Sovereignty & AI Act

The EU AI Act:
what an SME must do in 2026

No ban on AI. A common-sense process, scaled to risk. Here is the concrete to-do list.

SJ.CO

The AI Act does not ban AI

It scales obligations to risk, and says nothing about where data is located (that is GDPR territory). Most SMEs sit right at the bottom of the scale.

SJ.CO
The scale

Four risk levels

Unacceptable · banned
High risk · heavy obligations
Limited risk · transparency
Minimal risk · nothing imposed
SJ.CO
Timeline

A phased rollout

Feb. 2025
Bans + AI literacy
Aug. 2025
GPAI models + governance
Aug. 2026
General application (high risk, Annex III)
Aug. 2027
Regulated products (Annex I)
SJ.CO
Already in force

The obligation everyone forgets

Since February 2025, any team using AI must have a sufficient level of understanding: limits, error risks, data protection. This is AI literacy, and it can be funded through your OPCO.

SJ.CO
Where to start

Three deliverables, not one big project

01
Mapping

List and classify every use case by risk level.

02
Usage charter

Approved data, human validation, transparency.

03
Training

Bring every user to the expected level, traceably.

saint-jean.co · sovereign, compliant AI support, funded.

SJ.CO