Dosinescu.ro
AI Act for SMEs: a practical guide for 2026
A practical AI Act guide for SMEs covering roles, risk, transparency, AI literacy and the steps needed to use artificial intelligence responsibly.
AI ACT · OPERATIONAL GUIDE
The AI Act is not a reason to stop automation. It is a reason to know which systems you use, who is responsible for them, which people may be affected and what evidence you can provide about the way you work.
Why the AI Act has become a management issue
In many SMEs, artificial intelligence arrived without a formal project: a ChatGPT account used by marketing, a WordPress module that generates copy, a chatbot installed by an agency, a tool that classifies requests or an API integrated into an application. Each choice may look small. Together, however, they form an operating system that must be inventoried and understood. [EU-REG] [EU-NAV]
The Regulation follows a risk-based approach. It does not treat a tool that suggests title variants in the same way as a system that determines a person’s access to employment, education or an essential service. The first useful question is therefore not “do we use AI?” but “what do we use it for and what effect does it have?” [EU-REG] [EU-RISK]
What already applies in 2026
The obligation to take measures that support AI literacy already applies. Following the amendments that entered into force in July 2026, Article 4 does not impose one universal level or a standard examination for every employee. A company should nevertheless be able to show that people operating AI systems receive information and preparation appropriate to their role, experience and use context. [EU-LIT]
The transparency obligations in Article 50 apply from 2 August 2026. Depending on the role and system, they may require informing users that they are interacting with AI, technically marking synthetic content or clearly disclosing deepfakes and certain public-interest texts. The boundaries and exceptions matter: assisted editing, human editorial control and assumed responsibility must not be confused with unsupervised automated publication. [EU-A50] [EU-A50-G]
The two roles that cause the most confusion
A deployer is, in essence, an organisation that professionally uses an AI system under its authority. An agency using a model for research, a florist using stock forecasting or a department summarising requests will generally be on the usage side. An employee does not become a separate deployer when operating the system under the company’s control. [EU-A50] [EU-REG]
A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A company integrating a general-purpose model into its own product may become the provider of the resulting system without automatically becoming the provider of the underlying general-purpose model. This distinction is essential for SaaS products such as an AI agent integrated into WordPress. [EU-A50] [EU-REG]
A practical six-step process
Useful compliance starts with a register, not with a file hundreds of pages long. For each tool, record the internal owner, vendor, model or service used, purpose, input data, output recipient, whether the output affects people and what human control exists. This inventory allows the company to see quickly where it merely has a productivity tool and where a decision with real impact appears. [EU-DESK] [EU-RISK]
- Inventory every AI tool, including individual accounts and extensions installed without central procurement.
- Determine for every use whether the organisation is a deployer, provider or has another role in the chain.
- Assess purpose and effect, not merely the technology or the product’s commercial name.
- Document data, human control, output approval and the conditions in which the process must stop.
- Train people according to their role and retain evidence of AI-literacy measures.
- Review vendors and systems whenever the model, functionality, data or affected audience changes.
What the AI Act means for SEO and content
The AI Act does not prohibit using AI for research, structure, translation or drafting. For publishers, the important questions are who verifies the facts, who assumes editorial responsibility, whether the material informs the public about a matter of public interest and whether the output can mislead. A workflow in which a person verifies sources, rewrites, approves and signs the material is fundamentally different from automatically publishing thousands of pages. [EU-A50] [EU-A50-G]
From an SEO perspective, the legal obligation and the search engine’s recommendation must be assessed separately. An article may be lawfully published and still be useless, generic or uncompetitive. A good editorial cluster adds experience, analysis, examples and a structure that helps the reader make a decision; it does not disguise volume production as expertise.
Applying the rules to real products and businesses
In an SEO agency such as AYSA.RO, priorities include the tool inventory, rules for client data, editorial approval and a clear division of responsibilities. For a SaaS product such as AYSA.AI, the assessment goes further: the product, interface, underlying model, information provided to users and version changes must be documented as one operating chain. [EU-A50] [EU-LIT]
For AdverLink or CanUHelp APP, recommendations, moderation, support and fraud detection should be assessed according to their concrete effect; the existence of a ranking does not automatically turn it into a high-risk system. In ProFlorist, stock forecasting and procurement are primarily operational processes, but data quality, override capability and recommendation traceability remain sound management practices. [EU-RISK]
What an SME should be able to demonstrate
An SME does not need to imitate a large corporation. It needs clear process owners, an up-to-date register, short rules for data and publication, role-appropriate training, an escalation path and evidence that checks actually took place. Documentation should follow the risk and complexity of the use, not the fear created by a new legal term. [EU-LIT] [EU-DESK]
The correct starting point is simple: list the systems, describe the purpose, verify role and risk, record the data, appoint the person who approves the output and consult legal counsel or the DPO when the use affects people, sensitive data or important decisions. The AI Act becomes manageable when it is transformed from a PDF into a process. [EU-DESK]
Guides in this cluster
Official sources and verification date
- Regulation (EU) 2024/1689 — Artificial Intelligence Act
- European Commission — Navigating the AI Act
- European Commission — AI Act Service Desk and Compliance Checker
- European Commission — AI Literacy Questions & Answers
- European Commission — transparency obligations under Article 50
- European Commission — guidelines on transparency obligations
- European Commission — high-risk AI system classification