Does the EU AI Act Apply to Your Business? A Practical Test for SMEs

Most owners of 50-to-250 person companies in Czechia, Slovakia, Austria and Hungary have decided the EU AI Act is somebody else's problem. It regulates AI companies, and you are a manufacturer, a logistics firm, a clinic, an accountancy.
That reasoning is wrong in a specific and expensive way. The AI Act regulates use, not just development. If your team uses ChatGPT to draft customer emails, if your website runs a chatbot, if your HR software scores CVs, you may hold obligations under the Act as a deployer. That is the role most SMEs occupy without knowing the word exists.
And the timing is no longer theoretical. On 2 August 2026, most of the Act's transparency obligations became applicable across the EU.
What actually changed this month
Article 50 of the AI Act sets out transparency duties. As of 2 August 2026, most of them are live.
For providers, meaning those who develop an AI system and place it on the market:
- People interacting directly with an AI system must be told they are interacting with AI, unless it is already obvious from context.
- AI-generated or manipulated text, image, audio and video must be marked in a machine-readable format so it can be detected as artificial. For systems already on the EEA market before 2 August, this marking duty has a transition period to 2 December 2026.
For deployers, the category almost every SME falls into:
- If you use emotion-recognition or biometric categorisation systems, you must inform the people exposed to them.
- If you publish deepfakes or AI-generated content on matters of public interest, you must disclose that it is AI-generated.
The important detail: deployer duties have no transition period. They applied from 2 August. Breaching Article 50 carries fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher. There is no exemption for small companies.
Separately, the EU's "Digital Omnibus" package pushed back several high-risk obligations. Standalone high-risk systems now fall due 2 December 2027, and high-risk systems embedded in regulated products 2 August 2028. It also raised the SME simplification threshold to companies up to 750 employees and €150 million turnover, which brings most of the mid-market into the lighter regime.
Delayed is not deleted. And the transparency rules described above were not delayed.
The four-question test
Work through these in order. It takes ten minutes.
1. Does your company use any AI system at all?
Not "have you built one", but used one. ChatGPT or Copilot in daily work. A website chatbot. A CV-screening tool inside your recruitment platform. Predictive maintenance on the production line. AI-assisted translation. An AI feature your ERP vendor switched on last year. If the answer is no across all of these, you are outside scope today. Revisit in six months, because vendors keep adding features.
2. Do customers or the public interact with it directly?
A chatbot, an AI phone assistant, an AI-drafted reply sent under your company name. If yes, you owe those people disclosure that they are dealing with AI.
3. Do you publish AI-generated content?
Marketing images, synthetic voiceover, AI-written articles on matters of public interest. Marking and disclosure duties may apply.
4. Does it make decisions about people?
Screening candidates, scoring employees, assessing creditworthiness, sorting patients. This is the high-risk zone. The deadline moved to December 2027, but the compliance work (documentation, human oversight, logging, risk management) takes far longer than the paperwork implies, and 2027 is not far away.
If you answered no to all four, you are genuinely fine. Most companies answer yes to at least one and did not know it.
What most companies get wrong
Three patterns come up repeatedly in our technical audits across the region.
Shadow AI. Staff use AI tools nobody approved, procured or documented. Marketing has ChatGPT, finance has Copilot, someone in ops built a workflow on an API key charged to their personal card. You cannot comply with rules about systems you do not know you are running. Before anything else, produce an inventory.
Assuming the vendor handles it. Your HR platform's provider carries provider obligations. You still carry deployer obligations. The contract almost certainly does not transfer them. Ask each vendor, in writing, which AI Act role they take and what documentation they will supply. The answers vary enormously, and the weak ones tell you something about the vendor generally.
Waiting for national guidance. The Act is a regulation, not a directive. It applies directly and uniformly. Waiting for the ÚOOÚ or a national authority to publish a Czech-language handbook before starting is a way of spending eighteen months not starting.
What to do in the next thirty days
- Inventory every AI system in use. One spreadsheet: tool, owner, purpose, whether it touches customers, whether it touches personal data. Half a day of work, and it is the foundation for everything else.
- Classify your role per system, provider or deployer. For bought-in tools you are almost always the deployer.
- Add disclosure where people meet AI. A single clear line on the chatbot, the AI phone line, the automated reply. This is a small change that closes a real exposure.
- Write a one-page internal AI policy. What staff may use, what data must never be pasted into a public model, who approves new tools. One page that people read beats twenty that they do not.
- Put the high-risk deadlines in the calendar, December 2027 and August 2028, if question four applied to you.
- Send the vendor question to every supplier whose product has AI features.
None of this needs a law firm. It needs someone to sit down and do it, which is why it does not get done.
Why this matters beyond compliance
The companies that handle this well are not doing it for the regulator. Doing the inventory in step one is the first time most management teams see the full picture of where AI already sits inside their operations. That picture is usually a surprise, and it is the starting point for every serious conversation about where AI is worth investing in, rather than where it merely accumulated.
The obligation is the prompt. The inventory is the value.
FAQ
Does the EU AI Act apply to small companies?
Yes. The Act has no blanket small-business exemption. Obligations follow the role you play, provider or deployer, and the risk category of the system, not company size. The Digital Omnibus package did extend simplified compliance arrangements to companies up to 750 employees and €150 million turnover, which eases the documentation burden for most mid-market firms.
What happened on 2 August 2026?
Most of the Article 50 transparency obligations became applicable: telling people when they are interacting with AI, marking AI-generated content in machine-readable form, and disclosing deepfakes. Providers with systems already on the EEA market have until 2 December 2026 for the machine-readable marking requirement. Deployer duties had no transition period.
We only use ChatGPT internally. Are we in scope?
Purely internal use with no customer-facing output and no decisions about people carries the lightest obligations. But "purely internal" rarely survives an inventory. AI-drafted customer emails and AI-assisted hiring both cross the line, and both are common.
Were the AI Act deadlines delayed?
Some were. High-risk obligations moved to 2 December 2027 for standalone systems and 2 August 2028 for those embedded in regulated products. Prohibitions in force since February 2025 and the August 2026 transparency rules were not delayed.
Not sure which of your systems are in scope?
A RINVID technical audit maps every AI system in your stack, assigns your role under the Act, and gives you a prioritised action list. Thirty-minute introductory call, no obligation.
Get new articles in your inbox
One email whenever we publish. No spam, unsubscribe anytime.