TL;DR: The EU AI Act's main obligations take effect in August 2026. For most small businesses the practical impact is limited, though not zero. This guide covers which provisions apply to typical SMB operations, what you need to document, what the penalties are, and where it is safe to wait. Plain English, written for people who run businesses rather than compliance teams.
The EU AI Act is the first law to regulate AI across the board. It entered into force in August 2024, and its obligations are rolling out in phases through 2026 and 2027. If your business operates in the EU, or sells to EU customers, parts of it apply to you.
Most of the coverage focuses on large enterprises and AI developers. Very little is written for the operations manager at a 50-person company who uses a few AI tools and wants to know what they actually have to do.
This guide fills that gap. It is written for small business operators.
Important disclaimer: This is educational content, not legal advice. For specific compliance questions affecting your business, consult a qualified legal professional familiar with AI regulation.
First: what the AI Act actually regulates
The AI Act is a risk-based framework. It regulates AI systems by the risk they pose, not by the technology they use. That matters, because it means:
- Most AI tools used by small businesses fall into low-risk or minimal-risk categories with minimal obligations.
- A small number of AI applications carry significant obligations regardless of company size.
- "We are a small company" is not a compliance exemption.
The Act sorts AI systems into four tiers:
| Risk Tier | What It Covers | Your Obligations |
|---|---|---|
| Unacceptable (banned) | Social scoring, subliminal manipulation, real-time biometric surveillance | Prohibited entirely |
| High risk | Hiring, credit scoring, healthcare, critical infrastructure | Conformity assessments, documentation, human oversight, registration |
| Limited risk | Chatbots, deepfakes | Transparency: users must know they interact with AI |
| Minimal risk | Spam filters, recommendations, most business automation | None under the Act |
For most small businesses using AI on internal work like document processing, email drafting, scheduling, and reporting, you sit in the minimal risk tier with no specific obligations under the Act.
When it gets more complicated: are you a deployer?
The Act separates providers (companies that build AI systems) from deployers (companies that use them). Most small businesses are deployers.
As a deployer your obligations are lighter than a provider's, but they are real. Under the high-risk provisions, deployers must:
- Use AI systems in line with the provider's instructions
- Keep human oversight over AI decisions
- Keep logs of high-risk AI system use
- Report serious incidents to the relevant national authority
When does this apply to you? When you deploy an AI system that counts as high-risk. For small businesses, the high-risk categories that come up most often are:
- Recruitment and HR: AI tools that screen CVs, schedule interviews, or evaluate candidates
- Credit and financial assessment: AI tools that help judge the creditworthiness of clients or partners
- Customer profiling: AI used to make consequential decisions about individual customers
If you use AI-assisted hiring, credit scoring, or automated customer profiling, check whether those tools are high-risk under the Act and whether your provider has done the required conformity assessments.
The transparency obligations that affect everyone
Even minimal-risk AI carries transparency obligations once it interacts with people:
Chatbots and AI assistants: If a chatbot on your site talks to customers, those customers have to be told they are dealing with an AI. It does not need to be in large letters, but it does need to be clear and shown before the conversation starts.
AI-generated content: Deepfakes and AI-generated synthetic media must be labelled. This covers marketing content, not only news media.
Emotion recognition: If you use systems that read emotional states (now common in customer-experience platforms), you have to disclose it.
For most SMBs the practical step is simple: label any customer-facing AI clearly as AI-assisted or AI-generated.