The EU AI Act for a 40-Person Company: What Actually Applies to You

Photo: almathias, via Wikimedia Commons · CC0
Every few weeks someone asks me whether the AI Act means they have to stop using ChatGPT, hire a compliance officer, or both. Usually the answer is neither. But "usually" is doing some work in that sentence, so it is worth being precise about where the real obligations sit.
What follows is a practical reading for a typical Dutch SME: a manufacturer, wholesaler or installer with somewhere between twenty and two hundred people, using AI tools that other companies built. It is not legal advice. If you are close to one of the lines described below, talk to someone who does this for a living.
First question: are you a provider or a deployer?
The AI Act puts most of its weight on providers, the companies that develop an AI system and put it on the market. If you buy a tool that reads invoices, or use a chat assistant from one of the large vendors, you are a deployer. Deployers have obligations too, but they are lighter, and they are mostly about how you use a system rather than how it was built.
It gets less clear when you build something on top of a model yourself, or substantially change a system you bought, and then offer it to others. As long as it is for internal use, you are still mostly on the deployer side. The moment you start selling it, read the provider obligations properly.
Second question: is any of your use high-risk?
High-risk is a defined list, not a feeling. For most SMEs, the relevant parts of that list are fairly narrow:
- Recruitment and HR: filtering CVs, ranking candidates, or making or supporting decisions about promotion, termination or task allocation based on someone's behaviour or personal traits.
- Assessing the creditworthiness of private individuals, and pricing life or health insurance.
- AI used as a safety component in products that already fall under EU product safety rules, such as machinery.
Extracting fields from supplier emails is not on that list. Neither is drafting quotes, summarising meeting notes, planning machine capacity or forecasting stock. That covers the large majority of what SMEs are actually doing with AI today.
The HR line is the one to watch. A lot of recruitment software now comes with some form of automated ranking, and it is easy to switch it on without giving it much thought. If you do, you are deploying a high-risk system, with real obligations around human oversight, logging and informing the people it affects.
Where the dates stand
The Act entered into force in August 2024. The bans on prohibited practices and the AI literacy duty have applied since February 2025. Most high-risk and transparency obligations were scheduled for August 2026, but in late 2025 the European Commission proposed moving parts of that timeline back, in a package that also touches other parts of the Act. That discussion was still moving when I wrote this, so check the current dates before you plan around them.
The duty that already applies: AI literacy
Article 4 is short and easy to overlook. As adopted, it asks providers and deployers to take measures so that the people using AI systems on their behalf have a sufficient level of AI literacy, taking their role and the context of use into account.
In practice that does not mean sending everyone on a certification course. It means that the people who use AI tools at work roughly understand what the tool does, where it tends to go wrong, and what they are still responsible for. A planner who uses an AI suggestion should know it can be wrong and know how to check it. A sales colleague pasting customer data into a chat assistant should know which tools are approved for that and which are not.
Write down what you did. A short internal session, a one-page policy and a list of who attended is a sensible start for a small company. It is also a lot more than most companies have today, and it is good practice regardless of how the legal details settle.
Transparency: tell people when they are talking to a machine
If you put a chatbot on your website or in customer service, people should be told they are dealing with an AI system, unless that is already obvious. If you publish AI-generated images or video that look real, label them. These are not heavy obligations. They are mostly good manners with a legal basis.
What a sensible SME does this year
- Make an inventory of the AI tools in use, including the ones people signed up for themselves with a company email address. That list is usually longer than management expects.
- Mark anything that touches recruitment, employee evaluation or credit decisions about individuals. Those deserve a closer look.
- Run a short AI literacy session and keep a record of it.
- Write a one-page AI use policy: which tools are approved, what data may not go into them, and who owns decisions made with AI support.
- For every AI step in a real process, name the person who is accountable for the outcome. Not the tool. A person.
None of this is exotic. Most of it is the same hygiene you would apply to any system that touches customer data or affects people's jobs. The AI Act mainly makes it explicit.
If you want one extra bookmark, the Dutch data protection authority, the Autoriteit Persoonsgegevens, publishes regular reports and guidance on algorithms and AI. It is written for a general audience and is a good way to follow how the rules are being read in practice.