SWASocial Web Automation
Skip to content
AI Act

The AI Act: what it actually means for a small business

The European regulation on artificial intelligence is in force and its main rules apply from 2 August 2026. Many businesses do not realise they are covered, because they assume it concerns whoever builds AI systems. In fact it also concerns whoever uses them, and using an assistant that answers customers or a tool that writes text is enough to trigger some obligations. Not all of them, though, and the difference matters.

The AI Act: what it actually means for a small business
Illustrative image generated with AI.

The dates, in order

The AI Act is Regulation (EU) 2024/1689. It entered into force on 1 August 2024, but not everything applies at once: the deadlines are staggered, which is why many people stopped following it after the first headlines.

Prohibited practices — those of unacceptable risk — apply from 2 February 2025, together with the duty to ensure an adequate level of AI literacy among those who use it at work. From 2 August 2025 the rules on general-purpose models, governance and penalties apply. From 2 August 2026 the transparency obligations of Article 50 take effect and enforcement properly begins on prohibitions, general-purpose models, transparency and literacy. It is not the date on which “everything applies”: high-risk systems come later, and the calendar was amended along the way by the digital simplification package on AI. It is worth re-checking it on the Commission’s site before taking decisions. For some high-risk systems tied to regulated products the deadline is 2 August 2027.

  • 1 August 2024: entry into force
  • 2 February 2025: general provisions, AI literacy and prohibited practices
  • 2 August 2025: general-purpose models, national authorities, European governance
  • 2 August 2026: the transparency obligations of Article 50, measures supporting innovation, and the start of enforcement for general-purpose models, prohibited practices, transparency and literacy
  • 2 December 2026: new prohibitions on non-consensual sexual deepfakes and child sexual abuse material, and the transitional deadline for those already placing systems generating synthetic content on the market
  • 2 August 2027: every Member State must have at least one regulatory sandbox operational
  • 2 December 2027: high-risk systems listed in Annex III
  • 2 August 2028: high-risk AI embedded in products already regulated, Annex I

Provider or deployer: the question everything starts from

The regulation assigns different obligations depending on the role. Whoever develops an AI system and places it on the market under their own name is a provider, and carries the heaviest obligations. Whoever uses a system developed by somebody else, under their own authority and in the course of their own business, is a deployer, and carries far lighter obligations.

The great majority of small businesses sit in the second category: they use tools made by others. A beauty salon that switches on a phone assistant does not become an AI provider, any more than it becomes a software manufacturer by using practice management software.

One caution though: the role can change. If a system is substantially modified, or resold under your own brand, whoever does that may take on the provider’s obligations. That is a check to make beforehand, not afterwards.

The risk levels, and why almost everything you use is not high risk

The regulation classifies systems by risk. Some practices are prohibited outright: manipulation causing harm, exploitation of vulnerabilities, social scoring, certain forms of emotion recognition in the workplace.

Then there are high-risk systems, those used in areas such as recruitment, access to credit, education and certain essential services. Here the obligations are serious.

Below that sits the band covering the vast majority of everyday business use: tools that write text, answer the phone, organise appointments. They are not high risk, but neither are they exempt from everything: they carry transparency obligations.

Transparency: the rule that touches whoever answers customers

If a person interacts with an AI system, they have to be able to know it, unless it is already obvious from the context. In plain terms: an assistant answering the phone or a chat should not let anybody believe it is a person.

On artificially generated content there is a widespread misunderstanding worth clearing up. The duty to mark outputs in a machine-readable format falls on the provider of the system that generates them, that is on whoever makes the model: not on whoever uses it to work.

The deployer has narrower obligations: to declare deepfakes, to inform people exposed to emotion recognition or biometric categorisation, and to label AI-generated text published to inform the public on matters of public interest. On that last point the Commission spells out the exemption that covers almost everybody: if the text has undergone human review or editorial control, no label is needed. Human review means that a person with competence and professional judgement genuinely examined the substance of the content; a spellcheck is not enough.

Translated for a small business publishing commercial content approved by a person before it goes out: the labelling obligation generally does not apply. What does remain is the duty to declare the assistant when it speaks to customers, and staff AI literacy, both in force since February 2025.

The positive flip side: saying it is an assistant does not drive customers away. What drives them away is finding out afterwards.

The obligation almost nobody talks about: training

Since February 2025 providers and deployers must take steps to ensure that the staff dealing with the use of AI systems have a sufficient level of competence, taking into account their knowledge, the context, and the people the systems are used on.

That does not mean sending everybody on a master’s course. It means that whoever in the company uses an AI tool has to know what it does, what it does not do, and when to stop. It is an obligation of means, and for a small business it is met with proportionate, documented training.

It is also why this obligation goes unnoticed: there is no form to fill in and no body to send it to. But if it is ever challenged, being able to show you thought about it makes the difference.

What to do, in practice

The first step is not to buy anything: it is to take an inventory. Which AI tools are genuinely used in the business, who uses them, what data they work on and which people they come into contact with. The list is often longer than expected.

From there you look at the role — provider or deployer — for each one, check whether any falls among the prohibited or high-risk practices, and review the information given to customers when they speak to a system.

Finally the contracts: what your supplier guarantees, where they keep the data, what happens if the service changes. These are clauses negotiated before signing, not after.

  • An inventory of the AI tools genuinely in use
  • The role for each one: provider or deployer
  • A check on prohibited practices and high-risk cases
  • Information given to customers when they speak to a system
  • Proportionate, documented training for whoever uses them
  • Supplier contracts: guarantees, data, continuity

Frequently asked questions

Does the AI Act also apply to those who only use tools made by others?

Yes, with different and lighter obligations than for those who develop them. Whoever uses an AI system under their own authority in the course of their business is a deployer and still has duties, in particular on transparency and staff competence.

Do I have to tell customers that an AI assistant is answering?

The regulation provides that anybody interacting with an AI system must be able to know it, unless it is obvious from the context. In practice an assistant answering the phone or a chat should not let anybody believe it is a person.

Does using AI to write posts make my company high risk?

Generally no: marketing and communication uses do not fall into the high-risk categories, which cover areas such as recruitment, credit or essential services. The transparency obligations on artificially generated content still apply. The assessment has to be made on the actual case.

What is the risk of not complying?

The regulation provides for administrative fines, with different amounts depending on the infringement: the highest concern prohibited practices. The amount that applies depends on the infringement and on the size of the business.

Is one document enough to be compliant?

No. The obligations concern conduct, not forms: what you tell customers, how you train whoever uses the tools, what you checked before switching them on. Documentation serves to demonstrate that, not to replace it.

This is how we work on it

Sources

This article is for information only and does not replace advice on your actual situation. We are preparing video courses on the AI Act with Avv. Vincenzo Sapone, a Cassation lawyer: you can reserve a place from the legal AI consulting page.
See the packages and entry prices
Back to SWA Journal