megamenu

Joint Professional Master’s Degree in Advanced Digital Technologies for Business

The EU AI Act enters a new phase: what European SMEs need to know

Artificial intelligence is rapidly becoming part of everyday business. From customer service chatbots and recruitment tools to marketing content, forecasting and data analysis, AI is helping small and medium-sized enterprises improve efficiency and compete in increasingly digital markets.

However, as AI becomes more widely used, businesses also need to understand how these systems operate, what risks they introduce and what responsibilities come with using them.

On 2 August 2026, the European Union’s Artificial Intelligence Act entered an important new phase. The European Commission’s AI Office and national authorities began enforcing applicable provisions of the Act, while new transparency requirements for certain AI systems also came into effect.

For European SMEs, this does not mean that every use of AI will create a major regulatory burden. Most commonly used AI systems are considered minimal or limited risk. However, every business using AI should now be able to explain where it is being used, who is responsible for it and what safeguards are in place.

Businesses can find an overview of the regulatory framework on the European Commission’s EU AI Act information page.

The AI Act takes a risk-based approach

The AI Act does not regulate every AI system in the same way. Instead, requirements depend on the risks associated with how an AI system is used.

The Act identifies four broad levels of risk:

  • Unacceptable-risk AI practices, which are prohibited
  • High-risk AI systems, which are subject to detailed requirements
  • AI systems subject to specific transparency obligations
  • Minimal or no-risk applications, which are generally not subject to additional rules

Examples of high-risk uses can include certain AI systems used in recruitment, employee management, education, access to essential services and critical infrastructure. By contrast, many everyday applications, such as spam filters or AI-enabled productivity tools, may fall into the minimal-risk category.

The important point for SMEs is that classification depends not only on the technology itself, but also on its intended purpose and the context in which it is used.

An AI tool used to help draft an internal meeting summary, for example, will create different considerations from an AI system used to rank job candidates or determine whether someone should receive a financial service.

Understand your business’s role

The obligations that apply to an SME can also depend on its role in the AI value chain.

A business that simply uses an existing AI tool may be considered a deployer. A company that develops an AI system, markets it under its own name or substantially modifies an existing system could take on the responsibilities of a provider.

Many SMEs are likely to be deployers of AI rather than developers of foundational models. However, this does not mean they can leave all responsibility to the technology supplier.

Businesses still need to understand what the system is designed to do, whether it is suitable for the intended use and whether employees are using it appropriately. They should also establish who is responsible for approving new AI tools and reviewing their continued use.

AI literacy is now a business requirement

One of the most important elements of the AI Act for businesses is its focus on AI literacy.

Providers and deployers are expected to take measures to ensure that employees and others using AI systems on their behalf have a sufficient level of AI literacy. Training should take account of employees’ existing knowledge, the context in which the technology is used and the people who may be affected by its decisions or outputs.

For SMEs, AI literacy does not mean that every employee needs to become a machine learning specialist.

It does mean that people using AI should understand:

  • What the system can and cannot reliably do
  • How inaccurate or biased outputs can arise
  • When human review is required
  • What business or personal information should not be entered into a tool
  • How to identify potentially misleading AI-generated content
  • How to raise concerns about an AI system or output

This makes training an essential part of responsible AI adoption. A written policy alone will not be enough if employees do not understand how to apply it in their daily work.

Review customer-facing AI and generated content

Transparency is another immediate priority.

From 2 August 2026, transparency obligations apply to certain interactive and generative AI systems. These include requirements intended to ensure that people know when they are interacting with an AI system and when certain content has been generated or manipulated using AI.

SMEs should review areas such as:

  • Customer service chatbots and virtual assistants
  • AI-generated or manipulated images, audio and video
  • Synthetic spokesperson or avatar content
  • Deepfakes
  • AI-generated text relating to matters of public interest
  • Automated communications that customers could reasonably mistake for human interaction

The precise obligation will depend on the system, the content and whether the business is acting as a provider or deployer. However, businesses should avoid misleading customers about when AI is being used.

Where disclosure is required, it should be clear, accessible and easy to understand.

Create an inventory of the AI tools being used

Many organisations may already be using more AI than senior management realises.

Employees can access generative AI tools through browsers, software subscriptions, productivity suites and applications that have introduced AI functionality. This can create risks around confidential data, intellectual property, accuracy and inconsistent decision-making.

A practical starting point is to create an AI inventory covering:

  • The name and supplier of each system
  • The business purpose for which it is used
  • Which teams and employees have access
  • The types of data entered into the system
  • Whether outputs influence decisions about people
  • Whether customers or members of the public interact with it
  • Whether human review is required
  • The person responsible for overseeing its use

This inventory can help the business identify which uses are low-risk, which require additional controls and which may need specialist legal or technical assessment.

Ask more questions of technology suppliers

SMEs often rely on third-party technology providers rather than building AI systems themselves. Vendor selection and procurement are therefore becoming important parts of AI governance.

Before adopting a tool, businesses should ask suppliers how the system was designed, how information is processed, whether customer data is used to train models and what safeguards are in place.

Contracts and procurement assessments should consider:

  • Data protection and security
  • Ownership and permitted use of inputs and outputs
  • Accuracy and performance limitations
  • Human oversight features
  • Record-keeping and audit capabilities
  • Transparency and labelling functions
  • Incident reporting
  • Responsibilities under the AI Act

The European Commission has established an AI Act Service Desk and Single Information Platform to help organisations understand which obligations may apply.

Pay particular attention to employment decisions

SMEs should exercise particular care when AI is used in recruitment or employee management.

Certain systems used to filter job applications, evaluate candidates, allocate tasks, monitor performance or make decisions affecting working relationships may be classified as high-risk.

Even before all associated requirements apply, businesses should consider whether an AI-supported process could produce unfair or discriminatory outcomes.

AI should not be allowed to become an unexplained decision-maker. Human oversight remains essential, particularly when a decision could significantly affect someone’s employment, livelihood or access to an opportunity.

The AI Act is not only about compliance

For SMEs, the AI Act should not be viewed solely as another regulatory challenge.

Clearer rules can help businesses adopt AI with greater confidence, build trust with customers and distinguish responsible solutions from poorly governed ones. The Act also includes measures intended to support SMEs and start-ups, including access to regulatory sandboxes and testing environments.

The businesses that gain the most from AI will not necessarily be those that adopt the greatest number of tools. They will be the businesses that understand where AI can create genuine value and have the skills to use it strategically, ethically and securely.

Building practical AI capability through Digital4Business

Digital4Business is helping professionals develop the advanced digital skills needed to lead responsible business transformation.

The programme’s 10 ECTS AI for Business module combines artificial intelligence and machine learning knowledge with practical business applications.

It covers areas including machine learning, data and datasets, natural language processing, computer vision, AI tools and platforms, and the ethical and social implications of AI.

Through strategic applications and hands-on projects, learners explore how AI can improve decision-making and business performance while considering fairness, privacy, security, sustainability and wider societal impacts.

As the AI Act moves from legislation to practical implementation, this combination of technical understanding, strategic thinking and ethical awareness will become increasingly valuable for European organisations.

Learn more about the Digital4Business AI for Business module.

This article is intended to provide general information and does not constitute legal advice.

 

Master’s in Advanced Digital Technologies for Business
Application deadline:
Applications close June 20th. Application deadine for our September 2026 Scholarship is 4 September 2026, 17:00 CET.
Course starts:
September 2026
Course duration:
Up to one year depending on chosen format
Course delivery:
100% online.
Certification:
Master’s degree
Language:
English
Apply now
Apply nowcontact