The EU AI Act and your small business: what actually applies to you
Almost everything written about the AI Act is aimed at the companies building the models. If you are a twelve-person firm that uses ChatGPT and a chatbot on your website, the question is much narrower — and the answer is more manageable than the headlines suggest.
The AI Act does not regulate AI in the abstract. It regulates what a system is used for, and it treats the company that builds a system very differently from the company that merely uses one. Nearly every small business in Austria falls into the second group.
The Act calls you a deployer. Providers — the people who develop a system and put it on the market under their own name — carry the heavy obligations: conformity assessments, technical documentation, registration, post-market monitoring. Deployers carry a much shorter list. Knowing which word applies to you is most of the work.
The four tiers, in plain terms
Banned. A short list of practices no one may use, including social scoring and certain kinds of biometric categorisation and emotion inference in workplaces and schools. If you are not doing anything that sounds like surveillance, this is not about you.
High risk. This is where the serious obligations live, and it is defined by purpose. Using AI to screen job applications, to decide who gets credit, to assign people to training, or in certain safety components — those are high-risk uses even for a small firm. This is the tier most owners assume they are in, and most are not. But if you have quietly started ranking CVs with an AI tool, you have walked into it.
Transparency duties. The tier most small businesses actually touch. If people interact with a chatbot, they must be able to tell it is a machine. Synthetic or manipulated content needs to be marked as such. These are disclosure duties, not engineering ones.
Minimal risk. Everything else: drafting, summarising, translating, writing code, brainstorming. No specific obligations under the Act.
Regardless of tier, the Act expects staff who work with AI systems to have a level of AI literacy appropriate to their role. Not certification — just that the people using these tools understand roughly what they do, where they fail, and what not to put in them. A one-page internal policy plus a short briefing is a reasonable answer for a small firm.
The timeline, and why it feels sudden
The Act entered into force in August 2024 and applies in stages rather than all at once. The prohibitions and the AI-literacy expectation came first, in February 2025. Obligations for general-purpose AI models followed in August 2025. The bulk of the remaining regime, including much of the high-risk framework, lands from August 2026, with certain product-embedded high-risk systems phased in a year later.
That staggering is why the Act has arrived in the press three or four separate times, each wave read by business owners as a fresh emergency. It is one law with a long runway.
The realistic risk for a small firm is not the AI Act. It is the GDPR, which has been in force for years and already covers what your staff paste into a chatbot.
What to actually do this quarter
- Write down where AI is already used. Not a formal register — a list. Which tools, by whom, for what. Most owners are surprised by their own list.
- Check nothing on that list touches a high-risk purpose. Hiring and credit decisions are the two that catch ordinary businesses.
- Label your chatbot. If there is one on your site, make it obvious it is a machine. This is cheap and it is a real obligation.
- Give staff one page of rules and ten minutes of explanation. That covers the AI-literacy expectation far better than a policy nobody reads.
- Keep personal data out of public tools. This is a GDPR duty, not an AI Act one, and it is where the actual exposure sits.
None of this requires a consultant, a committee, or a compliance platform. It requires an afternoon and a decision about what your firm will and will not do.
This is an explanation, not legal advice. The Act is long, its guidance is still settling, and the details of how it lands on a particular business depend on facts we do not have. If you are in or near the high-risk tier, get a lawyer — that is exactly the situation where one is worth the money.
Start with the one page.
Answer five questions and we'll write your firm's AI usage policy — what staff may use AI for, what must never go in, and who signs off. Free, and yours to circulate.
Write my policy