
Artificial intelligence is no longer limited to global technology companies. Small firms, trades, agencies, online shops, professional practices and freelancers use AI every day. The good news: a business using ChatGPT for routine office work does not suddenly need a compliance department. It should not ignore the EU AI Act either.
What is the EU AI Act?
The EU AI Act, Regulation (EU) 2024/1689, governs the development, placing on the market and use of AI. Its approach is risk-based: the greater the potential impact on people, safety or fundamental rights, the more extensive the requirements.
Not every AI use is high-risk. Drafting a product description with ChatGPT differs considerably from automatically assessing job applicants.
Does the EU AI Act apply to small businesses?
Yes. There is no blanket exemption for SMEs or self-employed people. Under the EU definition, an SME generally has fewer than 250 employees and annual turnover of no more than €50 million or a balance-sheet total of no more than €43 million. The Act nevertheless provides support, regulatory sandboxes and simplified procedures, and business size matters when penalties are assessed.
What role does your business have?
1. You use a ready-made AI system
A business using ChatGPT, Microsoft Copilot, Google Gemini, a translator, image generator, chatbot or an AI feature in existing software is usually a deployer. This is the normal case for many SMEs.
2. You develop or market an AI solution
A company developing a system, selling it under its own name, substantially modifying it or repurposing it for a new high-risk use may assume provider obligations. Those can be much more extensive.
Can businesses still use ChatGPT?
Generally, yes. The Act does not prohibit using generative AI to draft text and emails, summarise, translate, brainstorm or prepare code. Use should be organised around approved tools, permitted data, human review and clear responsibility.
Use ChatGPT with clear, verifiable prompts (Read article)
AI literacy: an obligation without a standard certificate
Article 4 has applied since February 2, 2025. Following the AI Omnibus amendment, providers and deployers must take measures to support the development of AI literacy among staff and other people operating AI on their behalf. They do not have to guarantee a specific level for every individual. Compare training evidence and German certification routes in 2026 (Read article)
The approach may be contextual and risk-based. Someone occasionally drafting advertising copy needs different guidance from a person using AI output in employment decisions. Article 4 does not prescribe a standard certificate or specific governance structure; keeping an internal record of training and guidance is sensible.
A practical briefing can cover:
- Which AI systems are approved?
- Which company and personal data may be entered?
- Why can AI produce false information?
- When is human review required?
- Who is accountable for published content?
- Which uses are prohibited or require approval?
Review AI output and recognise risky recommendations (Read article)
Matching product · German-language edition
AI Without the Headache
This German-language practical guide helps small businesses introduce AI with internal rules, risk assessment, 50 prompt templates and a 21-day plan.
An AI inventory is especially useful
Even though ordinary AI use does not automatically create a universal register duty, businesses should know what they use. This also exposes shadow AI.
| AI system | Use | Owner | Data | Review |
|---|---|---|---|---|
| ChatGPT | Marketing copy | Marketing | No customer data | Low |
| Copilot | Summaries | Administration | Internal documents | Check privacy |
| AI chatbot | Customer service | Support | Customer requests | Check transparency |
| Recruitment AI | Selection | HR | Applicant data | Check high-risk status |
Take special care with recruitment and employment
AI used for recruitment, selection or certain employment decisions may fall within Annex III. High-risk systems face stricter requirements for risk management, documentation, transparency and human oversight. Under the 2026 AI Omnibus, the core rules for Annex III systems apply from December 2, 2027; those for certain product-related Annex I systems from August 2, 2028.
Must AI-generated content be labelled?
It depends. Article 50 contains several transparency duties. In the relevant circumstances, people must be able to recognise that they are interacting with AI. Deployers must disclose certain deepfakes as artificially generated or manipulated. Rules also cover certain AI-generated public-interest text. This does not mean that every ordinary AI-assisted product description needs a blanket “made with ChatGPT” label.
The AI Act does not replace the GDPR
The Act does not make personal-data processing automatically lawful. Customer databases, patient records, applicant files, confidential emails and contract repositories should not be pasted into a public AI service without assessment. Legal basis, purpose, data minimisation, processing agreements, international transfers and trade-secret protection remain separate questions.
Evaluate local AI as a more privacy-conscious deployment option (Read article)
Which uses deserve particular attention?
- Employment: assessing applicants or workers.
- Credit: evaluating the creditworthiness of natural persons.
- Biometrics: identifying or categorising people by biometric traits.
- Critical infrastructure: safety-relevant control functions.
- Medical and safety-critical products: AI as a product or safety component.
The more strongly AI influences decisions with serious effects on people, the more carefully its risk category should be assessed.
Timeline: what applies in 2026?
- Since February 2, 2025: definitions, prohibited practices and AI literacy.
- Since August 2, 2025: governance and general-purpose AI model duties.
- Since August 2, 2026: many further provisions, including major transparency and enforcement rules.
- From December 2, 2026: additional prohibitions introduced by the AI Omnibus and certain transitional deadlines.
- From December 2, 2027: core high-risk rules for Annex III.
- From August 2, 2028: high-risk rules for certain Annex I products.
What penalties can apply?
The framework provides, in principle, for fines of up to €35 million or 7% of worldwide annual turnover for prohibited practices, and up to €15 million or 3% for certain other infringements. For SMEs, the lower of the absolute maximum and percentage applies. Sanctions must be proportionate and account for size, seriousness, responsibility and organisational measures.
EU AI Act checklist for small businesses
- Inventory systems: include approved tools and potential shadow AI.
- Document purpose: record vendor, users, data and the system’s role in decisions.
- Assess risk: separate routine assistance from decisions with serious effects.
- Create an AI policy: define approved services, forbidden data, review and labelling.
- Build literacy: match guidance to actual use and risk.
- Document measures: record dates, attendees, topics and policies.
- Review privacy separately: especially for customer, employee, applicant and health data.
- Screen new systems: ask not just “Is it useful?” but “May and should we use it this way?”
Does a small business need an AI officer?
Not automatically. Article 4 does not mandate a particular governance structure. Someone should still own the topic—management, IT, privacy, information security or compliance. Clear responsibility matters more than the job title.
The simplest AI strategy for an SME
AI may assist, but people remain responsible.
- Do not enter confidential data without control.
- Review outputs before important decisions.
- Inform staff about limitations and risks.
- Document and assess critical uses.
- Assign clear responsibility.
The AI Act is not only bureaucracy
A clear strategy can reduce privacy risk, prevent shadow AI, protect trade secrets, improve output quality and build trust. For a ten-person business, a few clear rules may be more valuable than a 200-page manual.
FAQ: EU AI Act for small businesses
Does the EU AI Act apply to self-employed people?
Yes, when they professionally deploy or provide AI systems. There is no blanket exemption based only on size.
Can my business still use ChatGPT?
Yes. Ordinary generative-AI use is not prohibited, but privacy, confidential information, output review and AI literacy need attention.
Must I train employees?
Providers and deployers must support context-appropriate AI literacy. No standard course, certificate or guaranteed individual level is prescribed.
Must every AI-generated text be labelled?
No. Article 50 has specific transparency duties, including for certain deepfakes and public-interest text, but no blanket label for all AI-assisted writing.
Must I maintain an AI inventory?
There is no universal inventory duty for every ordinary use. An internal overview is nevertheless strongly recommended.
Is recruitment AI high-risk?
Systems for recruitment, candidate selection and certain employment decisions may be high-risk and need careful assessment.
When do high-risk rules apply?
For Annex III systems from December 2, 2027; for certain product-related Annex I systems from August 2, 2028.
Conclusion: act now without panicking
For most SMEs, compliance starts with five steps: inventory AI, assess risk, set rules, inform staff and assign responsibility. The key question is not “Do we use AI?” but “Which AI do we use—and what do we let it decide?”
Sources and further information
Editorial status: August 14, 2026. Primary sources: Regulation (EU) 2024/1689, European Commission: Navigating the AI Act, European Commission: AI Literacy FAQ, and European Commission: AI Omnibus enters into force. Businesses should monitor new guidance, especially for high-risk use cases.