# Does the EU AI Act apply to your business? A 2026 guide for SMEs

*Published: 2026-07-15*

*Author: Roberto — Full-Stack Developer*

Most SMEs using off-the-shelf AI tools are deployers with light duties under the EU AI Act. Two obligations bite now: AI literacy and Article 50 transparency. Here is what applies to you, with the June 2026 deferral explained.

Yes, the EU AI Act almost certainly applies to your business if you use AI and operate in or sell into the EU, but for most SMEs the duties are light. Two things matter right now: the AI literacy duty, in force since February 2025, and Article 50 transparency rules from August 2, 2026. The heavy high-risk obligations were just deferred to December 2, 2027.

That one paragraph resolves most of the panic we hear from clients. The rest of this guide explains who owes what, exactly what changed in the June 2026 Digital Omnibus votes, and what to do about it before August. We build AI features and agents for SMEs, so we deal with this regulation in scoping calls every week. It is more manageable than the headlines suggest.

## What is the short answer for your type of company?

If you only use off-the-shelf AI tools (ChatGPT, Claude, Copilot, an AI feature inside your CRM), you are a deployer with two live duties: train your staff on AI basics, and from August 2, 2026, be transparent when AI talks to your customers or generates certain content. No registration, no conformity assessment, no technical file.

If you embed AI in your own product, say a chatbot in your app built on someone else's model, you are still usually a deployer of that model, but the transparency duties become yours to implement in the interface. You also need to watch the provider trap, which we cover below.

If you develop and sell an AI system under your own name, you are a provider. Your obligations depend on the risk class of the system. Most business software is minimal or limited risk. If your system falls into a high-risk category listed in Annex III, your compliance deadline moved to December 2, 2027, which is a genuine reprieve.

If you are a non-EU company selling into the EU, the Act can apply to you. It covers providers and deployers in third countries when the output of the system is used in the EU. US SaaS companies with EU customers should not assume they are out of scope.

![34](https://media.secondseason.studio/magnific_recreate-img1_MBuZvTtDCm-aeaecbb318cd642a.webp)

## What changed in June 2026?

The Digital Omnibus deferred the high-risk obligations by sixteen months. The European Parliament endorsed the package on June 16, 2026 and the Council followed on June 29, 2026. Obligations for high-risk systems under Annex III, originally due August 2, 2026, now apply from December 2, 2027 (see the analyses by Latham & Watkins and Gibson Dunn linked in the sources).

What the Omnibus did not do is just as important. It did not repeal anything for SMEs, it did not touch the AI literacy duty, and it did not defer the Article 50 transparency obligations. Those still apply from August 2, 2026. The deferral bought time for the companies with the hardest obligations, not for everyone.

Here are the dates that matter, in one place:

- **Obligation — Who it hits — Date**
- AI literacy duty (Article 4) — Every provider and deployer — In force since February 2025
- Article 50 transparency (disclose AI interaction, mark AI content) — Providers and deployers of the relevant systems — August 2, 2026
- Watermarking grace period for systems already on the market — Providers of generative systems — Runs to December 2, 2026
- High-risk obligations (Annex III) — Providers and deployers of high-risk systems — Deferred to December 2, 2027

If a vendor or a consultant quotes you different dates, ask which document they are reading. Plenty of guidance written before June 2026 still shows August 2, 2026 as the high-risk deadline, and it is now wrong.

## What still kicks in on August 2, 2026?

Article 50, the transparency rules. These were not deferred, and they are the obligations most SMEs will actually feel. Four duties sit inside the article.

First, people must be told when they are interacting with an AI system, unless it is obvious from context. If your website chatbot could plausibly be mistaken for a human agent, it needs to say it is AI. A one-line disclosure in the chat window covers it. We have started adding this to every chatbot and agent build by default.

Second, providers of systems that generate synthetic audio, images, video, or text must mark the output as artificially generated in a machine-readable way. This is the watermarking duty. Systems already on the market get a grace period that runs to December 2, 2026, after which the marking must be in place. If you are a deployer, this one is mostly your vendor's problem, but you should confirm in writing that they handle it.

Third, deployers must disclose deepfakes: AI-generated or manipulated image, audio, or video content that resembles real people, places, or events. There are carve-outs for obviously artistic or satirical work, but a business publishing a synthetic video of a real person needs a label.

Fourth, deployers who publish AI-generated text to inform the public on matters of public interest must disclose that, unless a human has reviewed it and someone holds editorial responsibility. For most companies this exempts ordinary blog and marketing content that an actual person edits and signs off. It is one more reason to keep a human in the publishing loop, which you should be doing anyway for quality.

And separately from Article 50: the AI literacy duty under Article 4 has applied since February 2025. Anyone whose staff operates AI systems must make sure those people have a sufficient level of AI literacy. A short internal training session, documented, proportionate to how your team actually uses AI, is the sensible response. Most SMEs we talk to have not done this, and it is the cheapest obligation in the entire Act to satisfy.

![30](https://media.secondseason.studio/magnific_recreate-img1_LwRQ300swO-4d2f8be6ad3c6332.webp)

## Are you a provider or a deployer?

A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its own authority in a professional context. Almost every SME reading this is a deployer, and deployer duties are far lighter.

The distinction sounds clean. In practice there is a trap, and it catches exactly the kind of company we work with. You can become a provider of someone else's system if you put your name or trademark on a high-risk system, substantially modify one, or change its intended purpose into a high-risk use. The classic case: an agency or an internal team takes a general-purpose model, wraps it in a branded product, and sells it as "YourCo Screening AI" for filtering job applicants. Congratulations, you may now be a provider of a high-risk system, with the full obligation stack arriving December 2, 2027.

The practical questions to ask yourself: whose name is on the system the user sees? Did we change what the system is for? Are we selling it, or just using it? If you are white-labeling AI for clients, get the provider question answered properly before the contract is signed, not after. (This is one of the few places in this article where we would genuinely push you toward a lawyer.)

One more wrinkle: you can be both. A company can deploy ChatGPT internally and simultaneously provide an AI product to its customers. Classify each system separately. That is why the checklist below starts with an inventory.

## The SME checklist: what to do before August 2, 2026

You can get an SME to a defensible position in a few working days. Here is the order we recommend:

1. Inventory your AI use. List every AI system your business uses, embeds, or sells. Include the boring ones inside your CRM, support desk, and ad platforms. You cannot classify what you have not listed.
2. Classify each system. For each entry, decide: are we the provider or the deployer? Is the use case anywhere near Annex III (hiring, credit, education, essential services)? Most entries will land in minimal risk and need nothing further.
3. Run AI literacy training. One documented session covering what your tools can and cannot do, where they fail, and what data must never be pasted into them. Keep the attendance record. This has been due since February 2025.
4. Update customer-facing disclosures. Add "you are chatting with an AI assistant" to bots, label deepfake-style content, and confirm your published AI-generated text has human editorial review. Due August 2, 2026.
5. Ask vendors for documentation. Email each AI vendor and ask how they meet Article 50 marking duties and whether their system touches any Annex III category. Their answers become your compliance file. Watch the watermarking grace period ending December 2, 2026.
6. Check your contracts. If you build or resell AI for clients, make the provider-versus-deployer allocation explicit in the agreement.
7. Diarize the dates. December 2, 2026 for watermarking grace expiry, December 2, 2027 for high-risk obligations, and a quarterly review of the inventory, because your AI stack will change faster than the law does.

Steps one through four are the ones with a deadline you have already met or are about to meet. Do those first.

## What counts as high risk, and why most SMBs are not

High-risk systems are the specific use cases listed in Annex III of the Act, plus AI that is a safety component of regulated products. The Annex III list includes AI used in recruitment and employment decisions, creditworthiness scoring, education and exam assessment, access to essential services, law enforcement, migration, and the administration of justice.

Notice what is not on the list: writing tools, coding assistants, support chatbots, meeting transcription, image generation, analytics, recommendation features in ordinary software. The overwhelming majority of SME AI use falls outside Annex III entirely. Using AI in a risky-feeling way (say, drafting a contract) is not the same as operating a high-risk system under the Act. The list is closed and specific, not a vibe.

Where SMBs do wander into high-risk territory, it is almost always hiring. CV-screening tools, AI video interview scoring, and automated candidate ranking sit squarely in Annex III. If you use one of these, you are a deployer of a high-risk system, and your obligations (human oversight, using the system per the provider's instructions, input data care, logging) arrive December 2, 2027. That date came out of the June 2026 Omnibus votes; before June 16, 2026 it was going to be this August. If this describes you, the deferral is your window to choose vendors who can show real documentation, not a reason to ignore the question for another year.

Credit decisions are the other one to watch, mostly relevant if you offer financing or defer payments based on automated scoring.

![15](https://media.secondseason.studio/magnific_recreate-img1_DoQ2dO3pcl-f3dc096fc09683a0.webp)

## How we handle the AI Act in client projects

We are a studio, not a law firm, but every AI feature we ship now goes through the same short routine, and it has held up well.

At scoping, we classify. Before we build an AI agent or feature, we write down the intended purpose and check it against Annex III. This takes fifteen minutes and prevents the worst outcome, which is discovering the risk class after launch. (If you want the plain-English version of what an agent actually is before worrying about how one is regulated, we wrote a guide: [what is an AI agent](/posts/what-is-an-ai-agent).)

In the build, transparency is a default, not an option. Chat interfaces disclose that they are AI. Generated content passes through human review before publishing. Where we integrate a model vendor, we collect their Article 50 and data-processing documentation and hand it to the client as part of the deliverables. Clients are consistently surprised that this paperwork exists and that vendors will send it if asked.

At handover, we flag the provider question whenever a client wants their brand on an AI product, and we put the dates in the project documentation. This mirrors how we treat accessibility: compliance work is cheapest when it is a build requirement rather than a retrofit, a lesson the [European Accessibility Act](/posts/european-accessibility-act-website-guide) taught the whole industry in 2025.

The pattern we see go wrong is not defiance, it is drift. A tool adopted by one team spreads to five, someone wires it into a hiring workflow, and nobody re-runs the classification. The inventory habit, refreshed quarterly, is worth more than any single compliance document.

One necessary caveat: this article is general information, not legal advice. The Act's application turns on the specifics of your systems and contracts, so for high-risk classification, provider status, or anything with real money attached, talk to a lawyer qualified in EU law.

## FAQ

### Does the EU AI Act apply to a business that just uses ChatGPT?

Yes, but lightly. A business using off-the-shelf AI tools is a deployer, not a provider. Your current duties are the AI literacy requirement (in force since February 2025) and, from August 2, 2026, Article 50 transparency: telling people when they interact with AI and labeling certain AI-generated content. That is the whole list for most tool users.

### What is the difference between a provider and a deployer under the EU AI Act?

A provider develops an AI system, or has one developed, and places it on the EU market under its own name. A deployer uses an AI system in a professional context. Providers carry the heavy obligations. Deployers have lighter duties. Careful: putting your own brand on someone else's AI system can turn you into a provider.

### When do the high-risk obligations apply now?

December 2, 2027 for the high-risk systems listed in Annex III (hiring, credit scoring, education, essential services). The original date was August 2, 2026, but the Digital Omnibus deferred it after the European Parliament vote on June 16, 2026 and the Council vote on June 29, 2026. Transparency duties under Article 50 were not deferred.

### Does a US or UK company have to comply with the EU AI Act?

It can, yes. The Act applies to providers and deployers outside the EU when the output of their AI system is used in the EU, and to anyone placing AI systems on the EU market. If you sell into the EU or serve EU users with AI features, assume the Act is in scope and classify your systems accordingly.

### Does AI-generated marketing content need to be labeled?

Sometimes. From August 2, 2026, Article 50 requires machine-readable marking of AI-generated content by providers, and deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest. Ordinary marketing copy a human reviews and takes editorial responsibility for generally escapes the deployer disclosure duty. Check each use case.

---

Second Season designs brands and builds the websites, platforms, and AI products behind them. If you are adding AI features or agents to your product and want them scoped with the AI Act's dates already accounted for, [talk to us](/contact). We will tell you plainly whether your use case is boring (most are) or needs a lawyer.
