The EU AI Act for small businesses: what applies to you

What the AI Act means for a small business using AI tools rather than building them, which obligations attach and when.

4 minread 868words last updated

The short answer

The AI Act regulates artificial intelligence by role and by risk. The roles that matter most are provider, whoever develops an AI system and places it on the market under their own name, and deployer, whoever uses an AI system under their own authority. Almost every small business is a deployer: you use assistants, automation platforms and AI features inside software you already buy. The obligations are then concentrated by risk. Certain practices are prohibited outright. High-risk uses, which include employment and worker management and access to essential services, carry substantial obligations for both providers and deployers. Limited-risk uses carry transparency obligations, principally telling people when they are interacting with an AI system and marking generated content. Everything else is minimal risk with no specific obligations under the Act. Timing is phased: prohibitions and the AI literacy obligation applied from 2 February 2025, general-purpose model rules and governance from 2 August 2025, most high-risk rules from 2 August 2026 and a further tranche in 2027. Confirm current dates and national implementation before relying on them.

What applies to a deployer

SituationObligation
Any use of AI in the businessEnsure staff involved have sufficient AI literacy for their role
Any useDo not engage in prohibited practices
Chat, voice or other interaction with peopleYour supplier must design the system to disclose this under Article 50(1); check that it does, and say so yourself where it is not obvious
Publishing generated or manipulated contentMark or disclose it where required
Emotion recognition or biometric categorisationInform the people exposed; strict limits apply
High-risk use, such as recruitment or access to servicesUse according to instructions, ensure human oversight, monitor, keep logs, inform affected workers, cooperate with authorities
Rebranding or substantially modifying a systemYou may become a provider, with far heavier obligations
Minimal-risk uses: drafting, summarising, classification, automationNo specific AI Act obligations; data protection still applies

A proportionate response

  1. List your AI uses, including the features inside software you already pay for.
  2. Classify each: prohibited, high-risk, limited-risk transparency, or minimal.
  3. Stop anything prohibited immediately and check the list rather than assuming.
  4. Add disclosure where people interact with AI or receive generated content.
  5. Train your staff and record it, satisfying the literacy obligation.
  6. For any high-risk use, follow the deployer obligations properly: instructions, human oversight, monitoring, logs, information to affected people; take advice.
  7. Avoid becoming a provider unintentionally by rebranding or substantially modifying systems.
  8. Document the classification with dates, which is your evidence.
  9. Review as phases take effect and as national implementation develops.

What businesses find

Running the classification exercise usually shows that almost everything is minimal risk: drafting, summarising, classification, extraction, scheduling and automation. The obligations that attach are the disclosure where customers interact with AI, and staff literacy. One or two uses, typically in recruitment or in decisions about customers, sit in a higher category and need either proper treatment or a decision not to use AI there. That is a manageable outcome, and the value of the exercise is knowing which is which rather than guessing.

What this means for you

As a deployer, your AI Act obligations are ensuring staff AI literacy, avoiding prohibited practices, disclosing under Article 50(3) and 50(4) where they apply, and treating any high-risk use, recruitment and access to services especially, with the full deployer requirements. The disclosure that a person is talking to an AI system is the provider’s duty under Article 50(1), so check it rather than assume it. Note also Article 25(1)(c): repurposing an ordinary system, including a general-purpose one, for a high-risk use makes you its provider, with all the provider obligations of Article 16. Classify your uses, document the classification, train your staff and take advice on anything high-risk. The phase dates are set in Article 113. This is general information rather than legal advice.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Are we a provider or a deployer?

A deployer, if you use AI systems built by others under your own authority, which covers almost every small business using assistants, automation tools and platform features. You can become a provider without intending to, for example by putting your own name on a system, substantially modifying a high-risk system, or repurposing one for a high-risk use. That reclassification brings far heavier obligations, which is a reason to be careful about how you present AI features you did not build.

When do the obligations apply?

In phases. The prohibitions on certain practices and the obligation to ensure AI literacy among staff applied from 2 February 2025. Obligations for general-purpose AI models and governance provisions followed on 2 August 2025. The bulk of the high-risk system rules apply from 2 August 2026, with a further phase to 2 August 2027 for high-risk systems that are components of regulated products. Check the current national implementation and any updates before relying on a date.

What do we actually have to do?

For a typical small business: make sure staff using AI understand it, avoid any prohibited practice, and keep human decisions on anything significant about a person. Telling people they are interacting with an AI system is the provider's duty under Article 50(1); as a deployer you check that your supplier does it. Your own duties, under Article 50(3) and 50(4), cover emotion recognition, biometric categorisation, deep fakes and AI-generated text published to inform the public. For a high-risk purpose such as recruitment, the deployer obligations are substantial.

Sources

  1. European Commission: AI Act (accessed 2026-09-12)
  2. EUR-Lex: Regulation (EU) 2024/1689 (Artificial Intelligence Act) (accessed 2026-09-12)