From how many employees does the EU AI Act apply?
No article says you are exempt below fifty or two hundred and fifty people. Size counts in exactly three places, and none of them is an exemption.
This is the question we get asked most, and the answer surprises almost everyone: there is no employee threshold in the EU AI Act. No article says you are exempt below ten, fifty or two hundred and fifty people. The regulation does not look at how big you are, but at what you do with AI and what risk that creates.
That is the bad news and the good news at once. The bad: you cannot escape the law by being small. The good: the heaviest obligations only apply to a handful of use cases, and the odds are your company runs none of them. So the question is not how many people are on the payroll, but which systems are running and what your role is.
This page answers the literal question, shows the three places where company size genuinely counts, and explains which number matters instead. We covered the deadlines and the provider versus deployer distinction in a separate piece; we are not repeating that here.
Where the misunderstanding comes from
The confusion almost always traces back to the GDPR. That law does contain a number. Article 30(5) says organisations with fewer than 250 employees do not have to keep a record of processing activities. It is the one well-known threshold in European digital law, and it has lodged in many boardrooms as a general rule: below 250 you are off the hook.
Even within the GDPR that is wrong. The exemption falls away as soon as the processing is likely to result in a risk to the rights and freedoms of data subjects, as soon as it is not occasional, or as soon as it involves special categories of personal data. An employer holding personnel files meets at least one of those three by default, and usually two. In practice the exemption is far narrower than the number suggests.
The AI Act did not copy that construction. There is no Article 30(5) for AI. Anyone applying GDPR logic to the AI Act arrives at a conclusion the text does not support.
Reading a CV at a table. AI used in recruitment and selection is high risk under Annex III, at any company size.
What does determine your obligations
Two questions, in this order, and per system.
What is your role? If you build the system or place it on the market under your own name, you are a provider and you carry the bulk of the obligations. If you use a vendor's system inside your own organisation, you are a deployer and your package is much lighter. That same division applies to a company of twenty-five people and to a listed corporation. There is no scale in it.
Which risk class does it fall into? The regulation has four levels: prohibited practices, high risk, systems carrying a transparency duty, and everything else, for which nothing special applies. By far the most applications a normal company runs, from a text generator to a stock forecaster, sit in that last category.
For our own field it is less relaxed. AI used in recruitment and selection, in evaluating applications, or in decisions on promotion and termination, is listed in Annex III and therefore high risk. That applies to a thirty-person recruitment agency exactly as hard as to a multinational. The date has moved, though: since the Digital Omnibus entered into force in July 2026, the main obligations for this category apply from 2 December 2027 instead of 2 August 2026.
The only hard threshold in the law is about compute
There is a hard line in the AI Act, but it has nothing to do with staff. Article 51(2) says a general-purpose AI model is presumed to have high-impact capabilities once the cumulative compute used for its training exceeds ten to the power of twenty-five floating point operations. Above that line, heavier systemic-risk obligations kick in.
That is the kind of threshold the legislator did choose: a measure of what a system can do, not of how large the organisation behind it is. In practice it touches perhaps a dozen parties worldwide, and almost certainly not you. But it shows how the regulation thinks. Where the law draws a line, it draws it at risk, not at the size of the undertaking.
You see the same pattern in the risk classes. Whether a system is high risk depends on what it is used for and who it affects, not on who is using it. A CV screener assessing a hundred applicants a year falls in the same category as one assessing a hundred thousand.
The three places where company size genuinely counts
There are three provisions where SMEs are named separately. None of them is an exemption. All three are about how you do something, never about whether you have to.
Article 99(6), the fine. Where large undertakings face the higher of a fixed amount or a percentage of worldwide annual turnover, small and medium-sized enterprises face the lower of those two. For the heaviest category the figures are 35 million euro or 7 per cent. An SME with forty million in turnover is then looking at 2.8 million instead of 35 million. Still an amount that topples an organisation, but the difference is a factor of twelve.
Article 11(1), the technical documentation. If you are the provider of a high-risk system, you have to keep an extensive technical file as set out in Annex IV. SMEs, including start-ups, may supply those elements in a simplified manner, and the European Commission has to draw up a form aimed at small and micro enterprises. Notified bodies are obliged to accept it. This only touches you if you build.
Article 62, access and cost. Member States must give SMEs priority access to the AI regulatory sandboxes, organise targeted awareness and training, keep dedicated channels open for questions, and enable participation in standardisation. On top of that, conformity assessment fees have to come down for smaller companies, proportionate to their size. It is the only place where being small saves you money rather than work.
Signing at the table. Who owns your shares decides whether you count as an SME.
The number that counts is not on your payroll
This is where it goes wrong in practice. Those three provisions apply to SMEs, and most Dutch companies of fifty to three hundred and fifty people assume without thinking that they qualify. Often they do not.
The AI Act uses the official European SME definition from Recommendation 2003/361/EC. That sets two conditions at once. You have fewer than 250 staff, and your annual turnover is at most 50 million euro or your balance sheet total at most 43 million. You have to meet both, not one.
Then comes the part almost nobody factors in. You do not only count yourself. If another company holds between 25 and 50 per cent of your capital or voting rights, that is a partner enterprise and you add their figures pro rata. If a party sits above 50 per cent, or otherwise has a dominant influence, it is a linked enterprise and their figures count in full.
That changes the outcome more often than you would expect. An agency of 180 people with 30 million in turnover is comfortably an SME on its own. Have that same agency 60 per cent owned by an investment firm with a portfolio totalling 900 employees and 200 million in turnover, and the count crosses both ceilings. Then you are not an SME within the meaning of the regulation. Then a fine follows the higher of amount and percentage rather than the lower, and that is exactly the situation where it matters.
If there is a private equity firm, a holding company or a foreign parent in your structure, this is the one calculation in this whole piece you genuinely have to do.
Do the sum in five minutes
You need three numbers about yourself and the same three about every shareholder above 25 per cent: headcount in annual work units, annual turnover and balance sheet total. Use the last approved financial year.
Add up what has to be added, then hold the result against two ceilings. Fewer than 250 staff is the first condition. At most 50 million in turnover or at most 43 million in balance sheet total is the second. Fail either one and you are not an SME.
One nuance that reassures people, and it is correct: a single year over the line does not change your status. The definition works on two consecutive financial years. Cross 250 for one year and drop back, and you stay an SME. That gives room during a growth spurt, but it is no escape route in an acquisition; that changes your structure immediately and permanently.
What already applies, whatever your size
The table below is the entire article in one image. The right-hand column reads the same all the way down.
| Obligation | Applies from | From how many employees |
|---|---|---|
| Prohibited practices (Article 5) | 2 February 2025 | 1 |
| AI literacy (Article 4) | 2 February 2025 | 1 |
| Obligations for GPAI models | 2 August 2025 | 1, only if you offer a model yourself |
| Supervisory fining powers (Article 99) | 2 August 2025 | 1, with the SME rule in paragraph 6 |
| Transparency (Article 50) | 2 August 2026 | 1 |
| Marking AI content for existing systems | 2 December 2026 | 1 |
| High risk under Annex III, including recruitment | 2 December 2027 | 1 |
| High risk in regulated products, Annex I | 2 August 2028 | 1 |
A marker on a calendar. The dates shifted; the scope did not.
What the Omnibus did not change here
For many companies the Digital Omnibus of July 2026 was the moment they concluded the AI Act had been relaxed. That holds for the dates. It does not hold for the scope.
What moved were the deadlines. The main obligations for the Annex III high-risk category went from 2 August 2026 to 2 December 2027, sixteen months later. For high risk in regulated products, Annex I, it became a year: from 2 August 2027 to 2 August 2028. The marking duty for AI content in systems already on the market moved to 2 December 2026.
What did not change is precisely the subject of this page. No size-based exemption was added, not for registration, not for technical documentation, not for impact assessment. The regulation stayed risk-based. Anyone who read the Omnibus as the signal that small companies are now outside it drew the wrong conclusion from good news.
What to do instead of counting
Four steps, and the first matters most by a distance.
Make an inventory. Write down which AI systems are running in your organisation, including the tools departments bought themselves without involving IT. In the companies where we do this, consistently more surfaces than the board expected.
Determine your role per system. Provider or deployer. Watch the trap: buy a system, put your own brand on it or change its intended purpose, and you become the provider with every duty attached.
Test against Article 5. The prohibitions are absolute and have applied since February 2025. The two that actually turn up in ordinary companies are emotion recognition in the workplace and untargeted scraping of facial images.
Record your AI literacy effort. Who uses which system, what those people have been told, and when. There is more on this on our page about AI literacy, and on how to record it on the page about AI policy.
Three ways this goes wrong
"We are too small." The most common one, and there is no basis for it in the text. A company of eight running emotion recognition in job interviews breaks exactly the same provision as a company of eight thousand.
"Our vendor handles it." Partly true. The heavy obligations sit with the provider, but the transparency duty, the literacy duty and the prohibitions stay yours. You cannot contract them away.
"We are an SME, so we pay the low fine." Only if you actually are one under the European definition, shareholders' figures included. Do the sum before you count on it.
About this page
Outdated legal content does more harm than none. This is the state of play on 5 August 2026, and every claim carries the source below where you can check it yourself. The Digital Omnibus is not yet two weeks old and the Dutch implementation has not settled. Check the dates again before you base a decision on them, and put your own situation to a lawyer.
Frequently asked questions
Sources
- AI Act artikel 99, lid 6: boetes voor kleine en middelgrote ondernemingen— artificialintelligenceact.eu ↗
- AI Act artikel 62: maatregelen voor het mkb, waaronder voorrang bij testomgevingen— artificialintelligenceact.eu ↗
- AI Act artikel 11, lid 1: vereenvoudigde technische documentatie voor het mkb— artificialintelligenceact.eu ↗
- Verordening (EU) 2026/1744, de Digital Omnibus, volledige tekst op EUR-Lex— eur-lex.europa.eu ↗
- Aanbeveling 2003/361/EG: de officiele Europese definitie van het mkb— eur-lex.europa.eu ↗
- Europese Commissie: mkb-definitie, drempels en verbonden ondernemingen— single-market-economy.ec.europa.eu ↗
- AVG artikel 30, lid 5: de uitzondering onder 250 medewerkers en de drie voorwaarden— gdpr-info.eu ↗
Tell us what you need.
We respond within 24 hours, from a real human.
Get in touch

