Back to blog
#ai#business#strategy

The EU AI Act for SMEs: What Changes in August 2026

Enforcement of the EU AI Act begins on 2 August 2026. Here is what a small business actually has to do, in plain language and without the scaremongering.

By Rafael Costa5 min readEnglish
Share
The EU AI Act for SMEs: What Changes in August 2026

There is a date coming that a lot of small and medium businesses still do not have on their radar: 2 August 2026. From then on, the obligations for high-risk AI systems apply and the regulator gains full enforcement powers, fines included. It is not the end of the world, and for most small companies it does not call for an army of lawyers. But it does call for knowing where you stand, and most companies still do not.

The confusion is understandable. The AI Act came into application in phases, which makes it feel like there is plenty of time left. There is not. Some obligations have been in force since February 2025, notably the ban on certain practices and the AI literacy duty. In Portugal, ANACOM was designated in September 2025 as the national supervisory authority, coordinating 14 sector regulators. This guide explains, calmly and in plain English, what changes in August, what applies to an SME that merely uses AI, and what you should do now so the date does not catch you out.

The AI Act applies to your SME, even if you only use ChatGPT

The first myth to clear up is that this is "for the big tech companies". The regulation applies to whoever puts AI systems on the market and to whoever uses them. If your company uses ChatGPT, Copilot or any AI assistant day to day, you are a professional AI user in the eyes of the law, and you already have at least one obligation in force: AI literacy.

In practice, literacy means making sure the people who touch these tools understand what they are doing, the limits of the system and the risks. It is not a certified course or complex paperwork. It is basic training and documented common sense. The heavy obligations — technical documentation, conformity assessments, marking — fall on whoever develops or sells high-risk systems, not on whoever uses an everyday tool to write emails.

In two lines

If you only use AI: your main obligations are literacy and not using AI for prohibited practices. If you develop or embed AI in products, especially in high-risk areas, the work is considerably bigger and it starts now.

The four risk categories, without the legalese

The AI Act classifies systems by risk, and the level decides the obligations. It is worth understanding which one your company's use falls into.

  • Unacceptable risk. Practices banned since February 2025, such as social scoring or manipulation that exploits vulnerabilities. Prohibited, full stop.
  • High risk. Systems used in sensitive areas: recruitment and worker management, access to credit, education, critical infrastructure. This is where the heavy obligations land on 2 August 2026. If you use AI to screen applications, pay attention to this category.
  • Limited risk. Mostly transparency duties. A chatbot has to make clear it is a machine; AI-generated content should be identifiable.
  • Minimal risk. The overwhelming majority of everyday uses, from spam filters to text suggestions. No specific obligations.

Most SMEs live in minimal or limited risk. The real thing to watch is high risk, and the most common example in a small company is using AI in recruitment. If you screen candidates automatically, you are stepping into regulated territory.

What exactly changes on 2 August 2026

Two things happen on that date. First, the obligations for the Annex III high-risk systems apply — the ones tied to employment, credit and the like. Second, and just as important, the authority gains full powers: it can demand information, require corrections and impose fines.

A recent adjustment gave some breathing room to part of the high-risk obligations for more complex systems, pushing a few deadlines later. Do not be misled by the headline: the prohibitions (in force since February 2025) and the literacy duty stand, with no delay. Anyone using AI has no excuse for not having the basics covered already.

Fines: proportionate, and lighter for SMEs

The part that frightens everyone is the headline fine amounts, which at the top reach percentages of global turnover. That deserves context. Those ceilings were designed for large infringers and for prohibited practices. For SMEs, the regulation expressly provides that the lower amounts apply and that company size be taken into account, with guidance to use percentages rather than fixed sums where those would be disproportionate.

There is more good news for small companies. Free regulatory sandboxes are provided for — environments where you can test AI systems with the regulator alongside you — plus specific support measures. The European logic is not to fine the bakery that uses a chatbot. It is to stop serious abuse and give SMEs room to adopt AI responsibly.

The minimum plan for an SME, in four steps

You do not need a six-month project. For a company that only uses AI, the essentials take four to eight weeks and come down to four steps.

  1. Take an inventory. List where AI is already used in the company, including the tools that came in through the back door without formal approval. You cannot manage what you cannot see.
  2. Classify the risk. For each use, identify the category. The key question: does any of these tools touch recruitment, credit or another high-risk area? If so, it is the priority.
  3. Handle literacy. Give basic training to the people using these tools and write a simple internal policy on what can and cannot be done, especially with customer data. This connects directly to GDPR, which still applies whenever AI processes personal data.
  4. Get transparency right. If you run a chatbot or generate content with AI, make it clear to the user that they are talking to a machine or looking at generated content.

Do that and your company is in good shape for 2 August without drama. Compliance here is not an obstacle, it is a way to adopt AI with confidence — the same principle we apply when we help companies start with AI where it actually makes sense. If you have AI in recruitment or another sensitive area and are not sure where you stand, talk to us. We will do the inventory with you and tell you plainly what genuinely needs attention.

#ai#business#strategy
Share this article
Rafael Costa

Written by

Rafael Costa

Software Engineer & Technical Writer

Rafael is a software engineer at Lusivision who writes about web development, cloud architecture and applied AI. He has spent over a decade shipping production software for companies across Europe and enjoys turning hard technical topics into clear, practical guides.

View all articles

Related articles

Outcome-Based AI Pricing: A Buyer's Guide (2026)
EN
#ai#business

Outcome-Based AI Pricing: A Buyer's Guide (2026)

Vendors are moving from per-seat to pay-per-outcome AI. How outcome-based pricing really works in 2026, where it quietly costs more, and the clauses to insist on.

5 min read
How to Choose an AI Agent Development Company (2026)
EN
#ai#business

How to Choose an AI Agent Development Company (2026)

Most AI agent projects that fail were doomed at vendor selection. Here is how to choose an AI agent development company in 2026, the questions to ask, and how to de-risk the decision.

4 min read

Newsletter

Stay in the loop

Occasional notes on software, design and what we're building. No spam — unsubscribe anytime.