Insights · EU businesses

The EU AI Act for small businesses: what actually applies

Most coverage of the AI Act is written for big tech. If you run a clinic, a shop, a trade or an agency that uses AI, only a few rules touch you, and one of them has applied since August 2026. This guide covers those rules, the dates after this summer's changes, and what could still change.

Most small businesses sit in the bottom two levels. Pick a level to see what it means.

Since 2 August 2026Be open when people deal with AI or see AI-made content.
  • A chatbot or voice agent that talks to customers
  • Realistic AI images or video you publish
  • AI-written text published to inform the public

Checked on 29 September 2026, including the Digital Omnibus that changed the Act on 27 July 2026. This is general information, not legal advice.

The short version

Four things to know today

The AI Act sorts AI by risk. For most small businesses, it comes down to being open about AI, training your team, and staying clear of a few banned uses.

Tell people when it's AI

Since 2 August 2026, chatbots and voice agents must make clear they're AI, and realistic AI-made content must be labelled.

Help your team use AI well

Take measures that support your staff's AI literacy. Since July 2026 this is about effort, not a guaranteed result.

Avoid the few banned uses

Since February 2025, a short list is off limits, including reading employees' emotions at work.

High-risk rules come later

Only if you use AI to decide about people, such as in hiring or credit. Those rules now start on 2 December 2027.

The timeline

What applies now, and what's next

The rules arrive in stages, and the Digital Omnibus moved several dates this summer. Pick a date to see what it means.

Today
Already applies2 Aug 2026 · Transparency rules apply

Chatbots and voice agents must make clear they're AI, and AI-generated content must be marked or labelled. In Ireland, the new AI Office of Ireland was set up to be operational from this date.

Check your business

Does this apply to me?

Six questions. Answer them honestly and you'll see which rules apply to you, and from when.

  1. Does your team use AI tools at work?ChatGPT, Copilot, AI features in your software
  2. Does AI talk or write to your customers?A website chatbot, a voice agent, automatic replies
  3. Do you publish realistic AI-made images, video or audio?Or AI-written text to inform the public on matters of public interest
  4. Do you use AI to decide about people?Screening job applicants, credit, admissions or grading, access to essential services
  5. Do you use AI to read employees' emotions?Mood or stress detection on staff, outside medical or safety reasons
  6. Did you build an AI system, or have one built, under your own name?A custom chatbot or agent that you offer or run as yours
What applies to you · 0 of 6 answered

Answer the questions to see which rules apply, and from when.

A quick orientation, not legal advice. Your exact duties depend on your role and the system.

In practice

Who does what

The Act splits duties between the provider, who builds or sells the AI, and the deployer, who uses it. If you have an AI system built and run it under your own name, you may be both.

RuleApplies fromWhose job it isWhat to do
Tell people they're dealing with AI2 Aug 2026Mainly the provider, who must build it in. You, if you run itCheck your chatbot or voice agent says it's AI from the first message, unless that's obvious
Mark AI-generated content2 Aug 2026 (2 Dec 2026 for systems already on sale)Providers of generative AINothing for most businesses; the tools you use must do this
Label deepfakes and some AI text2 Aug 2026You, when you publish itLabel realistic AI images, video and audio; label AI text on matters of public interest unless a person reviewed it
Support AI literacy2 Feb 2025, softened July 2026Every business that uses AIA short training, a simple usage policy and a record of both
Don't use banned practices2 Feb 2025EveryoneCheck no tool reads employees' emotions or manipulates people in harmful ways
High-risk requirements2 Dec 2027 (products: 2 Aug 2028)Providers and deployers of high-risk AIHuman oversight, logs, following the provider's instructions, informing people
Enforcement

Fines, and who checks

The maximum fines are large, but they're maximums. For small businesses and start-ups, the lower of the two amounts applies.

BreachUp toOr
Using a banned practice€35 million7% of worldwide turnover
Breaking other obligations, including transparency€15 million3% of worldwide turnover
Giving regulators incorrect information€7.5 million1% of worldwide turnover
For large companies, the higher of the two applies. For SMEs and start-ups, the lower.
In IrelandThe AI Office of Ireland

Set up under the Regulation of Artificial Intelligence Act 2026, signed into law on 21 July 2026. It coordinates enforcement and is the single point of contact. Existing regulators, such as the Competition and Consumer Protection Commission and the Central Bank, oversee AI in their own areas.

Elsewhere in the EU, each member state has named its own authorities. Outside the EU, the Act can still apply if your AI is used by people in the EU.

Still open

What could still change

The AI Act is law, but parts of it are still being filled in. These are the ones to keep an eye on.

DraftFinal guidance on what counts as high-risk

The Commission published draft guidelines in May 2026 and consulted on them until July. The final version could still move the line between high-risk and not.

In progressTechnical standards for high-risk AI

European standards bodies are still writing the detailed standards that high-risk systems will be expected to meet.

Under negotiationGDPR changes for AI (the data omnibus)

Separate proposals would change how personal data can be used to develop AI. The Council has pushed back on parts of them, and agreement isn't expected before late 2026 at the earliest.

Every yearThe yearly review of bans and high-risk uses

The Commission must assess each year whether to add to the list of banned practices or high-risk uses. New uses can be added.

StartingHow national regulators enforce

In Ireland, the AI Office of Ireland and sector regulators have only just started. Their first guidance and priorities will shape what enforcement looks like in practice.

PossibleMore simplification or delays

The Omnibus showed that dates can move. Plan for the current dates, and treat further delays as a bonus, not a strategy.

This month

Five things to do now

An afternoon of work covers most of what the Act asks of a small business today.

List your AI

Every tool that uses AI, who uses it, and for what.

Check your disclosures

Any chatbot, voice agent or AI email says it's AI from the start.

Train and record

A short session and a one-page usage policy, with the date.

Flag high-risk uses

Anything that decides about people. Plan for December 2027.

Label what you publish

Realistic AI images, video and audio, marked as AI-made.

The bigger picture

Being open about AI is good business anyway

The rules that touch most small businesses ask for things customers expect already: tell them when they're talking to a machine, don't pass off AI-made content as real, and make sure your team knows what it's doing. Businesses that do this well tend to be the ones customers, and their AI assistants, trust.

The AI Act will keep changing in the details. We'll update this article when it does, and the date at the top will tell you when we last checked.

DL
Written byDirk LaudonFounder, SproutMedia

AI specialist with a master's degree in Business Informatics, studied in Germany and Sweden with a focus on artificial intelligence. Dirk has spent years building software and apps, and has worked hands-on in e-commerce, affiliate marketing and social media, so he knows how customers find and choose a business online. At SproutMedia he helps businesses get ready for their customers' AI assistants and agents.

LinkedIn

SproutMedia writes about AI agents and agent readiness for service businesses in Ireland, Europe, the United States and beyond.