Share it

Artificial intelligence has ceased to be an experimental technology and has become an increasingly common tool in small and medium-sized enterprises, which see these technologies as an opportunity to boost productivity and compete in an increasingly digital environment.

But this rapid adoption raises a question that goes beyond technology: are companies prepared to use artificial intelligence responsibly and in accordance with regulations?

This question has become particularly relevant because the European Artificial Intelligence Regulation (AI Act) has already entered its general application phase. Since August 2026, organisations have been operating under a regulatory framework that establishes specific obligations depending on the type of AI system, its purpose and the risks it may generate. Some provisions were already applicable before then, such as those relating to prohibited practices and AI literacy, while specific obligations for certain high-risk systems are subject to a later timetable.

The message for SMEs should be clear: it is not about stopping the use of AI, but about knowing how it is being used.

And this may be precisely one of the main challenges. While a large company may have departments specialising in technology, security, legal affairs or compliance, an SME can adopt a new AI tool in a matter of minutes. One employee uses a generative assistant to prepare a document, another automates a sales task and a third uses a tool to analyse customer information. Technology is advancing much faster than the internal procedures designed to control it.

For this reason, the first step towards the responsible use of AI should not be technological, but organisational: knowing what artificial intelligence the company uses and what it uses it for.

Having an inventory of AI tools and uses makes it possible to identify which systems are being used, who uses them, for what purpose, what information is entered into them and which provider is behind them. It also makes it possible to determine whether we are dealing with a merely auxiliary use or with a system that may have a significant impact on people, rights or business decisions.

This identification is particularly important because not all uses of AI present the same level of risk. The AI Act’s approach is precisely proportional and risk-based. It does not impose the same requirements on all systems and distinguishes between prohibited practices, high-risk systems, certain transparency obligations and other lower-risk uses.

For an SME, understanding this classification is essential. Using AI to generate a first draft of a text is not the same as using it to select candidates, evaluate employees or make decisions that may significantly affect people. In the latter cases, the legal and organisational implications can be much greater.

But even apparently simpler uses involve risks that are not always obvious. What happens to the personal data entered into an AI tool? Where is it stored? Can the provider use it for other purposes? What happens to the company’s confidential information? Who is responsible if the system generates incorrect information? How can it be ensured that AI-generated content does not infringe third-party rights or intellectual property rights?

These questions directly connect the AI Act with other traditional areas of regulatory compliance, such as the General Data Protection Regulation, information security, intellectual property, confidentiality and employment law. Artificial intelligence does not create a space outside existing legislation: it adds new obligations and new risks that must be integrated into the organisation’s overall compliance system.

Added to this is an issue that may seem minor, but is becoming increasingly important: people.

The AI Act establishes the obligation for providers and deployers to take measures to develop AI literacy among the people who use these systems on their behalf. This obligation has been in force since February 2025, and its supervision and enforcement began in August 2026. It is not simply a matter of teaching people how to use a tool, but of providing the knowledge necessary to understand its capabilities, limitations and risks depending on the context in which it is used.

This represents a significant change for companies. An AI usage policy cannot remain merely an internal document. It must be accompanied by training and clear criteria so that employees know what they can do, what information they can enter into a tool and when they should resort to human review.

Transparency is also taking on particular importance. Since 2 August 2026, the obligations under Article 50 of the AI Act have been applicable, which provide, among other aspects, for informing people when they interact directly with certain AI systems and establishing mechanisms to identify certain artificially generated or manipulated content.

For companies that generate content, use chatbots or incorporate AI into their customer and user interaction channels, this means reviewing processes and establishing clear criteria regarding when and how the use of artificial intelligence should be disclosed.

Therefore, the real challenge for SMEs does not consist solely of incorporating AI into their processes. It consists of incorporating governance into its use.

Governing AI means establishing responsibilities, identifying the systems being used, assessing their risks, defining internal policies, monitoring providers, protecting data, training people and establishing supervision and review mechanisms. And, above all, it means understanding that compliance does not end when a technological tool is purchased.

In fact, one of the most common mistakes may be to assume that, because a solution has been developed by a third party, all responsibility lies with the provider. The AI Act distinguishes between providers and deployers, and a company that uses an AI system under its authority may have obligations as a deployer, even if it did not develop the technology.

This makes it particularly advisable for SMEs to incorporate compliance criteria into the process of selecting AI tools itself. Before purchasing them, it is advisable to understand what the system does, what data it needs, what guarantees the provider offers and what controls it allows to be put in place. Afterwards, it will be necessary to periodically review whether the actual use remains consistent with the purpose for which it was introduced.

At first glance, regulation may seem like a new burden for organisations that already have to deal with numerous legal requirements. However, compliance with the AI Act can also become an opportunity to organise and professionalise the adoption of a technology that, in many cases, is already present in companies.

Because using AI responsibly does not mean using less AI. It means using it better.

SMEs that are able to understand their systems, identify their risks and establish clear rules will be able to take advantage of their benefits with greater security and confidence. And this confidence will become increasingly important for customers, employees, providers and business partners.

The challenge, therefore, is no longer to decide whether artificial intelligence will be part of the future of companies. It is already part of their present. The question is how we want to incorporate it.

The AI Act reminds us that innovation also involves taking responsibility. And that, with a technology capable of transforming the way we work, trust should not be the final outcome of the innovation process, but one of its starting conditions.

Because AI can make companies more agile, but only good governance will allow them to become safer, more responsible and more reliable as well.

Alfonso Corral Membrive
CEO of Conversia

Other articles

Data from the latest report “Global Entrepreneurship Monitor; “GEM” 2022-2023[1] indicate that Catalonia continues to lead entrepreneurial activity in Spain with a TEA of 6.9%. […]

The first European Union Artificial Intelligence Law known as the AI ​​Act has been a long time coming, but it is now a reality and, […]

Prof. Cecilio Angulo, Founder of IDEAI-UPC and President of the ACIA. In a digitized world, data is the new oil , but only a few […]