The EU AI Act became fully applicable in 2025, making it the world's first comprehensive legal framework for artificial intelligence. Most of the coverage has focused on large technology companies and high-risk systems. Far less attention has been paid to what it means in practice for the small and medium businesses that are the backbone of the European economy.

The basic structure you need to understand

The AI Act classifies AI systems into four risk categories:

Unacceptable risk — prohibited entirely. Social scoring systems, real-time biometric surveillance, systems that exploit psychological vulnerabilities. If your business is not doing any of these things, this category is irrelevant to you.

High risk — subject to strict requirements before deployment. AI used in hiring, credit scoring, education, critical infrastructure, and healthcare. If you use AI in any of these contexts, you need to pay attention.

Limited risk — transparency obligations. Chatbots and customer-facing AI systems must disclose that users are interacting with AI.

Minimal risk — no specific obligations. Most AI applications businesses use daily fall here: spam filters, recommendation engines, basic analytics.

What this means for a typical SME

If you are a small or medium business using AI primarily to improve internal efficiency — automating document processing, using AI writing tools, analysing sales data — you are almost certainly in the minimal or limited risk category. Your obligations are manageable.

The limited risk obligations are straightforward: if you deploy a customer-facing AI system, you must tell people it is AI. If you use AI-generated content in a way that could mislead, you must label it. These are not technically complex requirements.

Where things become more complicated is if you are using AI in HR decisions, credit-related decisions, or any context that significantly affects people's rights or access to services.

The intersection with GDPR

The AI Act does not replace GDPR — it sits on top of it. For most businesses, the more immediate compliance concern remains data protection: how is the data you feed into AI systems collected, stored, and processed?

Many AI compliance problems I encounter in practice are not AI Act problems — they are GDPR problems wearing AI clothes.

A company that connects its CRM to an AI tool without reviewing what customer data is being processed and where it is going is creating a GDPR liability, regardless of what the AI does with it.

Three things to do now

  1. Inventory your AI tools. List every AI-powered tool your company uses — including the ones embedded in software you already pay for. Many businesses are surprised by how many there are.
  2. Classify them by risk. For each tool, ask: does this affect hiring, lending, access to services, or any decision that significantly impacts a person? If yes, look more carefully.
  3. Review your data flows. For every AI tool that processes personal data, verify that your data processing agreements are in place and that your privacy policy reflects the use of AI.

None of this requires a legal team. It requires clarity and a couple of hours of structured thinking.

A note on the timeline

The prohibitions on unacceptable risk systems applied from February 2025. Obligations for high-risk systems are phasing in through 2025 and 2026. The general-purpose AI model requirements apply from August 2025. If you have been waiting to see how things develop before acting, the development has now happened.