Why the EU AI Act matters for SMEs now
The EU AI Act is the world’s first comprehensive AI law, and it applies well beyond big tech. If your business puts an AI system on the market or uses one in the EU — including many SMEs deploying automation or document processing — some of its obligations reach you. Crucially, it is risk-based: what you must do depends on what the system does, not how large your company is.
The pragmatic takeaway for 2026 is that compliance is not a one-off legal box-tick. It is an operating discipline — knowing your systems, classifying them honestly, and keeping the evidence to show you did.
The risk tiers, in plain terms
- Unacceptable risk — a small set of prohibited uses (e.g. social scoring). Simply off-limits.
- High risk — systems in sensitive domains (recruitment, credit, and similar) carry the heaviest duties: risk management, data governance, human oversight, and documentation.
- Limited risk — mainly transparency: people should know when they are dealing with an AI, and AI-generated content should be identifiable.
- Minimal risk — most everyday business automation, where obligations are light — but good governance still pays off.
Where GDPR and the AI Act overlap
If your AI touches personal data — and most business systems do — GDPR still applies in full, alongside the AI Act. The two reinforce each other: GDPR’s lawful basis, data minimisation, and right-to-explanation map neatly onto the AI Act’s demands for data governance and human oversight. Treating them as one programme, rather than two separate audits, is both cheaper and more defensible.
The failure mode we see most is a capable AI tool adopted without a record of what personal data it uses, on what basis, and who can override it. That gap is easy to close early and painful to close late.
A practical compliance checklist
- Inventory every AI system in use and classify each against the risk tiers.
- For anything touching personal data, document the lawful basis and data flows.
- Ensure a human can review, explain, and reverse consequential automated decisions.
- Label AI interactions and AI-generated content where transparency applies.
- Keep an audit trail — decisions, data sources, and model changes — as living evidence.
Blog
Insights, frameworks, and strategies from the Algorythmos team on AI, security, and data innovation.