← Back to Playbooks

Part 1 — The EU AI Act for SMBs

What the 2026 changes actually mean for a company your size

The EU AI Act applies to an SMB the same way it applies to anyone: by your role in the chain and the risk tier of what you use, not by headcount. That sentence explains why the same regulation is nearly invisible to one company and heavy for another of identical size.

Two axes decide it. First, role. Are you a provider — building or placing an AI system on the market — or a deployer, using someone else’s? Most SMBs are deployers: a CRM’s AI feature, ChatGPT or Claude for content, a support chatbot. Then risk tier: unacceptable, high-risk, limited, or minimal. Most SMB deployments land in limited or minimal, where the obligation is mostly transparency — a chatbot says it’s AI, generated media is labeled where it would otherwise mislead. The heavy machinery (technical documentation, conformity assessment, registration in an EU database) attaches to providers and deployers of high-risk systems: credit scoring, hiring and screening, biometric identification.

So the honest answer to “are we affected” is yes, usually at the transparency end rather than the conformity-assessment end.

What changed in May 2026

The EU agreed a simplification package on May 7, 2026 — the Digital Omnibus — and it moved both the timeline and the burden for smaller companies.

A short list stays fully regulated whatever your size: law enforcement, biometric identification in public spaces, critical infrastructure safety, and the administration of justice.

Separate from the SMC change, there is machinery built specifically for SMEs: free priority-access regulatory sandboxes in each Member State, conformity-assessment fees required to be proportional to size, simplified documentation templates that national authorities must accept from small and micro enterprises, dedicated communication channels and awareness programs per Member State, and SME representation in the standard-setting bodies and the AI Act advisory forum.

What to do about it this year

  1. Inventory what AI you use or provide, and tag each by role — provider or deployer — and rough risk tier.
  2. For anything that looks high-risk, check whether your size now qualifies for the SMC self-assessment path. That is a materially lighter lift than the original text required.
  3. If you’re borderline high-risk, don’t wait for the December 2027 deadline to start. Firms tracking this warn that notified-body capacity for third-party assessment will tighten as 2027 approaches; beginning in Q3 2026 avoids the crunch.
  4. Expect more detail through 2026. The Commission is still issuing implementing guidance, so treat today’s position as a moving one.

This is general information, not legal advice. If you’re genuinely borderline on the SMC thresholds, or building anything that touches a high-risk category, confirm your position with counsel.

Sources: A Small Business Guide to the AI Act; the EU AI Omnibus SMC exemptions; White & Case on the Digital Omnibus deal.