EU AI Act for European SMEs: Obligations, Penalties, and the Compliance Path
A structured reference for founder-led and operations-heavy businesses preparing for the EU AI Act's high-risk deadline of 2 December 2027, covering deployer obligations, penalties, ISO/IEC 42001 governance, and the practical three-step compliance path.
EU AI Act Obligation Timeline for European SMEs
Key dates and requirement levels for the EU AI Act, from Article 4 AI literacy (already in force) to Annex III high-risk system obligations (December 2027, as amended by Regulation (EU) 2026/1744). For SMEs the lower of the two penalty amounts applies (Article 99(6)).
| Obligation | Basis | Enforceable from | Who it applies to | Non-compliance penalty |
|---|---|---|---|---|
| AI literacy measures for staff | Article 4 EU AI Act | 2 February 2025 | All employers whose staff use in-scope AI | No specific fine in Article 99; set by national law |
| Ban on prohibited AI practices | Article 5 EU AI Act | 2 February 2025 | All providers and deployers | Up to 35M euros or 7% global turnover |
| Transparency for chatbots, voice agents and AI-generated content | Article 50 EU AI Act | 2 August 2026 (not postponed) | Providers and deployers of customer-facing or generative AI | Up to 15M euros or 3% global turnover |
| High-risk system deployer obligations | Article 26 EU AI Act | 2 December 2027 (moved from 2 August 2026) | Companies using Annex III AI from vendors | Up to 15M euros or 3% global turnover |
| Annex III category: AI in employment | Annex III EU AI Act | 2 December 2027 (moved from 2 August 2026) | HR/recruitment tools using AI | Up to 15M euros or 3% global turnover |
| Annex III category: access to essential services | Annex III EU AI Act | 2 December 2027 (moved from 2 August 2026) | Finance, insurance, credit tools using AI | Up to 15M euros or 3% global turnover |
| GDPR Article 28 DPA with AI vendors | GDPR / EU AI Act intersection | Already enforceable | All companies using AI SaaS vendors | GDPR penalties (up to 20M euros or 4% turnover) |
| ISO/IEC 42001 AI governance standard | ISO/IEC 42001:2023 | Voluntary (recommended before Dec 2027) | SMEs seeking structured governance | N/A, voluntary but audit-ready |
Frequently Asked Questions
Key EU AI Act obligations for European SMEs: timelines, deployer vs. provider distinctions, and the role of ISO/IEC 42001.
What does the EU AI Act actually require SMEs to do, and by when?
The EU AI Act creates a tiered obligation structure. The first tier, in force since 2 February 2025, is Article 4: since the July 2026 amendment (Regulation (EU) 2026/1744), every employer whose staff use AI systems within the Act's scope must take measures to support the development of AI literacy among those staff. The earlier wording required employers to 'ensure' a sufficient level. No training certificate is required. You are judged on the measures you took, so keep a record of who uses AI, for what decisions, and what training they received on the tool's limitations and failure modes. If your company uses any AI-assisted tool in HR, finance, customer service, or legal review without such a record, you have nothing to show an authority that asks. The second tier is Article 50 transparency, in force since 2 August 2026 and not postponed: people must be told when they are talking to a chatbot or voice agent, and deepfakes must be disclosed. The third tier now applies from 2 December 2027, after the amendment moved it from 2 August 2026, and covers providers and deployers of high-risk AI systems. Annex III of the EU AI Act defines the categories that matter for most SMEs: AI used in employment decisions (CV screening, performance ranking, promotion decisions), access to essential services (credit scoring, insurance underwriting, loan pricing), and critical infrastructure management. The distinction between 'provider' and 'deployer' is critical here. Most SMEs are deployers, they use a vendor's AI product rather than developing AI themselves. Deployer obligations under Article 26 include using the system according to the provider's instructions, implementing human oversight, monitoring operation, keeping logs, informing workers, and reporting serious incidents. Conformity assessment, CE marking and technical documentation are provider duties. Your vendor's CE mark or conformity declaration does not automatically cover your deployer obligations. Penalties for prohibited AI practices under Article 5, including social scoring and subliminal manipulation, reach 35 million euros or 7% of global annual turnover. Non-compliance with high-risk system rules under Article 26 carries penalties up to 15 million euros or 3% of global annual turnover. For SMEs the lower of the two amounts applies (Article 99(6)). The practical compliance path for a 10-250 person SME: first, inventory all AI tools and classify against Annex III; second, run and document Article 4 AI literacy measures for all staff who use in-scope AI systems; third, commission a structured AI Operations Audit to identify which tools require formal governance documentation. Mittelstand-Digital, the German government's SME digital programme, offers free readiness workshops as a starting point.
Are most SMEs providers or deployers under the EU AI Act, and does it matter?
The distinction matters a great deal. A provider under the EU AI Act is an organisation that develops an AI system and places it on the market, for example, an HR software company that builds a CV-ranking algorithm and sells it to employers. A deployer is an organisation that uses a provider's AI system in the course of its own business activities. Most SMEs with 10-250 employees are deployers, not providers. The significance is that providers carry the heaviest obligations: pre-market conformity assessment, technical documentation, registration in the EU AI Act database, and CE marking. Deployers carry a separate but still substantial set of obligations under Article 26: they must follow the provider's instructions for use, implement the required human oversight measures, log incidents, inform the provider if they identify a serious risk, and maintain records of use. A deployer cannot discharge these obligations simply by signing the vendor's terms of service or relying on a vendor-provided conformity declaration. The deployer is responsible for ensuring human oversight is actually implemented in their own workflows. The practical implication for SMEs using vendor AI tools in HR, finance, or customer-facing processes: review your vendor contracts for EU AI Act compliance clauses, ask the vendor in writing how it classifies the system and when its conformity assessment and EU declaration of conformity will be finished (providers now have until 2 December 2027), and document your own human oversight procedure for each AI-assisted decision. An AI Operations Audit is the fastest way to produce this documentation in structured form. For SMEs that also supply larger enterprise customers, the deployer compliance posture increasingly affects procurement eligibility; enterprise procurement teams are beginning to require vendor AI governance evidence as a condition of supplier onboarding.
What is ISO/IEC 42001:2023 and do SMEs need it for EU AI Act compliance?
ISO/IEC 42001:2023 is the first international standard for AI Management Systems, published by the International Organization for Standardization in December 2023. It specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system within an organisation, covering AI governance, risk management, impact assessment, and responsible AI practices. It is not legally required by the EU AI Act, but it is the most widely recognised governance scaffold for demonstrating compliance with both the EU AI Act's deployer obligations and broader AI governance expectations from enterprise customers. For SMEs, the practical value of ISO/IEC 42001:2023 is that it is significantly lighter than a full NIST AI RMF 1.0 implementation while covering the same core governance domains: risk classification, human oversight, incident management, and transparency. It also maps cleanly onto ISO 9001 (quality management) and ISO 27001 (information security management), certifications that many European Mittelstand companies already hold. The AI Act's deployer obligations under Article 26 do not require ISO/IEC 42001 certification explicitly. What they require is use according to the provider's instructions, documented human oversight, monitoring, and retained logs. ISO/IEC 42001 provides the structural framework for producing and maintaining this documentation in an auditable form. Companies that implement ISO/IEC 42001 well before 2 December 2027 will be in a materially stronger position than those relying on ad hoc documentation approaches, both with national enforcement bodies and with enterprise customers requiring supply-chain AI governance evidence. A structured AI Operations Audit is the recommended precursor to ISO/IEC 42001 implementation: the audit identifies which AI systems require governance documentation, which processes need human-in-the-loop design, and where ISO/IEC 42001 controls add the most compliance value for the lowest implementation cost.
Map your EU AI Act obligations before December 2027
Vectimo's AI Operations Audit is the structured diagnostic step before any compliance or implementation decision. Two weeks, fixed scope, 2,500 euros flat, no retainer required. Our lead consultant spent 14 years at one of Europe's largest mobility companies, most recently as Director of AI Strategy & Delivery. The audit classifies your current AI tools against Annex III, identifies Article 4 AI literacy gaps, reviews your GDPR Article 28 vendor obligations, and produces a governance roadmap that maps to ISO/IEC 42001:2023. No upsell until you see the roadmap.