Resource / EU AI Act

The EU AI Act, explained for SMEs.

The EU regulation on artificial intelligence already applies in the EU, and Norway is implementing it through a dedicated Norwegian AI Act. For small and medium-sized businesses using AI tools or commissioning AI solutions, it comes down to three things: some uses are prohibited, some require systematic work, and everyone must understand what the tools do. This is a practical overview, not legal advice.

Last updated: September 26, 2026. Last fact-checked September 26, 2026.

  1. 01

    What the AI Act is

    The AI Act is EU Regulation 2024/1689 laying down harmonised rules on artificial intelligence. It entered into force in the EU on 1 August 2024. Its purpose is to protect health, safety, and fundamental rights, and to create a single market for safe AI systems. The framework is risk-based: it prohibits a small number of uses, places strict duties on high-risk systems, requires transparency where people should know AI is involved, and leaves low-risk use largely unregulated. The regulation is EEA-relevant and will be implemented in Norway through a dedicated AI Act.

  2. 02

    Four risk levels, from banned to free use

    Prohibited AI practices are listed in Article 5 and include manipulative systems, exploitation of vulnerable groups, social scoring, and real-time remote biometric identification. In December 2026 a ninth prohibition arrives, targeting non-consensual intimate images and child sexual abuse material. High-risk systems are either safety components in regulated products (Annex I) or use cases in Annex III, such as recruitment, credit, and insurance. Chatbots and AI-generated content carry transparency duties, while spellchecking and spam filters count as minimal risk. Article numbers refer to the original numbering; check them against the consolidated legal text, since the Omnibus amendments may have moved numbers.

  3. 03

    Provider or deployer decides the duties

    Whoever develops or places an AI system on the market is the provider and carries the heaviest duties: risk management, documentation, logging, human oversight, conformity assessment, and CE marking. Whoever puts the system into use in their own organisation is the deployer and must follow the instructions for use, exercise oversight, monitor operations, report serious incidents, and inform those affected. Substantial modifications, a new purpose, or your own trademark on the system can turn the deployer into the provider. Light configuration normally does not move the role, but where the line falls in practice is not finally settled.

  4. 04

    Duties that typically affect an SMB

    An SMB using AI tools without selling AI systems still faces duties. The prohibitions apply to everyone, including pure users. Article 4 requires sufficient AI literacy among staff operating and using the systems, with no demand for formal certification. Chatbots and AI-generated content must be disclosed, and the deployer carries independent responsibility that the information reaches those affected. Using AI for recruitment, staff appraisal, credit, or insurance triggers the high-risk duties: oversight, monitoring, logging, and a fundamental rights impact assessment.

  5. 05

    The timeline covers the EU; Norway needs its own act

    Prohibitions and AI literacy have applied in the EU since 2 February 2025. Rules for general-purpose AI models, governance, and penalties followed on 2 August 2025. General application arrives on 2 August 2026, while the Omnibus amendments push the high-risk deadlines to 2 December 2027 for Annex III and 2 August 2028 for Annex I products. For SMB planning this means prohibitions, literacy, and transparency apply now, while the heaviest high-risk deadlines sit further out. In Norway the real deadlines depend on EEA incorporation and Norwegian entry into force.

  6. 06

    Norwegian implementation is in progress

    The Ministry of Digitalisation and Public Governance sent a proposal for a new AI Act for consultation on 30 June 2025, with a deadline of 30 September 2025. The consultation paper proposes Nkom as coordinating market surveillance authority, the Financial Supervisory Authority for finance, and the Data Protection Authority in the complaints role, with KI Norge in Digdir and regulatory sandboxes as support. The stated plan has been entry into force during 2026, but as of 26 September 2026 we have not found public confirmation of a proposition, adoption, EEA Committee decision, or final date. Verify the status against regjeringen.no and Lovdata before relying on it. Do not wait to prepare: mapping, training, and supplier documentation are useful whatever the final timeline turns out to be.

Overview

Checklist for the SMB

Ten practical steps before adopting or expanding AI. These are general pointers, not legal advice.

Map AI use

List every tool involving AI, including hidden AI in HR tools, marketing, and customer service. Note purpose, supplier, data sources, and who is affected.

Test against the prohibition list

Go through Article 5 and discontinue any use resembling prohibited practices. Document the assessment.

Clarify roles

Are you provider or deployer for each system? Have you made changes that could move the role? Get the answer in writing where in doubt.

Check high-risk

Do any use cases appear in Annex III? Start work on oversight, logging, monitoring, and impact assessment well before the deadlines.

Ensure AI literacy

Train staff for the tools they use: capabilities, limitations, checking routines, and escalation. Repeat for new tools and major updates.

Meet the transparency duties

Label chatbots, AI-generated content, and automated assessments. Agree with suppliers who does what.

Require supplier documentation

Instructions for use, limitations, test results, and an incident contact should exist in writing before purchase.

Establish an incident routine

Define what counts as a serious AI incident in your business, who is notified, and how it is logged and reported onward.

Track Norwegian status

Check regjeringen.no, the Data Protection Authority, and Lovdata regularly for proposition, adoption, and entry into force.

Consider the sandbox

For innovative AI uses with regulatory uncertainty, the Data Protection Authority sandbox or KI Norge may be relevant sparring partners.

FAQ

EU AI Act FAQ

Does the AI Act affect us if we only use ChatGPT and Copilot?
Partly, yes. The prohibitions and the literacy duty apply to all businesses, and the transparency duties apply when AI-generated content is shared onward. Plain office tools rarely trigger high-risk duties.
What is the practical difference between provider and deployer?
The provider makes or sells the AI system and carries the development and documentation duties. The deployer uses the system in its own operations and must follow the instructions, exercise oversight, monitor, and inform those affected. Substantial modifications or a new purpose can turn the deployer into a provider.
Must staff be certified in AI?
No, the regulation does not require formal certification. It requires sufficient literacy adapted to actual use: those operating and using the systems must understand what they do, where they fail, and how outputs are checked.
We use AI to rank job applicants. What applies?
Recruitment appears in Annex III and is high-risk. That triggers human oversight, monitoring, logging, information to those affected, and a fundamental rights impact assessment. Seek legal assistance before continuing such use.
When do the rules apply in Norway?
That depends on the Norwegian AI Act and EEA incorporation. The stated plan has been entry into force during 2026, but as of 26 September 2026 no final adoption or date is publicly confirmed as far as we have found. Businesses selling into the EU are already covered by the EU rules there.
What happens on breach?
The regulation has fine levels that for the most serious breaches can reach 35 million euros or 7 percent of global turnover. Enforcement in Norway will follow the Norwegian AI Act once adopted. Reputational and contractual risk often materialises before fines.
Where do we find official guidance?
The European Commission AI Act pages, EUR-Lex for the legal text, Datatilsynet for privacy guidance and the sandbox, Digdir and KI Norge for competence, and regjeringen.no for the status of Norwegian implementation. See the sources on this page.
Should we hold off on AI projects until everything is settled?
No. The prohibitions are clear, the literacy duty applies, and transparency is good practice in any case. Start with mapping, training, and supplier requirements, and build high-risk uses only once the duty picture is clarified legally.
Sources

Sources

This article builds on primary sources, last checked 26 September 2026. Check them again before important decisions.

Trust

A practical overview from Aprex

Aprex builds AI solutions for Norwegian businesses with open eyes: know what you use, make sure people understand it, be open about it, and keep high-risk uses away without a proper foundation. This article is a practical overview based on primary sources, not legal advice. When in doubt about duties or high-risk uses, consult a lawyer.

Want to map your AI use?

Send which AI tools you use, what they are used for, and who is affected. Aprex helps with mapping and safe next steps.

Contact Aprex about AI mapping →