Regulation Jun 24, 2026

The EU AI Act: what it means for small companies

For most small companies the EU AI Act is not about bans, but about transparency. Here is what you need to know, the dates that matter and how it connects to GDPR.

The EU AI Act is the world first comprehensive law on artificial intelligence. For most small companies it is not about bans, but about a simple principle: be open about when you use AI. The most important date is 2 August 2026, when the requirement to inform customers about AI chatbots and to label AI-generated content starts to apply.

The law is risk-based. The greater the risk an AI system poses to people, the stricter the requirements. The good news for smaller companies is that the heavy requirements target high-risk use and the large providers of AI models, not an ordinary company using an AI tool day to day.

The dates that matter

The AI Act entered into force on 1 August 2024 and is rolled out in steps. Here is the timeline for what concerns companies.

  • February 2025: prohibited AI practices and a requirement for staff AI literacy start to apply
  • August 2025: the rules for providers of general-purpose AI models start to apply
  • August 2026: the transparency requirements for chatbots and AI content start to apply, and enforcement gains full force
  • The high-risk requirements have been pushed to December 2027 through the Digital Omnibus, Regulation (EU) 2026/1744, which entered into force in July 2026

So for a small company, 2 August 2026 is the date to watch, and first of all if you have an AI chatbot or publish AI-generated content.

What applies to your company?

Most small companies are what the regulation calls deployers of AI, not developers. Then the requirements are manageable: clearly inform customers when they are talking to an AI and not a human, label content that is generated or manipulated with AI, and make sure those working with the tools have basic AI literacy.

The AI Act and GDPR

The AI Act does not replace GDPR. They are two separate laws that apply at the same time. As soon as you process personal data with the help of AI, GDPR applies just as usual. The Swedish data protection authority has published guidance on GDPR and AI, and one of its most important points is that what matters is not which technology you use, but who decides the purpose of the processing and on whose behalf it takes place.

In practice this means you are often the data controller and the AI provider is the data processor, which requires a data processing agreement. If you use AI in a flow with sensitive data you may also need to carry out a data protection impact assessment.

The penalties

The penalties sound dramatic but target the most serious breaches and the large players. Prohibited AI practices can lead to fines of up to 35 million euro or 7 percent of global turnover, and other breaches up to 15 million euro or 3 percent. The regulation explicitly says fines must be proportionate and take company size into account, so a small company does not face the same levels as a large group.

Practical steps for a small company

  • Map where in the business you actually use AI today
  • Inform customers clearly for AI chatbots and label AI-generated content
  • Make sure relevant staff have basic AI literacy
  • Choose European, GDPR-safe providers and sign data processing agreements
  • Handle sensitive flows with extra care and document your decisions

If it feels overwhelming you do not have to solve everything at once. A free efficiency audit can help you see where you use AI today and what is reasonable to prioritise.

Does the AI Act apply to my small company?+
Yes, but usually in a light form. If you use AI tools you are a deployer, and then it is mainly about being open about when AI is used and about staff having basic AI literacy. The heavy high-risk requirements rarely hit an ordinary small company.
What must we do if we use an AI chatbot?+
From 2 August 2026 you must clearly inform the visitor that they are talking to an AI and not a human. A short and clear notice in the chat is often enough.
What is the difference between the AI Act and GDPR?+
GDPR protects personal data and applies as soon as you process it. The AI Act regulates the AI systems themselves based on risk. They apply at the same time, so you need to follow both.
What happens on 2 August 2026?+
That is when the transparency requirements start to apply, meaning informing about AI chatbots and labelling AI-generated content, and the supervisory authorities gain full power to check and fine. The heavy high-risk requirements apply first in December 2027.

Book a free analysis

Want to see how this applies to you? Book a free analysis.

Book a free analysis