EU AI Act for Small Firms: Your Obligations From 2026, Without the Panic

The EU AI Act has applied to small companies since August 2026. What a small firm actually has to do, what does not apply to you, and where the fines for SMEs really stand.

The EU AI Act (Regulation (EU) 2024/1689) has applied in most of its parts since August 2, 2026, and that includes small companies. There is no exemption based on company size. What there is, however: a short list of obligations for the typical small firm, and a long list of obligations that apply to someone else. Most articles of the regulation are aimed at companies that build AI systems, not at an eight-person tax firm using Copilot.

That distinction is missing from most coverage of the topic. The AI Act gets dismissed as a paper tiger, or someone waves the 35 million euro fine around. Both are misleading. Here is the sober version for small firms, tax advisors, and financial advisors.

Does the EU AI Act apply to small companies?

Yes. The regulation has no threshold based on headcount or revenue. A five-person firm falls within scope just like a corporation, as soon as it uses AI systems professionally.

What the regulation does have: different roles with different obligations. And that is where the real answer to “what does this mean for me” lives.

Provider or deployer: your role decides

The AI Act distinguishes primarily between providers and deployers. Providers develop AI systems or put them on the market under their own name. Deployers use AI systems under their own authority.

If your firm uses ChatGPT, Copilot, or Gemini, you are a deployer. Microsoft, OpenAI, and Google are the providers. The bulk of the heavy obligations in the AI Act (technical documentation, conformity assessment, CE marking, risk management systems) falls on providers. Not on you.

That is the most important message in this post: as a deployer of standard AI tools, you carry a small, well-defined slice of the obligations. Anyone telling you otherwise has not read the regulation, or profits from your fear.

The four risk classes in everyday firm life

The AI Act sorts AI systems by risk. For classifying your tools, this short version is enough:

Prohibited practices (since February 2025): social scoring, manipulative systems, emotion recognition in the workplace. Practically irrelevant for a normal firm, as long as nobody gets the idea to analyze employee moods with AI.

High-risk systems: AI in areas like hiring decisions, creditworthiness assessment, or the justice system. This is where the strict obligations apply. Whether you are affected depends on what you use the tool for, more on that below.

Transparency-obligated systems: chatbots and AI-generated content. If you run a chatbot on your firm’s website, visitors must be able to recognize they are talking to a machine. The mainstream vendor solutions have this built in.

Minimal risk: everything else. Drafts, summaries, research, translations. This is where the vast majority of AI use in small firms lands. The AI Act imposes no special requirements here beyond the general ones.

What a small firm concretely has to do

If your firm uses standard tools like Copilot or ChatGPT for drafts, summaries, and research, three obligations from the AI Act remain at the core:

First: the AI literacy obligation from Article 4. It has applied since February 2025 and has been enforced since August 2026. Your employees must understand which tools they use, how those tools handle data, and where the limits are. Training, records, done. I broke down the details in my post on the AI literacy obligation under Article 4.

Second: transparency where AI meets people. Client contact via chatbot must be recognizable as such. AI-generated images or videos that could pass as real must be labeled. Internal use of text tools is not affected.

Third: knowing what runs in your office. Not an explicit standalone obligation, but the precondition for everything else. Without a list of the tools in use, you can neither train your team nor judge whether a high-risk case exists. A documented approved-tool list plus an AI acceptable use policy covers this.

That is the normal case. No risk management system, no conformity assessment, no reporting duties.

When a small firm does slip into high-risk territory

High-risk is not a property of the tool. It is a property of the use case. The same software can be harmless or high-risk depending on what you use it for.

Two scenarios are realistic for small firms and advisory practices:

Personnel decisions. Using AI to filter applications, score candidates, or prepare decisions about promotion or termination puts you in high-risk territory under Annex III of the regulation. That includes tools that merely “pre-sort.”

Creditworthiness. AI-supported credit scoring of natural persons is high-risk. For financial advisors working with such tools, this is the point to check.

As the deployer of a high-risk system, obligations from Article 26 would apply: use the system according to the provider’s instructions, ensure human oversight by trained people, retain the automatically generated logs, and inform affected employees in advance. Manageable, but considerably more work. My honest recommendation for most small firms: keep AI out of personnel and credit decisions entirely. Then the question never comes up.

What does not apply to you

For completeness, because these points tend to show up in sales pitches:

  • No CE marking and no conformity assessment. That is the provider’s job.
  • No technical documentation of the AI model. Also the provider’s job.
  • No legally mandated “AI officer.” That role does not exist in the AI Act.
  • No registration of your firm in an EU database, as long as you do not deploy a high-risk system.

If someone sells you one of these as an obligation for your firm, ask for the article number.

Fines, realistically

The famous 35 million euros or 7 percent of global revenue from Article 99 applies to prohibited AI practices. For most other violations, the range is up to 15 million euros or 3 percent.

For small companies, the regulation contains a provision that is often overlooked: for SMEs, the lower of the two values applies, and fines must take the company’s economic viability into account. The regulation also requires sanctions to be proportionate.

That does not mean nothing can happen. It means the realistic danger for a small firm is not a million-euro fine. It is an audit where no training records, no policy, and no tool list exist. Exactly the things that can be fixed in days.

The GDPR remains your bigger construction site

To close, the framing I give most often in consultations: for a small firm, the GDPR is almost always more relevant in daily AI use than the AI Act. Data processing agreement, data location, legal basis, data protection impact assessment for AI tools, handling of client data. These questions come up with every tool, regardless of risk class.

The AI Act does not replace the GDPR, it adds to it. The good news: if you have done your GDPR homework for AI tools, you have covered most of the AI Act documentation along the way. For an overview of all deadlines this year, see my post on the 2026 AI compliance deadlines.

Five steps for this week

  1. Tool inventory: which AI tools are actually in use? Ask your employees, check browsers and installed software.
  2. Check use cases: is AI used anywhere for personnel or credit decisions? If so, stop it or set it up properly under Article 26.
  3. Write or update your acceptable use policy: one page, clear rules.
  4. Train the team: 60 minutes, document attendance.
  5. Check client touchpoints: if a chatbot is running, it must be recognizable as AI.

With that, a typical small firm meets its obligations under the AI Act. No panic, no massive budget.

The next step

If you are unsure where your firm stands, or you would rather not set up the points above yourself, get in touch. I will walk through your tool list, use cases, and documentation with you and tell you honestly what is necessary at your size and what is not.


Jose Lugo is a CISSP-certified AI compliance consultant based in Germany. He helps tax advisors, law firms, and financial advisors deploy AI tools in compliance with the GDPR and the EU AI Act.