Sovereignty & AI ActPublished 27 June 2026· Updated 17 August 20265 min

The EU AI Act: A 2026 Compliance Checklist for SMEs

By Alexandre Saint-Jean

The EU AI Act: A 2026 Compliance Checklist for SMEs

Audio version

Audio version produced by text-to-speech from the article. Our AI charter

View the slides

The EU AI Act worries a lot of business owners, often for the wrong reasons. It does not ban AI. It does not force you to relocate everything to Europe. What it asks for is a common-sense process: know where you use AI, at what risk level, and make sure the people using it have been trained. Here is the practical checklist for 2026.

Does the AI Act ban AI or force me to host data in the EU?

Neither. Regulation (EU) 2024/1689 says nothing about data location: that question falls under GDPR and data sovereignty, two separate topics that get confused often (covered in more depth in using AI without losing control of your data).

What the AI Act actually does is regulate AI use by risk. The more sensitive the use, the stronger the obligations. Most SMEs, which use AI for drafting, summarising or assistance, sit at the lower end of that scale.

What are the four AI Act risk levels?

The regulation sorts uses into four categories, from the most tightly controlled to the least.

Pyramid of the four EU AI Act risk levels, from unacceptable risk (banned) to minimal risk

LevelExamplesWhat it means
UnacceptableSocial scoring, manipulation, certain biometric usesBanned since 2 February 2025
High riskHR screening, credit scoring, biometrics, critical infrastructureHeavy obligations (documentation, human oversight, risk management)
Limited riskChatbots, content generationTransparency: telling people they are interacting with AI
Minimal riskWriting assistance, spam filtersNo specific obligation

Most everyday SME uses fall into limited or minimal risk. The useful first check is whether any of your uses tips into high risk (typically automated CV screening or a credit decision), because that is where the obligations change scale.

Am I a provider or a deployer?

The AI Act distinguishes two roles, and your obligations depend on which one you are. A provider develops or places an AI system on the market. A deployer uses it in the course of its own activity. Nearly all SMEs are deployers: they use ChatGPT, Copilot or a business tool with AI built in, without building the system themselves. The heaviest obligations sit with providers and with high-risk uses. As a deployer running everyday uses, your main duties come down to transparency and training your staff.

What is the EU AI Act compliance timeline?

The regulation entered into force on 1 August 2024, but its obligations phase in over several years.

EU AI Act implementation timeline: prohibitions and AI literacy in February 2025, GPAI rules in August 2025, general application in August 2026, regulated products in August 2027

  • 2 February 2025: prohibited practices are banned and the AI literacy duty applies.
  • 2 August 2025: rules on general-purpose AI (GPAI) models and governance structures take effect.
  • 2 August 2026: general application, including the high-risk systems listed in Annex III.
  • 2 August 2027: high-risk systems embedded in products already regulated elsewhere (Annex I).

A simplification package (the Digital Omnibus, proposed by the European Commission in November 2025) is under discussion and could adjust some of the high-risk deadlines. That does not change what an SME needs to do right now.

Do I have to train my employees on AI under the AI Act?

Yes, and this is the most concrete, most overlooked obligation. Since 2 February 2025, Article 4 requires that people who use AI in your organisation have a sufficient level of understanding: what the tool is, its limits, the risk of error, and how it handles data.

AI Act compliance starts with training your teams, not a technical audit. It is the obligation already in force, and it is also the cheapest to satisfy.

Good news: in France, this kind of training is typically eligible for OPCO funding (France's sector-based training funding bodies), and it is exactly the kind of engagement I run for SMEs and schools (see how to fund an AI project). If you operate elsewhere in the EU, check your own country's training-funding schemes: several member states run comparable mechanisms.

How serious are the AI Act fines, really?

The headline figures are eye-catching: up to €35 million or 7% of global turnover for prohibited practices, up to €15 million or 3% for other breaches. Two nuances matter for an SME. First, these ceilings target serious breaches, mainly prohibited uses and high-risk obligations, not the everyday use of an AI assistant. Second, the regulation builds in proportionality for SMEs and start-ups, with adjusted caps.

In practice, the real risk for an SME using AI reasonably and training its staff is low. The real stake is not fear of a fine, it is doing things properly once, which costs little and reassures both clients and staff.

Where do I start? A three-step compliance checklist

For an SME, compliance comes down to three straightforward deliverables, with no large IT project involved.

  • A usage map: list where AI is used (tools, services, data involved) and classify each use by risk level.
  • An AI usage policy: clear rules on what data can be used, human validation, and transparency towards clients.
  • A training plan: bring every user to the expected literacy level, with a paper trail.

This is exactly the starting point of my sovereign, AI Act-compliant AI support: scope the real need, drop the risky uses, and put in place the minimum necessary, no more and no less. National data protection authorities also publish useful guidance on how the AI Act and GDPR fit together; in France, that is the CNIL.

Frequently asked questions

Does the AI Act apply to my SME if I only use ChatGPT or Copilot?
Yes, as a deployer of an AI system, but most of the heavy obligations target providers and high-risk uses. For everyday uses such as drafting, summarising or general assistance, you sit in the limited-risk or minimal-risk band: your main duties are transparency towards the people affected and training your staff.
What is the first AI Act deadline that has already passed?
2 February 2025. Since that date, prohibited AI practices are banned and the AI literacy duty (Article 4) applies. You need to make sure the people who use AI in your organisation understand it well enough to use it responsibly.
Do I have to host my data in the EU to comply with the AI Act?
No. The AI Act does not deal with data location, which is a GDPR and data-sovereignty matter, not an AI Act one. You can be AI Act compliant with a non-EU provider, and separately choose EU hosting for sovereignty reasons the AI Act does not require.
When do most of the AI Act's obligations become enforceable?
2 August 2026, for the bulk of the regulation, including the high-risk systems listed in Annex III. High-risk systems embedded in products already regulated elsewhere follow on 2 August 2027. A simplification package (the Digital Omnibus, proposed in November 2025) is under discussion and could adjust some of the high-risk deadlines.

Sources

Get the AI briefing, no commitment

Free · One email a month · Unsubscribe anytime · Your data is never sold

Free first call

Got an AI project in mind?

30 minutes to scope your need and see how to fund it. No commitment.

Working with companies across France, remote.