The EU AI Act: What SMEs Need to Know About AI Regulation

The EU AI Act is the first comprehensive regulation of artificial intelligence, and it applies to small and medium-sized businesses too. The good news: for most applications in a practice, workshop or law firm, the obligations are manageable. This article shows how to classify your AI tools, which obligations already apply and what to tackle in which order.
What the EU AI Act is about
The regulation has been in force since August 2024 and is taking effect in stages. It doesn't regulate the technology as such but how it is used, according to risk. The greater the possible consequences for people, the stricter the requirements. A spam filter is treated differently from software that helps decide on job applications or loans.
Two things have applied since February 2025: certain applications are banned, and businesses that use AI must ensure their staff have sufficient AI literacy. Further obligations, for example for high-risk systems and on transparency, come in step by step. At the end of 2025 the European Commission proposed changes to some deadlines. So check the current status before you plan around a particular date. This article is not legal advice.
Provider or deployer: your role determines your obligations
The AI Act mainly distinguishes between providers, who develop an AI system and place it on the market, and deployers, who use it under their own responsibility. The vast majority of SMEs are deployers. A dental practice that uses a phone assistant is a deployer. The maker of the assistant is the provider and carries most of the obligations, such as those on technical documentation.
Take care if you substantially modify someone else's system, offer it under your own name or use it for a purpose other than the one the manufacturer intended. You may then slip into the provider role yourself. If you resell an AI solution to clients, as an agency for example, have this checked carefully.
The risk classes, with examples from the Mittelstand
| Risk class | Examples | What deployers have to do |
|---|---|---|
| Prohibited | Social scoring, manipulative techniques that exploit vulnerabilities, emotion recognition in the workplace | don't use them |
| High risk | Automated pre-selection of job applications, assessment of employees, credit checks | follow the instructions for use, ensure human oversight, monitor operation, keep logs, inform the people affected |
| Transparency obligations | Chatbots and phone assistants dealing with customers, AI-generated images or texts meant to inform the public | disclose that AI is involved |
| Minimal risk | Spam filters, translation aids, text suggestions for internal use | no specific obligations under the AI Act, but AI literacy still applies |
A typical trades business using AI for bookings and customer communication falls into the transparency class. It's different if you use a tool that automatically sorts or rejects job applications. That counts as high risk, and you should get advice before using it.
What the EU AI Act means for SMEs in practice: six steps
- Create an AI inventory. List every tool that contains AI: the chatbot on your website, phone assistant, text generators, translation, features in your CRM. Also ask your team which services they use privately for work.
- Clarify your role. For each tool, note whether you only use it or modify it and pass it on.
- Assign a risk class. Most entries will be minimal risk or subject to transparency obligations. Flag anything to do with personnel decisions, loans or access to essential services.
- Ensure AI literacy. Anyone who works with AI should know what the system can do, where it makes mistakes and which data doesn't belong in it. In small businesses a short training session and a written usage rule are often enough. Document both.
- Build in transparency. Every chatbot and every phone assistant should identify itself as an AI at the start. Formally this duty falls mainly on the provider; in practice you, as the deployer, make sure the notice reaches the customer.
- Link it to the GDPR. The AI Act doesn't replace data protection. Data processing agreements, storage location and retention periods remain separate topics.
You can read more about how the two sets of rules fit together in our article GDPR and AI chatbots. The article EU or US hosting for AI tools explains why server location matters as well.
An example: the phone assistant in a physiotherapy practice
A physiotherapy practice has a digital assistant take calls outside treatment hours. It books and moves appointments and answers questions about prescriptions. The practice is the deployer, and the use falls under the transparency obligations. The assistant opens every call with a sentence such as "You're speaking to the practice's digital assistant". The team was briefly shown which requests the assistant passes on to people. Because health data may be involved, the practice also clarified with its data protection officer which details may be asked for during the call.
Neurobots assistants are designed for exactly this case: they work in line with the GDPR, with data on servers in Frankfurt, and we recommend that our customers build the AI notice into the greeting.
Where you don't need to go to great lengths
A beauty salon with online booking and a chatbot on its website doesn't need an expensive expert opinion. The inventory, proof of training, an AI notice in the conversation and the usual data protection documents cover most of it. Be sceptical of offers that use fear of fines to sell expensive all-in packages. External advice is worth it where you work with high-risk applications or offer AI products yourself.
Keeping your documents up to date matters more than a thick binder. New tools often arrive unnoticed, because a software vendor adds an AI feature or an employee discovers a handy service. So make it a rule that new AI applications are briefly reported and added to the inventory before they are used. In most small businesses, a look at the list once every six months is enough.
Frequently asked questions
Does the AI Act apply to very small businesses too?
Yes, there's no lower limit based on headcount. The regulation does provide relief for SMEs, for example on fines and on access to regulatory sandboxes run by the authorities. The obligations depend on the purpose of use, not on size.
Do I need rules on how my staff use ChatGPT and similar services?
That is strongly recommended. The AI literacy requirement covers these tools as well, and from a data protection point of view it's essential that no customer or patient data ends up in unvetted services. A one-page internal policy is a good start.
Is an AI phone assistant a high-risk system?
As a rule, no, as long as it books appointments and answers questions. It is subject to the transparency obligations. Things may be different if it decides on access to essential services.
What happens in the event of a breach?
The AI Act provides for substantial fines, graded by severity; for SMEs the lower of the respective maximum amounts applies. You'll find more on security in the article AI data security for businesses, and AI for German businesses gives an overview of the situation in Germany.
Conclusion
For most SMEs the EU AI Act is above all an obligation to get organised: know which AI you use, train your team and tell customers openly when they are talking to an AI. If you automate job applications, loans or similarly far-reaching decisions, look more closely and get advice.
The page Digital assistant for service centres shows how a transparent AI assistant in customer service is set up.
Neurobots for your industry
See how AI employees handle inquiries and appointments in your industry.
View all industry solutionsNote: This article is for general information only. It is not legal advice and was not written or reviewed by lawyers. For your specific situation, please consult a lawyer. All information is provided without guarantee.
Related Articles

EU vs US Data Hosting for AI Tools: Why Location Matters
What the difference between EU and US hosting means legally for your AI tools, and how to check providers with a checklist.

Why ISO 27001 Matters When Choosing an AI Provider
What an ISO 27001 certificate tells you about an AI provider, why the scope is decisive and which questions to ask before signing a contract.

AI Data Security for Businesses: Protecting Customer Data
Which customer data AI systems collect, where the typical weak points are, and which measures and provider questions help you protect that data effectively.
AI Automation for Your Business
Let's find out together which of your processes can be automated with AI employees — free and without obligation.
Book a free consultationROI
Calculated before the start, measured continuously
