GovCompass

EU AI Act for SMEs: practical guide for small organizations

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, including the 2026 Omnibus amendments.

For SMEs, EU AI Act compliance is manageable but not optional: the Art. 5 prohibitions and Art. 4 literacy apply regardless of size, and SME deployers of high-risk AI carry the full Art. 26 obligations in proportionate form. Micro-enterprises gain administrative simplifications, not exemptions.

Updated: June 2026

Introduction: proportionality is built in

The EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → explicitly acknowledges that a compliance burden designed for large enterprises would be disproportionate for small organizations. Art. 9.5, Art. 17.3, and various other provisions create proportionalityproportionalityMatching the weight of governance to the risk of the use case (heavy gates for high stakes, a light touch for low stakes), which keeps controls credible and followed.Open full entry → requirements: obligations must be implemented in a manner proportionate to the size of the organization and the nature of the AI systemsAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → used.

This does not mean SMEs are exempt from the EU AI Act. It means the obligations must be implemented differently, simpler documentation, fewer formal structures, more proportionate governancegovernanceThe system through which an organization steers itself: corporate governance, risk management, compliance, lines of accountability, risk appetite, and the operating model. It exists across everything the organization does, before and beyond AI. AI governance is this same system extended for AI. See AI governance, governance design, execution level.Open full entry →. This guide explains what proportionate compliance looks like for Dutch SMEs.

Micro-enterprise exceptions

Micro-enterprises (fewer than 10 employees and annual turnover or balance sheet under €2 million) benefit from specific simplifications:

  • Simplified technical documentationtechnical documentationRecords a provider must compile and keep for a high-risk AI system to demonstrate conformity, covering its design, data, testing, risk management and monitoring.Open full entry →: For AI systems they develop (providerproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry → role), micro-enterprises may use simplified documentation formats
  • Reduced conformity assessmentconformity assessmentThe pre-market process demonstrating a high-risk AI system meets the EU AI Act's requirements, leading to CE marking and registration.Open full entry → requirements: Where self-assessment is permitted, simplified procedures apply
  • Lighter governance requirements: Art. 17.3 explicitly allows micro-enterprises to implement the quality management system in a simplified manner

Note: The simplified pathway applies primarily to micro-enterprises in the provider role (building AI systems). Micro-enterprise deployersdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry → (using AI systems) benefit from the general proportionality principleprincipleOne of the seven responsible-AI values a governed system should live up to (fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, human oversight). A principle is abstract: it states an outcome, not a lever you can pull. It becomes governable by naming the harm that would breach it, assessing the risk that harm carries, and placing controls against that risk. Held this way, a principle becomes a pillar. See pillar, harm, risk.Open full entry → but do not have specific deployer-role simplifications beyond proportionate implementation.

SME simplified pathway (Art. 9.5)

For all SMEs (fewer than 250 employees and under €50 million annual turnover), Art. 9.5 provides that the riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → management system required under Art. 9 may be implemented through proportionate, less formal documentation. In practice:

  • A single AI governance document may suffice rather than a full quality management system manual
  • Risk assessments may be integrated into existing operational procedures rather than standalone documents
  • Human oversighthuman oversightDesigned-in human ability to monitor, intervene in, override or shut down an AI system. It is meaningful only when the human has authority, information and time to act. One of the seven pillars of responsible AI, and under the EU AI Act a requirement for high-risk AI systems: Article 14 requires that those systems are designed so natural persons can effectively oversee them. Oversight that exists on paper but amounts to confirming in practice does not meet that bar. See override rate, automation bias, high-risk AI system, fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, responsible AI. In the IAPP AIGP body of knowledge, this principle appears as human-centricity, with human oversight as one of its elements.Open full entry → arrangements may be documented in existing job descriptions and process maps

What SME deployers must still do

Proportionality reduces formality, it does not eliminate obligations. SME deployers of high-risk AI systemshigh-risk AI systemAn AI system that falls under the EU AI Act's strictest requirements, following Article 6. There are two routes in: a system that is a product or safety component covered by the Union harmonization legislation in Annex I and subject to third-party conformity assessment, or a system used in one of the areas listed in Annex III, such as employment, education, or access to essential services. Article 6(3) contains a filter: an Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights, although a system that profiles natural persons is always high-risk. See EU AI Act, Annex III, conformity assessment.Open full entry → must still:

  • Comply with Art. 5 (no exceptions for SMEs)
  • Ensure Art. 4 AI literacyAI literacySufficient understanding of AI's workings, capabilities and risks for one's role, an explicit expectation for provider and deployer staff under the EU AI Act.Open full entry → (proportionate to scale)
  • Verify provider compliance documentation
  • Implement human oversight for high-risk AI
  • Retain AI system logs (6-month minimum)
  • Notify individuals subject to high-risk AI
  • Report serious incidentsserious incidentAn AI incident causing (or nearly causing) death, serious harm to health, property, fundamental rights or infrastructure. It triggers regulatory reporting duties for high-risk systems.Open full entry →

Practical SME compliance starting points

  1. One-page AI inventoryAI inventoryA register of all AI systems an organization builds, buys or embeds, with owners and risk tiers. It is the prerequisite for governing any of them.Open full entry →: List every AI tool in use, even SaaS tools with AI features
  2. Three-question classification check: Is it an AI system? Is any use prohibited? Is any use high-risk?
  3. Supplier email: Write to every high-risk AI vendor requesting their compliance documentation
  4. One-pager AI policy: Simple document covering: who is responsible for AI governanceAI governanceGovernance extended for AI: the same organizational steering at the highest level, widened to cover what makes AI different (it works in probabilities rather than fixed rules, learns from data, and can act at a speed and scale no human reviewer can match). It inherits the existing governance structure and brings AI inside the disciplines the organization already runs, rather than creating a parallel system in a silo. It operates on two levels, design and execution. See governance, governance design, execution level, responsible AI.Open full entry →, what the approval process is for new AI tools, and what the escalation procedure is for AI incidentsAI incidentAny event where an AI system's outputs, actions or data handling caused or plausibly could cause harm, or materially deviated from validated behavior, including harmful outputs from a system that is technically working.Open full entry →
  5. Staff briefing: A 30-minute team briefing on EU AI Act basics satisfies the Art. 4 literacy obligation for most SME employees

Compliance checklist

  1. Is your organization classified as an SME or micro-enterprise under EU definitions?
  2. Have you applied the proportionality principle to your compliance implementation?
  3. Do you have a basic AI inventory (even a simple spreadsheet)?
  4. Have you conducted a high-level classification review for Art. 5 and high-risk?
  5. Have you assigned AI governance responsibility to a named person?
  6. Has your team received basic AI literacy training?
Legal referencesArt. 26Art. 5Art. 4
Share Share on LinkedIn

More on Accountability

Agentic AI and governance: why autonomy sharpens the control question

Analysis

Agentic AI does not need a new kind of governance. Autonomy widens the gap between what a system does and who is accountable for it, which makes the existing governance chain, control tracing to risk and forward to evidence, more important, not less. The actions are real and sometimes irreversible, so the stakes on each control rise.

Agentic AI risk assessment: from architecture decisions to control objectives

Analysis

Assessing the risk of an AI agent does not need a separate method. The steps stay the same: recognize the risk, assess how likely and how severe it is for your system, and control it. What changes is the input. An agent runs the process through recorded architecture decisions, about the model, the instruction, retrieved knowledge, tools, orchestration, memory, and autonomy, and each of those decisions, alone or in combination, creates the possibility of harm. The output of the assessment is a set of risk scenarios with a control objective for each.

AI certification: what exists and what it proves

Analysis

AI certification is not one category. Three different objects are assessed, each by a different kind of assessor: a person, an organization's AI management system, and an AI system placed on the EU market. The first two can be certified. The third is subject to a legal conformity assessment, which produces a certificate on one of its two routes and none on the other. Identifying which object a credential covers is the first step to judging what it is worth.

AI governance and enterprise risk management: where they meet

Analysis

AI governance is not a parallel structure that sits beside enterprise risk management. It belongs inside it. The seven pillars of responsible AI are the control structure the organization uses to govern each AI system; enterprise risk management is the machine that carries the residual risk those controls leave behind into the board's risk appetite, the risk register, and the assurance plan. The practical question is not whether to build AI governance or ERM, but how to slot the first into the second so that one accountable structure, not two competing ones, owns AI risk.