Autonomio AI
All insights
July 9, 2026 · eu-ai-act · governance

The EU AI Act for SMBs: what actually applies to you in 2026

Most SMBs are not building high-risk AI, but almost all of them are deployers under the EU AI Act. What that means in practice, the deadlines, and the 5 things to do now.

TL;DR: if your company uses AI at all, the EU AI Act almost certainly touches you as a deployer, even if you never train a model. Prohibited-practices and AI-literacy rules already apply since February 2025, general-purpose AI rules since August 2025, and the bulk of high-risk obligations land in August 2026. Most SMB obligations are manageable: know your AI inventory, classify the risk, train your people, and keep humans in the loop.

You are probably a "deployer", and that matters

The Act distinguishes providers (who build or sell AI systems) from deployers (who use them professionally). Using ChatGPT for client work, an AI receptionist on WhatsApp, or AI scoring in your CRM makes you a deployer. Deployer duties are lighter than provider duties, but they are not zero: use systems according to instructions, ensure human oversight, and make sure staff have adequate AI literacy (Article 4, already in force).

The timeline that matters for an SMB

The official European Commission AI framework page and the independent AI Act Explorer are the two references I actually use with clients.

What most SMBs get wrong

They either panic (freeze every AI project "until legal signs off") or ignore it entirely. Both are expensive. The Act is risk-based: a chatbot that drafts marketing emails is minimal-risk and needs little more than transparency; an AI that screens CVs is high-risk and needs documentation, oversight and logging. Knowing which bucket each use case falls into removes 80% of the fear, and that classification takes an afternoon, not a quarter. I wrote before about how the AI bottleneck moved from models to governance; this regulation is that shift becoming law.

The 5 things I do with every client

  1. Inventory: list every AI system in use, including the shadow ones your teams adopted on their own.
  2. Classify: map each to the Act's risk tiers.
  3. Literacy: short, role-specific AI training (it is already mandatory, and it is also just good adoption practice).
  4. Human oversight: define who reviews AI outputs that affect people.
  5. Paper trail: lightweight documentation per use case, so an audit is a folder, not a fire drill.

Governance designed in early is cheaper than governance bolted on after. It is a core part of my fractional AI CTO retainer, and the free readiness assessment includes a governance dimension so you can see your gap in 3 minutes.

See where your AI actually stands.

Take the free assessment