Every time a new piece of EU legislation appears, the SME reaction is the same: either panic ("this is going to cost us a fortune") or denial ("that's for the big companies"). With the EU AI Act, both reactions miss. It doesn't force you to build a compliance department, nor can you ignore it if you use AI with customers or employees. The key is understanding what actually applies to you.
(This isn't legal advice: it's a guide to knowing where to start and when to call the right people.)
The core idea: it's regulated by risk, not by technology
The Act doesn't say "AI is dangerous". It classifies uses by the risk they pose to people. The same kind of technology can be irrelevant in one case and closely watched in another. What matters isn't which model you use, but what you use it for.
- Unacceptable risk: prohibited uses (for example, scoring people socially). They simply can't be done.
- High risk: sensitive uses — recruitment, granting credit, certain fields — with strong obligations of oversight and documentation.
- Limited risk: mainly a transparency obligation (warning that someone is interacting with an AI, or that content is generated).
- Minimal risk: most office uses. Practically no specific obligations.
What actually applies if you're an SME
Most SMEs operate in minimal or limited risk. There, the obligations are reasonable:
- Transparency: if a customer talks to a chatbot, they should know it's an AI. If you publish generated content, in certain cases you have to indicate it.
- Human oversight in decisions that affect people: an AI can help filter CVs, but the decision with real impact needs a person behind it.
- Knowing what you use: being clear on what AI tools exist in the company, for what, and with what data. Without this inventory you can't prove anything.
What it does NOT require (and they scared you with it)
You don't need an ethics committee, or continuous external audits, or to stop your current tools, if your uses are minimal risk. Using an assistant to draft emails or summarise meetings doesn't turn you into a high-risk AI operator. The expensive mistake is the opposite: applying high-risk obligations to yourself that don't apply, and slowing the business out of fear.
The Act doesn't reward whoever uses the least AI. It rewards whoever knows what they use, for what, and can prove it. That, on top of everything, is good management with or without regulation.
Where the real risk is for an SME
The problem usually isn't the flashy use, but the invisible one: the salesperson pasting customer data into a free tool, the department using AI to pre-select candidates with no oversight, sensitive information travelling to places with no control. None of that shows up on an org chart, but all of it is exactly what the regulation — and GDPR before it — asks you to watch.
The three steps to comply without the stress
1. Inventory: make the real list of what AI is used in your company, official and unofficial, and for what. 2. Classify: mark each use by risk level. Most will fall into minimal; the few sensitive ones (people, credit, data) are the ones to look at closely. 3. Document and oversee: in uses that affect people, keep evidence that there's human control and transparency.
What dates should be on your calendar?
The Act does not land all at once: it rolls out in phases, and each phase activates different obligations. What matters for an SME is knowing what applies now and what comes next.
- From February 2025 — unacceptable-risk practices are banned (manipulation, social scoring). If you were not using them, nothing changes.
- From August 2025 — obligations for general-purpose AI models. This mostly affects providers; you, as a user, only indirectly.
- From August 2026 — the bulk: transparency, human oversight and the high-risk system obligations. This is the date an SME should care about.
- Until 2027 — extended deadlines for high-risk systems embedded in regulated products.
The practical reading: the time for "I will look at it later" is over. What you do this year is what the full-application date will find.
What are the penalties (and which could actually reach you)?
The fines look scary on paper: up to €35 million or 7% of global turnover for the most serious infringements. But read them calmly.
- Prohibited practices: up to €35M or 7% of turnover. Almost impossible for an SME to fall here unknowingly.
- Breaching high-risk obligations: up to €15M or 3%. Applies if you use AI in recruitment or credit decisions without oversight or documentation.
- Incorrect information to authorities: up to €7.5M or 1%.
The Act explicitly provides proportionate penalties for SMEs: the percentage or the fixed amount applies, whichever is LOWER. The real risk for an SME is not the million-euro fine: it is the uncomfortable inspection, the corporate client that demands compliance before signing, and the cost of fixing in a hurry what you could have organised calmly.
How does it affect each area of your company?
- Human resources: the most sensitive area. Filtering CVs or evaluating performance with AI is high risk: it demands documented human oversight. If your HR software "scores" candidates, ask your vendor how it complies.
- Customer service: chatbots = transparency. The customer must know they are talking to a machine. A clear notice is enough; hiding it is a direct infringement.
- Marketing: AI-generated content generally does not require labelling, but deepfakes and ads simulating real people do. And GDPR still governs the data you use for targeting.
- Administration and finance: customer scoring and credit decisions with AI fall under high risk. Automating reconciliations or internal forecasts, on the other hand, is minimal risk.
Minimal checklist to sleep well
1. Inventory of AI tools in use, official and unofficial, and what data they touch. 2. Classification of each use by risk (most: minimal). 3. Transparency switched on where it applies: identified chatbots, labelled sensitive content. 4. Documented human oversight in decisions about people. 5. One page summarising all of the above, with a named owner. That is what you will show if anyone asks.
Frequently asked questions
Does the EU AI Act apply to my SME even if we only use ChatGPT?
Yes, but with minimal obligations. Using AI assistants to draft or summarise is minimal risk: no specific documentation required. Transparency applies if you publish sensitive generated content and, always, GDPR governs the data you type in.
Do I need to hire an AI officer or a consultant to comply?
It is not mandatory. For minimal-risk uses, an inventory, common sense and transparency are enough. External help pays off when you use AI in decisions about people (HR, credit) or want it audit-ready once and for all.
What if I use a tool from a vendor that does not comply?
Responsibility is shared: the provider answers for the system and you for how you use it. In practice: ask your vendors for their compliance documentation and keep the trail. If a vendor cannot produce it, that is a signal.
Is the Spanish AI law different from the EU regulation?
The Act is directly applicable across the EU with no national law needed. Spain adds the supervision structure (AESIA) and may develop specific aspects, but the obligations that affect you come from the European text.
None of the three requires a big-company budget. It requires order — the same order that, as it happens, makes AI perform better. Complying with the Act and using AI well aren't two projects: they're the same one, seen from two angles.
Shall we apply it to your case?
The 360° AI Audit turns these ideas into a concrete plan for your company: three weeks, fixed price and the full picture of your AI before spending a euro.
See the 360° Audit→ Let's talk↗