EU AI Act, explained for non-lawyers: a 2026 guide for SMEs
If your team recently started using Copilot, ChatGPT, or an AI feature that quietly showed up inside a tool you already pay for, and someone forwarded you an article about the "EU AI Act" with a slightly panicked tone, this guide is for you. No legal background required.
This is not just a Big Tech law
The EU AI Act (formally Regulation (EU) 2024/1689) is easy to misread as a rulebook for the companies that build AI models: OpenAI, Google, Anthropic, and similar. That reading misses the point for most small and mid-sized businesses. The Act regulates AI systems based on how they are used, not just who built them. If your company uses AI tools in ways that touch hiring, HR decisions, credit or insurance decisions, or certain other sensitive areas, obligations can land on you even though you never wrote a line of model code.
In practice, most SMEs interacting with this law are not building AI. They are buying it, embedding it in a SaaS subscription, or letting employees use it day to day. That distinction matters, and we will come back to it.
The Act sorts AI use into four risk tiers
Instead of one set of rules for all AI, the Act uses a risk-based structure. The tier your use case falls into determines what, if anything, you need to do.
- Unacceptable risk: a short list of banned practices, such as certain manipulative or exploitative AI systems and specific forms of biometric categorisation or social scoring. These prohibitions have been in force since February 2025.
- High-risk: AI systems used in specific high-stakes contexts listed in the Act's Annex III, including employment and worker management (hiring, promotion, termination decisions), access to essential services, and creditworthiness assessment. Most of these obligations were originally due to apply from August 2, 2026, but the EU's "Digital Omnibus" package, in force since late July 2026, pushed that date back to December 2, 2027.
- Limited risk (transparency obligations): AI systems that must simply disclose themselves, such as chatbots that need to make clear a user is talking to AI, or content that is AI-generated and needs to be labelled as such.
- Minimal risk: everyday tools like spam filters, spell-checkers, or general-purpose writing assistants used for routine tasks. These face essentially no new obligations under the Act.
Most everyday AI use by SMEs sits in the minimal-risk tier. The work is figuring out, honestly, whether any specific use case in your business drifts into the high-risk or transparency tiers, since that is where real obligations show up.
Provider or deployer: the distinction that changes everything
The Act splits obligations between two main roles. A provider develops an AI system, or has one developed, and places it on the market under its own name. A deployer uses an AI system under its own authority, in the course of its own activities, without being the one who built it.
Almost every SME reading this is a deployer. You are using a hiring tool, a chatbot, or an AI feature built into software someone else made. Deployer obligations are generally lighter than provider obligations, but they are not zero, especially for high-risk use cases: things like human oversight, keeping records of use, and understanding what the system was actually designed and validated to do. We cover this split in full detail, including where the lines blur, in a dedicated follow-up post: "Provider or deployer? Why the EU AI Act sorts you into one, and it changes everything."
Why this is landing on your desk now
That is the practical reason this topic feels urgent this month rather than abstract. If your business uses AI anywhere near hiring, performance management, credit decisions, or another Annex III area, the question is no longer "when do we need to think about this" but "where do we actually stand today." That is worth a calm, structured look rather than a scramble.
Signs your business is already affected
- You use an applicant-tracking or recruiting tool that scores, ranks, or filters candidates automatically.
- You use software with AI features for performance reviews, scheduling, or workforce monitoring.
- You use or offer tools that assess creditworthiness, insurance risk, or eligibility for a financial product.
- You use a customer-facing chatbot and have not clearly told users they are talking to AI.
- You publish AI-generated content (text, images, audio, or video) without any indication that it is AI-generated.
- You are not sure which of your SaaS subscriptions have quietly added AI features in the last year.
If any of those sound familiar, it does not automatically mean you are out of compliance. It means the specific use case is worth checking against what actually applies to a deployer in your position.
General information, not legal advice
Everything above is general information to help you get oriented, not legal advice for your specific situation. The EU AI Act has detail and nuance that a short guide cannot fully capture, and how it applies depends on your exact use cases. Where Komplya publishes guidance like this, we are clear about which layers are legally reviewed and which are draft material, so you can weigh it accordingly.
Where to go from here
The fastest way to move from "I think this might apply to us" to a clear answer is to walk through your actual AI use case by use case, rather than trying to read the whole regulation. Answer a short set of questions about how your business uses AI, and get a plain-language read on where you likely stand.