The European Union has adopted a regulation specific to artificial intelligence. For a small business using off-the-shelf tools the impact stays limited, but it is not nil, and a few common uses fall into regulated categories.
This entry describes the logic of the text. It does not replace analysis by a legal professional on your specific case, all the more so as the regulation applies in stages over several years.
What we are talking about
The AI Act is the European regulation on artificial intelligence. Its guiding principle is simple: obligations depend on the use, not the technology. The same model can fall into different categories depending on what you do with it.
| Level | Principle | Example uses |
|---|---|---|
| Unacceptable | Prohibited | Social scoring, manipulating vulnerable people |
| High | Heavily regulated | Recruitment, credit access, education |
| Limited | Transparency obligation | Conversational agent, generated content |
| Minimal | No specific obligation | The vast majority of internal uses |
For most small businesses, what matters sits on the "limited" line: telling people they are talking to a machine, and flagging generated content. Two simple obligations, easy to respect from the design stage.
Common cases that move up a level
Sorting job applications. The most frequent use that moves into high risk. Using a model to rank CVs puts you in a demanding category, on top of the Algorithmic bias questions.
Automated customer service. Generally limited risk, with the obligation to state clearly that the interlocutor is not a person.
Published generated content. Marking machine-produced content falls under transparency, and the technical arrangements are still moving.
Useful habits right now
Inventory your uses. Knowing where you use AI is the prerequisite to any analysis, and many organisations discover uses they had not recorded.
Be transparent by default. Announcing that an assistant is a machine costs nothing and puts you on the right side whatever the text becomes.
Keep a record. Which model, for which use, with which data. That documentation serves compliance as much as debugging.
Keep humans on decisions with consequences. That principle runs through the whole regulation, and it is best practice regardless of it.
Do not take the categories in this table as a legal qualification of your situation. Classification depends on details of use, and a category error is not without consequence. On a case with stakes, have it validated.
Frequently asked questions
Am I concerned if I only use off-the-shelf tools?
You are then a deployer rather than a provider, and your obligations are considerably lighter. They do not disappear, particularly on transparency and on high-risk uses.
Does it apply to providers outside Europe?
The text reaches beyond European borders once the output is used in the Union, which is why the large providers are adapting to it.
When does all this apply?
Application is staged by category over several years. Precise deadlines should be checked against official sources rather than an article, since the timetable has already been adjusted.
Where do you start concretely?
With an inventory of your uses and with transparency, both useful whatever happens. Our Claude Cowork course helps establish that inventory as you put uses into production.