EU AI Act · limited-risk tier

Small Businesses under the EU AI Act: Your Compliance Guide

SMEs using off-the-shelf AI are usually deployers, meaning fewer obligations than providers. But you still must use AI per the provider's instructions, disclose AI use, and log high-risk activity. The EU AI Act also gives SMEs priority access to sandboxes.

Typical risk tier: limited-risk
Your actual tier depends on exactly how your system is built and used. A free scan of your codebase is the fastest way to confirm it.

Do you come under the EU AI Act?

The EU AI Act reaches any company whose AI output is used in the European Union — regardless of where the company is based. If your product has EU users or clients, the rules apply to you. The first question is always the same: which risk tier does your system fall into, and what duties come with that tier?

Which risk tier applies to you?

The Act sorts AI into four tiers: prohibited (banned outright), high-risk (heavy duties), limited-risk (transparency only), and minimal-risk (no mandatory duties). Most software starts in limited or minimal risk. The expensive surprises live in high-risk and prohibited — which is exactly why scanning early matters.

Free EU AI Act Compliance Scan

See your score in 2 minutes. No signup, no code stored.

Scan Your Codebase Now