AnyLearn
All lessons
Businessbeginner

The Proportionate Path: Compliance Without a Legal Department

There is no small-business exemption in the AI Act, but there is proportionality, and the 2026 Omnibus widened it. This lesson covers the simplifications for SMEs and the new small mid-cap category, the minimum defensible position for a deployer, how to sequence work against the amended deadlines, where GDPR work can be reused, and when you genuinely need a lawyer.

Updated · AI-authored, review-gated · how lessons are made

Not signed in: your progress and quiz score won't be saved.
Progress1 / 9

No exemption, but real proportionality

The question smaller organisations ask first is whether the Act applies to them. It does. There is no threshold of headcount or turnover below which the Regulation switches off, and a five-person company using a recruitment screening tool holds the same deployer duties as a multinational using the same tool.

What scales is not whether you comply but how much apparatus compliance requires. Three mechanisms do the scaling.

The obligations themselves are mostly outcome-stated rather than process-prescribed, so a small organisation can satisfy them with a document where a large one needs a department.

The Act contains explicit simplifications for smaller providers, which the 2026 Omnibus widened.

And the penalty caps apply differently to SMEs, taking the lower of the fixed amount or the percentage rather than the higher.

So the realistic goal for a small organisation is not a compliance programme. It is a small number of correct decisions, written down, and revisited when something changes.

Full lesson text

All 9 steps on one page, for reading, reference, and search.

Show

1. No exemption, but real proportionality

The question smaller organisations ask first is whether the Act applies to them. It does. There is no threshold of headcount or turnover below which the Regulation switches off, and a five-person company using a recruitment screening tool holds the same deployer duties as a multinational using the same tool.

What scales is not whether you comply but how much apparatus compliance requires. Three mechanisms do the scaling.

The obligations themselves are mostly outcome-stated rather than process-prescribed, so a small organisation can satisfy them with a document where a large one needs a department.

The Act contains explicit simplifications for smaller providers, which the 2026 Omnibus widened.

And the penalty caps apply differently to SMEs, taking the lower of the fixed amount or the percentage rather than the higher.

So the realistic goal for a small organisation is not a compliance programme. It is a small number of correct decisions, written down, and revisited when something changes.

2. What the Omnibus gave smaller organisations

The 2026 amendments were substantially aimed at reducing burden, and three changes matter here.

The simplified quality management system route, previously available only to microenterprises, was extended to all SMEs including start-ups. A quality management system is the documented set of processes a provider of a high-risk system must maintain, and the simplified form is a materially lighter obligation.

A new category, small mid-caps, was introduced for organisations with fewer than 750 employees and under 150 million euros in annual turnover. These benefit from simplified technical documentation for high-risk systems and lighter quality management requirements. This category did not exist before and it captures a large band of mid-sized European businesses that previously faced the full regime.

And the deferral of the high-risk deadlines, to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I, gives smaller organisations time that large ones did not need as badly.

Note what these simplifications are about: they reduce the documentation and process burden on providers. They do not change the substantive requirements a high-risk system must meet, and they do not touch deployer duties at all.

3. The minimum defensible position for a deployer

Most organisations reading this are deployers of systems that are not high-risk. That position is genuinely light, and it is worth stating exactly what it consists of so nobody builds more than it requires.

Know what AI systems you use. This is the foundation of everything else and the part most often skipped.

Confirm none of them involves a prohibited practice. The two that catch ordinary employers are emotion inference applied to staff and biometric categorisation inferring sensitive attributes.

Check whether any sits in an Annex III area. If one does, that is the system that needs real attention and probably advice.

Support the development of AI literacy among staff and others operating systems on your behalf, following the amended Article 4.

Meet the Article 50 transparency duties from 2 August 2026 where they apply: telling people they are dealing with an AI system, and disclosing synthetic or manipulated content.

Write down what you decided and why.

That is the whole list. For an organisation whose AI use is a general assistant and some features inside existing software, this is a few days of work, not a project.

4. The register that carries the work

One artefact does most of the load, and it is a table rather than a policy.

For each AI system, record: what it is and who supplies it; what it does and what decision it influences; who it affects, distinguishing staff, customers and the public; your role for that system, provider or deployer; the tier you assessed it into; the reasoning for that assessment; who owns it internally; and the date of the assessment.

The reasoning column is the one that matters and the one usually left blank. The Act is full of judgement calls, most obviously the Article 6(3) derogation, and a judgement without recorded reasoning is indistinguishable from an omission when someone asks about it two years later.

A spreadsheet is a perfectly adequate format at small scale. What makes it work is a trigger that keeps it current: bind an entry to the moment a new tool is approved, so the register updates as a side effect of procurement rather than as an annual exercise nobody schedules.

This register is also the input to everything else, including the governance framework and the vendor diligence covered in the companion cursus.

5. Reusing the GDPR work

Any organisation that did GDPR properly has already built much of what the AI Act needs, and rebuilding it separately is the most common source of wasted effort.

The record of processing activities overlaps heavily with the AI system register. Adding columns for role and risk tier is usually cheaper than starting a new inventory.

A data protection impact assessment covers much of the ground a fundamental rights impact assessment requires, and where both apply the Act allows the fundamental rights assessment to build on the data protection one rather than duplicate it.

The lawful basis analysis, the data minimisation reasoning, and the retention decisions are all reusable where the AI system processes personal data.

The governance apparatus, meaning the roles, the review cadence and the escalation route, is the same apparatus. It does not need a parallel structure.

What does not carry over: the AI Act's requirements about accuracy, robustness, human oversight and technical documentation have no GDPR equivalent, and the Act reaches systems that process no personal data at all. So reuse the structure, then add the parts that are genuinely new. The 2026 Omnibus also clarified that special category data may be processed where necessary for bias detection and correction, which resolves a real tension between the two regimes.

6. Regulatory sandboxes

The Act requires each Member State to establish at least one AI regulatory sandbox, a controlled environment in which providers can develop, train, test and validate innovative AI systems under regulatory supervision before placing them on the market.

Two features make it relevant to smaller organisations specifically.

SMEs including start-ups are to be given priority access, and access is free of charge for them, without prejudice to the recovery of exceptional costs.

Participation produces documented engagement with the supervisory authority, including a written exit report, which is useful evidence of good faith even where it confers no formal presumption.

The honest caveat is that sandbox capacity is finite and the participating population will be small relative to the number of organisations deploying AI. Treat it as a route worth investigating if you are building something genuinely novel in a high-risk area, and not as a general compliance mechanism.

The more broadly available equivalent is the national competent authority itself. Several Member States have set up guidance functions, and asking a question before deploying is cheaper than defending a decision afterwards.

7. Sequencing against the amended dates

With the timeline as amended, a proportionate order of work for an organisation starting now.

Immediately, and independent of any deadline: complete the AI system register and confirm no prohibited practice is running. Prohibited practices have been unlawful since February 2025, so this is not preparation, it is a check for an existing exposure.

Before 2 August 2026: meet the Article 50 transparency duties. Where you operate a customer-facing assistant, ensure people are told. Where you publish AI-generated content on matters of public interest, arrange either human editorial review or disclosure. This is the nearest real deadline for most organisations.

Before 2 December 2026: confirm marking obligations for generative systems already in use, and confirm nothing in your estate touches the new prohibition on AI-generated intimate imagery.

During 2027, for any Annex III system: the substantive high-risk work, ahead of 2 December 2027.

During 2027 to 2028, for embedded systems in regulated products: the Annex I work ahead of 2 August 2028.

The sequencing principle is that classification comes first and is cheap, while the high-risk work is expensive and now has room. Doing them in the wrong order is how organisations spend money preparing systems that turn out not to be high-risk.

8. What to put in contracts

A deployer's practical leverage sits in the contract, because most of the information you need to comply is held by the provider.

Four things belong in any agreement for an AI system.

A statement of the intended purpose, which is what the provider's conformity assessment was carried out against, and which fixes the boundary beyond which you may become a provider yourself.

An undertaking to supply instructions for use and the information a deployer needs to meet its own obligations, including for high-risk systems the information required to exercise human oversight.

Notification of substantial modification, since a change at the provider's end can alter your position, and notification of any change in the system's regulatory classification.

Allocation of responsibility for the Act's obligations, and cooperation in the event of a serious incident or an authority request.

One question is worth asking of every existing vendor now, because it has a bearing on grandfathering: was this system placed on the EU market before the applicable high-risk date, and what is your position on substantial modification? The answer determines which regime the thing you are using actually sits in. Vendor diligence in depth is the subject of the companion cursus on AI procurement.

9. When you actually need a lawyer

Most of the work above does not require legal advice. Some of it does, and knowing the boundary saves money in both directions.

Handle internally: building the register, identifying which systems are AI systems, confirming you are a deployer of ordinary tools, meeting transparency duties, and running an AI literacy programme.

Get advice when: a system sits in an Annex III area and you intend to rely on the Article 6(3) derogation, because that is a documented legal assessment you may have to defend; you may have become a provider by branding, modification or repurposing; you are building a high-risk system yourself; a system touches employment, credit, education, essential services or biometrics; you operate across several Member States with differing national implementations; or you are close to a prohibited practice, particularly emotion inference in a workplace context.

The general rule: the Act's boundaries are where the judgement lies, and the boundaries are exactly where an inexpensive question prevents an expensive position. An organisation that has done the register can ask a lawyer a narrow, cheap question about two systems, rather than an open-ended and expensive one about its whole estate.

That, ultimately, is what the proportionate path buys.

Check your understanding

The lesson ends with a 5-question quiz. Take it in the player above to see your score.

  1. What is the small mid-cap category introduced by the 2026 Digital Omnibus?
    • Organisations exempt from the AI Act entirely
    • Organisations under 750 employees and 150 million euros turnover, receiving simplified technical documentation and lighter quality management requirements
    • Providers of general-purpose AI models below a compute threshold
    • Deployers who use fewer than ten AI systems
  2. Which column in an AI system register is described as the one that matters most and is usually left blank?
    • The name of the vendor supplying the system
    • The date of the assessment
    • The reasoning behind the tier assessment
    • The internal owner of the system
  3. How does the AI Act treat the relationship between a fundamental rights impact assessment and an existing GDPR data protection impact assessment?
    • The fundamental rights assessment may build on the data protection one rather than duplicate it
    • The two must be carried out entirely separately
    • A DPIA satisfies the AI Act in full
    • A fundamental rights assessment replaces the DPIA
  4. What is the correct sequencing principle for an organisation starting AI Act work now?
    • Build the quality management system first, since it takes longest
    • Wait until 2027, since the high-risk deadlines were deferred
    • Begin with vendor contract renegotiation across the whole estate
    • Classify first because it is cheap, then sequence the expensive high-risk work against the new dates
  5. Which situation most clearly warrants legal advice rather than internal handling?
    • Building an inventory of AI systems in use
    • Relying on the Article 6(3) derogation for a system in an Annex III area
    • Informing users that they are interacting with an AI system
    • Running an AI literacy session for staff

Related lessons

Law & Compliance
advanced

Proof: Disclosure, Presumptions, and the Complexity Rule

Strict liability is worthless if the claimant cannot prove a defect they never saw. Articles 9 and 10 answer that with a disclosure order, three presumptions of defectiveness, a presumption of causation, and a rule turning complexity into the claimant's ally. This lesson works through the cascade, the three-year and ten-year clocks, and what a defendant should be able to produce.

10 steps·~15 min
Law & Compliance
advanced

Who Pays, and For What Damage

The Directive builds a chain of liable operators so an injured person in the EU always has someone to sue. This lesson covers the manufacturer and component manufacturer, the importer and fulfilment service provider route, the distributor's one-month rule, online platforms, how a modification makes you a manufacturer, the heads of damage including data loss, and the exemptions.

10 steps·~15 min
Law & Compliance
advanced

Defectiveness: The Safety a Person Is Entitled to Expect

A product is defective when it lacks the safety a person is entitled to expect. Article 7 turns that into circumstances a court weighs, several written for software: the ability to learn after release, interconnection, cybersecurity requirements, and recalls. This lesson works through the list, the rule that a later improvement is not an admission, and why compliance is not a defence.

10 steps·~15 min
Law & Compliance
advanced

Software as a Product: What the New Liability Directive Changed

Directive (EU) 2024/2853 replaces the 1985 regime and settles a forty-year argument by naming software a product. This lesson covers the new definition and why delivery method is irrelevant, why information is not a product, how components and related services extend the net, where open source sits, and why liability cannot be disclaimed by contract.

10 steps·~15 min