Monthly Background Newsletter - July

AI Rules Are Changing: What SMEs Should Know Now

July 2026 Edition

AI Rules Are Changing: What SMEs Should Know Now

Should your company already comply with the AI Act?

Many SMEs are not sure—and that uncertainty can make AI feel riskier than it needs to.

The good news? The rules are becoming clearer, and businesses now have more time to prepare. But that does not mean waiting is the best strategy.

Instead, use this time wisely:

  • Test AI safely
  • Build simple internal guidelines
  • Learn which AI use cases deserve closer attention


Why This Matters for SMEs

Many SMEs want to start using AI but hesitate because of regulation, data protection, or uncertainty about what is allowed. That is understandable, especially when AI tools evolve quickly and legal language often feels far removed from daily business.

The practical message is simple:

You do not need to stop experimenting—you just need to experiment in a structured way.

Start small, keep people in control, and document important decisions.


The AI Act in One Minute

The EU AI Act follows a risk-based approach.

Some AI practices are prohibited, many everyday AI applications have only limited obligations, while high-risk AI systems must comply with stricter requirements.

For most SMEs, there is no need for a legal deep dive.

Instead, ask yourself:

  • Where are we already using AI?
  • What data is involved?
  • Who checks the results?
  • Could the AI output significantly affect people?


What Is Changing at EU Level?

The implementation of some AI Act obligations has been postponed.

The key change is that companies now have more time to prepare before certain high-risk AI obligations apply.

This additional time should be used to:

  • Test AI tools
  • Develop internal processes
  • Prepare for future guidance and standards

The AI Act has not disappeared—the timeline has simply become more manageable for SMEs.


Less Bureaucracy Does Not Mean No Rules

Simplification is not deregulation.

AI applications involving:

  • personal data
  • automated decision-making
  • customer-facing content
  • HR processes
  • sector-specific regulations

still require careful assessment.

A useful rule of thumb:

The greater the impact an AI system has on people, rights, safety or finances, the more carefully it should be assessed and documented.


A Simple SME Risk Map

A practical first step is to divide AI use cases into three categories.

🟢 Low-risk support

Examples:

  • Drafting product descriptions
  • Summarising public information
  • Preparing meeting notes

🟡 Data-sensitive processes

Examples:

  • Summarising customer emails
  • Analysing invoices
  • Working with supplier or employee information

🔴 High-impact decisions

Examples:

  • Ranking job applicants
  • Assessing creditworthiness
  • Deciding access to services
  • Supporting safety-related decisions

This simple categorisation helps determine which AI pilots can start immediately and which require additional review.


Four Questions Before Testing an AI Tool

Before selecting an AI solution, ask yourself:

  1. What business process should improve?
  2. What information will the tool need?
  3. Who will review the results?
  4. How will we measure whether the pilot is successful?

These questions turn regulation into a practical design tool rather than a barrier.



What SMEs Should Do Now

A practical starting point:

  • Make a list of all AI tools currently used within the company.
  • Separate low-risk applications from higher-risk use cases.
  • Check which data is shared with AI providers.
  • Decide who reviews AI-generated outputs.
  • Keep short records of important AI use cases and responsibilities.


The Takeaway

SMEs do not need a dedicated compliance department to get started.

A simple AI register, a few internal guidelines and clear employee instructions already provide a strong foundation for responsible AI adoption.

The goal is not to slow innovation down.

The goal is to help SMEs adopt AI with confidence—step by step.

Future editions of the Boost AI Background Newsletter will explore topics such as AI pricing, hidden costs, cybersecurity, European AI sovereignty and local AI solutions.


Content provided by the Machine Learning Group at RPTU for the Boost AI Monthly Background Newsletter series, June 2026 edition.

Steffen Reithermann  <steffen.reithermann@cs.rptu.de - ml.cs.rptu.de


Monthly Background Newsletter - June
AI Types, Sovereignty and Deployment Choices