There has been a great deal written about the EU AI Act. Some of it is useful. Some is unnecessarily alarming, and quite a lot is already out of date.
The main provisions of the Act became applicable on 2 August 2026. However, the deadlines for the rules covering high-risk AI systems were extended by the EU’s AI Omnibus, which came into force in July 2026. High-risk systems used in areas such as employment, education and access to essential services now have until December 2027, while AI incorporated into regulated products has until August 2028. The European Commission provides the current timetable here.
So what does this mean for a small UK business using ChatGPT, Microsoft Copilot or another AI tool?
1. Does the EU AI Act apply to UK businesses?
It can.
The UK is no longer part of the EU, so the Act does not automatically apply to every UK business. However, its reach extends beyond businesses based within the EU.
It may apply if you:
- sell or provide an AI system in the EU;
- operate or have an establishment in the EU;
- use AI to provide services or produce outputs that are used in the EU; or
- affect customers, employees or other people located in the EU.
The official wording includes providers and users of AI systems outside the EU where the output produced by the system is used within the EU. You can read the EU AI Act’s scope in Article 2.
For a UK consultant preparing an AI-assisted report for a client in France, for example, the position may be different from that of a local retailer using AI only to draft internal notes.
The location of your business is not the only consideration. You also need to look at where your customers are and how the AI output is being used.
2. If I only use ChatGPT or Copilot, am I an AI provider?
Usually not.
The Act distinguishes between a provider, which develops or supplies an AI system, and a deployer, which uses an AI system professionally.
Most solopreneurs and SMEs using an established tool are deployers. The technology company providing the model carries many of the technical obligations.
That does not remove your responsibility for how you use the tool.
Your responsibilities can increase if you:
- build your own AI product;
- substantially modify an existing system;
- add an AI model to a service you sell;
- offer an AI system under your own business name; or
- use AI to make decisions about people.
Buying access to a compliant tool is only part of the picture. The supplier is responsible for the system it provides. You remain responsible for the business decisions you make with it.
3. Is ordinary use of generative AI classed as high-risk?
In most cases, no.
Using AI to draft an email, summarise a meeting, generate ideas or create a first version of a social media post will normally be considered minimal or limited risk.
Risk rises when AI is used to influence decisions that can significantly affect someone’s life. Examples include:
- screening job applicants;
- deciding who receives a loan or insurance;
- assessing eligibility for essential services;
- evaluating employees;
- making decisions in education, healthcare or legal services; and
- certain uses of biometric identification.
The purpose and context matter more than the name of the tool.
Using ChatGPT to improve the wording of a job advertisement is not the same as using an AI system to score candidates and decide who receives an interview.
4. Do I need to provide AI training?
The Act contains an AI literacy requirement. Providers and deployers must take measures to ensure that staff and others using AI on their behalf have an appropriate level of knowledge and understanding.
This requirement has applied since February 2025. The level of training should reflect the person’s role, the system being used and the risks involved. The European Commission has published guidance on AI literacy.
For a small business, this does not necessarily mean buying a formal qualification.
It does mean that people using AI should understand:
- what the tool can and cannot do;
- the risk of incorrect or invented information;
- what information must not be entered;
- when human review is required;
- how bias may affect outputs; and
- who is responsible for approving the final result.
If you are a solopreneur, the requirement still matters. You need to be able to show that you understand the tools you use and have made sensible decisions about risk.
5. Must I label everything created with AI?
No.
The Act does not require every AI-assisted email, blog post or social media update to carry an AI label.
Providers of generative AI systems have technical duties relating to the marking and detection of AI-generated content. Separate disclosure requirements apply to certain uses, including deepfakes and some AI-generated material published to inform the public on matters of public interest. These requirements are set out in Article 50.
If a person has reviewed the content, taken editorial responsibility and can be held accountable for it, different provisions may apply.
There is also a difference between legal compliance and building trust.
A statement such as:
“Human authored. AI assisted. Human reviewed.”
can be a useful declaration of working practice, even when it is not legally required. It tells readers that AI contributed to the process but a person remains responsible for the content.
6. What about AI-generated images, video and audio?
You need to be particularly careful where the content could be mistaken for a real person, event or statement.
If AI has created or manipulated an image, audio recording or video in a way that constitutes a deepfake, disclosure will generally be required. The disclosure needs to be clear and made when someone first encounters the content.
This is especially important when using:
- cloned voices;
- realistic avatars;
- altered photographs;
- synthetic testimonials;
- reconstructed events; or
- videos in which a real person appears to say something they did not say.
A lightly edited background image is not the same as a fabricated video of a real person. Context and the likelihood of deception matter.
7. Can I use AI in recruitment?
This is one of the areas requiring the most care.
AI used to filter applications, rank candidates, analyse interviews or evaluate employees may fall within the high-risk category. The relevant high-risk requirements are now due to apply from December 2027, following the revised EU timetable.
UK law already requires employers to consider data protection, discrimination and fairness. The EU deadline should not be treated as permission to ignore those issues until 2027.
If you use recruitment technology, ask the supplier:
- What role does AI play in the decision?
- What data is collected?
- Has the system been tested for bias?
- Can a person challenge or override its recommendation?
- What records and explanations are available?
- Does the supplier classify the system as high-risk under the EU AI Act?
Human involvement needs to be genuine. Clicking “approve” after accepting an AI recommendation without examining it is not meaningful oversight.
8. Can I enter customer or employee information into an AI tool?
The AI Act does not replace data protection law.
If you use personal data with AI, the UK GDPR and Data Protection Act continue to apply. You need an appropriate lawful basis, a clear purpose and suitable security. You must also consider what the AI supplier does with the information.
The Information Commissioner’s Office advises organisations to assess the risks to people’s rights and to explain decisions made or assisted by AI. The ICO’s AI and data protection guidance is available here.
Before entering information into an AI tool, check:
- whether it contains personal or confidential data;
- whether your account is a consumer or business version;
- whether the supplier uses prompts to train its models;
- where the data is stored;
- how long it is retained; and
- whether your client contract permits this use.
Removing a person’s name does not always make information anonymous. They may still be identifiable from the other details provided.
9. Do I need an AI policy if I am a very small business?
You may not need a lengthy policy, but you do need clear rules.
A useful policy for a small business should answer practical questions:
- Which AI tools are approved?
- What information must never be entered?
- Which tasks can AI assist with?
- Which decisions must remain with a person?
- Who checks facts, figures, sources and copyright?
- When should AI use be disclosed?
- What happens if something goes wrong?
- When will the policy be reviewed?
An AI policy should be part of your working process. A document that is written once, filed away and never mentioned again provides little protection.
Your policy, training and day-to-day instructions should all say the same thing.
10. What happens if a small business gets it wrong?
The maximum fines under the Act are substantial. The highest penalties apply to prohibited AI practices, with other levels covering breaches of provider, deployer and transparency obligations.
For SMEs, the Act states that the lower of the fixed maximum or turnover percentage should apply. Regulators must also consider the size of the organisation, the seriousness of the breach, whether it was deliberate, the steps taken to reduce harm and the level of co-operation. The penalty provisions are set out in Article 99.
The headline fines should not distract from the more immediate business risks:
- loss of client trust;
- disclosure of confidential information;
- inaccurate advice or content;
- discrimination;
- contractual disputes;
- reputational damage; and
- action under existing data protection or consumer law.
For most small businesses, these are more likely to be the first consequences of poor AI use.
What should you do now?
Start with a simple audit of how AI is already being used.
List the tools, the tasks they support, the information being entered and the person responsible for the final decision. Then identify where AI is being used with personal data, confidential material, recruitment, financial decisions or services delivered to EU customers.
You do not need to stop using AI. You do need to know where it is being used and where human judgement sits.
The practical principle remains straightforward:
AI can draft, analyse and assist. A person must remain responsible for the decision.
If you are unsure where your current AI use creates risk, an AI Adoption Audit can help you identify what is working, what needs clearer controls and what should change before AI becomes more deeply embedded in the business.
This article provides general information and is not legal advice. The application of the EU AI Act depends on the business, system, customer location and particular use of AI. Specialist legal advice may be needed for high-risk or regulated activities.
Human authored. AI assisted. Human reviewed.