ModelCharter
ModelCharter Team

AI Compliance: What It Is and What Your Business Must Do

Scales of justice representing AI compliance and legal obligations for business

Photo: Sora Shimazaki / Pexels

Key takeaways

  • AI compliance means meeting real legal and contractual obligations, not a vague commitment to being responsible.
  • Four frameworks cover most small businesses: the EU AI Act, GDPR, HIPAA and SOC 2.
  • The EU AI Act's AI-literacy duty for staff has applied since 2 February 2025.
  • Consumer AI tiers usually lack the DPA or BAA that regulated data requires.
  • A written policy, a tool register and staff attestation records satisfy most audits and due-diligence checks.

AI compliance means using AI tools in a way that satisfies the laws, regulations and contracts your business is actually subject to, not a vague commitment to being responsible. For most small and mid-sized businesses, that obligation clusters around four frameworks: the EU AI Act, GDPR, HIPAA if you handle US health data, and SOC 2 if you sell software to bigger customers. You're unlikely to face all four at once, but you almost certainly face at least one, and working out which is a smaller job than it sounds. Get it wrong and the cost usually isn't a fine, it's a stalled deal or a failed audit. This guide sets out what each framework actually asks of you, and the artefacts that cover most of it.

What AI compliance actually covers

It helps to separate AI compliance from AI ethics. Ethics is about doing the right thing in a general sense; compliance is about meeting specific, checkable requirements that someone else, a regulator, an auditor, a customer's legal team, can verify. That distinction matters because a company can feel very responsible about its AI use and still fail a due-diligence questionnaire, because nobody wrote anything down. Compliance work is mostly documentation work: knowing which rules apply, and having proof you follow them.

The EU AI Act: what a deployer has to do

If your business, or its output, reaches the EU, through EU customers or EU-based staff using AI on your behalf, the EU AI Act applies, even if you're headquartered elsewhere. Most SMBs are 'deployers' of general tools like ChatGPT or Copilot rather than 'providers' building AI systems, so the practical duties are narrower than the headlines suggest: ensure staff have basic AI literacy, stay transparent about AI-generated content, and avoid a short list of banned practices such as real-time biometric surveillance in public spaces. The AI-literacy duty, set out in Article 4, has applied since 2 February 2025, and a written policy plus a staff briefing is the simplest way to evidence it.

GDPR: the data processing layer AI adds

Any AI tool that touches the personal data of someone in the EU is acting as a data processor on your behalf, which means you need a lawful basis, a Data Processing Agreement with the vendor, and an entry in your record of processing activities. This is where consumer AI tiers usually fall down: free and personal-account tiers rarely come with a DPA at all, which makes them unsuitable for anything involving customer or employee data, however good the model is. If the AI vendor itself relies on subprocessors, other companies handling parts of the service behind the scenes, note those too; GDPR expects visibility into the whole processing chain, not just the vendor whose name is on the contract you signed. The ICO's guidance on AI and data protection is the clearest primer if you want the regulator's own framing, and our GDPR compliance hub covers the practical steps.

HIPAA: the healthcare boundary with no grey area

US healthcare organisations, and any business associate working with them, need a signed Business Associate Agreement in place before protected health information touches an AI tool, full stop. There's no threshold or intent test: the obligation exists the moment PHI could be involved, whether or not anything actually goes wrong. Enterprise AI tiers typically offer a BAA on request; consumer and standard business tiers usually don't, so check before a clinician or care coordinator starts pasting patient notes into whatever's fastest. Beyond the signed agreement itself, HIPAA's workforce training duty extends naturally to AI: anyone who might handle PHI needs to know which tools are approved before they start using them, not after an incident forces the conversation. HHS's guidance on business associates spells out exactly who counts, and our HIPAA compliance hub walks through the AI-specific version.

SOC 2: compliance your customers ask for, not a regulator

SOC 2 doesn't create AI-specific legal duties, but it's increasingly where AI governance gets tested in practice. Enterprise customers running vendor due diligence now routinely ask whether you have an AI usage policy, whether staff have acknowledged it, and how you vet the AI tools that touch their data, usually as a handful of questions buried in a longer security questionnaire that's easy to underestimate until it lands on your desk. Picture a 40-person marketing agency mid-renewal with its biggest client: the client's security questionnaire asks for an AI usage policy, the agency doesn't have one, and the scramble to write something from scratch nearly costs them the account. That's a far more common way for AI governance gaps to surface than a regulator's letter. The AICPA's Trust Services Criteria underpin what auditors check, and our SOC 2 compliance hub maps AI-specific questions onto it.

Do you need to comply if you only use AI, not build it?

Yes. This is the most common misconception. Building AI systems triggers the heaviest set of obligations, but using AI tools someone else built, ChatGPT, Copilot, an AI feature bolted onto your CRM, still makes you a deployer with real duties under the EU AI Act, and a customer of a data processor under GDPR. 'We didn't build it' has never been a defence for how you use it.

The paperwork that actually satisfies a reviewer

When someone finally asks to see your AI compliance, a customer's security team, an internal auditor, occasionally a regulator, keep four things ready in one folder: a dated, version-numbered AI usage policy; a register of every approved AI tool with its training and retention settings recorded against it; the DPA or BAA on file for any tool touching personal or health data, a signed document, not a link to the vendor's marketing page; and a log of when each staff member acknowledged the current policy, ideally timestamped per person. None of that is difficult to produce on its own. Almost nobody has it assembled before they're asked for it, which is exactly the moment it stops looking optional and starts looking like a gap. Build the folder once, and keeping it current becomes a five-minute quarterly task instead of a scramble.

What actually happens if you skip AI compliance?

For most SMBs, the immediate risk isn't a regulatory fine, low-risk deployer obligations under the EU AI Act carry limited direct penalties today for an AI-literacy shortfall on their own. The immediate risk is commercial: a lost deal when a customer's due-diligence process asks a question you can't answer, or a compliance gap that surfaces during a SOC 2 audit and delays your report. Regulatory risk grows sharply if you're in a more exposed sector, healthcare, finance, anything processing EU personal data at scale, where the obligations are sharper and better enforced.

Start with the policy, then build outward

AI compliance doesn't start with a legal team, it starts with a policy. ModelCharter's free AI usage policy generator produces one tailored to your regulatory context in a few minutes. From there, add a register of the AI tools you actually use and a record that staff have acknowledged the policy. Together, those three artefacts answer most of what a regulator, an auditor or a nervous customer will ask you.

FrameworkWho it applies toCore AI-related dutyKey artefact
EU AI ActAny business whose AI use reaches EU customers or staffStaff AI literacy; transparency; avoid banned practicesAI usage policy + staff briefing
GDPRAny AI tool processing EU personal dataLawful basis; Data Processing AgreementSigned DPA + record of processing activities
HIPAAUS healthcare organisations and business associatesBusiness Associate Agreement before PHI useSigned BAA on an enterprise AI tier
SOC 2B2B software companies selling to enterprise customersEvidence of AI vendor due diligenceAI tool register + policy + attestation log
Which AI compliance framework applies to you
Most SMBs don't fail AI compliance because they broke a law. They fail because nobody wrote anything down.
ModelCharter's compliance team

Frequently asked questions

Is there a single 'AI compliance' law?
No. It's a stack of existing laws plus new AI-specific rules layered on top, the EU AI Act, GDPR, HIPAA, SOC 2, treat it as an obligations map to check against, not one statute to read cover to cover.
Does AI compliance apply to companies with fewer than 10 staff?
Yes, if EU customers, personal data or health information are involved. Company size changes what's proportionate, not whether the obligation exists.
What's the fastest way to become AI compliant?
Write the policy first, then build a register of approved tools, then collect staff attestation. Those three artefacts cover most of what an auditor or regulator actually asks for.
Do free AI tools like ChatGPT Free break compliance automatically?
Not automatically, but consumer tiers often skip the DPA or BAA that regulated data requires and may train on what you type in by default, which makes them the wrong tool for anything sensitive, even if nobody has misused them yet.
Who should own AI compliance in a small company?
Someone needs to, even part-time, often whoever already owns IT or HR policy. Without a named owner, policies go stale and nobody notices when a new AI tool shows up unapproved.

Put this into practice

Generate a free AI usage policy for your team, then see which of your tools are safe to use.

Open the generator