Back to insights
20 September 2026·Koodi team·3 min read

EU AI Act Compliance for SMEs: What You Need to Know Now

Understanding the EU AI Act for Estonian SMEs

The European Union's Artificial Intelligence Act (AI Act) has officially entered into force, marking a significant shift in how AI systems are developed, deployed, and used across the EU. For small and medium-sized enterprises (SMEs) in Estonia, this means new considerations and, in many cases, new compliance requirements. While the full scope of obligations will roll out gradually, understanding the core principles now is vital.

The AI Act aims to ensure that AI systems used within the EU are safe, transparent, non-discriminatory, and environmentally sound, while also fostering innovation. It adopts a risk-based approach, categorizing AI systems into different levels of risk, with stricter rules for higher-risk applications.

What are the Risk Categories?

  • Unacceptable Risk: These AI systems are banned as they pose a clear threat to fundamental rights (e.g., social scoring by governments, real-time remote biometric identification in public spaces for law enforcement, with very narrow exceptions). It's unlikely most SMEs would intentionally deploy such systems, but awareness is key.
  • High-Risk: This category includes AI systems used in critical sectors like employment, education, critical infrastructure, law enforcement, migration, and certain medical devices. If your SME develops or uses AI in these areas, the compliance burden will be significant. Requirements include robust risk management systems, high-quality data sets, human oversight, transparency, and conformity assessments.
  • Limited Risk: AI systems that interact with humans (e.g., chatbots) or generate deepfakes fall into this category. The main requirement here is transparency, ensuring users are aware they are interacting with an AI or that content is AI-generated.
  • Minimal or No Risk: The vast majority of AI systems, such as spam filters or AI-powered games, fall into this category. These systems are generally not subject to specific obligations under the AI Act, though voluntary codes of conduct are encouraged.

Impact on Estonian SMEs

Many Estonian SMEs are already leveraging AI for various tasks, from customer support chatbots to predictive analytics in e-commerce. The AI Act's implications will depend heavily on how and where AI is integrated into their operations or products:

  • Developers of AI: If your SME develops AI systems, especially those falling into the 'high-risk' category, you will need to implement robust quality management systems, conduct conformity assessments, and ensure data governance.
  • Users of AI: If your SME uses AI systems developed by others, particularly high-risk ones, you will have obligations regarding human oversight, monitoring performance, and data input. You also need to ensure the system you use is compliant.
  • Data Governance: The Act places a strong emphasis on data quality and governance, especially for high-risk AI. This aligns with existing GDPR principles but adds specific AI-related requirements.
  • Transparency: Regardless of risk level, transparency is a recurring theme. Users should know when they are interacting with AI or consuming AI-generated content.

Next Steps for Your Business

The AI Act provides a phased implementation, giving businesses time to adapt. However, waiting until the last minute is not advisable. Estonian SMEs should start by:

  1. Inventorying AI Use: Identify all AI systems currently in use or under development within your company.
  2. Assessing Risk: Determine which risk category each identified AI system falls into based on the Act's definitions.
  3. Reviewing Data Practices: Ensure your data collection, storage, and processing for AI align with both GDPR and the emerging AI Act requirements.
  4. Seeking Expertise: For complex cases, consider consulting with legal or IT experts who specialize in AI regulation.

Navigating the complexities of the EU AI Act can be challenging, but proactive preparation is key to ensuring continued innovation while maintaining compliance. Koodi can help your Estonian business assess your AI usage, understand your obligations, and develop a roadmap for compliance with the new regulations.