EU AI Act: What a Belgian SME Actually Needs to Do, and When
The EU AI Act applies to Belgian SMEs that use, deploy, or market AI systems — not just tech giants. This article provides a clear, jargon-free roadmap…
By Laurent Maréchal · · 5 min read
The EU AI Act is the major European regulation on artificial intelligence. Since its phased implementation began, many Belgian SME leaders have been asking the same question: does this really apply to me, and if so, where do I start? The short answer: yes, it applies to you, but no, you don't have to do everything at once. What follows gives you a clear roadmap, with no sugarcoating.
What the EU AI Act Concretely Changes for an SME
The EU AI Act isn't just for tech giants. It applies to any organisation that uses, deploys, or places on the market an AI system within the European Union. A Belgian SME that uses a chatbot for customer service, an HR scoring tool, or a price recommendation system is potentially affected.
The regulation classifies AI systems into four risk levels: unacceptable (prohibited), high (heavy obligations), limited (transparency obligations), and minimal (almost nothing required). The majority of tools used by SMEs fall into the "limited" or "minimal" categories. But this needs to be verified, not assumed.
The Real Timeline of Obligations: Who Must Do What and When
The EU AI Act applies in a staggered manner. Absolute prohibitions (unacceptable-risk systems) have been in effect since February 2025. Rules on high-risk systems are progressively coming into force between 2025 and 2027. Transparency obligations for limited-risk systems also apply right now.
For a Belgian SME, the practical timeline looks like this:
- Right now: identify the AI tools used within the company and classify them by risk level.
- Before the end of 2025: put in place minimal documentation for limited-risk systems (disclosure of AI use, usage policy).
- By 2026–2027: if you use or deploy a high-risk system (automated recruitment, credit scoring, etc.), you will need to comply with specific technical and governance requirements.
If you haven't yet carried out this inventory, that is the first step. Not the most complex, but the most urgent.
Pitfalls to Avoid as an SME
The first pitfall is believing you are not affected because you didn't develop the tool yourself. Wrong: if you deploy an AI system to your employees or customers, you are considered a "deployer" under the regulation, and obligations apply to you.
The second pitfall is fully delegating compliance to your software provider. Your provider has its own obligations, but so do you. In particular: informing your users, training your teams, and documenting your usage.
The third pitfall is trying to do everything at once. A priority-based approach — first the inventory, then the classification, then corrective actions — is far more effective than a large compliance project that drags on for two years.
To help you navigate these requirements without getting overwhelmed, the website Audityo, specialising in EU AI Act compliance for SMEs, offers resources and support tailored to the size and means of smaller organisations.
What You Need to Document (and What You Can Ignore)
Documentation is often presented as an administrative monster. In reality, for most SMEs, it comes down to a few essential elements:
- An inventory of AI tools in use (name, provider, purpose, data processed).
- A risk level classification for each tool.
- An internal usage policy: who uses what, in what context, and with what limitations.
- An explicit disclosure to end users when they interact with an AI system (chatbot, automatically generated content, etc.).
What you can ignore for now: the detailed technical requirements for high-risk systems, if you don't use any. Don't get lost in obligations that don't yet apply to you.
If your company already uses AI assistants to automate internal tasks, that is precisely the type of usage that should be documented as a priority.
The Link with GDPR: What You've Already Done Counts
Good news: if your SME has already worked on GDPR compliance, you have a solid foundation. The EU AI Act and the GDPR share several common principles — transparency, documentation, individuals' rights, and accountability of the data controller. Your GDPR processing register can serve as a starting point for your AI inventory.
The main difference: the GDPR focuses on personal data, while the EU AI Act focuses on the AI system itself, whether or not it processes personal data. The two are complementary, not redundant.
Where to Concretely Start This Week
You don't need a large consulting firm to get started. Here are three actions achievable in less than a day's work:
- List all the digital tools you use that have an AI component: text generation tools, chatbots, predictive analytics tools, HR software with scoring, etc.
- For each one, ask yourself two questions: does this tool make decisions that affect people? Do users know they are interacting with an AI?
- Book an appointment with an expert to validate your classification before diving into unnecessary documentation.
If you have already started thinking about automating your business processes, integrating EU AI Act compliance into that approach is natural and far less costly than doing it after the fact.
Conclusion
The EU AI Act is not an abstract threat aimed at large tech companies. It is a real framework, with concrete deadlines, that affects Belgian SMEs today. The good news: if you start with the inventory and classification, you have already completed 60% of the work. The rest is a matter of organisation, not budget.
Don't know where to start, or want to validate your current situation? Book a free thirty-minute discovery call, with no commitment, to take stock of your actual obligations and priority actions. Request your AI diagnostic at ainspiration.eu/audit and leave with a clear roadmap tailored to your SME.