The most common mistake: assuming "small business" means "exempt"
GDPR does have a size threshold that exempts companies under 250 employees from certain record-of-processing obligations (Article 30(5)). The AI Act doesn't work that way. There's no employee count or revenue figure below which an obligation disappears entirely. If your company develops or uses AI systems, the general obligations — staff literacy, risk classification, and everything that follows from that classification — apply exactly as they would to a multinational.
What does exist is a real adjustment, and it comes from two different parts of the Regulation: Article 62, dedicated explicitly to SMEs and startups, and Article 17(2), which requires proportionality on one specific point. Neither exempts you — both reduce the cost and friction of complying.
What the AI Act actually adjusts for SMEs and startups (Article 62)
Article 62 requires Member States and the AI Office to offer four types of support specifically to SMEs and startups:
| Measure | What it means in practice |
|---|---|
| Priority access to regulatory sandboxes | If your AI project needs testing before going to market, SMEs get priority entry over larger companies, without relaxing the requirements being evaluated. |
| Reduced conformity assessment fees | When a high-risk system needs conformity assessment, the fee is reduced proportionately to the company's size and market. |
| Tailored training and communication channels | Member States must organize training activities specific to SMEs and maintain dedicated channels to resolve implementation questions — not the same generic channel a large corporation uses. |
| AI Office standardized templates | The AI Office must provide standardized compliance templates and a single information platform, cutting down the work of building documentation from scratch. |
What does NOT change because you're small
Three obligations apply exactly the same, regardless of company size:
- AI literacy (Article 4) — in force since February 2, 2025. It requires ensuring your staff (and any third party using AI on your behalf) has a sufficient understanding of the technology, its risks, and its limits.
- Risk classification (Article 6, Annex III) — every company using or developing AI has to run the exercise of knowing which risk category each system falls into, even if the result is "minimal risk" and the work stops there.
- Whatever obligations follow from a high-risk classification — if classification comes back high-risk, technical documentation and human oversight are still mandatory. All Article 17(2) adjusts is that the quality management system must be "proportionate to the size of the provider's organisation" — not that it disappears.
A practical path for a small business: 4 steps
Step 1 — AI system inventory
You can't classify what you haven't listed. Include the tools your team uses without anyone officially signing off on them (ChatGPT, Copilot, AI plugins inside your CRM).
Step 2 — Risk classification
For each system on the inventory: does it fall under Annex III? Most productivity tools don't — but a resume-screening or customer-scoring system might.
Step 3 — Staff AI literacy
Training proportionate to each department's actual risk, not one generic course for the whole company. Article 4 doesn't require certifications, but it does require evidence that the training happened.
Step 4 — Minimum documentation, only if it applies
If any system came out high-risk in step 2, that's where technical documentation, human oversight, and — where applicable — EU database registration come in.
Frequently asked questions
Does the AI Act exempt small businesses?
No. The AI Act has no size threshold that exempts SMEs, unlike some GDPR obligations. What it does is adjust the effort: Article 62 requires Member States to give SMEs and startups priority access to regulatory sandboxes, reduced conformity assessment fees, and tailored training, and Article 17(2) requires the quality management system to be proportionate to the size of the provider's organization.
Since when do I have to train my staff on AI?
Since February 2, 2025. Article 4 requires ensuring sufficient AI literacy among staff and any third party using AI on the company's behalf, regardless of company size — market surveillance began in August 2026, but the obligation was already in force before that.
What if my SME doesn't use high-risk AI systems?
Most of the heavier obligations — Annex IV technical documentation, EU declaration of conformity, EU database registration — only apply to high-risk systems under Annex III. You still need to run the classification exercise to confirm that, and Article 4's AI literacy requirement still applies regardless.
Can I comply without hiring a consultant?
In most cases, yes — especially if your company doesn't deploy high-risk systems. The map of what you can do yourself and when outside help actually makes sense is covered in our dedicated guide on this topic.
