AI Compliance: What It Is and What Your Business Must Do

Photo: Sora Shimazaki / Pexels
Key takeaways
- AI compliance means meeting real legal and contractual obligations, not a vague commitment to being responsible.
- Four frameworks cover most small businesses: the EU AI Act, GDPR, HIPAA and SOC 2.
- The EU AI Act's AI-literacy duty for staff has applied since 2 February 2025.
- Consumer AI tiers usually lack the DPA or BAA that regulated data requires.
- A written policy, a tool register and staff attestation records satisfy most audits and due-diligence checks.
AI compliance means using AI tools in a way that satisfies the laws, regulations and contracts your business is actually subject to, not a vague commitment to being responsible. For most small and mid-sized businesses, that obligation clusters around four frameworks: the EU AI Act, GDPR, HIPAA if you handle US health data, and SOC 2 if you sell software to bigger customers. You're unlikely to face all four at once, but you almost certainly face at least one, and working out which is a smaller job than it sounds. Get it wrong and the cost usually isn't a fine, it's a stalled deal or a failed audit. This guide sets out what each framework actually asks of you, and the artefacts that cover most of it.
What AI compliance actually covers
It helps to separate AI compliance from AI ethics. Ethics is about doing the right thing in a general sense; compliance is about meeting specific, checkable requirements that someone else, a regulator, an auditor, a customer's legal team, can verify. That distinction matters because a company can feel very responsible about its AI use and still fail a due-diligence questionnaire, because nobody wrote anything down. Compliance work is mostly documentation work: knowing which rules apply, and having proof you follow them.
The EU AI Act: what a deployer has to do
If your business, or its output, reaches the EU, through EU customers or EU-based staff using AI on your behalf, the EU AI Act applies, even if you're headquartered elsewhere. Most SMBs are 'deployers' of general tools like ChatGPT or Copilot rather than 'providers' building AI systems, so the practical duties are narrower than the headlines suggest: ensure staff have basic AI literacy, stay transparent about AI-generated content, and avoid a short list of banned practices such as real-time biometric surveillance in public spaces. The AI-literacy duty, set out in Article 4, has applied since 2 February 2025, and a written policy plus a staff briefing is the simplest way to evidence it.
GDPR: the data processing layer AI adds
Any AI tool that touches the personal data of someone in the EU is acting as a data processor on your behalf, which means you need a lawful basis, a Data Processing Agreement with the vendor, and an entry in your record of processing activities. This is where consumer AI tiers usually fall down: free and personal-account tiers rarely come with a DPA at all, which makes them unsuitable for anything involving customer or employee data, however good the model is. If the AI vendor itself relies on subprocessors, other companies handling parts of the service behind the scenes, note those too; GDPR expects visibility into the whole processing chain, not just the vendor whose name is on the contract you signed. The ICO's guidance on AI and data protection is the clearest primer if you want the regulator's own framing, and our GDPR compliance hub covers the practical steps.
HIPAA: the healthcare boundary with no grey area
US healthcare organisations, and any business associate working with them, need a signed Business Associate Agreement in place before protected health information touches an AI tool, full stop. There's no threshold or intent test: the obligation exists the moment PHI could be involved, whether or not anything actually goes wrong. Enterprise AI tiers typically offer a BAA on request; consumer and standard business tiers usually don't, so check before a clinician or care coordinator starts pasting patient notes into whatever's fastest. Beyond the signed agreement itself, HIPAA's workforce training duty extends naturally to AI: anyone who might handle PHI needs to know which tools are approved before they start using them, not after an incident forces the conversation. HHS's guidance on business associates spells out exactly who counts, and our HIPAA compliance hub walks through the AI-specific version.
SOC 2: compliance your customers ask for, not a regulator
SOC 2 doesn't create AI-specific legal duties, but it's increasingly where AI governance gets tested in practice. Enterprise customers running vendor due diligence now routinely ask whether you have an AI usage policy, whether staff have acknowledged it, and how you vet the AI tools that touch their data, usually as a handful of questions buried in a longer security questionnaire that's easy to underestimate until it lands on your desk. Picture a 40-person marketing agency mid-renewal with its biggest client: the client's security questionnaire asks for an AI usage policy, the agency doesn't have one, and the scramble to write something from scratch nearly costs them the account. That's a far more common way for AI governance gaps to surface than a regulator's letter. The AICPA's Trust Services Criteria underpin what auditors check, and our SOC 2 compliance hub maps AI-specific questions onto it.
Do you need to comply if you only use AI, not build it?
Yes. This is the most common misconception. Building AI systems triggers the heaviest set of obligations, but using AI tools someone else built, ChatGPT, Copilot, an AI feature bolted onto your CRM, still makes you a deployer with real duties under the EU AI Act, and a customer of a data processor under GDPR. 'We didn't build it' has never been a defence for how you use it.
The paperwork that actually satisfies a reviewer
When someone finally asks to see your AI compliance, a customer's security team, an internal auditor, occasionally a regulator, keep four things ready in one folder: a dated, version-numbered AI usage policy; a register of every approved AI tool with its training and retention settings recorded against it; the DPA or BAA on file for any tool touching personal or health data, a signed document, not a link to the vendor's marketing page; and a log of when each staff member acknowledged the current policy, ideally timestamped per person. None of that is difficult to produce on its own. Almost nobody has it assembled before they're asked for it, which is exactly the moment it stops looking optional and starts looking like a gap. Build the folder once, and keeping it current becomes a five-minute quarterly task instead of a scramble.
What actually happens if you skip AI compliance?
For most SMBs, the immediate risk isn't a regulatory fine, low-risk deployer obligations under the EU AI Act carry limited direct penalties today for an AI-literacy shortfall on their own. The immediate risk is commercial: a lost deal when a customer's due-diligence process asks a question you can't answer, or a compliance gap that surfaces during a SOC 2 audit and delays your report. Regulatory risk grows sharply if you're in a more exposed sector, healthcare, finance, anything processing EU personal data at scale, where the obligations are sharper and better enforced.
Start with the policy, then build outward
AI compliance doesn't start with a legal team, it starts with a policy. ModelCharter's free AI usage policy generator produces one tailored to your regulatory context in a few minutes. From there, add a register of the AI tools you actually use and a record that staff have acknowledged the policy. Together, those three artefacts answer most of what a regulator, an auditor or a nervous customer will ask you.
| Framework | Who it applies to | Core AI-related duty | Key artefact |
|---|---|---|---|
| EU AI Act | Any business whose AI use reaches EU customers or staff | Staff AI literacy; transparency; avoid banned practices | AI usage policy + staff briefing |
| GDPR | Any AI tool processing EU personal data | Lawful basis; Data Processing Agreement | Signed DPA + record of processing activities |
| HIPAA | US healthcare organisations and business associates | Business Associate Agreement before PHI use | Signed BAA on an enterprise AI tier |
| SOC 2 | B2B software companies selling to enterprise customers | Evidence of AI vendor due diligence | AI tool register + policy + attestation log |
“Most SMBs don't fail AI compliance because they broke a law. They fail because nobody wrote anything down.”