The EU AI Act for SMEs: what changed on 2 August 2026
4 min read
What has applied since 2 August 2026
On 2 August 2026 most of the European AI Act became applicable. Press coverage went mainly to the makers of the large language models. The question a smaller company actually has is more practical. Something is running here in the admin work, does anything now have to change?
For most companies the answer is reassuring. The Act looks at what an application does and who it affects, not at how advanced the technology is. A system that sorts incoming mail, or that prepares a supplier invoice for the accounts, sits in the lightest category. No heavy obligations come with it. The heavier duties apply where AI helps decide about somebody's job, money or health. For most automation in a smaller company that is not in play.
This article is meant as orientation. It is not legal advice. We are engineers and we read the text the way a company reads it, asking what has to be different tomorrow. If something is genuinely at stake, a lawyer who knows your file is the right person to take it further.
The obligations in plain words
Two things come back at almost every company. A third applies as soon as customers are looking at it.
The first is that the people working with AI understand what the thing does. That takes no training course with a certificate at the end. It comes down to knowing that a model can misread a supplier name, that it rarely says it is unsure, and that somebody therefore checks the result. In practice it is a conversation with the people using it, with a couple of examples of what can go wrong. Somebody who knows that uses such a system differently from somebody who assumes it is always right.
The second is that you know what is running. Which applications use AI, what exactly they do, what data goes in and who approves the result. For the lightest category that is not written into the text as a duty. The moment the duties do apply, that list is the first thing asked for. Drawing it up takes half a page.
The third is about your customers. Anyone talking to a machine has to know it. If a chat window on your site answers questions with AI, the window says so. If you make images or text with AI that could pass for real, it is marked as such. This is the duty that becomes visible fastest on a website. One sentence usually settles it.
When an application counts as high risk
The heavy duties hang on a limited list of applications. It is about AI that helps decide about people: software that ranks job applicants or helps determine who gets promoted, a system that judges whether somebody gets credit or insurance, AI sitting as a safety component inside a machine or a product.
If your application is in that category, a lot changes. Documentation is required on how the system works and what it was trained on. Somebody has to be able to step in, and a record has to be kept of what the system did. That work happens up front, not after something goes wrong.
At most smaller companies, admin automation does not fall under it. An invoice that is recognised and prepared decides nothing about a person. Neither does a mail routed to the right colleague. The line sits at applications that shape somebody's chances. That line is sharper than it looks at first. A system that pre-sorts CVs is on the other side of it, however much it feels like ordinary admin work.
If you are unsure about an application, one question takes you further. Does this system take a decision with consequences for a person, or does it prepare something a person then judges? The first asks for preparation. The second is what most smaller companies are running today.
What it means for AI already running
If something is already running, the useful exercise is a short one. Put on one sheet which applications use AI, what they do and who confirms the result. Add what data goes in and where that data is kept. Whoever has that sheet can answer every question about it without having to think.
Two things this site already promises do the work here. The first is the human click. A proposal only goes through when somebody confirms it, and that records who took the decision. The second is the activity log, holding what came in, what the system pulled out of it and who confirmed it. Together they answer the question almost every duty comes down to: who let this through?
That is no accident. We built it that way because an accountant asks that question and because a customer asks it too. That the legislator asks the same question makes the work no heavier. It mainly makes clear why it was there.
How we handle this in the way we work
We start with one process and describe the scope before anything is built. That description states which steps get taken over and which steps stay with a person. What is not in it is written down as well. That is the part that prevents the arguments later. It is a commercial agreement and at the same time the answer to who stays responsible for what.
The data stays in Europe and your existing packages stay where they are. What the system does is in the log. Where we put a model to work, it works where it is strong, on reading and recognising what comes in. Sending on and posting to the accounts stay with your people.
If nothing is written down at your company today, that list is the place to start. What is running, what does it do and who puts their name under it. Those three columns answer most of the questions an accountant or a customer asks later.
Show us one process.
We walk through a single step in your business together and discuss what automation would change there.