ModelCharter
ModelCharter Team

EU AI Act for Small Business: What You Must Do

Person reviewing EU AI Act compliance documents and legal regulations

Photo: Sora Shimazaki / Pexels

Key takeaways

  • If your business, staff or output reach the EU, EU AI Act compliance can apply to you, even based elsewhere.
  • Most small businesses are 'deployers' of tools like ChatGPT, not 'providers' of AI systems - a much lighter duty set.
  • The AI-literacy duty under Article 4 has applied since 2 February 2025.
  • Four risk tiers exist; almost everything a small business does falls into 'limited' or 'minimal' risk.
  • A written AI usage policy plus a short staff briefing covers most of the realistic first-step obligations.

The EU AI Act is the world's first comprehensive AI law, and the headlines about it read like it's aimed squarely at you. For a small business that simply uses AI tools, rather than building high-risk AI systems from scratch, eu ai act compliance is more manageable than the coverage suggests. The Act sorts obligations by how risky your use of AI actually is, and almost nothing a typical small team does lands in the heaviest tier. This guide covers who the Act actually reaches, what a small business realistically has to do, and where you can stop worrying and get back to work.

Does it apply to you?

If your business, or the output it produces, reaches the EU - EU customers, EU-based staff using AI on your behalf, or products sold into the EU market - then yes, the Act can apply, even if your company is headquartered outside Europe entirely. Geography of incorporation doesn't exempt you; geography of impact does the reaching. The full consolidated text of the Act defines this scope precisely, but the short version above covers the vast majority of small-business cases.

Does the Act apply if you're based outside the EU?

It can, and this catches people out. The Act follows effect, not address: a US-based agency with a handful of EU clients, or a UK company with EU-based remote staff, can fall within scope for exactly the same reasons an EU-headquartered company would. The test is whether AI output touches the EU market or EU people, not where your office happens to be. UK businesses in particular sometimes assume Brexit removed them from scope entirely; it removed direct jurisdiction, not the effect-based reach that catches any business selling into the bloc.

You're probably a deployer, not a provider

The Act splits obligations between 'providers,' who build and place AI systems on the market, and 'deployers,' who use AI systems built by someone else under their own authority. Most small teams are deployers of general tools like ChatGPT, Copilot or Claude, so the heaviest provider-level duties - technical documentation, conformity assessments, registration - simply don't apply. The practical deployer duties are narrower: don't use banned practices, ensure basic AI literacy among staff, and be transparent about AI involvement where it's required. Getting this distinction right early saves a lot of wasted reading, since most Act commentary online is written for providers, not for the far larger group of businesses just using the tools. You only become a provider if you take an existing model and substantially modify or rebrand it as your own product, which is a step most small businesses never take.

The AI-literacy duty, in plain terms

Since 2 February 2025, Article 4 has required providers and deployers to ensure staff have a sufficient level of AI literacy for their role. In practice, that doesn't mean a certification course. A written AI usage policy, the same kind covered in our guide on how to write one, plus a short briefing is the simplest way to evidence it, because it leaves you with two things an auditor or regulator would actually look for: a document, and a record that people read it.

What happens if you ignore it?

For a small business using general-purpose tools, the realistic near-term risk isn't a dramatic enforcement action; it's the same gap that shows up around any missing policy. A customer or partner asks how you meet EU AI Act obligations and you have no answer. An enterprise deal stalls in security review over a question you could have pre-empted with one document. Penalties under the Act scale with severity and company size, and they exist mainly for the practices the Act bans outright or for high-risk systems handled carelessly, not for a small team that simply hasn't written a policy yet. Still, 'we hadn't got round to it' isn't a great line in a security questionnaire.

Banned practices you almost certainly don't do

A short list of practices is banned outright regardless of company size: manipulative AI that exploits vulnerable groups, social scoring by public authorities, and certain uses of biometric categorisation. Worth a gut-check against your own use cases, but for a business using AI to draft emails, summarise documents or generate marketing copy, none of this applies, and you can move on without a second thought. This list exists mainly to stop the worst, most invasive uses of AI; it isn't aimed at day-to-day office work.

Transparency: telling people they're dealing with AI

Where AI generates content people might mistake for human-made, or where someone is interacting with an AI system directly, the Act expects disclosure. In practice that's usually a line on AI-generated marketing copy, or a note that a support chatbot is automated rather than staffed by a person. It's a small addition, not a redesign of how you work, and it doubles as good customer-trust practice regardless of what the law technically requires.

What this looks like for a small team

A twelve-person e-commerce business selling into Germany and France assumed the EU AI Act was someone else's problem, since they don't build AI and aren't based in the EU. Then a German wholesale partner's procurement team asked, directly, how the business met its AI-literacy obligations under Article 4. The honest answer at the time was that nobody had thought about it, and the deal stalled for a week while someone scrambled to find out what was actually required. The fix, once they looked into it, was small: a written policy covering the AI tools the team used for product descriptions and customer replies, a fifteen-minute team briefing recorded for anyone who missed it, and a line disclosing that some marketing copy was AI-assisted. The partnership went ahead, and the same document now gets reused for every new EU partner who asks.

What to do this quarter

Write an AI usage policy, keep a register of the AI tools your team uses, and make sure anyone using AI understands the basics covered above. That's the realistic scope of first steps for a small business, and none of it requires a lawyer on retainer or a compliance hire to get moving. For the fuller detail, including how risk tiers are defined, see our EU AI Act framework guide, and check our wider notes on what AI governance actually involves if you're starting from scratch.

Risk categoryWhat it coversExampleWhat deployers must do
Unacceptable riskPractices considered a clear threat to rights or safetySocial scoring, manipulative AI targeting vulnerable groupsBanned outright - do not deploy
High-riskAI used in areas like employment, credit or law enforcementAI screening job applicants or credit applicationsHuman oversight, record-keeping, extra due diligence
Limited riskAI that interacts with people or generates contentChatbots, AI-generated marketing copyDisclose that people are interacting with or viewing AI output
Minimal riskMost everyday AI toolsSpam filters, AI writing assistants used internallyNo specific obligations beyond the general AI-literacy duty
EU AI Act risk categories, in practice
Providers and deployers of AI systems must take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff.
EU AI Act, Article 4

Frequently asked questions

Do I need to register with an EU authority?
Most small businesses using general-purpose AI tools don't. Registration duties fall mainly on providers of high-risk AI systems, not on deployers using tools like ChatGPT or Copilot for everyday work.
Is the EU AI Act only for companies based in the EU?
No. It follows where the impact lands - EU customers, EU staff or EU market output - not where the company is incorporated, so non-EU businesses with any EU footprint can still be in scope.
What counts as 'AI literacy' training under Article 4?
There's no fixed course or certificate required. A written policy covering what AI tools are approved, what data rules apply, and a briefing that staff have actually attended is generally treated as sufficient evidence for a small team.
Does using ChatGPT at work make me a 'provider' under the Act, or does it apply to background AI features like spam filters?
Neither creates a heavy burden. Using a tool someone else built makes you a deployer, a much lighter role than the provider that built and placed the system on the market. Background AI features such as spell-checkers or spam filters sit in the minimal-risk tier, with no specific obligations beyond the general AI-literacy duty.
What's the realistic penalty risk for a small business?
Penalties scale with severity and company size, and are aimed mainly at banned practices or mishandled high-risk systems. For a small business using general AI tools, the more immediate risk is commercial - losing a deal or partner over an unanswered compliance question during due diligence - rather than a regulatory fine landing out of nowhere.

Put this into practice

Generate a free AI usage policy for your team, then see which of your tools are safe to use.

Open the generator