EU AI Act for SMEs: How to Classify Your AI Tools

Martin Bastius
21.04.2026
999
min.

Introduction

Artificial intelligence is no longer a topic for the future — it's part of everyday work. From customer service chatbots to automated invoice processing to AI-powered recruiting tools, many small and medium-sized enterprises already use AI systems today, often without realizing the regulatory implications involved. With the EU AI Act now in force, the legal landscape is changing fundamentally. The regulation introduces a mandatory risk classification that precisely determines which compliance obligations apply to your company.

But what does this mean in practice for mid-sized businesses? Do you now have to document every minor automation? How can you reliably tell whether a tool you use qualifies as high-risk AI? And why does systematically mapping your AI landscape suddenly become an existential safeguard for management? This article explains the logic behind the risk classification in the EU AI Act, shows why this classification forms the strategic core of corporate compliance, and builds awareness of the growing importance of transparent governance.

Why Risk Classification in the First Place?

The EU AI Act takes a consistently risk-based regulatory approach. That means it's not the technology itself that gets regulated, but its specific use case and the associated potential for harm. Many business owners already know this logic from data protection, where especially sensitive data (such as health data) is subject to stricter rules than general contact data.

The underlying idea is pragmatic: a simple spam filter AI carries different risks than a system that decides on credit applications or automatically pre-screens job applicants. The higher the potential risk to fundamental rights, safety, and people's health, the stricter the requirements for the system and its operation. For you as a business owner, this means you absolutely need to understand which category the AI tools you use or offer fall into.

Risk classification is far more than a bureaucratic exercise — it's the regulation's central steering mechanism. It determines whether you must fulfill extensive documentation requirements, whether complex conformity assessments are necessary, or whether a system is banned outright in the EU. Without a correct classification, you simply can't judge what legal risks your company is taking on.

The Four Risk Categories in the EU AI Act

As it currently stands, the EU AI Act distinguishes between four main categories you need to know:

Risk Level Definition Under the Regulation Practical Examples for SMEs Legal Requirements & Obligations
Unacceptable Risk (Banned AI) Systems that massively violate fundamental rights or have a manipulative effect. Social scoring, real-time remote biometric identification, manipulative behavioral influence. Strict ban: Use, placing on the market, and putting into service are prohibited in the EU.
High Risk (High-Risk AI) Systems with significant potential for harm to safety or fundamental rights. AI-powered recruiting (CV ranking), creditworthiness assessment, management of critical infrastructure. Strict compliance: Risk management, high data quality, human oversight, and comprehensive technical documentation.
Transparency Risk (Specific Obligations) Systems that interact with humans or generate content. Customer service chatbots, generative AI (e.g., ChatGPT), deepfakes. Disclosure obligation: Users must be actively informed that they are interacting with AI.
Minimal Risk Applications with no notable potential for harm. Spam filters, spell checkers, simple recommendation algorithms. No specific obligations: The AI Act imposes no new requirements; however, the GDPR remains fully applicable.

High-Risk AI: When Does It Become Relevant for SMEs?

For mid-sized businesses, the category of "high-risk AI" poses the biggest challenge. Lawmakers define these systems in two ways. On the one hand, it covers AI systems built as safety components into products already subject to EU safety regulations (e.g., machinery or medical devices). On the other hand, Annex III of the regulation lists specific use cases.

A typical example for SMEs comes from employment and HR. Do you use software that scans and evaluates CVs and ranks candidates for interviews? Such a tool has a major impact on access to employment and will almost always be classified as high-risk AI. In this case, you must ensure that the system has undergone a risk management process and that human oversight is guaranteed.

As a user (deployer) of such tools, you're responsible for using them as intended and monitoring them during ongoing operation. You must ensure that input data is appropriate for your company's context and that serious incidents or malfunctions are reported immediately.

Provider or User: Your Role Makes the Difference

A common stumbling block is the allocation of roles. The EU AI Act draws a strict distinction between the "provider" and the "deployer" (user).

The provider is the party that develops an AI system, or has one developed, in order to place it on the market under its own name. As a provider, you bear the full burden of conformity assessment, technical documentation, and CE marking.

The deployer (often referred to in the regulation as the "operator" or user) is the company that uses an AI system under its own responsibility. For most SMEs, this is the default role: you subscribe to HR software or use an AI writing assistant. But be careful: if you modify an existing system so significantly that its purpose changes, you can suddenly become a "provider" in the legal sense, with all the obligations that entails.

Why Systematic Tracking Becomes Mandatory

The reality in many companies is a fragmented AI landscape: marketing uses tools for content creation, HR uses software for applicant management, and IT relies on automated security analytics. This often happens without any central overview.

Without structured tracking, you as a business owner simply won't know where high-risk AI is in use or where transparency obligations are being violated. The EU AI Act turns this lack of visibility into a significant liability risk. Systematic tracking serves as proof of compliance for regulators, enables proactive risk assessment, and clarifies internal responsibilities. Much like the record of processing activities under the GDPR, a register of AI systems is becoming an indispensable management tool.

AI Systems Catalog: The New Structure for Your Management

A structured approach to managing this complexity is the "AI Systems Catalog." This central register of all AI systems used within a company follows the same methodology as data protection law. Instead of relying on manual, scattered lists that quickly become outdated in day-to-day business, a central catalog creates clarity.

An effective catalog captures not just the tool's name, but also its specific purpose, risk classification, the groups of people affected, and the person responsible internally. By using specialized compliance platforms like heydata, this AI management can be seamlessly integrated into existing data protection structures. That saves time and prevents synergies between the GDPR and the AI Act from going unused.

AI Competence: The New Obligation for AI Literacy

An often overlooked but central aspect of the AI Act is the requirement for AI literacy. Companies are required to take measures to ensure an adequate level of AI competence among their staff. In practice, this means employees who work with AI must understand how these systems function, what their limitations are, and what risks are associated with their use.

For SMEs, this means that training and awareness programs must become a fixed part of governance. A risk classification is worth little if the people using these tools can't recognize the risks of a "hallucinating" AI or a biased algorithm. This is a major lever for liability avoidance: well-trained staff are the best line of defense against compliance violations.

The Connection to Data Protection: Leveraging Synergies

Since many AI systems process personal data, the GDPR and the AI Act overlap significantly. That's no coincidence — it's by design: both frameworks protect citizens' fundamental rights. For SMEs, that's good news, because if you already have a functioning data protection management system, you don't need to reinvent the wheel.

An AI recruiting tool, for example, falls under both laws: the GDPR governs the protection of applicant data, while the AI Act examines the fairness and transparency of the algorithm. Integrated documentation, as enabled by modern platforms, prevents duplicate work and keeps information consistent. If your data protection officer already uses established processes for risk analysis, these can be ideally extended to meet the requirements of the AI Act.

What Does This Mean in Practice for SMEs?

The requirements depend heavily on your role and the risk profile of your tools. As a pure deployer, you mainly need to fulfill transparency and monitoring obligations. You must request information from your providers and ensure that usage complies with internal policies. If you develop AI solutions yourself (as a provider), however, significant documentation and certification burdens apply to you.

Getting started is often the biggest hurdle. Many SMEs underestimate the time it takes to build a reliable inventory. "Wait and see" is a risky strategy here, since the AI Act is being phased in over time and the first bans are already taking effect soon.

Conclusion: Transparency as the Foundation for Trust

The EU AI Act fundamentally changes the rules for using technology within companies. Risk classification is far more than a legal necessity — it's the foundation for responsible, future-proof action. For SMEs, this means manual lists and ad hoc decisions are no longer enough. Systematic AI management isn't a bureaucratic burden; it's a strategic safeguard against liability risk and reputational damage.

Companies that start now — structuring their AI landscape, clearly defining roles, and adopting modern compliance solutions — build trust with customers and partners. In the end, it won't be the company that adopts AI the fastest that wins, but the one that manages it most safely and transparently.

FAQ

Do SMEs have to write a separate risk analysis for every tool?

For systems with minimal risk, this isn't necessary. For high-risk applications, however, as a deployer you're obligated to assess the risks for your specific context of use. Your provider should supply you with the necessary basic technical information for this.

What happens in the event of a misclassification?

An incorrect classification can lead to breaches of legal obligations, which can result in fines. What matters most, however, is documenting your due diligence: if you can justify why you chose a particular classification, you significantly minimize your risk.

Does the AI Act also apply to free open-source tools?

Yes. A tool's price is irrelevant for regulation. What matters is the purpose for which the AI is used in a business context.

Are manual lists sufficient for documentation?

For an initial overview, that may be enough. However, as soon as you use multiple tools or have high-risk systems in place, manual lists quickly become confusing and error-prone. Specialized software offers a significantly higher level of legal compliance here.

Who is responsible for AI classification within the company?

Ideally, it's a collaboration between IT, the legal department (or external data protection consultants), and the specialist departments using the tool. However, final responsibility for compliance always lies with the management.

Published
21.04.2026
Martin Bastius
Co-Founder & CLO

More articles

View all articles
Data Protection & GDPR
4/3/24

Secure Handling of Ex-Employee Emails Under GDPR

Secure Handling of Ex-Employee Emails Under GDPR
AI & Data Governance
7/11/25

Balancing Trust and Control: How to Make AI-Recorded Online Meetings GDPR-Compliant

Balancing Trust and Control: How to Make AI-Recorded Online Meetings GDPR-Compliant
AI & Data Governance
6/12/26

Whistleblower System for SMBs: What You Need to Know About Whistleblower Protection

Whistleblower System for SMBs: What You Need to Know About Whistleblower Protection
Discover all stories