AI Act: what the new European AI regulation requires and how to prepare your company without complications

The world’s first artificial intelligence law is now in force. Understand the four risk levels, which obligations affect you, what deadlines you have and how to comply without needing your own legal department. The AI Act The European Artificial Intelligence Regulation is the world’s first comprehensive legislation on AI. It entered into force on August 1, 2024, and its obligations are being rolled out in phases between 2025 and 2027. It is not a future regulation: it is a legal reality that is already affecting how European companies can use artificial intelligence. If you have an SME, an ecommerce business or a medium-sized company that uses AI tools, even if it is just a customer service chatbot, a recommendation engine or an assistant for generating content, the AI Act affects you. The good news is that most of these uses fall into the categories of minimal or limited risk, whose obligations are manageable if you know what to do. In this article, we explain the AI Act in practical terms: what risk classification it establishes, what obligations each level involves, what deadlines you have and how to prepare your company with a concrete checklist.

What the AI Act is and why it matters to you even if you are an SME

The AI Act regulates the use of artificial intelligence systems in the European Union using a risk-based approach. It does not regulate the technology itself, but rather how it is used and what impact it has on people. This means that the same AI model may have different obligations depending on what you use it for. The logic is similar to that of the GDPR with personal data: it does not prohibit the use of AI, but requires you to do so with governance, transparency, evidence and human oversight proportionate to the risk. The AI Act does not operate in isolation. It is part of a broader regulatory landscape that includes:
  • GDPR: Personal data protection. Any AI system that processes personal data must comply with the GDPR (DPIA, legal basis, consent, data subject rights).
  • NIS2: Network and information systems security. If your AI operates on critical infrastructure, NIS2 applies.
  • DMA/DSA: Regulation of digital markets and services. Relevant if you operate in marketplaces or digital platforms.
Key for SMEs: The AI Act includes specific support measures for SMEs: regulatory sandboxes, proportionally reduced penalties and simplified documentation. You are not facing the regulation alone.

The four risk levels: the decision that determines everything

Risk classification is the central decision of the AI Act. It determines all all the obligations that are triggered. It is established by answering four questions: does it affect people? Does it produce legal or significant effects? In what environment is it used? What role does your company have: provider, deployer or distributor?

Unacceptable risk (prohibited)

Systems that cannot be put into service under any circumstances. They do not allow for controls or mitigation.
  • Subliminal manipulation that causes significant harm.
  • Social scoring by public authorities.
  • Biometric categorization based on sensitive attributes (race, religion, sexual orientation).
  • Emotion recognition in work or education settings.
  • Real-time biometric identification in public spaces (with specific law enforcement exceptions).
Penalty: Up to €35 million or 7% of global turnover.

High-risk

Systems that make decisions affecting fundamental rights. There are two types: High risk by use (stand-alone): Staff selection (hiring, dismissal), educational admission, academic assessment, access to essential services (public benefits, insurance, loans), law enforcement and justice. Embedded high risk: Safety components such as AI-powered medical devices, industrial emergency shutdown systems, and autonomous vehicles. Obligations: Documented risk management, mandatory human oversight, traceability logs, complete technical documentation, fundamental rights impact assessment (FRIA), post-market monitoring. Penalty: Up to 15 million euros or 3% of global turnover.

Limited risk

Systems that are not high risk but require transparency obligations:
  • Inform the user that they are interacting with an AI system (chatbots, virtual assistants).
  • Clearly label AI-generated content (text, images, video, audio).
  • Include watermarks or detectability metadata in synthetic content.
Penalty: Up to 7.5 million euros or 1% of global turnover.

Minimal risk

The vast majority of AI uses in an SME: spam filters, product recommendation engines, internal automations with no direct impact on people, AI in video games. They have no special restrictions beyond general compliance with laws.
Important: Los modelos de propósito general (GPAI) como ChatGPT, Gemini o Claude no son un nivel de riesgo: son una categoría aparte. Sus obligaciones recaen sobre el proveedor del modelo (OpenAI, Google, Anthropic), no sobre ti. Lo que define si tu caso es high-risk es el uso que haces en tu empresa, no el modelo que usas.

Which systems you already use are affected?

Do a quick inventory. These are the most common uses in SMEs and their likely classification:
  • Customer service chatbot: Limited risk. You must inform the user that they are speaking with an AI.
  • Product recommendation engine Minimal risk. No special obligations.
  • Content generation assistant (text, images): Limited risk. You must label the conte
  • Credit scoring or creditworthiness assessment tool: Alto riesgo. Requiere expediente técnico completo y FRIA.
  • AI-based candidate selection system: High risk. Same regime.
  • Marketing email automation: Minimal risk.
  • AI for internal data analysis: Minimal risk, unless it processes personal data (GDPR applies).
  • Spam filters and fraud detection: Minimal risk.
Most SMEs will operate in the minimal and limited risk areas. But it is essential to make this classification formally, because it is the first mandatory artifact under the AI Act: the risk classification sheet.

FRIA and technical documentation: what they are and when you need each one

Technical documentation

It is the central AI Act document for every high-risk AI system. A living document that describes what the system does, with what data, how it is controlled, how it is supervised, what risks it has and how they are mitigated. It must include, at a minimum: the system’s purpose and limits, datasets and data governance, quality metrics and thresholds, risks and safeguards, human oversight, logs and traceability, security and change management. It is the main documentary evidence in audits. If your AI is high risk and you do not have technical documentation, you are not compliant.

FRIA (Fundamental Rights Impact Assessment)

It complements the GDPR DPIA. It does not assess privacy, but rather impacts on fundamental rights: education, work, non-discrimination, presumption of innocence. It is mandatory for high-risk systems that affect people in areas such as social benefits, public housing, educational assessment or candidate preselection.
Good news for SMEs: If your AI operates at minimal or limited risk, you do not need technical documentation or a FRIA. What you do need is the risk classification sheet and to comply with transparency obligations where applicable. These are simple documents that can be prepared in hours, not months.

Application timeline: what deadlines you have

  • February 2025 (already in force): Prohibited AI practices and AI literacy obligations.
  • August 2025 (already in force): Rules for general-purpose AI models (GPAI). Member States designate national authorities and create regulatory sandboxes.
  • August 2026: Most rules enter into force. High-risk systems (Annex III) and transparency obligations (Article 50). This is the critical date for most companies.
  • August 2027: Full application. AI models already deployed before August 2025 must comply by this date.
Grace period: Grace period: If your company already had AI systems in operation before August 2025, you have until August 2027 to adapt them. But if you deploy a new high-risk system from August 2026 onwards, it must comply from day one.

The roles under the AI Act: what role does your company play?

The AI Act does not only regulate technology: it regulates who does what. Your role determines your obligations:
  • Provider: Whoever develops the AI system or makes substantial changes. They must provide risk management, technical documentation, human oversight, logs and post-market monitoring.
  • Deployer: The company that uses the system. It must validate it in a real-world environment, operate it with human oversight, record incidents, manage changes and withdraw the system if it degrades. This is probably your role.
  • Importer/Distributor: When the system comes from outside the EU or is relabelled.
If you use ChatGPT, Shopify Magic or any third-party AI, you are deployer. OpenAI, Shopify or Google are the providers. But you are responsible for how you use those tools in your business context.

Penalties: how much non-compliance can cost you

The AI Act establishes a tiered penalty regime depending on the severity of the infringement:
  • Prohibited practices (unacceptable risk): Up to €35 million or 7% of annual global turnover, whichever is higher.
  • Non-compliance with high-risk obligations: Up to 15 million euros or 3% of global turnover.
  • Other infringements (transparency, documentation): Up to 7.5 million euros or 1% of global turnover.
For SMEs, penalties are limited to the percentage or the fixed amount, whichever is lower. This means that an SME with €2 million in turnover would face a maximum of €140,000 for a high-risk infringement (3%), not €15 million. But it is still an amount that can seriously jeopardize the business.
Context: Beyond financial penalties, non-compliance with the AI Act may lead to the mandatory withdrawal of the AI system from the market, reputational damage and loss of trust from customers and partners. The real cost of non-compliance always exceeds the cost of preparation.

Compliance checklist for SMEs: 10 steps to prepare

  1. Create an AI inventory. List all AI tools and uses in your company, including Shadow AI.
  2. Classify each system by risk level. Use the AI Act classification sheet: does it affect people? Does it produce legal effects?
  3. Identify your role for each system. Are you a provider or a deployer?
  4. Comply with transparency requirements (limited risk). Add AI notices in chatbots and labels on generated content.
  5. Prepare the technical documentation (high risk only). Document purpose, data, controls, metrics and human oversight.
  6. Carry out a DPIA if you process personal data with AI. A GDPR obligation that is reinforced by the AI Act.
  7. Carry out a FRIA if your system is high risk. Assess the impact on fundamental rights.
  8. Require due diligence from your AI providers. Factsheet, DPA prohibiting retraining, SLAs.
  9. Implement human oversight (HITL). Define who reviews, when and how interventions are recorded.
  10. Document everything from day one. Records, logs, changelog, metrics, incidents. Traceability is the key to the entire AI Act.

“The AI Act is not an obstacle to innovation. It is the framework that turns regulatory compliance into a reputational and competitive asset.”

How the AI Act fits into your governance model

If you already have, or are setting up, an AI Steering Committee with a Gate system, the AI Act fits naturally. The artifacts required by the regulation are the same ones you already produce at each decision gate:
  • Gate 0 (Ideation): The risk classification sheet required by the AI Act is the first artifact of Gate 0. If you classify the risk at the start, you know exactly which obligations are triggered.
  • Gate 1 (Pilot): El DPIA-lite, la FRIA (si aplica), los controles de grounding y la factsheet del modelo son las evidencias que necesitas tanto para el Gate 1 de tu gobernanza como para demostrar cumplimiento al regulador.
  • Gate 2 (Production): The technical documentation, incident runbook, rollback test and SLAs are AI Act requirements for high-risk systems and, at the same time, the evidence for your Gate 2.
In other words: if you follow the Gate-based governance model, you are already doing 80% of the AI Act compliance work. The regulation does not add new bureaucracy; it gives legal form to the good practices you should already be following.

The conclusion: preparing now is cheaper than adapting later

The AI Act is not going to disappear and the deadlines are fast approaching. For most SMEs, the obligations are reasonable: classify your AI uses, comply with transparency requirements, carry out due diligence on your providers and document what you do. Companies that integrate compliance into their operating model from the start—with an AI Steering Committee, a Gate system and a Lite AI Policy—will not only avoid penalties: they will build trust with customers, partners and investors. Because in the age of AI, governance is not a brake. It is your best competitive advantage.

Do you need help classifying your AI systems and complying with the AI Act? At Impulsa3, we support you with a practical assessment, the classification sheet and your compliance roadmap tailored to your business.

Sources and references

  • Regulation (EU) 2024/1689 — AI Act (European Artificial Intelligence Regulation)
  • EU AI Act Implementation Timeline (artificialintelligenceact.eu)
  • Small Businesses’ Guide to the AI Act (EU)
  • European Postgraduate Institute — Master’s in AI Transformation documentation: AI Act for Managers I and II
  • GDPR (General Data Protection Regulation)
  • NIS2 (Directive on Security of Network and Information Systems)
  • NIST AI Risk Management Framework (AI 100-1)