Every time a new piece of EU legislation appears, the SME reaction is the same: either panic ("this is going to cost us a fortune") or denial ("that's for the big companies"). With the EU AI Act, both reactions miss. It doesn't force you to build a compliance department, nor can you ignore it if you use AI with customers or employees. The key is understanding what actually applies to you.
(This isn't legal advice: it's a guide to knowing where to start and when to call the right people.)
The core idea: it's regulated by risk, not by technology
The Act doesn't say "AI is dangerous". It classifies uses by the risk they pose to people. The same kind of technology can be irrelevant in one case and closely watched in another. What matters isn't which model you use, but what you use it for.
- Unacceptable risk: prohibited uses (for example, scoring people socially). They simply can't be done.
- High risk: sensitive uses — recruitment, granting credit, certain fields — with strong obligations of oversight and documentation.
- Limited risk: mainly a transparency obligation (warning that someone is interacting with an AI, or that content is generated).
- Minimal risk: most office uses. Practically no specific obligations.
What actually applies if you're an SME
Most SMEs operate in minimal or limited risk. There, the obligations are reasonable:
- Transparency: if a customer talks to a chatbot, they should know it's an AI. If you publish generated content, in certain cases you have to indicate it.
- Human oversight in decisions that affect people: an AI can help filter CVs, but the decision with real impact needs a person behind it.
- Knowing what you use: being clear on what AI tools exist in the company, for what, and with what data. Without this inventory you can't prove anything.
What it does NOT require (and they scared you with it)
You don't need an ethics committee, or continuous external audits, or to stop your current tools, if your uses are minimal risk. Using an assistant to draft emails or summarise meetings doesn't turn you into a high-risk AI operator. The expensive mistake is the opposite: applying high-risk obligations to yourself that don't apply, and slowing the business out of fear.
The Act doesn't reward whoever uses the least AI. It rewards whoever knows what they use, for what, and can prove it. That, on top of everything, is good management with or without regulation.
Where the real risk is for an SME
The problem usually isn't the flashy use, but the invisible one: the salesperson pasting customer data into a free tool, the department using AI to pre-select candidates with no oversight, sensitive information travelling to places with no control. None of that shows up on an org chart, but all of it is exactly what the regulation — and GDPR before it — asks you to watch.
The three steps to comply without the stress
1. Inventory: make the real list of what AI is used in your company, official and unofficial, and for what. 2. Classify: mark each use by risk level. Most will fall into minimal; the few sensitive ones (people, credit, data) are the ones to look at closely. 3. Document and oversee: in uses that affect people, keep evidence that there's human control and transparency.
None of the three requires a big-company budget. It requires order — the same order that, as it happens, makes AI perform better. Complying with the Act and using AI well aren't two projects: they're the same one, seen from two angles.
Shall we apply it to your case?
The 360° AI Audit turns these ideas into a concrete plan for your company: three weeks, fixed price and the full picture of your AI before spending a euro.
See the 360° Audit→ Let's talk↗