UbertAI engineering for SMEsBook an intro call
Insights / Law & privacy

The EU AI Act for SMEs, without legal jargon

September 2, 2026 · 6 min read

There is a European regulation on AI, and for many business owners that mainly means uncertainty. Do you now have to register something, apply for something, or keep a file. The short answer for most SMEs: less than you think, but not nothing.

What follows is an explanation in broad strokes. It is not legal advice, and if you are in doubt about your specific application, a lawyer should look at it.

The regulation looks at risk, not at technology

The premise is simple: the more harm an AI application can do, the heavier the requirements. A system that reads in your packing slips falls into a completely different category from a system that decides who gets hired.

  • Prohibited applications. Think of scoring people on social behaviour, or reading the emotions of employees on the shop floor. This is not allowed, full stop.
  • High risk. Applications that have a major impact on someone’s life: recruitment and selection, employee evaluation, access to education or essential services. Extensive obligations apply here.
  • Limited risk. Mainly transparency. If a customer talks to a chatbot, it must be clear that it is not a human. If you generate content with AI, that should be made known.
  • Minimal risk. By far the largest group: route planning, stock forecasting, document recognition, spam filters. No special obligations apply here under this regulation.

What already applies

Two parts have been in force since early 2025. The first is the ban on the most severe applications. For an ordinary wholesaler or installation company that is no daily concern, but watch out with HR applications: software that measures the mood or attentiveness of employees comes dangerously close.

The second is AI literacy. If you use AI in your business, you must ensure that the people who work with it understand what it does and what its limitations are. That does not have to be a course with a certificate. An explanation session, a short work instruction and a record that you have done it is a reasonable approach for an SME.

The rest of the obligations, including the heavy regime for high-risk systems, will come into force in phases over the coming years. Dates and details still shift at times, so do not rely on a date someone mentions in a sales conversation; look in the regulation itself or ask your lawyer.

Note

The regulation looks at your role. If you build an AI system yourself and put it on the market, you are a provider and more requirements apply. If you use a system from a supplier, you are a deployer and your set of obligations is lighter. Most SMEs are in the second category.

What you can do in practice

  1. Make a list of where you use AI. Including the things you do not think of as AI: the chatbot on your site, the assistant in your office suite, the forecasting feature in your stock package.
  2. For each application, write in one sentence what it does and what goes wrong if it makes a mistake. That gives you your risk picture.
  3. Check whether any application evaluates people. Staff, job applicants, customers you turn down. Those are the cases where you need to pay attention.
  4. Make sure your chatbots and AI-generated content are recognisable as such. That is cheap to arrange and it stands out if you do not.
  5. Give your people a short explanation of what the systems can and cannot do, and record that you have done so.

What to ask your supplier

Most of what you need does not come from you but from the party supplying the system. Ask for it specifically, and do not settle for a logo or a reassuring sentence on a product page. Three questions get you a long way: in which risk category does the supplier place this system, what documentation do you get with it, and what happens to your input.

If you get no clear answer to that, that is information in itself. A supplier who cannot classify their own product cannot help you either when a customer or regulator asks about it later. Keep the answers you do get in a folder with your other supplier documents, because they are hard to reconstruct later.

What disappoints about this

The honest answer is that practice has not yet crystallised. Standards, guidelines and supervision are still being developed, and that means nobody can tell you with certainty today how a regulator will look at your specific application in three years. Anyone who does is selling you something.

On top of that, a small AI compliance circus is emerging: expensive programmes for businesses that fall into the minimal risk category and probably do not need to do anything. Do not let anyone scare you. Determine your category first, then your measures.

When you need us and when you do not

If you are in the minimal risk category, and that applies to the vast majority of SME applications, you do not need an adviser for this. Going through the list above takes you a morning and then you are done.

We are useful if you use AI around staff, credit assessment or access to services, if you build something yourself that you supply to third parties, or if your customers ask for demonstrable compliance. Then it is about documentation, logging and human oversight in the design, and you want to arrange that up front rather than afterwards.

Sources
Further reading
GDPR and AI: what can you do with customer data?

The GDPR does not prohibit AI, but it does set requirements for purpose, legal basis and processors. Most mistakes at SMEs are carelessness, not a matter of principle.

Why AI projects in SMEs fail

Projects rarely fail on the technology. They fail on messy data, a pilot that never ends and nobody who owns it.

AI compliance & grantsAI guidance & trainingProfessional servicesAccountants & bookkeeping firmsLawyers & legal services

What did you think of this? One click is enough, no login needed.

Comments

An addition, a counterpoint or a question: all welcome. You first get an email to confirm your address, then we read along before your comment goes online. Your email address is never shown on the site.

Loading comments…

0/2500
We store your name, email address and comment so we can post it and reply to it. See the privacy statement.

Rather talk it through than read?

Half an hour with someone who builds it themselves costs you nothing. And we say honestly when you do not need us.

Book an intro callSee the pricing