, not high risk.
The ‘Digital Omnibus’: from proposal to law
On 19 November 2025 the European Commission proposed a simplification package, the ‘Digital Omnibus’, made up of two separate pieces. The AI part is already law: Regulation (EU) 2026/1744 was signed on 8 July 2026, published in the Official Journal on 24 July and has been in force since 27 July 2026. Its main changes, according to the consolidated Article 113:
- Annex III high-risk systems (employment, credit, education…): moved from 2 August 2026 to 2 December 2027.
- Annex I high-risk systems (regulated products): moved from 2 August 2027 to 2 August 2028.
- AI literacy (Art. 4): moves from ensuring ‘a sufficient level of AI literacy’ to taking measures to support the AI literacy of staff.
- New prohibitions: systems for creating non-consensual synthetic nudes or child sexual abuse material, from 2 December 2026.
- SMEs and small mid-cap enterprises: further simplification of documentation and fines.
What is still only a proposal
Classification
Which EU AI Act risk level is your AI agent in?
The EU AI Act distinguishes four levels: prohibited practices, high risk, limited risk (transparency obligations) and minimal risk. Most SME agents, such as customer service, internal support or document analysis agents, fall into limited or minimal risk. Systems that count as EU AI Act high risk are the exception: specific uses in employment, credit, education or essential services.
| Criterion | Prohibited | High risk | Limited risk | Minimal risk |
|---|---|---|---|---|
| Examples | Subliminal manipulation, social scoring, emotion recognition at work, synthetic nudes | Screening CVs, evaluating employees, credit scoring, pricing life or health insurance | Customer service chatbot, voice agent, generated images or videos | Summarising internal documents, sorting emails, spam filters, searching the knowledge base |
| Legal basis | Art. 5 | Art. 6 and Annex III | Art. 50 | No specific rules (Art. 95, voluntary codes) |
| Obligations | Cannot be used | Human oversight, logs, information for affected people; for the provider, conformity assessment and CE marking | Disclose that it is AI and label synthetic content | AI literacy only (Art. 4) |
| Applies from | 2 Feb 2025 (new ones: 2 Dec 2026) | 2 Dec 2027 (Annex III) | 2 Aug 2026 | Art. 4: 2 Feb 2025 |
| For an SME, this means… | Checking that no use comes close to these practices | A serious compliance project and a DPIA; start now | A clear notice and a labelling policy | Training the team and complying with the GDPR |
Try it with your own case. Six questions are enough for a first pass at your agent, your role and what the EU AI Act for SMEs and the GDPR require of you:
If you are not sure whether your tool is an agent, a chatbot or a simple automation, the guide AI agent vs chatbot vs automation will help you place it: the technical label doesn’t change the risk, but it does change how the tool interacts with people.
Obligations
What are the EU AI Act obligations for SMEs?
The obligations of the EU AI Act for SMEs depend above all on what you use AI for. Every SME that uses AI at work must meet the AI literacy requirement in Article 4 and, if its agent talks to people or generates content, the transparency obligations in Article 50. High-risk obligations only arise for specific Annex III uses.
What already applies to you in October 2026
- Avoid prohibited practices (Art. 5), in force since 2 February 2025.
- Take AI literacy measures for your staff (Art. 4). No certificate needed: tailored training and an internal record are enough.
- Tell users they are talking to an AI and label deep fakes (Art. 50), since 2 August 2026.
- Comply with the GDPR for any personal data that passes through the agent: that has not changed.
AI literacy (Art. 4)
Since the Omnibus, Article 4 requires providers and deployers to take measures to support the AI literacy of their staff, without guaranteeing a specific level. The Commission’s questions and answers make it clear that no certificate is needed and that an internal record of training is enough. In practice, whoever uses the agent should know what it does, where it goes wrong and what data must not be entered.
Transparency obligations: chatbots and generated content (Art. 50)
Since 2 August 2026, Article 50 has required that people know they are interacting with an AI, unless it is obvious, at the latest at the first interaction. That obligation sits with the provider; if your agent is custom-built and carries your brand, the provider is you. As a deployer, you must label deep fakes and any AI-generated text you publish to inform the public on matters of public interest, unless it has undergone human editorial review. On 10 June 2026 the Commission published a voluntary code of practice on marking and labelling.
EU AI Act and ChatGPT: what changes if your team uses it?
For an SME, the link between the EU AI Act and ChatGPT is indirect. ChatGPT, Claude and Gemini are built on general-purpose AI models, whose obligations (documentation, copyright, systemic risk) have fallen on OpenAI, Anthropic and Google since 2 August 2025. For you, using them means using an AI system: AI literacy applies, you need to check what data goes in and, if you build an agent on top, you need to classify that specific use.
EU AI Act high risk: what falls on the deployer
If your agent screens candidates, evaluates employees or scores customers’ creditworthiness, from 2 December 2027 Article 26 requires you to use it in line with the instructions, assign competent human oversight, monitor how it operates, keep the logs for at least six months, inform workers’ representatives before using it and inform the people affected. For credit and for life or health insurance, a fundamental rights impact assessment is added (Art. 27), and affected people have the right to an explanation (Art. 86).
The Article 6(3) exception
Personal data
EU AI Act and GDPR: what data protection law requires of your agent
On the EU AI Act and GDPR, the rule is simple: the EU AI Act does not replace the GDPR, the two apply side by side. If your agent reads emails, chats with customers or queries a CRM, it processes personal data, so you need a lawful basis, a contract with the provider, data minimisation and, often, an impact assessment.
In February 2026 the AEPD, Spain’s data protection authority, published guidance on agentic AI (in Spanish) built around one central idea that holds anywhere in the EU: adding an agent can change a processing operation you thought was settled. These are the six GDPR fronts to review:
- Lawful basis (Art. 6). Each purpose needs its own: performance of a contract to handle an order, legitimate interest (with its balancing test) to analyse incidents, consent if nothing else fits. Explain it in your privacy notice (Arts. 13 and 14).
- Data protection impact assessment, or DPIA (Art. 35). Mandatory if the processing is likely to result in a high risk: profiling, automated decisions, sensitive data or innovative technology at scale. Data protection authorities, such as the AEPD in Spain, publish indicative lists of processing that requires one.
- Automated decisions (Art. 22). No one may be subject to a decision based solely on automated processing that has legal or similarly significant effects, unless it is based on a contract, the law or explicit consent, and always with the right to human intervention. The Court of Justice applied this article to credit scoring (Case C‑634/21, SCHUFA, 2023).
- Data minimisation (Art. 5(1)(c)). Agents tend to accumulate context. Give them access only to the data the task needs and set deletion periods for memory and logs.
- International transfers (Chapter V). If the model processes data outside the European Economic Area, you need an adequacy decision (the EU-US Data Privacy Framework remains in force, although it has been challenged before the CJEU) or standard contractual clauses. Hosting and processing in the EU makes things much simpler.
- Processor agreement (Art. 28). The model or platform provider is usually a data processor. Sign its DPA, review its sub-processors and check that it does not use your data for training without your permission.
One agent, two laws
Penalties
What fines does the EU AI Act set for SMEs, and who enforces it?
Article 99 sets three tiers of maximum fines, and this is where the EU AI Act for SMEs is genuinely lighter: for SMEs, each fine is capped at the percentage or the fixed amount, whichever is lower (Art. 99(6)); for large companies, whichever is higher.
€35m
Maximum for prohibited practices, or 7% of worldwide turnover
Art. 99(3) AI Act
€15m
Maximum for other obligations, including the Article 50 transparency obligations, or 3%
Art. 99(4) AI Act
€20m
GDPR maximum for the most serious infringements, or 4% of worldwide turnover
Art. 83(5) GDPR
For example, an SME with a turnover of €5 million that breaches the Article 50 transparency obligations faces at most 3% of its turnover (€150,000), not €15 million. The Omnibus extended this ‘whichever is lower’ rule to small mid-cap enterprises, except for prohibited practices (Art. 99(6a)). Article 4 does not appear in the list of infringements in Article 99(4), although each Member State may set its own penalties.
If you operate in Spain: who enforces it
Each Member State designates its own authorities. In Spain, the Spanish Agency for the Supervision of Artificial Intelligence (AESIA), based in A Coruña, is the lead authority and has published practical guides and checklists (in Spanish) on the Regulation. The AEPD keeps its data protection role and, under the draft bill, will supervise certain uses such as biometrics. The draft Organic Law on the proper use and governance of AI (in Spanish), approved by the Spanish Government on 26 May 2026, sets out the Spanish penalty regime; it was published in the Spanish Parliament’s official gazette on 12 June 2026 and, at the time of writing, is still going through Parliament.
Action plan
EU AI Act for SMEs: how to comply this quarter
Six tasks, in this order, cover everything that is already enforceable and leave you ready for the high-risk rules. An SME with two or three agents can complete them in a few weeks.
Inventory every use of AI
List the agents, chatbots and tools such as ChatGPT or Copilot that your team uses. For each one, note the purpose, the provider, what data it processes, where that data is hosted and whether you use it under your own brand. Without an inventory, you cannot classify anything.
Classify the risk and rule out anything prohibited
Use the tool in this guide as a first filter. Check that no use falls within the prohibited practices in Article 5, including the new ones on synthetic nudes and child sexual abuse material, which apply from 2 December 2026.
Switch on transparency
Add a clear notice to the first message of every chatbot or voice agent that talks to customers or candidates. Label any realistic AI-generated image, audio or video that you publish as artificial. This has been mandatory since 2 August 2026.
Document AI literacy
Run short training tailored to each role: what the agent does, what it must not be used for, what data must not be entered and how to review its output. Keep an internal record of who received it and when. No certificate is required.
Close off the GDPR side
Set the lawful basis for each purpose, update your record of processing activities, sign a data processing agreement with each provider, check where the data is hosted, limit memory and logs to what is necessary and carry out a DPIA where the processing requires one.
Prepare for high risk in good time
If any agent influences hiring, employee evaluation or credit decisions, start designing now: human oversight, log retention, information for workers and affected people, and explanations of decisions. The obligations apply from 2 December 2027.
If you are designing a new agent, it is far cheaper to build these controls into the design (notices, logs, least-privilege permissions, EU hosting, human review) than to bolt them on afterwards.
FAQ
EU AI Act for SMEs and the GDPR: frequently asked questions
What is the EU AI Act and who does it apply to?
The EU AI Act is Regulation (EU) 2024/1689, the European regulation on artificial intelligence, which regulates AI according to the risk of each use. It applies to anyone who develops AI systems (providers) and anyone who uses them professionally in the EU (deployers), even if the business is based outside the EU. An SME that uses third-party agents or chatbots is usually a deployer.
What are the EU AI Act obligations for SMEs that use AI agents?
Today, the EU AI Act obligations for SMEs come down to three: avoid prohibited practices (Art. 5), take AI literacy measures for staff (Art. 4) and, since 2 August 2026, tell users they are talking to an AI and label deep fakes (Art. 50). If the agent makes decisions about employment or credit, high-risk controls will apply from 2 December 2027.
EU AI Act and ChatGPT: what does an SME that only uses ChatGPT or Copilot need to do?
Not much, but something. Under the EU AI Act, an SME using ChatGPT is a ‘deployer’, so the AI literacy duty in Article 4 already applies: take measures so that whoever uses it understands its limits. The obligations for general-purpose AI models fall on OpenAI or Microsoft. If you enter personal data, the GDPR applies as well.
Do I have to tell people that my chatbot is an AI?
Yes. Since 2 August 2026, Article 50(1) of the EU AI Act requires that people know they are interacting with an AI, unless it is obvious. The technical obligation falls on the provider of the system, but if the agent was built for you and you use it under your own brand, the provider is you. A clear notice in the first message solves it.
What is the EU AI Act timeline, and what has been delayed?
The key dates in the EU AI Act timeline are 2 February 2025 (prohibitions and AI literacy), 2 August 2025 (general-purpose AI models), 2 August 2026 (transparency and general application), 2 December 2027 (Annex III high-risk systems) and 2 August 2028 (Annex I). Regulation (EU) 2026/1744, in force since 27 July 2026, only delayed the high-risk rules.
Does an AI agent that screens CVs count as EU AI Act high risk?
Usually, yes: Annex III of the EU AI Act classifies systems used to select candidates, filter applications or evaluate them as high-risk. From 2 December 2027, whoever uses one must ensure competent human oversight, keep the logs for at least six months and inform workers’ representatives. The GDPR already requires genuine human intervention today if the decision is automated.
EU AI Act and GDPR: do I need a DPIA to use an AI agent?
It depends on the processing, not the technology. Where the EU AI Act and GDPR meet, Article 35 of the GDPR requires a data protection impact assessment (DPIA) if the processing is likely to result in a high risk to people: evaluation or profiling, automated decisions, sensitive data or innovative technology at scale. An agent that decides on candidates or customers will almost always need one; one that summarises internal documents without personal data probably won’t.
Can I use a US AI provider with customer data?
Yes, if the transfer is covered. The EU-US Data Privacy Framework remains in force for certified companies, although it has been challenged before the Court of Justice of the EU. If the provider is not certified, you need standard contractual clauses. The most stable option is to host and process the data in the EU, and always sign a data processing agreement.
Who enforces the EU AI Act in Spain?
If you operate in Spain, the Spanish Agency for the Supervision of Artificial Intelligence (AESIA), based in A Coruña, will be the main authority; the AEPD still enforces the GDPR and, under the draft bill, will supervise uses such as biometrics. The draft Organic Law on the proper use and governance of AI, which sets the Spanish penalty regime, has been before the Spanish Parliament since June 2026.
References
Sources
Consulted and verified in October 2026. The application dates come from the consolidated text of the AI Act following Regulation (EU) 2026/1744.
- Regulation (EU) 2024/1689, the Artificial Intelligence Act (EUR-Lex)
- Regulation (EU) 2026/1744, Digital Omnibus on AI (EUR-Lex)
- European Commission, AI Act Service Desk: consolidated Article 113
- AI Act Service Desk: Article 99, penalties
- AI Act Service Desk: Article 50, transparency obligations
- AI Act Service Desk: Article 4, AI literacy
- European Commission: AI literacy, questions and answers
- European Commission: guidelines on prohibited AI practices (4 February 2025)
- Regulation (EU) 2016/679, General Data Protection Regulation (EUR-Lex)
- AEPD: agentic artificial intelligence from a data protection perspective (February 2026, in Spanish)
- AESIA: guides to complying with the AI Regulation (in Spanish)
- Government of Spain: draft law on the proper use and governance of AI (26 May 2026, in Spanish)
This article was created with the help of AI and reviewed by José Galán. I take great care over every post and every translation, but the odd mistake can still slip through. If you find one, write to me: you will be helping me improve.
Custom AI agents
Agents that are compliant by design
I design AI agents for SMEs with risk classification, transparency notices, logging and data hosting sorted from day one, not patched on later.
See AI agents for business