2 August 2026 and your 40-person company: what the EU AI Act really asks of SMEs
On 2 August 2026 the transparency obligations of Article 50 start to apply. For small and mid-sized companies, though, the real news is a different one: the demanding high-risk machinery will not usually touch you — while two obligations have been binding since 2 February 2025. This article separates deployer duties from provider duties, works through the SME-specific fine rule in Article 99(6), and ends with a table you can fill in this afternoon.
"Deployer" or "provider" — this one question decides almost everything
The EU AI Act allocates duties by role, not by company size. Article 3 distinguishes the provider — whoever develops an AI system, or has one developed, and places it on the market or puts it into service under their own name or trademark — from the deployer, defined as a natural or legal person "using an AI system under its authority", except where the use is a personal, non-professional activity. If you subscribe to ChatGPT Business, switch on Microsoft 365 Copilot or run a bought-in website chatbot, you are a deployer. That is the role almost every SME occupies.
That distinction is not a formality; it is the lever that cuts the workload by an order of magnitude. The Regulation's heavy obligations — risk management system, data governance, technical documentation, conformity assessment, CE marking — are addressed to providers of high-risk systems. As a deployer you have a markedly shorter list to work through.
You use somebody else's AI system under your own authority.
- Ensure AI literacy among your staff (Art. 4)
- Refrain from prohibited practices (Art. 5)
- Disclose deep fakes and published AI-generated text (Art. 50(4))
- Inform people exposed to emotion recognition (Art. 50(3))
- Inform workers before high-risk use at the workplace (Art. 26(7))
You develop an AI system or place it on the market under your own name.
- Risk management system across the full lifecycle (Art. 9)
- Data governance and scrutiny of training data (Art. 10)
- Technical documentation and logging (Arts. 11, 12)
- Conformity assessment, CE marking, EU database
- Machine-readable marking of synthetic content (Art. 50(2))
What has applied since 2 February 2025: AI literacy under Article 4
Article 4 is the duty most often overlooked — probably because it consists of a single sentence: "Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf" — taking into account their technical knowledge, experience, education and training, and the context of use.
Three things about it matter for SMEs. First, the duty expressly binds deployers, not only providers. Second, it has applied since 2 February 2025 — not from August 2026. Third, Article 4 contains no headcount or turnover threshold; it bites from the first person who operates an AI system at work.
The phrase "to their best extent" is the proportionality anchor. Nobody expects a 40-person company to build a training curriculum; what is expected is a traceable measure proportionate to the risk. What counts is evidence: if you cannot produce anything when asked, from an authority's perspective you did nothing.
- A 60-minute briefing per team: which systems are approved and which are not.
- A one-page usage rule: which data must never go into an external system — HR records, client data, source code, unpublished figures.
- A short section on hallucinations and the duty to check outputs before using them.
- An attendance list with a date — that is your evidence.
- A repeat for every new tool, and for new joiners during onboarding.
2 August 2026: which paragraphs of Article 50 hit you
Article 50 is usually summarised as "the transparency obligation". In fact it contains four duties with different addressees — and only two of them are aimed at deployers.
Paragraph 1 — informing people that they are dealing with an AI system — and paragraph 2 — machine-readable marking of synthetic content — address providers. If you buy in a chatbot, designing that disclosure is your supplier's job. Yours is to hold them to it in the contract or product documentation — and not to configure the notice away.
Paragraphs 3 and 4 hit you directly. Paragraph 3: whoever operates an emotion recognition or biometric categorisation system must inform the natural persons exposed to it. Paragraph 4: whoever uses AI to generate or manipulate image, audio or video content constituting a deep fake must disclose that the content is artificially generated or manipulated. A corresponding duty applies to AI-generated text published to inform the public on matters of public interest — it falls away where the content underwent human review and a natural or legal person holds editorial responsibility.
Paragraph 5 requires that this information be provided in a clear and distinguishable manner, at the latest at the time of the first interaction or exposure. The provider marking duty in paragraph 2 follows only on 2 December 2026 after the Digital Omnibus amendment.
| Paragraph | Addressee | What is required | Applies from |
|---|---|---|---|
| 50(1) | Provider | Design AI systems that interact directly with people so the AI interaction is recognisable | 2 Aug 2026 |
| 50(2) | Provider | Mark synthetic audio, image, video and text output as AI-generated in a machine-readable format | 2 Dec 2026 |
| 50(3) | Deployer — that is you | Inform the people exposed to emotion recognition or biometric categorisation | 2 Aug 2026 |
| 50(4) | Deployer — that is you | Disclose deep fakes; label published AI text on matters of public interest | 2 Aug 2026 |
| 50(5) | Both | Information given clearly and distinguishably, at the latest at first interaction or exposure | 2 Aug 2026 |
- 2 Feb 2025Article 4 (AI literacy) and Article 5 (prohibited practices) — binding on the smallest business too
- 2 Aug 2025The Article 99 penalty regime applies — including the SME rule in paragraph 6
- 2 Aug 2026NewArticle 50 transparency obligations — for deployers, above all paragraphs 3 and 4
- 2 Dec 2026Machine-readable marking by providers (Art. 50(2)) and the new Article 5 prohibitions
- 2 Dec 2027High-risk obligations for standalone Annex III systems — including the deployer duties in Article 26
Two prohibitions that bite in small companies too
Article 5 bans certain AI practices outright — regardless of risk class, company size or role. A prohibition is not a requirement you can document your way through; it is a hard line, and it carries the Regulation's highest fine tier.
For mid-sized companies, Article 5(1)(f) is the most practically relevant point. It prohibits the use of AI systems "to infer emotions of a natural person in the areas of workplace and education institutions", except where the system is intended to be put in place for medical or safety reasons. Tools that infer employee mood from voice, face or text therefore fall under the ban — including when they are sold as a productivity or wellbeing feature.
The second relevant point is (a) and (b): AI systems deploying subliminal, purposefully manipulative or deceptive techniques, or exploiting vulnerabilities due to age, disability or a specific social or economic situation, in order to materially distort behaviour and thereby cause significant harm. That is the line at which aggressive marketing personalisation needs checking.
What does not apply to you — and what that saves
The list of what does not apply matters as much as the list of duties. Articles 9 to 15 — risk management system, data governance, technical documentation, logging, accuracy and robustness requirements — along with conformity assessment, CE marking and registration in the EU database are addressed to providers of high-risk systems. The Digital Omnibus amendment also pushed those duties to 2 December 2027, and to 2 August 2028 for embedded Annex I systems.
The much-cited relief article is narrower than its reputation too: Article 63 lets microenterprises without partner or linked enterprises comply with certain elements of the Article 17 quality management system in a simplified manner. Paragraph 2 makes clear that no other requirement of the Regulation is affected — Articles 9 to 15, 72 and 73 remain fully applicable. So the relief only helps if you are a provider of a high-risk system in the first place.
Conversely, there is support you are entitled to. Article 62 obliges Member States to give SMEs and start-ups with a registered office or branch in the Union priority access to AI regulatory sandboxes, to run awareness-raising and training tailored to applying the Regulation, and to use dedicated channels for advice and queries. Paragraph 2 requires conformity assessment fees for SME providers to be reduced proportionately to their size.
- Article 4 — AI literacy, in force since 2 February 2025
- Article 5 — prohibited practices, likewise since 2 February 2025
- Article 50(3) — notice for emotion recognition and biometric categorisation
- Article 50(4) — disclosure for deep fakes and published AI text
- Article 26(7) — informing workers before high-risk use (from 2 December 2027)
As long as you do not provide a high-risk system and Article 25 does not bite.
- Risk management system under Article 9
- Data governance and training-data scrutiny under Article 10
- Technical documentation under Article 11 and logging under Article 12
- Conformity assessment, CE marking and registration in the EU database
- Notified body, EU declaration of conformity, authorised representative in the Union
The SME rule on fines: Article 99(6)
The three fine tiers in Article 99 are almost always quoted with the big numbers: up to EUR 35M or 7% of worldwide annual turnover for prohibited practices under Article 5, up to EUR 15M or 3% for most other breaches, and up to EUR 7.5M or 1% for incorrect, incomplete or misleading information supplied to authorities or notified bodies. For companies, the rule is generally whichever amount is higher.
For SMEs, paragraph 6 inverts that rule: "In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to" — whichever of them is lower. That is not a detail; it is the difference between a six-figure ceiling and a fixed amount in the tens of millions.
The reference point is the EU-wide SME definition in Recommendation 2003/361/EC: fewer than 250 staff and at most EUR 50M turnover or at most EUR 43M balance sheet total; below that, "small" with fewer than 50 staff and at most EUR 10M, and "microenterprise" with fewer than 10 staff and at most EUR 2M. Companies belonging to a group must consolidate the figures of partner and linked enterprises — the rule does not help a subsidiary of a large group.
| Breach | Fixed amount | Percentage | General rule: higher | SME: lower |
|---|---|---|---|---|
| Prohibited practices (Art. 5) | EUR 35M | 7% = EUR 560,000 | EUR 35M | EUR 560,000 |
| Most other breaches | EUR 15M | 3% = EUR 240,000 | EUR 15M | EUR 240,000 |
| Incorrect information to authorities | EUR 7.5M | 1% = EUR 80,000 | EUR 7.5M | EUR 80,000 |
The first step is a four-column table
For a company of this size, the entry point to AI Act conformity is not a governance framework but a list. Without knowing which AI systems actually run in the building, none of the duties above can be assessed — and in practice the list is almost always longer than expected, because individual departments subscribed to tools on their own.
Four columns are enough to start: the system, what it is used for, who uses it, and which role you occupy. Only once the first rows exist is a fifth column for the risk classification worth adding.
| System | Used for | Who uses it | Role and classification |
|---|---|---|---|
| ChatGPT Business | Drafting, research, translation | Marketing, sales (6 people) | Deployer — not high-risk; Article 4 applies |
| Microsoft 365 Copilot | Minutes, email drafts, spreadsheets | all staff | Deployer — not high-risk; Article 4 applies |
| Website chatbot (bought in) | First-line answers for visitors | publicly accessible | Deployer — hold the provider to the Article 50(1) notice |
| Application pre-screening | Filtering and evaluating applications | HR department | Deployer of a high-risk system — Annex III(4)(a); Article 26 from 2 December 2027 |
| Image generator in marketing | Visuals for social media | Marketing (2 people) | Deployer — check the Article 50(4) disclosure |
- Build the inventoryCapture every AI system, including the ones individual departments subscribed to on their own. A spreadsheet is enough.
- Determine your role per systemDeployer or provider — and check whether Article 25(1) flips the role.
- Catch up on Article 4 and document itBriefing, usage rule, dated attendance list. This duty has been running since February 2025.
- Check HR and marketing tools against Article 5In particular, weed out every form of emotion inference applied to employees.
- Add disclosure wherever you publishLabel AI-generated images, video and published text under Article 50(4).
- Collect your vendors' commitmentsFor every bought-in system, record in writing how the provider meets Article 50(1) and (2).
Settle your role first. As a deployer, the whole AI Act comes down to four duties for you: Article 4, Article 5, and Article 50(3) and (4). Article 4 has applied since 2 February 2025, which makes it the most urgent — the transparency duties follow on 2 August 2026. And on fines, Article 99(6) gives SMEs the lower of the two figures, not the higher.
- Regulation (EU) 2024/1689 (EU AI Act) — EUR-Lex
- Article 4: AI literacy — AI Act Service Desk (European Commission)
- Article 5: Prohibited AI practices — AI Act Service Desk (European Commission)
- Article 25: Responsibilities along the AI value chain — AI Act Service Desk (European Commission)
- Article 26: Obligations of deployers of high-risk AI systems — AI Act Service Desk (European Commission)
- Article 50: Transparency obligations — AI Act Service Desk (European Commission)
- Article 62: Measures for providers and deployers, in particular SMEs — AI Act Service Desk (European Commission)
- Article 63: Derogations for specific operators — AI Act Service Desk (European Commission)
- Article 99: Penalties — AI Act Service Desk (European Commission)
- Annex III: High-risk AI systems referred to in Article 6(1) — AI Act Service Desk (European Commission)
- SME definition (Commission Recommendation 2003/361/EC) — European Commission
- Digital Omnibus on AI — European Parliament Legislative Train Schedule