EU AI Act — a post-Omnibus compliance checklist

EU AI Act compliance checklist for SMEs: the post-Omnibus calendar.

The deadlines you were told to panic about just moved. Regulation (EU) 2026/1744 — in force since 27 July 2026 — pushed every high-risk obligation to 2 December 2027 for standalone systems and 2 August 2028 for product-embedded ones. What did not move: the three duties already binding your company — Article 4 literacy and Article 5's bans (live since 2 February 2025) and Article 50's transparency rules (live since 2 August 2026), under penalty regimes in force since August 2025. Several of the checklists still ranking for this query were written against the dead calendar. This one is dated correctly.

Articles 4 · 5 · 50 live now · High-risk: 2 Dec 2027 · Checklist: 20 Sep 2026

Live now

Three duties already bind your SME.

None of them cares about your headcount. All three are checkable in a day.

  • Article 4 — AI literacy. Live since 2 February 2025.

    Every provider and deployer of an AI system must take measures to develop the AI literacy of staff and anyone operating AI on the company's behalf — no SME exemption, no risk-class threshold, no headcount floor. The Commission's FAQ puts a company whose staff draft ad copy with ChatGPT squarely in scope. The measures must be targeted to each person's knowledge, experience and context, and tiering by role is allowed — the Commission confirms there is no level to reach, no test to pass, and nothing to certify against. The full duty is in our field guide to EU AI Act AI literacy training.

  • Article 5 — the prohibited practices. Live since 2 February 2025.

    The bans bind users as well as builders. Screen what your team runs against the list: manipulative techniques that cause harm, social scoring, and emotion inference in the workplace — the trap SMEs spring most often through HR tools and people-analytics scripts. Two further bans arrive on 2 December 2026: AI-generated non-consensual intimate imagery (“nudifiers”) and child sexual abuse material.

  • Article 50 — transparency. Live since 2 August 2026.

    Chatbots must tell users they are AI — a duty on the provider of the bot, which may not be you. Synthetic audio, image, video and text must carry machine-readable marking — again the provider's job. Your deployer-side duties are concrete: disclose deepfakes you publish, and disclose AI-generated text published to inform the public on matters of public interest — human-reviewed editorial content is exempt outright, and evidently artistic, creative, satirical or fictional work owes a lighter-touch disclosure, not zero. If marketing ships AI drafts, the disclosure step is theirs.

Everything above is conduct you can evidence with a document — which is why a checklist works for this law and why no consultancy retainer is needed to start.

The checklist

The checklist, dated.

Five moves. Three are due now and have been for months; two have real deadlines ahead.

  • Now — write the AI inventory.

    One sheet: every AI system your staff touch, who owns it internally, and for each one your role. You are a deployer whenever someone uses an AI system under your authority — bought tools, embedded CRM features, the free chatbot someone adopted in 2023. You are a provider when you develop an AI system — or have one developed for you — and put it on the market or into service under your own name. The role decides which duties attach, so settle it per tool, not per company.

  • Now — run the two live screens.

    Against Article 5: does anything on the list touch manipulation, social scoring, or emotion inference at work? Against Article 50: who publishes AI drafts, do any chatbots sit on your properties, and could anything you ship be read as a deepfake? Both screens end in either a clean line or a small policy change — not a project.

  • Now — deliver tiered literacy measures and keep the record.

    Depth for daily users: prompt discipline, hallucination checks, what must never enter a prompt. Awareness for everyone else. Then the paper trail: a per-role training matrix and a one-page AI use policy. The people-plan detail — who must be trained, what to cover, what to document — is our EU AI Act training requirements for employees guide.

  • 2 December 2026 — close the marking grace period, widen the ban list.

    Synthetic-content systems placed on the market before 2 August 2026 must comply with Article 50(2) machine-readable marking from 2 December 2026. The two new Article 5 bans — “nudifier” imagery and CSAM — become applicable the same day. Both are one-line additions to the use policy.

  • 2 December 2027 — the high-risk gate.

    Ask one question of the inventory: does any system land on the Annex III list — recruitment screening, credit scoring, insurance pricing, education, biometrics? If yes, the Chapter III package arrives that day: risk management, data governance, logging, registration, and Article 26 deployer duties including human oversight by trained staff. If no, re-ask the question every time you buy a tool. Product-embedded systems (Annex I) follow on 2 August 2028. A next-budget-cycle project — not a this-week fire.

The correction

What the Digital Omnibus moved — and what it didn't.

One regulation, four dates. Get this part right and the rest of the checklist sorts itself.

  • Moved: the high-risk regime, twice.

    Regulation (EU) 2026/1744 was adopted by Parliament on 16 June 2026, by Council on 29 June 2026, published in the Official Journal on 24 July 2026, and in force from 27 July 2026. It moved standalone Annex III duties to 2 December 2027 and product-embedded Annex I duties to 2 August 2028. It also pushed the AI regulatory sandbox milestone to 2 August 2027, the same date by which GPAI models placed on the market before 2 August 2025 must be compliant.

  • Not moved: everything you're already on the clock for.

    Article 4 and Article 5 kept their 2 February 2025 date. Article 50 kept 2 August 2026. Member-state penalty regimes kept 2 August 2025. Enforcement powers activated with the 2 August 2026 milestone — the machinery is running while the postponed dates sit ahead of you.

  • Why so many checklists are wrong right now.

    Many were drafted against the pre-Omnibus calendar and still carry it. A checklist demanding conformity paperwork this quarter was written against a date that no longer exists — the corrected dates live in the Official Journal, not in last quarter's blog posts. Check any checklist's dates against Regulation (EU) 2026/1744 before you staff a single workstream.

Don't buy theatre

What an SME is not required to do.

The checklist has a minus side. Knowing it is how you avoid paying for compliance theatre.

  • No literacy level, no test, no certificate.

    The Omnibus amended Article 4 so the duty does not require any specific level of AI literacy of any individual, and the Commission confirms there is no obligation to measure or test employees — so there is nothing to certify against. A vendor selling “AI Act certification” for these duties is selling decoration.

  • No conformity assessment for ordinary deployers.

    Conformity assessment, technical documentation, registration — that machinery belongs to the high-risk package, and its clock starts 2 December 2027 for standalone systems and 2 August 2028 for product-embedded ones. If your systems stay off the Annex III list and you deploy no Annex I product, none of it applies to you on any date.

  • No mandated tooling.

    The Act is a conduct law: it asks for measures, screens, and records. A spreadsheet you actually maintain satisfies the inventory step better than a GRC suite nobody opens. Buy software when the paper trail outgrows the spreadsheet — not because a deadline approached.

  • But size buys real relief.

    SMEs and start-ups pay fines at the lower of the amount or the percentage (Article 99(6)), and the Omnibus extended SME-style relief — simplified documentation, sandbox priority, tailored penalty caps — to a new small mid-cap category: fewer than 750 employees and up to €150 million annual turnover (or ≤€129 million balance-sheet total).

What the minus side doesn't remove: the three live duties in section 01. Skipping them isn't an SME privilege — it's just exposure with a smaller denominator.

Exposure

The fines, sized for your turnover.

Article 99 has been in force since 2 August 2025. The caps are public; the arithmetic is simple.

  • The three tiers.

    Up to €35 million or 7% of total worldwide annual turnover, whichever is higher, for banned practices (Article 5). Up to €15 million or 3% for most other obligations — provider duties under Article 16, high-risk deployer duties under Article 26, and transparency under Article 50. Up to €7.5 million or 1% for supplying incorrect, incomplete or misleading information to notified bodies or authorities.

  • Your size caps the number.

    For SMEs and start-ups, each fine is capped at the lower of the amount or the percentage (Article 99(6)) — and authorities must consider the interests of SMEs, including start-ups, and their economic viability. Fines scale with worldwide turnover, so exposure is bounded by your own revenue, not by the headline figures.

  • Live enforcement, unglamorous start.

    Enforcement powers activated with the 2 August 2026 milestone, and member-state penalty regimes have been in force since 2 August 2025. None of the three live duties costs more to satisfy than a missed one costs to explain.

The full penalty map — the three tiers, the timing of fineable exposure, and the SME inversion with a worked example — is our EU AI Act penalties for companies guide.

Straight answers

Asked by operators, answered plainly.

Does the EU AI Act apply to small businesses?

Yes. Article 4's literacy duty has no SME exemption and no headcount floor — the Commission's own FAQ puts a company whose staff draft ad copy with ChatGPT squarely in scope. Company size changes the penalties and the available relief, not whether the Act applies.

What AI Act obligations apply to an SME right now?

Three are live: Article 4 AI literacy and Article 5's prohibited practices, both since 2 February 2025, and Article 50's transparency duties since 2 August 2026. Member-state penalty regimes have been in force since 2 August 2025.

Did the Digital Omnibus postpone the whole AI Act?

No. Regulation (EU) 2026/1744 moved the high-risk regime — standalone Annex III systems now carry it from 2 December 2027 and product-embedded Annex I systems from 2 August 2028. The duties that were already live — literacy, prohibitions, transparency — did not move.

What are the maximum AI Act fines for an SME?

Up to €35 million or 7% of worldwide annual turnover for banned practices, €15 million or 3% for most other obligations, and €7.5 million or 1% for supplying incorrect, incomplete or misleading information to notified bodies or authorities. An SME pays the lower of the amount or the percentage (Article 99(6)).

Is there an official EU AI Act certificate for SMEs?

No. There is nothing to certify against: post-Omnibus Article 4 requires no specific level of AI literacy of any individual, and the Commission confirms there is no testing obligation. Treat any vendor selling “AI Act certification” for these duties as a red flag.

Where should a small company start this week?

With the three live duties: write the AI inventory, screen it against Article 5's bans, and deliver tiered literacy measures with a record. Days of work, not quarters. Our field guide to EU AI Act AI literacy training and the training requirements for employees breakdown cover the people-side duties in depth.

Next

Run the checklist. Keep the file.

Fast path: the $30 self-serve courses — order tonight, start tonight, 30-day money-back. With your team: UpShift AI runs readiness snapshots, fluency audits, and hands-on bootcamps for EU companies of 10–500 — AI consulting and training for European teams, from checklist to production. Want the people-side duties in depth? The Article 4 AI literacy field guide and the training requirements for employees cover them end to end.

Reply within 24 hours · EU time zones · Remote across the EU, on-site by arrangement