← Blog

EU AI Act for Hungarian SMEs: what changes in 2026?

EU AI Act for Hungarian SMEs: what changes in 2026?

Our clients often put it this way: “the EU AI Act is for big companies; it does not affect us.”

That usually comes from one assumption. They imagine an “AI system” as something they see on social media: a self-driving car or a facial recognition camera. What they use is “just a chatbot,” “just a CV screener,” or “just a credit-scoring feature in the bank’s software.” Under the law, some of these “justs” are high-risk AI systems. Others have already been prohibited since February 2, 2025.

Updated: 10 August 2026. This article was first published in April 2026, when high-risk systems still faced the 2 August 2026 deadline. Since then the Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026) has moved the Annex III obligations to 2 December 2027, and those for systems embedded in products (Annex I) to 2 August 2028. The transparency rules, the prohibited practices and the AI literacy obligation all still apply. The text below has been updated accordingly.

As a founder with a law degree, let me explain what took effect in August 2026, what slipped to the end of 2027, and what will almost certainly affect you if your company uses AI tools.

What took effect, and what slipped?

Regulation (EU) 2024/1689, commonly known as the EU AI Act, entered into force two years ago, on August 1, 2024, but it becomes applicable in stages. That gives us several separate dates, and in the summer of 2026 the order of them changed.

February 2, 2025. Article 5 on prohibited AI practices and Article 4 on AI literacy became applicable. Certain uses of AI have been unlawful ever since. AI literacy affects every company: you must ensure that your staff have a “sufficient level” of understanding of the AI systems they use. There is no company-size threshold; it applies even to a two-person microbusiness.

August 2, 2025. The rules for providers of general-purpose AI models such as GPT, Claude, and Gemini became applicable. This probably does not affect you directly unless you build and place your own language model on the market, but you may feel its effects through providers: their model documentation and auditability are already held to a different standard.

August 2, 2026. Two things took effect that day, and the third one slipped.

What took effect: the transparency obligations in Article 50. A chatbot on your website must clearly tell visitors they are interacting with AI. Images, videos, and articles created with AI must be visibly labeled. This is a live obligation today, not a future one.

Also from that date: enforcement by national authorities began. In Hungary, Government Decree 344/2025 (X. 31.) appointed the minister responsible for industrial development for this role and the MNB for the financial sector. Hungary’s implementing legislation, Act LXXV of 2025, has been in force since December 1, 2025.

What slipped: the full set of obligations for high-risk AI systems. These are the systems listed in Annex III of the Regulation, including AI systems used for targeted job advertisements, CV screening, credit scoring, and educational assessment.

December 2, 2027. This is the new deadline for high-risk systems. The Digital Omnibus, Regulation (EU) 2026/1744, has been in force since 27 July 2026, and it moved the Annex III obligations from the earlier date of 2 August 2026. For systems embedded in products under Annex I, the date is 2 August 2028.

One clarification worth making: the delay is preparation time, not an exemption. The Commission proposed it because the harmonized standards were not finished on time and the designation of national authorities was running late. It is worth putting your documentation and data hygiene in order now, because a calm year costs less than a final quarter spent rushing.

Does this affect me? What are the four risk categories?

The AI Act is layered by use, not company size. Every AI system, including yours, whatever it does, can be placed in one of the four categories below. The category determines whether you have to do anything at all.

CategoryTypical SME exampleMain obligationApplicable from
Prohibited AI practice (Article 5)Emotion-recognition software for job interviews; “vulnerability” segmentation for advertising; subliminal manipulation campaignIts use is unlawful.February 2, 2025 (already applicable)
High-risk (Annex III)AI-based CV screener or recruitment scoring; credit and insurance risk assessment; employee performance measurementFull compliance system: documentation, human oversight, logging, employee information, incident reportingDecember 2, 2027 (moved by the Digital Omnibus)
Limited risk (Article 50)Customer service chatbot; AI image generator for marketing; deepfake-based contentTransparency: people must be told they are interacting with AI or viewing AI contentAugust 2, 2026 (already in force)
Minimal riskSpell checker; spam filter; recommendation systemNo obligation under the AI Act beyond “AI literacy” under Article 4.February 2, 2025 (already applicable)

The categories do not overlap, but the order matters: if a system is prohibited, you do not need to consider whether it is high-risk. Emotion-recognition software for job interviews is prohibited in the workplace under Article 5(1)(f). There is no judgment call to make.

One important mechanism: if your system is listed in Annex III but performs only a narrow procedural or preparatory task, or merely improves the result of a previously completed human activity, it is not high-risk under the exception in Article 6(3). But you must document that assessment and register the system in the EU database. The exemption is not automatic.

The three traps Hungarian SMEs fall into

The table above is clear. Reality is less so. Hungarian small and medium-sized businesses almost invariably misjudge the following three situations.

1. The CV screener is “just software”

Under point 4 of Annex III, AI systems used in “employment, workers management and access to self-employment” are high-risk. Specifically, this includes systems used to place targeted job advertisements, filter CVs, and rank or evaluate candidates.

A 15-person company that adds an AI-based recruitment tool to its HR process will become the deployer of a high-risk AI system from December 2, 2027. Its obligations under Article 26 include assigning human oversight, keeping logs for at least six months, informing employees and workers’ representatives in advance, reporting incidents, and informing affected persons, meaning the candidates.

Using a Workday integration or an AI feature built into LinkedIn does not exempt you. The provider has one set of obligations, you as the deployer have another, and the two apply separately.

2. The chatbot “only provides information”

Under Article 50, since August 2, 2026, an AI chatbot on your website, whether a SaaS solution or a custom GPT, must inform visitors that they are interacting with AI. A tiny disclaimer at the bottom of the footer is not enough. The Regulation says this must be done “in a clear and distinguishable manner at the latest at the time of the first interaction.”

The same applies to any image, video, or text generated by artificial intelligence and used in your marketing communications. If you publish an AI-written article under your name or post a Midjourney-generated advertising image on Facebook, the content must be labeled under Article 50(4). The exception is narrow: content under editorial control that informs the public on matters of public interest.

3. AI literacy is something “we will explain one day”

Article 4, one of the most frequently overlooked provisions in the entire Regulation, has applied since February 2, 2025, and it obliges every company. Anyone who uses an AI system in their work must have a “sufficient level of AI literacy.” The Regulation requires providers and deployers to ensure this “to their best extent,” which in practice is proportionate to size: a two-person company is not expected to do the same as a company with five hundred employees.

But you need to document what you have done. An internal training session on the basics of using ChatGPT and a short policy setting out what is and is not allowed will cover this reasonably well. What a regulatory inspection will not accept is nothing. If an inspection in 2026 finds that your team has used AI every day for six months and nobody ever gave them any guidance, that is a compliance gap in itself.

What could getting it wrong cost? And the SME exception few people know about

The headline fines are eye-catching. Under Article 99(3), prohibited AI practices under Article 5 can attract a fine of up to EUR 35 million or 7% of the company’s total worldwide annual turnover, whichever is higher. Breaches of the rules for high-risk systems and transparency under Article 99(4) can attract EUR 15 million or 3%. Supplying false information to an authority can cost EUR 7.5 million or 1%. Hungarian Government Decree 344/2025 expresses these amounts in forints: up to HUF 13.3 billion for prohibited practices and HUF 5.7 billion for high-risk infringements.

For a company with HUF 100 million (≈EUR 263,000) in revenue, those figures are absurdly large. And this is where we get to a detail few people know, even though it is right there in the text of the Regulation.

Article 99(6) says that for SMEs and start-ups, each fine is capped at the lower of the two amounts. Not the higher amount, as it is for large companies. The percentage or the absolute euro amount, whichever is lower.

That changes the calculation. For a Hungarian company with annual revenue of HUF 300 million (~EUR 760,000), the maximum fine for a prohibited practice is 7% × EUR 760,000 ≈ EUR 53,000 (approximately HUF 21 million). Not the EUR 35 million quoted in the press. It is a serious amount, but not one that makes it impossible for the company to continue.

This does not mean you can sit back and relax. It means the real risk at your scale is realistic: manageable, plannable, not fatal. If the effective upper limit of the fine is 7% of your revenue, that is in the same order of magnitude as a serious tax fine or employment-law penalty. It deserves the same level of responsibility.

What to do now: a five-step quick audit

If you reviewed your company’s use of AI today, these five steps are the minimum. AI literacy and transparency are already mandatory, and you have until December 2, 2027 for the full high-risk package. Each step can be done in a day once you get started.

1. Create an AI inventory. List everything, from official company tools such as a Microsoft Copilot subscription, through “shadow AI” such as a colleague copying customer data into ChatGPT, to integrated features such as the “AI assistant” built into your CRM. You cannot comply with requirements for a system you do not even know you use.

2. Assign each one to one of the four categories above. The table above and Annex III really are enough for this. The vast majority will be limited or minimal risk. The one or two high-risk systems are where the work lies.

3. Check the provider’s documentation. From December 2, 2027, high-risk systems must bear CE marking and be registered in the EU database. If your vendor cannot answer questions about that, the silence speaks for itself.

4. Put your AI literacy policy in writing. One A4 page is enough. Set out what is and is not allowed, for example, do not copy customer data into a public AI system, and have the team review the basics once a year. Date it and get it signed.

5. Name the person responsible. You need one specific name. You do not need to create a separate position: it can be the managing director, the HR lead, or the compliance officer. But from the authority’s perspective, someone has to raise their hand.

You can complete these five steps yourself. Most of this is not legal work but documentation and organization. The law becomes complicated when you have to interpret the exception under Article 6(3) or classify an edge case. At that point, it is worth asking someone who has actually read the Regulation and knows how to interpret it.

Closing thought

The EU AI Act was not written only for large companies. Article 62 specifically provides support for SMEs: they receive priority access to regulatory sandboxes, reduced fees for conformity assessments, and targeted information. Hungary had to establish its regulatory sandbox by August 2, 2026. It is worth watching because this will be the place to test a new AI product legally and with a relatively low administrative burden.

The Regulation does not prohibit the use of AI. It prohibits using AI without human oversight, information, and documentation. That difference is manageable if you address it in time.

If you want to know which category your company’s current use of AI falls into and what concrete steps you should take before the December 2027 deadline, let us talk in a 30-minute AI Act readiness consultation. We founded Andronia with a legal background and build our AI systems from that starting point: for us, compliance is not a layer added afterward but the very first design decision.

This content is not legal advice. If you need to make a decision in a specific situation, ask us!


This article was published on the Andronia blog. Andronia helps Hungarian businesses grow with AI solutions that include compliance from the start, not as an afterthought. Read about our services here.

↑ top