European update · checked 25 August 2026
The 2026 AI Act: what an SME should review
Checked on 25 August 2026: the European Commission says the AI Act became applicable on 2 August 2026, with exceptions and a progressive timetable. For many SMEs using off-the-shelf tools, the first job is not high-risk paperwork: it is knowing which systems are in use, whether they interact with people, and whether they generate or alter content.
What applies now
The Commission says supervisory powers and specific transparency duties apply from 2 August 2026. A chatbot must disclose that it is a machine; certain generated or manipulated content, such as deepfakes, must be identified; and synthetic content may need machine-readable marking where the rule applies.
One nuance matters: the Commission envisages a limited grace period for some content-generation systems placed on the market before 2 August 2026, with marking and detection duties from 2 December 2026. Do not turn that exception into permission to hide a new chatbot.
Are you a provider or a deployer?
A business integrating a third-party tool into support, marketing or back office is often a deployer; the organisation developing and placing a system on the market may be the provider. The role depends on the system and your conduct, not whether the company has five or fifty people. If you make substantial changes, rename the system or put it under your brand, get legal advice before assuming you are only a deployer.
An afternoon checklist
- Make an inventory: tool, provider, purpose, data, users and processing country.
- Mark customer interaction, voice, image, public text, or decisions affecting people.
- Keep the provider’s information on use, logs, training, filters and export.
- Write the notice a person will see when speaking to AI or viewing generated content.
- Name a human owner and a kill switch. A doubtful output is reviewed or stopped.
- Train the team on allowed use and what must never be pasted into the tool.
Dates not to mix up
The Commission places rules for high-risk systems in certain areas on 2 December 2027, and rules for AI embedded in regulated products on 2 August 2028, following the AI Omnibus agreement. Those dates do not postpone transparency duties that may already apply to your chatbot, image generator or public content.
The AI Act does not replace GDPR, employment law or sector rules. A system can be limited-risk and still need a legal basis, employee information or contractual controls.
What to ask the vendor
Ask for a purpose and role sheet, version, relevant training-data information, prompt retention, sub-processors, transparency controls, incident handling and support channel. “We comply with European AI law” on a marketing page is not enough. If the vendor will not answer, use synthetic data and do not connect the system to customers.
Bottom line: an SME does not need a legal department for every experiment, but it does need to stop treating AI as an invisible box. Inventory, notice, human review, an identifiable vendor and a last-checked date are a sound first control.
Official sources checked on 25 August 2026: European Commission · AI regulatory framework, European Commission · enforcement, European Commission · Article 50 transparency and European Commission · AI Omnibus. This is an operational guide, not legal advice.
Studio in Barcelona. Part of Clutch Developer. Oriented to Spain’s SME digitalisation programmes. Request an assessment.