EU AI Act 2026: What SMEs need to know now
The EU AI Act is already in force. Article 4 has applied since February 2025. The high-risk obligations kick in from August 2026. Here's what SMEs need to do now.
Date: 11.02.2026 | Author: David Hefendehl
The EU AI Act and SMEs: what already applies and what you need to prepare for
Many SMEs are still waiting. They think the EU AI Act is a problem for 2026. For big corporations. For tech companies. Not for the engineering firm in Remscheid or the logistics company in Münster.
That assumption is wrong. The EU AI Act and SMEs have been directly linked since February 2025. Article 4 is already in force, and it applies to every company in the EU that uses AI, regardless of size. That includes you if you use ChatGPT for emails, use Copilot with your team, or screen job applicants with an AI tool.
Ignore this and you're taking on a real legal risk. Not some abstract regulatory warning sign. A genuine one.
What Article 4 has required of you since February 2025
Article 4 of the EU AI Act requires AI competence, or "AI literacy" as it's officially called. Every person in your company who uses, develops, or oversees AI systems needs sufficient knowledge and understanding of the AI systems in use.
Exactly what this looks like in practice is still evolving. But the principle is clear: you can't claim your staff had no idea how an AI tool works or what risks it carries. That's not an excuse anymore. It's a compliance failure.
In practice, this means training needs to be documented. Systems in use need to be logged. If it ever comes to an audit, you need to be able to show who does what with which tool.
The simplest first step is to take stock. Which AI tools are actually being used in your company, official and unofficial? Because as of February 2025 at the latest, shadow AI isn't just a productivity problem anymore, it's a compliance problem. I cover how widespread uncontrolled AI use is in German companies in my article on shadow AI in the workplace.
What's coming in August 2026
From August 2026, the full requirements for high-risk AI kick in. This is the category where things get expensive if you're not ready.
What counts as high-risk AI? The EU has a list. The key categories for SMEs under the EU AI Act:
- HR and recruitment: AI that filters job applications, assesses employees, or influences hiring decisions
- Lending and credit scoring: AI used to assess creditworthiness or solvency
- Critical infrastructure: AI in areas such as energy, water, or traffic control
- Safety-critical product components: AI in machinery, vehicles, or medical devices
If you operate in one of these areas and use AI, you'll fall into the high-risk category from August 2026. That means risk analysis, technical documentation, human oversight, transparency towards users, and registration in the EU database.
Important: a lot of manufacturing SMEs are affected here without realising it. If you use AI for quality control or in safety systems, you need to check whether those systems fall into the high-risk category.
The penalties that make the EU AI Act worth taking seriously
The EU AI Act imposes stricter penalties than the GDPR.
Breach the GDPR and you're looking at a fine of up to 4% of global annual turnover. Breach the EU AI Act and it's up to 7%.¹ For a company with 20 million euros in turnover, that's the difference between a maximum fine of 800,000 euros and 1.4 million euros. On top of that comes reputational damage, and no insurance covers that.
This isn't some academic worst-case scenario. It's the framework the EU has set for high-risk AI. Experience with the GDPR shows the pattern: warnings first, then fines, and that hits companies of every size.
What the "Digital Omnibus" means for you
The European Commission has recognised that the EU AI Act can be disproportionately burdensome for smaller businesses. The "Digital Omnibus" is an ongoing legislative initiative aimed at simplifying requirements for SMEs in certain areas.
What's likely to be simplified: documentation requirements for certain low-risk systems, registration requirements for smaller high-risk AI applications, and transition periods for systems already in use.
What won't be simplified: the fundamental requirements on AI competence set out in Article 4, the bans on certain AI practices (social scoring, manipulative systems), and the core principles of transparency and human oversight.
The Digital Omnibus isn't a free pass. It eases the bureaucratic burden, not the actual requirements.
EU AI Act and SMEs: the three steps that matter now
Preparing for the EU AI Act doesn't have to be a year-long project. Here are three steps you can take right now:
Step 1: build an AI inventory. Which AI tools are used in your company? By whom? For what purposes? This includes both officially procured tools and shadow AI. Without this inventory, any further compliance work is built on shaky ground. This step costs very little time and gives you a clear picture of where you stand.
Step 2: run a risk categorisation. Which tools fall into which risk category? ChatGPT for internal summaries counts as low risk. A CV screening tool for job applications is potentially high risk. So is an AI-supported quality control system in production. You need this classification to know exactly what obligations apply to you.
Step 3: document training. Article 4 requires AI competence. Document who received which training and when. That evidence is the difference between "we took care of it" and a compliance failure that's hard to explain away.
I explain how to introduce AI in a structured way, building in compliance from day one instead of bolting it on later, in my article on AI strategy for SMEs.
Why waiting will cost you more this time
The GDPR caught a lot of companies off guard in 2018. Despite a two-year transition period, a large share of German companies still weren't ready by May 2018. Fixing things after the fact cost many times more than preparing early would have.
With the EU AI Act, the difference is right there on the table. Lay the groundwork now, AI inventory, risk assessment, documented training, and it costs you a few working days. Wait until summer 2026 and you risk the same mistake as 2018. Except this time the fines are higher.
The first step costs very little. An honest stock-take: which AI systems are in use, and which category does each fall into? Once you've done that, you'll know where you stand.
Your next step
Want to know where your business stands on the EU AI Act and what to actually do about it? Get in touch. I'll help you ask the right questions and build a framework before August 2026 arrives.
¹ Regulation (EU) 2024/1689 (EU AI Act), Article 4 (AI competence) and Article 99 (penalties of up to 7% of global annual turnover); Regulation (EU) 2016/679 (GDPR), Article 83 (penalties of up to 4% of global annual turnover), eur-lex.europa.eu