Does the EU AI Act concern SMEs?
Yes. The EU AI Act has been in force since February 2025 and applies to any organisation that develops, deploys or uses AI systems in the European Union — including SMEs.
The good news: most SMEs fall into the category of users, not high-risk AI developers. That means lighter obligations, but not zero obligations.
The even better news: those who build in AI governance before it becomes a perceived obligation gain a real competitive advantage.
The official summary from EUR-Lex makes clear that definitions, basic prohibitions and AI literacy have applied since 2 February 2025. For an SME, this is no longer something to watch from the sidelines. It’s something to organise.
Practical translation
For an SME, this comes down to one simple thing:
- you don’t have to become an AI legal expert
- you do have to avoid improvised use of AI in critical processes
- you do have to be able to explain how you’re using it
What are the concrete obligations for an SME that uses AI?
For SMEs that use AI systems (ChatGPT, Claude, Copilot, data-analysis tools), the main obligations are:
- Transparency: inform employees and customers when they interact with an AI system
- Human supervision: keep control over automated decisions
- Documentation: track how AI is used in decision-making processes
- Training: make sure the people using AI have the skills to do so responsibly
You don’t need a dedicated legal team. You need a system that builds these principles into the way you work.
The obligations, in checklist form
If you want the essentials, ask yourself:
- Do we know where AI is used?
- Do we know who validates the outputs?
- Do we know which outputs shouldn’t go out uncontrolled?
- Do we know who needs to be trained?
Article 4 of the AI Act is particularly useful from an operational perspective: it requires a sufficient level of AI literacy for the people who use and manage AI systems. In other words, it’s not enough to open an account. You have to prepare the people who use it.
Why don’t any competitors talk about the EU AI Act?
We have analysed several established AI-training providers serving SMEs in Italy — Morfeus, Martes AI and Holyn AI. None mentions the EU AI Act.
This is a glaring gap in the market. Anyone offering AI governance without the regulatory layer is selling a system with no foundations.
AIEH™ has built the EU AI Act framework into every product — from the Cruscotto Decisionale™ to the AI Mirror™. Not as an add-on, but as an architectural principle.
This is a competitive advantage in itself, because it lets you talk about efficiency, risk and reliability within a single architecture, rather than across three disconnected projects.
Why this matters commercially
When everyone promises efficiency but no one can explain governance and accountability, whoever also brings the EU AI Act layer:
- looks more credible
- is easier to defend in a sale
- is stronger with structured boards, partners or clients
How to transform compliance into a competitive advantage?
Compliance can be a cost or an investment. The difference lies in the approach:
Cost approach (what everyone does):
- Wait for someone to ask for documentation
- Fill out checklists afterwards
- Treat the EU AI Act as a bureaucratic requirement
Investment approach (what we do):
- Build AI processes that are documented and transparent by design
- Use governance as a differentiator in client presentations
- Position yourself as a partner who knows how to govern AI, not just use it
Key question
When a client asks you “how are you governing AI?”, today do you have:
- an opinion
- a policy
- or a traceable system?
For a fractional executive, turning up with a documented AI governance framework is an advantage in winning clients. For an SME’s GM, it’s a concrete answer to the board when it asks “how are we managing AI risk?”.
What’s more, the European Commission explicitly links adoption, trust, skills and implementation of the AI Act. So compliance done well isn’t a brake. It creates demonstrable operational reliability.
What are the concrete risks of non-compliance?
Fines under the EU AI Act can reach €35 million or 7% of global turnover for the most serious violations. For SMEs, the penalties are proportionate, but the reputational risk is identical.
The most concrete risk for an SME today isn’t the fine. It’s losing a client or a tender because you can’t show that you’re using AI responsibly.
In practice, we see three recurring risks:
- using AI without validation criteria
- no traceability of who did what
- AI-assisted outputs with no clear supervision
These are reputational risks before they’re regulatory ones. But they turn into commercial risks the moment a client or partner asks how you manage the process.
The most underestimated risk
It isn’t the theoretical fine. It’s this scenario:
- the team uses AI inconsistently
- a client asks for transparency
- you can’t explain the process, the boundaries and the validation
What an SME needs to do in the next 4 weeks
The minimum path is this:
- map where AI is already used
- define which outputs require human review
- assign an internal owner
- track critical use cases
- train the people who actually use the tools
If you start from a written policy alone, the policy stays sterile. If you build the system first, the policy becomes adoptable.
Minimum plan in 4 weeks
To make it concrete:
- Week 1: map uses and processes
- Week 2: define minimum boundaries
- Week 3: assign ownership and validation
- Week 4: train the people who actually use the tools
How to get started with AI governance compliant with the EU AI Act?
Our Diagnostic Assessment includes a specific section on EU AI Act readiness. In 7 minutes you get:
- a snapshot of your AI maturity level
- the specific gaps against the obligations of the EU AI Act
- a tailored path to close those gaps in 14–30 days
It’s not legal advice — it’s operational governance. The system we build with you automatically documents how AI is used, keeps a human in the loop, and produces traceable output.
If you want an even more practical take on the problem, continue with AI Policy for SMBs: an operational checklist to avoid chaos or go straight to the For Companies page.
“ROI-operational governance, not institutional governance. Total control, not black box.” — AIEH™