The world’s first artificial intelligence law is now in force. Understand the four risk levels, which obligations affect you, what deadlines apply and how to comply without needing your own legal department
The AI Act (European Artificial Intelligence Regulation) is the world’s first comprehensive AI legislation. It entered into force on 1 August 2024 and its obligations are being introduced in phases between 2025 and 2027. This is not future regulation: it is a legal reality that is already affecting how European companies can use artificial intelligence.
If you have an SME, an ecommerce business or a mid-sized company that uses AI tools, even if it is just a customer-service chatbot, a recommendation engine or a content-generation assistant, the AI Act affects you. The good news is that most of these uses fall into the categories of minimal or limited risk, whose obligations are manageable if you know what to do.
In this article, we explain the AI Act in practical terms: its risk classification, the obligations associated with each level, the applicable deadlines and how to prepare your company with a concrete checklist.
What is the AI Act and why does it matter to you even if you are an SME?
The AI Act regulates the use of artificial intelligence systems in the European Union using a risk-based approach. It does not regulate the technology itself, but how it is used and what impact it has on people. This means that the same AI model may have different obligations depending on what you use it for.
The logic is similar to that of the GDPR for personal data: it does not prohibit the use of AI, but requires you to use it with governance, transparency, evidence and human oversight proportionate to the risk.
The AI Act does not operate alone. It sits within a broader regulatory landscape that includes:
- GDPR: Protection of personal data. Any AI system that processes personal data must comply with the GDPR (DPIA, legal basis, consent and data-subject rights).
- NIS2: Security of networks and information systems. If your AI operates on critical infrastructure, NIS2 applies.
- DMA/DSA: Regulation of digital markets and services. Relevant if you operate on marketplaces or digital platforms.
Key point for SMEs: The AI Act includes specific support measures for SMEs: regulatory sandboxes, proportionally reduced penalties and simplified documentation. You are not alone in facing the regulation.
The four risk levels: the decision that determines everything
Risk classification is the central decision under the AI Act. It determines all the obligations that are triggered. It is established by answering four questions: does it affect people? Does it produce legal or significant effects? In what environment is it used? What role does your company have (provider, deployer or distributor)?
Unacceptable risk (prohibited)
Systems that cannot be placed into service under any circumstances. They do not admit controls or mitigation.
- Subliminal manipulation that causes significant harm.
- Social scoring by public authorities.
- Biometric categorisation based on sensitive attributes (race, religion or sexual orientation).
- Emotion recognition in workplaces or educational settings.
- Real-time biometric identification in public spaces (with narrowly defined police exceptions).
Penalty: Up to €35 million or 7% of global turnover.
High risk
Systems that make decisions affecting fundamental rights. There are two types:
High risk by use (stand-alone): Recruitment (hiring and dismissal), educational admission, academic assessment, access to essential services (public benefits, insurance and loans), law enforcement and justice.
Embedded high risk: Safety components such as AI medical devices, industrial emergency-stop systems and autonomous vehicles.
Obligations: Documented risk management, mandatory human oversight, traceability logs, a complete technical file, a fundamental rights impact assessment (FRIA) and post-market monitoring.
Penalty: Up to €15 million or 3% of global turnover.
Limited risk
Systems that are not high risk but require transparency obligations:
- Tell users that they are interacting with an AI system (chatbots and virtual assistants).
- Clearly label AI-generated content (text, images, video and audio).
- Include watermarks or detectable metadata in synthetic content.
Penalty: Up to €7.5 million or 1% of global turnover.
Minimal risk
The vast majority of AI uses in an SME: spam filters, product recommendation engines, internal automations without a direct impact on people and AI in video games. They have no special restrictions beyond general compliance with the law.
Important: General-purpose AI models (GPAI) such as ChatGPT, Gemini or Claude are not a risk level: they are a separate category. Their obligations fall on the model provider (OpenAI, Google or Anthropic), not on you. What defines whether your case is high risk is how you use it in your company, not which model you use.
Which systems you already use are affected?
Make a quick inventory. These are the most common uses in SMEs and their likely classification:
- Customer-service chatbot: Limited risk. You must tell users that they are speaking with an AI.
- Product recommendation engine: Minimal risk. No special obligations.
- Content-generation assistant (text and images): Limited risk. You must label the content as AI-generated.
- Credit-scoring or creditworthiness-assessment tool: High risk. Requires a complete technical file and FRIA.
- AI candidate-selection system: High risk. The same regime applies.
- Marketing email automation: Minimal risk.
- AI for internal data analysis: Minimal risk, unless it processes personal data (the GDPR applies).
- Spam filters and fraud detection: Minimal risk.
Most SMEs will operate in the minimal- and limited-risk zones. But it is essential to make this classification formally, because it is the first mandatory AI Act artefact: the risk-classification sheet.
FRIA and the technical file: what they are and when you need each
Technical file
This is the central AI Act document for every high-risk AI system. It is a living document describing what the system does, what data it uses, how it is controlled, how it is supervised, what risks it has and how they are mitigated. At a minimum, it must include: the system’s purpose and limits, datasets and data governance, quality metrics and thresholds, risks and safeguards, human oversight, logs and traceability, security and change management.
It is the main documentary evidence in audits. If your AI is high risk and you do not have a technical file, you are not compliant.
FRIA (Fundamental Rights Impact Assessment)
It complements the GDPR DPIA. It does not assess privacy, but impacts on fundamental rights: education, work, non-discrimination and the presumption of innocence. It is mandatory for high-risk systems that affect people in areas such as social benefits, public housing, educational assessment or candidate pre-selection.
Good news for SMEs: If your AI operates at minimal or limited risk, you do not need a technical file or FRIA. You do need the risk-classification sheet and must comply with transparency obligations where applicable. These are simple documents that can be prepared in hours, not months.
Implementation timetable: what deadlines apply?
- February 2025 (already in force): Prohibited AI practices and AI-literacy obligations.
- August 2025 (already in force): Rules for general-purpose AI models (GPAI). Member States designate national authorities and create regulatory sandboxes.
- August 2026: Most rules enter into force. High-risk systems (Annex III) and transparency obligations (Article 50). This is the critical date for most companies.
- August 2027: Full application. AI models already deployed before August 2025 must comply by this date.
Grace period: If your company already had AI systems operating before August 2025, you have until August 2027 to adapt them. But if you deploy a new high-risk system from August 2026 onwards, it must comply from day one.
The roles under the AI Act: what role does your company play?
The AI Act does not only regulate technology: it regulates who does what. Your role determines your obligations:
- Provider: The party that develops the AI system or makes substantial changes. It must provide risk management, technical documentation, human oversight, logs and post-market monitoring.
- Deployer: The company that uses the system. It must validate it in a real environment, operate it with human oversight, record incidents, manage changes and withdraw the system if it degrades. This is probably your role.
- Importer/Distributor: When the system comes from outside the EU or is relabelled.
If you use ChatGPT, Shopify Magic or any third-party AI, you are the deployer. OpenAI, Shopify or Google are the providers. But you are responsible for how you use these tools in your business context.
Penalties: how much can non-compliance cost you?
The AI Act establishes a graduated penalty regime according to the seriousness of the infringement:
- Prohibited practices (unacceptable risk): Up to €35 million or 7% of annual global turnover, whichever is higher.
- Failure to comply with high-risk obligations: Up to €15 million or 3% of global turnover.
- Other infringements (transparency and documentation): Up to €7.5 million or 1% of global turnover.
For SMEs, penalties are limited to the percentage or fixed amount, whichever is lower. This means that an SME with €2 million in turnover would face a maximum of €140,000 for a high-risk infringement (3%), not €15 million. But it is still an amount that could seriously jeopardise the business.
Context: Beyond financial fines, non-compliance with the AI Act can lead to mandatory withdrawal of the AI system from the market, reputational damage and loss of trust from customers and partners. The real cost of non-compliance always exceeds the cost of preparing.
Compliance checklist for SMEs: 10 steps to prepare
- Make an AI inventory. List every AI tool and use in your company, including Shadow AI.
- Classify each system by risk level. Use the AI Act classification sheet: does it affect people? Does it produce legal effects?
- Identify your role for each system. Are you the provider or the deployer?
- Meet transparency requirements (limited risk). Add AI notices to chatbots and labels to generated content.
- Prepare the technical file (high risk only). Document purpose, data, controls, metrics and human oversight.
- Carry out a DPIA if you process personal data with AI. A GDPR obligation reinforced by the AI Act.
- Carry out a FRIA if your system is high risk. Assess the impact on fundamental rights.
- Require due diligence from your AI providers. Factsheet, DPA prohibiting retraining and SLAs.
- Implement human oversight (HITL). Define who reviews, when and how interventions are recorded.
- Document everything from day one. Records, logs, changelog, metrics and incidents. Traceability is the key to the entire AI Act.
“The AI Act is not an obstacle to innovation. It is the framework that turns regulatory compliance into a reputational and competitive asset.”
How the AI Act fits with your governance model
If you already have (or are setting up) an AI Steering Committee with a Gate system, the AI Act fits naturally. The artefacts required by the regulation are the same ones you already produce at each decision gate:
- Gate 0 (Ideation): The risk-classification sheet required by the AI Act is the first Gate 0 artefact. If you classify the risk at the start, you know exactly which obligations are triggered.
- Gate 1 (Pilot): The DPIA-lite, FRIA (if applicable), grounding controls and model factsheet are the evidence you need both for Gate 1 of your governance and to demonstrate compliance to the regulator.
- Gate 2 (Production): The technical file, incident runbook, rollback test and SLAs are AI Act requirements for high-risk systems and, at the same time, the evidence for your Gate 2.
In other words: if you follow a Gate-based governance model, you are already doing 80% of the AI Act compliance work. The regulation does not add new bureaucracy; it gives legal form to the good practices you should already follow.
The conclusion: preparing now is cheaper than adapting later
The AI Act is not going away and the deadlines are approaching. For most SMEs, the obligations are reasonable: classify your AI uses, comply with transparency requirements, carry out due diligence on your providers and document what you do.
Companies that integrate compliance into their operating model from the start (with an AI Steering Committee, a Gate system and a Lite AI Policy) will not only avoid penalties: they will build trust with customers, partners and investors.
Because in the AI era, governance is not a brake. It is your best competitive advantage.
Do you need help classifying your AI systems and complying with the AI Act? At Impulsa3, we support you with a practical assessment, the classification sheet and a compliance roadmap adapted to your business.
Sources and references
- Regulation (EU) 2024/1689 — AI Act (European Artificial Intelligence Regulation)
- EU AI Act Implementation Timeline (artificialintelligenceact.eu)
- Small Businesses’ Guide to the AI Act (EU)
- European Institute of Postgraduate Studies — Master’s documentation on AI Transformation: AI Act for Managers I and II
- GDPR (General Data Protection Regulation)
- NIS2 (Network and Information Systems Security Directive)
- NIST AI Risk Management Framework (AI 100-1)