With the Digital Omnibus moving most of the high-risk timeline to 2027 and 2028, some SMEs have concluded there is nothing to do until then. That is the wrong read.
A smaller set of obligations still lands in 2026 — and it lands on the systems SMEs are most likely to have: chatbots, AI-generated content, AI-assisted support. Meanwhile the groundwork for the 2027 obligations is far cheaper to build now, in normal working weeks, than under deadline pressure with a customer security questionnaire on your desk.
Six steps, in the order that actually works.
Step 1 — Confirm what already applies to you
Two blocks of the Act are live today and were not touched by the Omnibus:
- Prohibited practices (since 2 February 2025). Social scoring, emotion recognition at work or school, biometric categorisation by protected characteristics, manipulative techniques. Two more prohibitions — non-consensual intimate imagery and AI-generated CSAM — apply from 2 December 2026.
- AI literacy (since 2 February 2025) and general-purpose AI model rules (since 2 August 2025). If you build on GPT, Claude, Gemini, Llama or Mistral, the model provider carries the model obligations — but you still need to know which model and version you use.
Step 2 — Identify your role for each AI system
Provider, deployer, importer or distributor. Under a delayed timeline this matters more, not less: your role determines whether the December 2027 date is a large project or a short checklist.
- Provider — you develop the system, or put it on the market under your name or brand. Heaviest obligations.
- Deployer — you use someone else's system in your operations. Lighter, mostly oversight, logging and informing affected people.
- Importer / distributor — you bring a third-party system into the EU market or resell it.
One warning worth repeating: if you rebrand or substantially modify a third-party system, you can become the provider of it. See do I need to comply?
Step 3 — Classify risk per system, not per company
There is no such thing as a high-risk company. Classification happens per system and per use context — the same model can be minimal risk in one product surface and high risk in another. Work through risk classification explained and record a one-line justification for each system.
Step 4 — Check if you qualify for SME or small mid-cap relief
The Omnibus wrote proportionality into the Act and added a new small mid-cap (SMC) category: fewer than 750 employees and either turnover under €150 million or a balance sheet under €129 million. SMEs and SMCs get:
- a simplified technical documentation form for high-risk systems
- proportionate quality management system requirements
- lower caps on administrative fines
- priority access to national AI regulatory sandboxes
Check which category you are in now — it changes how much work step 5 is.
Step 5 — Build minimum documentation now
Not full compliance. Just the record that makes everything else possible later. For each AI system, capture:
- what the system does, in one paragraph a non-technical colleague understands
- who owns it internally
- what data goes in, and where it comes from
- whether a human reviews the output, and at what point
- whether the output influences a decision about a person
That last line is the one that determines almost everything else. A spreadsheet is a perfectly acceptable format in 2026.
Step 6 — Set a review checkpoint, not a fixed deadline
The Act is phased across four more dates, guidance from the AI Office keeps arriving, and your own product changes faster than any of it. A single calendar entry for December 2027 will not survive contact with reality.
Put a quarterly 30-minute review in the calendar instead: new AI systems added, any change in how output affects people, any change in role.
A simple 2026 checklist
- AI system inventory exists and has a named owner
- Role (provider / deployer) recorded per system
- Risk level recorded per system, with a one-line justification
- No prohibited practice anywhere in the portfolio
- AI disclosure live in every user-facing AI interaction (due 2 August 2026)
- AI-generated content labelled and marked in machine-readable form
- SME / small mid-cap status confirmed
- Quarterly review scheduled
FAQ
Do I need to do anything before August 2026 if I'm a small startup?
If any user-facing feature involves AI, yes: the Article 50 transparency duties apply from 2 August 2026 regardless of company size. The inventory and classification work is preparation, not obligation — but it is what makes the 2027 date manageable.
What is a "small mid-cap" under the Omnibus?
A company with fewer than 750 employees and either turnover below €150 million or a balance sheet total below €129 million. It sits between the SME definition and large enterprises, and gets most of the same simplifications.
Does the delayed high-risk timeline mean I can ignore documentation?
No. The obligations arrive later; they do not arrive smaller. Documentation is also what enterprise customers ask for in procurement long before regulators do.
How often should I re-check my AI Act exposure?
Quarterly, plus any time you ship a new AI feature or change how an existing one influences decisions about people.
Where to go next
Work through the full AI Act compliance checklist, read what the Omnibus changed, or start with the plain-language EU AI Act for SMEs.
Indicative guidance only — not legal advice. ActNavigator provides guidance based on the EU AI Act (Regulation (EU) 2024/1689) as amended by Regulation (EU) 2026/1744.