Skip to main content

PAI-DOC-12

2026-07 · Trust

The EU AI Act: what an SME really has to do, and when.

The EU AI Act (Regulation (EU) 2024/1689) has applied in stages since February 2025, and an SME is almost always a deployer under it: it uses AI systems, it does not make them.

Its real obligations fit in three blocks: demonstrable AI-literacy measures since 2 February 2025, transparency on 2 August 2026 for the minority that exposes an agent or AI-generated content to the public, and prohibited practices that rarely touch day-to-day management.

Three steps answer them: an AI-usage register, a signed policy, documented training.

01

The regulation separates roles, and an SME is almost always a deployer.

The EU AI Act (Regulation (EU) 2024/1689) allocates obligations by role: the provider builds or markets an AI system, the deployer uses it in its business.

An SME that uses generative-AI assistants, the AI features of its software or an engine installed by a provider is a deployer: its obligations are real, but nowhere near those of a model maker.

So the first step is not legal, it is factual: knowing what is already running in your business, on which accounts, with which data. That is the purpose of the AI-usage register.

02

An SME's real obligations fit in three blocks.

First block, since 2 February 2025: AI-literacy measures. Article 4 requires, from every company whose teams use these tools, measures suited to its uses, and the ability to demonstrate them. The text does not speak of mandatory training or a qualification: it asks for measures, demonstrable ones.

Second block, from 2 August 2026: transparency. A company that exposes a conversational agent or AI-generated content to the public must flag it as such. A minority of SMEs is concerned, and an inventory establishes whether you are one of them.

Third block, permanent: the prohibited practices, which target uses a management SME does not engage in (manipulation, social scoring, certain biometrics). Knowing them is usually enough to confirm you are clear of them.

03

The timeline is known, in stages, and it is already under way.

The regulation timelineAbsolute dates
  1. 12 July 2024

    Publication

    Regulation (EU) 2024/1689 is published in the Official Journal of the European Union. It enters into force on 1 August 2024, applying in stages.

  2. 2 February 2025

    Literacy and prohibitions

    The prohibited practices apply, and Article 4 requires demonstrable AI-literacy measures from every company whose teams use these tools.

  3. 2 August 2025

    General-purpose models

    The obligations on providers of general-purpose models apply. They target the model makers, not the SMEs that use them.

  4. 2 August 2026

    General application

    The regulation applies as a whole, including transparency: a company that exposes a conversational agent or AI-generated content to the public must disclose it. A minority of SMEs is concerned.

  5. 2 August 2027

    Final stages

    High-risk systems embedded in products already regulated get this extended deadline. Few service SMEs are concerned.

Fig. 01 · The official timeline of Regulation (EU) 2024/1689, in stages.

The regulation applies in stages, from February 2025 to August 2027. The dates that concern an SME are past or near: literacy already applies, transparency arrives on 2 August 2026.

There is nothing to watch out for: every stage is dated, and the steps to take (register, policy, documented training) are the same whatever your situation.

04

Four frameworks make compliance verifiable, not just declared.

Our method rests on public texts: the EU AI Act, the GDPR for personal data, the NIST AI Risk Management Framework for risk analysis, and the ISO/IEC 42001, 23894 and 42005 standards for AI system governance.

The wording is deliberately precise: our method is aligned with these frameworks, and every deliverable ties back to them so it can be verified by a lawyer or an auditor. We never write 'certified' without a certification obtained: that is our discipline, and it holds for this page too.

05

Getting compliant fits in three steps, already tooled.

The first step is the AI-usage register: who uses what, on which accounts, with which data. The second is the usage policy, signed: it gives a written framework to what is permitted. The third is documented training: the record that demonstrates your literacy measures.

These three steps are exactly the deliverables of our four-week audit, and they are yours to keep, with or without a follow-up. Compliance is not a separate project: it happens through the same documents that bring order to your uses.

Sources: Regulation (EU) 2024/1689, Official Journal of the EU, 12 July 2024; entry into force on 1 August 2024; application in stages from February 2025 to August 2027.

07

Commitments

Four commitments, on every engagement

These commitments are set out in our presentation deck. They hold for every engagement, from the diagnostic to managed operations.

Service commitmentsEvery engagement
Contact
Dedicated, end to end
Progress point
Weekly
Environments
Permanent access
Reply
Within 24 working hours

08

Decide

Two minutes to know where you stand.

Take the test

A straight answer: what applies to you, and whether a project makes sense. If the answer is no, you leave with the answer.

Regulation (EU) 2024/1689 · PAI-DOC-12

PropulAI

Site hosted in France, and therefore within the European Union.
Publisher
Propul'SEO
Hosting
France (EU)
Reference
EU 2024/1689

Regulation (EU) 2024/1689 · AI consulting and implementation for SMEs