The first distinction to grasp is between provider and deployer. The provider develops and places an AI system on the market; the deployer uses it in their own activity. Most SMEs are deployers: they use tools built by others. The regulation's heaviest obligations — technical documentation, risk management, product conformity — fall on providers. The deployer's job is mainly to use the system according to the instructions, with adequate human oversight.
The second key concept is the risk pyramid. Prohibited practices (manipulation, social scoring) don't concern an SME's typical operations. High-risk systems touch specific areas — recruitment, access to credit, critical infrastructure — and there the obligations really do grow. Most everyday commercial uses, such as customer support and marketing, instead fall into the limited or minimal risk tiers, where the central obligation is transparency: people must know when they are interacting with an AI.
What to do in practice, today: map where you already use AI in your business; check that your tools disclose their AI nature in conversations with customers; choose vendors able to give you documentation and traceability — an audit trail of agent actions helps here too; train the people who use these tools, because staff AI literacy is among the first obligations already in force.
Disclaimer: the regulation's deadlines and application details are evolving, and your specific case may have particularities. For decisions with legal impact, consult a qualified professional.