Most of what SMEs read about the AI Act is either panic or sales copy. The honest version: most small and mid-sized companies are 'deployers' with limited obligations — but the AI-literacy duty (Article 4) already applies to every company whose staff use AI, and the next wave of obligations starts on 2 August 2026. Here's the checklist, without the fear marketing.
Last updated: 11 June 2026
Answer 4 questions and our EU AI Act risk checker classifies your AI system — prohibited, high, limited or minimal risk (plus GPAI) — with your obligations and the compliance deadline.
Most Dutch SMEs are 'deployers' of AI under the EU AI Act, with limited obligations. Two things matter now: the AI-literacy duty (Article 4) already applies to every organisation whose employees use AI tools like ChatGPT or Copilot, and the high-risk obligations start on 2 August 2026 (parts have been deferred by the EU's Digital Omnibus). Our fixed-price AI Act Check (€950) tells you in one week which category your AI use falls into and exactly what to arrange — and, just as often, what you can safely ignore.
The AI Act regulates uses of AI, not AI itself. Four classes decide your obligations:
| Class | Examples | What it means for an SME |
|---|---|---|
| Prohibited | Social scoring, manipulative AI, emotion recognition at work | Simply don't. These are banned outright. |
| High-risk | AI in recruitment/selection, credit scoring, safety components | Heavy obligations (risk management, logging, human oversight). Most SMEs only touch this via HR tooling — check your recruitment software. |
| Limited risk | Chatbots, AI-generated content | Transparency: people must know they're talking to AI or seeing AI content. |
| Minimal risk | Spam filters, spellcheck, most office AI use | No specific obligations — but Article 4 AI literacy still applies to your staff. |
Our AI Act Check gives you certainty for a fixed €950 (ex VAT), delivered within one week: an inventory of your AI use, a risk classification per system, your role (provider/deployer) per system, an AI usage policy template tailored to your business, and a concrete to-do list — including what you can safely ignore. If training is needed, the SLIM subsidy often covers a substantial part of the cost. We are AI practitioners, not a law firm: for contested legal questions we'll tell you honestly when you need a lawyer.
The AI Act entered into force in stages. Prohibitions and the Article 4 literacy duty already apply. The high-risk obligations become binding on 2 August 2026, but the EU's Digital Omnibus agreement (2026) deferred parts of the high-risk regime by 12–16 months for many categories. What this means in practice: the fear-marketing deadline is softer than advertised — but the literacy duty and transparency rules are not postponed, and they're the ones that actually touch most SMEs. Verify current status on the official implementation timeline; this page reflects the position at the 'last updated' date above.
First practical step for most SMEs: writing an AI usage policy.
The EU AI Act is built on a risk pyramid. The obligations that apply to your business depend entirely on which tier each of your AI uses falls into — so this is the classification you must get right before anything else.
The honest reality for the typical Dutch MKB: most of your AI is minimal or limited risk. A chatbot, a document summariser, an email drafter, a forecasting model — these are not high-risk. You only enter high-risk territory when AI helps decide who gets hired, who gets credit, or who someone is (biometrics). If that describes you, treat it seriously. If it does not, do not let consultants sell you a high-risk compliance programme you do not need. Not sure where a specific use lands? That is exactly what an AI scan is for.
Even at limited risk, three transparency obligations catch a huge share of ordinary businesses:
These are low-effort but easy to forget. A one-line disclosure on your chatbot and a labelling habit for AI-produced marketing assets covers most of it.
The Act does not switch on all at once; it phases in over several years. In broad strokes: it entered into force in August 2024. The prohibited-practice bans and AI-literacy duties applied first, in early 2025. Rules for general-purpose AI (GPAI) models followed in August 2025. The bulk of the high-risk obligations phase in across 2026 and 2027. Because exact application dates and transition periods have moved and may still be adjusted, do not commit budget against a specific date from memory — verify the current text of the Regulation and any Dutch implementing guidance before you plan around a deadline.
AI literacy is a live obligation, not a future one. Providers and deployers must ensure staff who work with AI systems have a sufficient level of understanding of how they work and their risks. For an MKB this is proportionate — a short internal training and a written policy, not a university course. Our guide to writing an AI policy covers what that document should contain.
The AI Act does not replace the AVG/GDPR — the two run in parallel. If your AI processes personal data (and most does), you still need a lawful basis, data-minimisation, and often a DPIA. The AI Act adds requirements on top; it does not subtract any privacy duty. Treat them as one combined programme, not two competing ones.
The fines are structured by severity. The top tier is up to €35 million or 7% of global annual turnover, whichever is higher, for engaging in prohibited practices. Lower tiers apply to other breaches. For an MKB the point is not the headline number but the principle: get the classification and documentation right and you stay well clear of enforcement.
A method any MKB can run:
That is a day of structured work for most MKB, not a compliance department. If you want a second pair of expert eyes on the classification, that is what our AI-for-MKB service is built for.
AI Act Check: €950 fixed, delivered in one week — including what you can safely ignore.
Book your AI Act Check →