← Back to blog
27 July 20266 min read

EU AI Act explained for SMEs: does it apply to your business?

What is the EU AI Act?

The EU AI Act (officially: Regulation (EU) 2024/1689) is the first comprehensive European law regulating the use of artificial intelligence. It entered into force in August 2024. Most obligations apply from August 2026.

The law takes a risk-based approach: the greater the risk an AI system poses to health, safety or fundamental rights, the stricter the requirements. There are four risk categories: unacceptable risk (prohibited), high risk (strict requirements), limited risk (transparency obligations) and minimal risk (no obligations).

Who does the EU AI Act apply to?

The law addresses four types of parties:

Providers — companies that develop AI systems and place them on the market. Think of a software company that sells an AI tool.

Deployers — companies that use AI systems developed by others within their own business processes. Think of an HR department that uses an AI tool for CV screening.

Importers and distributors — companies that import AI systems from third countries or resell them within the EU.

Manufacturers of products with built-in AI — think of a machine builder that integrates an AI-driven safety function.

If your company falls into none of these categories — you do not use AI, do not develop AI, and do not sell products with built-in AI — then no obligations under the EU AI Act apply to you.

Does the EU AI Act apply to my SME?

In most cases, not directly. An installation firm, contractor, haulier or manufacturer that neither develops nor sells AI systems falls outside the direct scope of the law.

But there are three situations in which the EU AI Act may affect you after all:

Situation 1 — You use AI for decisions about people. If you deploy AI for personnel decisions (recruitment, appraisal, dismissal), credit assessment of customers, or safety assessments in the workplace, that may fall under the high-risk category. You are then a deployer with obligations: transparency towards those affected, human oversight, and logging of the AI decisions.

Situation 2 — Your customer asks for an AI Act declaration. If you supply software or technology services to a large customer that is itself a deployer of high-risk AI, that customer may — through its supply chain due diligence — ask whether your products or services contain AI and, if so, at what risk level. This is comparable to the way CSRD passes sustainability questions down the chain.

Situation 3 — You develop AI functionality in your product. If your company makes software and adds AI to it — even as a small feature — you are a provider within the meaning of the law. Technical documentation obligations then apply, a conformity assessment for high-risk systems, and registration in the EU database.

For the vast majority of Dutch and European SMEs, situation 1, 2 or 3 does not apply. A roofer, an electrician or a wholesaler of building materials falls outside the direct scope.

What are high-risk AI applications?

Annex III of the EU AI Act lists the high-risk applications. For SMEs, the most relevant categories are:

Employment and workforce management — AI that screens applicants, assesses performance, advises on promotions, or supports contract termination. If you use an HR tool that deploys AI for these decisions, your company is a deployer of high-risk AI.

Access to education and vocational training — AI that determines admission to a course or assesses learning performance.

Safety components of products — AI in machinery, vehicles or medical devices that already fall under existing safety regulation.

Critical infrastructure — AI in energy, water or transport networks.

If your use of AI does not fall into these categories — such as a chatbot on your website, a spell checker, or a product recommendation system — you are dealing with minimal or limited risk. Minimal risk carries no obligations. Limited risk carries only a transparency obligation: users must know that they are interacting with AI.

Prohibited AI applications — what you may never do

Regardless of company size, certain AI applications have been prohibited since 2 February 2025:

Social scoring — AI systems that give people a general score based on behaviour and use that score to disadvantage them in unrelated contexts.

Real-time biometric identification in public spaces — facial recognition on the street or in shops for identification purposes (with narrow exceptions for law enforcement).

Manipulative AI — systems that influence users subconsciously in a way that is harmful to their interests.

Exploitation of vulnerable groups — AI that deliberately exploits the vulnerabilities of children, the elderly or people with disabilities.

For most SMEs, these prohibitions are not relevant to day-to-day operations.

What should you do now, in practical terms?

For most SMEs the answer is straightforward: take stock of which AI tools you use and for what purpose.

Step 1 — Make a list of the AI tools in use. Think of: ChatGPT or comparable tools for text work, AI features in your accounting software, CV screening tools, chatbots on your website, recommendation systems in your web shop.

Step 2 — Assess the use. Do you use these tools for decisions about people (staff, customers)? Then closer examination is needed. Do you use them only for productivity support (writing, translating, summarising text)? Then you fall into the minimal-risk category and there are no obligations.

Step 3 — Document your conclusion. Even if you conclude that the EU AI Act does not apply, it is wise to document that conclusion briefly. Should your customer ever ask, you can give a clear answer.

Step 4 — Keep track of developments. The EU AI Act is new, and its practical application will be filled in further over the coming years through delegated acts and guidelines from the European AI Office. Keep track of this if you deploy AI structurally.

verified.supply helps you keep your compliance profile in order — for sustainability (VS Standard), human rights (CSDDD) and cybersecurity (NIS2). The EU AI Act sits outside our platform because it is not a supply chain reporting obligation, but we do keep you informed about the relevant regulation.

What if my customer asks for an AI Act declaration?

If a large customer asks you to demonstrate that your products or services comply with the EU AI Act, there are two scenarios:

Scenario A — You do not supply AI systems. A short written declaration suffices: "Our products and services contain no AI systems within the meaning of Regulation (EU) 2024/1689. We are not a provider or deployer of AI systems that fall within the scope of the EU AI Act."

Scenario B — You do supply AI functionality. Then, as a provider, you have obligations: technical documentation, a conformity assessment (for high-risk), and registration in the EU database for high-risk systems. For this scenario, consult a legal adviser specialising in EU regulation.

The EU AI Act follows a logic comparable to the CSDDD: large companies must map their chain and can therefore put questions to their suppliers. But unlike CSRD and CSDDD, no standardised reporting format for suppliers has been defined. That makes a simple written declaration the most practical solution for now.

Read also

Build your VS profile (formerly VSME) once

Create an account and get started today.

No password needed — we email you a login link.