AI ACT WIKI · START HERE

The AI Act in 10 minutes

The European framework, the risk levels and the first deadlines. · 10 min read.

EXPLAINER

The answer in thirty seconds

The AI Act is a European regulation that classifies not technologies but uses. The more a use can harm a person, the heavier the obligations. The vast majority of small businesses sit right at the bottom of the scale: using ChatGPT, an automatic proofreader or a customer service chatbot creates, today, one single concrete obligation — saying when it is an AI that is speaking or that produced the content.

The four levels, in order

Prohibited. A short list of practices has been banned outright since February 2025: social scoring, manipulation that exploits a vulnerability, emotion recognition in the workplace and in schools, and the untargeted scraping of facial images to build facial recognition databases. Two further prohibitions are added on 2 December 2026, covering non-consensual intimate content and AI-generated child sexual abuse material.

High-risk. The uses that decide a person’s fate: recruiting, granting credit, marking a pupil, filtering access to an essential service — that is Annex III. And AI embedded in products that are already regulated, from machinery to medical devices — that is Annex I. The matching obligations only start to apply in December 2027 and August 2028.

Transparency risk. Chatbots, generated content, deepfakes. You have to disclose it. This has applied since 2 August 2026, and it is by far the most common case in business.

Minimal risk. Everything else, with no particular obligation: spam filters, product recommendations, proofreaders.

Who is covered

The regulation does not talk about ‘companies’ but about roles, and that distinction changes everything. The provider develops the system or places it on the market under its own name. The deployer uses it in the course of its professional activity. A small business using off-the-shelf tools is a deployer: its obligations are vastly lighter. But it becomes a provider if it puts its own brand on an AI tool, or if it substantially modifies the intended purpose — and many do not realise it.

A real example

A six-person agency uses a generative assistant for writing, a chatbot on its website and a tool that screens job applications. Today it has to: flag its chatbot as automated, state that the content it publishes on matters of public interest is AI-generated when it has not been reviewed by an identified human, and take reasonable measures so that its teams know how to use these tools. Its CV-screening tool is indeed high-risk — but it has until December 2027 to get ready.

The fines, without the hype

The ceilings are high: 35 million euros or 7% of worldwide turnover for prohibited practices, 15 million or 3% for the other obligations including transparency, 7.5 million or 1% for inaccurate information supplied to the authorities.

But one paragraph changes everything for a small business, and it is almost always passed over in silence. Article 99(6) says, word for word: ‘In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.’ For a small company it is therefore the lower figure that applies, not the higher one. In other words: the numbers circulating everywhere are not the ones that concern you.

What you can do tomorrow

The mistakes you read everywhere

‘Since 2 August 2026, the whole regulation applies.’ No: that is the general date of application, but the ‘high-risk’ obligations are precisely the ones postponed to December 2027 and August 2028 by the Digital Omnibus, which entered into force on 27 July 2026.

‘2 August 2027, high-risk systems embedded in products.’ That date still exists, but for the national regulatory sandboxes and the oldest general-purpose AI models. High-risk embedded in products is 2 August 2028.

‘A 15 million fine if your staff are not trained.’ See the page on using ChatGPT at work: the obligation has been rewritten, and it is far milder than announced.

Your next step

Compare this page with how you actually work, then ask the community if anything is still unclear.

Ask the community →

Reference sources

Going further

This page is based on the consolidated text of Regulation (EU) 2024/1689 in its version of 27 July 2026. Verified 26 August 2026. General information: it does not constitute individual legal advice.