It is already in force. Most European SMBs still have nothing written down.
Since 2 August 2026 the Article 50 transparency duties and the GPAI penalty powers apply. If your team uses Copilot, ChatGPT, Claude, or any AI that produces content shown to customers, you have to disclose the AI interaction and label synthetic content, with fines reaching 15 million euros or 3 percent of global turnover. The heavier high-risk obligations under Annex III were deferred to December 2027, which is time to prepare, not permission to skip the part already live. 3DH delivers a 4-week sprint that closes the gap.
Five obligations every SMB using AI needs to close
AI literacy (Article 4)
Everyone in your organisation using AI tools needs documented training appropriate to their role. Not a one-line policy. Evidence.
Risk classification
Each AI use case is either prohibited, high-risk, limited-risk, or minimal-risk. Wrong classification creates exposure. Most SMBs have not done this yet.
Transparency obligations
When AI generates content shown to customers, employees, or counterparties, certain disclosures are mandatory. The format and triggers depend on use case.
Technical documentation
For any high-risk AI system, you need a documentation pack covering training data, intended purpose, risk management, human oversight design, and accuracy / robustness measures.
Human oversight
Some AI workflows now require designed-in human review before action. The design needs to be documented, not improvised.
From unknown exposure to documented compliance
- Week 1
AI inventory and risk classification
We map every AI use case in your business. Copilot in Outlook, ChatGPT used by anyone, custom GPTs, Make / Zapier flows touching AI, shadow agents in Copilot Studio. Each one gets classified against the AI Act risk tiers. Output: a written register your legal counsel can sign.
- Week 2
AI literacy programme and transparency baseline
Role-based AI literacy training designed for your specific tool stack. Documented attendance, documented content, documented refresh cadence. Transparency disclosures drafted and approved for the use cases that need them, in the languages your customers actually use.
- Week 3
Technical documentation pack
For each high-risk system in your inventory: intended purpose statement, data documentation, risk management plan, oversight design, accuracy measurements, post-deployment monitoring plan. Format is the EU template, not invented ad hoc.
- Week 4
Handover and monitoring retainer
We hand the full compliance pack to you and your counsel. Walk through every artifact. Set up the monthly retainer that watches for enforcement signals, updates the documentation when your tooling changes, and refreshes AI literacy each year.
A fixed fee, quoted for your firm in one conversation.
A price here is a conversation, not a table. It depends on the size of your AI inventory, how many tools face clients, and how much of the documentation your team wants to own, so every engagement is quoted individually and fixed in writing before work starts. We scope in the first 30 minutes of a call, not after a paid discovery.
Portuguese SMEs may qualify for PRR funding covering up to 75 percent of digital transition spend. We help you check eligibility at no cost during the initial call.
What people actually ask about the AI Act
Does the AI Act apply to a company that only uses AI tools?
Yes. Anyone operating an AI system they did not build is a deployer. That covers a support chatbot, a CV filter, lead scoring, and any general writing assistant. You do not have to develop AI to have obligations under it.
What applies right now, in 2026?
Article 50 transparency duties applied from 2 August 2026: disclose that a chatbot is AI, label AI-generated or AI-edited content, and mark deepfakes as artificial. These are disclosure duties, not prohibitions.
Were the high-risk rules delayed?
Yes, and a lot of published advice has not caught up. The Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026, moved the Annex III high-risk obligations from August 2026 to December 2027. If someone is still selling you August panic about high-risk systems, they are out of date.
What does an ordinary SMB actually have to produce?
In practice: an inventory of the AI systems in use, a note of who is responsible for each, the disclosures on anything customer-facing, and evidence of human oversight where a system informs decisions about people. Most of that is documentation, and most of it can live in the Microsoft 365 tenant you already run.
You have less than three months. Start now.
We take a limited number of compliance engagements per month to keep delivery quality high. If your business uses any AI in production and you have not yet classified the risk, we should talk this week.
Book a 20-minute call