EU AI Act Info

Solutions · Startups and small companies

Under fifty people, GDPR and the AI Act still apply. NIS2 mostly does not.

Below the medium-sized ceiling NIS2's size gate usually keeps you out, but GDPR applies to every controller and the AI Act's literacy duty applies to every employer using AI. Buyers ask anyway, so a trust center pays for itself early.

Typical profile

Sector
Software or SaaS (not a listed digital provider)
Employees
Under 50
AI
Uses AI tools
Flags
None
  • Under 50 employees is below NIS2's size gate for most sectors.
  • GDPR applies regardless of size; the 72-hour breach clock is yours.
  • Using AI tools makes you a deployer: Article 4 literacy applies now.

Obligations to prove

8

Outside NIS2's size gate on this profile; GDPR and any AI Act duties still apply.

First statutory clock if something goes wrong: GDPR breach notification, 72 hours (GDPR Art 33(1)).

Computed by the platform's scope finder. A starting point, not a legal determination.

The modules that matter here

Start with these 8 obligations.

Sign up, confirm the scope in onboarding, connect your first system.

Start free →