Monthly Background Newsletter- August


August 2026 Edition

EU AI Act & GDPR for SMEs: What Applies Now — and What Comes Next

What Applies Now — and What Comes Next?

Many SMEs are asking a simple question: if we use AI, what exactly do we need to do now — and what can wait? After last month’s overview of the changing regulatory landscape, this edition looks at the obligations already active, the main dates still ahead, and what they mean for typical SME use cases.

Why this matters now

Not every AI use case is treated the same. Some duties already apply to everyday use, especially when personal data are involved. Others become relevant later, particularly for high-risk AI. A simple inventory and a few clear rules help SMEs prepare without turning every experiment into a legal project.

The Key Dates at a Glance

25 May 2018 — GDPR: Personal Data

Purpose/lawful basis; minimise data; inform people; rights; retention/security; vendor and processor checks; DPIA and Article 22 safeguards where required.

2 February 2025 — AI Literacy + Prohibited Practices

Proportionate literacy measures. Prohibited examples include harmful manipulation, social scoring, facial-image scraping, certain biometric uses, and most workplace emotion recognition.

2 August 2026 — Article 50 Transparency + Enforcement

Where triggered, inform people interacting with AI and label deepfakes or certain AI-generated public-interest text. Applicable enforcement has started.

2 December 2026 — Additional Prohibitions + Transition

New prohibitions for non-consensual intimate content and child sexual abuse material; a limited Article 50 transition ends.

2 December 2027 — Annex III High-Risk AI Duties

Examples can include recruitment, workers, education, credit, life/health insurance, certain biometrics, and critical infrastructure.

2 August 2028 — Regulated-Product High-Risk AI

AI used as a regulated product or safety component; interface with product-compliance duties.

Simplified orientation only — not legal advice. Whether a duty applies depends on the specific role and use case.

What the Current Duties Mean in Practice

GDPR — whenever personal data are involved

Personal data may appear in prompts, uploaded files, logs, outputs, or AI-supported decisions. SMEs should define a purpose and lawful basis, minimise the data used, inform people where required, enable their rights, and set appropriate retention and security rules.

Check processor terms, subprocessors, international transfers, retention, and whether submitted data may be used for model training. A data protection impact assessment is required before processing likely to create a high risk; safeguards apply to solely automated decisions with legal or similarly significant effects.

AI literacy and prohibited practices — active now

Article 4 requires proportionate measures to support AI literacy for staff and others operating or using AI on the organisation’s behalf. There is no prescribed course, exam, certificate, or competence score. A practical model is a short baseline for all users plus role-specific guidance for HR, marketing, IT, procurement, and managers.

Prohibited examples include harmful manipulation or exploitation, social scoring, untargeted facial-image scraping, certain sensitive biometric categorisation, and workplace emotion recognition except for narrow medical or safety situations.

Transparency duties — where triggered

Relevant duties include informing people when they interact with AI, informing people exposed to emotion recognition or biometric categorisation, and clearly labelling deepfakes and certain AI-generated public-interest text. Machine-readable marking duties mainly concern providers.

Provider alert

Do not automatically assume “we only use a vendor tool”. If an SME offers an AI system under its own name, substantially modifies it, or changes its intended purpose, provider obligations may shift to the SME. Those duties are materially broader and should trigger specialist review.

High-Risk AI: Prepare, Do Not Panic

Annex III high-risk AI — from 2 December 2027

SME-relevant examples can include recruitment and CV filtering, worker management or monitoring, education assessment, credit scoring, life or health insurance, certain biometric uses, and critical infrastructure. Deployer duties include following instructions, ensuring competent human oversight, controlling relevant input data, monitoring operation, suspending and reporting serious risks or incidents, retaining logs, and informing workers before workplace use.

Regulated-product high-risk AI — from 2 August 2028

This applies where AI is a regulated product or a safety component of one. For many SMEs it will be a specialised situation, but it matters in product environments such as machinery or medical devices and requires coordination with product-compliance duties.

A 60-Second Triage for Each AI Use Case

  1. Role: deployer only, or could own-branding, substantial modification, or a changed intended purpose make you a provider?

  2. Personal data: do prompts, files, logs, outputs, or decisions identify people?

  3. Prohibited practice: does the use involve banned manipulation, social scoring, workplace emotion recognition, or prohibited biometric use?

  4. Transparency: is the AI public-facing, or does it create or deploy synthetic content, deepfakes, emotion recognition, or biometric categorisation?

  5. High-risk trigger: does it concern recruitment, workers, education, credit, life/health insurance, biometrics, critical infrastructure, or a regulated product?

New Boost AI Self-Assessment Tool helps SMEs take their first steps with AI

Artificial Intelligence offers SMEs significant opportunities – from improving productivity and working smarter to developing new products, services and markets. But knowing where to start, and how to manage risks around data, security and compliance, can be challenging.

That is where the Boost AI Self-Assessment Tool comes in.

The new tool will help SMEs understand where they currently stand with AI, identify areas for improvement and determine which practical steps they can take next. It forms the starting point of the wider Boost AI Toolkit, which will support SMEs with AI self-assessment, AI literacy planning, AI risk management and AI opportunities.

Designed specifically for SMEs

Rather than taking a one-size-fits-all approach, the Self-Assessment Tool is being developed around the realities and needs of smaller businesses. Expertise from across the Boost AI partnership is being brought together, including AI future scanning, legal and ethical considerations, AI literacy and practical experience in supporting SMEs through digital transformation. Most importantly, the approach is demand-led: feedback from SMEs helps shape what the tool covers and how businesses can use the results.

From assessment to action

The assessment is not intended to end with a score. SMEs will be able to use their results as the starting point for an AI Canvas and a tailored customer journey, connecting them with the wider Boost AI tools and support relevant to their needs.

The Self-Assessment Tool launches in September, followed by a restricted pilot running until November. The lessons from these first SME pilots will help further refine the tool before wider use.

Stay tuned – we will share the first insights and lessons from the pilots in an upcoming Boost AI update.

What SMEs Should Do Now

  1. Create a simple AI inventory: tool, provider, purpose, owner, users, affected people, data involved, and current status.

  2. Provide basic AI literacy for all users and short role-specific guidance for teams such as HR, marketing, IT, procurement, and management.

  3. Set approved-tool and human-review rules: what data may be entered, what must not be entered, and which outputs always need verification or approval.

  4. Review the vendor and contract: security, retention, model-training use, subprocessors, transfers, and processor terms.

  5. Keep lightweight evidence: training records, responsible owners, review points, incidents, changes of purpose, and the next review date.

Looking Forward

This is not about turning every SME into a compliance department. It is about making AI use more structured, confident, and future-proof. An inventory, basic literacy, clear tool rules, and early attention to sensitive or high-risk use cases already create a strong foundation.

Content provided by the Machine Learning Group at RPTU for the Boost AI Monthly Background Newsletter series, June 2026 edition.

Steffen Reithermann  <steffen.reithermann@cs.rptu.de - ml.cs.rptu.de\

Newsletter archive: ml.cs.rptu.de/projects/Boost-AI/newsletter/


Monthly Background Newsletter - July
AI Rules Are Changing: What SMEs Should Know Now