The European Union's AI Act has been in force since August 2024 and has been phased in step by step ever since: the bans on certain practices have applied since February 2025, the obligations for providers of large foundation models since August 2025 — and since 2 August 2026 the core of the law, the requirements for high-risk systems. Time for a sober look at what actually affects a small or medium-sized business.

The principle: risk, not technology

The AI Act does not regulate "AI" as such; it regulates use cases, graded by risk:

The good news for most SMEs is in that last line. If you use AI as a writing and research assistant, you are not operating a high-risk system.

What affects every company regardless

AI literacy. Article 4 has required since February 2025 that staff working with AI systems have adequate competence. A documented internal training session and a clear usage policy cover this for typical office use — and both should exist for data protection reasons anyway.

The deployer role. Even a company that merely buys AI rather than building it has duties as a deployer once a high-risk case is involved. The critical moment is inconspicuous: a tool that "pre-sorts" job applications sounds like a convenience feature — it is a high-risk use case. So the question belongs in your procurement process: does this fall under Annex III?

Labelling. If you offer customers a chatbot or publish AI-generated images, you must make that transparent. It costs little effort — and is forgotten all the time.

The sovereignty angle

Almost every obligation in the AI Act comes down to the same thing: knowing what you operate, and being able to show it. That is precisely what fails when AI has crept into a company through free browser accounts — nobody knows who is processing what with which tool.

A self-operated system reverses the relationship. If model, index and logs live in your own house, you can answer every question about data flows, access and purpose from first-hand knowledge instead of pointing at a provider's assurances. Compliance then stops being an occasion for paperwork and becomes a side effect of orderly infrastructure.

My advice: no panic about fines, but an honest inventory. Which AI is in the house, on which contractual basis, with which data? If you can answer those three questions, most of the road is already behind you.