TL;DR: if your company uses AI at all, the EU AI Act almost certainly touches you as a deployer, even if you never train a model. Prohibited-practices and AI-literacy rules already apply since February 2025, general-purpose AI rules since August 2025, and the bulk of high-risk obligations land in August 2026. Most SMB obligations are manageable: know your AI inventory, classify the risk, train your people, and keep humans in the loop.
You are probably a "deployer", and that matters
The Act distinguishes providers (who build or sell AI systems) from deployers (who use them professionally). Using ChatGPT for client work, an AI receptionist on WhatsApp, or AI scoring in your CRM makes you a deployer. Deployer duties are lighter than provider duties, but they are not zero: use systems according to instructions, ensure human oversight, and make sure staff have adequate AI literacy (Article 4, already in force).
The timeline that matters for an SMB
- February 2025 (in force): prohibited practices banned (manipulative systems, social scoring, emotion recognition at work) and AI-literacy duties for anyone using AI professionally.
- August 2025 (in force): transparency rules for general-purpose AI models.
- August 2026: the big one. Full obligations for high-risk systems: recruitment and HR screening, credit scoring, education assessment, critical infrastructure. If your AI touches hiring or lending decisions, this is your deadline.
The official European Commission AI framework page and the independent AI Act Explorer are the two references I actually use with clients.
What most SMBs get wrong
They either panic (freeze every AI project "until legal signs off") or ignore it entirely. Both are expensive. The Act is risk-based: a chatbot that drafts marketing emails is minimal-risk and needs little more than transparency; an AI that screens CVs is high-risk and needs documentation, oversight and logging. Knowing which bucket each use case falls into removes 80% of the fear, and that classification takes an afternoon, not a quarter. I wrote before about how the AI bottleneck moved from models to governance; this regulation is that shift becoming law.
The 5 things I do with every client
- Inventory: list every AI system in use, including the shadow ones your teams adopted on their own.
- Classify: map each to the Act's risk tiers.
- Literacy: short, role-specific AI training (it is already mandatory, and it is also just good adoption practice).
- Human oversight: define who reviews AI outputs that affect people.
- Paper trail: lightweight documentation per use case, so an audit is a folder, not a fire drill.
Governance designed in early is cheaper than governance bolted on after. It is a core part of my fractional AI CTO retainer, and the free readiness assessment includes a governance dimension so you can see your gap in 3 minutes.