The AI Act for your SME: the technical side.
Last updated: July 2026
Updated 8 July 2026 — includes the current status of the Digital Omnibus.
The Regulation (EU) 2024/1689 —the AI Act— is already in force and applies in phases through 2027-2028. Most SMEs don't develop AI: they use it (ChatGPT, Copilot, a CRM with AI), and that already makes them deployers, with light but real obligations. This guide covers the technical side —inventorying, classifying and documenting your systems—, which is where a CTO or architect adds value and a legal advisor doesn't reach.
- If you use third-party AI, you are a deployer: train your team (Art. 4), be transparent and document.
- The real risk isn't the fine: it's landing in "high-risk" without realising (CV screening, scoring, biometrics).
- Start with inventory + classification: it's cheap and it brings order.
- The prohibitions, AI literacy and transparency are not deferred. High-risk is only deferred if the Digital Omnibus is published in the Official Journal before 2 August 2026; otherwise it keeps its dates.
Confused by the deferral headlines? We break it down separately: Is the EU AI Act delayed? What applies on 2 August 2026.
AI Act timeline.
Updated: 8 July 2026-
Regulation (EU) 2024/1689 enters into force
-
Prohibitions (Art. 5) and AI literacy (Art. 4)
-
GPAI, governance, penalties and national authorities (AESIA)
-
General application: transparency (Art. 50) and national sandbox apply NO MATTER WHAT; Annex III high-risk, conditional on the Omnibus
deferral pendingThe Digital Omnibus (a provisional political agreement) would defer Annex III high-risk to 2 Dec 2027 — but it only binds if published in the EU Official Journal before 2 Aug 2026. If it is not published in time, high-risk also applies on this date.
-
End of the watermarking grace period for systems already on the market, plus the CSAM / “nudifier” ban
-
High-risk embedded in regulated products (Annex I)
deferral pendingThe Omnibus would defer it to 2 Aug 2028, under the same condition: publication in the Official Journal before 2 Aug 2026.
The 3 milestones ahead.
If you only remember three dates from the calendar, make it these — and what each one means for you.
2 Aug 2026 · General application
Transparency (Art. 50) starts applying no matter what —label AI-generated content and disclose chatbots—, and every country must have a national sandbox up and running. Annex III high-risk also applies on this date… unless the Omnibus makes it in time (see note). What's on you: comply with transparency now; and if any system is near Annex III (CV screening, customer scoring…), have its classification ready instead of betting on the deferral. The Digital Omnibus would defer Annex III high-risk to 2 Dec 2027, but it only binds if published in the EU Official Journal before 2 Aug 2026; otherwise this date stands.
2 Dec 2026 · Synthetic-content marking
The watermarking grace period ends —systems from before August 2026 must now mark synthetic content— and a new ban kicks in (CSAM and "nudifier" apps). What's on you: if you generate images, audio or video with AI, make sure marking is in place, including on what's already published.
2 Aug 2027 · High-risk in regulated products
Annex I high-risk obligations apply: AI embedded as a safety component in already-regulated products (machinery, medical devices, toys, lifts…). What's on you: usually nothing, unless you manufacture or integrate that kind of product. The Omnibus would defer it to 2 Aug 2028, under the same condition: publication in the Official Journal before 2 Aug 2026.
Your role, in one sentence.
If you use third-party AI, you are a deployer (Art. 26: human oversight, adequate input data, records and informing your staff). If you develop it, put your brand on it or substantially modify it, you are a provider and take on the bulk of the obligations (Art. 16). Most SMEs are deployers.
The technical side: a checklist
- Inventory — list every AI tool in use, including shadow AI (about half of staff use AI not sanctioned by their employer).
- Classification — apply Annex III case by case and document the reasoning behind each decision.
- Documentation — for high-risk: technical documentation (Annex IV), a risk-management system and logging.
- Human oversight — define who reviews what, and with what competence.
- Transparency — label AI-generated content and disclose when users interact with a chatbot.
- Governance — an AI Act compliance owner and a usage policy tailored to your real tools.
Fines: the official reference.
Three tiers under Article 99 of Regulation (EU) 2024/1689:
| Infringement | Maximum fine |
|---|---|
| Prohibited practices (Art. 5) | up to €35M or 7% of worldwide turnover |
| Breaching obligations (high-risk, Art. 4, provider/deployer…) | up to €15M or 3% |
| Incorrect or misleading information to authorities | up to €7.5M or 1% |
As a general rule the higher figure applies. But SMEs and start-ups get the lower of the fixed amount and the percentage (Art. 99.6): the real risk isn't the theoretical cap, but a wrong classification.
Spain: AESIA and the sandbox
In Spain the AESIA (based in A Coruña) is the supervisor; it runs the national regulatory sandbox —a EU pioneer— and has published 16 free technical guides. Before paying for expensive consultancy, lean on those guides and the AI Act Service Desk.
We handle the technical side
Inventory, classification, documentation and technical audit of your AI systems, from Zaragoza for SMEs across Aragón and Spain.
This is not legal advice: it is the engineering that supports your legal advisor and AESIA.
Frequently asked questions.
-
Q01
Does the AI Act affect me if I only use AI like ChatGPT or Copilot?Yes. Using third-party AI in your professional activity makes you a deployer: your obligations are light —training, transparency and oversight— but they already apply.
-
Q02
What is a "deployer" and what do I have to do?It is whoever uses an AI system under their authority. Article 26 asks them to use it according to the instructions, assign competent human oversight, watch the input data, keep records and inform affected workers. Much lighter than being a provider.
-
Q03
Is it true that the AI Act has been postponed?Only partly, and conditionally. The Digital Omnibus (a provisional political agreement) would defer Annex III high-risk to 2 December 2027 and Annex I to 2 August 2028, but it only binds if published in the EU Official Journal before 2 August 2026; if it isn't published in time, the original calendar stands. The prohibitions, AI literacy (Art. 4) and transparency (Art. 50) keep their dates no matter what: don't wait.
-
Q04
How do I know if my AI system is "high-risk"?It is if it falls into one of the eight Annex III domains (biometrics, employment, education, essential services such as credit scoring…) and the Art. 6(3) exception does not apply. The typical SME mistake is landing there without realising: screening CVs, evaluating employees or scoring customers with AI is usually high-risk.
-
Q05
What is AI literacy and since when does it bind me?Since 2 February 2025 (Art. 4), providers and deployers must ensure their staff has sufficient AI competence, proportionate to their role. There are no minimum hours or certification, but documented evidence of the training is required.
-
Q06
Where do I start, technically?With inventory and classification: list every AI tool in use (including shadow AI) and classify each use case by risk, documenting the reasoning. It is cheap, needs no consultancy and is the basis for everything else.
-
Q07
How much can I be fined as an SME?Caps reach €35M or 7% of turnover for prohibited practices, but SMEs and start-ups get the lower of the fixed amount and the percentage (Art. 99.6). The real risk is not the theoretical cap, but non-compliance from a wrong classification.
-
Q08
What is a regulatory sandbox and is it worth it?It is a supervised testing environment where you validate an AI system with legal certainty. For SMEs access is priority and free, and the documentation you generate helps prove conformity. In Spain it is run by AESIA.
-
Q09
Is this legal advice?No. This guide and our work cover the technical side of compliance —inventory, classification, documentation and audit—, the engineering complement to your legal advisor and AESIA. For legal interpretation, consult a specialised lawyer.