The EU AI Act, Regulation (EU) 2024/1689, classifies AI systems by risk; for most small businesses that only use AI tools, what mainly applies is the duty to ensure AI literacy among staff, transparency rules for chatbots and a few prohibitions. The duties take effect in stages. This article summarises what matters for you as an SME. It is not legal advice.
What does the EU AI Act regulate?
The AI Act has been in force since 1 August 2024 and applies to providers and deployers of AI systems whose output is used in the EU. It takes a risk-based approach: the greater the risk of a use for people, the stricter the duties. Providers develop or distribute AI systems. Deployers use them professionally, as you would ChatGPT or a recruitment tool. You can find the regulation on EUR-Lex and explanations on the European Commission's page.
Which risk tiers are there?
| Tier | Meaning | Examples | What applies |
|---|---|---|---|
| Unacceptable | Prohibited (Art. 5) | Manipulative techniques, scoring people by social behaviour, emotion recognition in the workplace (with exceptions) | May not be used |
| High | Sensitive areas (Art. 6, Annex III) | Recruitment, education, creditworthiness | Strict duties, such as human oversight, logs |
| Limited | Transparency duty (Art. 50) | Chatbots, AI-generated images and video | Label |
| Minimal | Everyday applications | Spam filters, writing aids | No special duties under the law |
General-purpose AI models, meaning the large language models, have their own duties for their providers. These do not fall on you as a user but on the model provider.
What applies to businesses that only use AI?
As a deployer you essentially have three tasks. First, AI literacy (Art. 4): you should ensure, to the best of your ability, that your staff have a sufficient understanding of AI. The regulation prescribes no particular training; a short, documented briefing with rules on data, checking and responsibility is a sensible start.
Second, transparency: if you use a chatbot, users must be able to tell that they are talking to an AI. Third, respect the prohibitions and avoid or carefully examine high-risk uses. Anyone using AI, for example, to pre-select applications is subject to strict deployer duties. For infringements, heavy fines are provided for, up to €35 million or 7 per cent of worldwide annual turnover for prohibited practices; for SMEs the lower amount applies in each case (Art. 99).
When does what apply?
The deadlines under the text of the regulation are staggered.
| Date | What applies |
|---|---|
| 1 August 2024 | Regulation enters into force |
| 2 February 2025 | Prohibited practices and AI literacy duty |
| 2 August 2025 | Duties for providers of general-purpose AI models, governance and penalty rules |
| 2 August 2026 | Most of the remaining rules, including transparency duties and high-risk systems under Annex III |
| 2 August 2027 | High-risk AI in regulated products (Annex I) |
What should you do now?
Begin with an inventory: which AI tools do you use, for what, and with which data? Assign each use to a risk tier. Most fall into the limited and minimal tiers. Set a short usage rule and document the briefing of your staff. How humans and machines complement each other is described in What is human in the loop?; on data protection, read Using ChatGPT in your business, GDPR-compliant.
- All AI tools in use and their purposes listed
- Each use assigned to a risk tier
- High-risk uses such as selecting applicants examined separately
- Chatbots made recognisable
- Staff briefing carried out and documented
- Usage rule on data, checking and responsibility set
- Deadlines and changes to the regulation monitored
Conclusion: literacy and transparency first
For most SMEs the AI Act mainly means diligence: knowing which AI runs in the house, briefing staff and labelling chatbots. Examine special cases such as recruitment closely and watch the deadlines. If you would like support with rollout and rules, see our AI automation service or describe your situation. This article is not legal advice.




