Blog
Practical guides, real-world feedback and best practices to accelerate your digital transformation.
Our experts share real-world insights: generative AI integration, business process automation and no-code development. Every article is designed to give you actionable takeaways, tailored to SMBs and mid-market companies.
Blog
Stay up to date with our latest news and practical advice.
An AI information notice is the public document explaining how your AI systems process personal data. It answers the GDPR, not Article 50 of the AI Act, which requires disclosure at the moment of interaction. You need both.
The AI Act and the GDPR do not address the same thing: the GDPR protects personal data, while the AI Act governs artificial intelligence systems. Both apply at the same time as soon as your AI touches customer, employee or prospect data. For an SME, the real question is not which one to follow, but how to fit both into a single compliance effort.
AI Act sanctions can reach 35 million euros or 7 % of worldwide annual turnover for the most serious breaches. But for a small business the rule flips: the fine is capped at the lower of the fixed amount and the percentage, not the higher one. In practice, a compliant small organisation risks almost nothing, and a negligent one is mostly exposed to the middle tier of 15 million euros or 3 %.
A high-risk AI system is one that Article 6 of Regulation EU 2024/1689 places under the AI Act's heaviest obligations. It opens two classification routes: Annex I products and Annex III use cases, whose obligations apply from 2 December 2027.
Since 2 February 2025, eight uses of artificial intelligence have been outright banned across the European Union. Article 5 of Regulation EU 2024/1689 classifies them as unacceptable risk: there is no compliance path, only stopping the use. Here is the exact list and what it means in practice for a small business or a nonprofit.
Since 27 July 2026, Article 4 of the AI Act no longer requires companies to reach a specific level of AI literacy. The Digital Omnibus replaced that binding obligation with simple encouragement. Training your teams is still strongly advised, and it remains required for high-risk uses. Here is what changed, what remains, and what you should actually do.
The AI Act timeline runs from its entry into force on 1 August 2024 through August 2028, with obligations applying in stages rather than all at once. Since the "Digital Omnibus" package was given final approval by the Council of the EU on 29 June 2026, several deadlines have shifted: rules for standalone high-risk systems are now pushed back to 2 December 2027. Here are all the binding dates, what applies at each one, and what changed.
If you use an AI system in your professional activity, even a simple chatbot, the AI Act applies to you. The European regulation on artificial intelligence covers any organisation, business, nonprofit or public body that supplies, imports, distributes or deploys AI within the European Union. So the real question is not whether you are affected, but in what capacity and with which obligations.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Complete no-code guide 2025/2026: tools, techniques, best practices. Learn to build applications without coding with GrowthPerf.