Significant sanctions also for SMEs
For serious violations (prohibited practices, false declarations). For SMEs, the fines are proportionate but still high relative to their size.
From August 2, 2026 The EU AI Act applies to any company that uses AI systems in a professional context. We map out the systems in use, prepare the minimum required documentation, and train the team—the technical aspects that lawyers don’t cover.
Not just those who develop AI. To anyone who uses it in the company: even just ChatGPT, Copilot, a CRM with predictive functions, a chatbot on the website.
For serious violations (prohibited practices, false declarations). For SMEs, the fines are proportionate but still high relative to their size.
Anyone using AI systems in a company must have sufficient literacy. The obligation is in effect from February 2025, regardless of the 2026 deadline.
Four operational documents ready for audit: AI systems inventory, risk classification, internal use policy, transparency information for end customers.
If you answer 'yes” to at least one of these questions, you are classified as a deployer under AI Act and have specific obligations. There is no opt-out based on size: this applies even to SMEs with as few as three employees.
Even occasionally. Even with a personal account ("shadow AI"). Yes → you are the deployer.
Lead scoring, suggested responses, candidate screening, call summaries. Yes → you are a deployer.
This includes third-party embedded tools (Intercom AI, Drift, WordPress plugin). Transparency toward users is required.
These are classified as "high-risk": reinforced obligations (DPIA, human oversight, detailed logging).
Map of all AI tools we officially use: enterprise licenses, plugins in your SaaS, embedded models in CRMs, agents we built ourselves.
AI systems the team uses without telling you: personal ChatGPT accounts, browser plug-ins, custom GPTs. Team survey + network/log audit.
For each system: minimal / limited / high risk according to the AI Act criteria. Documentation of the reasons for the choices made.
Audit-ready log + internal use policy (what you can and cannot do with ChatGPT, sensitive data, escalation). Versioned.
2-3 hour session for the team, tailored to roles. What is an LLM, what can/cannot it do, risks, literacy required by Article 4.
From €250/month: registry update when you add tools, training refresh, regulatory monitoring, and policy updates.
Summary of key AI Act deadlines for an Italian or Swiss SME. Bookmark this page.
All employees using AI systems must have sufficient technical knowledge of the context, risks, and implications. If you haven't done so already, you are already exposed.
Providers of GPAI (OpenAI, Anthropic, Google) have transparency obligations. For those using them: it's necessary to demonstrate that they know what they are using.
All obligations for deployers come into effect: AI registry, risk classification, user transparency, human supervision for high-risk systems. The full sanctioning regime also begins here.
Extended obligations for AI embedded in medical devices, automotive, and machinery. Relevant if you develop products with AI inside.
A practical checklist to understand where you are and what to do before August 2, 2026. Designed for small businesses of 1-10 people. No jargon, just action items.
Yes. The AI Act has no size-based thresholds: it applies to anyone who uses AI systems in a professional context. For an SME, the requirements are simplified but still apply. The good news is that 3–6 weeks of work covers everything.
Yes, if you use it for work. It's called "shadow AI" and it's one of the most critical points for SMEs: the company is still responsible for AI systems used for business purposes, even if it doesn't know they exist.
Because the 80% role is technical, not legal: understanding what an 'AI-powered" CRM actually does, classifying a custom agent, taking inventory of browser plugins, and writing policies that the team can understand. The legal team is there to handle interpretive gray areas. We’ll handle the rest and collaborate with your legal team as needed.
Until August 2, 2026, the sanctioning regime is incomplete. After that date, national authorities (in Italy, AgID + Privacy Guarantor) will be able to initiate proceedings. For an SME, fines can range from thousands to hundreds of thousands of euros depending on the violation and the risk of the system.
The AI Act is an EU regulation, so technically no, but if you serve EU customers or process data belonging to EU citizens, then yes—by virtue of extraterritoriality. Furthermore, Switzerland is preparing its own aligned legislation. In practice: if you’re Swiss and do business in the European market, it’s in your best interest to comply.
Initial setup: 3-6 weeks. Then maintenance is required. Every time you add a new AI tool (which happens often), the register needs to be updated. That's why we offer a light retainer (starting at €250/month) which covers updates, refresher training, and regulatory monitoring.
We'll tell you where you stand regarding 2026 obligations, how much work is needed, and if it's worth it for your company. Honestly.