This article provides general informational guidance. See Legal Disclaimer.
- The EU AI Act's Article 4 (mandatory AI literacy) has been in force since February 2, 2025. Any SME using AI tools professionally is already a "deployer" subject to obligations (not just companies building AI).
- The market now offers four distinct categories of AI Act compliance tools with significantly different scopes, pricing, and suitability for EU SMEs.
- Most enterprise governance platforms were not built for the EU regulatory context or for SMEs; selecting the wrong category creates false security and real gaps.
- The key criteria for EU SMEs: data hosted in the EU, multi-regulation coverage (AI Act + GDPR + NIS2 in one workflow), and pricing proportionate to company size.
- This guide explains what each category of tool can and cannot do, and how to match the right approach to your company's actual profile.
If your team uses any AI tool in its work, the EU AI Act already applies to you.
That is not a future deadline or a hypothetical; it is the current legal position under Regulation (EU) 2024/1689. Since February 2, 2025, Article 4 of the AI Act has required every organisation that deploys AI systems in a professional context to ensure its staff have adequate AI literacy: knowledge of what the system does, what it cannot do, how to interpret its outputs, and what risks it poses.
A deployer, under the AI Act's definitions, is any company that uses an AI system in a professional context. If your team uses an AI-powered recruitment tool, a content generation assistant, a customer service chatbot, a predictive analytics module, or a smart ERP system, you are a deployer. According to the France Num 2025 Barometer, 26% of European VSEs and SMEs now use at least one AI tool in their business. The majority are unaware this places them under binding regulatory obligations today.
The question for most SMEs is therefore not whether to comply, but how, and which tools can make compliance achievable without a dedicated legal team.
What the EU AI Act requires from SME deployers right now
Before evaluating any compliance tool, it helps to understand precisely which obligations are already active.
In force now (2025):
- Article 4: AI literacy (in force since February 2, 2025): All deployers must ensure staff using AI systems have sufficient knowledge of the system's capabilities, limitations, and appropriate use. No exemption by company size.
- Article 5: Prohibited AI practices (in force since February 2, 2025): Certain AI applications are banned outright: systems that manipulate users subliminally, exploit vulnerabilities, or enable mass social scoring. Update (June 2026): this list now also includes an outright EU-wide ban on "nudifier" apps and AI-generated child sexual abuse material (systems that create non-consensual intimate or sexually explicit imagery, video, or audio of an identifiable person, or CSAM) added under the Digital Omnibus package approved by the European Parliament (June 16, 2026) and the Council (June 29, 2026). Providers and deployers have until December 2, 2026 to bring existing systems into compliance. These bans apply to every company regardless of size or sector.
- Chapter V: General Purpose AI models (in force since August 2, 2025): Rules for companies that build applications on top of foundation models (GPT, Claude, Gemini, Mistral, etc.), including transparency, copyright, and systemic risk obligations for model providers.
Coming into force (2027–2028):
High-risk AI system full obligations (Articles 9–15, 26): Mandatory risk management systems, technical documentation, data governance, human oversight, and post-market monitoring for companies deploying AI in high-risk categories (recruitment and HR management, creditworthiness assessment, biometric identification, critical infrastructure management, education and vocational training, access to essential services). Update (June 2026): the original August 2, 2026 deadline no longer applies. Under the finalized "Digital Omnibus on AI" package, approved by the European Parliament on June 16, 2026 and given final sign-off by the Council on June 29, 2026, obligations now follow a two-tier timeline: stand-alone high-risk AI systems (Annex III) must comply by December 2, 2027, while high-risk AI systems embedded as safety components in regulated products (Annex I) have until August 2, 2028.
For a typical EU SME not deploying AI in formally classified high-risk categories, the 2025 priority is concrete: inventory AI tools in use, document Article 4 training, assess whether any tool falls into a high-risk category, and build a compliance file (for a structured roadmap, see our step-by-step guide on AI Act compliance in 5 steps). That workflow is precisely what a compliance tool should automate.
Who is subject to the AI Act: geographic scope
| Company profile | AI Act applies? | Notes |
|---|---|---|
| EU-incorporated SME using any AI tool | ✅ Yes | Deployer obligations under Articles 4–5 and Chapter III |
| EEA company (Norway, Iceland, Liechtenstein) | ✅ Yes | AI Act incorporated into EEA legal framework via EEA Joint Committee |
| Non-EU company whose AI outputs are used in the EU | ✅ Yes | Extraterritorial reach: Article 2(1)(c)–(d) |
| EU accession country company (Western Balkans, Ukraine, Moldova) | ⚠️ Partial | Not directly subject unless outputs reach EU market; alignment required under accession chapters; EU investors and buyers increasingly require compliance evidence regardless |
| SME in EU using no AI tools whatsoever | ⚠️ Minimal | Prohibited practices ban still applies; no other active obligations |
| Micro-enterprise (under 10 employees) | ✅ Yes | No general exemption; proportionality applies to some high-risk obligations only |
Key point: The AI Act contains no blanket SME or micro-enterprise exemption. The European AI Office has published guidance on proportionality, but the obligation itself is not waived for small companies.
The four categories of AI Act compliance tools
The market for AI Act compliance tooling is still forming. Products fall into four distinct categories with meaningfully different risk profiles for EU SMEs.
Category 1: Enterprise GRC and AI governance platforms
Platforms built for large enterprises and scale-ups managing complex, multi-jurisdictional compliance programs (SOC 2, ISO 27001, AI risk registers). They offer comprehensive frameworks and automated evidence collection, but carry significant licensing costs and require dedicated technical or compliance staff.
Representative solutions:
- OneTrust (AI Governance): enterprise suite for large accounts with extensive compliance teams. High depth of customization, but complex implementation and annual licensing typically starting between €15,000 and €50,000+.
- Vanta: automated compliance platform originally designed for SOC 2 and ISO 27001, now offering an AI governance module. Excellent for venture-backed tech startups, with pricing typically between €8,000 and €25,000/year.
Best for: Mid-market firms and enterprises (100+ employees) or venture-backed tech companies already managing SOC 2 / ISO certifications with dedicated security engineers.
Not suitable for: Traditional SMEs or small businesses needing fast, practical compliance without implementation overhead or five-figure budgets.
Category 2: GDPR & privacy-first compliance tools
A mature category of tools built primarily for GDPR compliance: processing registers (ROPA), consent management, cookie banners, and data subject access requests (DSAR). Several are progressively adding AI Act modules.
Representative solutions:
- Legiscope: French privacy platform providing GDPR compliance packs and starting to integrate AI Act deployer assessments (~€80 to €200/month).
- Axeptio & Didomi: market leaders in consent and preference management, addressing user transparency and cookie compliance, but limited in scope regarding technical AI Act obligations (risk classification, technical documentation).
Best for: SMEs whose immediate bottleneck is GDPR consent and data mapping.
Limitation: GDPR coverage alone does not cover AI Act deployer obligations (Article 4 literacy, prohibited practice screening, high-risk technical governance).
Category 3: EU-native multi-regulation & dedicated platforms
A new generation of tools built specifically for the 2024–2027 European regulatory landscape. Rather than treating each regulation in a silo, they assess an SME's operations across multiple frameworks (AI Act, GDPR, NIS2) simultaneously, pinpointing critical intersections that single-regulation tools miss.
Representative solutions:
- aiacto: European solution for assessing and inventorying AI systems against AI Act requirements. Well-tailored for startups and product teams.
- Complizo & SetAIComply: AI compliance assessment and obligation mapping tools for technology companies.
- Themio (Themio belongs to this category): digital compliance desk for SMEs, combining automated document analysis, dual AI Act and GDPR coverage, and article-by-article cited verdicts in under 2 minutes, from €49/month at launch (100% EU hosted).
Key structural differentiators: 100% EU data hosting (no data leaves Europe), explainable AI (every recommendation cites the relevant regulatory article number, making it fully defensible before an auditor or regulator), SME-calibrated workflows without legal jargon, and continuous regulatory monitoring.
Best for: European SMEs managing multiple regulatory requirements; founders needing to prove compliance to European enterprise clients or investors; tech companies in accession countries preparing EU alignment.
Limitation: Does not replace formal legal counsel when contested high-risk AI system classification requires a certified legal opinion.
Category 4: External legal counsel and manual compliance
Engaging a specialized law firm or compliance consultancy to conduct a formal AI Act audit. This delivers the most defensible compliance documentation and is the only recommended route for companies facing formal regulatory scrutiny or deploying AI in contested high-risk categories.
Typical players: Law firms specialized in tech and AI regulation (August Debouzy, Bird & Bird, DLA Piper, etc.) and specialized data governance consultancies.
In Europe, specialized legal firms typically charge between €5,000 and €30,000 for an initial AI Act compliance program, with substantial recurring follow-up costs.
Best for: Companies with confirmed high-risk AI deployments, companies facing regulatory inquiries, or those requiring formal legal sign-off for investor due diligence or insurance.
Not efficient for: Routine deployer gap assessments, Article 4 literacy tracking, or basic AI inventorying for standard SMEs.
Five criteria that separate adequate tools from inadequate ones
- EU data hosting. Compliance documentation contains sensitive information about internal systems and risk assessments. It must be stored on EU infrastructure under EU data protection law. Always verify: which cloud provider? Which region? Ask for a DPA.
- Multi-regulation coverage. Any company subject to the AI Act is almost certainly also subject to GDPR (AI systems process personal data) and may be subject to NIS2. A tool covering AI Act alone creates compliance gaps from day one.
- Explainable, cited recommendations. Every compliance recommendation should reference the specific article and regulation it derives from. A compliance output you cannot trace to a source is not a compliance output: it is a checklist you cannot defend.
- Proportionate scope and pricing. An SME compliance workflow should look fundamentally different from an enterprise one. If a tool's default workflow assumes a large legal team, a multi-jurisdictional AI portfolio, and months of implementation, it is not the right tool.
- Regulatory update coverage. The AI Act's implementing regulations, technical standards (from CENELEC and ETSI), and enforcement guidance from the European AI Office are published continuously. Your compliance posture from today may be incomplete within six months without a tool that updates alongside the regulation.
A decision framework by company profile
| SME Situation | Recommended Approach | Example Solutions & Indicative Costs |
|---|---|---|
| EU SME using AI tools, no prior assessment | EU-native multi-regulation platform (Category 3). Gap analysis + Article 4 documentation + AI inventory. | Themio, aiacto · From €49 to €150/month (€500 to €2,000/year) |
| EU SME with GDPR in place, now adding AI Act | Add an AI-Act-native layer to existing setup, or migrate to a multi-regulation platform to consolidate. | Themio, Legiscope · From €49 to €200/month |
| Company deploying AI in recruitment, credit scoring, or high-risk categories | Category 3 platform for initial screening, then specialized legal counsel for formal validation. | Themio / aiacto + Law firm · €5,000 to €20,000 (one-off project) |
| Scale-up or tech company with SOC 2 / ISO audits and group governance | Enterprise GRC suite with integrated AI governance modules. | Vanta, OneTrust · From €8,000 to €30,000+/year |
| Non-EU company whose AI outputs reach EU users | AI Act applies (Art. 2). Prioritize deployer/provider obligations (technical docs, transparency). | Themio (Category 3) + Legal review · From €49/month + external audit |
Frequently Asked Questions
This article provides general information to help you understand AI Act obligations. It does not constitute legal advice and does not replace review by a qualified lawyer, DPO, or compliance specialist familiar with your organization's specific situation. Regulatory requirements and thresholds can change: always verify current obligations against the primary source cited below. Last reviewed: July 6, 2026.
