
EU AI Act for SMB: What €35M / 7% turnover means for your compliance roadmap
TL;DR
- •The EU AI Act exempts most SMBs unless revenue exceeds €35M or AI-related turnover hits 7% of total.
- •High-risk AI systems (e.g., hiring tools, credit scoring) trigger conformity assessments regardless of size.
- •Start with an internal AI inventory to map what you build or use — this determines your obligations.
- •Definition:** High-risk AI — AI systems listed in Annex III of the EU AI Act (e.g., biometrics, critical infrastructure, employment, education, law enforcement) that require conformity assessments before deployment.
- •Definition:** SMB under the EU AI Act — enterprises with fewer than 250 employees and either annual turnover ≤ €50M or balance sheet total ≤ €43M. Note: the €35M / 7% rule applies specifically to AI-related revenue thresholds for certain obligations.
- •Definition:** Conformity assessment — the process of verifying that a high-risk AI system meets the Act's requirements (data governance, transparency, human oversight, accuracy, robustness) before market placement.
When a founder of a 40-person logistics team told me they were building an AI agent for route optimization but froze when they heard 'EU AI Act fines,' I realized the real blocker wasn't the law — it was the mystery around what it actually demands.
What triggers the €35M / 7% rule?
This threshold applies to providers of general-purpose AI models (like foundation models) when their AI-related revenue exceeds €35M or represents 7% of total annual turnover. For most SMBs deploying off-the-shelf or narrow AI (e.g., invoice processing agents, internal knowledge bots), this does not apply. However, if you're building or fine-tuning a model used across multiple clients or internal products, track AI-specific revenue separately.
Step 1: Inventory your AI — don't guess
Before assessing risk, list every AI system your company builds, deploys, or uses. Include:
- LLMs used for contract drafting or customer support
- ML models for demand forecasting or lead scoring
- Embedded AI in third-party tools (e.g., CRM with predictive analytics)
Tool tip (AIAdvisoryBoard.me): Run a 7-day diagnostic to surface what your teams actually automate — not what you assume. This creates your Plan → Fact → Gap baseline for AI inventory. See how the 7-day diagnostic works.
Step 2: Classify risk — most SMB AI is limited or minimal risk
The Act uses a pyramid:
- Unacceptable risk (banned): social scoring, real-time facial recognition in public spaces, manipulative AI.
- High risk: Annex III systems (e.g., AI for recruitment, worker management, creditworthiness).
- Limited risk: chatbots, emotion recognition systems — requires transparency (disclose AI use).
- Minimal risk: spam filters, AI-enabled video games — no obligations.
Most internal automation (e.g., HR resume screening, sales lead scoring) falls into high or limited risk depending on use case. An AI agent that suggests job candidates? High risk. One that drafts rejection emails? Limited risk — but only if you disclose it's AI-generated.
Tool tip (AIAdvisoryBoard.me): Use the free org chart tool to map routine work by department — this reveals where AI is already touching decisions that could trigger compliance review. Enter your site and headcount to get a visual map in 30 seconds.
Manager scan (2-minute digest example)
- CEO: Reviewing AI agent for vendor contract comparison — flagged as limited risk (transparency needed)
- COO: Evaluating demand forecasting model — internal use, but influences procurement → assess as high-risk if tied to public tenders
- Head of Sales: Using lead-scoring AI — if it affects pricing or credit terms, treat as high-risk
- HR Lead: Testing resume-screening tool — high-risk under Annex III (employment)
- Finance Team: AR reconciliation agent — minimal risk (no individual impact)
- Support Lead: Chatbot for FAQs — limited risk (must disclose AI use in chat window)
Micro-case (what changes after 7–14 days)
A 60-person SaaS company built an internal AI agent to prioritize customer support tickets. After running the diagnostic, they discovered the agent was using past ticket data to infer customer sentiment and escalate to managers — a profiling function. Though not customer-facing, the logic touched behavioral inference. They added a transparency note in the internal tool and logged training data sources. No fines, no redesign — just clarity on what needed documentation.
Note on this case: This example is illustrative — based on typical patterns we observe with companies of 30–500 employees, not a single named client. Specific numbers are rounded approximations of common ranges, not guarantees.
FAQ
Do I need to appoint an AI officer under the EU AI Act? Only if you're a provider of high-risk AI systems and meet certain scale thresholds. Most SMBs deploying AI internally do not require a dedicated officer — but someone must own the AI inventory and risk classification.
What if I use a third-party AI tool that's high-risk (e.g., a hiring platform)? As a deployer, you're responsible for ensuring the system is used according to instructions, monitoring performance, and maintaining logs. You don't need to redo the conformity assessment, but you must verify the provider's CE marking and documentation.
Does the Act apply if my AI doesn't process personal data? Yes. Risk classification depends on the system's purpose and impact (e.g., biometric identification, social scoring), not just data type. An AI that evaluates vocal stress in job interviews is high-risk even if anonymized.
How often should I update my AI inventory? Quarterly — or whenever you deploy a new model, integrate a new AI feature, or change the purpose of an existing one. Treat it like a security asset register.
Where can I find the official list of high-risk AI systems? Annex III of the EU AI Act is available on EUR-Lex. Search for "Annex III high-risk AI systems" — it includes eight categories from biometrics to law enforcement.
Conclusion
The EU AI Act isn't a blanket ban on AI for SMBs — it's a targeted framework that leaves most internal automation untouched. Your first step isn't legal review; it's visibility. Know what AI you have, where it makes decisions, and whether it falls into Annex III. From there, compliance becomes a documentation task, not a redesign.
What to do today
Spend 30 minutes listing every AI-assisted workflow in your company — even if it's just a prompt in ChatGPT used weekly. This inventory is your foundation.
If you want a system that surfaces the Plan → Fact → Gap automatically — every day, across the company — see how the 7-day diagnostic works.
Frequently Asked Questions

Implements AI agents in companies and teaches founders and their teams to work with them — through courses and corporate programs.
This article was prepared with AI assistance, based on Yaroslav Maxymovych's methodology and materials. Spotted an inaccuracy — let us know via the form below.
Your company's first 3 AI automations — in 2 weeks
A corporate AI-transition program: 4 live sessions with your team plus a video course for every employee. Up to 20 people for one fixed price. If it doesn't work — money back.
New case studies on AI adoption — in your inbox
Once a week: practical breakdowns of what companies automate with AI and what actually comes out of it.
No spam. Unsubscribe anytime.
Related Articles

Converting AI 'Time Saved' to Actual Dollars: The Honest Version
Learn how to convert AI time savings into real dollar impact using a transparent, founder-tested method. Avoid inflated ROI claims and focus on verifiable gains.
Read more
How to Avoid Vendor Lock-In After AI Implementation
Learn how to retain code, data, and team autonomy when using external contractors for AI automation. Practical steps, checklist, and FAQ for business owners evaluating AI adoption.
Read more
AI vendor due diligence checklist for SMB
A founder-focused checklist for evaluating AI vendors: contracts, data security, and change management — so you buy based on operating reality, not demos.
Read more