Short answer: If your business uses AI tools, two obligations apply now: prohibited practices (since February 2025) and AI literacy for staff dealing with AI systems (also since February 2025). Transparency obligations under Article 50 became enforceable from 2 August 2026. The heavy documentation requirements apply only to high-risk systems — which most small businesses never deploy — and those deadlines have been pushed back.
This is general information, not legal advice, and the timetable has moved more than once. Verify current dates before relying on them.
What's actually live for a typical small business
Prohibited practices. A short list of banned uses — social scoring, certain manipulative techniques, some biometric categorisation, emotion inference in workplaces and education. Applicable since February 2025. Most small businesses aren't near these, but the workplace emotion-inference prohibition catches some HR and monitoring tools that businesses adopt without realising.
AI literacy. Organisations must ensure that staff dealing with AI systems have a sufficient level of AI literacy, taking into account their role and context. There's no prescribed curriculum. In practice, a documented usage policy plus recorded training satisfies it, and that record is what you'd produce if asked.
Transparency (Article 50). Enforceable from 2 August 2026. Covers three situations relevant to small businesses: telling people when they're interacting with an AI system, disclosing emotion-recognition or biometric categorisation, and marking AI-generated or manipulated content in a machine-readable way. For most businesses this is a chatbot notice and a content disclosure practice — not an engineering project.
What's been delayed
The obligations for high-risk systems — conformity assessment, technical documentation, risk management systems, registration — were originally due in August 2026 and have been pushed back through the Digital Omnibus process, with the high-risk timetable now running into late 2027 and 2028 depending on category.
This is the source of most of the confusion in 2026. "The AI Act has been delayed" is true of the high-risk regime and false of everything above. If your business doesn't deploy AI in hiring, credit scoring, education, essential services or similar, the delay changes very little for you — because those obligations were never going to apply.
Are you a provider or a deployer?
The distinction determines almost everything.
- Provider — you develop an AI system and put it on the market under your own name. Heavier obligations.
- Deployer — you use an AI system in your business. Lighter obligations, and this is what most small businesses are.
The trap: if you take a third-party model, put your branding on it and offer it as your own product, you may become a provider. Businesses embedding chatbots or AI features into a client-facing product should check this carefully rather than assuming deployer status.
What to actually do
- Build an AI use register. Every AI tool in use, who uses it, for what, on what data. Include the tools nobody officially approved — that's where the surprises are.
- Check against prohibited practices. A short review, usually a clear pass.
- Classify each use. High-risk, limited-risk (transparency obligations), or minimal. Most will be minimal.
- Write a usage policy and run training. Record it. This satisfies the literacy obligation.
- Fix your transparency gaps. Chatbot disclosure, AI-generated content labelling.
- Review annually or when you adopt a significant new tool.
For a business with a handful of AI tools, that's a few days of work, not a compliance programme.
Frequently asked questions
Does this apply if we only use ChatGPT for drafting?
The literacy obligation applies. Transparency obligations generally don't unless output is customer-facing in a way that triggers disclosure. The high-risk regime doesn't.
What if we're UK-based?
The Act applies extraterritorially where AI output is used in the EU, so many UK businesses are in scope. See our dedicated guide on this.
Who enforces it?
National market surveillance authorities in each member state, with the AI Office handling general-purpose AI models at EU level.
We help founder-led businesses find the handful of obligations that genuinely apply — without the scare tactics. Start a free assessment.
