Skip to content
Novot AI
NLBook a call
← Back to knowledge base

The AI Act for SMEs: what already applies today

Two things affect SMEs directly. Nine practices have been prohibited since February 2025, including emotion recognition in the workplace — except where the use is intended for medical or safety reasons. And since August 2026 you must let people know they are interacting with a machine. The rest of the regulation largely concerns high-risk applications the average SME does not deploy.

Published on · Last updated on

The four risk levels

The AI Act classifies AI systems by risk, not by technology. The same model can fall under minimal risk in one application and high risk in another. Confusing, but logical: what matters is what you do with it.

Risk levels under the AI Act and what they mean for an SME application
Level What it entails Affects an AI customer assistant?
Unacceptable risk Prohibited, nine practices Only if you measure employee or customer emotions outside medical or safety reasons
High risk Heavy requirements on documentation, oversight and accuracy Rarely — think recruitment, credit scoring, education
Transparency risk Disclosure obligation towards the user Yes, this is the category customer contact falls into
Minimal or no risk No rules under the regulation Internal tools with no outside contact

What is prohibited, and already applies

The regulation prohibits nine practices. The first eight took effect in February 2025. For an employer one stands out: emotion recognition in the workplace and in educational institutions. That ban has one exception, written into the law itself: Article 5(1)(f) allows use intended for medical or safety reasons. Outside that, measuring the mood, motivation or stress of employees is not a grey area you can consent your way around — it sits in the same category as social scoring and untargeted scraping of CCTV footage for facial recognition.

That is more relevant than it sounds, because product pitches for "sentiment analysis on your team" or "engagement monitoring" operate in exactly that territory.

What became mandatory in August 2026

The transparency rules took effect this month. The European Commission writes that when using AI systems such as chatbots, people must be made aware that they are interacting with a machine so they can make an informed decision.

In practice: every message your AI sends makes clear it comes from an AI. Not in the small print of a privacy statement, but visibly at the moment itself. In addition, AI-generated content carries a labelling obligation — relevant as soon as your AI publishes text rather than answering it.

What this means for choosing a vendor

Three questions to ask up front, to which a vendor should have a concrete answer:

  1. How does the system make clear it is an AI? Ask for a sample message, not a description.
  2. Can that disclosure be switched off? If the answer is yes, it is not a built-in property but a setting — and settings do get flipped by accident.
  3. Which applications do you explicitly not offer? A vendor who cannot name a limit probably does not have one.

This article is not legal advice. The regulation applies in phases and its interpretation continues to develop; the dates and obligations above are those published by the European Commission as of the retrieval date.

See what Novot AI can do for your business.

Book a call