EU AI Act for SMEs: obligations and current deadlines

Start by checking whether your business falls within the regulation’s scope and in which role. Obligations depend on the system and its intended use. The July 2026 Digital Omnibus changed the AI Act, so blanket timelines showing an August 2026 start for high-risk requirements are outdated. Build an AI inventory and check the applicable rules and transitions.

15 September 20265 min read
Illustration: Document with a ring of stars above four risk tiers.

Checklist to get started

The AI Act after the Digital Omnibus: roles, AI literacy, transparency and high-risk timelines for businesses. Updated September 2026.

  • Record each AI system, provider, responsible team, purpose, affected people and connected data sources.
  • Identify your role for each system. Developing a system, making substantial changes or changing its intended purpose may require a new assessment.
  • Assess applicable prohibitions, high-risk classification and transparency separately. A product name cannot answer these questions.
  • Plan relevant literacy measures, human review, access controls, documentation and a way to stop or escalate problems.
  • Assign an owner and deadline to every action. Assess data protection, employment law and other applicable requirements separately.

Role and intended use shape the assessment

A provider develops a system or places it on the market under its own name. A deployer uses a system under its authority. These roles have different obligations; conformity assessment should not be attributed to every person using an AI tool.

Risk categories provide an initial orientation. The actual provisions, particularly Articles 5, 6 and 50 and the relevant annexes, determine the assessment. Not every chatbot is high-risk; uses such as recruitment require careful examination of their intended purpose.

Current deadlines after the 2026 amendment

Legal sources checked on 15 September 2026. Read the original regulation together with the amending regulation.

DateProvisionScope
2025-02-02Early provisionsThe original Chapters I and II have applied since this date. Article 4 changed in July 2026; new prohibitions have their own application dates.
2026-07-27Digital OmnibusAmending Regulation (EU) 2026/1744 enters into force, changing Article 4 and the high-risk timelines, among other provisions.
2026-08-02General application dateThe general application date, including transparency rules where no specific exception or transition applies. Postponed high-risk requirements need separate consideration.
2026-12-02Additional transitionsNew prohibitions under Article 5(1)(ba)/(bb) and paragraphs 1a/1b start. Systems generating synthetic content placed on the market before 2 August 2026 have a transition for Article 50(2).
2027-12-02Annex III high-risk systemsChapter III, Sections 1–3, excluding Article 6(5), applies to systems classified under Article 6(2) and Annex III.
2028-08-02Annex I high-risk systemsThe corresponding date for systems under Article 6(1) and Annex I. Existing systems and special situations may have additional transition rules.

Develop AI literacy for the actual work

Amended Article 4 requires providers and deployers to take measures supporting the development of AI literacy among staff and other people acting on their behalf. Knowledge, experience, education, training and the use context matter. It does not require a guaranteed individual level of literacy.

A suitable programme connects relevant basics with the systems actually used: data permissions, output limitations, human oversight and failure cases. Document content, audiences, participation and follow-up. A certificate or blanket training promise does not replace an assessment of the concrete requirements.

Culturetek supports process discovery, system inventories and practical team training. Agree a clear scope and learning outcomes; applicable legal requirements belong in the responsible professional and legal assessment.

Example: AI in recruitment

A system that ranks applications or evaluates candidates needs a different assessment from an assistant drafting an internal text. Record purpose, decision influence, data and human responsibilities before deciding its risk classification.

A later start for certain high-risk requirements does not justify an unassessed deployment. Rules already applicable, data protection and requirements for fair decisions must be considered in the specific process.

EU AI Act questions

Is every company using ChatGPT automatically a high-risk deployer?

No. Classification depends on the system and its intended use. General assistance and specific uses such as employment decisions require different assessments.

Does Claude training automatically satisfy every requirement?

No. Training can be one component. Roles, systems, audiences, process rules and any additional human-oversight requirements also need consideration.

Can we postpone all action until 2027?

No. The extension concerns specific high-risk provisions. Other rules already apply or have different deadlines. Check the current legislation and your situation.

Official sources

Legal sources checked on 15 September 2026. Read the original regulation together with the amending regulation.

Review your AI use

Record each AI system, provider, responsible team, purpose, affected people and connected data sources.

Start potential analysis

If you want to prioritize a real process, a few clear inputs are enough for a strong first assessment.