1. Who does the AI Act cover?

The AI Act is an EU regulation and applies directly across the Union. It covers providers, deployers, importers and distributors of AI systems as well as product manufacturers. A company outside the EU may also be in scope if it places a system on the EU market or the system’s output is used in the EU.

A typical SME is most often a deployer: it uses ChatGPT, Copilot, recruitment software or a customer-service bot under its authority. A business can become a provider if it develops a system and sells it under its own name, makes a substantial modification or changes the intended purpose in a way covered by the Act. Provider obligations are considerably broader.

Purpose matters. The same model may be low-risk when drafting copy and part of a high-risk system when used to evaluate job applicants.

2. AI Act timeline

The Regulation entered into force.

Article 4 on AI literacy and most prohibited practices began to apply.

Rules for general-purpose AI (GPAI) models, governance and penalties began to apply.

Most of the Regulation became applicable, including transparency duties. Member State penalty regimes apply.

Certain biometric prohibitions added by Regulation 2026/1744 begin to apply.

Requirements for use-case-based Annex III high-risk systems begin to apply. These include certain uses in employment, education, creditworthiness and essential services.

Requirements for high-risk systems linked to product safety legislation under Annex I begin to apply.

Many pages online still show dates published before July 2026. This guide follows Article 113 of the consolidated Regulation, not the previous timeline or an earlier political agreement.

3. Four practical risk levels

Prohibited practices

Examples include harmful manipulation, exploitation of vulnerabilities, social scoring, certain crime-risk predictions, untargeted scraping of facial images, emotion recognition at work and in education subject to exceptions, and some biometric categorisation and real-time remote identification. Article 5 contains the precise list and exceptions.

High risk

There are two main groups: safety components of regulated products (Annex I) and specified use cases (Annex III), including biometrics, critical infrastructure, education, employment and worker management, access to essential services, law enforcement, migration and justice. Not every AI tool in these fields is automatically high-risk; check Article 6 and its exclusions.

Transparency risk

A chatbot must generally disclose that the person is interacting with AI. Synthetic audio, images, video and text must be machine-readable. Deepfakes and certain AI-generated public-interest text require a clear disclosure. Article 50 sets out the precise timing, wording requirements and exceptions.

Other AI use

Drafting, brainstorming and internal search are often lighter uses under the AI Act. They are not risk-free: data protection, copyright, confidentiality, employment law and consumer rules may still apply.

4. Identify your role first

Deployer

Uses an AI system under its authority in a professional context. Personal non-professional use is excluded. A high-risk deployer must follow instructions, assign competent human oversight, retain logs under its control, inform workers and, in some cases, perform an impact assessment.

Provider

Develops a system, or has one developed, and places it on the market under its own name. A high-risk provider is responsible for risk management, data governance, technical documentation, logs, instructions, conformity assessment, registration and post-market monitoring.

Importers and distributors have their own checking and cooperation duties. A product manufacturer may take on provider duties when high-risk AI is built into a product. Contract labels do not decide the role; what the company actually does does.

5. What SMEs need to do in practice

AI literacy already applies

Providers and deployers must take measures to ensure a sufficient level of AI literacy among staff and other people operating systems on their behalf. The Act does not mandate a particular course or certificate. Training should fit people’s knowledge, the context of use and those affected. Keep a simple record of the content, participants and date.

High-risk use needs more than a vendor promise

If a system is high-risk, check its CE marking, EU declaration of conformity, instructions and registration. Assign trained people to oversee it, ensure input data is relevant and sufficiently representative, and monitor its operation. Act on risks and serious incidents as required.

Public bodies and private entities providing public services must perform a fundamental-rights impact assessment before deploying certain high-risk systems. The same applies to specified creditworthiness and life or health insurance risk-assessment uses.

Using GPAI does not usually make you a model provider

GPAI model providers must maintain technical documentation, give information to downstream system providers, adopt a copyright policy and publish a summary of training content. Models with systemic risk carry extra duties. A normal API or software customer is not usually the GPAI provider, but repackaging or substantial modification can change the role.

6. An AI Act checklist for SMEs

  1. Assign an owner. Someone must maintain the AI inventory and track changes.
  2. Inventory systems. Include team-bought services, browser extensions and embedded AI features.
  3. Record the purpose. What does it do, what data does it use, who relies on the output and who is affected?
  4. Identify the role. Are you a deployer, provider, importer, distributor or product manufacturer?
  5. Classify the risk. Check Article 5 first, then Article 6 and Annexes I/III, followed by Article 50.
  6. Review the vendor. Obtain instructions, security and privacy details, logging, known limitations and required conformity documents.
  7. Set boundaries. Decide which data may be entered and where a human approves the output. Prevent unlawful solely automated decisions.
  8. Train the right people. Examples from your own tools beat a generic lecture.
  9. Make disclosures visible. Review chatbots, deepfakes, generated content and employee notices.
  10. Keep evidence. Version decisions, instructions, training records, assessments, vendor material and incident records.
  11. Review changes. A new purpose or substantial modification may change both the classification and your role.

7. Fines are not one fixed percentage

The maximum for prohibited practices is EUR 35 million or 7% of the preceding financial year’s worldwide annual turnover. Breaches of other listed operator duties can reach EUR 15 million or 3%. Supplying incorrect or misleading information to authorities can reach EUR 7.5 million or 1%.

For SMEs, each maximum is the lower of the fixed sum and percentage, not the higher. A fine is not automatic: authorities consider severity, duration, intent, cooperation and company size, among other factors. The Commission may fine a GPAI model provider up to EUR 15 million or 3% of its worldwide annual turnover in the preceding financial year, whichever is higher.

8. Frequently asked questions

Does the AI Act cover ChatGPT or Copilot at work?

Yes, but obligations depend on use. Drafting a marketing text and automatically screening job candidates are not the same risk.

Must every AI system be registered?

No. The EU database concerns high-risk systems and operators specified by the Act. An internal AI inventory is still good practice.

Can AI make a recruitment decision?

AI used for recruitment may be an Annex III high-risk system. It requires the safeguards in the Act and meaningful human oversight. GDPR Article 22 may also restrict solely automated decisions with legal or similarly significant effects.

Is a vendor’s “AI Act compliant” statement enough?

Not always. Deployers have their own duties, and classification cannot be outsourced through one contract clause.

Is this the same as GDPR?

No. The AI Act regulates AI systems and their risks. GDPR regulates personal-data processing. Both can apply to the same system.

Who enforces the Act in Finland?

Supervision is divided among competent authorities according to the system and use case. Check the current national allocation of powers with an official source before filing a report or making a legal assessment.

9. Sources and limitations

We used official EU legislation and European Commission guidance as primary sources. Article references point to the consolidated Regulation.

Limitations: This page is a general practical summary, not a legal opinion. The final assessment always depends on the specific system, purpose, operator role and other applicable law.