The most common mistake: assuming "small business" means "exempt"

GDPR does have a size threshold that exempts companies under 250 employees from certain record-of-processing obligations (Article 30(5)). The AI Act doesn't work that way. There's no employee count or revenue figure below which an obligation disappears entirely. If your company develops or uses AI systems, the general obligations — staff literacy, risk classification, and everything that follows from that classification — apply exactly as they would to a multinational.

What does exist is a real adjustment, and it comes from two different parts of the Regulation: Article 62, dedicated explicitly to SMEs and startups, and Article 17(2), which requires proportionality on one specific point. Neither exempts you — both reduce the cost and friction of complying.

What the AI Act actually adjusts for SMEs and startups (Article 62)

Article 62 requires Member States and the AI Office to offer four types of support specifically to SMEs and startups:

MeasureWhat it means in practice
Priority access to regulatory sandboxesIf your AI project needs testing before going to market, SMEs get priority entry over larger companies, without relaxing the requirements being evaluated.
Reduced conformity assessment feesWhen a high-risk system needs conformity assessment, the fee is reduced proportionately to the company's size and market.
Tailored training and communication channelsMember States must organize training activities specific to SMEs and maintain dedicated channels to resolve implementation questions — not the same generic channel a large corporation uses.
AI Office standardized templatesThe AI Office must provide standardized compliance templates and a single information platform, cutting down the work of building documentation from scratch.

What does NOT change because you're small

Three obligations apply exactly the same, regardless of company size:

  • AI literacy (Article 4) — in force since February 2, 2025. It requires ensuring your staff (and any third party using AI on your behalf) has a sufficient understanding of the technology, its risks, and its limits.
  • Risk classification (Article 6, Annex III) — every company using or developing AI has to run the exercise of knowing which risk category each system falls into, even if the result is "minimal risk" and the work stops there.
  • Whatever obligations follow from a high-risk classification — if classification comes back high-risk, technical documentation and human oversight are still mandatory. All Article 17(2) adjusts is that the quality management system must be "proportionate to the size of the provider's organisation" — not that it disappears.
In one line: the AI Act doesn't ask how many employees you have before it applies — it asks what kind of system you use. Company size affects how much it costs you to comply, not whether you have to.

A practical path for a small business: 4 steps

Step 1 — AI system inventory

You can't classify what you haven't listed. Include the tools your team uses without anyone officially signing off on them (ChatGPT, Copilot, AI plugins inside your CRM).

Step 2 — Risk classification

For each system on the inventory: does it fall under Annex III? Most productivity tools don't — but a resume-screening or customer-scoring system might.

Step 3 — Staff AI literacy

Training proportionate to each department's actual risk, not one generic course for the whole company. Article 4 doesn't require certifications, but it does require evidence that the training happened.

Step 4 — Minimum documentation, only if it applies

If any system came out high-risk in step 2, that's where technical documentation, human oversight, and — where applicable — EU database registration come in.

AI Act Starter Kit Classification checklist, system registry, and the starter policies most small businesses need first — built to do without a consultant. €29, VAT incl.
Buy →

Frequently asked questions

Does the AI Act exempt small businesses?

No. The AI Act has no size threshold that exempts SMEs, unlike some GDPR obligations. What it does is adjust the effort: Article 62 requires Member States to give SMEs and startups priority access to regulatory sandboxes, reduced conformity assessment fees, and tailored training, and Article 17(2) requires the quality management system to be proportionate to the size of the provider's organization.

Since when do I have to train my staff on AI?

Since February 2, 2025. Article 4 requires ensuring sufficient AI literacy among staff and any third party using AI on the company's behalf, regardless of company size — market surveillance began in August 2026, but the obligation was already in force before that.

What if my SME doesn't use high-risk AI systems?

Most of the heavier obligations — Annex IV technical documentation, EU declaration of conformity, EU database registration — only apply to high-risk systems under Annex III. You still need to run the classification exercise to confirm that, and Article 4's AI literacy requirement still applies regardless.

Can I comply without hiring a consultant?

In most cases, yes — especially if your company doesn't deploy high-risk systems. The map of what you can do yourself and when outside help actually makes sense is covered in our dedicated guide on this topic.