GovCompass

Simplified pathway for micro-enterprises under the EU AI Act

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, including the 2026 Omnibus amendments.

Micro-enterprises (fewer than 10 employees and turnover up to €2 million) can use a simplified compliance pathway under the EU AI Act, mainly for the provider role: simplified technical documentation (Art. 11.3) and a proportionate quality management system (Art. 17.3). The material obligations, the Art. 5 prohibitions, human oversight, and incident reporting, still apply in full.

Updated: June 2026

Introduction: who qualifies as a micro-enterprise?

The EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → adopts the EU's standard definition of micro-enterprise: fewer than 10 employees and an annual turnover or balance sheet total not exceeding €2 million. This definition is applied at the level of the individual legal entity, not at group level, so a subsidiary of a large corporation that itself meets the thresholds may qualify.

Micro-enterprise status matters because the EU AI Act's most significant simplifications are specifically designed for organizations of this size. Understanding which simplifications apply, and which obligations remain, is essential for proportionate compliance.

Simplifications available to micro-enterprises

Technical documentation (provider role)

For micro-enterprises acting as providersproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry → of AI systemsAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → (building or significantly modifying AI), Art. 11.3 permits simplified technical documentationtechnical documentationRecords a provider must compile and keep for a high-risk AI system to demonstrate conformity, covering its design, data, testing, risk management and monitoring.Open full entry →. Instead of the full documentation set required by Annex IV, micro-enterprises may use a streamlined format that covers the essential elements with a lighter documentation burden.

Quality management system

For micro-enterprises the quality management system that Art. 17 requires may be applied in a simplified, proportionate way, under the micro-enterprise derogation in Art. 63, rather than in full. In practice, a single AI governance document covering the relevant elements can substitute for a full ISO 9001-style quality management system.

Conformity assessment

Where self-assessment is permitted (most Annex IIIAnnex IIIThe EU AI Act's list of high-risk use-case areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.Open full entry → high-risk AI systemshigh-risk AI systemAn AI system that falls under the EU AI Act's strictest requirements, following Article 6. There are two routes in: a system that is a product or safety component covered by the Union harmonization legislation in Annex I and subject to third-party conformity assessment, or a system used in one of the areas listed in Annex III, such as employment, education, or access to essential services. Article 6(3) contains a filter: an Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights, although a system that profiles natural persons is always high-risk. See EU AI Act, Annex III, conformity assessment.Open full entry →), micro-enterprises can conduct a simplified self-assessment. The assessment must be substantive, it must genuinely evaluate conformity, but the formal documentation requirements are reduced.

What micro-enterprise deployers must still do

The simplifications above primarily benefit micro-enterprises in the provider role. Micro-enterprise deployersdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry → still face the full Art. 26 obligation set for high-riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → AI systems, with one important qualifier: proportionate implementation.

Proportionate implementation means:

  • Human oversighthuman oversightDesigned-in human ability to monitor, intervene in, override or shut down an AI system. It is meaningful only when the human has authority, information and time to act. One of the seven pillars of responsible AI, and under the EU AI Act a requirement for high-risk AI systems: Article 14 requires that those systems are designed so natural persons can effectively oversee them. Oversight that exists on paper but amounts to confirming in practice does not meet that bar. See override rate, automation bias, high-risk AI system, fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, responsible AI. In the IAPP AIGP body of knowledge, this principle appears as human-centricity, with human oversight as one of its elements.Open full entry → documentation can be a simple log in a spreadsheet rather than a formal system
  • AI literacyAI literacySufficient understanding of AI's workings, capabilities and risks for one's role, an explicit expectation for provider and deployer staff under the EU AI Act.Open full entry → training can be a team discussion rather than a formal training program
  • Risk assessments can be brief written analyses rather than formal matrices
  • GovernancegovernanceThe system through which an organization steers itself: corporate governance, risk management, compliance, lines of accountability, risk appetite, and the operating model. It exists across everything the organization does, before and beyond AI. AI governance is this same system extended for AI. See AI governance, governance design, execution level.Open full entry → can be a single named person rather than a committee

The non-negotiables

Regardless of enterprise size, these obligations apply in full:

  • Art. 5 prohibitions, no exceptions
  • Art. 4 AI literacy, proportionate but not waivable
  • Human oversight for high-risk AI, proportionate implementation is permitted but the obligation exists
  • Incident reporting, simplified process permitted but the obligation to report serious incidentsserious incidentAn AI incident causing (or nearly causing) death, serious harm to health, property, fundamental rights or infrastructure. It triggers regulatory reporting duties for high-risk systems.Open full entry → cannot be waived
  • Individual transparencytransparencyOpenness about the fact that AI is used and how it operates in general: disclosures, documentation, notices. Pairs with explainability, which addresses individual outcomes.Open full entry → (Art. 26(11)), the right of individuals to know they are subject to high-risk AI applies regardless of enterprise size

Practical steps for micro-enterprise compliance

  1. 30-minute AI inventoryAI inventoryA register of all AI systems an organization builds, buys or embeds, with owners and risk tiers. It is the prerequisite for governing any of them.Open full entry →: List every AI tool. Be thorough, include SaaS tools with AI features.
  2. One-page classification analysis: Check each tool against Art. 5 and Art. 6. For most micro-enterprises, this reveals that most tools are minimal risk and one or two may be high-risk.
  3. Supplier email to high-risk AI vendors: Request compliance documentation. File the response.
  4. Team briefing: 30–60 minutes covering what AI is, what the EU AI Act requires, and what to do if there's an incident. Document attendance.
  5. One-page AI policy: Who is responsible, what is the approval process for new AI tools, what is the incident escalation procedure.

FAQ

Q: We are a startup of 6 people. Do we really need to comply with the EU AI Act?
A: If you use AI systems (including SaaS tools with AI features) that affect individuals, and particularly if any are high-risk, yes. But the compliance burden at your scale is manageable: a half-day exercise can achieve proportionate compliance for most micro-enterprises that are deployers (rather than providers) of AI.

Q: We are building an AI product. Does the simplified pathway apply to us?
A: Yes, the provider-role simplifications (technical documentation, QMS) apply if you qualify as a micro-enterprise. However, if your AI system will be used in high-risk contexts by your customers, the conformity assessmentconformity assessmentThe pre-market process demonstrating a high-risk AI system meets the EU AI Act's requirements, leading to CE marking and registration.Open full entry → and declaration of conformitydeclaration of conformityThe provider's signed statement that a high-risk AI system meets the AI Act's requirements, drawn up before the system is placed on the market.Open full entry → obligations still apply, in simplified form.

Continue withAccountability
Share Share on LinkedIn

More on Accountability

Agentic AI and governance: why autonomy sharpens the control question

Analysis

Agentic AI does not need a new kind of governance. Autonomy widens the gap between what a system does and who is accountable for it, which makes the existing governance chain, control tracing to risk and forward to evidence, more important, not less. The actions are real and sometimes irreversible, so the stakes on each control rise.

Agentic AI risk assessment: from architecture decisions to control objectives

Analysis

Assessing the risk of an AI agent does not need a separate method. The steps stay the same: recognize the risk, assess how likely and how severe it is for your system, and control it. What changes is the input. An agent runs the process through recorded architecture decisions, about the model, the instruction, retrieved knowledge, tools, orchestration, memory, and autonomy, and each of those decisions, alone or in combination, creates the possibility of harm. The output of the assessment is a set of risk scenarios with a control objective for each.

AI certification: what exists and what it proves

Analysis

AI certification is not one category. Three different objects are assessed, each by a different kind of assessor: a person, an organization's AI management system, and an AI system placed on the EU market. The first two can be certified. The third is subject to a legal conformity assessment, which produces a certificate on one of its two routes and none on the other. Identifying which object a credential covers is the first step to judging what it is worth.

AI governance and enterprise risk management: where they meet

Analysis

AI governance is not a parallel structure that sits beside enterprise risk management. It belongs inside it. The seven pillars of responsible AI are the control structure the organization uses to govern each AI system; enterprise risk management is the machine that carries the residual risk those controls leave behind into the board's risk appetite, the risk register, and the assurance plan. The practical question is not whether to build AI governance or ERM, but how to slot the first into the second so that one accountable structure, not two competing ones, owns AI risk.