There’s no separate, lighter version of the EU AI Act for small companies. If your startup builds or deploys a high-risk AI system, the same risk-management, documentation, and conformity assessment requirements apply as they would to a multinational. What the Act does provide is a set of SME-specific support measures and proportionality provisions — not a smaller rulebook, but a somewhat friendlier path through the same one. Knowing what those measures actually are (and aren’t) matters, because “small companies get a pass” is a common and costly misreading.

What Does NOT Change for SMEs

Get this clear first, because it’s where most confusion causes real risk:

  • The prohibited practices list (Article 5) applies identically regardless of company size — there is no small-company exception to the bans.
  • High-risk classification under Annex III applies identically. A 15-person startup’s HR-screening tool is high-risk under exactly the same criteria as an enterprise vendor’s equivalent product.
  • Core documentation and conformity assessment obligations apply identically — a smaller team still needs Annex IV documentation and a completed conformity assessment before a high-risk system goes to market.
  • GPAI provider obligations apply identically if you provide a general-purpose model, regardless of company size — see our GPAI obligations guide.

What Actually Is Different for SMEs

Article 62 sets out concrete measures specifically for SMEs, including start-ups:

1. Reduced conformity assessment fees. Article 62(2) requires that when notified bodies set fees for conformity assessment, the specific interests and needs of SME providers must be taken into account, with fees reduced proportionately to size, market share, and other relevant indicators. This doesn’t waive the assessment — it’s meant to keep the cost from being disproportionate to a smaller provider’s revenue.

2. Priority access to AI regulatory sandboxes. SMEs and start-ups registered in the EU get priority access to regulatory sandboxes — controlled environments where providers can test AI systems under regulatory supervision before full market placement, with support in interpreting requirements.

3. Dedicated awareness, training, and communication channels. Member States are required to run SME-specific awareness and training activities on the Act, and to maintain dedicated channels for SME questions about implementation — separate from generic enterprise-oriented guidance.

4. AI Office support infrastructure. The AI Office is required to provide standardised templates, maintain a single information platform for all operators, and run communication campaigns — resources aimed at reducing the “we don’t know where to start” barrier that hits smaller teams hardest.

5. A lower fine structure. Under Article 99(6), each fine tier for SMEs (including start-ups) is capped at whichever is lower between the flat amount and the percentage of turnover — the opposite of the “whichever is higher” rule that applies to larger undertakings. Article 99(1) also directs regulators to weigh SME economic viability when setting penalties. This meaningfully changes worst-case exposure, though it does not reduce the underlying obligation to comply.

The Proportionality Trap

“SME-friendly” provisions are frequently misread as “SME-exempt.” They are not. The fine cap in Article 99(6) reduces the ceiling on a penalty if you’re found non-compliant — it does nothing to reduce the underlying requirement to classify your systems correctly, document them, and complete conformity assessment before deployment. A startup that skips documentation on the assumption that “we’re too small for this to apply to us” is still fully in scope for enforcement; the SME provisions only change what the penalty calculation looks like if that enforcement happens.

A Practical Starting Point for Small Teams

The instinct at a resource-constrained startup is to treat AI Act compliance as a future problem — something to address once you’ve raised the next round or hit a customer requirement. Two things argue against waiting:

Enterprise and public-sector buyers are already asking. Procurement processes for larger customers increasingly require AI Act readiness — and increasingly ISO 42001 evidence — as a gating requirement, independent of the statutory deadline.¹ For an early-stage company, “we can’t sell to that customer segment yet” is often a more immediate cost than the regulatory deadline itself.

The actual first step is cheap and undersized compared to its reputation. Compliance work sounds like it requires a legal team and a six-figure budget, but the real starting point is small: build a system inventory, check it against the prohibited practices list, and run a first-pass risk classification. That’s a days-long exercise for a startup with a handful of AI systems, not a months-long program.

Where Aikraft Fits

Aikraft’s Free plan covers one AI system with full risk classification at no cost — built specifically so a small team can get a first, accurate read on their exposure before deciding what to invest further. Get started free, or take the risk quiz for a quick, no-signup read on a single system today.


¹ Küsters & Waber, “AI Act: The clock is ticking,” cepInput No 17, Centrum für Europäische Politik, 2 October 2025, p. 3.