Skip to content
All posts

19 August 2026

5 min read

Written by

Clément Lacaille

Clément Lacaille

Founder, Tech-Bharat

About the author
Business & compliance

EU AI Act: what became mandatory on August 2, 2026 — and what it means for your SMB

Since August 2, 2026, the EU AI Act is generally applicable: transparency duties for chatbots and AI-generated content, the high-risk regime, national authorities and fines. Most SMB uses remain untouched — but two obligations concern almost everyone. The factual rundown, without the drama.

August 2, 2026 was written into the law from day one: under its article 113, Regulation (EU) 2024/1689 — the AI Act — became generally applicable across the EU on that date. It is the third wave of a calendar that started with the ban on prohibited practices and the AI-literacy duty on February 2, 2025, and continued with the rules for general-purpose AI models on August 2, 2025. This time the change concerns companies that merely use AI, not just those that build it — including SMBs.

What became applicable on August 2, 2026

  • Transparency duties (article 50): a person interacting with a chatbot must be able to tell they are dealing with an AI, and AI-generated or manipulated content — deepfakes in particular — must be identified as such.
  • The high-risk regime: obligations attached to the systems listed in Annex III — recruitment and employee evaluation, credit scoring, access to essential services, education — now apply, for providers and for the companies deploying them.
  • Enforcement: member states had to designate their market-surveillance authorities and lay down penalty rules. The ceilings set by the regulation: up to €35 million or 7% of worldwide turnover for prohibited practices, up to €15 million or 3% for most other breaches — with a rule capping fines at the lower of the two amounts for SMEs.
  • One prudent caveat: the simplification package ("digital omnibus") proposed by the European Commission in November 2025 would adjust parts of the high-risk timetable. Check the current status before building a compliance plan on dates alone.

The question to ask: are you a deployer of a high-risk system without knowing it?

The regulation distinguishes the provider, who builds the system, from the deployer, who uses it under its own authority. An SMB is almost never a provider — but it becomes a deployer of a high-risk system the day it uses software that filters job applications, scores loan applicants or evaluates employees. In that case the obligations are concrete: use the system according to the provider’s instructions, ensure human oversight of the decisions, keep the logs, and inform the employees concerned before putting it into service. Legal scholars saw this architecture coming well before the final text: the reference analysis by Michael Veale and Frederik Zuiderveen Borgesius, published in 2021 in Computer Law Review International, Demystifying the Draft EU Artificial Intelligence Act, already noted that the regulation places most duties on whoever puts the system on the market — leaving the deployer with fewer, but very tangible, operational obligations.

What does not change for most SMB uses

The bulk of what SMBs actually do with AI — drafting assistance, document summarisation, support chatbots, internal automations — sits in the minimal-risk category, with no new authorisation and no registration to complete. For a customer-facing chatbot, the operational requirement boils down to honesty: say clearly that it is an AI, something a well-designed assistant should do anyway. And GDPR has not moved: whenever an AI tool processes personal data, the rules the CNIL has been detailing in its AI guidance apply exactly as before. The AI Act adds a layer for specific uses; it does not rewrite the basics.

The 5-point check before the end of the quarter

  • Inventory the AI tools actually used in the company — including the ones adopted team by team without an IT decision.
  • Compare that list against Annex III: anything touching recruitment, employee evaluation, credit or access to essential services deserves a closer look.
  • For each match, ask the vendor for its AI Act documentation: intended purpose, instructions for use, human-oversight measures.
  • Make your customer-facing chatbots and AI-generated content identifiable as such — the article 50 duty that concerns nearly everyone.
  • Document the AI training given to staff: the AI-literacy duty of article 4 has applied since February 2, 2025 and is the cheapest one to satisfy.

The lesson we draw from compliance projects: the companies that suffer are not the ones using AI ambitiously, but the ones unable to say where AI is used in their own processes. An afternoon spent building that inventory is worth more than any speculation about fines.

Frequently asked questions

Does my customer chatbot have to say it is an AI?+

Yes. Since August 2, 2026, article 50 of the AI Act requires that people interacting with an AI system be informed of it, unless it is obvious from the context. A clear mention in the conversation window satisfies the duty.

Is a CV-screening tool really "high risk"?+

Yes: Annex III of the AI Act explicitly lists AI systems used for recruitment and for selecting or evaluating candidates. The company using such a tool is a deployer, with duties of human oversight, correct use and information of the persons concerned.

What fines can an SMB actually face?+

The regulation caps fines at €35 million or 7% of worldwide turnover for prohibited practices and €15 million or 3% for most other breaches — and specifies that for SMEs the lower of the two amounts applies. Enforcement runs through the national authorities designated by each member state.

Free resource

The self-assessment grid: 20 tasks AI can automate

Sales, admin, support, operations: the 20 tasks AI agents already handle in SMEs — with, for each one, the tell-tale sign that your team is concerned.

Read next