⭐ Star on GitHub

Summary: The Act mentions SMEs 38 times and builds in six categories of relief — sandboxes, fee proportionality, governance participation, simplified documentation, dedicated communication, and proportionate GPAI obligations.

Sources: raw/AI-regulations/Small Businesses' Guide to the AI Act...md; raw/AI-regulations/Regulation - EU - 2024_1689.md

Last updated: 2026-07-28


SMEs are “mentioned 38 times in the Act compared to 7 mentions of ‘industry’ and 11 mentions of ‘civil society’” (source: Small Businesses’ Guide to the AI Act…md).

The six reliefs

1. Regulatory sandboxes — “SMEs will have priority access to sandboxes free of charge, and the procedures shall be simple and clear,” with exemption from administrative fees and facilitated real-world-conditions testing. See Regulatory sandboxes.

2. Reduced costs and fees — “assessment fees shall be proportional to the size of SMEs and the Commission will regularly assess and work to lower compliance costs.”

3. Standard setting and governance participation — the Commission and Member States “shall facilitate participation of SMEs in standard setting and in the AI advisory forum.” The Advisory Forum’s membership brief explicitly includes “industry, start-ups, SMEs, civil society, and academia” (source: raw/Laws/The Advisory Forum...md).

4. Simplified documentation and training — the Commission “will develop simplified SME technical documentation forms that are accepted by national authorities for conformity assessments” plus Article 62 training activities. This is grounded in Art 11(1): SMEs “may provide the elements of the technical documentation specified in Annex IV in a simplified manner,” and “Notified bodies shall accept the form” (source: Regulation - EU - 2024_1689.md).

5. Dedicated communication — “guidance and response to queries through dedicated channels.”

6. Proportionate GPAI obligations — obligations “should be commensurate and proportionate to the type of model provider. For example, there will be separate Key Performance Indicators for SMEs under the Code of Practice.”

The Code of Practice confirms this: “Small and medium enterprises (SMEs) and small midcaps (SMCs) may provide reduced detail levels” in Safety and Security Model Reports, and KPIs and reporting commitments “shall reflect differences in size and capacity between various participants” (sources: raw/Laws/Overview of the Code of Practice...md; Regulation, Art 56(5)).

Penalties too

Art 99(1) instructs Member States to set penalties that “take into account the interests of SMEs, including start-ups, and their economic viability” (source: Regulation - EU - 2024_1689.md). See enforcement-and-penalties.

The caveat the source itself raises

The guide’s closing section is titled “It all depends on implementation” (source: Small Businesses’ Guide to the AI Act…md). Almost every relief here is a commitment to facilitate, develop or assess — dependent on Member State and Commission delivery. The one that is hard law today is Art 11’s simplified documentation form, because it comes with “Notified bodies shall accept the form.”

Where the relief does not reach

None of the six reduces the substantive requirements. An SME building a high-risk system still owes Articles 9–15 in full, including Article 15 cybersecurity. What is reduced is documentation burden, fees, and reporting detail — not the engineering.

The sandbox route is the only one that changes exposure rather than paperwork: following national competent authority guidance inside a sandbox means “providers will not face administrative fines for infringements of the Act,” though they remain liable for third-party damages (source: raw/Laws/AI Regulatory Sandbox Approaches...md).

For a resource-constrained team, that makes the sandbox the highest-value provision in this entire list.