Updated on 3 October 2026: Regulation (EU) 2026/1744 (the Digital Omnibus on AI), published in the Official Journal of the EU on 24 July 2026, postponed the high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). We have corrected the dates in this guide, which said 2 August 2026, and added what already applies (AI literacy and transparency) and the two new prohibitions that arrive on 2 December 2026.
The EU AI Act for SMBs has stopped being a Brussels debate and turned into a calendar with very specific deadlines. The European AI Regulation entered into force on 1 August 2024 and is being phased in. Since 2 August 2026 it has applied in general, including the Article 50 transparency rules (chatbots and AI-generated content). The bulk of obligations for systems classified as “high-risk”, originally due on that same date, has been postponed: Regulation (EU) 2026/1744 moves it to 2 December 2027, and to 2 August 2028 when the system is built into a regulated product.
The good news is that not every automation you have running falls under the regulation — far from it. The bad news is that some common ones, like a CV-screening filter or a system that scores the creditworthiness of individuals, are squarely inside it. This article is a pragmatic, jargon-free guide so you can understand which automations in your business are affected, what already applies and what to prepare before December 2027.
We’re writing this from the trenches: we deploy AI automations for small and mid-sized companies in Spain and review every project through this lens. What follows is what a CEO, an operations manager or an IT lead needs to know — not a legal team.
Quick answer: The EU AI Act classifies AI by risk. Most SMB automations are minimal-risk (invoice OCR) or transparency (chatbots); only some, like CV screening, are high-risk and will require human oversight from 2 December 2027.
The 4 risk categories of the EU AI Act explained for SMBs
The regulation classifies AI systems by their impact on fundamental rights and safety. Each tier triggers very different obligations:
- Unacceptable risk (banned). Systems forbidden in the EU since February 2025: China-style social scoring, subliminal manipulation, real-time mass biometric identification, purely profile-based predictive policing. From 2 December 2026 the Omnibus adds two more: systems that generate or manipulate realistic intimate or sexual images, video or audio of identifiable people without their consent, and systems that generate child sexual abuse material. SMBs rarely cross paths with these.
- High risk. The core of the regulation. It covers systems affecting employment, education, access to essential services, credit, insurance, justice and critical infrastructure. This is the tier most SMBs underestimate and where they get it wrong.
- Limited risk (transparency obligations). Chatbots, content generators, deepfakes. Main duty: warn the user they’re interacting with an AI or that the content is AI-generated. These rules apply from 2 August 2026 (Article 50).
- Minimal risk. Typical business automations such as invoice OCR, product recommenders, spam filters or predictive maintenance. No obligations specific to this tier (codes of conduct are voluntary), although, like any business use of AI, they fall under the Article 4 AI literacy duty.
Where common SMB automations fall
To make the categories concrete, here’s what we see in real projects:
- Automated CV screening and candidate ranking: high risk (Annex III, employment area). If your ATS scores, sorts or rejects candidates with AI, you’re a deployer of a high-risk system.
- Creditworthiness or credit scoring of individuals, and risk assessment or pricing in life and health insurance: high risk (Annex III, point 5). Note: only when the people assessed are natural persons (a sole trader is one), not companies; fraud detection is excluded.
- AI-based evaluation of employees (productivity, promotions): high risk.
- Customer-service chatbot on your website or WhatsApp: limited risk. You must disclose it’s an AI.
- AI assistant that drafts email replies which a human reviews before sending: minimal risk. No specific obligations beyond AI literacy.
- Invoice OCR feeding your ERP, bank reconciliation, expense classification: minimal risk.
- E-commerce recommenders, predictive maintenance, anomaly detection: minimal risk.
- AI-generated images, audio or video that could pass for real, and AI-generated text published to inform the public on matters of public interest: limited risk. You must disclose that they are artificial; for text, unless a person reviews it and someone takes editorial responsibility (Article 50(4)).
A useful mental shortcut: if the AI’s output decides something about a person (hiring them, lending them money, evaluating them, monitoring them), prepare for high risk. If the output is administrative data a human uses to work faster, it’s almost always minimal risk.
What you actually have to do if you operate a high-risk system
It matters whether you’re a provider (you build and sell the system) or a deployer (you use it inside your company). Most SMBs are deployers of third-party tools, and their obligations (Article 26) are lighter but still real. For Annex III systems they apply from 2 December 2027:
- Use the system according to the provider’s instructions and keep records of its use.
- Assign effective human oversight: a person with real authority to correct or shut down the system.
- Make sure input data is relevant and representative for the intended use case.
- Inform workers and their representatives before deploying a high-risk system in the workplace.
- Report serious incidents to the provider and, when applicable, to the national authority.
- Run a fundamental-rights impact assessment when applicable (typical for banking, insurance, public sector).
- Keep the system’s logs for at least six months.
The regulation sets the maximums: up to €35M or 7% of worldwide turnover for a prohibited practice, and up to €15M or 3% for breaching, among others, the deployer or transparency obligations; for SMEs, the lower of the two figures applies. Each Member State sets its own penalty rules: in Spain, the law that sets out infringements and fines is still going through Parliament (Organic Law bill on the proper use and governance of artificial intelligence, 121/000096), with no amounts approved yet.
Key dates 2025-2028
- 2 February 2025: prohibited practices and AI literacy (Article 4) apply. The Omnibus softened the latter: you must take measures to support the AI literacy of your staff and of anyone using AI systems on your behalf, without having to guarantee a specific level.
- 2 August 2025: obligations for general-purpose AI models (GPAI) and the start of national authorities plus the European AI Office.
- 2 August 2026: general application: authorities start supervising and the Article 50 transparency rules apply (chatbots and AI-generated content). High-risk, originally scheduled for this date, was postponed.
- 2 December 2026: the two new prohibitions in the Omnibus apply (non-consensual intimate or sexual content, and child sexual abuse material).
- 2 December 2027: obligations for high-risk Annex III systems (employment, credit, education, essential services, etc.), after the postponement in Regulation (EU) 2026/1744.
- 2 August 2028: obligations for high-risk systems embedded in regulated products (Annex I: machinery, medical devices, toys, lifts and so on).
Compliance checklist for an SMB
- Inventory. List every system or automation that uses AI, including Copilot, embedded ChatGPT, SaaS tools and in-house projects built with n8n or RPA.
- Classify each one into one of the four categories. Document the reasoning.
- Train your team. The AI literacy duty (Article 4) has applied since February 2025 to any business using AI systems, ChatGPT included. After the Omnibus you must take measures to support it, with no specific level to guarantee and no certificate required: you can show it with training tailored to your tools and an internal record.
- Label chatbots and generated content on websites, emails and social media.
- Ask your providers for technical documentation, declaration of conformity and CE marking for their high-risk systems.
- Design human oversight where required: roles, authority to stop the system, audit trails.
- Update internal policies: supplier contracts, AI usage policy, worker information notices, GDPR alignment.
Does it make sense to act now?
Yes — but with focus. Most SMBs will find that their actual automations are minimal-risk and that the real work concentrates on two or three specific tools. That quick map is worth having now: AI literacy and transparency already apply, and high-risk rules arrive on 2 December 2027.
At AIPROCESSIA we run that audit with a process mindset, not a paperwork one: we identify which automations you actually have, classify them, suggest technical changes when something can be downgraded by redesigning it (for example, keeping a “human in the loop” on a decision affecting people) and leave you with an actionable plan.
| Risk level | Example in an SMB | Obligation |
|---|---|---|
| Unacceptable | Social scoring | Prohibited |
| High | CV screening, creditworthiness of individuals | Assessment + human oversight |
| Limited | Customer-service chatbot | Transparency (disclose it’s AI) |
| Minimal | Invoice OCR, bank reconciliation | No specific obligations |
Frequently asked questions
Which SMBs does the EU AI Act affect?
Almost all, depending on how they use AI. It is not about size but the system’s risk: the more it affects people’s rights, the more obligations apply.
Which automations are high-risk?
Those that decide about people: CV screening, employee evaluation, credit scoring or access to essential services. They require human oversight, transparency and bias control.
When does it apply and what are the deadlines?
The regulation entered into force on 1 August 2024 and applies in phases: prohibited practices and AI literacy from February 2025, transparency from August 2026, and high-risk from 2 December 2027 (Annex III) or 2 August 2028 (Annex I), after the postponement in Regulation (EU) 2026/1744. It is wise to prepare your system inventory now.
Official sources
- Regulation (EU) 2024/1689, the AI Act (Official Journal of the EU, 12 July 2024): Articles 4, 5, 26, 27, 50, 99 and 113 and Annex III.
- Regulation (EU) 2026/1744, Digital Omnibus on AI (Official Journal of the EU, 24 July 2026, in force since 27 July 2026): new high-risk timeline, new Article 4 and the two new prohibitions.
- European Commission: AI literacy questions and answers.
- European Commission: questions and answers on the Article 50 transparency obligations.
- Spanish Organic Law bill on the proper use and governance of artificial intelligence (121/000096), Official Gazette of the Spanish Parliament, 12 June 2026 (in Spanish): still going through Parliament.
Sources checked on 2 October 2026. This guide is for information only and is not legal advice.
Contact us and we’ll analyse your case for free →
About the author
Jose A. Parra
CEO & Founder of AIPROCESSIA — 30 years as IT consultant for Spanish SMBs.
For three decades I’ve been deploying ERP systems, integrations and — since 2023 — AI agents, RPA and OCR in real-world flows for invoicing, maintenance and customer service. My focus: automate 5 key processes for under €100/month and give back 20-40 hours per week to the team — no one gets replaced.
Certified Generative AI Expert · UDIA · 2026.

[…] The practical rule is simple: automate the administrative paperwork without fear, but always keep a human in charge of any decision affecting someone’s hiring or career. If you want to understand in detail which automations are affected and the key deadlines, we cover it in our guide on the EU AI Act for SMBs. […]
[…] A properly governed AI agent concentrates access, logs it and limits it. Instead of twenty copies of a data point circulating by email, there’s a single controlled point with permissions and traceability. Done well, it complies with data-protection law by design (minimisation, access control, activity logging) and fits the transparency obligations of the EU AI Act. If you automate processes with AI, this piece matters as much as the process itself: review it alongside our guide on which automations the EU AI Act affects. […]
[…] There is a further layer: since 2 August 2026, the EU AI Act’s obligations for high-risk systems apply, and its Article 14 requires effective human oversight — whoever oversees the system must be able to understand its limitations, interpret its output, disregard or reverse it, and stop the system through a stop button or equivalent procedure. If your automation touches recruitment, credit decisions or worker evaluation, this is no longer best practice: it is a legal requirement. We cover it in our EU AI Act guide for SMBs. […]
[…] Talk to a specialist first if you handle especially sensitive categories (health, criminal or biometric data): they are possible, but they demand specific decisions. In that territory it is also worth reviewing what obligations the EU AI Act places on you. […]
[…] Updated on 3 October 2026: EU AI Act high-risk date corrected; after Regulation (EU) 2026/1744 it applies from 2 December 2027. What already applies, in our EU AI Act guide for SMBs. […]