The European AI Act passes its first application milestone
Since 2 February 2025, the first provisions of the European regulation on artificial intelligence have come into effect. The ban on AI systems presenting an unacceptable risk — social scoring, subliminal manipulation, exploitation of vulnerabilities — is now in force. In parallel, AI literacy obligations for companies have become mandatory. A major regulatory turning point that concerns every organization operating in the European market.
What this changes for you
✦ The opportunity
The entry into force of the AI Act creates a framework of trust that is unique in the world. Companies that anticipate compliance position themselves as responsible players and attract clients, partners and investors who are sensitive to ethical issues.
Competitive advantage
Demonstrating AI Act compliance is becoming a differentiating selling point, particularly in public tenders and B2B relationships with large accounts.
Structured governance
The AI literacy obligation pushes companies to train their teams and document their use cases, which improves the overall quality of deployments.
An exported European standard
Like the GDPR before it, the AI Act is establishing itself as a global benchmark. Being compliant today prepares you for similar regulations that will emerge elsewhere.
⚠ The risk
Underestimating the complexity
Many SMBs believe the AI Act does not concern them. Yet as soon as a company uses a chatbot, a scoring tool or a recommendation system, it is potentially subject to transparency and documentation obligations. Ignorance of the text does not protect against penalties.
Cost of compliance
For systems classified as high-risk, the documentation, audit and human oversight requirements represent a significant investment. Estimates range between €5,000 and €50,000 for an SMB depending on the complexity of the use cases.
Our recommendation
Compliance is a marathon, not a sprint. Here are the three priority steps we recommend to French SMBs and mid-market companies.
Map your AI use cases
Inventory all the tools and systems using AI in your organization: chatbots, analytics tools, automations, SaaS software that integrates AI. Classify them according to the risk levels defined by the regulation (minimal, limited, high, unacceptable).
Launch an AI literacy program
Train your employees in the fundamentals of AI and the obligations of the regulation. This obligation has been in effect since February 2025. Start with management and the business teams most exposed.
Appoint an AI Act lead
Name a person responsible for regulatory monitoring and for coordinating compliance. This role can be combined with that of DPO for moderately sized organizations.
In summary
Frequently asked questions
Which companies are affected by the AI Act as of 2025?
All companies that develop, deploy or use AI systems within the European Union are affected, regardless of their size. SMBs do, however, benefit from extended deadlines and partial exemptions for certain obligations.
What penalties are provided for in case of non-compliance?
Fines can reach 35 million euros or 7% of annual worldwide turnover for the most serious infringements. For SMBs, reduced caps are provided so as not to jeopardize their economic viability.
How do I know if my AI system is classified as high-risk?
Annex III of the regulation lists the high-risk domains: healthcare, education, recruitment, credit scoring, critical infrastructure. If your system significantly impacts people's lives in these areas, it is probably affected.
Is there any support available to get compliant?
Yes, the European Commission has set up regulatory sandboxes and practical guides. In France, the CNIL and Bpifrance also offer dedicated support for SMBs.
For tech profiles
The AI Act regulation is built around a risk-level classification that determines the applicable technical obligations:
| Risk level | Examples | Main obligations | Deadline |
|---|---|---|---|
| Unacceptable | Social scoring, subliminal manipulation | Total ban | February 2025 |
| High | AI recruitment, credit scoring, medical diagnosis | Technical documentation, audit, human oversight, CE marking | August 2026 |
| Limited | Chatbots, deepfakes, recommendation systems | Transparency obligations | August 2025 |
| Minimal | Anti-spam filters, video games | No specific obligation | - |
Key technical points: Foundation model providers (GPAI) must provide detailed technical documentation including training data, evaluation metrics and robustness tests. Models presenting a systemic risk (threshold: 10^25 training FLOP) are subject to reinforced obligations for red teaming and adversarial evaluation.