EU AI Act for Small Business: What You Must Do

Photo: Sora Shimazaki / Pexels
Key takeaways
- If your business, staff or output reach the EU, EU AI Act compliance can apply to you, even based elsewhere.
- Most small businesses are 'deployers' of tools like ChatGPT, not 'providers' of AI systems - a much lighter duty set.
- The AI-literacy duty under Article 4 has applied since 2 February 2025.
- Four risk tiers exist; almost everything a small business does falls into 'limited' or 'minimal' risk.
- A written AI usage policy plus a short staff briefing covers most of the realistic first-step obligations.
The EU AI Act is the world's first comprehensive AI law, and the headlines about it read like it's aimed squarely at you. For a small business that simply uses AI tools, rather than building high-risk AI systems from scratch, eu ai act compliance is more manageable than the coverage suggests. The Act sorts obligations by how risky your use of AI actually is, and almost nothing a typical small team does lands in the heaviest tier. This guide covers who the Act actually reaches, what a small business realistically has to do, and where you can stop worrying and get back to work.
Does it apply to you?
If your business, or the output it produces, reaches the EU - EU customers, EU-based staff using AI on your behalf, or products sold into the EU market - then yes, the Act can apply, even if your company is headquartered outside Europe entirely. Geography of incorporation doesn't exempt you; geography of impact does the reaching. The full consolidated text of the Act defines this scope precisely, but the short version above covers the vast majority of small-business cases.
Does the Act apply if you're based outside the EU?
It can, and this catches people out. The Act follows effect, not address: a US-based agency with a handful of EU clients, or a UK company with EU-based remote staff, can fall within scope for exactly the same reasons an EU-headquartered company would. The test is whether AI output touches the EU market or EU people, not where your office happens to be. UK businesses in particular sometimes assume Brexit removed them from scope entirely; it removed direct jurisdiction, not the effect-based reach that catches any business selling into the bloc.
You're probably a deployer, not a provider
The Act splits obligations between 'providers,' who build and place AI systems on the market, and 'deployers,' who use AI systems built by someone else under their own authority. Most small teams are deployers of general tools like ChatGPT, Copilot or Claude, so the heaviest provider-level duties - technical documentation, conformity assessments, registration - simply don't apply. The practical deployer duties are narrower: don't use banned practices, ensure basic AI literacy among staff, and be transparent about AI involvement where it's required. Getting this distinction right early saves a lot of wasted reading, since most Act commentary online is written for providers, not for the far larger group of businesses just using the tools. You only become a provider if you take an existing model and substantially modify or rebrand it as your own product, which is a step most small businesses never take.
The AI-literacy duty, in plain terms
Since 2 February 2025, Article 4 has required providers and deployers to ensure staff have a sufficient level of AI literacy for their role. In practice, that doesn't mean a certification course. A written AI usage policy, the same kind covered in our guide on how to write one, plus a short briefing is the simplest way to evidence it, because it leaves you with two things an auditor or regulator would actually look for: a document, and a record that people read it.
What happens if you ignore it?
For a small business using general-purpose tools, the realistic near-term risk isn't a dramatic enforcement action; it's the same gap that shows up around any missing policy. A customer or partner asks how you meet EU AI Act obligations and you have no answer. An enterprise deal stalls in security review over a question you could have pre-empted with one document. Penalties under the Act scale with severity and company size, and they exist mainly for the practices the Act bans outright or for high-risk systems handled carelessly, not for a small team that simply hasn't written a policy yet. Still, 'we hadn't got round to it' isn't a great line in a security questionnaire.
Banned practices you almost certainly don't do
A short list of practices is banned outright regardless of company size: manipulative AI that exploits vulnerable groups, social scoring by public authorities, and certain uses of biometric categorisation. Worth a gut-check against your own use cases, but for a business using AI to draft emails, summarise documents or generate marketing copy, none of this applies, and you can move on without a second thought. This list exists mainly to stop the worst, most invasive uses of AI; it isn't aimed at day-to-day office work.
Transparency: telling people they're dealing with AI
Where AI generates content people might mistake for human-made, or where someone is interacting with an AI system directly, the Act expects disclosure. In practice that's usually a line on AI-generated marketing copy, or a note that a support chatbot is automated rather than staffed by a person. It's a small addition, not a redesign of how you work, and it doubles as good customer-trust practice regardless of what the law technically requires.
What this looks like for a small team
A twelve-person e-commerce business selling into Germany and France assumed the EU AI Act was someone else's problem, since they don't build AI and aren't based in the EU. Then a German wholesale partner's procurement team asked, directly, how the business met its AI-literacy obligations under Article 4. The honest answer at the time was that nobody had thought about it, and the deal stalled for a week while someone scrambled to find out what was actually required. The fix, once they looked into it, was small: a written policy covering the AI tools the team used for product descriptions and customer replies, a fifteen-minute team briefing recorded for anyone who missed it, and a line disclosing that some marketing copy was AI-assisted. The partnership went ahead, and the same document now gets reused for every new EU partner who asks.
What to do this quarter
Write an AI usage policy, keep a register of the AI tools your team uses, and make sure anyone using AI understands the basics covered above. That's the realistic scope of first steps for a small business, and none of it requires a lawyer on retainer or a compliance hire to get moving. For the fuller detail, including how risk tiers are defined, see our EU AI Act framework guide, and check our wider notes on what AI governance actually involves if you're starting from scratch.
| Risk category | What it covers | Example | What deployers must do |
|---|---|---|---|
| Unacceptable risk | Practices considered a clear threat to rights or safety | Social scoring, manipulative AI targeting vulnerable groups | Banned outright - do not deploy |
| High-risk | AI used in areas like employment, credit or law enforcement | AI screening job applicants or credit applications | Human oversight, record-keeping, extra due diligence |
| Limited risk | AI that interacts with people or generates content | Chatbots, AI-generated marketing copy | Disclose that people are interacting with or viewing AI output |
| Minimal risk | Most everyday AI tools | Spam filters, AI writing assistants used internally | No specific obligations beyond the general AI-literacy duty |
“Providers and deployers of AI systems must take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff.”