Skip to content
EU AI ActSMB GuideEnforcement 8 min read

EU AI Act August 2 Enforcement: The 5-Minute SMB Readiness Check

As of August 2, 2026, EU AI Act Article 50 transparency and GPAI obligations are active — but high-risk (Annex III) obligations were separately deferred to December 2027 (see below). Most SMBs don't know which track applies to them. Five questions tell you everything you need to know to act this week.

EU AI Act enforcement status (as of August 2026)

  • • Prohibited AI systems (Art. 5): Banned since February 2, 2025
  • • High-risk AI obligations (Annex III): Deferred to December 2027 (2025 Digital Omnibus)
  • • GPAI model obligations: Active since August 2, 2025
  • • Limited-risk transparency (Art. 50): Active since August 2, 2026

Why most SMBs are behind

The EU AI Act was discussed extensively in tech media, but almost always in the context of large AI companies — OpenAI, Google, Microsoft. The law applies to them. It also applies to the 50-person SaaS startup selling HR software into Germany, the 30-person recruitment platform serving French companies, and the healthtech startup serving NHS-adjacent providers.

Most of those companies never got a clear, practical explanation of what they need to do. They got news articles about fines of 3% of global revenue and assumed the law was aimed at someone bigger than them.

It isn't. The EU AI Act has no SMB exemption for high-risk AI systems. If your AI feature makes high-risk decisions about EU residents, the obligations are the same whether you have 30 employees or 30,000.

The 5-question readiness check

1

Does your product operate in EU markets, make decisions about EU residents, or have EU customers?

If YES

EU AI Act applies to you — extraterritorial reach mirrors GDPR.

If NO

EU AI Act probably does not apply directly. Watch for contracts requiring compliance anyway.

2

Does your AI system make decisions about hiring, credit, insurance, education access, or critical infrastructure?

If YES

High-risk AI system (Annex III). Full technical documentation, DPIA, conformity assessment required — obligations apply from December 2027 (deferred from August 2026 by the 2025 Digital Omnibus), so you have runway, but the documentation work is substantial and worth starting now.

If NO

Continue to question 3.

3

Does your product interact with natural persons without clearly disclosing it is AI?

If YES

Limited-risk AI system (Art. 50). Transparency disclosures have been required since the August 2, 2026 enforcement date — this track was NOT deferred.

If NO

Continue to question 4.

4

Is your AI system a general-purpose AI model (GPAI) with more than 10^25 FLOPs training compute?

If YES

GPAI provider obligations apply (Art. 51–56). Systemic risk assessment required.

If NO

If you use a third-party GPAI provider (GPT-4, Claude, Gemini), you are a deployer — not a provider — and have a different set of obligations.

5

Did you train or fine-tune an AI model on copyrighted text or content?

If YES

GPAI transparency requirements (Art. 53) require publishing a summary of training data. Opt-out mechanisms for copyright holders must be honoured.

If NO

Standard AI Act obligations for deployers apply.

What high-risk actually means for you

If any of your AI features are high-risk under Annex III, the obligations are substantial — and the compliance deadline is December 2027, not August 2026 (deferred by the 2025 Digital Omnibus). That runway is real, but Annex IV technical documentation is the most time-consuming item on this list, so waiting until 2027 to start is a mistake:

Risk management system (Art. 9)

Document the identified risks, the testing methods, and the residual risk decision. Not a checkbox — an ongoing process.

Technical documentation (Annex IV)

8 required sections: system description, intended purpose, training data governance, accuracy and robustness metrics, human oversight design, post-market monitoring plan, and more.

Data governance (Art. 10)

Training and validation datasets must meet quality criteria. Bias testing is required before deployment.

Instructions for use to deployers (Art. 13)

Providers must give deployers clear instructions covering the system's capabilities, limitations, human oversight measures, and provider contact details — this is a provider-to-deployer duty, not a direct notice to end users.

Human oversight (Art. 14)

High-risk AI systems must be designed so humans can understand, monitor, and intervene. Automated decisions without human review are prohibited in most high-risk categories.

Post-market monitoring (Art. 72)

Performance must be monitored after deployment. Incidents must be reported to national market surveillance authorities.

What limited-risk means for you

Limited-risk AI systems — chatbots, AI-generated content, synthetic media — primarily have transparency obligations under Art. 50:

These are simpler obligations — but many SaaS companies have not yet shipped the required disclosures. Enforcement for transparency violations will come from national data protection authorities, who already have experience with GDPR enforcement. The machinery exists.

What to do this week

Run your EU AI Act classification free

Answer 5 questions about each AI feature. Get your risk tier, the specific Annex III category, and the obligations that apply. No account required.

This article is informational and does not constitute legal advice. EU AI Act compliance determinations should be confirmed with qualified legal counsel in your jurisdiction. References: Regulation (EU) 2024/1689 (EU AI Act); EU AI Office enforcement guidance Q1 2026. Last updated: April 2026.

EU AI Act August 2 Enforcement: The 5-Minute SMB Readiness Check | Aegis Firma