Trump Rules Out US-China AI Joint Venture Over Technology-Sharing Concerns
Trump rejects a U.S.-China AI joint venture over technology-sharing concerns while bilateral AI risk dialogue continues. Here is what it...
Does the EU AI Act apply to your SME? Learn your role, current obligations, and 2026 deadlines, with a practical compliance roadmap.
Being a small or medium-sized enterprise does not create a blanket exemption from the EU AI Act. What matters is what AI systems your business uses or provides, what role it holds in relation to those systems, and which provisions apply to those activities. Some obligations, such as the ban on certain AI practices and the duty to support AI literacy, have applied since February 2025. Others, particularly the detailed high-risk requirements, now apply on later dates following the 2026 amendments.
Those amendments matter for anyone researching this topic in 2026. On 27 July 2026, Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force and changed several deadlines and provisions in Regulation (EU) 2024/1689, the EU AI Act. Guidance written before mid-2026 may describe a timeline or an Article 4 wording that no longer reflects current law. This article sets out, as of September 2026, what an SME should do now and what to prepare for next, based on its role and its actual use of AI.
There is no general SME carve-out. Applicability depends on the organisation's activities, its AI systems, and its role in relation to each one, not on headcount alone. An SME can be a deployer, using an AI system built by someone else under its own authority; a provider, developing or placing an AI system on the market under its own name; an importer or distributor, where relevant; or several of these at once, depending on the system in question.
An SME might deploy an AI accounting tool, provide AI features built into its own software, and distribute a third-party AI application, all simultaneously. Internal use of AI and providing or embedding AI in a product raise different obligations, so each system needs its own assessment. Size alone does not determine which obligations apply, though it can affect available support and, in places, how proportionately obligations are applied.
Before any legal analysis is possible, an SME needs to know what AI it actually has in place. A practical first step is to create an inventory covering, for each tool: its purpose and business function; the department and users; the vendor; the data involved, including personal data; the people or groups affected; whether it is customer-facing or employment-related, or touches another sensitive context; its likely AI Act role; and any obligations that appear relevant.
This inventory is not itself a statutory requirement. It is a governance step that makes every later question answerable, including the ones that do carry legal weight. It is also the practical way to surface "shadow AI": tools individual teams have adopted without formal review, which are easy to miss and often disproportionately risky.
Purchasing and using an AI product does not automatically make an SME its provider. However, substantially modifying a system, repurposing it for a materially different use, integrating it into your own product in a way that changes its intended purpose, or placing it on the market under your own name can shift that position. Where any of these apply, the analysis should be revisited rather than assumed.
|
Question |
Why it matters |
|
Are we a provider or deployer for this system? |
Determines which responsibilities may apply |
|
Is the use a prohibited practice? |
Immediate action may be required |
|
Does a transparency obligation apply? |
Specific disclosure duties may arise |
|
Could the system be high-risk? |
More extensive requirements may apply, subject to current dates |
|
Are we developing, modifying or repurposing AI? |
Provider-level responsibilities may become relevant |
Article 5 bans a defined set of AI practices considered unacceptable, in force since 2 February 2025. The 2026 Digital Omnibus added further prohibitions, including practices involving AI-generated non-consensual intimate imagery and child sexual abuse material, effective from 2 December 2026. Whether a use falls within a prohibited category depends on the precise legal criteria, not on a general impression. Where an SME suspects a use might qualify, that use warrants immediate, specific review.
Article 50 sets out several distinct obligations rather than one universal disclosure rule: telling people they are interacting with an AI system, labelling AI-generated or manipulated content, and disclosing emotion recognition or biometric categorisation are treated differently. Drafting a document with generative AI internally is not the same scenario, under Article 50, as running a public-facing chatbot or publishing synthetic media. Each use case should be checked against the specific paragraph it might engage.
High-risk classification depends on the criteria in Article 6 and the relevant annex, not on sector alone. AI used in recruitment is not automatically high-risk merely because it touches employment; it depends on how it is used and whether it meets the Annex III criteria. The same caution applies to healthcare or other regulated sectors. Where a system does qualify, obligations can involve risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy and cybersecurity, monitoring, incident-related processes, and conformity assessment where applicable. SMEs working through a specific classification may find the EU AI Act compliance guide useful for that deeper analysis.
Article 4 has applied since 2 February 2025 and requires providers and deployers to take measures supporting the AI literacy of staff and others operating AI systems on their behalf. Following the 2026 amendment, this is explicitly an obligation of effort rather than guaranteed outcome: it does not require guaranteeing any specific level of literacy for any individual, and it does not require identical training or certification for every employee. It does require measures reasonably tailored to people's technical knowledge, experience, education and training, the context of use, and the people likely to be affected. National market surveillance authorities supervise and enforce Article 4, so this is a live obligation, not a future one.
Structured training can support these efforts. EU AI Act compliance training can help staff build a working understanding of AI Act concepts, provider and deployer distinctions, and governance considerations. Completing a course is not, on its own, equivalent to satisfying every Article 4 duty or achieving broader legal compliance; it is one measure among several an SME might use.
Using the inventory, check each system against Article 5, paying attention to manipulation, exploitation of vulnerabilities, social scoring, and the categories added in 2026. Separately, work through the specific Article 50 scenarios that might apply to your actual use cases and note what disclosure or labelling step each requires. Treat genuinely uncertain cases as priorities for closer review rather than deferring them.
Beyond these obligations, a proportionate governance response is sensible for most SMEs actively using AI: defining approved and restricted uses, setting expectations for human review of AI-assisted decisions, establishing basic data-handling rules, assigning responsibility for AI-related questions, requiring a lightweight approval step before new tools are adopted, and keeping a short record of decisions made. These are recommended practices, not statutory mandates, and the right level of formality should reflect the system, its role, and the people it affects.
Where a system meets the high-risk criteria, the practical implications depend heavily on whether the SME is provider or deployer. Providers carry the heavier documentation, risk management and conformity obligations; deployers are generally responsible for appropriate human oversight, using the system as instructed, and monitoring its operation. An SME that has substantially modified or repurposed a third-party system may find itself closer to the provider end of that spectrum.
The 2026 Digital Omnibus deferred the detailed Chapter III obligations, and the relevant date depends on the classification route:
Article 6(2) and Annex III (stand-alone high-risk systems, including certain uses in employment and education): the relevant Chapter III, Sections 1 to 3 obligations now apply from 2 December 2027.
Article 6(1) and Annex I (AI embedded as a safety component in products already regulated under EU product-safety law): the equivalent obligations apply from 2 August 2028.
Transitional provisions, including Article 111, remain relevant for systems already placed on the market or in service and for systems undergoing significant changes, and should be checked before assuming a system automatically follows the standard timeline. If your SME provides or deploys an AI system likely to fall into one of these categories, this is the point to begin building the underlying documentation and controls, rather than waiting for the application date itself.
Where an SME relies on third-party AI tools, vendor due diligence is a practical extension of its own compliance work. Useful questions include the system's intended purpose, who the legal provider is, what AI Act role the vendor considers itself to hold, whether the system has been classified as high-risk and on what basis, what documentation is available, what transparency measures are built in, how data is handled, how responsibilities are allocated contractually, and how the vendor will communicate serious incidents or significant changes. This kind of EU AI Act vendor due diligence helps an SME understand what it is deploying, but it does not transfer the SME's own obligations as a deployer, or as a provider if its own actions have shifted its role.
|
Timing |
What it means for SMEs |
|
Already applicable |
Article 5 prohibited practices and Article 4 AI literacy measures, both since 2 February 2025 |
|
From 2 August 2026 |
The Act's general application date; Article 50 transparency obligations apply from this date for new systems, alongside general-purpose AI model obligations in force since August 2025 |
|
From 2 December 2026 |
Article 50(2) watermarking and content-marking obligations extend to systems already on the market before August 2026, and the additional Article 5 prohibitions take effect |
|
From 2 December 2027 |
Chapter III, Sections 1 to 3 obligations apply to Article 6(2) / Annex III high-risk systems, if your SME provides or deploys one |
|
From 2 August 2028 |
Equivalent obligations apply to Article 6(1) / Annex I high-risk systems, if your SME provides or deploys one |
Not every SME needs to prepare for every row. The relevant question is whether your inventory contains a system that falls within it.
Identify the AI systems and tools actually in use.
Identify your SME's role for each one.
Review each system against the prohibited practices in Article 5.
Assess which transparency obligations and high-risk criteria might apply, based on current dates.
Support AI literacy among relevant staff, proportionate to their role.
Review vendors and put proportionate internal controls in place.
Document the compliance decisions made and set a schedule to revisit them.
Working through this roadmap is easier when the people responsible for it, whether that's an owner, a compliance lead, an IT manager, or someone who has simply been handed the task, share a common, structured understanding of how the AI Act actually works. For SMEs building that foundation, EU AI Act compliance training covers AI Act requirements, provider and deployer distinctions, and practical governance concepts in a self-paced format designed for non-specialists as well as compliance professionals.
Completing the course does not, on its own, make an organisation legally compliant, satisfy every Article 4 AI literacy obligation, or replace legal advice, and it does not guarantee any particular outcome. It is best used as one part of a proportionate approach: a way to give relevant staff a working vocabulary and a clearer sense of what to look for as they work through their own inventory, roles and vendor reviews.
In the near term: identify what AI is in use, check for immediate concerns around prohibited practices, assign clear responsibility for AI-related questions, put proportionate controls in place, and prepare only for the future obligations that actually apply to your systems. A structured EU AI Act compliance checklist can help keep this sequence on track without turning it into an exhaustive project. Many SMEs find it useful to treat this as a standing process rather than a one-off exercise; guidance on complying with the EU AI Act over time can help build that habit once the initial review is complete.
Article 62 requires Member States and the AI Office to provide SME support, including awareness and training activities, dedicated communication channels for practical guidance, and consideration for SMEs in conformity-assessment fees and priority sandbox access where sandboxes are established nationally. The 2026 amendment extends some of these considerations to small mid-cap enterprises. These are support mechanisms that ease the practical burden of compliance, not exemptions from the underlying obligations, and should sit alongside, not instead of, an SME's own role and risk analysis.
No. There is no general SME exemption. Obligations depend on the SME's role, its AI systems, and the provisions those systems engage, though some support measures target smaller organisations.
It can, typically as a deployer. The exact obligations depend on how the tool is used, whether transparency or high-risk criteria are engaged, and whether the SME has modified or repurposed it in a way that shifts its role.
The AI Act requires measures supporting AI literacy among relevant staff, tailored to their role and context. It does not require identical training, a certificate, or a guaranteed level of literacy for every individual.
Where it develops an AI system, places one on the market under its own name, or substantially modifies, repurposes or integrates a third-party system in a way that changes its intended purpose.
By checking it against the specific criteria in Article 6 and the relevant annex, rather than relying on the sector or general use case alone.
Article 5 prohibited practices and Article 4 AI literacy obligations, both since February 2025. Article 50 transparency and general-purpose AI model obligations apply from their 2025 and 2026 dates. Detailed high-risk requirements have been deferred to December 2027 and August 2028 depending on classification route.
Ask about the system's intended purpose, the vendor's own AI Act role, any risk classification, available documentation, transparency measures, data handling, and how responsibilities and incident notifications are allocated contractually.
Trump rejects a U.S.-China AI joint venture over technology-sharing concerns while bilateral AI risk dialogue continues. Here is what it...
AI Law
Compare AI laws around the world in 2026, including binding laws, proposed rules, regulatory frameworks, effective dates and business implications...
OpenAI shelved GPT-6.1 Astra after safety tests flagged scope, authorization and action-reporting issues. See what is confirmed and what remains...