Knowledge base

August 24, 2026

The AI Act for Small and Medium-Sized Businesses: What Actually Applies (and What Has Been Postponed)

On August 2, 2026, a new phase of the AI Act went into effect. What didn’t happen that day: no regulator showed up, the fine that made headlines didn’t land on anyone’s doorstep, and the stringent requirements for high-risk AI—which had been the subject of all those alarmist articles—were postponed until December 2027 as part of the Digital Omnibus.

The rules that do apply are straightforward: a chatbot must identify itself as AI, certain AI content must be recognizable, and the AI literacy requirement—which has been in effect since February 2025—is now subject to oversight. However, according to a Chamber of Commerce survey, only a small proportion of business owners feel well-informed about this law; the rest get their information from headlines that play on people’s fears.

This blog post outlines what actually applies to an SME that simply uses ChatGPT, Copilot, or a chatbot: what has been postponed, what currently applies, what has always applied, and the five steps you can take to handle it in practice.

Three categories: postponed, currently in effect, previously in effect

The confusion surrounding the AI Act disappears as soon as you categorize the requirements into three groups. Postponed: The stringent requirements for high-risk AI systems have been postponed by the Digital Omnibus (Regulation (EU) 2026/1744, in effect since July 27, 2026) to December 2, 2027, and for systems covered by Annex I, to August 2, 2028. Effective as of August 2, 2026: the transparency obligations under Article 50, regarding chatbots and AI-generated content. Already in effect since February 2025: the AI literacy requirement under Article 4 and the prohibited practices under Article 5; what is new is that these are now subject to oversight.

That oversight falls to the national market surveillance authorities. In the Netherlands, the implementing law has not yet entered into force, so the enforcement body is still being established. The obligation itself, however, is not subject to this: the regulation is directly applicable.

Is your customer talking to AI? If so, they need to know about it.

If your website has a chatbot, it must be clear to visitors that they are talking to AI, not to a colleague who just happens to never sleep. And that information can’t be buried in the terms and conditions: the law requires clarity at the very moment of the interaction. In practice, this means a notice above the chat window or in the opening message: “You’re chatting with [company]’s AI assistant.” This isn’t a project—it’s a matter of an afternoon.

AI-Generated Content: What It Really Covers

There is a lot of misunderstanding about the recognizability of AI-generated content, so let’s be clear. The labeling requirement under Article 50 focuses primarily on deepfakes and AI-generated texts that inform the public about matters of general interest. Not every marketing text you write using AI automatically falls under this requirement, especially if a human reviewed it and editorial responsibility applies. Furthermore, a transition period extending until December 2, 2026, applies to machine-readable labeling by providers—but only for systems that were on the market before August 2, 2026.

The down-to-earth approach: Be transparent about where AI was used, especially when a reader or viewer would reasonably want to know. It costs nothing, customers appreciate it, and you’ll be well on the safe side when it comes to your obligations.

The training you should have already taken

“AI literacy? Our people hardly ever use AI.” Then ask one question: Who on the team has used ChatGPT, Copilot, or an AI feature in our own software in the past month? The answer is almost always: everyone, actually. That’s exactly what Article 4 is about: anyone who works with AI needs to understand what it can and cannot do, and when to be skeptical of the results.

It is a best-efforts obligation, not a degree requirement. But the effort must be demonstrable: who took which training, when, and how it was documented. Basic training for everyone who works with AI, plus advanced training for heavy users, is sufficient. Document it, and this requirement is met. There it is again—the common thread running through every law this year: demonstrable.

Why Human Oversight Is Not Just a Formality

A lesson from our own experience. After a client meeting, we had AI generate minutes: a neat summary, action items—everything seemed complete—and the feedback was sent to the client. One topic that had been discussed was missing. It was actually in the full transcript, but the summary had omitted it because it was a brief, off-the-cuff discussion. The client noticed it was missing, and we had to follow up with an additional email.

Since then, the rule has been: always compare the minutes with the transcript before turning them into customer communications. That is exactly what the AI Act means by human oversight and literacy. Not because AI is bad; we use it every day, and it saves hours. But anyone who forwards AI output without checking it is responsible for errors they didn’t catch. AI is a tool. The verification remains a human task.

Bans don’t work

“We’ve simply banned AI at work,” said one executive proudly. Our follow-up question: And how do you monitor that? Silence. Here’s what really happens when you ban AI: employees use it on their personal phones. Same work, same company data—but in a free account with no restrictions, completely out of sight. That’s called “shadow AI,” and it poses a greater risk than the use you banned.

The AI Act doesn’t call for a ban, but rather for regulation: know which tools your organization uses, agree on what is and isn’t allowed, and ensure that sensitive customer and company data never ends up in a public tool. A one-page AI policy that permits use under certain conditions will be followed. A ban, on the other hand, will be circumvented.

The A4 with Five Points

Everything mentioned above can be summarized in five points. An AI registry: which AI tools does your organization use, for what purposes, and what data is processed. An AI policy: who is authorized to use what, and what data should never be included. Demonstrable literacy: a record of who received which explanations. Transparency: the chatbot identifies itself, and AI-generated content is clearly labeled where required by law. And the vendor check: do your AI vendors have a data processing agreement, and has it been signed? Five points—no compliance department needed.

You can create the registry and transparency statements today. Our free AI check at airegister.alta-ict.nl reviews your AI usage in about ten minutes and generates your AI registry and transparency statements as documents. Just to be clear up front: the wizard is based on the information you enter, so anything you don’t provide won’t be included, and it does not constitute legal advice. For an SME that simply wants to know where it stands, this is the quickest first step.

Do you recognize the five-point pattern? It’s the same level of accountability that your customers are demanding from you under the Cybersecurity Act. If you establish it for one law, you’re mostly set for the other.

ALTA-ICT’s Position on This Matter

We use AI every day in our own work and know the pitfalls from real-world experience, not from brochures; the lesson on meeting minutes mentioned above is one of them. For clients, we address these five points during an AI check-in: an assessment of the tools, a customized registry and policy, and team training tailored to the size of the company. We base this work on our own certification for ISO 27001:2023, ISO 9001:2015, and NEN 7510:2024, so documenting things the way an auditor wants to see them is part of our daily routine.

Frequently Asked Questions

Does the AI Act apply to my company if we only use ChatGPT or Copilot?

Yes, regarding the requirements that apply to users: the literacy requirement for anyone working with AI, and the transparency requirement if you use AI to handle customer contact or create content that falls under the labeling requirement. The strict high-risk requirements do not affect most SME users.

What exactly has been postponed with the Digital Omnibus?

The requirements for high-risk AI systems: December 2, 2027, for Annex III, and August 2, 2028, for Annex I. The transparency requirement under Article 50 has not been postponed and has been in effect since August 2, 2026.

Do I have to flag every piece of text I write using AI?

No. The labeling requirement focuses primarily on deepfakes and AI-generated texts that inform the public about matters of public interest. A marketing text for which a human bears editorial responsibility is not automatically subject to this requirement. However, being transparent when the reader wants to know remains the sensible approach.

What are the consequences of violating the transparency requirement?

The regulation provides for fines of up to 15 million euros or 3 percent of global annual revenue, with proportionality for small and medium-sized enterprises. In the Netherlands, enforcement is still being developed, but the obligation applies directly; the honest answer is that the risk for a small business right now is primarily to its reputation and customer trust, and that compliance costs very little.

Wouldn’t a ban on AI be the simplest solution to this issue?

No. A ban simply shifts usage to personal phones and free accounts, out of sight and without any guidelines. A concise policy that allows usage under certain conditions is followed; a ban is circumvented.

Conclusion

For the average small and medium-sized business, the AI Act isn’t a major overhaul but rather a process of taking stock: knowing which tools you use, agreeing on what’s allowed, ensuring your team is demonstrably up to speed, being transparent where the law and your customers require it, and keeping your suppliers in order. Any company that can outline all of this on a single A4 page is ahead of most others and ready for the questions that customers and regulators will ask.

Would you like to have all five points in place in just one afternoon? Schedule an AI check-in with ALTA-ICT, and we’ll assess your tools and work with you to establish your registry, policies, and training.

Source: AI Regulation and Regulation (EU) 2026/1744 (Digital Omnibus), EUR-Lex and the European Commission, accessed on July 26, 2026.

Want to know more?

Get in touch
Hero bij de AI Act voor het MKB: een A4 met de vijf punten die nu gelden, van AI-register tot leverancierscheck