Phase 2: In effect since August 2, 2025
The Phase 2 obligations of the EU AI Act came into effect on August 2, 2025, creating significant compliance requirements for European SMEs that use AI systems. Most SMEs are not yet aware of these requirements.
Critical Warning
Organizations using ChatGPT, Copilot, Claude, or Gemini face fines of €35 million or 7% of global annual revenue – whichever amount is higher.
Two Primary Requirements
1. Transparency Obligations for GPAI Providers
- Technical documentation on training processes and model limitations
- Disclosure of training data summaries to identify potential biases
- Documentation of copyright compliance procedures
- Publication of contact information for regulatory inquiries
2. Reporting and Risk Obligations
Organizations deploying AI models with systemic risk must notify EU authorities.
Three Practical Scenarios
Scenario 1: Customer Service Chatbots
Requires disclosure to customers, documentation practices, and governance structures with human oversight protocols.
Scenario 2: Recruiting AI (High Risk)
Requires risk assessments, mandatory human review of decisions, candidate transparency, and detailed audit trails with decision justifications.
Scenario 3: Business Analytics (Lower Risk)
Requires system documentation, understanding of training data, and human verification prior to implementation.
Compliance Timeline
- By December 2025: Inventory of all AI systems including users, applications and risk classifications
- By February 2026: Establish governance structure, appoint AI officer, develop usage policies
- By March 2026: Conduct team training, create documentation
- Ongoing: Document all systems, identify risks, record compliance measures
Penalty Structure
- Prohibited practices: €35 million or 7% of global annual turnover
- High-risk systems non-compliance: €15 million or 3% of annual turnover
- Transparency violations: €7.5 million or 1% of annual turnover
Example: An SME with €10 million turnover risks €100,000 minimum penalties for 1% violations.
Conclusion
The regulation promotes transparent, safe and ethical AI implementation. Responsible SMEs that adequately document their practices will face minimal compliance challenges. Non-compliance results from failing to document systems and address inherent risks such as discrimination or data protection violations.

