Skip to content
Novot AI
NLBook a call
Back to knowledge base

The AI Act for SMEs: what already applies today

Two things affect SMEs directly. Nine practices have been fully prohibited since February 2025, including emotion recognition in the workplace. And since August 2026 you must let people know they are interacting with a machine. The rest of the regulation largely concerns high-risk applications the average SME does not deploy.

Published on

The four risk levels

The AI Act classifies AI systems by risk, not by technology. The same model can fall under minimal risk in one application and high risk in another. Confusing, but logical: what matters is what you do with it.

Risk levels under the AI Act and what they mean for an SME application
Level What it entails Affects an AI customer assistant?
Unacceptable risk Fully prohibited, nine practices Only if you start measuring employees or customers emotionally
High risk Heavy requirements on documentation, oversight and accuracy Rarely — think recruitment, credit scoring, education
Transparency risk Disclosure obligation towards the user Yes, this is the category customer contact falls into
Minimal or no risk No rules under the regulation Internal tools with no outside contact

What is prohibited, and already applies

The regulation prohibits nine practices outright. The first eight took effect in February 2025. For an employer one stands out: emotion recognition in the workplace and in educational institutions. Measuring the mood, motivation or stress of employees is therefore not a grey area you can consent your way around — it sits in the same category as social scoring and untargeted scraping of CCTV footage for facial recognition.

That is more relevant than it sounds, because product pitches for "sentiment analysis on your team" or "engagement monitoring" operate in exactly that territory.

What became mandatory in August 2026

The transparency rules took effect this month. The European Commission writes that when using AI systems such as chatbots, people must be made aware that they are interacting with a machine so they can make an informed decision.

In practice: every message your AI sends makes clear it comes from an AI. Not in the small print of a privacy statement, but visibly at the moment itself. In addition, AI-generated content carries a labelling obligation — relevant as soon as your AI publishes text rather than answering it.

What this means for choosing a vendor

Three questions to ask up front, to which a vendor should have a concrete answer:

  1. How does the system make clear it is an AI? Ask for a sample message, not a description.
  2. Can that disclosure be switched off? If the answer is yes, it is not a built-in property but a setting — and settings do get flipped by accident.
  3. Which applications do you explicitly not offer? A vendor who cannot name a limit probably does not have one.

This article is not legal advice. The regulation applies in phases and its interpretation continues to develop; the dates and obligations above are those published by the European Commission as of the retrieval date.

See what Novot AI can do for your business.

Book a call