Skip to content
Free diagnostic

BlogFramework and control

AI Act: what changes for SMEs and mid-sized companies, and when

Prohibited practices, AI literacy, transparency, high risk: the AI Act timeline and what it concretely requires from an SME or a mid-sized company.

By Stéphane Barrio Published on 3 min readFor SMEsMid-sized companies

The European regulation on artificial intelligence — the "AI Act" — is often feared for the wrong reasons. For an SME or a mid-sized company that uses AI tools, it mainly asks for three things: transparency, skills, and caution about a few uses. Here is the timeline and what it changes, as the law stood on 11 September 2026.

The timeline

Date What applies
Since February 2025 Prohibited practices (for example social scoring of people, or emotion recognition in the workplace) and the AI literacy obligation: the people who use AI in the company must be trained, in proportion to their use.
Since 2 August 2025 Obligations for providers of general-purpose AI models (they concern software publishers, not users).
Since 2 August 2026 Transparency: telling people they are dealing with an AI, flagging generated content.
2 December 2026 Technical marking of generated content, for systems already on the market.
2 December 2027 Obligations for so-called high-risk systems, including those used for recruitment — a deadline postponed by a regulation of July 2026.

What it changes for an SME or a mid-sized company

  1. Tell the people you deal with when they are interacting with an AI — on your website, by phone, by email.
  2. Flag content generated by an AI.
  3. Build your teams’ skills on the tools they use.
  4. Do not leave a tool alone to sort applications or assess your employees.
  5. Know the prohibited practices, so as not to stray into them unknowingly.

The real trigger: a customer

For most companies, the question will not come from an inspection, but from a client who asks, in a tender or a questionnaire, for guarantees about your use of AI. This is already happening with other security regulations.

Penalties exist; for an SME, the lower of the two ceilings applies, a rule extended to mid-sized companies in 2026. But the concrete challenge is being able to answer your customers: knowing which AI tools are used in your company, under which rules, and proving it.

Where to start

  1. Take stock of the uses of AI in the company, including those nobody has declared. See Your teams already use AI without saying so.
  2. Write a usage charter: which tools, which data, who reviews.
  3. Correct the gaps: informing people, flagging content, records, human approval.
  4. Build a file of evidence, reusable to answer a customer.

That is exactly the content of the AI Usage Audit, delivered within five working days.

What we build in by default

In everything we deliver that interacts with people, the notice "you are dealing with an AI" is built in by default. No irreversible action is left to an agent alone. The details, updated every six months: AI Act.

Our field is technical compliance. The legal assessment, a certificate of compliance or an opinion on a risk of penalty are matters for your data protection officer or your lawyer.

Sources

  • Regulation (EU) 2024/1689 on artificial intelligence, in particular its Articles 4 (AI literacy), 50 (transparency) and 99 (penalties); official text.
  • Regulation (EU) 2026/1744 ("Digital Omnibus"), published in the Official Journal of the EU on 24 July 2026, which postpones certain deadlines.

Frequently asked questions

Is my company concerned if it only uses ChatGPT?

Yes, for the AI literacy obligation: the people who use AI must be trained, in proportion to their use. And if you publish generated content or an assistant deals with your customers, the transparency rules apply.

What penalties for an SME?

Penalties exist, with high ceilings; for SMEs — and, since 2026, mid-sized companies —, the lower of the two ceilings applies. For most companies, the question will come from a customer first, not from an inspection.

Is AI-assisted recruitment prohibited?

No, but systems used for recruitment are classified as high-risk, with stricter obligations from 2 December 2027. Never leave the sorting of applications to a tool alone.

Share on LinkedIn All articles

Read next

In the same category

Framework and control 3 min read

AI and the GDPR: what to check before deploying an agent

Necessary data, legal basis, retention periods, people’s rights, processors: the GDPR checklist to go through before entrusting data to an AI agent.

SMEsMid-sized companies

Framework and control 2 min read

Where does your data go when you use AI?

Europe, France or your own premises: where your data is processed when an AI agent works, what processing in France really costs, and what to require in writing.

SMEsMid-sized companies

Flash Diagnostic · free

Start with a one-hour interview, free of charge.

A questionnaire that takes under 10 minutes, a one-hour interview, then within 72 hours a written report: what you can stop doing by hand, the time saved and the order of magnitude of the budget. If an off-the-shelf tool is enough, we will tell you.