← All Insights AI Regulation

AI Act: What Your SME Actually Needs to Do Before 2027

Most SMEs assume the AI Act is a rulebook for technology companies. It is not. If you use ChatGPT to draft emails, a CV-screening tool to sort applicants, or a chatbot on your website, the regulation already applies to you. Here is what you actually have to do, by when, and why the 2027 deadline you have probably heard about is only part of the story.

In a hurry

These are the questions we get asked most. The full reasoning is below.

Does the AI Act apply if I only use ChatGPT?

Yes. Using AI in your business makes you a deployer, and deployer obligations apply regardless of which tool you use. They are light for everyday uses like drafting, but they are not zero: the AI literacy duty applies now.

I bought GPUs and built an internal AI on our own documents. Am I a provider?

Almost certainly not. Running your own hardware changes nothing, and feeding an existing model your documents is use, not building. You are a deployer. You would only cross into provider territory if you sold that tool to others under your own brand.

What are the fines for a small company?

Much smaller than the headlines suggest. Article 99(6) inverts the calculation for SMEs: you pay the lower of the percentage or the fixed cap, where large companies pay the higher. A firm with €500,000 of turnover facing a breach in the main penalty band tops out around €15,000, not €15 million.

Do I have to tell customers my chatbot is a bot?

Yes, in practice. The letter of Article 50(1) puts the duty on the chatbot’s provider, who has to build the disclosure into the product. But your customers are the ones talking to it, and if you configure and brand it heavily enough you can become its provider yourself. One line of disclosure on the chat window settles the question either way.

Everyone says the deadline is 2027. Do I have until then?

Not for everything. December 2027 is the deadline for high-risk AI, which most SMEs do not operate. The duties that reach ordinary business use arrived earlier: AI literacy since February 2025, and telling people they are dealing with an AI since August 2026. One date is still ahead, 2 December 2026, but it is a provider deadline for marking AI-generated content. If you buy AI rather than sell it, that one reaches you as a procurement question rather than an obligation.

Do we need a compliance consultant?

For most SMEs, no. The inventory-and-classify work is something a business owner can do. Outside help earns its keep when you are operating a genuinely high-risk system, or selling AI as a provider.

What the AI Act actually is

The AI Act (Regulation 2024/1689) is the EU’s rulebook for artificial intelligence. It regulates the companies that build AI, but also the ones using it, which is almost everyone. It sorts AI tools into tiers based on how much harm they could do, and your obligations depend entirely on which tier your tools fall into.

The four risk tiers, and where an ordinary SME usually lands.
Tier What it covers Examples Applies to most SMEs?
Banned Clear threat to people’s rights Social scoring, manipulating vulnerable people Almost never
High-risk Decisions that seriously affect someone’s life CV screening, creditworthiness Sometimes
Limited-risk AI people interact with directly Chatbots, AI-generated content Often
Minimal-risk Everything else Spam filters, Copilot, scheduling tools Almost always

The one concept that changes everything: provider or deployer?

The distinction that decides everything

If you bought it or subscribed to it, you are a deployer. If you built it to sell, you are a provider.

The tiers tell you how risky a tool is. This distinction tells you who is responsible for it, and almost every obligation depends on it. A provider builds an AI system and puts it on the market under its own name. A deployer uses one in their business.

You are a deployer if you:

  • Use ChatGPT, Claude, or Copilot to draft documents or emails
  • Put a chatbot on your website using an existing tool
  • Use an off-the-shelf CV-screening or bookkeeping AI
  • Build an internal assistant on top of an existing model, feeding it your own documents, and use it yourself

You are a provider if you build, white-label, or wrap an existing model into something you sell or license to others under your own brand.

The deployer list is the entire everyday reality of an SME, including building your own internal tool. The overwhelming majority of SMEs are deployers. You cross into provider territory mainly when you start selling AI to others, not when you use it for yourself.

The timeline: what applies now, and what is next

Your actual dates
  • AI literacy Live
  • Telling people they are dealing with an AI Live
  • Machine-readable marking of AI-generated content (a provider duty) 2 December 2026
  • High-risk obligations 2 December 2027

The obligations roll out in phases. Most of the early ones are already live. The heavy lifting for high-risk systems has been pushed to late 2027.

Already in force

Prohibited practices. A short list of AI uses considered a clear threat to people’s rights (social scoring, manipulating vulnerable people, certain biometric categorisation by law enforcement) is banned outright. Almost no SMEs do these, so for most readers this is a line to note and move past.

AI literacy. This one does apply to you. Every business has to make sure staff who use AI actually understand it: what the tool does, where it is unreliable, when a human needs to check its output. For most SMEs this means basic internal training or guidance, plus a simple record that you have done it. The legal text has been in force since February 2025, and national enforcement powers arrived on 2 August 2026.

Transparency duties. Three of them, and they land on different parties:

  • People have to be told when they are talking to a chatbot rather than a person. The duty sits with the system’s provider, but you are the one facing the customer, so check that your tool actually does it
  • Deep fakes have to be disclosed when you publish them: AI-generated or manipulated image, audio or video that could be confused with reality
  • AI-generated or manipulated text has to be disclosed when it is used to inform the public on matters of public interest, unless it has undergone human review and sits under editorial responsibility

The Commission has published a Code of Practice and a set of icons to help with these labelling duties.

Coming next

2 December 2026: technical marking of AI-generated content. Providers of AI systems that generate audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated. New systems have had to do this since August 2026; December 2026 is the end of the grace period for systems already on the market before then. For deployers this is not a new obligation, it is a procurement question: buy tools that comply. Your own human-readable disclosure duties have been live since August 2026.

2 December 2027: high-risk AI. These obligations (human oversight, logging, using the system as specified) were originally due in August 2026, but the EU deferred most standalone high-risk obligations to 2 December 2027, and to 2 August 2028 for AI built into regulated products. For most SMEs this does not matter, because most do not operate high-risk systems at all. The main exception is AI used to screen or rank job candidates, which is high-risk and falls under the 2027 deadline.

What this means for a typical Belgian SME

Say you run a 20-person firm. You use Microsoft Copilot for documents, a chatbot for customer queries, and an AI tool to help screen job applicants. You are a deployer in all three cases, but different tiers apply.

Copilot: minimal-risk, one duty. The staff using it need to understand what it does and where it gets things wrong. That is the literacy obligation, and it is live now.

The chatbot: limited-risk, two duties. Literacy again, plus transparency: anyone talking to it has to know they are dealing with an AI and not a person. Both are live now.

The recruitment tool: high-risk, with runway to December 2027. AI used to screen or rank job candidates sits in the high-risk tier. As a deployer you will have real obligations: keep a human meaningfully in the loop on decisions, retain the tool’s logs, and use it the way the provider specifies. You have time, but only if you know it is coming and do not discover it the month before.

The SME rule most people miss

Article 99(6): SMEs pay the lower of the percentage or the fixed cap. Everyone else pays the higher. A firm with €500,000 of turnover: maximum €15,000, not €15 million.

On fines, the headline numbers are large: up to €35 million or 7% of turnover for banned practices, up to €15 million or 3% for most other breaches. Those are the figures for large companies, and there is a specific provision that changes the arithmetic for you.

Under Article 99(6), SMEs pay whichever is lower, the percentage or the fixed amount. That inversion is the whole story. A firm with €500,000 of turnover facing a breach in the main penalty band is looking at a maximum of €15,000, which is 3% of turnover, not €15 million.

The six things you need to do

  1. Build an AI inventory. You cannot comply with rules for tools you have not listed. Start with every AI your business touches, including the AI features built into software you already pay for.
  2. Sort each tool by risk tier. Banned, high-risk, limited, minimal. Most will land in the bottom two; the occasional high-risk one is what needs your attention.
  3. Meet the AI literacy obligation. Live now, and the easiest to overlook precisely because it is low-effort.
  4. Handle your transparency duties. Disclose AI interactions, label AI-generated content.
  5. Check whether you are ever a provider. Almost every SME is a deployer, but confirm it, because the obligations jump sharply if you are selling AI under your own brand.
  6. Embed AI governance into existing processes. Tie AI risk and compliance into the policies you already have: data protection, IT security, HR, procurement. You do not need a separate AI Act department, you need clear ownership and basic controls.

Most SMEs find they are in far better shape than they feared once they have looked. The work is knowing where you stand, not scrambling to fix everything at once.

Where Ozymind comes in

The inventory and the tier sort are work a business owner can do in an afternoon. Where it gets harder is the case that sits on a line: a screening tool a vendor insists is not high-risk, an internal assistant that has quietly grown into something you might be selling, a use case that is legal in principle but not with the data you hold. That is what our AI Strategy & Legal Review is for. We map the use cases against the AI Act and GDPR together, alongside legal specialists, so the constraint arrives as a design input rather than as a finding after the build.

The author

Olivier Moisse is Co-Founder & CEO of Ozymind. He scaled Riaktr from startup to its acquisition by SDS (listed in Stockholm) and ran commercial operations across 60+ countries as CRO.

Want to know where your AI use actually stands before someone else tells you?

Map your obligations with us