International Insights · 2026

EU AI Act compliance for smaller technology companies

Scope assessment and implementation documents for technology businesses navigating the EU digital regulatory framework in force in 2026.

Consultations and professional correspondence are available in Romanian or English. Other language versions of this website are provided for information.

01

Key legal and practical points

  • AI role and risk classification with obligation mapping
  • Internal AI-use policies and supplier clauses
  • Platform notice-and-action and transparency workflows
  • Initial MiCA, Data Act and digital-compliance perimeter review

03

01

Identify the system, use case and legal role

AI Act compliance begins with an inventory, not with a generic policy. A smaller technology company should list every system it develops, sells, integrates or uses, including third-party models embedded through an API. For each use case it should record the intended purpose, affected persons, input and output data, degree of autonomy, deployment countries and human decision process. The same company can be a provider for one system and a deployer for another. It may also become an importer, distributor, product manufacturer or downstream provider depending on how it places or modifies the system.

Contract labels do not determine the regulatory role. Rebranding a system, making a substantial modification or changing the intended purpose can shift responsibilities. A business that merely uses a general-purpose model to assist staff is in a different position from one that builds a customer-facing decision tool on top of it. The inventory should connect each AI use to GDPR, consumer, employment, intellectual-property, cybersecurity and sector rules. The AI Act does not replace those laws, and a low-risk classification under the Act does not mean that personal-data or discrimination risks are low.

02

Apply the 2026 timeline correctly

The AI Act entered into force on 1 August 2024 and applies in stages. Prohibited-practice rules and the original AI-literacy obligation began applying on 2 February 2025. Governance and obligations for general-purpose AI models began applying on 2 August 2025. From 2 August 2026, important transparency obligations apply and enforcement powers are active for the provisions then applicable. Users must be informed in required cases when they interact with AI, and providers or deployers may have marking and disclosure duties for generated or manipulated content, deepfakes, emotion recognition or biometric categorisation.

The 2026 AI Omnibus changed parts of the implementation calendar. According to the European Commission's current framework, the rules for high-risk systems listed in Annex III apply from 2 December 2027, while high-risk systems embedded in regulated products apply from 2 August 2028. Other dates and transitional provisions remain relevant, including the limited grace period described for certain marking obligations. Companies should therefore avoid both extremes: claiming that the Act is entirely postponed or claiming that every high-risk obligation already applies. The correct compliance plan links each obligation to the company's role, system category and applicable date.

03

Screen prohibited, transparency and high-risk use cases

Every inventory item should pass through three early filters. First, determine whether the intended practice is prohibited, including manipulative or exploitative uses and other practices listed by the Act. Second, check the transparency rules: chatbots, synthetic content, deepfakes and certain biometric or emotion-related tools can require user information, machine-readable marking or disclosure. Third, assess whether the system falls into a high-risk area such as employment, education, essential services, biometrics, critical infrastructure, migration or law enforcement, or is a safety component of a regulated product.

Classification needs evidence. The file should contain the intended-purpose statement, product documentation, workflow diagrams and the reason a category applies or does not apply. If a system appears within a high-risk area but is claimed not to create the relevant risk, the exemption analysis and any registration consequence should be documented under the rules applicable at that date. Teams should not rely on a vendor's marketing phrase such as compliant AI. The deployer's own use can differ from the provider's intended purpose, and combining tools can create a new decision process with different consequences.

04

Build proportionate controls before buying paperwork

A smaller company needs controls proportionate to its systems, not an enterprise-sized document library copied from the internet. The useful core is an owner for each use case, approved-purpose record, vendor review, data and rights assessment, human-oversight design, testing criteria, incident channel, change log and retention plan. Staff should understand what the tool may be used for, which data may be entered, how outputs are checked and when a human must stop or escalate the process. Training should reflect roles and risk rather than a single awareness slide for everyone.

Vendor due diligence should cover the model or system description, regulatory role, intended purpose, data sources where relevant, security, subcontractors, service changes, output limitations, intellectual-property position, incident cooperation and access to information needed for compliance. Contracts should not promise that the customer bears every legal obligation if the supplier controls the design. Conversely, a deployer should not expect a vendor certificate to resolve its own workplace, consumer or professional-use decisions. Technical, legal and operational evidence should point to the same controls.

05

Coordinate AI Act, GDPR and product governance

Where personal data is involved, the company still needs a GDPR lawful basis, purpose limitation, transparency, data minimisation, retention, security and rights process. High-impact profiling or systematic evaluation may require a data-protection impact assessment. Special-category data, children's data and employee monitoring require additional care. The AI Act's documentation can support the GDPR analysis, but the two are not interchangeable. Synthetic or inferred data may still be personal data, and a human review label does not make automated influence irrelevant if reviewers routinely accept the output.

The implementation file should end with a dated classification register and roadmap. Immediate actions in 2026 include inventory, prohibited-practice screening, transparency implementation where Article 50 applies, review of general-purpose AI dependencies, staff instructions, contract remediation and preparation for later high-risk dates where relevant. The roadmap should name the official source used for each date and assign an owner to monitor Commission guidance, standards and national enforcement. For a smaller technology company, good compliance is not the largest policy. It is the ability to explain what each system does, why it is lawful, what humans control and how the company will detect and correct failure.

04 · PROCESS

How the work is delivered

01

Scope

We identify the jurisdictions, business model, documents, deadlines and decision points.

02

Risk map

You receive a practical view of material legal risks, assumptions and available routes.

03

Delivery

Advice is converted into contracts, policies, notices, checklists or a written legal opinion.

04

Implementation

We refine the documents, support negotiation and clarify the actions your team must take.

AVOCAT BASUC

Need a defined legal workstream?

Describe the product, jurisdictions and desired deliverable. The first response will focus on scope, prerequisites and a realistic route forward.

AVOCAT BASUC

Cosmin Ștefan Basuc · Aleea 1 Iunie 17/30 · Focșani, Romania

Consultations and professional correspondence are available in Romanian or English. Other language versions of this website are provided for information.

© 2026 Avocat Basuc