A new EU law with fines in the millions – and hardly anyone tells small businesses clearly which parts actually apply to them. The EU AI Act has been in force since 2024, but its obligations take effect in stages over several years. On 2 August 2026, the stage most relevant to small and medium-sized enterprises goes live: the transparency obligations for AI systems. This article explains, without legalese, which obligations really apply to your business, from when – and which of the much-discussed postponements actually concern you.
This article reflects the status as of 26 July 2026 and is not legal advice. For a binding assessment of your individual case, consult a lawyer or your data protection officer.
The four risk classes in plain terms
The EU AI Act regulates AI based on risk: not every application is treated the same, but according to its potential to harm people. Four classes determine which obligations apply – and for the vast majority of SME applications, only the third is relevant.
- Prohibited AI practices (Art. 5): applications such as social scoring or manipulative nudging have been banned since 2 February 2025. Practically never relevant for a normal business website.
- High-risk AI (Annex III): AI in sensitive areas such as recruitment, credit scoring or critical infrastructure. Heavily regulated, but rarely applicable to a typical SME offering.
- Limited risk / transparency (Art. 50): chatbots, AI-generated text, images and video. This is where the duty to disclose AI interactions and AI content applies – exactly the layer that affects most SMEs.
- Minimal risk: everyday applications such as spam filters or product recommendations. No specific obligations.
Am I affected as an SME? The 3-question test
First things first: the AI Act has no general exemption for small businesses. Whether you are affected depends not on company size but on whether and how you use AI. Three questions quickly narrow down your obligations.
- Are you a provider or a deployer?Deployers use AI in their own operations – for example ChatGPT for text or a purchased website chatbot. Providers develop or market AI systems themselves. Most SMEs are deployers, for whom significantly lighter obligations apply.
- Do you use a chatbot or AI content on your website?If visitors interact with an AI, or you publish AI-generated text, images or video, the transparency obligation under Art. 50 applies from 2 August 2026 – disclosure and labelling become mandatory.
- Do you use AI internally in your team?As soon as employees use AI tools, the AI literacy obligation under Art. 4 applies – regardless of risk class and already since February 2025.
From when does what apply? The timeline
The AI Act's deadlines are staggered, and the Digital Omnibus finally adopted in June 2026 postponed part of them. Crucial for SMEs: the postponement concerns the high-risk layer – not the transparency obligations.
| Obligation | Legal basis | Applies from | Which SME it affects |
|---|---|---|---|
| Prohibited practices | Art. 5 | 2 February 2025 | practically none |
| AI literacy of staff | Art. 4 | 2 February 2025 | any using AI internally |
| Transparency for chatbots & AI content | Art. 50 | 2 August 2026 | any with a chatbot or AI content |
| Marking of AI-generated content (machine-readable) | Art. 50(2) | 2 August 2026 (existing systems: 2 December 2026) | providers of generative AI |
| High-risk obligations (Annex III) | AI Act with Digital Omnibus | 2 December 2027 | hardly any typical SME |
| High-risk in regulated products (Annex I) | AI Act with Digital Omnibus | 2 August 2028 | hardly any typical SME |
EU AI Act deadlines for businesses (as of 26 July 2026)
AI literacy (Art. 4) – the underrated obligation
Since 2 February 2025, Art. 4 requires companies to ensure a "sufficient level of AI literacy" among staff and contractors who use AI – for example through training and clear usage rules. This obligation applies regardless of risk class to every provider and deployer. It becomes enforceable by authorities from 3 August 2026; Art. 4 itself provides no direct fines, but a lack of AI literacy can be an aggravating factor in other breaches. Anyone using ChatGPT, Copilot or similar tools in the team should provide documented training on their use.
Transparency (Art. 50) – labelling chatbots and AI content
From 2 August 2026, the transparency obligation applies: users must be informed before interacting that they are dealing with an AI and not a human (Art. 50(1)) – unless it is already obvious. A human-seeming service bot does not meet that exception. Likewise, AI-generated or manipulated content must be recognisable as such – AI labelling covers this in detail. For the machine-readable marking of AI-generated content (Art. 50(2)) there is a nuance: systems already on the market before 2 August 2026 have until 2 December 2026; newly introduced systems must mark immediately. What this means concretely for your website is covered in the article on AI Act obligations for websites obligations for your own site.
Fines: what is realistically at stake
The AI Act's penalties (Art. 99) are tiered: up to €35 million or 7% of global annual turnover for prohibited practices, up to €15 million or 3% for breaches of the transparency obligations under Art. 50, and up to €7.5 million or 1% for supplying incorrect information to authorities. For small and medium-sized enterprises and start-ups, the lower of the two amounts applies in each case. The deterrent percentages target large corporations – for an SME the real exposure is the absolute euro cap, combined with the principle of proportionality. Even so, the obligations should be taken seriously, because warning letters from competitors do not require an authority fine.
Wasn't everything postponed? What the Digital Omnibus actually changed
The headline "EU postpones the AI Act" is misleading. The Digital Omnibus, given final approval by the Council of the EU on 29 June 2026, postpones the high-risk obligations – for stand-alone Annex III systems to 2 December 2027, and for AI embedded in products under Annex I to 2 August 2028. The transparency obligations under Art. 50 are unaffected and become binding on 2 August 2026. So anyone operating a chatbot or publishing AI text cannot rely on the "postponement" – for them nothing was postponed. The changes take legal effect upon publication in the Official Journal, expected before the deadline.
In practice: building AI features compliant from the start
In our own web projects with AI functionality – such as the AI-assisted booking and assistant feature in our PMS project Lease Loop – we build the transparency notice and GDPR-compliant data processing in from the start, rather than retrofitting them. That is the cheaper route: a labelling notice already embedded in the component costs nothing in development – a later rebuild under deadline pressure does.
In short
- No general SME exemption – the obligation follows AI usage, not company size.
- For most SMEs it is exactly two tasks: make staff AI-literate (Art. 4) and transparently label AI interactions (Art. 50).
- Art. 4 has applied since February 2025, Art. 50 becomes binding on 2 August 2026.
- Only the high-risk obligations were postponed (December 2027 / August 2028) – not transparency.
- Fines for transparency breaches up to €15 million / 3%, for SMEs the lower amount; warning letters are the more realistic risk.
