Home / EU AI Act checklist for SMEs
Guide — EU AI Act for SMEs

The EU AI Act for SMEs: what you actually need to arrange (2026 checklist)

Most of what SMEs read about the AI Act is either panic or sales copy. The honest version: most small and mid-sized companies are 'deployers' with limited obligations — but the AI-literacy duty (Article 4) already applies to every company whose staff use AI, and the next wave of obligations starts on 2 August 2026. Here's the checklist, without the fear marketing.

Last updated: 11 June 2026

Free interactive tool

Not sure which risk tier applies to you?

Answer 4 questions and our EU AI Act risk checker classifies your AI system — prohibited, high, limited or minimal risk (plus GPAI) — with your obligations and the compliance deadline.

Summarize with AI Prompt copied — paste it into the chat
Share
In short

Most Dutch SMEs are 'deployers' of AI under the EU AI Act, with limited obligations. Two things matter now: the AI-literacy duty (Article 4) already applies to every organisation whose employees use AI tools like ChatGPT or Copilot, and the high-risk obligations start on 2 August 2026 (parts have been deferred by the EU's Digital Omnibus). Our fixed-price AI Act Check (€950) tells you in one week which category your AI use falls into and exactly what to arrange — and, just as often, what you can safely ignore.

Risk classes

What applies to whom: the four risk classes

The AI Act regulates uses of AI, not AI itself. Four classes decide your obligations:

ClassExamplesWhat it means for an SME
ProhibitedSocial scoring, manipulative AI, emotion recognition at workSimply don't. These are banned outright.
High-riskAI in recruitment/selection, credit scoring, safety componentsHeavy obligations (risk management, logging, human oversight). Most SMEs only touch this via HR tooling — check your recruitment software.
Limited riskChatbots, AI-generated contentTransparency: people must know they're talking to AI or seeing AI content.
Minimal riskSpam filters, spellcheck, most office AI useNo specific obligations — but Article 4 AI literacy still applies to your staff.
Checklist

The 8-point AI Act checklist for SMEs

The offer

AI Act Check — €950 fixed, one week

Our AI Act Check gives you certainty for a fixed €950 (ex VAT), delivered within one week: an inventory of your AI use, a risk classification per system, your role (provider/deployer) per system, an AI usage policy template tailored to your business, and a concrete to-do list — including what you can safely ignore. If training is needed, the SLIM subsidy often covers a substantial part of the cost. We are AI practitioners, not a law firm: for contested legal questions we'll tell you honestly when you need a lawyer.

Deadlines

The honest timeline (including what was postponed)

The AI Act entered into force in stages. Prohibitions and the Article 4 literacy duty already apply. The high-risk obligations become binding on 2 August 2026, but the EU's Digital Omnibus agreement (2026) deferred parts of the high-risk regime by 12–16 months for many categories. What this means in practice: the fear-marketing deadline is softer than advertised — but the literacy duty and transparency rules are not postponed, and they're the ones that actually touch most SMEs. Verify current status on the official implementation timeline; this page reflects the position at the 'last updated' date above.

First practical step for most SMEs: writing an AI usage policy.

The four risk tiers, and where MKB uses actually land

The EU AI Act is built on a risk pyramid. The obligations that apply to your business depend entirely on which tier each of your AI uses falls into — so this is the classification you must get right before anything else.

  • Unacceptable risk (prohibited). A short list of banned practices, including social scoring by public authorities, manipulative techniques that exploit vulnerabilities, and untargeted scraping of facial images to build recognition databases. If you are doing any of these, stop — no compliance paperwork makes them legal.
  • High-risk. AI used in sensitive domains: recruitment and CV-screening, credit scoring, biometric identification, and safety components of regulated products. This tier carries the heavy obligations — risk management, data governance, human oversight, logging, and conformity assessment.
  • Limited risk. Systems that interact with people or generate content. The obligation here is transparency, not a full compliance regime. Most customer-facing MKB automation lands here.
  • Minimal risk. Everything else — spam filters, inventory forecasting, most back-office automation. No specific obligations under the Act.

The honest reality for the typical Dutch MKB: most of your AI is minimal or limited risk. A chatbot, a document summariser, an email drafter, a forecasting model — these are not high-risk. You only enter high-risk territory when AI helps decide who gets hired, who gets credit, or who someone is (biometrics). If that describes you, treat it seriously. If it does not, do not let consultants sell you a high-risk compliance programme you do not need. Not sure where a specific use lands? That is exactly what an AI scan is for.

The transparency duties that touch almost every SME

Even at limited risk, three transparency obligations catch a huge share of ordinary businesses:

  • Label your chatbots and AI agents. When a person interacts with an AI system, they must be told — unless it is obvious from context. A support bot on your site needs to make clear it is a bot.
  • Mark AI-generated content. Synthetic text, images, audio, and video should be detectable as machine-generated, in a machine-readable way where feasible.
  • Disclose deepfakes. If you publish AI-generated or manipulated media that resembles real people or events, you must disclose that it is artificial.

These are low-effort but easy to forget. A one-line disclosure on your chatbot and a labelling habit for AI-produced marketing assets covers most of it.

The phased timeline — verify the current text

The Act does not switch on all at once; it phases in over several years. In broad strokes: it entered into force in August 2024. The prohibited-practice bans and AI-literacy duties applied first, in early 2025. Rules for general-purpose AI (GPAI) models followed in August 2025. The bulk of the high-risk obligations phase in across 2026 and 2027. Because exact application dates and transition periods have moved and may still be adjusted, do not commit budget against a specific date from memory — verify the current text of the Regulation and any Dutch implementing guidance before you plan around a deadline.

AI literacy, and how the Act sits alongside the AVG

AI literacy is a live obligation, not a future one. Providers and deployers must ensure staff who work with AI systems have a sufficient level of understanding of how they work and their risks. For an MKB this is proportionate — a short internal training and a written policy, not a university course. Our guide to writing an AI policy covers what that document should contain.

The AI Act does not replace the AVG/GDPR — the two run in parallel. If your AI processes personal data (and most does), you still need a lawful basis, data-minimisation, and often a DPIA. The AI Act adds requirements on top; it does not subtract any privacy duty. Treat them as one combined programme, not two competing ones.

Penalties, and a practical five-step method

The fines are structured by severity. The top tier is up to €35 million or 7% of global annual turnover, whichever is higher, for engaging in prohibited practices. Lower tiers apply to other breaches. For an MKB the point is not the headline number but the principle: get the classification and documentation right and you stay well clear of enforcement.

A method any MKB can run:

  • 1. Inventory. List every place AI touches your business — bought tools, embedded features, and anything you built.
  • 2. Classify. Assign each use to a tier: prohibited, high, limited, or minimal.
  • 3. Apply. Match the obligations to the tier — transparency labels for limited, the full regime only where you are genuinely high-risk.
  • 4. Document. Write down the inventory, the classifications, and your reasoning. Documentation is your defence.
  • 5. Assign an owner. One named person accountable for keeping the register current as tools and rules change.

That is a day of structured work for most MKB, not a compliance department. If you want a second pair of expert eyes on the classification, that is what our AI-for-MKB service is built for.

Buyer guides

Compare further

FAQ

Frequently asked questions

Does the EU AI Act apply to small companies?

Yes — but proportionally. Most SMEs are 'deployers' with limited obligations: AI literacy for staff (Article 4, already in force), transparency for chatbots and AI content, and care with AI in decisions about people. The heavy high-risk regime mostly concerns providers and specific uses such as recruitment screening or credit scoring.

What is the AI-literacy duty (Article 4)?

Article 4 requires every organisation that uses AI to ensure its staff have a sufficient level of AI literacy — understanding what the tools do, their risks and limitations. It already applies. There is no prescribed course; documented, role-appropriate training is the practical way to demonstrate compliance.

Does ChatGPT use by employees fall under the AI Act?

Using ChatGPT or Copilot makes your company a 'deployer' of a general-purpose AI system. That doesn't trigger high-risk obligations by itself, but Article 4 (AI literacy) applies, and you should have a usage policy governing what data staff may enter.

What fines can SMEs get under the AI Act?

Maximum fines are severe on paper (up to €15 million or 3% of turnover for high-risk violations), but the Act instructs regulators to weigh company size, and an amended SME framework provides reduced fines and simplified compliance. For a typical SME deployer, the realistic exposure is being unable to demonstrate literacy training or transparency — cheap to fix now, awkward to explain later.

What is an AI Act Check and what does it cost?

Crux Digits' AI Act Check is a fixed-price (€950 ex VAT) one-week assessment: an inventory of your AI use, risk classification per system, your role per system, a tailored AI usage policy template and a concrete to-do list — including what you can safely ignore.

Has the AI Act been postponed?

Partially. The EU's Digital Omnibus (2026) deferred parts of the high-risk regime by 12–16 months for many categories. The prohibitions, the Article 4 literacy duty and transparency rules were not postponed — those already apply.

Know where you stand in one week

AI Act Check: €950 fixed, delivered in one week — including what you can safely ignore.

Book your AI Act Check →