EU AI Act for SMEs 8 min read

EU AI Act for SMEs: the user carries the responsibility

Published on EBM Solution

A business team reviewing artificial intelligence tools against the EU AI Act requirements

The EU AI Act for SMEs places the responsibility on the user. Twelve of the world's most widely used artificial intelligence models were tested against the European rules on consent, profiling, manipulation and handling of sensitive data. The result: none was compliant in every scenario. The best performer — Claude Opus 4.7 by Anthropic — respected European law in 54% of cases. The worst managed 7%. Mistral, the only European model in the test, stayed below 12%.

These are the findings of the Aithos study published in June 2026, run by the Dutch non-profit research foundation that built the LARA system to test models in real agentic scenarios. The researchers checked six provisions of the AI Act — from manipulation of vulnerabilities to social scoring, from emotion recognition to profiling by origin — and six articles of the GDPR. In every scenario tested, the models agreed to monitor employees' emotional state. In every scenario, they agreed to exploit personal vulnerabilities to close a sale.

The question that matters to the small Italian companies using these tools every day is simple: who answers when the models break the law?

Provider and deployer: two roles, different responsibilities

The AI Act splits the market into roles with distinct responsibilities. The provider develops and markets the model: OpenAI, Anthropic, Google, Meta. The deployer uses it in a business context to carry out concrete tasks.

Almost every small and medium Italian company is a deployer. In most cases the use is direct: a ChatGPT subscription to draft documents, a Claude account to analyse contracts, Gemini to classify customer requests. The interaction happens through the provider's generic interface, with no data governance, no traceability of outputs and no control over the model version in use. This is very different from integrating the same models into an architecture designed for the company — with defined rules, usage perimeters and independence from a single vendor — but the Regulation assigns the same obligations to both. The actual level of risk, however, changes radically.

The deployer's obligations are lighter than the provider's — no technical file, no CE marking, no registration in the European databases — but they exist and are already applicable. Article 26 of Regulation (EU) 2024/1689 sets out explicitly the obligations of those who use high-risk AI systems. The risk assessment depends on the specific use case.

What makes the situation harder is the contractual structure of most AI tools. The terms of service of nearly every provider transfer responsibility for the outputs to the user: if the model generates wrong, discriminatory or non-compliant content and the company uses it with customers, employees or candidates, the burden of final control falls on whoever deployed it. This is the ordinary working of the AI market, consistent with the design of the Regulation and stated in every provider's terms of service.

The context of use determines compliance

The Aithos study checked whether the models respect European law when used as agents for typical business tasks: human resources management, sales support, customer classification, communication with end users.

The results show a structural mechanism. The models break the rules because they operate without the contextual constraints that belong to whoever integrates them into processes. When a company entrusts part of its sales cycle or human resources to an AI tool through a generic interface, the model operates according to its own training — without knowing the sector's rules, the company's contractual constraints or the limits the GDPR places on processing that specific data. Those contextual constraints can only be defined by whoever designs the architecture the model sits in.

The Regulation makes this transfer of risk explicit. The provider guarantees that the model exists and works. The company that uses it guarantees that it is deployed in a way that fits the context, the declared purposes and the applicable rules. That guarantee is not a statement of intent: it requires traceability of outputs, governance of inbound data and perimeter rules — tools a consumer subscription does not include and an integrated solution builds in by design.

Two ways to use AI in a company, one responsibility

The distinction the Regulation makes implicit — and practice makes urgent — is between two profoundly different ways of bringing artificial intelligence into a company.

The first is direct use through a consumer interface. The company takes out a subscription to ChatGPT, Claude, Gemini or Copilot. Each employee logs in with their own credentials, interacts with the model through the provider's generic interface, enters data, receives outputs and uses them in work processes. There is no central governance: no control over which data enters the system, no traceability of outputs, no perimeter rules. If the model changes version tomorrow or the provider changes the terms of service, the company absorbs the change.

The second is integration into an architecture designed for that specific business context. The same models — available through APIs — are placed in a pipeline that defines the constraints before the interaction: which data can be transmitted, which outputs are admissible, which regulatory rules must be respected, with what traceability. The interface is proprietary, the rules are set by the company or by whoever supports it, and the provider is interchangeable.

Legally, both modes create identical obligations for the deployer. In practice, the ability to meet those obligations — and above all to prove it — is radically different. A consumer subscription, however upgraded to an enterprise plan, is not an architecture.

Three areas of concrete risk for small businesses

Most small Italian companies use AI for activities that do not formally fall under high-risk systems. The boundary, however, is closer than it looks, and in some cases already crossed.

Recruitment is the most exposed area. Any system that contributes — even partly — to screening CVs, classifying candidates or supporting assessments about people falls under Annex III of the AI Act, which lists high-risk systems. This includes everyday tools used for HR purposes even when they were not designed specifically for it.

Customer scoring is another critical zone, particularly relevant for those working in consumer credit, financial services or any context where AI contributes to decisions about access to products or services. Under the Regulation, it is enough that the system significantly influences the decision.

Informal use with personal data is the third area, and the most widespread. A personal or free ChatGPT, Claude or Gemini account was not designed for sensitive business data. Business and enterprise plans offer different guarantees: a data processing agreement you can sign, data not used to train the model, administrative controls. For professional use with customer or employee data, choosing a business plan is the minimum requirement for a defensible contractual position — but it remains a starting point. A business plan improves the contractual terms on data processing; it does not solve the absence of governance over daily use. Who queries the model, with which data, for what purpose, with what traceability: these questions find an answer only in an architecture designed for the business context.

Italian law no. 132 of 23 September 2025 transposed the European framework, designating AgID and ACN as the competent national authorities. Compliance is now a concrete path.

August 2026: what actually changes

Since 2 February 2025, the bans on unacceptable AI practices and the AI literacy obligations for employees who use these tools have been mandatory. Many small companies are unaware of this, because nobody told them explicitly.

From 2 August 2026, the transparency obligations of article 50 enter into force: when an interaction or a piece of content is generated by an AI system, the user must be able to know it. This covers chatbots on the website, automated assistants in customer communications, and content generated with AI and published as one's own. The transparency obligation requires an owner and a documented trail.

Also from 2 August, the sanctioning powers of national authorities become operational on general-purpose models. The penalties follow the logic already seen with the GDPR: up to 35 million euros or 7% of worldwide turnover for the most serious breaches, with lower thresholds for smaller companies. The Digital Omnibus moved the deadlines for high-risk systems in the most complex sectors to 2027-2028. The obligations already in force remain unchanged.

Compliance is an exercise in clarity

A company's legal position depends on having a clear picture of what it uses, for what purpose, with which data — and on the ability to prove it when asked.

The path starts with mapping: which AI tools are active in the company — including those introduced informally by individual employees — which contractual plan is active for each, which data passes through them and for what purpose. This picture reveals the real exposure profile. The internal policy and the documented record of training — mandatory since 2025 — are the next steps, within a path that leads to governance of the usage architecture.

For small companies, the operational burden of this path is limited. The starting point is mapping. Without knowing which AI systems are used, by whom, for what purpose and with which data, any compliance assessment is built on nothing. The cost of preventive adjustment is, according to European Commission estimates, three to five times lower than the cost of remediation after a sanction.

The user's responsibility translates into capability, and AI literacy training for employees is the first article of the Act that a company has to apply.

Have a project in mind?

Do you know where to start?

The goal is to pin down the problem, the priorities and the timing.

Book a first call

Frequently asked questions

Do the AI Act obligations also apply to small companies that only use ChatGPT or Gemini?

Yes. The AI Act applies to any company that uses AI systems professionally in the European Union, regardless of size or mode of use, whether through a direct subscription to a consumer interface or a solution integrated into business processes. Small companies benefit from proportionate sanction thresholds, but the obligations already in force — bans on unacceptable practices and mandatory training — apply to everyone. The level of exposure varies significantly with the usage architecture adopted.

What is the difference between using an AI tool through a direct subscription and integrating it into a business architecture?

A direct subscription — personal, business or enterprise — governs the contractual relationship with the provider: data processing, exclusion from training, access controls. A platform designed for the company adds a further layer: governance of inbound and outbound data, traceability of the entire interaction with the model, rules that precisely define what can be produced and in what form for the company's needs, and independence from a single provider. These are just examples: design from scratch varies with every company, and the degree of control achievable is far richer than a list can convey. Legally, a business plan is the minimum requirement; operationally, an integrated solution is what makes it possible to meet the deployer's obligations in practice.

What counts as a high-risk AI system for a small company?

High-risk systems are listed in Annex III of the AI Act. The most common areas for small companies are recruitment — any tool that helps screen or classify candidates — and services with scoring components on customers. HR software with automated CV screening falls into this category regardless of how the vendor markets it.

What is actually at stake if a company does not adapt by August 2026?

Sanctions vary with the breach: up to 35 million euros or 7% of worldwide turnover for banned practices, up to 15 million or 3% for other breaches. For small companies the lower of the fixed amount and the percentage applies. Beyond direct sanctions, non-compliance can be used as evidence of fault in civil disputes and, for those applying for public funding, can lead to the loss of the benefit under general clauses on compliance with current law.

How do I know whether my company's use of AI is adequate?

The starting point is mapping the active tools, the contractual plans and the data passing through them. This picture makes it possible to judge whether the current usage architecture is compatible with the deployer obligations set by the Regulation, or whether it needs a structural change. For small companies, a conversation with someone who understands both the regulatory framework and technical architectures is the fastest way to get that assessment without wasting resources on partial compliance efforts.

Sources

Aithos study — LARA: compliance testing of AI models against European law (AI Act and GDPR), June 2026. Italian article on Euronews: https://it.euronews.com/next/2026/06/02/agenti-di-ia-ignorano-attivamente-le-leggi-ue-per-raggiungere-gli-obiettivi-secondo-uno-st

Regulation (EU) 2024/1689 (AI Act) — full text on EUR-Lex, including articles 4, 26, 50, 99 and Annex III: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202401689

Article 26 of Regulation (EU) 2024/1689 — obligations of deployers of high-risk AI systems, official text by article: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26

European Commission — official AI Act page with the application timeline, deadlines and the Digital Omnibus: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

Italian law no. 132 of 23 September 2025 — provisions and delegations to the Government on artificial intelligence: https://innovazione.gov.it/notizie/articoli/approvata-in-via-definitiva-la-legge-italiana-sull-intelligenza-artificiale/

European Commission estimates on the cost of post-enforcement remediation compared with preventive compliance (3-5x ratio): https://matproof.com/it/blog/eu-ai-act-fines-penalties

Computerworld, 29 May 2026 — "Study Finds All Major AI Models Violate EU Regulations": https://www.computerworld.com/article/4178393/study-all-major-ai-models-violate-eu-regulations.html

TechRadar, 8 June 2026 — "AI Agents Are Becoming a Live Operational Security Risk" (Deloitte figure: only 21% of organisations have mature governance for autonomous agents): https://www.techradar.com/pro/a-live-operational-risk-why-ai-agents-are-outrunning-your-security