The EU AI Act Explained for Small Businesses
By CodexierPublished 6 min read
The AI Act is the EU's product regulation for artificial intelligence, and it has produced a wave of compliance offers aimed at small companies. Most of them are unnecessary. If you use a chatbot on your website, an AI receptionist on the phone or ChatGPT for drafting, you are a deployer of limited-risk systems, and your obligations fit on one page. This guide shows which ones apply and when.
Provider or deployer: which one are you?
The distinction matters because the heavy duties in the Act, from risk management to conformity assessment, fall on providers. When you buy a chatbot, configure it with your own FAQ and put it on your site, the vendor is the provider and you are the deployer. You only move into provider territory if you substantially modify a system or sell it under your own name, which a company using an off-the-shelf tool does not do.
The risk tiers in plain language
The Act sorts AI systems into four tiers by what they are used for, not by how advanced the model is. The same language model can sit in different tiers depending on the job you give it.
| Tier | Typical examples | What a deployer must do |
|---|---|---|
| Prohibited | Social scoring, manipulative systems exploiting vulnerabilities, untargeted face scraping | Not use them at all |
| High risk | CV screening, credit decisions, access to essential services, safety components | Human oversight, use per instructions, log keeping, inform affected people, staff training |
| Limited risk | Chatbots, AI receptionists, generated images or text shown to the public | Tell people they are interacting with AI; label synthetic content where required |
| Minimal risk | Spam filters, internal drafting, spellcheck, most automation | Nothing specific under the Act |
GDPR continues to apply in every tier. The Act adds to it; it does not replace it.
The trap for a small company is the high-risk row. Using AI to rank job applicants or to decide who gets a payment plan pulls you into duties you probably do not want. Keep AI out of those decisions, or keep a human genuinely making them, and the rest of your automation stays in the two lowest tiers.
Transparency duties for chatbots
This is the obligation that applies to most of our customers. If a person interacts with an AI system, they must be informed of that, unless it is obvious from the context. In practice that means:
- A website chatbot introduces itself as an assistant or AI, in the first message, in the language of the site.
- An AI receptionist on the phone says so in its greeting before the caller starts explaining their errand.
- AI-generated images, audio or video published as if real carry a label; ordinary marketing drafts edited by a person do not.
- There is a way to reach a human, which is also what makes the automation trustworthy rather than a dead end.
None of this is expensive. It is a line in the greeting and a handover rule, both of which we configure as standard in an AI chatbot setup. The comparison with a plain FAQ page, which carries none of these duties, is in our chatbot versus FAQ guide.
Timeline of when rules apply
The Act entered into force in August 2024 and phases in over several years. The dates that matter for a deployer:
- February 2025: prohibited practices banned, and the general duty to ensure AI literacy among staff who operate AI systems applies.
- August 2025: obligations for providers of general-purpose models such as the large language models behind chatbots.
- August 2026: the bulk of the Act, including transparency duties for chatbots and most high-risk requirements.
- August 2027: remaining high-risk rules for AI embedded in regulated products.
The AI literacy duty is the one most small firms have missed. It does not require certification, only that people who use AI tools at work understand what the tools can and cannot do. A short internal session, documented, satisfies it, and combining it with your GDPR rule for ChatGPT at work saves a second meeting.
A short compliance checklist
For a company that deploys off-the-shelf AI in customer contact and internal work, this is the whole list:
- Inventory: which AI systems you use, from which vendor, for what purpose.
- Tier check: confirm none of them make or materially influence decisions about employment, credit, or access to essential services.
- Transparency: every public-facing chatbot or voice agent announces itself and offers a human route.
- Vendor documentation: keep the provider's instructions for use and its statement on which tier the system falls in.
- AI literacy: one recorded training session for staff who use the tools.
- GDPR: DPA in place, record of processing updated, retention set.
When you do not need to buy anything for this: if you use one or two vendor tools for limited-risk purposes, the checklist above is a morning's work and no consultant is required. What justifies an AI integration audit is a different problem: several tools, unclear ownership, or AI creeping into a decision that could be high risk. If you are unsure which situation you are in, a short call settles it faster than a compliance quote.
Frequently asked questions
Does the AI Act apply to a small company with ten employees?
Yes, but almost entirely as a deployer of limited or minimal-risk systems. There is no small-company exemption, yet the duties that apply at that level are transparency, staff AI literacy and not using AI for prohibited or high-risk purposes without the extra safeguards.
Is a customer chatbot high risk under the AI Act?
No. A chatbot answering questions about opening hours, orders or services is limited risk. The duty is to tell people they are talking to AI and to make a human reachable. It would only become high risk if it took decisions about, say, granting credit or filtering job applicants.
What is the AI literacy requirement?
Since February 2025 organisations must ensure staff who operate AI systems have a sufficient understanding of them. For a small firm that is a short, documented training on what the tools do, their limits and your internal rules. No certificate or external course is required.
Do we need to label AI-generated marketing text?
Text that a person has reviewed and edited before publication does not need a label. Synthetic images, audio or video presented as genuine, and content that could be mistaken for a real event or person, do. If in doubt, a plain note that an image is AI-generated costs nothing.
Want a straight answer on which tier your AI use falls in?
Describe the tools you use in a fifteen-minute call and we will tell you whether the checklist above is enough or whether something you run is closer to high risk than you think.
Book a free 15-minute call