Skip to content

EU AI Act for Small Business: What Your Software Needs to Do

The EU AI Act for small business, explained by a developer: what applies to chatbots, generated content and other AI features, and the dates that matter.

By

Freelance full-stack developer

Published
Reading time
13 min
In this post9

For a small business that builds or sells software, the EU AI Act mostly comes down to a few practical duties: tell people when they're talking to an AI, mark AI-generated content, and make sure your team knows how to use AI tools sensibly. The heavy obligations only apply if your product is used for things like hiring, credit scoring or grading students, and for those systems the rules start on 2 December 2027.

I'm a freelance developer based in Denmark, not a lawyer, so read this as a technical and practical walkthrough rather than legal advice. The dates were checked in October 2026 against the European Commission's official timeline, which now reflects the Digital Omnibus on AI: an amending regulation that entered into force on 27 July 2026 and pushed back the high-risk deadlines.

The short answer: which rules hit which features

Common AI features in small software companies and what the EU AI Act requires (checked October 2026)
CategoryWhat you need to doApplies from
Customer-facing chatbot or AI assistantTransparencyTell users it's an AI, at the latest in the first message2 August 2026
Generated text, images or audio inside your productTransparencyMark outputs as AI-generated in a machine-readable way2 August 2026 (2 December 2026 for systems already on the market)
Product recommendations, search and sortingMinimal riskNothing specific beyond AI literacyAI literacy since 2 February 2025
Internal automation, such as summarizing or tagging emailsMinimal riskNothing specific beyond AI literacyAI literacy since 2 February 2025
CV screening or candidate rankingHigh riskRisk management, documentation, human oversight, registration and more2 December 2027
Credit scoring of consumersHigh riskAs above2 December 2027
Emotion recognition of employees via camera or voiceProhibitedDon't build itBanned since 2 February 2025

My quickest test is one question: does the AI make or shape decisions about a person's job, education, finances or access to services? If not, it's mostly about transparency. If it does, read the high-risk rules before you write more code.

If you're turning a Lovable, Bolt or Cursor prototype into a real product, the AI Act is only one item on the list. The rest is in my guide to taking a vibe-coded app to production.

Who the AI Act covers, and how risk is tiered

The Act applies to providers that place AI systems on the EU market, wherever they're based, and to deployers established in the EU. It also covers providers and deployers outside the EU when the system's output is used in the EU. A UK or US SaaS with customers in Germany or Sweden is in scope, much like with GDPR. Purely personal use and research before a system reaches the market are exempt.

Obligations follow four risk tiers, as set out in the Commission's AI Act overview:

  • Prohibited. Since 2 February 2025 you can't use AI for harmful manipulation, social scoring, building facial recognition databases by scraping images, or emotion recognition at work or in education, except for medical or safety reasons. From 2 December 2026, AI that generates intimate imagery of people without their consent or child sexual abuse material is banned too.
  • High risk. Specific areas such as employment, education, credit and public services, plus AI built into regulated products like machinery and medical devices.
  • Transparency. Chatbots, generated content and deepfakes. People have to be told.
  • Minimal risk. Everything else, from spam filters to recommendations. According to the Commission, the vast majority of AI systems in the EU sit here.

The bans rarely touch a normal SaaS product, but note one detail: the Act defines emotion recognition as inferring emotions from biometric data such as faces and voices. Sentiment analysis on the text of support tickets isn't caught by the ban. A tool that reads your employees' facial expressions on video calls is.

Provider or deployer: the role that sets your obligations

Your duties depend on your role, and this is where most of the confusion sits.

  • Provider: the company that develops an AI system, or has it developed, and places it on the market or puts it into service under its own name. That includes systems you build purely for internal use.
  • Deployer: the company that uses an AI system in a professional context. Buy a ready-made chatbot widget for your site, and you're the deployer.

Here's what surprises people: wrap GPT or Claude in a feature and ship it in your SaaS, and you're the provider of that AI system. OpenAI and Anthropic provide the underlying general-purpose models and carry the obligations that come with them. The Commission's guidelines say only significant modifications turn a downstream company into a model provider, not minor tweaks. Making sure your assistant tells users it's an AI, however, is on you.

Article 25 is the trap to watch. Repurpose a general AI system for a high-risk job, such as ranking job applicants with an LLM, and you become the provider of a high-risk system with every obligation that implies. That can apply even when the whole thing is a prompt and a few lines of code. The same goes if you put your brand on a high-risk system someone else built.

Chatbots and AI-generated content (Article 50)

Article 50 is the part most small software companies will actually deal with. It has applied since 2 August 2026.

Chatbots and AI assistants

A system that talks directly to people must be designed so they know it's an AI. The notice has to be clear and come at the latest at the first interaction. There's an exception when it's obvious to a reasonably well-informed, observant person, but I wouldn't rely on it. One line in the chat window costs nothing.

In practice:

  • Put "AI assistant" in the chat header and the welcome message, not only in your privacy policy.
  • Skip the human name and stock photo for the bot, unless "AI" sits right next to them.
  • Think about voice bots and automated replies too, wherever customers might assume a person is answering.

I compare the two routes in build vs buy for an AI chatbot. If you buy, the vendor is the provider, so check that their widget makes the disclosure obvious.

Generated text, images, audio and video

Providers of systems that generate synthetic content must make sure outputs are marked in a machine-readable format and detectable as AI-generated. That covers, for example, a feature that creates product photos or writes copy for your users. Features that only assist with standard editing, or don't substantially change the input, are exempt. Systems already on the market before 2 August 2026 got a grace period until 2 December 2026.

Technically, this often means watermarks or metadata in the generated files and a database flag for AI output. Check what your model provider already embeds, and make sure your own image pipeline (resizing, compression, CDN transforms) doesn't strip it.

Your own AI-assisted content falls under a different rule. Deepfakes must be disclosed, and so must AI-generated text published to inform the public on matters of public interest, unless a human has reviewed it and someone holds editorial responsibility. Blog posts and marketing copy that you edit and stand behind are, in my reading, generally outside that rule.

Recommendations, search and internal automation

Most of what small companies build with AI is minimal risk: product recommendations, semantic search, ticket triage, meeting summaries and drafting help carry no specific obligations. If you're still deciding where AI fits, I've collected 12 practical AI features for SaaS products and 15 processes a small business can automate with AI.

The same technique can change category depending on where you use it:

  • Recommendations on a job board. Systems that place targeted job ads or filter applications are on the high-risk list. A recommendation engine for shoes isn't.
  • Ranking people instead of things. Sorting tickets by topic is minimal risk. Deciding who gets credit is high risk.
  • Profiling. A system in a high-risk area that profiles individuals is always high risk, even if it's a small part of your product.

Minimal risk doesn't mean no rules, though. GDPR applies in full to any personal data you send to a language model, and the rules on automated decisions may be relevant. I cover that side in GDPR and LLM APIs: what you can send to OpenAI and Claude.

If your product falls into high-risk territory

For software companies, three areas in Annex III of the Act matter most:

  • Employment: targeted job ads, filtering applications, evaluating candidates, decisions on promotion and termination, allocating tasks based on behavior or personal traits, and monitoring employee performance.
  • Education: admissions, evaluating learning outcomes, assessing the level of education a person can access, and detecting cheating during tests.
  • Essential services: creditworthiness assessment of individuals (fraud detection is excluded), risk assessment and pricing in life and health insurance, and eligibility for public benefits.

Article 6(3) offers a way out. A system isn't high risk if it only performs a narrow procedural task, improves the result of work a human has already completed, detects patterns without replacing human judgment, or performs a preparatory task. If you rely on one of these exceptions, you have to document the assessment before the system reaches the market and register it in the EU database.

What compliance involves

As the provider of a high-risk system, you need risk management, data governance for training data, technical documentation, automatic logging, instructions for use, built-in human oversight, accuracy and cybersecurity measures, a quality management system, a conformity assessment, CE marking and registration. Your customers, as deployers, must follow your instructions, assign competent people to oversee the system, keep logs for at least six months, and inform employees and other affected people.

There's some relief for smaller companies. SMEs can use simplified technical documentation, and the Omnibus extends that to small mid-caps. Fines for SMEs are capped at the lower of two amounts, and regulatory sandboxes are open to them. Still, a high-risk product in a small company is a product workstream, not a checklist. If you have one, start now.

How to map your AI features in 7 steps

  1. List every AI feature. Include the ones you built and the ones inside tools you pay for, such as chat widgets, CRMs and recruitment software. Note what each does and who it affects.
  2. Decide your role for each feature. You're the provider if you built it or sell it under your name, and the deployer if you use someone else's system.
  3. Rule out the bans. It takes five minutes: no emotion recognition of employees, no manipulation, no social scoring.
  4. Check the high-risk areas. Go through Annex III for each feature. If one lands close, write down whether an Article 6 exception applies and why. The Commission's AI Act compliance checker, in beta when I checked it in October 2026, gives a useful first read.
  5. Build transparency in. Disclosure in chat interfaces, machine-readable marking of generated content, and a field in your data model recording what was AI-generated.
  6. Train your team. Article 4 requires providers and deployers to take measures that support AI literacy among the people working with their AI systems. After the Omnibus you don't have to guarantee any particular level for each person, but a short internal policy and an introduction to the tools you use are a sensible minimum.
  7. Write it down and set a review date. A one-page note per feature with role, category and reasoning is enough for most small teams. Revisit it with every new AI feature and at least yearly, since guidance keeps arriving.

Next steps

You don't always need a developer for this. If your company only uses ChatGPT or Copilot internally, or you've bought an off-the-shelf chatbot, an internal policy and a quick check of your vendor will do. If your idea falls into a high-risk area, talk to a lawyer who knows the AI Act before anyone writes code. Classification is a legal question, even though logging, oversight and documentation have to be built into the software.

Before you launch an AI feature to EU users

  • You have a list of every AI feature, built or bought.
  • You know whether you're the provider or the deployer for each one.
  • None of your features touch the Article 5 bans.
  • You've checked each feature against the high-risk areas and written down your reasoning.
  • Chatbots and AI assistants clearly say they're AI in the first message.
  • Generated content carries machine-readable marking that survives your own image processing.
  • Your team has a short policy on using AI and knows what's allowed.
  • There's a date in the calendar for the next review.

If you need an AI feature built, or an existing one brought up to standard for both users and regulators, here's how I work on web apps and platforms.

Frequently asked questions

Do I need to register my chatbot or get CE marking?

No, not if it simply answers questions and helps customers. Registration in the EU database and CE marking apply to high-risk systems, and registration also covers systems in high-risk areas where you rely on an Article 6(3) exception. A standard customer service chatbot only has to meet the Article 50 transparency duty, meaning it tells users it's an AI, and GDPR still applies to the personal data it handles.

How big are the fines for a small business?

Breaching obligations such as the transparency rules can cost up to €15 million or 3% of global annual turnover, and prohibited AI up to €35 million or 7%. For SMEs, the lower of the two figures applies instead of the higher. The Omnibus extends that to small mid-caps, except for prohibited AI. These are ceilings rather than fixed tariffs.

Who enforces the EU AI Act?

Each member state designates national authorities to supervise the rules, while the Commission's AI Office oversees general-purpose AI models. In Denmark, for example, the Agency for Digital Government (Digitaliseringsstyrelsen) is the national coordinating authority, with oversight split by sector. Data protection authorities still enforce GDPR alongside the AI Act, so personal data questions go to them as before.

Does using ChatGPT internally count?

Yes, but the obligations are light. Your company is a deployer, so the AI literacy duty in Article 4 applies and your staff should understand the tools they use. If people start using a chatbot to sort job applicants or assess employees, you're moving toward high-risk territory. GDPR also applies to any personal data pasted into the tool.

Should I wait for the rules to settle before building AI features?

No, not if your feature is minimal risk or only needs transparency. Those rules are already in force and manageable. Build disclosure, logging and marking of generated content in from the start, and it costs almost nothing. Only if your idea sits in a high-risk area should you pin down the requirements first, because they shape your architecture, documentation and timeline.