On August 2, 2026, the EU AI Act reaches its next major milestone. For months, two narratives have been circulating: one promises a bureaucratic monster that forces expensive certifications on every company with a ChatGPT account. The other waves it off, claiming it only affects the big tech corporations. Both are wrong. Anyone in the SME sector who uses AI or plans to should know what actually applies. It is less than many fear, but it is not nothing.
At AI Værk, we don't just work on AI projects for small and medium-sized companies; we are also involved in political bodies dealing with regulation and European AI infrastructure. From this dual perspective, we want to put into context what the AI Act means in practice. This is explicitly not legal advice; in individual cases, the matter belongs with lawyers. But the underlying logic of the law can be understood without being an attorney.
The timeline, and what changed in 2026
The AI Act has been in force since August 1, 2024, but takes effect in stages. Since February 2, 2025, the prohibitions on certain practices have applied, such as social scoring or manipulative systems, along with the AI literacy obligation under Article 4. Since August 2, 2025, the rules for providers of general-purpose AI models, meaning the large foundation models, have been in effect. On August 2, 2026, the next stage follows: from then on, the transparency obligations of Article 50 apply, and the national supervisory authorities receive their full enforcement and sanctioning powers.
What matters is what changed this spring. With the so-called Digital Omnibus, the EU eased parts of the timeline in June 2026. The extensive obligations for standalone high-risk systems, which would originally have applied from August 2, 2026 as well, were postponed to December 2, 2027. For AI embedded in regulated products, such as machinery or medical devices, the date is now August 2, 2028 instead of 2027. So anyone who was under time pressure regarding high-risk requirements has gained some breathing room. Nothing was repealed: the obligations are coming, just later.
The logic behind it: risk-based, not blanket regulation
The AI Act does not regulate "AI" as a technology, but concrete use cases, tiered by risk. At the top are prohibited practices. Below them are high-risk applications, subject to strict requirements for data quality, documentation, human oversight, and risk management. Below those are systems with limited risk, for which essentially transparency obligations apply. And at the bottom, the large remainder, for which the AI Act imposes hardly any specific requirements.
This tiering is the reason the panic narrative doesn't hold up. A company that uses an AI assistant to draft emails, summarize meeting minutes, or sketch out proposal texts is not operating a high-risk system. It sits in the lowest or second-lowest tier, and there the obligations are manageable.
What concretely applies to most businesses
For the typical SME that uses AI tools rather than developing them, the obligations essentially come down to two things.
First, AI literacy under Article 4, which has already applied since February 2025: anyone deploying AI systems must ensure that the employees working with them have an adequate understanding. That does not mean every clerk must be able to explain neural networks. It means people should know what the tool can do, where it typically goes wrong, and which data may go into it. The Digital Omnibus recently softened the wording of this obligation somewhat; the basic idea remains, and it is simply sensible even without a law.
Second, the transparency obligations under Article 50, which take effect on August 2, 2026. Anyone operating a chatbot must make it clear that the person on the other end is talking to a machine, unless that is obvious anyway. Anyone publishing AI-generated content, especially deceptively realistic images, audio, or video, must label it as such. For systems already on the market before the deadline, there is a short transition period for the technical labeling requirements until early December 2026. None of this is a certification procedure; it is essentially honesty toward customers and the public.
The short version for most small and medium-sized businesses: from August 2026, the AI Act primarily requires that you know which AI you are using, that your people can handle it, and that you don't deceive anyone about where AI is involved. The heavy high-risk obligations only affect specific use cases, and for those, the deadline is now the end of 2027 anyway.
When you do slip into high-risk territory
The high-risk category is not a question of company size, but of use case. The most relevant scenario for SMEs is human resources: AI systems that filter applications, evaluate candidates, or prepare decisions about promotion and dismissal are explicitly classified as high-risk in Annex III of the law. The same applies, for instance, to creditworthiness assessments or systems in critical infrastructure. A twenty-person business that lets an AI tool pre-sort applicants is operating in a regulated area; a corporation that only uses AI for text drafts is not.
Anyone using or planning such applications doesn't need to abandon them immediately. But they should take the timeline until December 2027 seriously and clarify early on which requirements are coming their way, above all human oversight, documentation, and the question of whether the tool's provider is doing its homework.
Provider or deployer: the role question decides everything
The AI Act distributes obligations by role. The provider, meaning whoever develops an AI system and puts it on the market under their own name, carries the main burden: conformity assessment procedures, technical documentation, quality management. The deployer, meaning whoever uses a system professionally under their own responsibility, has considerably leaner obligations: use the system as intended, ensure the prescribed oversight, and exercise additional care with high-risk systems.
Most SMEs are deployers. But the line can shift: anyone who substantially modifies a purchased system, offers it under their own brand, or repurposes it for a high-risk use can end up in the provider role themselves, with all the consequences. Anyone developing their own AI products and selling them to customers is a provider in any case. This role clarification is not a formality; it is the point that determines which catalog of obligations applies at all.
A pragmatic approach
So what does this mean in concrete terms? From our perspective, four steps that won't overwhelm any company.
First, an honest inventory: which AI systems are actually in use in the company, including the unofficial ones? In our experience, this list is longer than management believes. Then the role and risk assessment: for each system, the question of whether you are a provider or deployer, and whether the use case falls into one of the high-risk categories. In the vast majority of cases, the answer is deployer and no, and then the largest part of the work is already done. Third, training: the employees who work with AI get a realistic picture of the tools' strengths, limits, and data rules. And fourth, lean documentation that records what is being used, for what purpose, and who is responsible. Not a hundred-page compliance manual, but a maintained overview you can show a regulator or a customer if needed.
Anyone who has completed these four things is well positioned for August 2026 and has also laid the groundwork in case a high-risk topic comes up later. Most of it is not a regulatory issue anyway, but simply a leadership one: knowing what is running in your own business.
Our core message is therefore unspectacular: no panic, but no looking away either. For the typical SME with sound process awareness, the AI Act is entirely manageable, and by postponing the high-risk deadlines, the EU has shown that it keeps feasibility in view. Anyone who ignores the rules still risks real sanctions from August 2026, because from then on the supervisory authorities can actually pursue violations. The effort of doing it right is, in most cases, small enough to simply get it done.
If you are unsure where your specific AI applications fall within this framework, we'll gladly work through it together in a conversation, soberly and without it having to turn into a major project.