EU AI Act 2026: The Complete Compliance Guide for SMEs and Tech Companies
The EU AI Act (Regulation (EU) 2024/1689) entered into force in August 2024 and is the world's first comprehensive horizontal regulation on artificial intelligence. Prohibitions on banned AI practices have applied since February 2025. Obligations for high-risk AI systems take full effect in August 2026. Maximum fines reach €35M or 7% of global turnover. For SMEs and tech companies, the most important immediate step is classifying every AI system you develop or deploy into the correct risk category.
EU AI Act (Regulation (EU) 2024/1689): The world's first comprehensive horizontal AI regulation. Applies to all providers and deployers of AI systems placed on or used in the EU market, regardless of where the provider is established. Uses a risk-based tiered approach: unacceptable risk (banned), high risk, limited risk, minimal risk. Enforced by national market surveillance authorities and the European AI Office.
€35M
"Maximum fine for violating the AI Act's prohibited practices provisions — or 7% of total worldwide annual turnover if that figure is higher. For non-compliance with high-risk AI obligations: €15M or 3%."
— Regulation (EU) 2024/1689, Art. 99
What are the four risk categories under the EU AI Act?
The Regulation classifies all AI systems into four tiers based on the risk they pose to fundamental rights and public safety. Classification drives the entire compliance obligation:
| Category | Examples | Obligation |
|---|---|---|
| Unacceptable (Prohibited) | Social scoring by public authorities, real-time biometric surveillance in public, subliminal manipulation | Banned from Feb 2025 |
| High Risk | HR recruitment AI, credit scoring, critical infrastructure, education assessment | CE marking, risk management, EU AI Database registration (Aug 2026) |
| Limited Risk | Chatbots, image generators, deepfakes, emotion recognition | Transparency obligations (inform user it is AI) |
| Minimal Risk | Spam filters, AI in video games, recommendation systems | Voluntary codes of conduct only |
Which AI practices are banned from February 2025?
The following AI system uses became illegal across the EU from 2 February 2025. Any company still operating these systems faces immediate enforcement action:
- Social scoring systems operated by public authorities that evaluate citizens based on their social behaviour
- Real-time remote biometric identification in publicly accessible spaces (narrow law enforcement exceptions apply)
- Subliminal techniques or deliberately deceptive manipulation that distorts behaviour without user awareness
- Exploitation of vulnerabilities of specific groups (based on age, disability, social situation)
- Predictive policing based solely on profiling without objective, verifiable indicators of criminal activity
- Emotion recognition in workplaces and educational institutions
- Scraping facial images from the internet or CCTV to build or expand biometric recognition databases
What is the full EU AI Act compliance timeline?
| Date | Obligation |
|---|---|
| August 2024 | Regulation entered into force |
| February 2025 | Prohibited AI practices apply — immediate enforcement |
| August 2025 | GPAI (General Purpose AI) model obligations apply, including systemic risk rules for frontier models |
| August 2026 | Full high-risk AI system obligations apply (Annex III) — conformity assessment, CE marking, registration |
| August 2027 | High-risk AI systems in Annex I safety legislation fully applicable |
What are the obligations for a company with a high-risk AI system?
If your company develops or deploys an AI system listed in Annex III (HR recruitment, credit decisions, educational assessment, critical infrastructure, law enforcement, border control, administration of justice), you must comply from August 2026 with the following requirements:
- Establish and maintain a documented risk management system (continuously updated throughout the lifecycle)
- Complete a conformity assessment and affix CE marking
- Register the system in the EU AI Database before placing it on the market
- Create complete technical documentation (system specification, training data, performance metrics)
- Implement an active human oversight mechanism during deployment
- Maintain logs of system decisions for traceability and audit purposes
- Establish a post-market monitoring system and report serious incidents to authorities
SME compliance checklist for the EU AI Act
- Inventory all AI systems your company develops or deploys — including tools bought from third parties
- Classify each system using the four-tier risk framework (Annex I and Annex III)
- Check whether any fall into the prohibited category — cease operation immediately if so
- For high-risk systems: begin the conformity process now to meet the August 2026 deadline
- For limited-risk systems (chatbots, generators): implement user transparency disclosure
- Establish an AI governance policy and assign an internal AI compliance lead
- Update contracts with AI tool providers to include AI Act compliance warranties
- Create and maintain an internal AI Register documenting all systems and their classifications
How IgeraRegtech handles it
Company question:
"We use an AI tool for CV screening in HR recruitment. What risk category does it fall into?"
IgeraRegtech answers:
"HR recruitment AI falls under Annex III, point 4 — HIGH RISK category. Obligations from August 2026: conformity assessment and CE marking, risk management system, EU AI Database registration, technical documentation and active human oversight mechanism. We recommend starting the conformity process now. Source: Regulation (EU) 2024/1689, Annex III(4)."
Do you know which risk category your AI systems fall into?
IgeraRegtech automatically classifies your AI systems, generates compliance documentation and monitors regulatory updates. Free 14-day trial.
Try IgeraRegtech free — no card requiredSummary: EU AI Act for SMEs
- Prohibited practices active from February 2025: social scoring, real-time biometric surveillance in public, subliminal manipulation.
- High-risk AI systems (HR, credit, critical infrastructure): full obligations from August 2026 — CE marking, risk management, EU AI Database registration.
- Limited-risk systems (chatbots, generators): transparency obligation to inform users they are interacting with AI.
- Maximum fines: €35M or 7% of global turnover for prohibited practice violations.
- IgeraFincas and IgeraLegal are limited-risk systems: active transparency, no autonomous decisions with legal impact.
Frequently asked questions
Does the EU AI Act apply to non-EU companies selling to European customers?
Yes. The AI Act has extraterritorial effect: it applies to any provider that places AI systems on the EU market or whose systems are used in the EU, regardless of where the provider is established. A US startup selling an HR screening tool to European companies must comply if the system is high-risk.
Is a customer service chatbot considered high-risk?
Generally no. A customer service chatbot falls into the limited-risk category and carries only a transparency obligation: inform users they are interacting with an AI system, not a human. If the chatbot autonomously makes decisions with significant impact on rights — such as denying credit or insurance — the classification escalates to high-risk.
Can the DPO take on the role of AI Officer under the AI Act?
The AI Act does not formally mandate an "AI Officer" for all companies (unlike the DPO under GDPR). However, appointing an internal AI compliance lead is best practice, particularly for companies developing or deploying high-risk systems. The DPO can take on this role if they have appropriate AI regulation training. For companies that are both GDPR and AI Act subject, combining the roles can be efficient — the AI Act and GDPR often overlap in data governance requirements.
What is the EU AI Database and who must register?
The EU AI Database is a public registry of high-risk AI systems managed by the European Commission. Providers of Annex III high-risk systems must register before placing them on the market or putting them into service. The registration covers provider details, system description, use case, and training data information. The database will be publicly searchable, creating transparency for regulators, procurement bodies and the public.
How does the AI Act interact with GDPR?
The AI Act and GDPR overlap significantly when AI systems process personal data. A high-risk AI system processing personal data (e.g. an HR recruitment tool) must comply with both frameworks simultaneously. The AI Act's technical documentation and logging requirements complement GDPR's accountability obligations. The European Data Protection Board has published guidance on the interaction between the two regulations.
Are IgeraFincas and IgeraLegal high-risk AI systems?
No. IgeraFincas and IgeraLegal are limited-risk AI systems: they are chatbots that provide regulatory information and answer resident or user queries. They do not make autonomous decisions with significant legal effects. They comply with the transparency obligation — users are always informed they are interacting with an AI — and every answer cites the exact regulatory source.
Article by the Igera Solutions editorial team. Based on Regulation (EU) 2024/1689 (EU AI Act) and European AI Office guidance, updated June 2026. Not legal advice.