The European regulation on AI does not transform all SMEs into compliance laboratories, but it requires knowing what uses exist, who carries them and what risk they create.
Map your tools, classify your use cases, then document decisions before the emergency decides for you.
1. Key figures
| Number | Source and date | Scope | Interpreting for an SME |
|---|---|---|---|
| Regulation (EU) 2024/1689 was published in the Official Journal on 12 July 2024 and entered into force on 1er August 2024 | EUR-Lex, regulation 2024/1689, consulted on 17 June 2026 | European Union | The text is already in force; the real question concerns the dates of application according to the obligations. |
| General application of the regulation begins on August 2 2026 | Article 113 of regulation 2024/1689 | European Union | SMEs must have an inventory and sorting of uses before this deadline, not after. |
| Prohibited AI practices apply as of February 2 2025 | Article 113 and article 5 of the regulations | AI systems falling under prohibited practices | Certain uses do not require better governance: they must be excluded. |
| Obligations for general purpose AI models apply from August 2 2025 | Article 113 of the regulations | GPAI model providers and chain players | SME users should especially look at contractual guarantees and supplier documentation. |
| Sanctions can reach 35 M EUR or 7 % of global annual turnover for certain violations | Article 99 of regulation 2024/1689 | Most serious offenses | Financial risk mainly concerns critical cases, but it requires proportionate governance. |
| 20 % of EU companies used AI in 2025, compared to 13 % in 2024 | Eurostat, "Use of artificial intelligence in enterprises", accessed on June 17 2026 | Companies with 10 employees and more in the EU | Adoption is growing faster than internal documentation; This is the gap to be filled. |
2. Introduction
An employee uses ChatGPT to write emails, marketing tests an image generator, HR filters applications with a SaaS, customer support connects a chat agent, the data team experiments with a churn score. Nothing seems spectacular.
However, the verdict is clear: the AI Act requires us to look at these uses as a portfolio of risks.
Most SMEs will not develop a foundation model, publish a general AI platform or submit technical documentation worthy of a large publisher. They will often be deployers, integrators or buyers of solutions. This role remains less burdensome than that of supplier, but it is not empty.
In 2026, the main change is in the proof. Who uses what? For what decision? With what data? Which supplier? What level of human supervision? What information given to users? What trace in the event of a dispute?
The point is not to panic. You have to organize.
3. Stakeholder Mapping: AI Office, General Purpose AI Models, and High-Risk Systems
The European Commission sets the framework and coordinates application. The AI Office, attached to the Commission, plays a central role for general-purpose AI models, codes of practice, technical expertise and consistency of the system.
National authorities, which still vary between Member States, will supervise local implementation, controls, complaints and certain sanctions. For French SMEs, the cro dialogue will also include CNIL benchmarks, cyber practices, RGPD requirements and sectoral rules.
Suppliers develop or bring to market AI systems. Deployers use these systems under their own operational responsibility. Importers and distributors are involved in the supply chain. An SME can occupy several roles: simple user of an AI SaaS, publisher of a product integrating an external model, or service provider who configures an agent for a client.
The tools involved vary: ChatGPT Enterprise, Claude, Gemini, Microsoft Copilot, Mistral, HR platforms, sales scoring, chatbots, call analytics, content generation, fraud detection, computer vision, personalization e-commerce, compliance tools or business co-pilots.
Without mapping, each use remains anecdotal. With it, the company can classify, prove and arbitrate.
4. Definition: AI Act, SMEs, risks and compliance
The European AI Act is a regulation that regulates artificial intelligence systems using a risk-based approach. It distinguishes in particular between prohibited practices, high-risk systems, transparency obligations, general-purpose AI models and uses with limited or minimal risk.
For an SME, compliance is therefore not about banning AI. It consists of identifying uses, qualifying the role of the company, verifying the risk category, documenting controls, informing people when necessary and monitoring suppliers.
Short definition: the AI Act transforms the use of AI into a subject of documented governance.
5. Why this matters now
The calendar makes the subject concrete. The bans began to apply on February 2 2025. Obligations for general purpose AI models started on August 2 2025. The general application arrives on August 2 2026. Certain high-risk systems integrated into regulated products have specific time limits until 2027.
This progressiveness can give an illusion of time. Above all, it produces a risk of catching up. AI uses quickly enter teams, sometimes without formal purchase: browser extensions, personal accounts, functions activated in SaaS suites, no-code automations, CRM plugins, HR tools or data analysis.
Eurostat observes a clear increase in European companies using AI in 2025. Governance maturity progresses more slowly. The gap creates a gray area: lots of use, little inventory, little evidence.
The text does not signify the end of the experiment. It requires us to distinguish between experimentation, business decisions and impactful automation.
6. SEO/GEO: what the contents should clarify
For SEO, the searches are practical: "am I affected?", "what obligations?", "what fines?", "what to do with ChatGPT?", "what dates?", "what is a high-risk system?". A helpful article answers without jargon.
For GEO, citability is based on autonomous blocks: absolute dates, sanction amounts, risk categories, roles, SME case examples, nearby regulatory sources. Generative engines must be able to take a sentence without taking it out of context.
AI compliance becomes a subject of explanation. Vague content provides little reassurance.
7. Recommended method
7.1. Inventory real uses
We start with uses, not with texts. List the AI tools in the teams: text generators, office assistants, dev co-pilots, scoring, chatbots, transcription, image analysis, CRM enrichment, Make or Zapier automations, AI modules in SaaS.
Each line must specify the owner, the supplier, the data processed, the objective, the users, the level of autonomy and the impacted decision.
7.2. Qualify the role of the company
A mid-sized company can be a deployer when using a third-party system, a provider when bringing an AI solution to market, or an integrator when configuring a service for its customers. This role changes obligations.
A consultant who installs a chatbot for a hotel, a startup which sells an HR analysis tool and a store which uses a writing assistant do not have the same exposure.
7.3. Classify risks
Classify each use: prohibited, high risk, specific transparency, limited risk, minimal risk. HR uses, education, access to certain essential services, sensitive scoring, biometrics and security require increased attention.
The classification must remain documented. One sentence in a Slack channel is not enough.
7.4. Check suppliers
Request available documents: system purpose, data, limits, security measures, logs, user information, contractual conditions, subcontracting, localization, RGPD compliance, AI Act commitments, audit rights when realistic.
For general purpose AI models, the SME does not always have access to all the details. It must at least verify public guarantees, contracts, security policies and usage limits.
7.5. Supervise human decisions
Human supervision must be concrete: who validates, at what time, with what information, according to what threshold? A human who automatically clicks "approve" does not supervise anything.
Sensitive cases require a procedure: weak signal, escalation, refusal of exit, dispute, correction, logging.
7.6. Train the teams
Training should not be limited to "writing good prompts". It must cover confidential data, bias, hallucinations, copyright, customer transparency, automated decisions, security, RGPD and internal responsibilities.
An organization of this size does not need an AI campus. It needs a short doctrine, read, applied and maintained.
7.7. Install a periodic review
Models change, SaaS add functions, teams invent uses. The review must therefore be regular: quarterly for sensitive uses, half-yearly for the rest, immediate in the event of a new critical tool.
Conformity comes alive. The register must follow.
8. Tips Logiks
We recommend starting with uses that affect a person, a decision or sensitive data. HR, customer relations, sales scoring, automated support, personalization, health data, finance, education and security must come before content experiments.
Second priority: distinguish individual use and business processes. An employee who uses an assistant to reformulate a note creates limited risk if the data is controlled. A system that sorts applications, recommends refusal or personalizes a price changes in nature.
Third point: keep track of arbitrages. Why was this case not classified as high risk? Why was this supplier chosen? What data was excluded? What information is given to the customer? This memory avoids facade conformity.
Finally, don't turn the AI Act into a global brake. The text especially pushes to professionalize uses. A well-framed AI can remain a profitable, concrete and measurable lever.
Useful compliance does not slow down innovation. She avoids improvisation.
9. Decision grid
| Category | SME Examples | Dominant requirement | Priority action |
|---|---|---|---|
| Minimal risk | Help with internal writing, summary of non-sensitive documents, brainstorming | Best practices and data security | Internal policy and short training |
| Transparency | Customer chatbot, synthetic content generation, interaction with AI assistant | Inform the user when required | Clear message, logs and human escalation |
| High risk potential | Recruitment, professional assessment, access to essential services, sensitive scoring | Risk management, data quality, supervision, documentation | Legal and supplier analysis before deployment |
| Prohibited practice | Prohibited behavioral manipulation, exploitation of vulnerabilities, certain biometric uses | Ban | Stop or exclude the use case |
| Integrated GPAI model | Product SaaS connected to external model | Check documentation, conditions and limits | Contract, monitoring, customer clauses |
10. Common mistakes
The first mistake is that the AI Act only concerns large publishers. An SME that deploys an AI tool in a sensitive process remains concerned.
The second consists of classifying a use too quickly as "simple productivity". Context matters: an internal summary is not worth an HR recommendation or credit score.
The third is to confuse AI Act compliance with RGPD compliance. The two cro interact, but do not replace each other. Data can be processed legally within the meaning RGPD and still produce an AI risk.
The fourth is to let teams purchase or activate AI functions without a registry. AI modules often arrive via update SaaS, without an official project.
The fifth is to write an internal policy that is too abstract. Teams need examples: what is allowed, prohibited, subject to validation, or reserved for approved tools.
11. 30 / 60 / 90-day action plan
11.1. days: inventory and freezing of obvious risks
We identify the tools used, sensitive cases, exposed data and critical suppliers. Prohibited or obviously risky practices are stopped. A short rule governs confidential data.
11.2. days: classification and evidence
We classify uses, document roles, request supplier information, add the necessary transparency notices, formalize human supervision and update critical contracts.
11.3. days: light governance
We install a living register, a periodic review, internal training, a request channel for new uses and a risk monitoring table. Management then has a clear vision.
12. FAQ
12.1. Is an SME that uses ChatGPT affected by the AI Act?
Yes, but the obligation depends on usage. An internal writing assistant does not have the same level of risk as a tool that influences a hiring, a rating, access to service or a customer decision.
12.2. Does the regulation require stopping the AI?
No. It imposes a risk-based approach. Certain uses are prohibited, others are strongly regulated, many remain possible with transparency, security and proportionate documentation.
12.3. Are marketing tools high risk?
Often no, but it depends on the context. Generating an ad or summarizing customer reviews generally remains less sensitive than individual scoring having a significant impact. However, personal data and transparency must be controlled.
12.4. What to do with HR tools integrating AI?
HR uses require increased vigilance. It is necessary to verify the supplier, the purpose, the biases, the human supervision, the information of the candidates, the documentation and the channels of dispute.
12.5. Who should manage the subject in an SME?
The management must have the arbitrage. Execution can involve DSI, DPO, HR, marketing, legal and business managers. The subject crosses the organization; he should not stay in just one department.
12.6. What evidence to keep?
Maintain inventory, classification, contracts, supplier documentation, internal policy, training, deployment decisions, incidents, human validations and periodic reviews. These elements show reasonable governance.
13. Conclusion
This European framework changes less the possibility of using AI than the way of governing it. For an SME, the subject is not to build a regulatory factory. It is a question of knowing where the uses are found, what risks they create, what evidence governs them and who assumes them.
A company that maps early maintains margin. A company that discovers its uses in the event of litigation is subject to the schedule.
AI ceases to be a scattered experiment. It becomes a governed asset.
14. Main sources
- EUR-Lex, Regulation (EU) 2024/1689 on artificial intelligence: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- European Commission, European regulatory framework for AI: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- European Commission, AI Office: https://digital-strategy.ec.europa.eu/en/policies/ai-office
- European Commission, AI Pact: https://digital-strategy.ec.europa.eu/en/policies/ai-pact
- European Commission, questions and answers on the AI Act: https://ec.europa.eu/commission/presscorner/detail/en/qanda_24_1683
- Eurostat, Use of artificial intelligence in businesses : https://ec.europa.eu/eurostat/statistics-explained/index.php?title=Use_of_artificial_intelligence_in_enterprises
- CNIL, artificial intelligence and RGPD: https://www.cnil.fr/fr/intelligence-artificielle
