Key Takeaways
- The AI Act is already partially in effect: the prohibited AI practices and the training requirement (AI Literacy) have been in effect since February 2, 2025. The rules on general-purpose AI (ChatGPT, Copilot, Gemini) have been in effect since August 2, 2025.
- The Digital Omnibus has postponed the high-risk obligations (recruitment, credit, health) from August 2, 2026, to December 2, 2027; it was approved by the European Parliament on June 16 and by the Council on June 29, 2026. Publication in the Official Journal of the EU is currently underway.
- There are no size-based exemptions: the AI Act applies to both SMEs and large companies. The difference is that penalties are proportional to revenue.
- 78% of employees use AI at work without telling their managers (Shadow AI). This risk exists now, not in 2027.
- The CNIL is the national authority responsible for overseeing the implementation of the AI Act in France.
- Your primary role is that of an implementer: if your small or medium-sized business uses an AI tool—even one purchased from a software vendor—you are jointly responsible for ensuring it is used in compliance with regulations.
- IT Systèmes supports small and medium-sized businesses with their AI governance: usage policies, AI literacy training, and the secure deployment of Microsoft Copilot.
What SMEs Often Overlook About the AI Act
The AI Act (EU Regulation 2024/1689) is not a 2027 regulation that can be set aside. A significant portion of it is already in effect. And the postponement of high-risk obligations—which has been widely discussed since May 2026—creates a false sense of relief that is leading companies to take no action.
The reality: If your employees use AI tools, this applies to you now. The AI Literacy training requirement (Article 4 of the regulation) has been in effect since February 2, 2025. It applies to anyone who uses, supervises, or deploys an AI system in a professional context, with no threshold based on the number of employees and no sector-specific exceptions.
The Actual Timeline for the AI Act
The postponement of Annex III to December 2, 2027, is the result of the Digital Omnibus, which was formally approved by the European Parliament (June 16, 2026) and the Council of the EU (June 29, 2026). Publication in the Official Journal of the EU—and thus its official entry into force—is expected in July 2026.
Are you a provider or a deployer? The distinction that makes all the difference
The AI Act distinguishes between two main roles. Most French SMEs are implementers, not providers.
Supplier: You develop or market an AI system. This applies to software publishers, AI startups, and digital services companies that create custom AI solutions. The technical compliance requirements (documentation, CE marking, conformity assessment) primarily apply to them.
Deployer: You use an AI system developed by a third party in your professional activities. This is the case for an SME that uses recruitment software with automated resume screening, a marketing content generation tool, or Microsoft Copilot for its teams. The deployer is jointly responsible for human oversight, transparency toward the individuals concerned, and the retention of usage logs.
What this means in practice: If your HR firm uses software that screens applications, your software vendor is the service provider, but you are responsible for ensuring that a human oversees the decisions, that candidates are notified, and that you retain the logs for 6 months.
What applies now, without waiting until 2027
AI Literacy (Article 4), effective as of February 2, 2025
Anyone who uses an AI tool in a professional setting must have received sufficient training to understand the system's capabilities and limitations. This training is the employer's responsibility, not the software vendor's.
In practice, this means documenting who uses what, training teams on the tool’s biases, hallucinations, and limitations, and maintaining records of this training. Cyber insurers are beginning to include this requirement in their questionnaires. IT Systèmes offers AI Literacy training courses that are eligible for funding through OPCO programs.
Prohibited Practices (Article 5), effective as of February 2, 2025
The AI Act categorically prohibits certain uses, regardless of the company's size:
For an SME, the real risk lies in the use of a tool to “monitor the productivity” of remote workers based on the analysis of facial expressions or behavior: some software vendors used to offer this type of solution. Such practices have been prohibited since February 2025.
The GPAI Rules (Articles 51–56), effective as of August 2, 2025
If your company uses ChatGPT, Claude, Copilot, Gemini, or any other general-purpose AI model, certain obligations already apply. The key requirements for deployers are: informing users when they are interacting with AI (chatbots, assistants), labeling AI-generated content in certain contexts (deepfakes, synthetic content), and not using these tools for prohibited purposes. To learn more about the specific risks associated with these tools, see our article ChatGPT, Claude, Grok, Mistral: Cybersecurity and AI for SMEs.
The Shadow AI Risk: A Threat That Won't Wait Until 2027
78% of employees use AI at work without informing their supervisors. This phenomenon, known as “Shadow AI,” creates immediate risks that won’t wait until 2027 to materialize.
Privacy risk: An employee who pastes a client contract or HR data into ChatGPT to summarize it could potentially result in a GDPR violation: the data could be used to train the models if the settings are not configured correctly.
Quality risk: A quote, legal opinion, or financial analysis generated by unsupervised AI may contain factual errors (hallucinations) that no one has detected.
AI Act Compliance Risk: The employer is responsible for ensuring that its employees use AI tools in compliance with regulations. If an employee uses an unlisted tool, the company cannot demonstrate that it has fulfilled its AI literacy training obligation, nor can it prove that the required human supervision has been provided.
The answer isn't to ban AI—it's to regulate it. A well-documented AI usage policy, properly configured and vetted tools, and training for teams enable us to reap the benefits of AI while managing the risks.
IT Systems helps small and medium-sized businesses map their existing AI usage and implement an operational governance policy.
What Lies Ahead in 2027: How to Prepare
High-risk AI systems (Annex III), effective December 2, 2027
Here are the categories most likely to apply to an SME:
What an SME deployer must do for each of these tools by 2027: designate a person in charge, document usage, train teams, ensure that a human can always override or correct the AI’s decision, notify the individuals concerned, and retain activity logs for at least 6 months. Our MSP offering includes the traceability and audit logs required for this compliance.
Penalties: Proportionate, Not Nonexistent
The regulation explicitly provides for protection for SMEs: while large companies pay the higher of a fixed amount or a percentage of revenue, SMEs pay the lower of the two. For an SME with €5 million in revenue, the maximum fine for a non-compliant high-risk system is €150,000 (3% × €5 million), not €15 million.
This does not mean the penalties are insignificant. And the CNIL, designated as the competent national authority for the AI Act, can also issue notices of noncompliance with AI Literacy or the GPAI rules effective immediately. If you are also subject to NIS2, the two regulations apply concurrently with regard to training and digital risk management obligations.
IT Systèmes: AI Governance Partner for SMEs
IT Systèmes provides support on three levels for small and medium-sized businesses that use AI on a daily basis.
Mapping of AI usage: identification of the tools used by teams, including unreported ones (Shadow AI); classification by AI Act risk level; and identification of immediate compliance gaps.
AI Literacy Training: sessions designed to raise awareness among teams and executives about the capabilities and limitations of AI tools, best practices for their use, and risks specific to your industry. These training programs directly address the requirements of Article 4 of the AI Act, which has been in effect since February 2025, and are eligible for funding through OPCO programs.
Microsoft Copilot Governance: Secure deployment of Microsoft 365 Copilot with properly configured data policies (protection of sensitive data, access control, audit logs), so your company can benefit from AI without exposing its customer data or confidential information.
FAQ — AI Act and SMEs
Does the AI Act apply to SMEs or only to large companies? The AI Act does not include any size threshold. It applies to any company—whether an SME, mid-sized company, or large company—that develops, deploys, imports, or distributes an AI system within the European Union. The only difference for SMEs concerns how penalties are calculated: the lower of the fixed cap in euros and the percentage of revenue applies, whereas the higher of the two applies to large companies. This does not exempt them from compliance.
My company uses ChatGPT and Copilot—what should I do now? Two requirements are already in effect. First, AI Literacy (Article 4, effective since February 2025): every employee who uses these tools must have received documented training on their capabilities and limitations. Second, the GPAI rules (effective since August 2025): you must inform users when a chatbot or AI assistant is interacting with them, and you must not use these tools for prohibited practices. In practice, if you do not yet have a documented AI usage policy, this should be your top priority.
Does the postponement to December 2, 2027, mean I don’t have to do anything before then? No. The postponement applies only to the obligations related to high-risk AI systems listed in Annex III (recruitment, credit, healthcare, education). AI Literacy, prohibited practices, and GPAI rules are in effect now. Furthermore, compiling documentation, mapping tools, and training teams takes time: waiting until late 2027 to begin would be like finding ourselves in the same situation we were in before the GDPR took effect in May 2018.
What is Shadow AI, and why is it a risk for my small business? Shadow AI refers to AI tools used by employees without formal authorization from the company: typically the free version of ChatGPT, AI browser extensions, and image or document generators. The risks are threefold: GDPR violations if personal data is pasted into these tools, undetected hallucinations in business documents, and the inability to prove compliance with the AI Act since you don’t know what your teams are using. The solution is a clear AI usage policy, with approved tools that are properly configured.
Is my payroll or recruitment software considered high-risk? Perhaps. Payroll software that calculates coefficients without human intervention is generally not considered high-risk. However, a tool that automatically screens job applications, evaluates employee performance, or recommends decisions regarding promotions or terminations falls under the “high-risk” category in Annex III. The key factor is the actual use of the software and its impact on individuals’ rights, not the name of the software itself. The European Commission published classification guidelines on May 19, 2026.
Can the CNIL already monitor companies for compliance with the AI Act? Yes. The CNIL has been designated as the competent national authority for the AI Act in France. It can monitor compliance with prohibited practices and the GPAI rules, which have been in effect since February and August 2025, respectively. For the high-risk obligations listed in Annex III, the CNIL will be authorized to conduct inspections starting from the effective date of entry into force (December 2027). In the meantime, violations of AI Literacy requirements or GPAI transparency rules may already be subject to notification.
See also
- ChatGPT, Claude, Grok, Mistral: Cybersecurity and AI for Small and Medium-Sized Businesses : The Real Risks of Generative AI in Business
- NIS2: Will My Company Be Affected in 2026? : NIS2 sectors, thresholds, and requirements, to be considered in conjunction with the AI Act for entities falling within both scopes



