EU AI Act for SMBs 2026: what you really need to do before August 2
August 2, 2026, less than three months away. The EU AI Act enters into full force. 99% of SMBs have done nothing. Here is what you actually need to do, without panic and without an expensive consultant.
TerenceOn August 2, 2026, less than three months from now, the EU AI Act enters into full force. Fines can run up to 15 million euros or 3% of your global annual turnover. Yet 99% of Dutch SMBs have done nothing. The law sounds big and scary, but in practice it comes down to a handful of concrete actions. Here is the honest version: what you really need to do, what is overblown, and how to handle it in one afternoon.
Does the AI Act apply to me?
Almost certainly yes. The AI Act applies to any organisation that uses AI in its operations, whether you are an installation company, run a webshop or operate a transport firm. Company size does not matter. Whether you built the AI yourself does not matter either. If you buy and deploy AI, you fall under it.
And "deploying AI" is broader than you think. Do you use ChatGPT to draft emails? Have Copilot in Word or Excel? Does your accounting software have AI features (Exact, AFAS, e-Boekhouden, Visma)? Is there a chatbot on your website? Do you use LinkedIn Recruiter? Grammarly? AI features in your CRM? Then you fall under it.
of Dutch SMBs already use an AI tool, often without realising it.
What needs to be in place by August 2, 2026?
For most SMBs it comes down to five concrete components. None of them are technically complex. But you do need to document them and make them verifiable.
- An AI register, a list of all AI tools your company uses, with: name, vendor, purpose, what data goes in, and who uses it. An Excel file with six columns is enough.
- An AI policy, an internal one-pager with rules: which tools is everyone allowed to use, which not, what you do and do not do with customer data, who reviews. Not legal dictation, just clear rules.
- Demonstrable employee training, everyone working with AI needs basic knowledge (article 4 of the AI Act, "AI literacy"). This has been mandatory since February 2025. An hour-long internal session with a brief test is enough.
- Transparency toward customers, if you deploy AI in communication (like a chatbot), you must disclose it. One line in your footer or the first message is enough: "You are talking to an AI assistant."
- Data processing agreements with AI vendors, if personal data passes through an AI tool, you need a processing agreement. Major vendors (OpenAI, Microsoft, Google) publish these as standard, print and archive them.
The fines, what is real, what is overblown?
The numbers are substantial: up to 35 million euros or 7% of global turnover for deploying prohibited AI practices (like social scoring), up to 15 million or 3% for non-compliance with high-risk obligations, and up to 7.5 million or 1% for providing incorrect information to supervisors.
In practice: for the average SMB using only "ordinary" AI (ChatGPT, Copilot, a chatbot, AI in accounting), these maximum fines are not realistic. But missing basic documentation, AI register, policy, training, can result in an administrative fine if the Dutch Data Protection Authority (AP) audits you. The AP is the designated supervisor and has been running spot checks since 2025.
The AP has made it clear: in 2026 they will not hunt SMBs doing their best. But anyone who has done nothing at all, and then ends up in the news because of a data breach or complaint, will not be given mercy anymore.
Which AI tools belong in my register?
Most entrepreneurs stumble here. They think "AI" means ChatGPT and forget that AI is now in nearly every modern piece of software. Quick scan, does your business use one or more of these?
- Generic AI assistants: ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity
- Office AI: Copilot in Word/Excel/Outlook, Google Workspace AI, Notion AI
- CRM AI: Salesforce Einstein, HubSpot AI, Pipedrive AI, ActiveCampaign AI
- Accounting AI: Exact AI Connect, AFAS InSite AI, Yuki AI, Klippa, Visma AutoInvoice
- Communication AI: website chatbots, AI receptionists, WhatsApp Business bots
- HR AI: LinkedIn Recruiter, Recruitee AI, Bullhorn AI
- Writing AI: Grammarly, DeepL Write, ProWritingAid
- Marketing AI: ChatGPT plugins, AI in Mailchimp, AI in Meta Ads Manager
- Industry-specific: planning AI for installers, routing AI for transport, inventory AI for retail
Nearly every SMB uses at least three tools from this list. Write them all down. That is your AI register.
GDPR and AI Act, how do they relate?
The GDPR still applies as usual. The AI Act is an addition, not a replacement. If your AI tool processes personal data (and most do), you must comply with both.
In practice: for every AI application involving customer data, ask yourself two questions. One: is the data processing GDPR-compliant (legal basis, purpose, retention, security)? Two: does the AI system meet the risk category the AI Act prescribes? For most SMB applications, your tools fall into the "limited risk" category, only transparency obligations apply.
A chatbot answering customer questions = limited risk, transparency required. An AI making automatic decisions about loans or recruitment hires = high risk, much more documentation needed. Know the difference.
The 5-step approach for your SMB
- Step 1, Inventory (1–2 hours): Walk through every software tool with your team. Check for AI features. Create an Excel with columns: tool, vendor, purpose, data, users, risk level.
- Step 2, Policy on one page (1 hour): Write down which AI tools are allowed, which are not, and what the rules are for customer data. Have it approved by one person and share it in your team folder.
- Step 3, Training (1 hour per employee): Hold a brief session on what AI is, what the risks are, and what the rules are. Close with a short test or a signed acknowledgement.
- Step 4, Adjust customer communication (30 minutes): Add an AI disclosure to your chatbot, your email signature where relevant, and your privacy statement.
- Step 5, Check processing agreements (1–2 hours): For every AI vendor that processes personal data: download the standard processing agreement and archive it.
total time for an average SMB to become compliant. No consultant needed.
What do you NOT need to do?
A whole industry has sprung up around AI compliance, and it would love to sell you expensive packages. For most SMBs this is unnecessary. Honest overview of what is overkill:
- An external compliance consultant at €5,000–€15,000, not needed unless you deploy high-risk AI (HR decisions, credit scoring, biometric ID)
- Expensive compliance software with dashboards, an Excel does the same for zero euros
- ISO 42001 certification, interesting for enterprise, overkill for SMB
- Your own Data Protection Officer (DPO), only required if you structurally monitor personal data at scale
- A full risk analysis report per AI tool, only required for high-risk systems
What if you are too busy to handle this yourself?
Realistic: a busy entrepreneur is not going to do this on a Saturday between football and groceries. Two options then: one, hand it to someone in your team with a knack for structure (often your office manager or HR) and block a day for it. Two, bring in a partner who does it with you, not for you. Then it costs you 2–3 hours instead of 6.
At Socialo we build automations that are AI Act and GDPR-proof by default. That is not a marketing claim, it is just how we work. Whether you are automating customer service, handling emails or deploying an AI receptionist: we handle the AI register and transparency obligations for you.
What changes after August 2026?
The AI Act is not a one-off hurdle. From August 2, 2026 onwards, the Dutch Data Protection Authority will actively supervise. In 2027 additional obligations arrive for general-purpose AI models. And the European Commission has announced the law will be evaluated every two years. Those who set up a workable structure now only need to update it later.
Companies that get AI implementations right now, register, policy, training, transparency, gain a lasting advantage. They can deploy AI faster and more broadly than competitors who only act when the fine arrives in the mail.
Three common mistakes
- Mistake 1: Thinking the AI Act does not apply to you because you "only" use ChatGPT. It does. It does not matter how simple or standard the tool is.
- Mistake 2: Waiting until August 1. By then you will hit vendors with no time and staff on holiday. Do it in June.
- Mistake 3: Only training your own team and forgetting your freelancers. The law also applies to contractors working on your behalf with AI. Include them in your policy.
Ready to get started?
Request a free consultation. We look together at where you are losing time.
Schedule free callThe AI Act sounds like regulation for multinationals, but the practical impact lands mostly on SMBs. The good news: for a normal SMB it can be handled in a few hours. The bad news: if you do nothing, in August 2026 you will be empty-handed, while your competitors are ahead. The choice is simple.